Privacy Policy
At Spotline, we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy is designed to help you understand how we collect, use, disclose, and safeguard your personal information when you use our website.
Please take a moment to read this Privacy Policy carefully. By accessing or using our website, you consent to the practices described in this Privacy Policy.
Table of Contents
- Introduction
- About Spotline
- Scope
- Information We Collect
- Sources of Collection
- Business Areas
- Audience-Specific Processing
- Product Demonstration and Consultation Requests
- How We Use Personal Information
- Lawful Basis for Processing (GDPR)
- Cookies and Similar Technologies
- Marketing Communications
- Sharing Information and Subprocessors
- International Data Transfers
- Data Retention Schedule
- Global Privacy Control (GPC)
- Children's Privacy
- Third-Party Links
- Modernize Legacy Template Language
- Changes to this Privacy Policy
- Privacy Requests and Complaints
- Contact Information
Introduction
Spotline Inc. ("Spotline," "we," "our," or "us") is committed to protecting the privacy, confidentiality, and security of the personal information entrusted to us by our customers, business partners, website visitors, employees, and other stakeholders. As a trusted provider of digital transformation, validation, and regulatory technology services for the life sciences industry, werecognize the importance of maintaining the highest standards of privacy and data protection.
This Enterprise Privacy Policy explains how Spotline collects, uses, stores, shares, transfers, and safeguards personal information when you access our website, use our products or services, communicate with our team, attend our events, participate in marketing activities, or otherwise interact with Spotline.
The purpose of this Privacy Policy is to provide transparency regarding our privacy practices and to demonstrate our commitment to protecting personal information in accordance with applicable global privacy laws and industry best practices. This Policy has been developed to support compliance with:
- General Data Protection Regulation (EU GDPR)
- United Kingdom General Data Protection Regulation (UK GDPR)
- EU ePrivacy Directive
- California Consumer Privacy Act (CCPA)
- California Privacy Rights Act (CPRA)
- Brazil's Lei Geral de Proteção de Dados (LGPD)
- Canada's Personal Information Protection and Electronic Documents Act (PIPEDA)
- India's Digital Personal Data Protection Act (DPDP Act), where applicable
- Other applicable privacy and data protection laws in jurisdictions where Spotline operates or provides services
This Privacy Policy also supports the privacy and security expectations commonly required by enterprise organizations in the pharmaceutical, biotechnology, medical device, healthcare, and regulated technology sectors.
About Spotline
Spotline is a global technology consulting and professional services company specializing in digital transformation and compliance solutions for the life sciences industry. We help regulated organizations implement, optimize, validate, and manage mission-critical business applications while maintaining compliance with applicable regulatory requirements.
Our expertise spans the complete lifecycle of regulated technology solutions, including strategy, implementation, migration, validation, quality assurance, managed services, artificial intelligence, automation, and ongoing operational support.
Spotline's service offerings include, but are not limited to:
- Veeva Vault implementation, configuration, deployment, and optimization
- Veeva Vault migration and legacy system modernization
- Computer Systems Validation (CSV)
- Validation automation using Spotline's V-Assure platform
- AI-powered productivity solutions, including V-Assist
- Quality management and regulatory compliance consulting
- Managed application support services
- Data migration and integration services
- Digital transformation consulting
- Regulatory technology implementation
- Cloud application validation
- Quality and compliance assessments
- Business process optimization for regulated environments
Our customers include pharmaceutical manufacturers, biotechnology companies, medical device organizations, contract research organizations (CROs), healthcare organizations, and other regulated businesses operating under FDA, EMA, MHRA, GxP, and other global regulatory frameworks.
As part of providing these services, Spotline may process personal information on behalf of customers as either a Data Controller or Data Processor, depending on the nature of the engagement and applicable contractual obligations.
Scope
This Privacy Policy applies to all personal information collected by Spotline through our websites, products, services, digital platforms, communications, and business operations.
It applies to individuals who interact with Spotline in various capacities, including:
- Visitors to the Spotline website and related digital properties
- Individuals requesting product demonstrations or consultations
- Prospective customers and sales inquiries
- Customers and authorized users of Spotline products and services
- Webinar, seminar, and event participants
- Newsletter and marketing subscribers
- Business partners and strategic alliance partners
- Suppliers, vendors, and contractors
- Job applicants and recruitment candidates
- Existing and prospective employees, where applicable
- Individuals contacting Spotline through email, telephone, live chat, social media, or contact forms
This Privacy Policy also governs personal information collected through:
- Website forms
- Customer onboarding activities
- Technical support requests
- Customer success engagements
- Product evaluations and demonstrations
- Marketing campaigns
- Surveys and feedback programs
- Industry conferences and trade shows
- Virtual events and webinars
- Business development activities
- Professional networking platforms
- Customer relationship management (CRM) systems
This Policy applies regardless of whether you interact with Spotline online, by email, by telephone, during virtual meetings, or through in-person business engagements.
Information We Collect
Depending on the nature of your relationship with Spotline, we may collect various categories of personal information necessary to provide our services, support our business operations, comply with legal obligations, and improve customer experiences.
Identity Information
We may collect personal identifiers such as your name, business title, employer, department, professional role, company affiliation, and professional credentials.
Contact Information
This may include your business email address, telephone number, mailing address, company address, country or region, and preferred communication methods.
Professional and Business Information
To better understand your organization's needs, we may collect information relating to your industry, organization size, regulatory environment, technology landscape, business interests, project requirements, and purchasing preferences.
Technical Information
When you visit our website or interact with our online services, we may automatically collect technical information such as:
- IP address
- Browser type and version
- Operating system
- Device identifiers
- Network information
- Language preferences
- Time zone settings
- Referral URLs
- Session identifiers
- Security logs
Website Usage Information
We collect information about how visitors interact with our website, including:
- Pages visited
- Time spent on pages
- Downloads
- Navigation paths
- Search terms
- Form submissions
- Clickstream data
- Website performance metrics
Marketing and Communications Information
Where you engage with our marketing activities, we may collect information regarding:
- Newsletter subscriptions
- Email preferences
- Webinar registrations
- Event attendance
- Marketing campaign interactions
- Downloaded resources
- Survey responses
- Communication history
Customer Support Information
When you contact Spotline, we may collect information relating to:
- Support requests
- Technical issues
- Product inquiries
- Service tickets
- Meeting notes
- Customer communications
- Feedback and satisfaction surveys
Recruitment Information
If you apply for employment opportunities with Spotline, we may collect:
- Resume or CV
- Employment history
- Education
- Certifications
- Professional references
- Interview notes
- Skills assessments
- Background information where legally permitted
Contractual and Financial Information
For customers, suppliers, and partners, we may collect information necessary to establish and manage contractual relationships, including billing contacts, purchase order information, and payment-related administrative records. Spotline does not intentionally collect or store payment card information unless required as part of an authorized payment process managed by approved payment service providers.
Sources of Collection
Spotline collects personal information from several sources depending on the nature of our business relationship.
Information You Provide Directly
We collect information that you voluntarily provide when you:
- Complete website forms
- Contact our sales or support teams
- Request product demonstrations
- Download white papers or other resources
- Register for webinars or events
- Subscribe to newsletters
- Participate in surveys
- Apply for employment
- Engage with Spotline representatives
Information Collected Automatically
When you use our website or digital services, certain technical information is collected automatically through technologies such as:
- Cookies
- Web beacons
- Pixels
- Analytics tools
- Server logs
- Security monitoring systems
Information Received from Customers
As part of delivering consulting, implementation, validation, managed services, or AI solutions, enterprise customers may provide information necessary for us to perform contracted services. In these situations, Spotline processes such information in accordance with customer agreements and applicable data protection laws.
Publicly Available Sources
Spotline may obtain professional information from publicly available sources, including company websites, professional directories, industry publications, conference attendee lists (where permitted), and publicly accessible business networking platforms.
Business Partners and Referrals
We may receive business contact information from strategic partners, referral partners, technology partners, distributors, or authorized resellers to support legitimate business development and customer engagement activities.
Recruitment Sources
Candidate information may also be obtained from recruitment agencies, professional networking platforms, employee referrals, or publicly available professional profiles, where permitted by applicable law.
Business Areas
Spotline operates across multiple service lines that support the digital transformation and regulatory compliance needs of life sciences organizations. Depending on the services provided, different categories of personal information may be processed to deliver professional services, manage customer relationships, and meet contractual or regulatory obligations.
Veeva Implementation Services
Spotline provides end-to-end implementation, configuration, deployment, customization, integration, and optimization services for Veeva Vault applications. Personal information may be processed to manage project delivery, user provisioning, training, testing, issue resolution, customer support, and ongoing governance activities.
Veeva Migration Services
Our migration services assist organizations in securely transferring data, documents, configurations, and business processes from legacy systems to modern Veeva platforms. Processing activities may include migration planning, data mapping, validation, quality assurance, user acceptance testing (UAT), and post-migration support, all performed under strict confidentiality and security controls.
Computer Systems Validation (CSV)
Our migration services assist organizations in securely transferring data, documents, configurations, and business processes from legacy systems to modern Veeva platforms. Processing activities may include migration planning, data mapping, validation, quality assurance, user acceptance testing (UAT), and post-migration support, all performed under strict confidentiality and security controls.
Computer Software Assurance (CSA)
Spotline supports risk-based Computer Software Assurance methodologies that emphasize critical thinking and quality assurance over excessive documentation. Processing activities may include risk assessments, test strategy development, evidence collection, quality reviews, defect tracking, and regulatory documentation.
V-Assist AI Solutions
Spotline's AI-powered solutions, including V-Assist, help improve operational efficiency, knowledge discovery, and productivity within regulated environments. Depending on customer configuration and usage, processing activities may include user authentication, prompt handling, knowledge retrieval, interaction logging, system monitoring, and performance analytics. AI services are designed to support enterprise governance requirements and operate in accordance with applicable contractual, security, and privacy obligations.
Life Sciences Consulting
Spotline provides strategic consulting services covering digital transformation, regulatory compliance, quality management, process optimization, validation strategy, inspection readiness, and technology modernization. These engagements may involve the processing of business contact information, project communications, workshop documentation, stakeholder feedback, and other information necessary to deliver professional consulting services.
Managed Services
Our managed services provide ongoing application administration, monitoring, maintenance, user support, release management, incident resolution, system enhancements, and operational governance. Authorized personnel may process customer-related information necessary to deliver contracted support services while maintaining appropriate confidentiality and security controls.
Audience-Specific Processing
Spotline processes personal information differently depending on how individuals interact with our organization. The categories of information collected, the purposes for processing, and the legal basis for processing may vary based on the nature of the relationship. The following sections describe how we process personal information for different audiences.
Website Visitors
When you visit the Spotline website, we automatically collect certain technical and usage information necessary to operate, secure, and improve our digital services. This may include your IP address, browser type, device information, operating system, referring URLs, pages visited, session duration, language preferences, and website interaction data collected through cookies and similar technologies.
We use this information to:
- Deliver website content and functionality
- Monitor website performance and availability
- Improve user experience and navigation
- Analyze website traffic and visitor behavior
- Detect and prevent security threats
- Maintain website integrity
- Diagnose technical issues
- Comply with legal and regulatory obligations
Where required by applicable law, non-essential cookies and analytics technologies are activated only after obtaining your consent.
Product Demonstration and Consultation Requests
If you request a product demonstration, consultation, or discovery meeting, Spotline collects information necessary to understand your business requirements and provide relevant solutions.
Information collected may include:
- Name
- Company name
- Job title
- Business email address
- Telephone number
- Country or region
- Industry
- Areas of interest
- Current technology environment
- Business objectives
- Regulatory requirements
- Project timelines
This information is used to:
- Schedule demonstrations
- Evaluate business requirements
- Recommend appropriate services and solutions
- Prepare customized presentations
- Follow up on inquiries
- Maintain sales records
- Improve customer engagement
Webinar and Event Participants
When you register for webinars, virtual events, conferences, workshops, or training sessions hosted or sponsored by Spotline, we collect information necessary to administer your participation.
This may include:
- Registration details
- Attendance records
- Organization information
- Professional role
- Event participation history
- Questions submitted during sessions
- Feedback surveys
- Continuing education interests
This information helps us:
- Deliver event content
- Provide event communications
- Share presentation materials
- Improve future educational programs
- Evaluate event effectiveness
- Respond to participant questions
- Maintain attendance records
Where permitted, we may also send relevant follow-up communications related to the event.
Newsletter Subscribers
Individuals who subscribe to Spotline newsletters or marketing communications provide contact information that enables us to share educational content, product updates, industry insights, regulatory developments, webinars, and company announcements.
Marketing communications may include:
- Product updates
- Industry news
- White papers
- Case studies
- Regulatory insights
- Webinar invitations
- Event announcements
- Technical articles
- Company news
Subscribers may withdraw their consent or update communication preferences at any time using the unsubscribe link included in our communications or by contacting Spotline directly.
Customer Inquiries
When individuals contact Spotline through our website, email, telephone, social media, or other communication channels, we process information necessary to respond to inquiries and provide requested assistance.
This may include:
- Contact information
- Communication history
- Business requirements
- Technical questions
- Product interests
- Meeting notes
- Support documentation
- Follow-up correspondence
This information allows us to:
- Respond to inquiries promptly
- Provide accurate information
- Schedule meetings
- Deliver customer support
- Improve customer satisfaction
- Maintain communication records
Enterprise Customers
Spotline provides implementation, migration, validation, managed services, AI solutions, and consulting services to enterprise customers operating in regulated industries. During the course of providing contracted services, Spotline may process business-related personal information associated with customer personnel, authorized users, project stakeholders, administrators, and other designated contacts.
Processing activities may include:
- Project planning
- User provisioning
- Configuration support
- Validation documentation
- Training coordination
- Quality reviews
- Issue resolution
- Managed services
- Technical support
- Customer success activities
- Regulatory documentation
- Compliance reporting
Where Spotline processes personal information on behalf of enterprise customers, we act as a Data Processor and process information only in accordance with customer instructions, contractual agreements, and applicable data protection laws.
Business Partners and Vendors
Spotline maintains relationships with technology partners, suppliers, consultants, contractors, and vendors necessary to support business operations.
Information processed may include:
- Business contact information
- Contract information
- Procurement records
- Payment administration
- Professional certifications
- Service delivery records
- Compliance documentation
- Communication history
This information is used to:
- Manage contractual relationships
- Evaluate vendor performance
- Process invoices
- Maintain supplier records
- Support procurement activities
- Meet legal and regulatory obligations
Job Applicants
Individuals applying for employment opportunities with Spotline voluntarily provide personal information during the recruitment process.
Information collected may include:
- Resume or curriculum vitae
- Employment history
- Education
- Certifications
- Professional references
- Interview evaluations
- Skills assessments
- Background verification information where legally permitted
Recruitment information is used solely for:
- Evaluating qualifications
- Managing recruitment activities
- Scheduling interviews
- Conducting reference checks
- Assessing candidate suitability
- Complying with employment laws
- Maintaining recruitment records
Candidate information is retained only for the period necessary to complete recruitment activities or as otherwise permitted by applicable law.
How We Use Personal Information
Spotline uses personal information only for legitimate business purposes that are necessary to deliver our services, fulfill contractual obligations, comply with applicable laws, maintain secure operations, and improve the customer experience.
Depending on the nature of your relationship with Spotline, we may use personal information for the following purposes.
Service Delivery
To provide our professional services, including:
- Veeva Vault implementation
- Veeva migration services
- Computer Systems Validation (CSV)
- Computer Software Assurance (CSA)
- Managed application services
- AI-powered solutions, including V-Assist
- Life sciences consulting
- Quality and compliance assessments
- Digital transformation projects
- Technical support and customer success
Customer Relationship Management
To establish, manage, and maintain customer relationships by:
- Responding to inquiries
- Scheduling meetings
- Managing projects
- Providing customer support
- Delivering requested information
- Monitoring customer satisfaction
- Managing contracts and renewals
Product and Service Improvement
We analyze aggregated and non-identifiable information to:
- Improve website functionality
- Enhance user experience
- Develop new products and services
- Improve existing solutions
- Evaluate product performance
- Support innovation initiatives
- Improve AI capabilities where appropriate and contractually permitted
Marketing and Communications
Subject to applicable law and your communication preferences, Spotline may use personal information to:
- Send newsletters
- Share product updates
- Promote webinars
- Invite participation in industry events
- Provide regulatory insights
- Distribute educational content
- Share case studies and success stories
- Inform customers of new services
Recipients may opt out of marketing communications at any time.
Website Administration
To maintain the operation, performance, and security of our websites, including:
- Monitoring website traffic
- Managing cookies
- Detecting suspicious activity
- Preventing fraud
- Diagnosing technical issues
- Maintaining website availability
Security and Fraud Prevention
Personal information may be processed to:
- Protect our systems
- Prevent unauthorized access
- Detecting suspicious activity
- Investigate security incidents
- Maintain audit logs
- Protect customer information
- Comply with security standards
Regulatory Compliance
Spotline processes personal information where necessary to comply with applicable legal and regulatory obligations, including:
- Financial reporting
- Tax obligations
- Employment regulations
- Data protection laws
- Regulatory inspections
- Government requests
- Audit requirements
- Contractual compliance obligations
Business Administration
Personal information may also be processed to support routine business operations, including:
- Contract administration
- Procurement
- Vendor management
- Billing
- Payment processing
- Corporate governance
- Risk management
- Internal reporting
- Business continuity planning
Spotline limits the use of personal information to the purposes described in this Privacy Policy or to other compatible purposes permitted by applicable law. We do not use personal information for automated decision-making or profiling that produces legal or similarly significant effects without appropriate safeguards.
Lawful Basis for Processing (GDPR)
Where the General Data Protection Regulation (GDPR) or the United Kingdom General Data Protection Regulation (UK GDPR) applies, Spotline processes personal information only where a valid legal basis exists under applicable data protection laws.
Performance of a Contract
We process personal information when necessary to enter into, perform, or manage contractual relationships with our customers, partners, vendors, employees, and service providers.
Examples include:
- Delivering Veeva implementation services
- Performing CSV and CSA engagements
- Providing managed services
- Delivering AI solutions
- Providing technical support
- Managing customer projects
- Processing vendor agreements
- Responding to service requests
Legitimate Interests
Spotline may process personal information where necessary to pursue our legitimate business interests, provided those interests are not overridden by the rights and freedoms of individuals.
Legitimate interests include:
- Business development
- Customer relationship management
- Service improvement
- Website analytics
- Network and information security
- Fraud prevention
- Corporate governance
- Internal administration
- Marketing to existing business contacts where permitted by law
- Protecting legal rights
- Quality assurance and compliance monitoring
Before relying on legitimate interests, Spotline conducts appropriate assessments to ensure that our processing is fair, proportionate, and respects individual privacy rights.
Consent
Where required by law, Spotline relies on your consent before processing certain categories of personal information.
Examples include:
- Sending promotional email communications to individuals who have opted in
- Placing non-essential cookies and similar technologies on your device
- Collecting personal information through optional forms or surveys
- Recording webinars or meetings where notice and consent are required
You may withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
Compliance with Legal Obligations
Spotline processes personal information where necessary to comply with applicable legal, regulatory, or statutory obligations.
This may include processing related to:
- Tax and accounting requirements
- Employment laws
- Court orders and legal proceedings
- Government or regulatory requests
- Data protection compliance
- Record retention obligations
- Audit and inspection requirements
Protection of Vital Interests
In limited circumstances, Spotline may process personal information where necessary to protect the vital interests of an individual or another natural person, such as responding to emergencies or addressing situations involving health, safety, or security where permitted by law.
Accountability and Purpose Limitation
Spotline maintains records of its processing activities as required by applicable privacy laws and applies the principles of accountability, transparency, data minimization, purpose limitation, accuracy, storage limitation, integrity, and confidentiality.
We process personal information only for specified, explicit, and legitimate purposes and do not use it in ways that are incompatible with those purposes unless required or permitted by applicable law. Appropriate technical and organizational measures are implemented to demonstrate ongoing compliance with GDPR, UK GDPR, and other relevant privacy regulations.
Lawful Basis for Processing Personal Data
Spotline processes personal information only where there is a valid legal basis under applicable privacy laws, including the General Data Protection Regulation (GDPR) and the UK GDPR.
| Contact Forms | Personal Data | Purpose | Lawful Basis |
|---|---|---|---|
| Contact Forms | Name, Email, Company, Phone | Respond to inquiries | Legitimate Interest |
| Demo Requests | Contact Details, Business Information | Product demonstrations | Pre-contractual Steps |
| Customer Services | Contact Details | Deliver contracted services | Contract Performance |
| Newsletter | Email Address | Marketing communications | Consent |
| Events & Webinars | Registration Details | Event administration | Contract / Legitimate Interest |
| Recruitment | Resume, Employment History | Recruitment | Legitimate Interest |
| Website Analytics | IP Address, Browser Information | Improve website performance | Consent (where required) |
| Security Monitoring | Device Information, IP Address | Fraud prevention and security | Legitimate Interest / Legal Obligation |
Cookies and Similar Technologies
Spotline uses cookies and similar technologies to ensure the reliable operation, security, performance, and continuous improvement of our website and digital services. Cookies are small text files stored on your device that help websites recognize your browser, remember user preferences, improve navigation, and collect analytical information regarding website usage.
Depending on your interaction with our website, Spotline may use the following categories of cookies:
Strictly Necessary Cookies
These cookies are essential for the operation and security of our website and cannot be disabled through our cookie preference center. They enable core website functionality such as secure browsing, session management, load balancing, authentication, fraud prevention, and the storage of your cookie consent preferences.
Functional Cookies
Functional cookies enhance your browsing experience by remembering preferences you have selected, such as language settings, accessibility options, regional preferences, and other website customizations. These cookies help deliver a more personalized and consistent user experience.
Analytics Cookies
Analytics cookies help Spotline understand how visitors interact with our website by collecting aggregated information regarding page views, navigation paths, user engagement, referral sources, and website performance. These insights enable us to improve website usability, optimize content, enhance customer experience, and measure the effectiveness of our digital initiatives.
Where required by applicable law, analytics cookies are activated only after obtaining your consent.
Marketing Cookies
Marketing cookies support our business development and marketing activities by measuring campaign effectiveness, tracking webinar registrations, evaluating content engagement, and delivering communications that may be relevant to your professional interests. These cookies may be placed by Spotline or trusted third-party service providers acting on our behalf.
Similar Technologies
In addition to cookies, Spotline may use web beacons, tracking pixels, local storage, session storage, software development kits (SDKs), server logs, and similar technologies that perform comparable functions. These technologies help us monitor website performance, detect security incidents, analyze user engagement, and support customer interactions.
Managing Cookie Preferences
When you first visit the Spotline website, you will be presented with a cookie consent banner that enables you to accept, reject, or customize your cookie preferences. You may update or withdraw your consent at any time through the "Cookie Preferences" link available on our website.
Most web browsers also allow you to manage, delete, or block cookies through browser settings. Please note that disabling certain cookies may affect the functionality, security, or performance of portions of our website.
For additional information regarding our use of cookies, please refer to our separate Cookie Policy.
Marketing Communications
Spotline communicates with customers, prospects, business partners, and subscribers regarding our services, products, educational resources, industry developments, and corporate announcements in accordance with applicable privacy and electronic communications laws.
Our marketing communications may include:
- Product and service announcements
- Regulatory and compliance updates
- Industry insights and technical articles
- White papers and case studies
- Webinar and event invitations
- Company news
- Product demonstrations
- Customer success stories
- Educational newsletters
Where required by law, Spotline will obtain your consent before sending marketing communications. In certain business-to-business contexts, we may rely on legitimate interests where permitted by applicable law.
Recipients of marketing communications may:
- Unsubscribe at any time using the unsubscribe link included in our emails
- Update communication preferences through available preference centers
- Contact Spotline directly to modify subscription settings
- Withdraw previously granted consent without affecting the lawfulness of processing conducted prior to withdrawal
Even if you opt out of marketing communications, Spotline may continue to send transactional or service-related communications that are necessary to fulfill contractual obligations, respond to customer inquiries, administer customer accounts, provide technical support, or comply with legal requirements.
Sharing Information and Subprocessors
Spotline values the confidentiality of personal information and does not sell personal information to third parties. We only disclose personal information where necessary to provide our services, comply with legal obligations, protect our legitimate business interests, or where you have authorized such disclosure.
Depending on the nature of our services, personal information may be shared with carefully selected third parties, including:
- Cloud hosting and infrastructure providers
- Customer relationship management (CRM) platforms
- Marketing automation providers
- Webinar and virtual event platforms
- Email communication providers
- Website analytics providers
- Identity and access management providers
- Cybersecurity and monitoring vendors
- Professional advisers, including legal, accounting, and auditing firms
- Payment processing providers, where applicable
- Technology partners supporting our products and services
- Customer-approved subcontractors engaged in project delivery
Where Spotline engages subprocessors to support the delivery of services, appropriate contractual safeguards are implemented to ensure that personal information is processed only on documented instructions, remains confidential, and is protected using appropriate technical and organizational security measures.
Spotline conducts due diligence when selecting service providers and periodically evaluates their security, privacy, and compliance practices to ensure they meet our business and regulatory requirements.
Personal information may also be disclosed where required to:
- Comply with applicable laws or regulatory obligations
- Respond to lawful requests from government authorities
- Protect the rights, property, or safety of Spotline, our customers, or others
- Enforce contractual agreements
- Support corporate transactions such as mergers, acquisitions, or reorganizations, subject to appropriate confidentiality obligations
Public Subprocessor List
This is one of the biggest improvements.
| Processor | Service | Region | Transfer Mechanism |
|---|---|---|---|
| HubSpot | CRM & Marketing | USA | SCCs |
| Analytics | USA | SCCs | |
| Microsoft | Microsoft 365 | USA | SCCs |
| Cloudflare | CDN & Security | Global | SCCs |
| AWS | Cloud Infrastructure | USA/EU | SCCs |
Describe Vendor Selection
Spotline conducts appropriate due diligence before engaging third-party service providers. We assess security practices, privacy controls, contractual commitments, and applicable certifications where appropriate.
Describe Processor Contracts
All processors handling personal information on behalf of Spotline are contractually required to:
- Process data only on documented instructions.
- Maintain appropriate technical and organizational security measures.
- Notify Spotline of security incidents where required.
- Assist Spotline in responding to data subject requests.
- Delete or return personal information upon termination of services where applicable.
Explain International Transfers
Expand your international transfer section to mention:
- Standard Contractual Clauses (SCCs)
- UK International Data Transfer Addendum (where applicable)
- Adequacy decisions (where applicable)
- Transfer impact assessments (when appropriate)
Data Processing Agreement (DPA)
Enterprise customers may request Spotline's Data Processing Agreement by contacting privacy@spotline.com
Security Certifications
Below is the list of Spotline security certifications
- ISO 27001:2022
- ISO 9001
- SOC 2 Type 2
- ISO 27017
- ISO 27018
Annual Reviews
Spotline periodically reviews third-party service providers to ensure continued compliance with contractual, security, and privacy requirements.
International Data Transfers
Spotline is a global technology and consulting company that supports customers across multiple countries. As part of providing our services, personal information may be transferred to, processed, or accessed in countries other than the country in which it was originally collected.
These transfers may occur when:
- delivering implementation, validation, migration, managed services, or consulting engagements;
- responding to customer inquiries and support requests;
- operating our website and digital services;
- operating our website and digital services;
- using trusted cloud infrastructure and software providers;
- collaborating with affiliates, partners, and authorized subcontractors; or
- complying with applicable legal or regulatory requirements.
Where personal information originating in the European Economic Area (EEA), the United Kingdom, or Switzerland is transferred to countries that have not been recognized as providing an adequate level of protection, Spotline implements appropriate safeguards in accordance with applicable data protection laws.
Depending on the circumstances, these safeguards may include:
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- the UK International Data Transfer Addendum or other approved UK transfer mechanisms, where applicable;
- transfers to jurisdictions that are subject to an adequacy decision by the European Commission or other competent authority;
- contractual commitments requiring service providers to protect personal information in accordance with applicable privacy laws; and
- additional technical and organizational security measures designed to safeguard personal information.
Spotline also evaluates cross-border transfers through risk-based assessments where appropriate and requires third-party processors handling personal information on our behalf to implement appropriate technical, organizational, and contractual safeguards.
Examples of these safeguards include:
- encryption of personal information during transmission and, where appropriate, at rest;
- role-based access controls and least-privilege access;
- multi-factor authentication for administrative access, where applicable;
- security monitoring and incident response procedures;
- contractual confidentiality obligations; and
- regular security assessments and audits.
Individuals may request additional information regarding the safeguards used for international transfers by contacting Spotline using the contact information provided in this Privacy Policy.
Cross-Border Data Protection
Spotline continuously reviews applicable privacy laws and regulatory guidance to ensure that international transfers remain compliant with evolving legal requirements. Where required by law, we update our contractual safeguards and operational practices to reflect changes in regulatory guidance or judicial decisions affecting international data transfers.
Data Retention Schedule
Spotline retains personal information only for as long as necessary to fulfill the purposes for which it was collected, satisfy contractual commitments, comply with legal or regulatory obligations, resolve disputes, maintain security records, or enforce our legal rights.
Retention periods vary depending on the nature of the information and applicable legal requirements. Examples include:
| Category | Typical Retention |
|---|---|
| Website inquiries | Up to 24 months |
| Marketing subscribers | Until consent is withdrawn or after a defined period of inactivity |
| Customer contracts and project documentation | Duration of the engagement plus applicable statutory retention periods |
| Customer support records | Up to 7 years |
| Customer support records | Up to 7 years |
| Recruitment records | Up to 24 months, unless otherwise required by law |
| Security and audit logs | 12–24 months, depending on business and security requirements |
| Financial and accounting records | As required by applicable tax and financial regulations |
Spotline periodically reviews retention schedules to ensure information is not retained longer than necessary. Once retention periods expire, personal information is securely deleted, anonymized, or destroyed using industry-recognized methods that help prevent unauthorized recovery or access.
Security Measures
Protecting customer and business information is fundamental to Spotline's operations. We maintain a comprehensive information security program designed to safeguard personal information against unauthorized access, disclosure, alteration, loss, destruction, or misuse.
Our security program incorporates administrative, technical, and organizational safeguards, including:
- Encryption of data during transmission using industry-standard protocols
- Encryption of sensitive information at rest where appropriate
- Multi-factor authentication (MFA) for privileged access
- Role-based access controls and least-privilege principles
- Identity and access management procedures
- Continuous monitoring of systems and infrastructure
- Security event logging and audit trails
- Vulnerability scanning and remediation
- Regular software patching and security updates
- Endpoint protection and malware detection
- Secure software development practices
- Periodic penetration testing and security assessments
- Employee privacy and cybersecurity awareness training
- Vendor security due diligence and ongoing assessments
- Business continuity and disaster recovery planning
- Backup and restoration procedures
- Incident response planning and security breach management
- Physical safeguards for facilities and equipment, where applicable
While Spotline employs industry-standard security measures, no method of electronic transmission or storage can be guaranteed to be completely secure. We continuously evaluate and enhance our security controls to address evolving cybersecurity risks and regulatory expectations.
Individual Privacy Rights
Spotline respects the privacy rights granted to individuals under applicable data protection laws, including the General Data Protection Regulation (GDPR), UK GDPR, California Consumer Privacy Act (CCPA), California Privacy Rights Act (CPRA), and other applicable privacy regulations.
Subject to applicable law and appropriate verification of identity, individuals may have the right to:
Right of Access
Request confirmation regarding whether Spotline processes your personal information and obtain access to the information we maintain about you.
Right to Rectification
Request correction of inaccurate, incomplete, or outdated personal information maintained by Spotline.
Right to Erasure
Request deletion of personal information where retention is no longer necessary or where deletion is otherwise required by applicable law, subject to legal or contractual exceptions.
Right to Restrict Processing
Request that Spotline temporarily limit the processing of your personal information under circumstances provided by applicable law.
Right to Object
Object to certain processing activities, including processing based on legitimate interests or direct marketing communications.
Right to Data Portability
Request a copy of certain personal information in a structured, commonly used, and machine-readable format and, where technically feasible, request transmission to another organization.
Right to Withdraw Consent
Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal does not affect processing conducted before consent was withdrawn.
Right to Lodge a Complaint
If you believe that Spotline has not processed your personal information in accordance with applicable law, you may lodge a complaint with the relevant supervisory authority or data protection regulator in your jurisdiction.
Exercising Your Rights
To protect the privacy and security of individuals, Spotline will verify the identity of any person submitting a privacy request before providing access to personal information or processing requests involving sensitive actions such as deletion or correction.
Privacy Policy. It is intended to comply with the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and other applicable California privacy laws.
Subject to applicable legal exceptions, California residents have the right to understand how Spotline collects, uses, retains, and discloses personal information and to exercise certain rights regarding that information.
Categories of Personal Information Collected
During the preceding twelve (12) months, Spotline may have collected the following categories of personal information, depending on your relationship with us:
- Identifiers (such as name, business email address, business telephone number, company name, and online identifiers)
- Professional or employment-related information
- Commercial information relating to products or services requested
- Internet or electronic network activity information, including website usage and analytics
- Geolocation information derived from IP addresses (general location only)
- Communications with Spotline, including customer support and inquiry records
- Audio, visual, or electronic information where participation in webinars, virtual meetings, or recorded events has been disclosed
- Recruitment and employment information for job applicants
- Technical and security information collected to protect our systems and services
Spotline collects only the categories of information reasonably necessary to provide our services, operate our business, meet legal obligations, and improve customer experiences.
Purposes for Collection and Use
Personal information may be used for purposes including:
- Delivering consulting, implementation, validation, managed services, and AI-powered solutions
- Responding to customer inquiries and support requests
- Managing contracts and customer relationships
- Improving our website, products, and services
- Conducting marketing activities where permitted by law
- Administering webinars and educational events
- Complying with legal, contractual, and regulatory obligations
- Maintaining information security and fraud prevention
- Supporting business operations and internal administration
Disclosure of Personal Information
Spotline may disclose personal information to trusted service providers and business partners that assist us in delivering our services. These disclosures occur under written agreements requiring recipients to maintain appropriate confidentiality, security, and privacy protections.
Spotline does not sell personal information as that term is defined under the CCPA/CPRA. Spotline also does not knowingly share personal information for cross-context behavioural advertising.
Sensitive Personal Information
Spotline does not collect or use sensitive personal information for the purpose of inferring characteristics about individuals. Any sensitive personal information that may be processed in limited circumstances is used only for legitimate business purposes permitted by applicable law and is protected using appropriate security measures.
California Privacy Notice
This section applies solely to California residents and supplements the information contained elsewhere in this Privacy Policy.
California residents may have the right to:
- Know the categories and specific pieces of personal information collected about them
- Request access to personal information
- Request correction of inaccurate personal information
- Request deletion of personal information, subject to applicable exceptions.
- Request information regarding categories of information disclosed to third parties.
- Limit the use of sensitive personal information where applicable.
- Receive equal service and pricing regardless of whether they exercise their privacy rights.
Spotline will verify the identity of individuals submitting privacy requests before fulfilling requests and will respond within the timeframes required by applicable California law.
Spotline will not discriminate against any individual for exercising rights provided under the CCPA or CPRA.
Global Privacy Control (GPC)
Spotline recognizes the importance of browser-based privacy preferences and supports the Global Privacy Control (GPC) standard where required by applicable law.
Global Privacy Control is a browser or browser extension setting that communicates a user's privacy preferences to participating websites. Where legally required, Spotline interprets a valid GPC signal as a request to opt out of the sale or sharing of personal information and certain forms of targeted advertising.
If your browser transmits a recognized GPC signal, Spotline will process that request in accordance with applicable privacy laws without requiring additional action from you, except where identity verification or additional information is reasonably necessary.
Support for GPC is provided in accordance with applicable legal requirements and may vary depending on the services or technologies used on our website.
Children's Privacy
Spotline's website, products, and professional services are designed exclusively for business users, enterprise customers, and professionals working within regulated industries. Our services are not intended for use by children or minors.
Spotline does not knowingly collect, solicit, or process personal information from children under the age specified by applicable law, including individuals under the age of 16 where required by certain jurisdictions.
If we become aware that personal information relating to a child has been inadvertently collected without appropriate authorization, we will take reasonable steps to promptly delete or anonymize that information unless retention is required by law.
Parents or legal guardians who believe that a child has provided personal information to Spotline may contact us using the contact details provided in this Privacy Policy. We will investigate such requests promptly and take appropriate action where necessary.
Third-Party Links
For your convenience, the Spotline website may include links to third-party websites, applications, social media platforms, partner portals, educational resources, technology providers, and other external services that are not owned or controlled by Spotline.
These links are provided solely as a convenience to our visitors and do not constitute an endorsement of the third-party organizations, their products, services, or privacy practices.
Once you leave the Spotline website or interact with third-party content embedded within our website, any personal information you provide will be governed by the privacy policies, terms of use, and security practices of those third parties.
Spotline does not control and is not responsible for:
- The privacy practices of third-party websites
- The security measures implemented by external organizations
- The accuracy or content of third-party websites
- Cookies or tracking technologies deployed by external sites
- The collection, use, disclosure, or retention of personal information by third parties
We encourage all users to carefully review the privacy policies and terms of any external websites before submitting personal information or using their services.
Changes to this Privacy Policy
Spotline may update this Privacy Policy from time to time to reflect changes in applicable laws, regulatory guidance, industry standards, technologies, business operations, products, services, or organizational practices.
Examples of circumstances that may require updates include:
- New privacy or data protection legislation
- Regulatory guidance issued by supervisory authorities
- Introduction of new products or services
- Changes to our technology infrastructure
- Changes in business operations or organizational structure
- Implementation of new security measures
- Updates to customer or vendor processing activities
Whenever material changes are made, the revised Privacy Policy will be published on the Spotline website together with an updated "Effective Date" or "Last Updated" date.
Where required by applicable law, Spotline will provide additional notice or obtain consent before implementing changes that materially affect the way personal information is processed.
We encourage visitors and customers to review this Privacy Policy periodically to remain informed about our privacy practices.
Modernize Legacy Template Language
If your Privacy Policy still includes generic statements such as:
- "place an order"
- "administer contests"
- "Google DART cookie"
- "shopping cart"
- "products purchased"
replace them with language specific to Spotline's business, such as:
- Requesting demonstrations
- Downloading resources
- Registering for webinars
- Contacting Spotline
- Applying for employment
- Receiving newsletters
- Engaging Spotline for consulting, validation, managed services, AI solutions, or implementation services
Privacy Requests and Complaints
Spotline is committed to responding promptly, fairly, and transparently to privacy-related inquiries and requests.
Individuals may contact Spotline to:
- Request access to personal information
- Request correction of inaccurate or incomplete information
- Request deletion of personal information
- Withdraw previously provided consent where applicable
- Object to certain processing activities
- Exercise data portability rights where applicable
- Submit questions regarding our privacy practices
- Report suspected privacy incidents or concerns.
- Request additional information regarding this Privacy Policy
Upon receiving a request, Spotline may take reasonable steps to verify the identity of the individual making the request before disclosing or modifying personal information. Additional information may be requested where necessary to prevent unauthorized access.
We acknowledge receipt of privacy requests and strive to investigate and respond within the timeframes required by applicable privacy laws. If additional time is required due to the complexity of a request, we will inform the individual and provide updates as appropriate.
If an individual believes that Spotline has not handled their personal information in accordance with applicable privacy laws, they may also have the right to submit a complaint to the appropriate supervisory authority or data protection regulator within their jurisdiction.
Spotline is committed to cooperating with relevant regulatory authorities and resolving privacy concerns in a timely and transparent manner.
Contact Information
If you have any questions regarding this Privacy Policy, our privacy practices, or the processing of your personal information, or if you wish to exercise your privacy rights, please contact Spotline using one of the methods below.
Privacy Contact
Spotline Inc.
Email: privacy@spotline.com
Website: https://spotline.com
For privacy requests, please include:
- Your full name
- Company name (if applicable)
- Email address or other contact information.
- Country or state of residence.
- A description of your request or concern.
- Any information that may help us identify the relevant records.
Providing complete information will help us verify your identity and process your request more efficiently.
Enterprise customers with contractual privacy, security, or data processing obligations may also contact their designated Spotline Account Manager, Customer Success Manager, or the contact identified in their applicable services agreement or Data Processing Agreement (DPA).
Spotline is committed to handling all privacy inquiries professionally, maintaining appropriate confidentiality, and responding in accordance with applicable legal and contractual requirements.
The future of enterprise AI is harmonized and compliant. See what it looks like today.
Experience certified, production-ready AI built for regulated enterprise.
No commitment required. Speak directly with a domain expert who knows your stack.