Privacy policy
This policy explains what personal data UAB „Empera LT“ processes when you use the spincrm.com website or the Spin CRM business management system.
Spin CRM is a system into which our customers enter their own customers’ data. Our role therefore depends on which data we are talking about — and this document keeps that difference separate:
- Section 2 — you are visiting spincrm.com. We are the data controller.
- Section 3 — you are using Spin CRM as a user. We are the data controller.
- Section 4 — your company keeps its customers’, suppliers’ or employees’ data in the system. You are the data controller and we are only a processor acting on your instructions.
If you are looking for the terms covering the fourth case, they are in a separate document — Data processing terms. It can be attached to a service agreement on its own.
1. Who we are
| Data controller | UAB „Empera LT“ |
|---|---|
| Company code | 304066716 |
| VAT number | LT100009542010 |
| Address | Dūkštelių g. 106, Gudelių k., LT-14247 Vilnius district, Lithuania |
| [email protected] | |
| Phone | +370 663 52000 |
For any data protection question write to [email protected] or call +370 663 52000. We reply on working days.
Our Data Protection Officer is Darius Vitkus. Write to [email protected] or by post: UAB „Empera LT“, Data Protection Officer, Dūkštelių g. 106, Gudelių k., LT-14247 Vilnius district, Lithuania.
2. When you visit spincrm.com
2.1. The enquiry form
When you fill in the enquiry form you give us your name, company name, email address, phone number and the text of your message.
The website does not store this data in its own database. The contents of the form travel straight into our own Spin CRM system and become a lead record. If the system is unreachable at that moment, the contents are emailed to us so that the enquiry is not lost — no other copies are made.
| Data | Name, company, email, phone, message text, the address of the page the form was sent from |
|---|---|
| Purpose | To answer your enquiry and get in touch about it |
| Legal basis | Steps taken at your request before entering into a contract (GDPR Art. 6(1)(b)); our legitimate interest in answering enquiries (Art. 6(1)(f)) |
| Retention | 24 months from last contact, then the record is anonymised |
2.2. Signing up for the trial
When you sign up for the 14-day trial you give us your name, work email address, phone number and company name. We do not ask for and do not collect card details.
Along with the sign-up we pass on your IP address — it is needed so we can tell a genuine sign-up from automated abuse.
| Data | Name, work email, phone, company, IP address |
|---|---|
| Purpose | To create the trial environment and send the invitation; to protect against abuse |
| Legal basis | Steps taken at your request before entering into a contract (Art. 6(1)(b)); legitimate interest in protecting the system (Art. 6(1)(f)) |
| Retention | 90 days from creation. After that the trial environment and the data in it are deleted automatically, unless agreed otherwise |
2.3. Protection against abuse
So that the forms cannot be used for bulk spam, we limit how many times a form can be sent from one IP address: the enquiry form 6 times per hour, the sign-up 5 times per minute. For counting we use not the IP address itself but its cryptographic hash, which is held in temporary storage and deleted when it expires. The IP address cannot be recovered from the hash.
2.4. Cookies and analytics
How the site uses cookies, which ones there are and how to change your choice is described separately — Cookie policy. In short:
- Essential cookies are always on. Today there is one —
pll_language, which remembers whether you are reading the Lithuanian or the English version. It needs no consent, because without it the site would not work the way you asked. - Analytics cookies (Google Analytics 4) are switched on only if you agree. Until you do, Google Analytics writes no cookies and sends no data. You can withdraw your consent at any time.
The website loads no external resources at all — fonts, styles and scripts all come from our own server. That means that simply opening a page does not make your browser contact third-party servers, and they learn nothing about your visit. The one exception is Google Analytics, and only after you agree.
2.5. Server logs
Like every web server, ours records technical details of requests: IP address, time, the address requested, browser type and response code. Cloudflare sits in front of the site — a service that protects against attacks and overload; it sees these technical details too.
| Purpose | Keeping the site running, security, troubleshooting |
|---|---|
| Legal basis | Legitimate interest in network and information security (Art. 6(1)(f)) |
| Retention | Up to 12 months |
3. When you use the Spin CRM system
This section is about you as a user: your account, logins, billing and support. For the data you enter into the system yourself, see section 4.
3.1. Account and login data
| Data | First and last name, work email, phone, job title, department, role and permissions, language choice; password (stored only as a one-way hash), two-factor authentication settings |
|---|---|
| Purpose | To give access to the system, tell users apart, manage permissions |
| Legal basis | Performance of the contract with your company (Art. 6(1)(b)) |
If your account was created by your employer, we received your name, email and job title from them rather than from you.
3.2. Security and activity logs
The system records logins, login attempts, information about the devices used and significant changes to records. This is needed so that your company can see who changed what and when, and so that we can investigate an incident.
| Legal basis | Performance of the contract (Art. 6(1)(b)); legitimate interest in system security (Art. 6(1)(f)) |
|---|---|
| Retention | While the contract with your company is in force — the log is part of your system data and is deleted along with it |
3.3. Billing
To issue invoices we process company registration details, the contact person’s details, the chosen plan, the number of users and payment history. Accounting documents are kept for as long as the law requires — 10 years.
| Legal basis | Performance of the contract (Art. 6(1)(b)); legal obligation to keep accounts (Art. 6(1)(c)) |
|---|
3.4. Help and support
When you get in touch with a question or a problem, we process your contact details, the content of your message and any files or screenshots you attach. If solving the problem requires looking at data inside your system, we do so under the rules described in section 4 and in the Data processing terms.
| Legal basis | Performance of the contract (Art. 6(1)(b)); legitimate interest in improving service quality (Art. 6(1)(f)) |
|---|---|
| Retention | 24 months from resolution |
3.5. Newsletters and notifications
We keep two things apart:
- Service messages — about planned work, outages, security updates and material changes to the terms. We send these to every user, because they are part of the service rather than marketing. You cannot opt out of them, but you will not receive any other kind of email because of that.
- Newsletters and offers — only if you agree. You can withdraw that consent at any time: every email carries an unsubscribe link that works without our involvement.
When you withdraw consent we keep the fact that you withdrew it — otherwise we would not know whom not to email. That is data minimisation, not the opposite.
3.6. System usage statistics
So that we can see which modules are used and which are not, and plan improvements, we collect aggregated usage statistics. For this analysis we use neither your name, nor your contact details, nor the contents of any record — only event counts. We make no automated decisions about you and build no profiles.
| Legal basis | Legitimate interest in improving the product (Art. 6(1)(f)) |
|---|
4. The data you enter into the system
When your company keeps its customers’, contacts’, suppliers’ or employees’ data in Spin CRM, you are the data controller. You decide what data to collect, on what basis and for how long to keep it. We are the data processor — we process that data only in order to provide you with the service, and only on your instructions.
In practice that means:
- We do not use the data in your system for our own purposes — not for marketing, not for sales, not for analysis.
- We do not pass it on to third parties, except to sub-processors where that is necessary to provide the service, and where the law requires it.
- We touch your data only when the service needs maintaining or when you ask us for help.
- When the contract ends we return or delete the data — your choice.
Every customer has a separate database. There is no shared table holding every company’s information.
The full terms of this relationship — including the list of sub-processors, security measures, breach notification and data return — are in a separate document: Data processing terms.
5. Who we share data with
5.1. Sub-processors that are always involved
These providers take part in delivering the service to every customer:
| Provider | What for | Where |
|---|---|---|
| Hosting and data centre provider | Servers, data storage, backups | European Union |
| Cloudflare | Protecting the site against attacks, content delivery | EU / USA (see s. 6) |
| OpenAI | Artificial intelligence features — document scanning, turning emails into tickets, filling in forms | USA — standard contractual clauses (see s. 6) |
| Google (Firebase Cloud Messaging) | Notifications to the browser and the mobile app | EU / USA (see s. 6) |
| Google (Analytics) | Website traffic statistics — only if you agree | EU / USA (see s. 6) |
5.2. Connectors you switch on yourself
Spin CRM connects to more than twenty external services, but none of them runs by itself. You switch each one on, in your own settings and with your own credentials. By switching a connector on you decide that certain data will travel to that service — and that is your decision as the data controller.
| Area | Providers |
|---|---|
| Accounting | Rivilė, Finvalda, Robolabs |
| Banking and payments | Enable Banking (PSD2), Montonio, NeoPay |
| Electronic signature | Mark ID (Smart-ID, mobile signature) |
| Messaging and chat | Meta (Messenger, Instagram Direct), Telegram |
| Email and calendar | Microsoft 365, Google Workspace, any IMAP / SMTP provider |
| Telephony and SMS | Telia, Tele2, Bitė, Peoplefone, Kalbu, TCG Telecom, SMSAPI |
| Marketing | MailerLite, Omnisend |
| Company data | Okredo, the European Commission’s VIES |
| Industry-specific | Autoplius, Autogidas, Wialon |
| Analytics and BI | Microsoft Power BI and other OData tools |
The full and current list is on the integrations page. Before switching a connector on, check that service’s privacy terms: from that moment its rules govern how it processes the data.
5.3. Other recipients
- Auditors, lawyers, accountants — where our own operations require it, and only as far as necessary.
- Public authorities — where the law requires it and only in the manner the law prescribes.
- In case of a business transfer — if the company or part of it were transferred, we would inform you in advance.
We do not sell data and do not exchange it with advertising networks.
6. Where we process data
Your system data is held in the European Union.
Several of the services listed in section 5.1 are US companies. Where data reaches them, the transfer relies on the European Commission’s standard contractual clauses and, where applicable, the EU–US Data Privacy Framework. We have a data processing agreement with each such provider.
Artificial intelligence features operate outside the EU. AI requests are processed by OpenAI in the United States. The transfer relies on the European Commission’s standard contractual clauses and on the data processing agreement concluded with OpenAI. OpenAI does not use the transferred data to train models and keeps it for no longer than 30 days — for abuse monitoring only — after which it is deleted.
Artificial intelligence features. We send the AI model only what a specific action requires — for example, the contents of the document being scanned. Public models are not trained on your data. The AI connector that lets you ask questions about your own data is read-only and sees exactly as much as that same person would see at that moment — it does not bypass the permission system. AI features can be switched off entirely; the system works the same without them.
7. How long we keep data
| Data | Retention |
|---|---|
| Enquiry from the website | 24 months from last contact |
| Trial environment | 90 days from creation, then deleted automatically |
| Account data | For as long as the contract with your company is in force |
| System data after the contract ends | Returned or deleted within 30 days (see Data processing terms) |
| Backups | Taken once a day at night, kept for 14 days |
| Accounting documents | 10 years (statutory requirement) |
| Marketing consent and the proof of it | While the consent is valid + 3 years after withdrawal (so that we can show it was lawful) |
| Server logs | Up to 12 months |
When the period ends we delete the data or irreversibly anonymise it. If the data is the subject of a legal dispute, we keep it until the dispute is over.
8. How we protect data
- A separate database for every customer — there is no shared pot holding every company’s data.
- Encrypted connection (TLS) between your browser and the system.
- Two-factor authentication (Google Authenticator or SMS), which an administrator can make mandatory for the whole company.
- An allowed IP address list and protection against password guessing.
- Permissions down to a single record and field, a role hierarchy and sharing rules.
- An activity log and device management.
- Regular backups.
- Our staff access customer data only where needed and are bound by confidentiality.
Even so, no transmission over the internet is completely secure. If you become aware of a security flaw, please report it to [email protected] — we take such reports seriously and act on them without delay.
9. Your rights
You have the right to:
- Access the data we hold about you.
- Rectify inaccurate data.
- Erase data where there is no longer a basis for keeping it (the “right to be forgotten”).
- Restrict processing.
- Object to processing based on our legitimate interest.
- Port your data to another controller in a machine-readable format.
- Withdraw consent at any time where processing is based on it. Withdrawal does not apply retroactively.
Important. If your data is in a customer’s system (section 4), please contact that company — they are the controller, not us. If you come to us, we will point you to them and let them know about your request.
Send requests to [email protected]. We reply within one month; in complex cases we may extend that by a further two months, having told you so. So that we do not disclose data to the wrong person, we first have to establish your identity — we may ask you to confirm the request from an email address known to us.
If you believe we are handling data improperly, please come to us first. You also have the right to lodge a complaint with the State Data Protection Inspectorate of Lithuania (L. Sapiegos g. 17, Vilnius, vdai.lrv.lt).
10. Changes
We update this policy when the system or the law changes. The current version is always on this page, and its date is given below. We announce material changes affecting system users by email or in the system at least 30 days before they take effect.
This version applies from 31 August 2026.