Privacy Policy
Effective: April 8, 2026 · Last updated: April 8, 2026
Speislink is committed to protecting your personal data. This Privacy Policy explains what data we collect, why we collect it, and how we use and protect it. We process your data in compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Italian privacy law. Fields marked [YOUR COMPANY NAME], [YOUR REGISTERED ADDRESS], [YOUR CITY], and [YOUR VAT NUMBER] must be replaced with actual legal entity details before publication.
1.Data Controller
The Data Controller responsible for processing your personal data is:
- ▸Company: [YOUR COMPANY NAME]
- ▸Registered address: [YOUR REGISTERED ADDRESS], [YOUR CITY], Italy
- ▸VAT number: [YOUR VAT NUMBER]
- ▸Email: privacy@speis.link
- ▸Website: https://speis.link
For all data protection inquiries or to exercise your rights under the GDPR, please contact us at privacy@speis.link.
2.Data We Collect
We collect the following categories of personal data:
- ▸Account Data: Your email address and chosen username, collected when you register.
- ▸Profile Data: Information you voluntarily add to your public profile, including display name, bio, and avatar image.
- ▸Content Data: Links, link groups, and digital product files that you create or upload on the Platform.
- ▸Payment and Transaction Data: We work with Stripe for subscription payments and product purchases. We do not store your full payment card details. We retain transaction IDs, subscription status, amounts, currencies, and timestamps.
- ▸Stripe Connect Data: If you sell products, we store your Stripe Connect Account ID, onboarding status, and payout-related information.
- ▸Creator Analytics Data: Aggregate statistics for your public profile page, including page views, link clicks, referrer domains, country-level geographic data (derived from IP addresses that are not stored individually), and device type classifications.
- ▸Usage Data: Data about how you interact with the Service, collected via PostHog, including pages visited, features used, and session duration.
- ▸Technical Data: Browser type and version, operating system, session tokens, and similar technical identifiers used for security and operational purposes. IP addresses are used transiently and are not stored permanently at an individual level.
- ▸Communications: Records of any correspondence with us, including support or legal inquiries.
We do not collect special categories of personal data (such as health, racial origin, political opinions, or biometric data) and ask that you not submit such data through the Service.
3.Legal Basis for Processing (GDPR Article 6)
We process your personal data on the following legal bases:
- ▸Performance of a Contract (Art. 6(1)(b)): To create and manage your account, provide the Service, process payments, and fulfill digital product orders. This is the primary legal basis for core Service functions.
- ▸Legitimate Interests (Art. 6(1)(f)): For security and fraud prevention, detecting and investigating abuse, Service improvement, bug detection, aggregate analytics, and enforcing our Terms of Service. Our legitimate interests are proportionate and do not override your fundamental rights and freedoms.
- ▸Compliance with a Legal Obligation (Art. 6(1)(c)): For retaining financial and transaction records as required by Italian accounting and tax law (10-year retention period), and for responding to lawful requests from public authorities.
- ▸Consent (Art. 6(1)(a)): For analytics cookies and any optional non-essential data processing. You may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
4.How We Use Your Data
We use your personal data to:
- ▸Create, manage, and authenticate your account.
- ▸Provide the Service, including hosting your public Speislink page and processing link clicks and page views.
- ▸Process subscription payments and manage billing via Stripe.
- ▸Facilitate digital product sales, including secure file delivery and download token generation.
- ▸Provide Creator analytics (page views, clicks, referrers, and geographic data).
- ▸Send transactional communications, including magic link authentication emails and important service notices.
- ▸Detect, investigate, and prevent fraud, spam, abuse, and security incidents.
- ▸Comply with legal obligations and respond to lawful requests from authorities.
- ▸Improve, develop, and troubleshoot the Service.
We do not sell, rent, or trade your personal data to third parties. We do not use your data for profiling or automated decision-making that produces legal or similarly significant effects without human review.
5.Data Sharing and Processors
We share your personal data only with the following categories of recipients, each bound by data processing agreements consistent with GDPR requirements:
| Processor | Purpose | Location | Transfer Safeguard |
|---|---|---|---|
| Supabase, Inc. | Database hosting, file storage, user authentication | USA (AWS us-east-1) | Standard Contractual Clauses (SCCs) |
| Stripe, Inc. | Subscription payment processing, Stripe Connect payouts | USA | SCCs + Stripe Data Processing Agreement |
| PostHog, Inc. | Product analytics and usage tracking | EU — Frankfurt, Germany | EU-based infrastructure; no EEA transfer |
| Cloudflare, Inc. | Content delivery network, edge computing, DDoS and bot protection | USA + global edge | SCCs |
Stripe for Creators: If you are a Creator, your Stripe Connect Account ID and payout information are shared with Stripe to facilitate payouts. Buyers' payment information is processed directly by Stripe and is subject to Stripe's Privacy Policy.
Legal Disclosures: We may disclose personal data if required by law, court order, or governmental authority, or if we reasonably believe disclosure is necessary to protect rights, property, or safety, or to detect, prevent, or address fraud or security issues.
Business Transfers: In the event of a merger, acquisition, or asset sale, your data may be transferred to the successor entity under equivalent protections.
6.International Data Transfers
Some of our processors (Supabase, Stripe, Cloudflare) are based in or operate infrastructure in the United States or other countries outside the European Economic Area (EEA). When we transfer personal data outside the EEA, we rely on appropriate safeguards as required by GDPR Article 46, including Standard Contractual Clauses (SCCs) approved by the European Commission.
PostHog analytics data is processed exclusively on EU-based infrastructure (Frankfurt, Germany) and does not leave the EEA.
You may request a copy of the relevant transfer safeguards we have in place by contacting us at privacy@speis.link.
7.Data Retention
We retain your personal data only for as long as necessary for the purposes described in this Policy, or as required by law:
| Data Category | Retention Period |
|---|---|
| Account data (email, username) | Until account deletion + 30 days for backup expiry |
| Profile data (links, bio, settings, avatar) | Until account deletion + 30 days |
| Product files uploaded by Creators | Until deletion by Creator + 30 days |
| Transaction records (purchases, subscriptions) | 10 years (Italian Civil Code and tax law — Art. 2220 c.c.) |
| Aggregate analytics events | 13 months rolling window |
| Support and legal correspondence | 3 years from last communication |
| Database backup snapshots | Up to 90 days after the applicable retention period |
After the applicable retention period, we delete or irreversibly anonymize your data. Note that account deletion initiates the deletion process, but data may remain in encrypted backups for up to 90 additional days.
8.Your Rights Under GDPR
As a data subject in the EU/EEA, you have the following rights under the GDPR. To exercise any of these rights, contact us at privacy@speis.link. We will respond within one (1) month; for complex or multiple requests, we may extend by up to two additional months with prior notification.
- ▸Right of Access (Art. 15): Request a copy of all personal data we hold about you and information about how we process it.
- ▸Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal data.
- ▸Right to Erasure / "Right to be Forgotten" (Art. 17): Request deletion of your data where it is no longer necessary for its original purpose, or where you withdraw consent. Note: we are legally required to retain financial records for 10 years.
- ▸Right to Restriction of Processing (Art. 18): Request that we limit how we process your data in certain circumstances (e.g., while we verify the accuracy of disputed data).
- ▸Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format and transmit it to another controller, where processing is based on contract or consent and is automated.
- ▸Right to Object (Art. 21): Object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
- ▸Rights Related to Automated Decision-Making (Art. 22): We do not engage in fully automated decision-making that produces legal or similarly significant effects.
- ▸Right to Withdraw Consent (Art. 7(3)): Where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
We may ask you to verify your identity before processing your request. Exercising your rights is free of charge in most cases. If requests are manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act.
9.Security
We implement appropriate technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction, including:
- ▸Encryption of all data in transit using TLS/HTTPS.
- ▸Encryption of sensitive data at rest in Supabase storage.
- ▸Role-based access controls and Row-Level Security (RLS) on database tables.
- ▸Secure, signed download URLs for product files with 48-hour expiry.
- ▸Passwordless authentication to eliminate credential theft vectors.
- ▸Regular security reviews and dependency updates.
No method of electronic storage or transmission is 100% secure. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and, where required, notify affected users without undue delay.
11.Children's Privacy
The Service is not directed to children under the age of 16. We do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe we have inadvertently collected personal data from a child under 16, please contact us at privacy@speis.link and we will promptly delete the data upon verification.
12.Changes to This Policy
We may update this Privacy Policy from time to time. For material changes — such as new categories of data collected, new purposes, or new third-party sharing — we will notify you by email at least thirty (30) days before the changes take effect, and by posting the updated Policy on our website with a revised effective date.
Your continued use of the Service after the effective date constitutes acceptance of the updated Policy. If you do not agree with the changes, you may delete your account before the new Policy takes effect.
13.Contact and Supervisory Authority
For questions, concerns, or to exercise your rights under this Privacy Policy, contact us at:
- ▸Email: privacy@speis.link
- ▸Company: [YOUR COMPANY NAME]
- ▸Address: [YOUR REGISTERED ADDRESS], [YOUR CITY], Italy
If you are not satisfied with our response or believe we are processing your personal data unlawfully, you have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali):
- ▸Website: www.garanteprivacy.it
- ▸Address: Piazza Venezia 11, 00187 Roma, Italy
- ▸Phone: +39 06 696771
- ▸Email: garante@gpdp.it
If you reside in another EU member state, you may also lodge a complaint with the data protection authority of your country of residence.