1. Who We Are
Spekir is a Danish sole proprietorship (enkeltmandsvirksomhed) currently undergoing business registration, and is the data controller for personal data processed through Spekir Atlas. CVR number and registered address will be published here once the registration process is complete.
In the meantime, data processing inquiries can be directed to privacy@spekir.com.
2. Data We Collect
2.1 Account data
- Email address (required for account creation)
- Name (optional)
- Profile image (if signing in with Google OAuth)
2.2 Workspace and architecture content
Content you create in Atlas — applications, capabilities, technologies, decisions, strategy hierarchies, and alignments. This content is stored within your workspace and visible only to workspace members you invite.
2.3 AI processing data
When you use Atlas' AI features, your input (application descriptions, strategy content, questions) is processed by our AI provider Anthropic to generate analyses, summaries, and recommendations. Anthropic processes this data under our data processing agreement; they do not use customer content to train their models. See Anthropic's Privacy Policy.
2.4 Usage and analytics data
With your consent, we collect anonymised product analytics via PostHog (feature interactions, page views — no personally identifiable information in analytics events). You can withdraw consent at any time via the cookie banner or Settings → Security.
2.5 Technical data
- IP address (for security and abuse prevention — not stored long-term)
- Browser type and session tokens
- Error logs and performance traces (via Sentry and Langfuse, for service quality)
3. Legal Basis (GDPR)
- Contract performance (Art. 6(1)(b)): Account data, workspace data — necessary to provide the Atlas service
- Legitimate interest (Art. 6(1)(f)): Security, fraud prevention, error monitoring, service improvement
- Consent (Art. 6(1)(a)): Analytics cookies — you can withdraw at any time
- Legal obligation (Art. 6(1)(c)):Accounting records retained per Danish bookkeeping law (Bogføringsloven)
4. Where Data Is Stored
- Database: Neon PostgreSQL — EU region, Frankfurt, Germany (eu-central-1). All customer data at rest is within the EU.
- Application hosting: Vercel — serverless compute may run on EU edge nodes; Vercel CDN is global
- AI inference: Anthropic — processed in the USA under a data processing agreement with Standard Contractual Clauses
- Transactional email: Resend — processed in the USA under SCCs
- AI observability: Langfuse — EU-hosted (Germany)
5. Sub-processors
A full list of third parties that process personal data on our behalf is available at /legal/sub-processors. We notify workspace admins 30 days in advance of material sub-processor changes.
6. Your Rights (GDPR)
- Right of access:Request a copy of your data via Settings → Account → Export Data, or email privacy@spekir.com
- Right of erasure:Delete your account via Settings → Account → Delete Account. A 30-day grace period applies; you can cancel before deletion runs.
- Right of rectification: Edit your data directly in Atlas or contact privacy@spekir.com
- Right to data portability:Export available as JSON via Settings → Account → Export Data
- Right to object: Contact privacy@spekir.com
- Right to lodge a complaint: Contact the Danish Data Protection Authority (Datatilsynet) at datatilsynet.dk
7. Data Retention
- Active workspaces: retained for the duration of the service relationship
- Deleted workspaces: removed within 30 days of deletion request
- Deleted user accounts: anonymised within 30 days of erasure request
- Accounting records: 5 years per Danish bookkeeping law (Bogføringsloven)
- Database backups: 7-day rolling point-in-time recovery (Neon)
8. Cookies
We use essential cookies (authentication, security) and optional analytics cookies. See our Cookie Policy for full details. Manage preferences via the cookie banner or Settings → Security.
9. International Transfers
Some sub-processors (Anthropic, Vercel, Resend) process data outside the EU/EEA. Transfers are covered by Standard Contractual Clauses (EU Commission Decision 2021/914) or the EU-US Data Privacy Framework where applicable.
10. Children
Atlas is not directed at persons under 16. We do not knowingly collect data from minors.
11. Changes to This Policy
Material changes will be communicated by email and noted on this page with an updated date. Previous versions available on request.