SPONA ERP — LEGAL DOCUMENTS 2026-09-17 · 1.1 English is the governing language of the Terms to the extent permitted by law. # Privacy notice ## 1. Scope and responsibility This notice covers the Spona website, business accounts, enquiries, support and optional financing requests. Top Digital Agency Limited, company number 642562, VAT ID IE3613706OH, 6B Raven Terrace, Galway, H91 H24H, Ireland, provides the ERP. Top Digital d.o.o., MBS 081170998, OIB 72317551155, VAT ID HR72317551155, Vladimira Nazora 23, 49210 Zabok, Croatia, administers financing. For privacy enquiries and rights requests, contact connect@spona.io and identify the service concerned. This address is the privacy contact, not a claim that a statutory Data Protection Officer has been appointed. ## 2. Two different roles For managing its business relationships, account security and its own enquiries, the operator acts as a controller. For personal data a customer places in Work, People, Salaries, Purchasing, Sales or Accounting, the customer generally decides the purposes and acts as controller; the operator processes those records on documented instructions under the Data Processing Agreement. A customer acting for another controller must obtain the necessary authority. Financing participants may act as separate controllers for their own assessment and legal obligations; their notices must identify those activities. ## 3. Data and its sources Data may include names, work email addresses, company identifiers, account roles, authentication records, enquiries and support messages. Customer-controlled ERP records may include employees, salary amounts, clients, suppliers, project assignments, milestones, orders, invoices and attachments. Financing requests may add identification and contact information, transaction documents, requested amounts and terms, acknowledgements and application status. Sources are you, your organisation and its authorised users, counterparties and documents you supply. Where data comes from another source, the responsible controller must provide the required indirect-collection information, subject to lawful exceptions. ## 4. Purposes and legal bases We use necessary account and enquiry information to provide the service, respond to requests and manage the business relationship. Where you personally contract with us, this relies on contract performance or requested pre-contractual steps under Article 6(1)(b) GDPR. For corporate representatives, relationship administration and business communication rely on our legitimate interest in operating and supporting business services under Article 6(1)(f). Security, preventing misuse and establishing or defending legal claims also serve legitimate interests, subject to necessity and your rights. Processing required by a specific legal obligation relies on Article 6(1)(c). Optional tracking and marketing use separate consent where required. Customer-controlled ERP records are processed on documented instructions under the DPA; the customer establishes the basis for those records. Accepting service terms does not consent to every use of data. ## 5. Employee activity and sensitive records The ERP code records authenticated activity and visited application routes, and exposes authorised team activity views. Presence buckets and page-view records have a 90-day pruning window, triggered by application activity; this is not a guarantee of deletion at exactly day 90 or a retention rule for all audit logs and backups. Employers must assess necessity, proportionality, access and employee transparency before using these features. Do not use activity alone to make employment decisions. Health, union membership and other special-category data require an Article 9 condition as well as an Article 6 basis; do not upload them unless the service scope and safeguards have been expressly agreed. ## 6. Recipients and hosting Authorised personnel and contracted providers may access data where needed to deliver and support the service. Spona hosting is provided by Hetzner in Nuremberg, Germany. Hosting data may include account details, company records, uploaded files and technical logs needed for the service. Relevant transaction data may be shared with the identified financing counterparty and its authorised providers; an enquiry does not grant access to an entire ERP workspace. Professional advisers and competent authorities may receive data where lawfully required. Additional provider, backup and transfer arrangements must be disclosed for the affected service before activation. The German hosting location alone is not a statement that every external service processes data only in Germany. Transfers outside the EEA require applicable safeguards; contact connect@spona.io for information and copies of relevant safeguards. ## 7. Analytics, datasets and AI The website includes a consent-gated Google Analytics 4 integration planned for production, currently disconnected pending its measurement ID. See the Cookie notice for controls, data and cookie details. Advertising integrations remain off. The platform includes optional AI briefing code which, when enabled, sends selected findings, narrative labels and figures to the Anthropic API. Reduced or aggregated inputs can still identify a person or reveal confidential business information. Production activation, provider terms, retention and safeguards require confirmation. This notice does not authorise customer personal data or confidential content to train general-purpose models, be sold or be shared across customers. Properly anonymised, non-identifying statistics may support product improvement, research and commercial benchmarks under the safeguards in the Terms and DPA; creating those statistics is itself processing that first needs authority and a lawful basis. ## 8. Retention and security We retain account records while needed to administer the service and complete closure; enquiries and support records while needed to respond, resolve the matter and handle related claims; and financing and transaction records for the agreement and applicable legal recordkeeping or claims periods. Customer-controlled ERP records follow documented instructions and the DPA. Legal holds are limited to the relevant records and obligation. Backup copies are restricted to recovery and lawful retention and must not restore deleted records to ordinary use. Contact connect@spona.io for the period or criteria applicable to a specific record and to request deletion. Account access and file access are permission-controlled. No system is absolutely secure; no independent security certification or contractual availability percentage is claimed here. Any specific recovery or availability commitment must be separately agreed. ## 9. Your choices and rights Subject to the applicable conditions, you can request access, correction, erasure, restriction and portability, and object to processing based on legitimate interests. You can object to direct marketing at any time and withdraw consent without affecting earlier lawful processing. Contact connect@spona.io and identify the service and request; provide only information reasonably needed to verify identity. Requests are normally answered within one month. A lawful extension of up to two further months requires notice and reasons within the first month. For customer-controlled ERP records, contact your organisation; the operator assists it. You may complain to a supervisory authority in your habitual residence, workplace or the place of the alleged infringement, including the Data Protection Commission in Ireland and AZOP in Croatia. No prior complaint to us is required. ## 10. Required information and decisions Without necessary account or transaction information, the relevant service or financing assessment may not be possible. Optional marketing permission must not be a condition of core ERP access. The reviewed financing flow contains a review process; it does not establish that every production decision is manual. Before any solely automated decision with legal or similarly significant effects is used, the responsible controller must establish a lawful basis, provide meaningful information about its logic and consequences, and implement applicable safeguards, including human intervention and challenge rights. # Website & ERP terms ## 1. Parties, scope and acceptance These terms govern business use of Spona websites and ERP services. Businesses worldwide may register for the ERP, subject to these terms and applicable law. Registration does not guarantee financing availability or support for every country’s accounting, payroll or tax requirements. The ERP provider is Top Digital Agency Limited, company number 642562, VAT ID IE3613706OH, 6B Raven Terrace, Galway, H91 H24H, Ireland. Top Digital d.o.o., MBS 081170998, OIB 72317551155, VAT ID HR72317551155, Vladimira Nazora 23, 49210 Zabok, Croatia, administers the optional financing service. Together they are referred to as Spona where the context permits; each is responsible for the services it provides. You must be at least 18, have legal capacity and be authorised to bind the business you represent. By registering or accepting these terms you agree for yourself and that business. A separately signed agreement prevails for its subject matter; the Data Processing Agreement governs processing on your instructions, and the transaction agreement governs financing. Merely using a calculator or viewing these pages does not enter you into a financing agreement. ## 2. Free ERP and separately agreed services The available Work, People, Salaries, Purchasing, Sales and Accounting modules and their Power add-ons have no licence or per-user fee. You choose the modules and permissions that fit your business. Separately agreed implementation, maintenance, consulting and custom or white-label work may carry fees. Agreed API integration development is free; feasibility, scope, timing, third-party costs and maintenance are agreed before work starts. Financing is optional and carries the single disclosed transaction fee described below. There is no additional undisclosed platform administration fee. Features marked coming soon are not available features or delivery commitments. Any future material change to the free offer or charges is prospective, notified reasonably in advance and does not alter an already agreed transaction. ## 3. Accounts and lawful use The customer controls user invitations, permissions, accurate records and lawful instructions. Protect credentials, remove departing users and report suspected compromise promptly. Do not upload unlawful content, malware or data you lack authority to process; bypass access controls, interfere with other tenants or use the service for fraud. Security testing requires written agreement on scope. The customer must give appropriate employee and counterparty notices and establish a legal basis for their data; accepting these terms cannot waive those individuals’ rights. ## 4. Ownership and processing licence The customer retains its rights in uploaded content. It grants the operator a non-exclusive right to host, reproduce, organise, transmit and otherwise process that content only to deliver the contracted services, follow documented instructions, secure the service and meet applicable law. Approved providers may exercise those rights only within their contracted tasks. The operator retains rights in its software, designs and documentation. Feedback may be used without payment provided it does not disclose customer confidential information or personal data. No general ownership transfer of customer datasets occurs. ## 5. Permitted aggregate datasets Subject to an approved lawful processing arrangement, the operator may develop and commercially use statistics that cannot reasonably identify a person or customer, reveal customer trade secrets, or permit singling out, linkage or reconstruction. Permitted purposes include service improvement, capacity planning, research and published benchmarks. Anonymisation must be assessed against reasonably available means and reviewed as risks change; small groups and identifiable outliers must be excluded or protected. Pseudonymisation alone is insufficient. Personal data remains subject to the DPA and GDPR until effectively anonymised. These terms do not authorise selling personal records, cross-customer disclosure of source records or training general-purpose AI on confidential content. Any such additional project requires a separate, specific assessment and agreement before processing. ## 6. Confidentiality and providers Each party must protect the other’s non-public business information, limit access to people who need it and are bound by confidentiality, and use it only for the agreement. Exceptions apply to information lawfully public, independently developed or lawfully received without restriction. A legally required disclosure must be limited and, where permitted, notified. Approved subprocessors remain subject to the DPA. A financing partner’s independent assessment is governed by its disclosed role and transaction documents, not an unrestricted licence to the ERP database. ## 7. Records, estimates and professional judgement The ERP supports business records and workflows. It does not replace the customer’s accountant, lawyer or statutory reporting responsibilities. Salary records do not promise a compliant payroll calculation or filing. A financing estimate is illustrative and is not an offer, approval or guarantee. Customers must check source records and outputs, including AI summaries, before acting. The operator remains responsible for obligations that cannot lawfully be excluded; these provisions do not excuse its own failure to provide agreed services with the legally required standard of care. ## 8. Suspension and termination Either party may terminate the service agreement by notice. Contact connect@spona.io for account closure. Spona may restrict or suspend access where reasonably necessary for a breach, credible security threat, fraud, unlawful use, inability to verify necessary information or a binding legal requirement. Where lawful and practicable, notice and an opportunity to remedy will be provided; urgent protection may require immediate action. Spona will notify you of a suspension and its grounds within three business days unless prohibited by law. Closing an ERP account does not cancel outstanding financing agreements or accrued payment obligations. Confidentiality, intellectual-property rights, lawful retention, liability provisions and applicable dispute-resolution terms survive termination. Mandatory data retrieval and switching rights remain unaffected. ## 9. Your records, export and switching You retain ownership of your records and applicable portability and switching rights. Contact connect@spona.io to request export or plan a move, identifying the company, records and intended destination. Available module exports can be used directly; a complete workspace transfer may require assistance and is not represented as an automatic one-click feature. Agree the scope, available formats, transition and retrieval arrangements before closing the account. Any charges, exclusions or operational arrangements remain subject to mandatory law, including the EU Data Act where applicable. No intellectual-property or trade-secret exclusion may defeat those rights. At the end of processing, personal data is returned or deleted as provided in the DPA, except where lawful retention applies. ## 10. Availability, warranties and liability To the fullest extent permitted by law, the service is provided as is and as available, without implied warranties of merchantability, fitness for a particular purpose, accuracy or non-infringement. Spona does not promise uninterrupted or error-free operation, business results or a particular financing outcome. Subject to mandatory law and any expressly agreed service commitment, Spona and its affiliates and service providers are not liable for indirect, incidental, consequential or punitive loss, including lost profits, opportunities, reputation, revenues or data. Aggregate liability shall not exceed the lesser of the fees you paid Spona in the twelve months preceding the claim and EUR 1,000. These exclusions and limits do not apply to fraud, wilful misconduct, gross negligence or liability that cannot lawfully be excluded, including mandatory data-subject rights and remedies. Spona remains responsible for its own obligations under applicable law. Nothing transfers liability for Spona’s own breach to you. ## 11. Platform role and your business relationships You choose and evaluate your clients, suppliers and subcontractors and agree the scope, delivery, price and payment dates with them. Spona does not select a counterparty for you, warrant its reliability, carry out its work or become its employer or partner. Ordinary ERP records and recorded payments do not require all your business payments to pass through Spona. An optional financing transaction has its own payment instructions. Spona is not a party to your underlying supply or service contract merely because it is recorded in the ERP. Any expressly appointed agency for transaction notices is limited to that written authority. Information and tools are not legal, tax or financial advice. ## 12. Accounts, notices and authorised users Provide accurate registration information, protect credentials and keep company and contact details current. You are responsible for the users you authorise and for activity under their permissions; revoke access promptly when authority ends and notify us of suspected compromise. Account creation requires the applicable registration and verification steps. Financing may require additional identity and business checks. Notices may be delivered within the service or to your supplied contact details. Optional communication preferences do not prevent necessary security, contractual or service notices. General and privacy enquiries: connect@spona.io. Formal legal notices: office@topdigital.agency; intellectual-property reports: legal@spona.io. ## 13. Optional financing The Financing disclosures form part of these terms. Supplier advances and client payment deferrals are separate alternatives, not two fees on one transaction. Each request requires review, applicable verification and signed transaction documents before a payment can be arranged. The agreement identifies the financing counterparty, recipient, fee, dates and obligations, including any responsibility if the original debtor does not pay. No acceptance of these general terms alone creates a financing commitment. Existing signed financing agreements remain governed by their agreed terms. ## 14. Disputes, governing law and language For disputes with Spona, email office@topdigital.agency with the account, facts and contact details. The parties will attempt informal resolution for 45 days after notice. Subject to mandatory law, these terms are governed by Irish law and disputes are subject to the exclusive jurisdiction of the Irish courts. A dispute exclusively about the financing service between a Croatian-established user and Top Digital d.o.o. is governed by Croatian law: the parties first negotiate, then attempt mediation through the Croatian Association for Conciliation for up to 60 days unless extended by agreement, and if unresolved proceed before the competent court in Zagreb. Mandatory rights to urgent relief, complaints to authorities and data-protection remedies are not excluded. A signed transaction agreement may specify the law and forum for that transaction. English is the governing language to the extent permitted by law; Croatian is provided for convenience. ## 15. General provisions and changes If a provision is unenforceable, it will be limited to the minimum extent necessary or severed without invalidating the remaining terms. Failure to enforce a provision is not a waiver. You may not transfer your account or agreement without Spona’s written consent. Spona may transfer its agreement to an affiliate or business successor subject to applicable law and without reducing mandatory rights. No employment, partnership or general agency is created and no third-party beneficiary is intended unless expressly stated. Material changes will be notified with the applicable effective date and any required acceptance process; a website edit does not retrospectively rewrite signed transaction agreements. The version shown on this page identifies the terms presented for acceptance. # Data Processing Agreement ## 1. Parties, scope and instructions This DPA forms part of the customer’s ERP agreement for personal data processed on the customer’s instructions. The customer acts as controller, or as an authorised processor appointing the operator as subprocessor; the operator acts as processor for the covered customer records. Process only on documented instructions, including transfers, unless Union or Member State law requires otherwise; inform the customer of that requirement beforehand unless prohibited. Immediately inform the customer if an instruction appears to infringe data-protection law and suspend the affected instruction while it is resolved. Own-controller activities disclosed in the Privacy Notice are outside this DPA. ## 2. Processing schedule Subject: delivery and support of selected ERP modules. Duration: the service term plus agreed retrieval and deletion periods, subject to lawful retention. Operations: collection, storage, organisation, access, calculation, transmission, export and deletion as instructed. Data subjects: customer users, employees, contractors, business contacts, clients and suppliers. Categories: identifiers and work contacts, roles, activity records, project and transaction records, salary and payment information and instructed attachments. The signed order must narrow these categories to the modules actually used and expressly identify any permitted special-category data. Financing-partner assessment is not automatically included in this processor schedule. ## 3. Confidentiality and security Authorised personnel must be bound by confidentiality. The processor must implement appropriate Article 32 measures proportionate to risk, including access management, tenant isolation, protection of data in transit and at rest where appropriate, resilience, recovery and regular evaluation. Any agreed security annex identifies the measures applicable to your service. This DPA does not claim an independent certification or a specific recovery time. Security changes must not materially reduce the agreed protection. ## 4. Subprocessors and transfers The customer must receive the completed subprocessor register before authorisation. Under the general-authorisation mechanism, give at least 30 days’ advance notice of additions or replacements and allow reasoned data-protection objections. Resolve an objection through reasonable alternatives or permit termination of the affected service before the provider begins processing. Each subprocessor must accept materially equivalent data-protection duties; the operator remains responsible for its performance. No international transfer may occur without applicable Chapter V safeguards and documented instructions. The provider register identifies approved hosting; additional providers require disclosure and authorisation under this clause. ## 5. Rights, incidents and regulatory assistance Taking account of the nature of processing, assist the customer with data-subject requests, security duties, breach assessment, DPIAs and prior consultation. Forward requests without answering for the customer unless authorised or legally required. Notify the customer without undue delay after becoming aware of a personal-data breach, with available facts about its nature, affected categories and approximate numbers, contact, likely consequences and mitigation; supplement information as it becomes available. The controller determines its own notification duties, including the GDPR 72-hour authority deadline where applicable. Assistance arrangements must not prevent statutory compliance. ## 6. Demonstrating compliance Make available the information necessary to demonstrate compliance and allow and contribute to audits, including inspections, by the customer or its mandated auditor. Reasonable confidentiality, scheduling and security arrangements may protect other customers and systems but must not defeat Article 28 audit rights or regulatory access. Maintain the required processing records and evidence of instructions, provider approvals, incidents and deletion. The customer remains responsible for its lawful purposes, notices, minimisation and employee-monitoring assessment. ## 7. Return, deletion and further use At the customer’s choice, return or delete covered personal data after the service ends and delete remaining copies unless applicable law requires storage. Agree export and retrieval periods before closure. Legally retained copies must be isolated and used only for that obligation. The final annex must define backup expiry and restoration controls so deleted records are not returned to active use. Processing to create anonymous datasets requires documented customer instructions and the customer’s lawful authority; this DPA does not permit independent reuse of personal data for advertising or general AI training. Genuine anonymous outputs may be used only within the Terms’ confidentiality and re-identification safeguards. # Cookies & browser storage ## 1. Website storage and your choices The website stores spona.website.consent in first-party localStorage to remember your privacy choice for up to 180 days. It contains the policy/provider version, choice time, expiry, language and category choices; no account identifier is added. Accept and reject choices use the same duration. The record expires on the next visit or while the page is active; the browser may retain expired bytes until the site runs again or you clear storage. Expired, missing, malformed or outdated records do not enable optional services. If storage is unavailable, the choice applies to the current page session and the site may ask again on reload. Necessary preference storage is used to honour your choice, not to advertise. When you select a website language, spona.website.language remembers that choice in first-party localStorage for up to 180 days, with the language, save time and expiry only. You can change it using the language switcher or remove it by clearing site storage. On a homepage visit without an explicit language, we use your saved choice first, then a country code supplied by Cloudflare from your connection, or your browser language if that code is unavailable. This feature does not request precise device location or store your IP address in the language preference. Explicit language links remain available. ## 2. ERP authentication The API sets a first-party HttpOnly cookie named token for authenticated sessions. The source sets no explicit cookie expiry, so browser session handling applies; restoring a browser session may preserve it. The dashboard and command centre also use spona.session in sessionStorage and localStorage to maintain and restore sign-in. Session storage normally lasts for the tab session; local storage has no automatic expiry in the reviewed implementation. Logout clears these client-side records and the current server session. Clearing browser storage alone does not establish that every server session has been revoked. ## 3. Accept, refuse or withdraw Use Reject optional to keep optional services off, Accept all to enable only the configured and disclosed categories, or Manage choices to choose individual categories. Unconfigured categories are disabled; no advance permission is recorded for them. Close or Escape dismisses the settings panel without saving. Cookie settings remains available below the footer and in the legal centre. You can change or withdraw permission there at any time; refusal does not block navigation, calculators or contact features. Changes apply to open tabs on this same origin through browser storage events. This choice does not cover another device, browser, subdomain or ERP application, marketing email, AI training or contractual acceptance. ## 4. Your controls You can clear cookies and site storage in your browser settings and sign out of the ERP. Clearing authentication data may require you to sign in again; clearing preferences resets the saved layout. On a shared device, sign out when finished. Privacy requests about server-side records should be sent to connect@spona.io or to your organisation for its ERP records; browser deletion does not delete those records. ## 5. Google Analytics 4 — planned live integration Spona has selected Google Analytics 4 for website measurement. It remains disconnected until the live measurement ID is configured. The implementation uses basic consent gating: no Google tag is loaded and no analytics requests or denied-consent pings are sent by this integration before analytics permission. Once enabled and accepted, GA4 measures page views and usage, using browser/device information and cookie identifiers; Google receives network information such as IP addresses in the request. Our explicit page-view events use an allowlisted page route and exclude query strings, form fields and referrer values. Google advertising signals and advertising consent are disabled. Production Enhanced Measurement settings must be reviewed before activation. This is website measurement, not access to ERP records. ## 6. Analytics cookies and withdrawal When analytics is connected and accepted, the integration configures first-party _ga and _ga_ cookies on the current hostname and root path, with a 180-day lifetime and rolling updates disabled. Withdrawal sets Google’s measurement-disable flag, stops our page-view listener, removes the tag and accessible _ga cookies, clears its local command queue and reloads the page to unload already executed Google code. Requests already sent cannot be recalled and withdrawing consent does not automatically erase data already received by Google. Contact connect@spona.io for a separate data-rights request. We cannot delete cookies belonging to unrelated sites or applications. # Financing disclosures ## 1. Roles and scope Top Digital d.o.o., MBS 081170998, OIB 72317551155, VAT ID HR72317551155, Vladimira Nazora 23, 49210 Zabok, Croatia, administers the financing service on the Spona platform. The financier and all contracting parties are identified in the documents for the individual transaction. The administrator is not automatically the financier or the party assuming payment risk. Spona’s ERP provider is Top Digital Agency Limited, Ireland, company number 642562, VAT ID IE3613706OH. Financing is optional; you may use the free ERP without it. No banking licence, regulatory exemption or approval of a transaction is asserted by this page. ## 2. Two financing directions As a supplier, you may request earlier payment on an eligible unpaid amount; the agreed fee is deducted and your client pays the original financed amount on the agreed date to the party named in the payment instructions. As a client, you may request more time to pay; your supplier receives the financed amount and you pay that amount plus the agreed fee on the agreed later date. These are separate alternatives. A company’s role depends on the transaction. A counterparty invitation is an invitation to review information, not approval or an obligation to accept financing. ## 3. Requests and eligibility Businesses worldwide may submit financing requests. Each request is assessed individually, including the country, parties, transaction and applicable requirements. Submission does not guarantee availability, an offer or approval. A request may start from a completed, client-confirmed Work stage, an eligible accepted purchase order, an eligible unpaid sales invoice or the direct questionnaire. Internal projects cannot be financed. Provide accurate business and transaction information, the requested documents and relevant identity or business-verification information. Do not submit fictitious, disputed, previously assigned or encumbered amounts, conceal restrictions on transfer, duplicate a financing request for the same exposure or manipulate amounts and dates. Inform Spona promptly of disputes, payments or changes. Supporting records, confirmations and an invitation do not guarantee eligibility. Spona or the identified financier may decline or request further information. ## 4. Fees and payment dates The website illustrates a single one-time transaction fee of 2.95% for 30 days, 6.38% for 60 days and 9.99% for 90 days, calculated on the financed amount. For EUR 10,000 these examples are EUR 295, EUR 638 and EUR 999. The calculator is not a binding offer. The agreement confirms the actual amount, fee, applicable tax treatment, due dates and any consequences of late payment before you accept. There is no separate additional platform administration fee under this offer. Changes to published pricing do not change a signed transaction. Payment timing follows the agreement and completion of its conditions; no same-day or one-business-day payout is promised by the website. ## 5. Review, signing and payment After submission, Spona reviews the request and may ask for additional information or documents. If an offer is made, review its conditions and the parties involved. Complete required verification and signing by all required parties before payment is arranged. Follow requests, responses, documents and status in the financing workspace. A signed status is separate from payment: Spona records when funds have actually been sent. The agreement determines the recipient and payment direction. Where a receivable is assigned, the applicable agreement and notice identify the new recipient of payment; follow verified payment instructions and report any conflicting request. ## 6. Non-payment and disputes Financing does not insure payment or remove all commercial risk. The transaction agreement determines liability if the original debtor does not pay, including whether payment may be demanded from the supplier, relevant deadlines, permitted charges and remedies. Review those provisions before signing. Notify Spona and the named financing counterparty promptly of a dispute or a payment received contrary to assignment instructions. Where the agreement requires onward transfer, follow its stated deadline. ERP confirmation does not waive rights that cannot lawfully be waived. General website copy neither replaces nor changes an existing agreement. ## 7. Documents, privacy and access restrictions Only provide information relevant to the request and ensure you have authority to share it. Relevant data may be disclosed to the identified financier and authorised providers for verification, review and fulfilment of the transaction, under their disclosed roles and privacy notices. It does not give them access to your entire ERP workspace. Marketing choices remain separate. Access may be suspended for suspected fraud, disputed transactions, missing verification or breach, with notice of the grounds within three business days unless prohibited by law. General privacy rights and the applicable DPA remain unaffected. # Providers, retention & requests ## 1. Hosting and service providers Hosting provider: Hetzner. Hosting location: Nuremberg, Germany. Purpose: operating the Spona website and platform infrastructure, including storage and processing needed to deliver the service. Information about Hetzner and its data-processing agreement: https://docs.hetzner.com/general/company-and-policy/data-protection-at-hetzner/. Other services, including separate email delivery, external file storage, backups and optional AI, require service-specific provider and location disclosures before use. Contact connect@spona.io for the register applicable to your service. A provider’s own certification does not certify the Spona application. ## 2. Retention and deletion Retention depends on the record and purpose. Accounts are retained for service administration and closure; enquiry and support records for response, resolution and related claims; business and financing records for the agreement, instructions and applicable statutory obligations. Legal holds apply only to the necessary scope. Presence buckets and page-view records use a 90-day pruning window triggered by application activity; this is not a universal retention period for other records or backups. Website consent preferences last up to 180 days. For account export, closure, deletion or the applicable retention criteria, contact connect@spona.io. Customer-controlled personal data is returned or deleted according to the DPA, subject to lawful retention. Recovery copies must not reintroduce deleted records into normal processing. ## 3. Make a request Email connect@spona.io with the subject “Privacy request”, “Data export” or “Account closure”. Include the relevant company, service and a concise description; do not send passwords, full identity documents or unrelated employee records. We may need proportionate identity and authority checks. An individual’s GDPR request and a company’s complete ERP export are different requests and may have different scopes. For records controlled by your employer or another customer, contact that organisation; the platform supports its response. ## 4. Google Analytics — not activated Planned provider: Google Analytics 4. Purpose: consented website measurement. Status: not connected; no measurement ID supplied. Before activation, confirm the Google contracting entity, accepted data-processing terms, relevant processing countries and international-transfer safeguards, account data-sharing settings and event-data retention. The local 180-day consent/cookie setting is not the GA server-side retention period. Google information: https://policies.google.com/technologies/partner-sites and https://privacy.google.com/businesses/processorterms/. This entry discloses the selected service without claiming its contract or transfer arrangements have already been approved. # Analytics, AI & data use ## 1. Intended scope and activation Spona intends to develop product analytics, anonymised benchmarks, AI training and evaluation, marketing and financing-partner collaboration. These are distinct purposes, not an unlimited data licence. This notice defines conditions for future activation; it does not state that all these uses currently operate. Each programme needs an identified controller, data categories, legal basis, recipients, duration and safeguards before it starts. The customer may authorise use of content it owns but cannot consent on behalf of employees, contacts or other individuals without lawful authority. ## 2. Product analytics and research Use the minimum events and attributes needed to understand feature adoption, reliability and user experience. Where legitimate interests are proposed, document the specific benefit, necessity, less intrusive alternatives, reasonable expectations and balancing of individual rights; provide the applicable objection route. Obtain prior consent for non-essential browser access where required even if subsequent processing has another GDPR basis. Research is not a universal exemption. Cross-module linkage, employee-level analysis and new purposes require a fresh assessment and updated information before use. ## 3. Anonymous benchmarks and commercial datasets Spona may retain, combine, license and publish genuinely anonymous statistics for research, product development and commercial benchmarking within the Terms’ safeguards. The process must remove reasonably foreseeable identification, linkage and reconstruction risks and protect confidential business information. Approve dataset provenance, permissions, cohort thresholds, outlier treatment and release tests before distribution; do not invent a numeric threshold as a guarantee of anonymity. Retest when datasets are combined or external information changes. Raw customer records and pseudonymous identifiers are not anonymous commercial outputs. ## 4. AI training and evaluation programmes AI inference, model evaluation and model training must be distinguished. For a separately approved training programme, a signed schedule must identify the model and provider, training purpose, data scope and sources, intellectual-property permission, lawful basis, retention, recipients, transfers, opt-out or withdrawal process where applicable and how rights can be honoured in datasets and models. Use genuinely anonymous or synthetic inputs where feasible. Do not include payroll, identity documents, special-category records or confidential customer content by default. Consent, where relied on, must be specific and freely given, with no loss of core ERP access for refusal. A legitimate-interest route requires a documented case-specific assessment; these terms do not predetermine the outcome. No training permission is activated by a general terms checkbox. ## 5. Marketing and financing collaboration Service messages needed to operate an account are separate from promotional messages. Marketing programmes must identify channels and recipients and comply with applicable electronic-marketing rules, including consent where required and a simple, free unsubscribe. Do not enrich marketing audiences with customer-controlled employee, salary or client records under the ERP processing licence. Financing disclosures must be limited to relevant application and transaction data and the disclosed recipient’s purpose; a partner’s independent marketing requires its own lawful arrangement. Consent choices must be granular and recorded by purpose and version, and changes must reach downstream recipients where required.