Privacy Policy
How Spire Innovations, Inc. collects, uses, discloses, and processes your personal data when you use the OpenKnowra platform, including your rights in relation to it.
Spire Innovations, Inc., a Delaware corporation with registered office at 1013 Centre Road, Suite 4038, Wilmington, DE 19805, United States, and principal place of business at 33 Wood Avenue South, Suite 600, Iselin, NJ 08830, United States ("Spire," "we," "our," or "us"), is an enterprise AI company operating the OpenKnowra platform, including our website at www.spire.ai, our APIs, AI Agents, Digital Workers, AI Agentic Applications, Assemblies, Outcomes, and related services (collectively, the "Services").
This Privacy Policy explains how we collect, use, disclose, and process your personal data when you use our Services and other places where Spire acts as a data controller, for example when you visit our website, sign up for an account, attend our events, or interact with our marketing materials.
This Privacy Policy does not apply where Spire acts as a data processor and processes personal data on behalf of an enterprise customer using our commercial Services, for example where your employer has provisioned an OpenKnowra account for you, or where another organization uses our Services to process information about you. In those cases, the enterprise customer is the data controller, and you should review that organization's privacy policy and contact them directly to exercise your rights. Our processing in such cases is governed by our Data Processing Addendum ("DPA") and the underlying agreement with that customer.
This Privacy Policy describes your privacy rights. More information about your rights and how to exercise them is set out in Section 4 ("Rights and Choices") and Section 11 ("Regional Supplemental Disclosures").
1Personal Data We Collect
In this Privacy Policy: "Agent" or "AI Agent" means an AI-powered software process within the Services that operates autonomously or semi-autonomously to plan, decide, and execute one or more steps in pursuit of an objective specified by a user. "Digital Worker" means a configurable, persistent software instantiation of one or more Agents and supporting tools, designed to perform a defined business role or function (such as a Workforce Planner, Recruiter, Customer Success Manager, Brand Manager, or Process Analyst) over time within scopes a user configures. A Digital Worker is software, not a natural person, and is not an employee or worker of Spire or any user. "Agentic Action" means any action taken by an Agent or Digital Worker on a user's behalf. "Workforce Individual" means any natural person whose personal data is processed by a Digital Worker, Agent, or other component of the Services in connection with employment, hiring, contracting, evaluation, performance management, or similar activity. We collect the following categories of personal data.
1.1Personal data you provide to us directly
- Identity and Contact Data: Name, business email address, phone number, job title, employer, and country, when you sign up for an account (including the Developer free tier, Studio pay-as-you-go tier, or Enterprise tier), request a demo, register for an event, or correspond with us. We may also generate indirect identifiers (e.g., "USER12345").
- Payment Information: Where you purchase a paid plan, we (or our payment processors, such as Stripe, Inc.) collect billing information including billing address, tax identification numbers (e.g., VAT, EIN), and the last four digits of the payment card or bank account used. Full payment-card numbers are processed by our payment processors and are not stored on Spire servers.
- Inputs, Outputs, and Agent and Digital Worker Configurations: You may interact with the Services in a variety of formats, including chat, document upload, structured data import, agentic sessions, and API calls ("Inputs"). The Services and their Agents and Digital Workers generate responses, recommendations, classifications, scores, communications, transactions, and other outputs ("Outputs") and may take Agentic Actions based on your Inputs and configurations. If you include personal data or reference external content in your Inputs, we will collect and process that information, and it may be reproduced in Outputs or transmitted to systems via Agentic Actions you configure.
- Connected Account Information: When you connect an Agent or Digital Worker to a third-party system ("Connected Account") such as an HRIS, ATS, CRM, calendar, email, communications, or productivity platform, we collect the credentials (e.g., OAuth tokens, API keys, service-account identifiers) and metadata necessary to enable the Agent's or Digital Worker's authorized access. We store credentials in encrypted form and access them only as needed to execute Authorized Actions. We do not store passwords for Connected Accounts in plaintext.
- Customer Eligibility Information: When you sign up for the Services, we may verify your business activities through publicly available information (such as your company website, public filings, and trade registries) to confirm eligibility under our Terms of Service, including our Restricted Competitor policy. This processing is limited to publicly available business information and does not include sensitive personal data.
- Feedback: If you provide feedback on the Services, for example by rating an Output, submitting a bug report, or responding to a survey, and we may store your feedback together with the related conversation, prompt, session, or Agentic Action context.
- Communication Information: If you communicate with us (including through email, our help site, in-product chat, or sales enquiries), we collect your name, contact information, and the contents of the messages you send.
- Event and Marketing Information: If you register for our events, webinars, or download our content (such as whitepapers or case studies), we collect the registration details you provide and information about your engagement with our marketing communications.
1.2Personal data we receive automatically from your use of the Services
When you use the Services, we receive certain technical data automatically (collectively, "Technical Information"). This includes:
- Device and Connection Information: Device type, operating system, browser type and settings, language preference, mobile network or internet service provider, time zone, IP address (including approximate location derived from your IP address), device or advertising identifiers, and other unique online identifiers.
- Usage Information: Dates and times of access, pages visited, links clicked, features used, dashboards viewed, query frequency, session duration, and other information about how you use the Services.
- Agentic Action Logs: Records of each Agentic Action taken by Agents and Digital Workers on a user's behalf, including the planning steps, tool calls, decisions, inputs received from third-party sources, outputs produced, recipients of communications or data transmissions, and outcomes. These logs are retained for at least six (6) months and up to twelve (12) months, or longer where required by applicable law (such as the EU AI Act for high-risk AI systems). Logs are used for security investigation, regulatory compliance, audit, debugging, and explanation of decisions.
- Log and Troubleshooting Information: Log files, error reports, crash data, the time an error occurred, the feature, Agent, or Digital Worker being used, and the state of the application when the error occurred.
- Cookies and Similar Technologies: We and our service providers use cookies, scripts, pixels, and similar technologies ("Cookies") to operate the Services, recognize you, remember your preferences, market our products, and analyze use of the Services. For more details, see our Cookie Policy.
1.3Personal data we receive from third parties
- Authentication providers: If you sign in using single sign-on (SSO) or a third-party identity provider (such as Google, Microsoft, or Okta), we receive identifiers and profile information from those providers.
- Connected Accounts: When you authorize an Agent or Digital Worker to connect to a third-party system, the Agent or Digital Worker will read data (which may include personal data of third parties, such as your colleagues, candidates, customers, employees, or counterparties) from that system as required to perform the Authorized Actions you have configured.
- Customer organizations: Where Spire acts as a data processor on behalf of an enterprise customer, that customer may upload data about its employees, contractors, candidates, customers, or other natural persons into the Services.
- Trusted partners and security/fraud-prevention vendors: We may receive information to help protect our Services and prevent fraud, abuse, or other threats.
- Marketing and data partners: We may receive business contact information from marketing vendors who provide us with information about prospective enterprise customers.
1.4Sensitive personal data
Spire does not knowingly collect, and does not request, sensitive or special-category personal data such as genetic data, biometric data used to uniquely identify a person, health information, religious beliefs, sexual orientation, government identifiers, or financial-account credentials, except as may be unavoidably contained in Inputs voluntarily submitted, or in data accessed through Connected Accounts, by enterprise customers under a DPA that expressly contemplates such categories. Definitions of "sensitive personal information," "special-category personal data," and similar terms vary by jurisdiction (including under the GDPR Article 9 and the CCPA/CPRA); we comply with the applicable definition in each jurisdiction. You should not submit sensitive personal data to the Services unless permitted under a separate written agreement with us.
1.5Children
Our Services are not directed to, and we do not knowingly collect personal data from, children under the age of eighteen (18). If you become aware that a child has provided personal data to us, please email privacy@spire.ai and we will investigate and, if appropriate, delete the information.
2How We Use Personal Data
We use personal data for the following purposes, in each case in accordance with applicable law and the legal bases described in Section 10:
- To provide, maintain, and operate the Services across the four product layers (APIs, AI Agents, Digital Workers, Outcomes) and the five product categories (Customer Value Management, Enterprise Digital Twin, Brand Voice Control, Custom Context Graphs, and Work and Workforce), including configuring, executing, monitoring, and logging Agentic Actions taken by Agents and Digital Workers on a user's behalf;
- To create and administer your account and authenticate Authorized Users, Agents, and Digital Workers;
- To facilitate payments and process billing for paid Services (including the Studio pay-as-you-go tier and Enterprise tier);
- To communicate with you, including to send you technical notices, security alerts, support messages, and information about events;
- To send you marketing communications about Spire products and services, where permitted by applicable law (you may opt out at any time using the unsubscribe link in any marketing email; where applicable law requires opt-in consent, including under Canada's CASL and Australia's Spam Act, we will obtain your prior express or implied consent before sending you marketing communications);
- To verify customer eligibility, including under our Restricted Competitor policy in our Terms of Service, using publicly available business information;
- To prevent, detect, and investigate fraud, abuse, security incidents, unlawful or criminal activity, unauthorized access, anomalous Agent or Digital Worker behavior, and violations of our Terms of Service or Acceptable Use Policy;
- To investigate and resolve customer complaints and disputes;
- To investigate and resolve security issues, including monitoring our Services for intrusion, compromise, or adversarial inputs (including prompt-injection attacks);
- To debug and identify and repair errors that impair existing functionality;
- To improve the Services and conduct research, including evaluating use of features, developing new features, Agents, and Digital Workers, and improving safety and trust classifiers;
- To maintain audit trails and logs of Agentic Actions sufficient to satisfy regulatory obligations under applicable law (including the EU AI Act and the GDPR);
- To provide explanations of AI decisions where required by law (including under EU AI Act Article 86, the GDPR, and analogous laws);
- To enforce our Terms of Service and similar terms and agreements; and
- To meet legal, governmental, regulatory, tax, accounting, and institutional-policy obligations.
2.1Use of Inputs and Outputs for model training
Our approach to model training is intentionally conservative and aligned with enterprise expectations:
- Studio (paid) and Enterprise customers: We do not use Inputs, Outputs, or other Customer Data of Studio or Enterprise customers to train, fine-tune, or evaluate general-purpose AI models, Agents, or Digital Workers for use outside that customer's tenant, except (a) with that customer's prior written opt-in consent, or (b) in fully de-identified, aggregated form that cannot reasonably be associated with any individual or customer.
- Developer (free) tier and evaluation users: We may use Inputs, Outputs, and Feedback to improve the Services and to train, fine-tune, and evaluate our AI models, Agents, and Digital Workers, subject to the disclosures presented at sign-up and the opt-out controls available in your account settings.
- Safety and trust review: Where Inputs, Outputs, or Agentic Actions are flagged by our automated systems or reported through our Feedback mechanisms as potentially violating the Acceptable Use Policy or applicable law, we may use that material to investigate, enforce our policies, and improve our trust and safety classifiers, regardless of plan type.
2.2Aggregated and de-identified information
We may process personal data in aggregated or de-identified form to analyze and improve the Services, study usage patterns, conduct research, publish industry benchmarks, and train internal classifiers, in each case as permitted under applicable laws. We will maintain de-identified information in its de-identified form and will not attempt to re-identify it, except as may be required by law or to enforce the Acceptable Use Policy with the responsible user.
2.3Automated decision-making and agentic operation
The Services include AI Agents and Digital Workers that operate autonomously or semi-autonomously within the scopes a user configures. While Agents and Digital Workers may make routine operational decisions (such as which records to read, what content to generate, or how to sequence steps), Spire does not engage in solely-automated decision-making producing legal or similarly significant effects on individuals (within the meaning of GDPR Article 22 or analogous laws) on behalf of users without express configuration. Where you (or an enterprise customer) configure Agents or Digital Workers to make or execute employment, hiring, promotion, performance-evaluation, compensation, customer-eligibility, credit, or similar decisions, you are responsible for ensuring qualified human review and approval, lawful basis under applicable data-protection law, compliance with high-risk AI laws (including the EU AI Act), and required disclosures and rights to affected individuals.
2.4Agentic processing and onward transmissions
When you use our agentic Services, an Agent or Digital Worker processes personal data in the course of executing Agentic Actions on your behalf, including reading from third-party systems you have connected, transmitting data to recipients you have specified, and creating or modifying records. Such processing is performed at your instruction and within the scope you have configured. Where Spire acts as a data processor for an enterprise customer, agentic processing is governed by the DPA between Spire and that customer. The customer (as data controller) is responsible for ensuring it has lawful basis, consents, and appropriate safeguards for any onward transmission to third-party recipients made through agentic processing.
2.5Personal data of Workforce Individuals and other end-users
Where Digital Workers and Agents process personal data about identifiable Workforce Individuals (employees, contractors, candidates, applicants, and former workforce members) or other end-users (such as customers, prospects, or partners of an enterprise customer) on behalf of an enterprise customer, that enterprise customer is the data controller. Such individuals have the privacy rights described in Section 4 directly against that controller, not against Spire.
Where applicable law (including the EU AI Act Article 86, the GDPR Article 22, NYC Local Law 144, the Colorado AI Act, the Illinois AI Video Interview Act, and analogous laws) provides such individuals with rights to (i) be informed that an AI system is being used in connection with decisions about them, (ii) obtain a meaningful explanation of decisions taken or significantly informed by AI, (iii) object to processing, or (iv) request human review of automated decisions, Spire will assist enterprise customers in providing such disclosures, explanations, and human-review pathways to the extent feasible and consistent with the protection of trade secrets and intellectual property.
Such individuals seeking to exercise rights should in the first instance contact the enterprise customer that is using the Services in connection with them. Where Spire is the controller, individuals may contact privacy@spire.ai.
Customers who use the Services in employment, hiring, customer-decisioning, or similar contexts are reminded that processing in those contexts may be subject to additional consultation, notice, or co-determination requirements under local law (including the German Federal Data Protection Act §26, the French Code du Travail, and the EU Platform Work Directive 2024/2831), and that compliance with those requirements is the customer's responsibility.
3How We Disclose Personal Data
We disclose personal data to the following categories of third parties for the purposes explained in this Policy:
- Service providers and business partners: We disclose personal data to vendors that support our business operations and help us deliver and improve the Services, including providers of cloud hosting, AI model hosting, analytics, customer support, communications, payment processing, security and fraud detection, compliance services, and IT infrastructure. These parties are contractually required to process personal data only as necessary to perform services on our behalf and consistent with our and your instructions and applicable law. A list of subprocessors used in our commercial Services shall be made available upon written request.
- Recipients of Agentic Actions: When you instruct an Agent or Digital Worker to communicate with, transmit data to, or interact with a third party (such as sending an email, posting to a system, or making an API call), the Agent or Digital Worker will disclose to that third party such information as required to perform the Agentic Action you have configured. Spire is not the originator of those communications and is not responsible for how those third parties handle the disclosed information.
- Significant corporate event: If we are involved in a merger, acquisition, restructuring, financing, bankruptcy, or other transaction involving the transfer of business assets, personal data may be disclosed to counterparties and advisers as part of due diligence or transferred as part of the transaction.
- Third-party services and integrations: Our Services may include integrations with, or links to, third-party websites, apps, or services. If you choose to interact with these third parties, you are providing information directly to them, and that information is governed by their own privacy policies.
- Legal compliance and protection of rights: We may disclose personal data to government authorities or other third parties where we believe doing so is necessary to (i) comply with applicable laws, regulations, or legal processes; (ii) respond to lawful requests or investigations; (iii) protect the safety, rights, or property of any person; (iv) prevent fraud, security incidents, or other unlawful activity; (v) enforce our Terms of Service or other legal rights; or (vi) protect Spire against legal liability.
- Business-account administrators: If you create an account using an email address associated with an organization, we may disclose account-related information (such as your email address, account status, and aggregated usage and Agentic Action logs) to that organization. Administrators of an enterprise account may access and manage your use of the Services.
- Other users you share information with: Certain features of the Services may allow you to share Inputs, Outputs, or other content with collaborators or third-party applications. Any information you voluntarily share is subject to the recipients' terms and privacy policies.
- With your consent: We may disclose personal data when you give us permission or direct us to do so.
We do not "sell" personal data, and we do not "share" personal data for cross-context behavioral advertising, in each case as those terms are defined under applicable U.S. state privacy laws. To the extent any analytics or marketing technologies on our website are deemed to constitute "sharing" under the CPRA or analogous laws, we provide opt-out controls through our cookie banner and honor Global Privacy Control signals.
4Rights and Choices
Depending on where you live and the laws that apply in your country of residence, you may have certain rights in relation to your personal data. To exercise any of these rights, you or an authorized agent may contact us at privacy@spire.ai. We may verify your identity before responding. We will not discriminate against you in violation of applicable law for exercising your privacy rights. However, we may be unable to continue providing certain Services if you exercise rights in a manner that prevents us from providing them (for example, deletion of essential account data). You may also have the right to appeal a decision we make in response to a request, by emailing the same address.
Subject to applicable law, your rights may include:
- Right to know: What personal data we process about you, the categories of sources, the purposes of processing, and the categories of third parties with whom we share it.
- Access and portability: Request a copy of the personal data we hold about you and, where applicable, in a portable format.
- Deletion: Request that we delete personal data collected from you in connection with your use of the Services, subject to certain exceptions. You may also delete individual conversations or sessions in-product, where supported.
- Correction: Request that we correct inaccurate personal data. Please note that, due to the nature of generative AI, we cannot guarantee the factual accuracy of Outputs, but we will make reasonable efforts to address correction requests.
- Objection: Object to processing of your personal data in certain circumstances, including for direct marketing.
- Restriction: Restrict our processing of your personal data in certain limited circumstances.
- Withdrawal of consent: Where the legal basis for processing is consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of prior processing.
- Right to explanation: Where applicable law (including the EU AI Act Article 86 and the GDPR Article 22) provides a right to a meaningful explanation of decisions taken by AI systems, you may request such an explanation. Spire will provide explanations to the extent feasible and consistent with the protection of trade secrets, intellectual property, and the rights of others.
- Lodging a complaint: Lodge a complaint with your local data protection authority (see Section 11 for regional contacts).
If you have a Spire account, many of these rights can be exercised directly through your account settings, including the ability to update profile information, manage marketing preferences, manage cookies, review and revoke Connected Account access, view and export Agentic Action logs, and (where supported) opt out of model training.
5International Data Transfers and Processing Locations
Spire is a global business. The OpenKnowra platform is operated by Spire Innovations, Inc. from regional cloud infrastructure. Customer Data is processed in the following regions, depending on the Customer's tier, the Services subscribed, and operational availability at the time of provisioning:
- European Economic Area / United Kingdom: EEA-resident and UK-resident Customer Data is processed in the European Union (Frankfurt, Germany), on cloud infrastructure provisioned and operated by Spire on Amazon Web Services (AWS) and, where applicable, Microsoft Azure.
- United States and the Americas: Customer Data is processed in the United States (us-east-2), on cloud infrastructure provisioned and operated by Spire on Amazon Web Services (AWS).
- Asia-Pacific: Customer Data may be processed in Singapore or Tokyo, depending on Customer election in the Order Form, on cloud infrastructure provisioned and operated by Spire on Amazon Web Services (AWS).
Where personal data is transferred outside the EEA, the United Kingdom, or Switzerland (for example, where a non-EEA customer's data is processed in the United States), we ensure that it benefits from an adequate level of data protection by relying on:
- Adequacy decisions: Decisions of the European Commission under Article 45 GDPR (or equivalent decisions under the UK GDPR or other laws), including the EU-US Data Privacy Framework where applicable;
- Standard contractual clauses: Approved standard contractual clauses ("SCCs") under Article 46 GDPR (and the UK and Swiss equivalents); or
- Other lawful safeguards: Other lawful transfer mechanisms permitted by applicable law, including derogations available under Article 49 GDPR in limited circumstances.
Where applicable law restricts cross-border processing, Customer Data is processed in jurisdictions consistent with those restrictions. EEA-resident and UK-resident personal data is, by default, processed in Frankfurt and is not transferred outside the EEA except under one of the safeguards described above.
6Data Retention, Lifecycle, and Security Controls
We retain personal data for as long as reasonably necessary for the purposes set out in this Privacy Policy, including to provide the Services, comply with our legal, tax, accounting, and reporting obligations, resolve disputes, enforce our agreements, and protect against fraud and abuse.
Specific retention periods depend on the type of personal data and the purpose for which we use it. Account information is retained for the duration of your account and for a reasonable period thereafter; payment, tax, and accounting records are retained for the longest applicable statutory period (which is typically up to ten (10) years, depending on jurisdiction); Inputs and Outputs are retained in accordance with the controls available in the Services and the terms of any Enterprise Agreement or DPA; and Agentic Action logs are retained for at least six (6) months and up to twelve (12) months (or longer where required by applicable law, such as the EU AI Act for high-risk AI systems). When personal data is no longer needed, we and our service providers will delete, erase, de-identify, or anonymize it in accordance with applicable laws.
6.1Security and certifications
The Services are operated within an environment that maintains SOC 2 Type II and ISO/IEC 27001 certifications. Such certifications are held by an affiliate of Spire Innovations, Inc. that operates the certified processing environment supporting the Services. We implement administrative, technical, and physical safeguards designed to protect personal data from loss, misuse, and unauthorized access, disclosure, alteration, or destruction. Specific safeguards for agentic operation include encryption of Connected Account credentials, scoped access tokens, rate limits on Agentic Actions, monitoring for anomalous Agent and Digital Worker behavior, and audit logging. However, no method of transmission over the Internet or method of electronic storage is completely secure; you should use caution when deciding what information to share.
6.2Security incidents
In the event of a confirmed personal data breach affecting your data, we will notify you and the relevant supervisory authorities as required by applicable law and our DPA (typically without undue delay and, where feasible, within seventy-two (72) hours of becoming aware).
7Cookies and Similar Technologies
We use cookies and similar technologies to operate the Services, recognize you, customize your experience, market our products, and analyze use of the Services. The categories include strictly necessary cookies, performance and analytics cookies, functional cookies, and marketing cookies. You can manage cookie preferences through our cookie banner, which provides equally prominent "accept" and "reject" options for non-essential cookies in compliance with EU ePrivacy and similar laws, or through your browser settings. We honor Global Privacy Control signals where applicable. For more information, please see our Cookie Policy.
8Children
Our Services are not directed to, and we do not knowingly collect, use, disclose, sell, or share any personal data from, children under the age of eighteen (18). If you become aware that a child under eighteen has provided personal data to us, please email privacy@spire.ai and we will investigate and, if appropriate, delete the information.
9Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will publish the updated version with a revised effective date. Where required by applicable law, we will provide additional notice (for example, by email or in-product notice) of material changes. Your continued use of the Services after the revised Privacy Policy takes effect constitutes acceptance of the changes.
10Legal Bases for Processing
If you are located in the EEA, the United Kingdom, or Switzerland, the table below summarizes the legal bases on which we process your personal data under the GDPR and equivalent laws. Where we rely on legitimate interests, we have conducted a balancing assessment to ensure your rights are not overridden.
| Purpose | Type of Data | Legal Basis (GDPR / similar) |
|---|---|---|
| To provide, maintain, and operate the Services (including APIs, AI Agents, and Digital Workers) | Identity & Contact Data; Inputs and Outputs; Agentic Action Logs; Technical Information; Payment Information | Performance of contract |
| To create and administer your account | Identity & Contact Data; Payment Information | Performance of contract |
| To facilitate payments | Identity & Contact Data; Payment Information | Performance of contract |
| To communicate with you and respond to inquiries | Identity & Contact Data; Communication Information; Technical Information | Performance of contract; Legitimate interests |
| To send marketing communications about Spire products and services | Identity & Contact Data; Technical Information | Consent (where required); Legitimate interests in promoting our Services |
| To verify customer eligibility (including under our Restricted Competitor policy) | Identity & Contact Data; publicly available business information | Legitimate interests in protecting our commercial position |
| To prevent and investigate fraud, abuse, security threats, and AUP violations | Identity & Contact Data; Inputs and Outputs; Agentic Action Logs; Technical Information | Legitimate interests; Legal obligation |
| To investigate and resolve disputes | Identity & Contact Data; Inputs and Outputs; Feedback; Agentic Action Logs | Legitimate interests; Legal obligation |
| To investigate and resolve security incidents | Identity & Contact Data; Technical Information; Inputs, Outputs, Agentic Action Logs | Legitimate interests; Legal obligation |
| To debug and repair errors that impair existing functionality | Identity & Contact Data; Technical Information; Feedback | Legitimate interests |
| To improve the Services and conduct research (excluding model training of paid-customer tenants) | Identity & Contact Data; Technical Information; Inputs, Outputs, Feedback | Legitimate interests |
| To improve the Services through model training (free / trial users only, or with paid-customer opt-in) | Inputs, Outputs, Feedback | Consent (where required); Legitimate interests |
| To maintain audit trails and logs of Agentic Actions for AI Act and regulatory purposes | Inputs, Outputs, Agentic Action Logs; Technical Information | Legal obligation; Legitimate interests |
| To provide explanations of decisions taken by AI systems where required by law (e.g. EU AI Act Art. 86) | Inputs, Outputs, Agentic Action Logs; Identity & Contact Data | Legal obligation; Legitimate interests |
| To enforce our Terms of Service and Acceptable Use Policy | Identity & Contact Data; Inputs, Outputs, Agentic Action Logs; Technical Information | Performance of contract; Legitimate interests |
11Regional Supplemental Disclosures
11.1European Economic Area, United Kingdom, and Switzerland
If you are in the EEA, the UK, or Switzerland, the following applies in addition to the rest of this Privacy Policy:
- Data controller: The data controller for your personal data is Spire Innovations, Inc.
- Processing location: Personal data of EEA, UK, and Swiss residents is, by default, processed in the European Union (Frankfurt, Germany). Cross-border transfers, where they occur, are made only under safeguards described in Section 5.
- EU/UK Representative: Where required under Article 27 GDPR (and the UK GDPR equivalent), our representative is to be appointed prior to onboarding individual EEA or UK consumers; current EEA and UK enterprise customers contracting on behalf of legal entities may contact privacy@spire.ai. We expect to publish the appointed representative's contact details by amendment to this Privacy Policy upon appointment.
- Data Protection Officer: You can contact our Data Protection Officer at dpo@spire.ai.
- Right to lodge a complaint: You have the right to lodge a complaint with your local supervisory authority. A list of EEA supervisory authorities is available at the European Data Protection Board's website. UK residents may contact the Information Commissioner's Office at ico.org.uk.
- EU AI Act: Where the Services include high-risk AI systems within the meaning of the EU AI Act, we comply with applicable provider obligations and assist deployers (our customers) in complying with their obligations, including transparency, logging, human-oversight, post-market monitoring, and explanation requirements (including under Article 86). Our Work and Workforce category Services are most likely to constitute high-risk AI systems under Annex III(4); our Customer Value Management category Services may constitute high-risk AI systems under Annex III(5) where used for credit, insurance, or eligibility decisions.
11.2California (CCPA / CPRA)
If you are a California resident, you have the rights described in Section 4 above, including the right to know, delete, correct, and limit use of sensitive personal information, and the right to opt out of "sale" or "sharing" of personal information for cross-context behavioral advertising. Spire does not sell personal information for monetary consideration. To the extent any of our marketing or analytics technologies constitute "sharing" under the CPRA, we provide opt-out controls through our cookie banner and honor Global Privacy Control signals. To exercise California-specific rights, please email privacy@spire.ai. We will not discriminate against you in violation of applicable law for exercising your rights.
11.3Other U.S. States
Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have rights similar to those described in Section 4, including rights to access, delete, correct, and port their personal data, to opt out of targeted advertising and "sale," and to appeal denials. Please email privacy@spire.ai to exercise these rights. Where the Colorado AI Act, Illinois AI Video Interview Act, or NYC Local Law 144 apply to a customer's use of the Services in employment-decision contexts, the obligations under those laws (including notice, opt-out, bias-audit, and reporting obligations) rest with the deploying customer; Spire provides supporting tooling where available.
11.4Brazil (LGPD)
If you are a resident of Brazil, the Brazilian General Data Protection Law (LGPD) provides you with rights including the right to confirm processing, request access, correct incomplete or outdated data, request anonymization or deletion, request portability, request information about parties with whom we shared data, revoke consent, and request a review of decisions made solely based on automated processing. Please contact privacy@spire.ai to exercise these rights. Our Encarregado de Dados (Brazilian Data Protection Officer) can be contacted at dpo@spire.ai. You may also lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD).
11.5Canada (PIPEDA / Quebec Law 25)
Residents of Canada may exercise rights of access and correction by emailing privacy@spire.ai. By providing personal data, you consent to the cross-border transfer and processing of your personal data outside Canada, including in the United States and the European Union, where laws may be less stringent than in Canada. You may withdraw consent subject to legal or contractual restrictions and reasonable notice. For commercial electronic messages, we will obtain your prior express or implied consent in accordance with Canada's Anti-Spam Legislation (CASL). You may also lodge a complaint with the Office of the Privacy Commissioner of Canada or, where applicable, the Commission d'accès à l'information du Québec.
11.6Australia
Residents of Australia have rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. To exercise your rights, please email privacy@spire.ai. For commercial electronic messages, we will obtain your prior consent in accordance with the Spam Act 2003 (Cth). You may also lodge a complaint with the Office of the Australian Information Commissioner (OAIC).
11.7South Korea, Japan, and Other Jurisdictions
Residents of South Korea, Japan, and other jurisdictions have additional rights under their respective national privacy laws (including the Personal Information Protection Act of South Korea ("PIPA"), Japan's Act on the Protection of Personal Information ("APPI"), and similar). Please contact privacy@spire.ai to exercise such rights, and refer to your local supervisory authority for additional information.
12Contact Information
If you have any questions or concerns about this Privacy Policy, or wish to exercise any of your rights, please contact us: