Spensa - Privacy Policy
Effective date: 11.06.2026
This Privacy Policy explains how Spensa Ges.m.b.H. processes personal data in connection with the Spensa website, web application, mobile application, and related services.
Spensa is a business software service for restaurants, hospitality operators, and their staff. It is not intended for private consumer use.
1. Controller and contact
The controller for data processing carried out by Spensa for its own purposes is Spensa Ges.m.b.H., Jungstraße 15/6/18, 1020 Vienna, Austria. You can contact us at hello@spensa.ai.
Spensa has not appointed a data protection officer. Data protection requests can be sent to the contact address above.
2. Roles under data protection law
Spensa acts as controller for account administration, website operation, billing, security, support, service communication, and optional product analytics.
For personal data that customers upload, enter, or generate while using the service for their own restaurant operations, Spensa usually acts as processor. This includes staff, supplier, invoice, POS, inventory, scheduling, order, and document data. In that role we process personal data on the customer's instructions and under the Data Processing Agreement at /data-processing-agreement.
3. Data subjects and sources
The service may process data relating to customer administrators, organization members, establishment staff, supplier contacts, customer support contacts, and people named in uploaded or received business documents.
We receive data directly from users, from customer administrators, from documents and files uploaded or emailed into Spensa, from connected operational workflows, from payment and security providers, and from technical logs generated when the service is used.
4. Categories of personal data
Account and authentication data: names, email addresses, usernames, roles, permissions, password hashes, login events, invitation data, and session-related technical data.
Customer operational data: organization and establishment data, staff records, supplier contacts, products, orders, order emails, delivery notes, invoices, POS uploads, menu and recipe data, inventory records, schedules, availability, time-off records, shift requests, notes, and attachments.
Billing and contract data: billing contacts, plan data, subscription status, invoices, payment status, and payment provider references.
Support, security, and technical data: messages to Spensa, device and browser data, IP addresses, timestamps, request logs, error reports, performance data, abuse-prevention tokens, and consent preferences.
Optional analytics data: product usage events and account or organization identifiers processed only if analytics consent is given.
5. Purposes and legal bases
We process personal data to provide and maintain the service, authenticate users, manage organizations and establishments, support restaurant workflows, process documents, send transactional emails, provide billing, respond to support requests, keep the service secure, comply with legal obligations, and improve the product.
For Spensa as controller, processing is based on contract performance or pre-contractual steps, legitimate interests in operating and securing a B2B software service, consent where requested for optional analytics or comparable technologies, and legal obligations such as accounting and tax retention.
For customer-controlled operational data, Spensa processes the data on the customer's documented instructions. The customer is responsible for choosing the correct legal basis for its own staff, supplier, and document processing.
6. AI-assisted and automated processing
Spensa uses automated extraction and AI-assisted processing to read documents, classify attachments, suggest matches, support analytics, and assist users in working with restaurant data.
These functions are assistive. Outputs can be incomplete or incorrect and must be reviewed by users before they are relied on. Spensa does not use these systems to make decisions that produce legal or similarly significant effects for individuals within the meaning of Art. 22 GDPR.
7. Recipients and subprocessors
We share personal data only where needed to provide, secure, bill, support, or improve the service, or where required by law. This includes hosting, database, storage, cache, email, payment, security, analytics, error monitoring, OCR, and AI providers.
The current customer-facing subprocessor list is available at /subprocessors. Customer data is not sold.
8. International transfers
Some providers process personal data in the EU or EEA. Others may process data in third countries, including the United States. Where required, Spensa uses adequacy decisions, standard contractual clauses, transfer impact safeguards, or comparable lawful transfer mechanisms.
PlanetScale PostgreSQL and Upstash Redis are configured in EU regions for production database and cache processing.
9. Retention
Account and customer operational data is generally retained for the term of the customer relationship and then deleted or returned according to the contract and the Data Processing Agreement, unless longer retention is required by law or needed to establish, exercise, or defend legal claims.
Billing, accounting, and tax-relevant records are generally retained for seven years under Austrian business and tax retention rules, and longer where a pending proceeding requires it.
Security logs, error reports, support records, consent records, and backups are retained for limited periods based on operational, security, legal, and recovery needs.
10. Cookies, local storage, and analytics consent
Spensa uses necessary cookies and local storage for login, security, language selection, consent preferences, and core application functions. These are required to provide the requested service.
Optional product analytics, including Mixpanel, are used only after analytics consent. You can reject optional analytics, accept it, or change your preference later through the privacy settings link.
Sentry is used for error and performance monitoring on the basis of Spensa's legitimate interest in keeping the service secure and reliable. Sentry Session Replay, broad page unmasking for replay capture, and richer browser user context are used only after analytics consent.
11. Data subject rights
Subject to the legal requirements and limits of the GDPR, data subjects may request access, rectification, erasure, restriction, portability, and objection. Where processing is based on consent, consent can be withdrawn at any time with effect for the future.
Requests can be sent to hello@spensa.ai. If Spensa processes the relevant data as processor for a customer, we may forward the request to the customer or ask the data subject to contact the customer directly.
Data subjects also have the right to lodge a complaint with a supervisory authority. In Austria, complaints can be submitted to the Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna, Austria, dsb@dsb.gv.at.
12. Customer responsibilities
Customers and their administrators are responsible for ensuring that they are allowed to upload, enter, email, and process personal data in Spensa. This includes staff data, supplier contact data, invoice data, POS data, scheduling data, and any personal data contained in documents or attachments.
Customers must provide required notices to their own staff, suppliers, and other affected individuals and must configure access rights appropriately.
13. Security
Spensa uses technical and organizational measures designed to protect personal data, including access controls, tenant separation, encryption in transit, controlled storage access, logging, monitoring, backups, and internal confidentiality obligations.
No system is completely secure. Customers must also protect their own accounts, devices, permissions, and exported files.
14. Changes and contact
We may update this Privacy Policy when our service, providers, or legal requirements change. The current version is published on this page.
Questions about privacy or data protection can be sent to Spensa Ges.m.b.H., Jungstraße 15/6/18, 1020 Vienna, Austria, or hello@spensa.ai.