Compliance

What standards we meet, what we're working on, what we don't claim

Spun is built with privacy and security by design. We use encryption in transit, controlled access, audit logging, configurable data retention, and customer-controlled AI features. We do not overclaim โ€” every status below is current.

Status by framework (SOC 2, GDPR, ISO 27001, and more)

The detailed standard-by-standard breakdown now lives on the Security page, alongside the rest of the security content.

See framework status

Data retention

Retention limits per plan

Older messages automatically prune at the plan limit. You can tighten retention further per-chat in Safety & Privacy โ†’ Message Storage Limit, or wipe everything on demand.

PlanMessage historyMedia storage
Free Trial7-day trial30 days5 GB
Basic90 days10 GB
Pro1 year75 GB
PowerUnlimited500 GB

On account deletion, all personal data is removed or anonymized within 30 days, except where retention is required by law (financial records, fraud prevention).

Where your data lives

Regional hosting

Spun runs two data cells: eu-1 in Nuremberg, Germany โ€” the primary cell, where every new organisation is created โ€” and us-1 in Manassas, Virginia. Each organisation is homed on exactly one of them. The marketing site and media files are served globally from Cloudflare's edge network.

๐Ÿ‡ฉ๐Ÿ‡ช

Hetzner Nuremberg

EU (Germany) โ€” application servers + PostgreSQL

Available

The primary cell: control plane, application servers, database and Redis. New organisations are created here โ€” no country is mapped to another cell.

๐Ÿ‡บ๐Ÿ‡ธ

netcup Manassas

US (Virginia) โ€” regional cell

Available

A second cell with its own application servers and database. Two organisations are homed here today; every other organisation is in Germany.

๐ŸŒ

Cloudflare Pages

Global edge โ€” marketing site & static assets

Available

spun.com and 20+ regional domains served from Cloudflare's global edge network. Visitors get the nearest PoP automatically.

โ˜๏ธ

Cloudflare R2

Global โ€” images, video, file attachments

Available

All media (images, video, audio, documents) stored in R2. Never served from a public bucket address โ€” access is gated by per-object signed URLs.

๐Ÿ‡ฎ๐Ÿ‡ฑ

Israel region

Israel

Roadmap

Under evaluation for Israeli market expansion. Currently Israeli customers are served from Hetzner Nuremberg (EU).

๐Ÿ‡ฎ๐Ÿ‡ณ

India region

India

Roadmap

Under evaluation for Indian-language voice features and data residency.

Where we sell, and why

International launch roadmap

We launch in markets where WhatsApp is core business infrastructure first, and expand to higher-compliance enterprise markets as our certification matures.

  1. 1

    Israel & Latin America (current)

    Israel (Hebrew + English UI, GDPR-aligned). Mexico, Colombia, Argentina, Chile, Peru, UAE โ€” WhatsApp is universal business infrastructure, sales cycles are short. SOC 2 readiness sufficient.

  2. 2

    US SMBs (current, expanding)

    Home services, real estate, e-commerce support, travel, education, wellness. SOC 2 Type I and a complete DPA package make Spun viable for most US SMB and mid-market buyers.

  3. 3

    EU & UK enterprise (after SOC 2 Type I)

    Enter once SOC 2 Type I is signed and ISO 27001 work is underway. Requires polished DPA + SCCs, EU hosting confirmation, and full deletion/export tooling โ€” all of which are in place but benefit from third-party attestation before larger enterprise sales.

Documents available

Request from [email protected]

Data Processing Agreement (DPA)

GDPR-aligned draft, available on request โ€” currently in legal review.

Sub-processor notification list

Get email updates when we add or change a sub-processor.

Security overview

Architecture, encryption, access control, vulnerability management.

AI data processing policy

Which AI vendors, what data they see, no-training commitment.

Incident response policy

Detection, containment, customer notification timelines.

Acceptable Use Policy

What is permitted on Spun and the basis for enforcement.

Have a security questionnaire?

We respond to standard security questionnaires (SIG, CAIQ, custom enterprise) within 5 business days. Email [email protected] with your timeline.