Skip to content
homepricingaboutcontact
Sign inSign up

Legal

Privacy Policy

Last updated: August 2026

This Privacy Policy explains how Spore collects, uses, shares, and protects personal data when you visit our website, create an account, and use the Spore platform, and how we handle the limited personal data that appears in our company database because it is published in official company registers. We are committed to handling personal data in line with the General Data Protection Regulation (GDPR) and applicable Estonian data protection law.

On this page

  • 1. Who We Are
  • 2. Scope of This Policy
  • 3. Our Role Controller and Processor
  • 4. Information We Collect
  • 5. Company Registry Data
  • 6. How We Use Your Information
  • 7. Legal Basis for Processing
  • 8. Data Sharing and Subprocessors
  • 9. International Data Transfers
  • 10. Data Retention
  • 11. Security
  • 12. Your Rights
  • 13. Customer Content and Data Subject Requests
  • 14. Children
  • 15. Changes to This Policy
  • 16. Contact Us

1. Who We Are

Spore is operated by:

Sporenet OÜ (operating as Spore)

Erika tn 14, Põhja-Tallinna linnaosa

10416 Tallinn, Harju maakond

Estonia

Registry code: 16686175

Email: info@netspore.ee

For the personal data described in this policy, Sporenet OÜ is the data controller unless stated otherwise in Section 3.

2. Scope of This Policy

This policy applies to:

  • Visitors to our marketing website
  • People who sign up for and use a Spore account, including team members invited to an organization and users of our API
  • People who contact us for sales or support
  • People whose information appears in our company database because an official company register lists them in connection with a company (see Section 5)

It does not govern how our customers use the platform to process data about their own contacts and leads, or how they use data obtained through the platform after they export it or act on it. For data our customers upload or generate, our customer is the controller and we act as their processor; for data they take out of the platform, they act as an independent controller. See Section 3.

3. Our Role Controller and Processor

Spore is a company-intelligence platform for business research, verification, and lead workflows. Our relationship to personal data depends on the type of data:

  • We are the controller for account, billing, and usage data: the information needed to create your account, operate the platform, take payment, and improve the service.
  • We are the controller for our company database: the company records we compile from official company registers, including the limited board-member and company-contact information described in Section 5.
  • We are a processor for the contacts, leads, and other records you upload, import, or generate through the platform, including the results of enrichment and research workflows you run ("Customer Content"). You decide what data to process and for what purpose; we process it on your documented instructions to provide the service. As the controller of Customer Content, you are responsible for having a lawful basis for that processing and for responding to the rights requests of the individuals it concerns.
  • Our customers are independent controllers of the data they export from the platform or otherwise use for their own purposes, such as outreach. Their processing is governed by their own privacy notices and legal bases, not by this policy.

Processing of Customer Content is governed by the Data Processing Terms annexed to our Terms of Service.

4. Information We Collect

4.1 Information You Provide

When you sign up, contact us, or use the platform, we collect:

  • Account data: name, email address, password (stored hashed), and organization name
  • Profile and team data: your role within an organization and invitations you send or receive
  • Billing data: plan selection and billing details. Card payments are processed by Stripe; we do not store full card numbers.
  • Support and sales data: the contents of messages you send us

4.2 Information We Collect Automatically

When you use the platform we automatically collect:

  • Log and device information: IP address, browser type, operating system, access times, and pages or features viewed
  • API usage data: API keys are organization-scoped; we log API and integration requests (including requests made by automated tools or AI agents using your keys) for security, billing, and abuse prevention
  • Product analytics: how you navigate and use the platform, collected through PostHog (EU-hosted). Optional analytics tracking on our marketing site is activated only after you consent via our cookie banner.
  • Cookies and similar technologies: as described in our Cookie Policy

4.3 Customer Content

When you upload, import, or enrich records, the platform processes the personal data contained in those records (for example, business contact names, email addresses, job titles, and company details). Enrichment and research workflows collect information from publicly available sources only when you run them — through the app, the API, or an integration — and their results become part of your Customer Content. We process Customer Content as your processor, as described in Section 3.

5. Company Registry Data

Spore operates a database of companies compiled from official government company registers. Its purpose is company research and market intelligence: letting our customers identify, verify, and assess companies. This section is our notice under GDPR Article 14 to people whose information appears in that database because of their role in a company.

We provide this notice publicly because we cannot notify each person individually: the registers do not give us personal contact details for these people, so individual notification would be impossible or would involve disproportionate effort (Article 14(5)(b)). We apply the safeguards described below instead.

5.1 What We Include

From each register we take company records: legal names, registration identifiers, status, addresses, industry classifications, financial figures, and company-to-company relationships. The only information about natural persons that we retain is:

  • Current board members: full name, first and last name where the register provides them, and the appointment date where available. We include a person only when the official register explicitly identifies them as a current member of a company's management or supervisory board or as a director.
  • Company contact channels: email addresses, phone numbers, and websites that a register designates as the company's official contact details. These belong to the company record and are not linked to any person, although a value may incidentally identify someone (for example, a firstname@company email address).
  • Marketing-protection indicators: where a register records that a company has opted out of direct marketing or enjoys a similar protection, we record and display that indicator so our customers can honor it. Our Terms of Service require them to.

5.2 What We Deliberately Exclude

Our data pipeline applies a default-deny rule to personal data: anything not explicitly allowed never enters our database. We do not collect or publish:

  • Owners, shareholders, beneficial owners, or founders
  • Liquidators, administrators, procurists, authorized representatives, or auditors
  • Ended or future board appointments — when a register shows that an appointment has ended, the person is removed from our database at the next synchronization
  • Birth dates or personal identification codes
  • Ownership stakes or shareholding percentages of any person
  • Values a register marks as hidden, restricted, or non-public
  • Private-life information of any kind: nothing about anyone's assets, finances, home address, or personal history

5.3 Where the Data Comes From

We collect company data from the official company registers and related official open-data services of the countries we cover:

  • Denmark: Central Business Register (CVR), Danish Business Authority
  • Estonia: e-Business Register, Centre of Registers and Information Systems (RIK)
  • Finland: Finnish Patent and Registration Office (PRH) open data
  • France: SIRENE register, INSEE
  • Latvia: Register of Enterprises open data
  • Lithuania: Register of Legal Entities, State Enterprise Centre of Registers
  • Norway: Central Coordinating Register of Legal Entities, Brønnøysund Register Centre
  • Poland: National Court Register (KRS), Ministry of Justice
  • Romania: national open-data portal (data.gov.ro) company datasets
  • Slovakia: Register of Financial Statements, Ministry of Finance
  • Sweden: Swedish Companies Registration Office (Bolagsverket) open data

We supplement these with other official public sources for company-level information (for example, tax authorities' public datasets and national address registers) and, in limited cases, licensed distributors of official register data. These sources are public by law: register publicity exists so that anyone dealing with a company can know who is authorized to represent it.

5.4 Why We Process It

We process registry data, including the limited personal data above, on the basis of legitimate interests (GDPR Article 6(1)(f)): our interest in operating a company-research service and our customers' interest in identifying, verifying, and assessing the companies they do business with. This mirrors the purpose for which the registers themselves publish the data. We have documented this assessment in a legitimate interest assessment; you may request a copy using the contact details in Section 16.

Where our customers use registry data for their own purposes, such as contacting a company, they do so as independent controllers under their own legal basis.

5.5 How We Limit Exposure

We deliberately process and expose less than the registers themselves publish:

  • Board-member and contact information is available only to authenticated customers inside the platform, through their exports, and through our API under their organization's credentials.
  • People are not searchable: the platform has no person search, and names cannot be used as search criteria.
  • Public pages, where they exist, contain company-level information only: we do not show board members or contact persons on any public or search-indexed page, and previews our customers share by link exclude people data.
  • People data is carried for display and export only; it is excluded from our search indexes.
  • We do not profile, score, or rank natural persons, and we never augment our shared database with information about people gathered from the open web. Enrichment workflows run only on a customer's instruction, and their results belong to that customer's Customer Content — they are never merged into the shared database.

5.6 How Long We Keep It

We retain board-member and contact information only while the source register lists it as current. Our database is rebuilt from the registers on a regular synchronization schedule (typically weekly): when a register shows that an appointment has ended or a contact has changed, the corresponding data is removed at the next synchronization. We keep no historical archive of people data.

5.7 Who Receives It

Registry data is available to our customers and their team members through the platform, their exports, and our API and integrations operating under their credentials. It is hosted and processed by the infrastructure subprocessors listed in Section 8. We may also disclose data where required by law.

5.8 Your Rights and How to Object

If you appear in our database, you have all the rights listed in Section 12. Two of them work in a particular way for registry data:

  • Rectification: our database mirrors the official registers. If register data about you is wrong, the effective correction is at the source register; corrections propagate to us automatically at the next synchronization. If you tell us about a correction the register has already accepted, we will refresh the affected record.
  • Objection (Article 21): you may object to our processing of your data at any time by contacting us. We review every objection individually, weighing your particular situation against the interests described in Section 5.4 and the registers' statutory purpose of publicizing who represents a company. Where your interests prevail, we will remove or restrict the data.

You may also lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or your local supervisory authority.

6. How We Use Your Information

As controller, we use account, billing, and usage data to:

  • Provide, maintain, secure, and improve the platform
  • Authenticate you and protect against fraud and abuse
  • Process transactions, manage credits, and send related billing information
  • Provide customer support and respond to your requests
  • Send service and security notices, and (where permitted) product updates
  • Monitor and analyze usage trends to improve features and performance
  • Comply with our legal obligations

7. Legal Basis for Processing

Under GDPR, we rely on the following legal bases for processing data where we are the controller:

  • Contractual necessity (Article 6(1)(b)): to create and operate your account and deliver the platform you have signed up for
  • Legitimate interests (Article 6(1)(f)): to secure the platform, prevent abuse, understand product usage, and communicate with business customers, and to operate the company database described in Section 5. We balance these interests against your rights and you may object at any time.
  • Consent (Article 6(1)(a)): for optional analytics cookies and any marketing emails. You may withdraw consent at any time.
  • Legal obligation (Article 6(1)(c)): to meet accounting, tax, and other legal requirements

8. Data Sharing and Subprocessors

We do not sell your personal data. We share data only with service providers ("subprocessors") who process it on our behalf under appropriate data processing agreements, and where required by law. Our key subprocessors include:

  • Stripe: payment processing
  • PostHog (EU-hosted): product analytics
  • Resend: transactional email delivery
  • Vercel: application hosting and delivery
  • Amazon Web Services (AWS): file and image storage
  • Cloudflare: bot protection (Turnstile) and content delivery
  • Google: authentication (Google sign-in) and AI model processing
  • OpenAI: AI model processing for in-product AI features
  • OpenFreeMap: interactive map tiles; it receives standard request metadata such as IP address and page origin, but we do not send company names or addresses to the tile service

We may also disclose data when required by law, court order, or to protect our legal rights, and in connection with a merger, acquisition, or sale of assets (with notice where required).

9. International Data Transfers

We aim to keep personal data within the European Economic Area (EEA) wherever possible. Some subprocessors operate outside the EEA. When we transfer data internationally, we rely on appropriate safeguards under GDPR Chapter V, including:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions where applicable
  • Other legally recognized transfer mechanisms

10. Data Retention

We retain personal data only as long as necessary for the purposes described in this policy:

  • Account data: for the life of your account and deleted within 90 days after account closure, unless a longer period is required by law
  • Customer Content: processed for as long as you keep it in the platform; deleted in line with your instructions and within 90 days after account closure
  • Company registry data: only while the source register lists it as current, as described in Section 5.6
  • Billing and financial records: as required by Estonian accounting and tax law (typically 7 years)
  • Analytics data: retained in aggregated or pseudonymized form
  • Support and sales communications: up to 24 months after the last contact

After the applicable period, data is securely deleted or anonymized.

11. Security

We take appropriate technical and organizational measures to protect personal data against loss, misuse, and unauthorized access, including encryption in transit, hashed credentials, access controls, and least-privilege practices. No method of transmission or storage is completely secure, but we work to protect your data and to respond promptly to any incident.

12. Your Rights

Under GDPR you have the following rights regarding personal data we hold about you as controller:

  • Access (Article 15): request a copy of your personal data
  • Rectification (Article 16): request correction of inaccurate or incomplete data
  • Erasure (Article 17): request deletion of your personal data
  • Restriction (Article 18): request that we limit how we use your data
  • Portability (Article 20): receive your data in a structured, machine-readable format
  • Objection (Article 21): object to processing based on legitimate interests
  • Withdraw consent: where processing is based on consent

To exercise any of these rights, contact us at info@netspore.ee. We will respond within one month, as required by GDPR. For data described in Section 5, the process in Section 5.8 applies. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or your local supervisory authority.

13. Customer Content and Data Subject Requests

If you are an individual whose personal data has been uploaded or processed by one of our customers through the platform, that customer is the controller of your data. Please direct access, correction, or deletion requests to them.

If you contact us directly, we will forward your request to the relevant customer and provide reasonable assistance, but the customer bears primary responsibility for responding as the controller.

14. Children

The platform is intended for business use and is not directed to individuals under 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version on this page with a revised "Last updated" date and, for material changes, provide additional notice where required. We encourage you to review this policy periodically.

16. Contact Us

If you have any questions about this Privacy Policy or how we handle personal data, contact us at:

Email: info@netspore.ee

Address: Sporenet OÜ, Erika tn 14, 10416 Tallinn, Estonia

B2B lead intelligence built on official government company registers. Primary-source records, synced weekly, with AI enrichment layered on top.

The B2B lead generation agency behind Spore. We research your market, enrich it with AI, and hand it back ready for outreach.

Product

  • source
  • workflow
  • pricing

Company

  • about
  • contact

Resources

  • faq

Legal

  • privacy
  • terms
  • cookies
© 2026 Sporenet OÜ
  • inLinkedIn