Spectra

Privacy Policy

Last updated: not yet published

Who we are

Spectra is run by Rahul Kumar, a sole proprietor in India rather than a company. For anything in this policy you can write to privacy@spectra-trace.com.

Our representatives in the EU and the UK

We are established in India, and on our customers' behalf we record how people in the European Economic Area and the United Kingdom behave on their websites. Article 27 of the GDPR and of the UK GDPR therefore require us to appoint a representative in each, who may be contacted on any matter relating to our processing as an alternative to contacting us.

We have not appointed either representative yet. Until we do, write to privacy@spectra-trace.com and we will answer you directly, and we will name them here as soon as they are in place. We would rather say so than leave the question open.

What this policy covers

There are two different groups of people in this document and the distinction matters.

Data we collect as a controller

Data we process for customers

Session recordings: what changed on the page, where a visitor clicked and scrolled, page addresses, browser and device characteristics, and errors the page reported. Recordings are grouped by a visitor identifier, which is either an identifier the customer supplies or a random value we generate and store in the visitor's browser.

Behaviour measurements, where the customer has enabled them: one summary for each page a visitor sees, containing counts and timings rather than content. Which elements were clicked and how often, how far the page was scrolled, how long the visit lasted, how fast the page loaded, the page address with any query removed, the name of the referring website, any campaign tags in the address, and a device category. Elements carry the visible text of buttons and links so the customer can recognise them; the contents of form fields are never included, and the masking rules below apply to these labels exactly as they apply to a recording.

We do not sell this data, we do not use it to build profiles across different customers' websites, and we do not use it to train models.

What we never collect at all

We do not collect visitor IP addresses. Not masked, not truncated, not held briefly and discarded: there is nowhere in the system that stores one. Most of this industry records the IP of every visitor to a customer's website and then works out how to defend it. We decided not to take it, so the most common piece of personal data in web analytics is one we cannot lose, cannot be compelled to hand over, and never have to delete.

We also place no advertising or cross-site tracking cookie, and we do not build profiles of people across different customers' websites.

What is masked before it leaves the browser

Masking happens on the visitor's own device, before anything is sent, so the masked content never reaches our servers at all.

Masking cannot be perfect. A website that renders a person's data as ordinary page text will have that text recorded, which is why customers choose what to mask and are the controller for what they record.

Do Not Track, Global Privacy Control and consent

Our recorder can be configured to stop recording any visitor whose browser sends Do Not Track or Global Privacy Control, and to wait for a consent platform before recording at all. Whether those are switched on is the website owner's decision, because they are the controller and they know what they told their visitors.

Why we process it

For account data, to perform our contract with the customer and for our legitimate interest in running and securing the service. For recordings, on the instructions of the customer, who is responsible for having a lawful basis for the recording they have chosen to carry out.

We are established in India, so the Digital Personal Data Protection Act 2023 governs our own processing. Where a customer or a visitor is in the European Economic Area or the United Kingdom the GDPR applies as well: for account data we rely on performance of our contract and on our legitimate interest in running and securing the service, and for recordings we act only as a processor on the customer's documented instructions, on the terms set out in our data processing agreement.

Sub-processors

We use a small number of other companies to run the service. We name each of them, and what they do, to any customer who asks: write to privacy@spectra-trace.com and we will send you the current list. We give 30 days' notice by email before a new one starts, and a customer may object.

By category, they are:

If we ever keep a copy of recordings with another provider, we will say so here and give notice first.

International transfers

Recordings are stored in France, inside the European Economic Area, and running the service does not move them out of it.

We are based in India and administer the service from there, so operating it means reaching data held in France from outside the EEA. That access relies on the European Commission's Standard Contractual Clauses (Decision 2021/914), which form part of our data processing agreement, alongside the measures described below: recordings are scoped to one workspace, nobody can open one without a time-limited grant that names the individual, and every grant is recorded and visible to the customer.

Our other providers may process data outside the EEA under their own data processing terms, which incorporate those same clauses or rely on an adequacy decision. A list of provider locations is available on request.

Retention

Recordings are kept for the retention window of the plan in force when the recording was made, and are deleted automatically afterwards. Every recording is measured against the window that applied on the day it was made, so buying a longer window does not extend the life of older recordings and moving to a shorter one does not shorten recordings already made under a longer plan.

Account and billing records are kept for as long as the account exists and then for six years, to meet the accounting and tax obligations that apply to us in India.

Your rights

Depending on where you live you may have the right to access, correct, delete or export your data, to object to or restrict processing, and to complain to a supervisory authority.

If you are a visitor to a website that uses Spectra, contact that website first: they decide what is recorded and they can have it deleted. If you cannot reach them, write to us and we will identify the customer and pass the request on.

Customers can delete an individual visitor's recordings, delete a whole site and its recordings, or ask us to close their account. Deletion removes the recordings, everywhere they are listed or searched, and every other copy we hold.

Cookies and browser storage

Our own website and dashboard store your sign-in session in your browser so you stay signed in. We do not use advertising or cross-site tracking cookies.

On a customer's website, our recorder stores a random visitor identifier so that a visitor's pages group into one session. It contains no personal information and is not shared between customers. If a customer has enabled a consent gate, nothing is stored until consent is given.

Security

Children

Spectra is a business product and is not directed at children. We do not knowingly collect data from children. Under Indian law that means anybody under 18. In the European Economic Area and the United Kingdom the age at which a child can consent for themselves to an online service is between 13 and 16 depending on the country. A customer who records a site aimed at children is the controller for those recordings and is responsible for the consent they require.

Changes to this policy

We will post any change here and update the date at the top. If a change materially affects how we handle personal data we will tell customers by email before it takes effect.

Contact and complaints

Write to privacy@spectra-trace.com. If you are not satisfied you may complain to the Data Protection Board of India. If you are in the European Economic Area or the United Kingdom you may instead complain to the supervisory authority where you live, where you work, or where the matter arose; in the United Kingdom that is the Information Commissioner's Office.