Privacy Policy
This English version is a convenience translation. The German version is the legally binding text, and in the event of any discrepancy or doubt in interpretation, the German version prevails.
1. Controller
The controller responsible for the processing of personal data on this website is:
Sprad Software GmbH
Kaiserstraße 16 / 7–9
1070 Vienna, Austria
E-mail: mail[@]@sprad.io
Company register number: FN 558095d
We are not legally required to appoint a data protection officer and have not appointed one. For all data protection matters, you can reach us at the email address above.
2. Scope
This privacy policy applies to our website and the features offered on it. The Sprad application itself, which our customers use under a contractual relationship, is governed by separate data protection arrangements and is not covered by this policy.
3. General Information
Protecting your personal data is of particular importance to us. We process your data exclusively on the basis of the applicable legal provisions, in particular the General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG) and the Austrian Telecommunications Act 2021 (TKG 2021). This privacy policy informs you about the most important aspects of data processing on our website.
We only process personal data where a legal basis exists and limit processing to what is necessary.
4. Hosting and Server Log Files
Our website is hosted by Webflow, Inc., San Francisco, USA. Delivery takes place via a Cloudflare content delivery network with edge locations inside the EU.Each time our website is accessed, the following data is processed in server log files for technical reasons:
- IP address of the accessing device
- date and time of access
- page or file requested
- volume of data transferred and status code
- referrer URL
- browser type, browser version and operating system
This data is necessary for the operation, security and stability of the website. It is not merged with other data sources.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and uninterrupted operation of the website)
Storage period: HTTP request logs are disabled in our Cloudflare configuration. Data is processed there only transiently for delivery and attack prevention and is not stored persistently. No fixed period is published for the server-side log files held by our hosting provider Webflow. This data is retained only for as long as necessary for the technical operation and security of the website and is deleted afterward.
Processors: Data processing agreements are in place with Webflow and Cloudflare. Both providers are certified under the EU-US Data Privacy Framework. In addition, we have concluded the EU Standard Contractual Clauses under Art. 46(2)(c) GDPR so that transfers remain safeguarded even if the adequacy decision ceases to apply.
5. Cookie Consent Tool
We use the consent management service provided by Usercentrics GmbH, Munich, Germany, to obtain, manage and document consent.
When you visit our website, you are shown cookie categories that you can accept or reject individually. Rejecting is just as easy as accepting. Non-essential cookies and scripts are only loaded after you have given consent.
Usercentrics processes your consent decision, an anonymous identifier, the time of consent, device and browser information, and your truncated IP address.
Legal basis:
- Art. 6(1)(c) GDPR together with Art. 7(1) GDPR (obligation to demonstrate consent)
- Art. 6(1)(f) GDPR (legitimate interest in compliant consent management)
Storage period: consent records are stored for the duration of the demonstration obligation, generally three years.
6. Cookies and Similar Technologies
Our website uses cookies and comparable technologies to ensure basic functionality and, subject to your consent, to enable marketing and analytics features.
Access to your terminal equipment is governed by section 165(3) TKG 2021. Cookies that are strictly necessary to provide a service you have expressly requested may be set without consent. For all other cookies, we obtain your consent in advance.
You can find an up-to-date overview of all cookies used, their purposes and their lifetimes in the Usercentrics consent banner.
Legal basis:
- strictly necessary cookies: section 165(3) TKG 2021 (exemption from the consent requirement) together with Art. 6(1)(f) GDPR
- all other cookies: section 165(3) TKG 2021 together with Art. 6(1)(a) GDPR (consent)
Withdrawal: at any time via the Usercentrics consent banner, without affecting the lawfulness of processing carried out up to that point.
7. Data Security and Encryption
Our website uses TLS encryption (indicated by "https" in the address bar) to protect the transmission of your data. We also apply technical and organizational measures to protect your data against loss, manipulation, and unauthorized access, and we keep these measures aligned with the current state of the art.
8. Contacting Us
If you contact us via a form or by email, we process the data you provide in order to handle your inquiry.
Data processed: name, email address, company, message content, and any other information you provide voluntarily.
Legal basis:
- Art. 6(1)(b) GDPR (contract or pre-contractual measures)
- Art. 6(1)(f) GDPR (legitimate interest in communication where there is no contractual context)
Storage period: deletion once your inquiry has been completed, unless statutory retention obligations or pending claims prevent this. Providing your data is voluntary. Without the necessary details, however, we cannot process your inquiry.
9. Demo Appointment Booking via Cal.com
You can book an appointment for a product demo directly on our website. Bookings are handled via Cal.com, Inc., USA. The data involved is processed on servers in the USA.
Data processed: name, email address, the appointment slot and time zone selected, company, company size, product interest, and any optional details entered in a message field. Technically, your IP address and the time of booking are also processed.
Purposes: arranging, holding and following up on the appointment, and preparing a possible contractual relationship.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures)
Recipients: Cal.com, Inc. as processor. A data processing agreement under Art. 28 GDPR is in place with Cal.com. Appointment data is also processed in our internal customer management systems.
Third-country transfer: As processing takes place in the USA, we base the transfer on the EU Standard Contractual Clauses under Art. 46(2)(c) GDPR. Further information on transfers to the USA can be found in section 19.
Security: Cal.com is certified to ISO 27001 and SOC 2 Type II and has the application tested for vulnerabilities by an external party every year.
Contacts: Cal.com has appointed a data protection officer (legal@cal.com) and a representative in the European Economic Area under Art. 27 GDPR (legal+eu@cal.com). You can therefore also exercise your data subject rights directly with Cal.com.
Storage period: booking data is deleted once the appointment has been completed and no business relationship is being pursued, at the latest after 24 months. Statutory retention obligations remain unaffected.
10. Email Communication and Business Outreach
When communicating by email, we process name, email address, company affiliation, position, and message content.
We use the service Smartlead, with servers located in Ireland (EU), to send emails. Links in our emails may be routed through our own service t.sprad.io. This allows us to see whether and which links were clicked so that we can improve our communication.
Legal basis:
- Art. 6(1)(b) GDPR (contract or pre-contractual measures)
- Art. 6(1)(f) GDPR (legitimate interest in communication and in evaluating delivery)
- Art. 6(1)(a) GDPR (consent) where the message constitutes electronic direct marketing within the meaning of section 174 TKG 2021
Storage period: in accordance with statutory retention obligations, otherwise until the purpose of processing no longer applies.
11. Newsletter
You can subscribe to our newsletter on our website. We require your email address for this. Registration uses a double opt-in procedure: after signing up, you receive a confirmation email, and we only add you to the recipient list once you have confirmed.
Data processed: email address, optionally name and company, the time of registration and confirmation, and the IP address used (to demonstrate consent). We analyze whether our newsletters are opened and which links are clicked so that we can improve content and send times. Link tracking takes place via t.sprad.io. This analysis is covered by the consent you give when subscribing.
Legal basis: Art. 6(1)(a) GDPR (consent) together with section 174 TKG 2021
Storage period: until withdrawal. We retain consent records for three years after unsubscription in order to meet our obligation to demonstrate consent.
Withdrawal: at any time via the unsubscribe link in every newsletter email or by emailing mail[@]sprad.io.
12. AI Chat Assistant "Atlas"
On our product pages, you can interact with our AI-based chat assistant "Atlas", which answers questions about the Sprad product. This is an AI assistant, not a human contact person. This is indicated permanently and visibly within the chat window. Responses from an AI can be inaccurate, so please verify important information.
Data processed
- chat messages (your inputs and the assistant's responses)
- a functional first-party cookie spb_visitor_id (storage period 6 months) storing a random identifier (UUID) to recognize your session without establishing any link to your IP address
- technical session data: product page visited, language, timestamp, referrer and, where applicable, UTM parameters
- your email address, provided you supply it voluntarily to receive a written response or a summary ("recap") by email
- your IP address is processed only transiently for abuse prevention and rate limiting and is not stored
Email response and follow-up: If you request a response by email, we first obtain your explicit consent via a separate checkbox. Without this consent, no email address is processed, and no email is sent. On the basis of this consent, we send you the requested response and, where applicable, a single follow-up email (approximately 5 days later) with further information. Links contained in these emails are routed through our own service t.sprad.io to measure usage (for example, clicks). You can withdraw your consent at any time with effect for the future, either via the unsubscribe link in every email or by emailing mail[@]sprad.io.
Enrichment of business email addresses (optional): If you provide a business email address, it may be matched against a business contact database via the service Apollo.io (ZenLeads Inc., Covina, California, USA). This allows us to supplement your address with business information such as company, company size, or professional role and to better classify your request. Private email addresses are excluded from this matching.
During this matching, Apollo processes your data not only on our behalf but also for its own purposes as an independent controller. Your data may be added to Apollo's contact database and made available to other Apollo customers. We have no influence over this processing by Apollo and cannot guarantee deletion for this part. You can find information about it in Apollo's privacy policy. Objections and deletion requests can be addressed directly to privacy@apollo.io.
You may object to the matching at any time by informing us, in which case it will not take place.
Purposes: Responding to your product inquiry, follow-up by email where requested, sending further information, abuse and overload prevention, and internal analysis for product improvement.
Legal bases:
- Art. 6(1)(b) GDPR: pre-contractual measures (responding to product inquiries)
- Art. 6(1)(a) GDPR: consent for the email response and promotional follow-up emails, together with section 174 TKG 2021
- Art. 6(1)(f) GDPR: legitimate interest (product communication, abuse prevention and product improvement, and classifying business inquiries by matching business contact data)
Recipients and processors
- Supabase (Frankfurt, EU): database and backend
- Anthropic PBC (USA): "Claude" AI language model, transfer based on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR)
- Cloudflare (EU edge): technical delivery and email link tracking (t.sprad.io)
- Smartlead (Ireland, EU): email delivery
- Apollo.io, ZenLeads Inc. (USA, optional): matching of business email addresses, partly as processor and partly as an independent controller, transfer based on the EU Standard Contractual Clauses
Storage period
- chat sessions without an email address: deletion after 6 months at the latest
- chat sessions with an email address: deletion after 12 months at the latest
This applies unless statutory retention obligations exist or a continuing legitimate interest (for example an ongoing business relationship) applies.
Appointment booking via the chat: If the chat assistant offers you a demo appointment, the booking is handled via Cal.com. You can find the data processed and the applicable legal basis in section 9.
Automated decisions: The chat assistant does not make automated decisions with legal effect for you.
Withdrawal, objection and deletion: You may object to the processing at any time, withdraw any consent given with effect for the future, and request deletion of your data. To do so, contact us by email at mail[@]sprad.io.
13. YouTube
We embed YouTube videos in enhanced privacy mode via youtube-nocookie.com. The provider is Google Ireland Limited, Dublin, Ireland.
Data is only transmitted to YouTube and Google once you actively play a video, in particular your IP address, device and browser information, and details of the video played. If you are logged into Google at the same time, Google may associate this usage with your account. Data may be transferred to the USA.
Legal basis: Art. 6(1)(a) GDPR (consent) together with section 165(3) TKG 2021
Third country transfer: Google LLC is certified under the EU-US Data Privacy Framework. The EU Standard Contractual Clauses apply in addition.
Withdrawal: at any time via the Usercentrics consent banner.
14. Google Analytics 4
We use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Dublin, Ireland.
The data processed includes page views, interactions on the website, time on page, device and browser data, approximate location information based on the truncated IP address, and a pseudonymous user identifier. The IP address is truncated before analysis and is not stored.
Legal basis: Art. 6(1)(a) GDPR (consent) together with section 165(3) TKG 2021
Storage period: the retention period is set to 14 months for both event data and user data. For user data, this period is reset with each new activity. It therefore runs from your last interaction with our website, which means the actual storage period can be longer if you visit repeatedly. Aggregated report data is not affected by this.
Third-country transfer: data may be transferred to Google LLC in the USA. Google LLC is certified under the EU-US Data Privacy Framework, and the EU Standard Contractual Clauses apply in addition.
Withdrawal: at any time via the Usercentrics consent banner.
15. Google Ads and Remarketing
We use Google Ads including conversion tracking and remarketing to measure the effectiveness of our campaigns and to display relevant advertising. The provider is Google Ireland Limited, Dublin, Ireland.
Data processed: cookie identifiers, usage behavior on our website, device and browser information, conversion events.
Legal basis: Art. 6(1)(a) GDPR (consent) together with section 165(3) TKG 2021
Third country transfer: as described in section 14.
Withdrawal: via the Usercentrics consent banner and via the Google ad settings at https://adssettings.google.com/
16. Meta Pixel
We use the Meta Pixel to measure the effectiveness of advertising campaigns and to display relevant ads. The provider is Meta Platforms Ireland Limited, Dublin, Ireland.
Data processed: actions on our website, cookie identifiers, device and browser information, and your Meta identifier if you are logged into Facebook or Instagram.
Joint controllership: we and Meta are joint controllers within the meaning of Art. 26 GDPR for the collection and transmission of data to Meta, on the basis of the controller addendum provided by Meta. Meta is solely responsible for any further processing of the data. You can exercise your rights against us as well as against Meta.
Legal basis: Art. 6(1)(a) GDPR (consent) together with section 165(3) TKG 2021
Third country transfer: data may be transferred to Meta Platforms, Inc. in the USA. Meta is certified under the EU-US Data Privacy Framework, and the EU Standard Contractual Clauses apply in addition.
Withdrawal: via the Usercentrics consent banner or via your Meta ad preferences.
17. LinkedIn Ads
We use the LinkedIn Insight Tag for conversion measurement and retargeting. The provider is LinkedIn Ireland Unlimited Company, Dublin, Ireland.Data processed: page views, cookie identifiers, device and browser information, and aggregated demographic details from your LinkedIn profile.
Legal basis: Art. 6(1)(a) GDPR (consent) together with section 165(3) TKG 2021
Third country transfer: data may be transferred to LinkedIn Corporation in the USA. Microsoft and LinkedIn are certified under the EU-US Data Privacy Framework, and the EU Standard Contractual Clauses apply in addition.
Withdrawal: via the Usercentrics consent banner or at https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out
18. Microsoft Advertising (Bing Ads)
We use Microsoft Advertising conversion tracking to analyze website usage and the effectiveness of advertisements. The provider is Microsoft Ireland Operations Limited, Dublin, Ireland.
Data processed: cookie identifiers, page views, conversion events, device and browser information.
Legal basis: Art. 6(1)(a) GDPR (consent) together with section 165(3) TKG 2021
Third country transfer: data may be transferred to Microsoft Corporation in the USA. Microsoft is certified under the EU-US Data Privacy Framework, and the EU Standard Contractual Clauses apply in addition.
Withdrawal: via the Usercentrics consent banner or at https://account.microsoft.com/privacy/ad-settings/signedout
119. Transfers to Third Countries
Some of the services we use are based in the USA. Where personal data is transferred to the
USA, we rely on the following safeguards:
- the European Commission's adequacy decision on the EU-US Data Privacy Framework under Art. 45 GDPR, where the provider concerned is certified, and
- in addition, the European Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR, combined with an assessment of transfer risks.
The validity of the adequacy decision is the subject of ongoing proceedings before the Court of Justice of the European Union. Because we have also concluded the Standard Contractual Clauses, transfers remain safeguarded even if the decision is annulled.Despite these safeguards, transfers to the USA carry a residual risk that US authorities may access data without a remedy being available that fully matches the European level of protection.
20. Overview of Recipients
Agreements under Art. 28 GDPR are in place with all processors. Where a provider acts as an independent controller for its own purposes, this is noted in the table.
21. Storage Periods at a Glance
Beyond this, we only store data for as long as statutory retention obligations exist or the data is required to assert or defend legal claims.
22. Automated Decision-Making
We do not carry out automated decision-making, including profiling, that produces legal effects concerning you within the meaning of Art. 22 GDPR.
23. Obligation to Provide Data
Providing your data is generally voluntary and is neither required by law nor by contract. Without the relevant details, however, we cannot provide certain services, such as answering a contact inquiry or sending the newsletter.
24. Your Rights
You have the following rights in relation to us:
- right of access (Art. 15 GDPR)
- right to rectification (Art. 16 GDPR)
- right to erasure (Art. 17 GDPR)
- right to restriction of processing (Art. 18 GDPR)
- right to data portability (Art. 20 GDPR)
- right to object to processing based on legitimate interests (Art. 21 GDPR)
- right to withdraw consent at any time (Art. 7(3) GDPR), without affecting the lawfulness of processing carried out up to that point
Specific notice of your right to object to direct marketing: you may object at any time to theprocessing of your data for direct marketing purposes, without having to give reasons. Following such an objection, we will no longer process your data for advertising purposes. Please send your request to mail[@]sprad.io. We will respond within the statutory time limits, generally within one month.
Right to lodge a complaint: If you believe that the processing of your data infringes data protection law, you can lodge a complaint with the supervisory authority:
Austrian Data Protection Authority (Datenschutzbehörde) Barichgasse 40-42, 1030 Vienna
Phone: +43 1 52 152-0 Email: dsb@dsb.gv.at Web: https://www.dsb.gv.at
25. Changes to This Privacy Policy
We update this privacy policy when our website, our services, or the legal requirements change. The version published on this page applies. The date given above shows the current status.
This English version is a convenience translation. The German version is the legally binding text, and in the event of any discrepancy or doubt in interpretation, the German version prevails.