Compliance

What standards we meet, what we're working on, what we don't claim

Spun is built with privacy and security by design. We use encryption in transit, controlled access, audit logging, configurable data retention, and customer-controlled AI features. We do not overclaim — every status below is current.

Status by standard

Where we stand

Every standard below is shown with current status. If a status is "In progress" or "Roadmap," ask us for the latest milestone.

SOC 2

In progress

What it is

AICPA framework covering security, availability, confidentiality, processing integrity, and privacy controls for service organizations. Type I is point-in-time; Type II is over a 6–12 month period.

Our position

SOC 2 readiness program in progress: access logging, change-management, vendor review, vulnerability scanning, incident response, employee access policy, and least-privilege controls are all in place. Type I attestation targeted for the second half of 2026; Type II to follow once we have operational history.

GDPR (EU/EEA)

In place

What it is

EU regulation governing personal data of EU/EEA residents. Spun typically acts as a data processor; the customer is the controller of their end-user data.

Our position

GDPR-aligned controls in place: lawful basis documentation, DPA available on request (with EU Standard Contractual Clauses for international transfers), published sub-processor list, data minimization defaults, retention controls, customer-controlled export and deletion, AI processing disclosure, and breach-notification procedure within the 72-hour requirement.

ISO/IEC 27001

Roadmap

What it is

International standard for information security management systems (ISMS). Widely recognized for enterprise / international procurement.

Our position

On the roadmap after SOC 2 Type II. Many of the underlying controls overlap with our SOC 2 readiness work, so the incremental effort is significant but not green-field.

EU AI Act

In progress

What it is

EU regulation in force since 1 August 2024, with most rules applying from 2 August 2026. Risk-tiered obligations: prohibited / high-risk / limited-risk / minimal-risk AI systems.

Our position

Spun's AI features (compose, summarize, transcribe, translate, smart replies, classification) are limited-risk by default — used for general business communication, not high-stakes decisions about people. We provide AI-usage disclosure, customer toggles per feature, audit logging (optional), human-approval modes, no training on customer data, vendor disclosure, and PII redaction before AI processing. If you are using Spun in a use case that becomes high-risk under the Act (hiring decisions, credit, health, education, legal advice, biometric ID), contact us.

Israeli Privacy Protection Law (Amendment 13)

In progress

What it is

Israel's privacy law modernized in 2024 (effective August 2025), bringing it closer to GDPR-style obligations.

Our position

Spun's GDPR-aligned controls cover most of the core obligations under the updated Israeli law. Database registration: Spun stores customer contact data only to provide the SaaS workspace to each customer — we do not sell, broker, transfer, or independently use customer contact lists. Contact data remains logically separated by organization (RLS-enforced). Spun is not a public body. Under Amendment 13, registration mainly applies to public-body databases and data-broker/direct-mailing databases exceeding 10,000 records; our processor-only model does not trigger registration at launch. We will reassess if Spun offers large-scale direct-mailing/broadcast services, combines contact lists across customers, or transfers contact data beyond listed sub-processors. Hebrew-language privacy materials and DPO designation (if required at scale) are in progress.

Data retention

Retention limits per plan

Older messages automatically prune at the plan limit. You can tighten retention further per-chat in Safety & Privacy → Message Storage Limit, or wipe everything on demand.

PlanMessage historyMedia storage
Free Trial7-day trial30 days5 GB
Basic90 days10 GB
Pro1 year75 GB
PowerUnlimited500 GB

On account deletion, all personal data is removed or anonymized within 30 days, except where retention is required by law (financial records, fraud prevention).

Where your data lives

Regional hosting

All application servers and the database live in a single EU data center. The marketing site and media files are served globally from Cloudflare's edge network for low latency everywhere.

🇩🇪

Hetzner Nuremberg

EU (Germany) — application servers + PostgreSQL

Available

The single data tier. All application servers, database, and Redis run here. AES-256 encrypted disks.

🌐

Cloudflare Pages

Global edge — marketing site & static assets

Available

spun.com and 20+ regional domains served from Cloudflare's global edge network. Visitors get the nearest PoP automatically.

Cloudflare R2

Global — images, video, file attachments

Available

All media (images, video, audio, documents) stored in R2 with AES-256 at rest. Access gated by per-org, per-object signed URLs.

🇮🇱

Israel region

Israel

Roadmap

Under evaluation for Israeli market expansion. Currently Israeli customers are served from Hetzner Nuremberg (EU).

🇮🇳

India region

India

Roadmap

Under evaluation for Indian-language voice features and data residency.

Where we sell, and why

International launch roadmap

We launch in markets where WhatsApp is core business infrastructure first, and expand to higher-compliance enterprise markets as our certification matures.

  1. 1

    Israel & Latin America (current)

    Israel (Hebrew + English UI, GDPR-aligned). Mexico, Colombia, Argentina, Chile, Peru, UAE — WhatsApp is universal business infrastructure, sales cycles are short. SOC 2 readiness sufficient.

  2. 2

    US SMBs (current, expanding)

    Home services, real estate, e-commerce support, travel, education, wellness. SOC 2 Type I and a complete DPA package make Spun viable for most US SMB and mid-market buyers.

  3. 3

    EU & UK enterprise (after SOC 2 Type I)

    Enter once SOC 2 Type I is signed and ISO 27001 work is underway. Requires polished DPA + SCCs, EU hosting confirmation, and full deletion/export tooling — all of which are in place but benefit from third-party attestation before larger enterprise sales.

Documents available

Request from [email protected]

Data Processing Agreement (DPA)

GDPR-aligned, includes EU Standard Contractual Clauses for international transfers.

Sub-processor notification list

Get email updates when we add or change a sub-processor.

Security overview

Architecture, encryption, access control, vulnerability management.

AI data processing policy

Which AI vendors, what data they see, no-training commitment.

Incident response policy

Detection, containment, customer notification timelines.

Acceptable Use Policy

What is permitted on Spun and the basis for enforcement.

Have a security questionnaire?

We respond to standard security questionnaires (SIG, CAIQ, custom enterprise) within 5 business days. Email [email protected] with your timeline.