Monitored company
Spendesk
clause.watch tracks 2 legal documents published by Spendesk (spendesk.com), re-reading each one every six hours. Below is what each document covers, in plain English.
Privacy Policy
Privacy Policy Overview
Provider: Spendesk SAS, France
Last updated: March 2025 (Version 0.5)
Regulatory framework: Primarily the EU General Data Protection Regulation (GDPR)
1. Data Collection and Use
Spendesk may act as either:
- Data controller: Spendesk decides why and how data is used.
- Joint controller: Spendesk and Spendesk Financial Services jointly process data for payment services in the EEA.
- Data processor: Spendesk processes business users’ data on behalf of the employer/customer, which generally remains the controller.
Data collected may include
- Identity and contact details: Name, email, telephone number, company, job title
- Account and security data: User ID, login information, device ID, IP address, system logs
- Expense and financial information: Financial transactions and expense information recorded through the Platform
- Recruitment data: CV and candidate contact details
- Community data: Slack ID and professional information
- Browsing and tracking data: Cookie IDs, browsing activity, session information and advertising identifiers
- Call recordings: Voice and image from recorded calls
Main purposes
Spendesk uses data to:
- Operate user accounts, the Platform and payment services
- Manage sales, contracts, marketing and community activities
- Monitor and supervise accounts
- Detect fraud, illegal activity and security incidents
- Conduct research and development
- Improve services and train or monitor staff
- Record calls for service improvement, training and staff performance
- Meet legal, regulatory and financial obligations
The stated legal bases include consent, legitimate interests, contract performance, pre-contractual steps and legal obligations. Some processing—particularly fraud prevention, account supervision and marketing—may occur based on Spendesk’s legitimate interests rather than consent.
Retention periods vary. Examples include up to three years after last marketing contact, five years after a business relationship ends, six months for recorded calls, and 365 days for login logs. Cookie retention is governed separately by the Cookies Policy.
2. User Rights
Subject to GDPR exceptions, users may request:
- Access to their data
- Correction
- Erasure
- Restriction of processing
- Objection to processing
- Data portability
- Instructions concerning data after death
Requests can be sent to privacy@spendesk.com or by post to Spendesk’s Data Protection Officer. Spendesk says it will respond within 30 days, potentially extendable. It may request identity verification.
For Platform data, the employer/customer is often the formal controller. Users may therefore need to contact both their employer and Spendesk. Rights may be refused or limited where processing is required for a contract or legal obligation. AML/CFT access requests must be made indirectly through France’s CNIL.
Users may complain to CNIL, the French data protection authority.
3. Third-Party Sharing
Data may be shared with:
- Subprocessors providing hosting, support or other services. They may access only data necessary for their tasks and are contractually restricted from independent use. The current list is published on Spendesk’s subprocessors page.
- Independent providers, including Adyen, Wise, Sutton Bank, Dwolla, Google Pay and Apple Pay, depending on location and services used. These providers have their own privacy policies and may independently determine how data is processed.
- Spendesk Financial Services, as joint controller for EEA payment services.
- Authorities, regulators, government bodies and financial institutions where legally required.
4. AI/ML Training
The policy does not expressly state whether user data is used to train artificial intelligence or machine-learning models. It mentions “research and development,” service improvement, and staff training, but these provisions do not clearly authorize or prohibit AI training. Users should seek clarification from Spendesk, particularly regarding expense, transaction, call-recording or browsing data.
5. Key User Responsibilities and Restrictions
By using the Website or Platform, users acknowledge and accept the described processing. Users should:
- Review the separate Cookies Policy
- Understand that employers may control Platform data and may import user information
- Review third-party providers’ policies when using payment or wallet services
- Keep account information secure and accurate
- Recognize that marketing/community data may be used for prospecting and advertising targeting
The policy does not provide detailed user conduct rules; those are likely in the General Terms and Platform policies.
6. Liability and Disputes
This Privacy Policy contains no detailed liability cap, warranty disclaimer, indemnity, governing-law clause or dispute-resolution procedure. It describes security commitments but does not guarantee that security will never be breached. Contractual liability and dispute provisions should be reviewed in Spendesk’s General Terms and any employer/customer agreement.
7. Policy Changes
Spendesk may update the policy due to legal or processing changes. The version posted on the Website on the date of use applies. The policy does not promise advance notice, email notification or specific user consent for changes, so users should periodically check the Website.
Terms of Service
Change history
2026-09-04 · Privacy Policy
2026-09-04 · Privacy Policy
Summary
Material Provided
The diff contains only the statement:
> “Added approximately 187 words to the document”
No actual added, deleted, or replaced contract language was provided.
Legal and Commercial Impact
Because the substantive text is missing, it is not possible to determine:
- What contractual provisions changed;
- Whether obligations, rights, liability, fees, confidentiality, or termination rights were modified;
- Whether new risks were introduced for the customer; or
- Whether the changes affect ownership, access, retention, disclosure, or use of customer data.
AI Training and Data Use
The provided diff does not include any language concerning:
- Training, fine-tuning, or improving AI or machine-learning models;
- Use of customer data, prompts, outputs, content, or personal information for model development;
- Whether data is used for general or service-specific models;
- Opt-out or consent requirements;
- Human review or provider access to customer data;
- Data anonymization, aggregation, or de-identification;
- Retention and deletion of data used for training; or
- Restrictions on using confidential, personal, or regulated information.
Accordingly, no conclusion can be reached about whether the contract permits or restricts AI training using customer data.
Information Needed
Please provide the actual 187 words that were added, together with any surrounding text and the relevant deleted or replaced language. The changes can then be reviewed for:
1. Scope of permitted data use
2. AI training and model-improvement rights
3. Confidentiality and privacy implications
4. Ownership and intellectual-property rights
5. Customer consent and opt-out rights
6. Data retention, deletion, and security
7. Allocation of liability and regulatory risk
2026-09-02 · Privacy Policy
Summary of Important Changes
1. New or clearer privacy-policy structure
- The document is now titled “Privacy policy” and dated “Last Updated: March 2025.”
- A table of contents has been added, covering:
- Overview and introduction
- Data Protection Officer
- Processing descriptions
- Data recipients
- Security measures
- Hosting and international transfers
- Data-subject rights
- The policy now more clearly states that capitalised terms are defined in the General Terms and Conditions or, failing that, under the GDPR.
Risk/impact: The changes improve organisation and transparency, but the new “last updated” date may indicate that the policy is intended to replace the previous version in full. Customers should check whether the underlying processing tables and third-party disclosures have also been updated elsewhere.
2. Data Protection Officer
- The wording changes from Spendesk “may have appointed” a DPO to stating that Spendesk “has appointed” one.
- A direct DPO contact is provided:
- Email: privacy@spendesk.com
- Postal address: Spendesk SAS, Data Protection Officer, 51 rue de Londres, 75008 Paris, France
Risk/impact: This is generally favourable for data subjects and gives a clearer escalation route. It also represents a stronger formal commitment regarding Spendesk’s GDPR governance.
3. Processing roles and purposes
- The policy now expressly says Spendesk may act as either a data controller or data processor, depending on the processing.
- Processing purposes and legal bases remain broadly based on legitimate interests, consent, and contractual or pre-contractual necessity.
- Several wording changes clarify categories of individuals and information, including recruitment, marketing, community, customer contacts, fraud monitoring, account supervision, and security logs.
Risk/impact: The controller/processor distinction is important because it affects who determines the purposes of processing and who is responsible for responding to rights requests. Customers should ensure their contracts or data-processing agreements identify these roles consistently.
4. New or expanded recipients and international transfers
The policy adds or more clearly identifies third parties, including:
- Adyen and Wise for UK international wire transfers
- Sutton Bank and Dwolla in the United States for certain UK international wire transfers
- Google Pay and Apple Pay as digital-wallet providers
It directs users to those providers’ own privacy policies.
Risk/impact: Personal data may be disclosed to additional payment and financial-service providers, including providers in the United States. This creates potential international-transfer, government-access, and third-party privacy risks. The policy excerpt does not specify the transfer mechanism or safeguards, such as Standard Contractual Clauses or a transfer-impact assessment.
5. Joint controllership with Spendesk Financial Services
- The policy more clearly states that Spendesk SAS and Spendesk Financial Services SAS process certain customer data as joint data controllers to provide payment services and meet legal and contractual obligations.
- It refers users to a separate Information Notice for further details.
Risk/impact: Customers may have more than one responsible Spendesk entity, which can complicate accountability and rights requests. The separate Information Notice should be reviewed.
6. Government and authority disclosures
- The wording expressly permits disclosure of all or part of personal data to public authorities, government bodies, and other financial institutions where legally required.
Risk/impact: This is a broad but common compliance disclosure. It confirms that financial, fraud-prevention, or regulatory obligations may override confidentiality expectations.
7. Data-subject rights
- Users may contact their employer, where the employer is the controller, or contact Spendesk directly.
- Spendesk may inform the employer of the request and action taken.
- Requests are to be answered within 30 days, potentially renewable, and Spendesk may request identity documentation for verification.
- Some requests may be refused where legally permitted.
- The policy adds a link to the CNIL website.
Risk/impact: Employer notification may reduce confidentiality for employee/user requests. Identity-verification requirements should be limited to what is necessary.
8. AI-model training
- No express change concerning the use of customer data to train, fine-tune, evaluate, or improve AI models is visible in this diff.
- The diff does not add an AI-training purpose, an AI provider, model-development permission, opt-out right, or retention rule specifically addressing AI.
Risk/impact: This diff does not create a stated AI-training authorization. However, the absence of an express restriction means customers should review the complete policy, product terms, and any AI-specific terms to confirm whether data may be used for model development.
2026-08-31 · Privacy Policy
Summary
The diff states only that approximately 187 words were added. It does not provide the actual wording of those additions, nor identify any deleted or replaced language.
AI Training and Data-Use Changes
- It is not possible to determine whether the customer’s data may now be used to train, fine-tune, evaluate, or improve AI models.
- The diff does not reveal whether any new provisions address:
- Use of customer content or personal data for model training;
- Whether training is performed by the provider or third-party vendors;
- Whether data is used in aggregated, de-identified, or identifiable form;
- Customer opt-out or consent rights;
- Retention or deletion of data used for training;
- Ownership of inputs, outputs, or model improvements;
- Confidentiality, security, or cross-customer disclosure risks.
Other Legal Risks
The available information is also insufficient to assess whether the added language changes:
- The provider’s rights to use or commercialize customer data;
- Confidentiality obligations;
- Privacy-law compliance responsibilities;
- Data retention and deletion requirements;
- Liability, indemnification, or limitations of liability;
- Subcontractor or third-party access;
- Customer audit, notice, or termination rights.
Conclusion
No substantive legal change can be reliably analyzed from the provided diff. The actual 187-word addition—and any surrounding language affected by it—is required to determine whether the customer’s data may be used for AI training or whether other material risks have been introduced.
2026-08-26 · Privacy Policy
Key Changes and Risks
1. New policy format and scope clarification
- The policy is now identified as “Privacy policy — Last Updated: March 2025.”
- A clearer table of contents has been added, covering:
- Data Protection Officer
- Processing activities
- Recipients
- Security
- Hosting and transfers
- Individual rights
- Definitions are tied more explicitly to the General Terms and Conditions and, where necessary, the GDPR.
Risk/impact: Primarily structural, but the revised organisation may make additional processing and transfer disclosures easier to locate.
2. Data Protection Officer formally identified
- The wording changes from Spendesk “may have appointed” a DPO to stating that Spendesk “has appointed” one.
- The DPO can be contacted at privacy@spendesk.com.
Risk/impact: This is generally positive for transparency and accountability. It creates a clear privacy contact, although the policy should be checked for consistency with Spendesk’s actual DPO appointment and responsibilities.
3. More detailed processing and retention information
- The policy continues to list categories of individuals, data collected, purposes, legal bases and retention periods.
- Minor wording and formatting changes affect references to legitimate interests, consent, recruitment, marketing, community participation, sales management, recordings, account supervision and security/fraud monitoring.
Risk/impact: The revised tables should be reviewed carefully to confirm that every purpose and retention period is complete and accurate. In particular, processing based on legitimate interest and the monitoring of transactions, login data and accounts may permit relatively broad operational and fraud-prevention use.
4. New or expanded payment-service recipients
The policy now specifically identifies providers and regions, including:
- Adyen and Wise for UK customers/users using international wire transfers;
- Sutton Bank and Dwolla for US customers/users;
- Google Pay and Apple Pay as digital-wallet providers.
Users are directed to those providers’ separate privacy policies.
Risk/impact: This expands transparency about third-party disclosures but also confirms potential sharing with independent controllers and, for some users, transfers or processing involving the United States. The policy should be checked for the applicable GDPR transfer mechanism and safeguards, such as adequacy decisions or standard contractual clauses.
5. Spendesk Financial Services as joint controller
- The policy now explains that Spendesk SAS and Spendesk Financial Services SAS process certain Customer Personal Data together as joint Data Controllers.
- The stated purposes are providing payment services and meeting legal and contractual obligations.
- Users are directed to a separate information notice.
Risk/impact: Customers may have more than one responsible entity for the same processing. The separate notice should clearly explain each entity’s responsibilities, rights-contact process, data categories and legal bases.
6. Disclosures to authorities broadened or clarified
- The policy expressly states that Personal Data may be provided to public authorities, government bodies and other financial institutions where legally required.
Risk/impact: This is broadly worded, though limited by the legal-compliance context. Customers should verify whether the policy explains the relevant regulatory, anti-money-laundering and fraud-reporting circumstances.
7. Exercise of rights revised
- A postal address and email address for the DPO are added.
- The response period is stated as 30 days, possibly renewable.
- Spendesk may request an identity document for verification.
- Users may contact both their employer (where the employer is controller) and Spendesk; Spendesk will inform the employer of the request and action taken.
- A link to CNIL guidance is added.
Risk/impact: The employer-notification process may reduce confidentiality for workplace users. Identity-document requests should be proportionate and limited to verification.
8. AI-model training
- No express provision addressing AI, machine learning, generative AI, model training, model improvement, or use of Customer Data to train AI models appears in this diff.
- The changes therefore do not expressly authorise or prohibit AI training.
Risk/impact: The absence of an AI-training clause leaves uncertainty. The policy should be reviewed alongside the Terms, product documentation and vendor terms to determine whether Customer Data, prompts, transactions, recordings or support content may be used for model training or service improvement.
2026-08-25 · Privacy Policy
Summary
The provided diff does not include the actual contractual language. It only states:
> “Added approximately 187 words to the document”
Without the added text, it is not possible to identify:
- Changes to customer data rights or permitted uses
- Whether customer data may be used to train, fine-tune, or improve AI models
- Any new data-retention, confidentiality, security, or deletion obligations
- Changes to ownership of inputs, outputs, or model-generated materials
- New disclosures, consent requirements, or opt-out rights
- Liability, indemnity, or regulatory risks associated with AI training
AI-Training Review
No conclusion can be drawn about whether the agreement now permits the provider to:
- Use customer content or personal data to train general-purpose AI models
- Use data for model evaluation, testing, analytics, or service improvement
- Share data with affiliates, contractors, or model providers
- Retain data after termination for training or other purposes
- Exclude confidential information or personal data from training
- Offer the customer an opt-out or require affirmative consent
Needed Information
Please provide the actual 187 words added, together with any surrounding or replaced language. The relevant provisions should be reviewed in context because a new sentence may be limited or expanded by definitions, data-use provisions, confidentiality terms, or exceptions elsewhere in the agreement.
2026-08-18 · Privacy Policy
Summary of Important Changes
1. Policy structure and scope
- The policy is now titled “Privacy policy” and dated Last Updated: March 2025.
- A formal table of contents has been added, covering:
- Spendesk’s Data Protection Officer
- Processing activities
- Data recipients
- Security
- Hosting and international transfers
- Individual rights
- References to the GDPR have been clarified, including that undefined capitalised terms take their meaning from the General Terms and Conditions or the GDPR.
2. Data Protection Officer
- Spendesk’s wording has changed from “may have appointed” a DPO to “has appointed” a DPO.
- A DPO contact route is expressly provided:
- Email: privacy@spendesk.com
- Postal address: Spendesk SAS – Data Protection Officer, 51 rue de Londres, 75008 Paris, France
This is a positive clarification for customers and may indicate a more formalised compliance structure.
3. Data-controller roles
- The policy now expressly states that Spendesk may act as either a data controller or data processor, depending on the processing.
- The policy adds a detailed description of Spendesk SAS and Spendesk Financial Services SAS acting as joint controllers for certain Customer Personal Data, particularly to:
- Provide payment services; and
- Meet legal and contractual obligations.
- Customers are directed to a separate information notice for further details.
Risk/impact: Customers may need to determine which entity is responsible for a particular processing activity and which entity should receive rights requests. The joint-controller arrangement may also involve additional data sharing within the Spendesk group.
4. New or clarified recipients and international transfers
The policy now identifies specific independent service providers, including:
- UK customers/users: Adyen and Wise for international wire transfers.
- US customers/users: Sutton Bank and Dwolla.
- Digital wallets: Google Pay and Apple Pay.
Users are directed to the providers’ own privacy policies.
Risk/impact: This makes transfers and disclosures to payment and wallet providers more explicit. The inclusion of US-based providers may involve international transfers outside the EEA and reliance on transfer safeguards or the providers’ own legal mechanisms. Customers should review the linked notices for retention, security, onward-transfer, and local-law provisions.
5. Government and institutional disclosures
- The policy clarifies that Spendesk may disclose some or all Personal Data to public authorities, government bodies, or other financial institutions where legally required.
This is broadly standard for financial-services providers but expands the description of potential recipients.
6. Individual rights process
- The policy now explains that users may contact their employer, as the relevant data controller, and may also contact Spendesk directly.
- Spendesk will inform the employer of the request and the action taken.
- The response period is stated as 30 days, possibly renewable, and Spendesk may request an identity document for verification.
- The policy expressly notes that some requests may not be answered where legally permitted.
- The right to complain to the French supervisory authority, CNIL, and a link to CNIL’s website have been added.
7. AI-model training
- No express provision has been added or removed concerning the use of Customer Personal Data to train, fine-tune, evaluate, or improve AI models.
- The revised text does not identify AI providers, model-training purposes, opt-out rights, anonymisation measures, or retention rules specifically for AI training.
- Accordingly, this diff does not establish a new contractual permission to use Customer Data for AI training. However, the absence of an explicit restriction means customers should seek confirmation elsewhere in the contract, product terms, or vendor documentation.
2025-03-01 · Privacy Policy
The publisher records this document as revised on this date (“Last Updated: March 2025”).
Between 2024-01-27 and 2024-09-05 · Privacy Policy
Between 2022-12-08 and 2024-01-27 · Privacy Policy
Between 2021-10-25 and 2022-12-08 · Privacy Policy
Between 2021-01-23 and 2021-10-25 · Privacy Policy