Last updated: April 28, 2026
This Privacy Policy implements Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) and the Austrian Data Protection Act (Datenschutzgesetz, “DSG”). The English version prevails; any local-language version is provided for convenience.
The controller within the meaning of Art. 4(7) GDPR is:
influence solutions fm GmbH
Gemeindeaugasse 22/2
1220 Vienna, Austria
Email: customer-support@specky.space
Firmenbuchnummer: FN 675374y · Firmenbuchgericht: Handelsgericht Wien
Full statutory disclosure pursuant to § 5 ECG / § 14 UGB is available in our Imprint.
We have not appointed a designated Data Protection Officer because we are not subject to the mandatory designation criteria in Art. 37(1) GDPR. For all data-protection enquiries and to exercise your rights, please contact customer-support@specky.space. EU/EEA-based data subjects who wish to address an EU representative pursuant to Art. 27 GDPR may write to the same address; we will route the request internally.
We process the following categories of personal data:
| Purpose | Legal basis |
|---|---|
| Account creation, authentication, provision of the Service | Art. 6(1)(b) — contract performance |
| AI assistance features (chat, generation, search) | Art. 6(1)(b) — contract performance |
| Billing, invoicing, fraud prevention | Art. 6(1)(b) and (c) — contract / legal obligation |
| Statutory accounting retention (7 years, § 132 BAO) | Art. 6(1)(c) — legal obligation |
| Product analytics and bug debugging (PostHog) | Art. 6(1)(a) — consent (cookie banner) |
| Marketing analytics (Google Analytics) | Art. 6(1)(a) — consent (cookie banner) |
| Service improvement, security, abuse prevention | Art. 6(1)(f) — legitimate interest in operating a secure, reliable service |
| Optional third-party integrations | Art. 6(1)(a) — consent, granted on connect, withdrawable any time |
| Direct e-mail marketing to existing customers | § 174(4) TKG 2021 / Art. 6(1)(f); opt-out in every message |
| Compliance with legal requests, court orders | Art. 6(1)(c) — legal obligation |
Where we rely on legitimate interest (Art. 6(1)(f) GDPR) we have performed a balancing test; you can request a summary from us. Where consent is the basis, you may withdraw it at any time without affecting prior processing.
Specky uses generative AI (Google Gemini, hosted by Google LLC) to power chat, document generation and search features. Pursuant to our agreement with Google and the Google Cloud Data Processing Addendum:
We do not use your data for solely automated decision-making with legal or similarly significant effects within the meaning of Art. 22 GDPR. AI-generated outputs are advisory, never determinative, and you remain in full control of any decision based on them. As required by Article 50 of Regulation (EU) 2024/1689 (the EU AI Act), we make it visually clear in the product that you are interacting with an AI system.
Within Specky, access to personal data is limited to authorised personnel on a need-to-know basis. We share personal data with the following sub-processors (Art. 28 GDPR), each bound by a written data-processing agreement:
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Supabase Inc. | Database, authentication, file storage | EU (Frankfurt, eu-central-1) | Within EEA — none required |
| Vercel Inc. | Application hosting & edge network | EU edge with US origin | EU SCCs (2021/914) + DPF |
| Google LLC (Gemini) | Generative AI inference | United States | EU SCCs + EU-US Data Privacy Framework |
| Stripe Payments Europe Ltd. | Payment processing | Ireland (EU) | Within EEA — none required |
| PostHog Inc. | Product analytics (consent-based) | EU (eu.posthog.com) | Within EEA — none required |
| Resend Inc. | Transactional email | United States | EU SCCs + DPF |
| Google LLC (Analytics) | Marketing analytics (consent-based) | United States | EU SCCs + DPF |
| Upstash Inc. | Rate limiting and caching (Redis) | EU (eu-west-1) | Within EEA — none required |
An up-to-date sub-processor list is maintained at /security. We notify business customers in advance of any new sub-processor. Beyond the above, we do not share personal data with third parties, except where required by law or in the event of a corporate transaction (in which case the recipient is bound to equivalent confidentiality and data-protection obligations).
Where personal data is transferred outside the EEA, we rely on one or more of the following safeguards under Chapter V GDPR:
You can request a copy of the relevant transfer mechanism by emailing customer-support@specky.space.
Anonymised, aggregated information may be retained indefinitely as it is no longer personal data within the meaning of Art. 4(1) GDPR.
We use cookies and similar technologies on the basis of § 165 Austrian Telecommunications Act 2021 (TKG 2021) and Art. 5(3) of Directive 2002/58/EC (“ePrivacy Directive”). Strictly necessary cookies do not require consent. All other cookies (analytics, performance, marketing) are loaded only after you have given prior consent through our cookie banner. You can withdraw consent at any time via the “Cookie preferences” link in the footer with the same ease as you gave it.
ph_*), retention up to 14 months; aggregated event analytics, no advertising._ga*) under Google Consent Mode v2; retention 14 months.We do not use third-party advertising or cross-site tracking cookies.
You have the following rights under the GDPR:
We respond within one month of receipt (Art. 12(3) GDPR). The period may be extended by up to two further months for complex or numerous requests, in which case we will inform you within the first month and explain the reason.
You also have the right to lodge a complaint with a supervisory authority — in particular in the Member State of your habitual residence, place of work or place of the alleged infringement (Art. 77 GDPR). For Specky the lead supervisory authority is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40-42, 1030 Vienna, Austria, dsb@dsb.gv.at, www.dsb.gv.at.
We implement appropriate technical and organisational measures within the meaning of Art. 32 GDPR, including TLS 1.2+ in transit, AES-256 at rest, role-based access control, row-level security, audit logging, and regular vulnerability management. We notify the competent supervisory authority within 72 hours of becoming aware of a personal data breach likely to result in a risk to rights and freedoms (Art. 33), and the affected data subjects without undue delay where the breach is likely to result in a high risk (Art. 34).
Specky integrates with Google Workspace (Drive, Gmail, Calendar, Docs, Sheets) via OAuth 2.0. We process Google user data only to provide the integration features you have explicitly enabled and strictly in accordance with the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, use it for advertising, transfer it except to operate the Service, or use it to develop, improve or train AI models. You can revoke access at any time from your Google account or from the Integrations panel in Specky.
Where Specky acts as a processor on behalf of a business customer, a Data Processing Agreement compliant with Art. 28 GDPR (including the EU SCCs as Annex) is available on request from customer-support@specky.space. For workspaces under a paid plan, the DPA is incorporated into the order form by reference.
The Service is not directed at and may not be used by individuals under 16. Where Austrian law applies, § 4(4) DSG sets the digital age of consent at 14, but we voluntarily set 16 as a more protective minimum. If we learn we have collected personal data from a child below the applicable threshold without verifiable parental consent, we will delete it without undue delay.
If you are a California resident, you have the right to know, the right to delete, the right to correct, the right to opt-out of the sale or sharing of personal information (we do not sell or share personal information for cross-context behavioural advertising), the right to limit the use of sensitive personal information (we do not collect sensitive PI as defined in CPRA), and the right to non-discrimination. To exercise these rights, email customer-support@specky.space. We respond within 45 days as required by Cal. Civ. Code § 1798.130.
We may update this policy from time to time. Material changes will be notified to registered users by e-mail or in-app notice at least 30 days before they take effect. The “last updated” date at the top reflects the most recent version. Previous versions are available on request.
For privacy-related questions, data subject requests or to obtain a DPA, write to customer-support@specky.space. Postal correspondence should be sent to the address listed in our Imprint.