What standards we meet, what we're working on, what we don't claim
Spun is built with privacy and security by design. We use encryption in transit, controlled access, audit logging, configurable data retention, and customer-controlled AI features. We do not overclaim - every status below is current.
Status by framework (SOC 2, GDPR, ISO 27001, and more)
The detailed standard-by-standard breakdown now lives on the Security page, alongside the rest of the security content.
Data retention
Retention limits per plan
Older messages automatically prune at the plan limit. You can tighten retention further per-chat in Safety & Privacy → Message Storage Limit, or wipe everything on demand.
| Plan | Message history | Media storage |
|---|---|---|
| Free Trial7-day trial | 30 days | 5 GB |
| Pro | 90 days | 10 GB |
| Max 10x | 1 year | 100 GB |
| Max 40x | Unlimited | 500 GB |
On account deletion, all personal data is removed or anonymized within 30 days, except where retention is required by law (financial records, fraud prevention).
Where your data lives
Regional hosting
Spun runs two data cells: eu-1 in Nuremberg, Germany - the primary cell, where every new organisation is created - and us-1 in Manassas, Virginia. Each organisation is homed on exactly one of them. The marketing site and media files are served globally from Cloudflare's edge network.
Hetzner Nuremberg
EU (Germany) - application servers + PostgreSQL
The primary cell: control plane, application servers, database and Redis. New organisations are created here - no country is mapped to another cell.
netcup Manassas
US (Virginia) - regional cell
A second cell with its own application servers and database. Two organisations are homed here today; every other organisation is in Germany.
Cloudflare Pages
Global edge - marketing site & static assets
spun.com and 20+ regional domains served from Cloudflare's global edge network. Visitors get the nearest PoP automatically.
Cloudflare R2
Global - images, video, file attachments
All media (images, video, audio, documents) stored in R2. Never served from a public bucket address - access is gated by per-object signed URLs.
Israel region
Israel
Under evaluation for Israeli market expansion. Currently Israeli customers are served from Hetzner Nuremberg (EU).
India region
India
Under evaluation for Indian-language voice features and data residency.
Where we sell, and why
International launch roadmap
We launch in markets where WhatsApp is core business infrastructure first, and expand to higher-compliance enterprise markets as our certification matures.
- 1
Israel & Latin America (current)
Israel (Hebrew + English UI, GDPR-aligned). Mexico, Colombia, Argentina, Chile, Peru, UAE - WhatsApp is universal business infrastructure, sales cycles are short. SOC 2 readiness sufficient.
- 2
US SMBs (current, expanding)
Home services, real estate, e-commerce support, travel, education, wellness. SOC 2 Type I and a complete DPA package make Spun viable for most US SMB and mid-market buyers.
- 3
EU & UK enterprise (after SOC 2 Type I)
Enter once SOC 2 Type I is signed and ISO 27001 work is underway. Requires polished DPA + SCCs, EU hosting confirmation, and full deletion/export tooling - all of which are in place but benefit from third-party attestation before larger enterprise sales.
Documents available
Request from [email protected]
Data Processing Agreement (DPA)
GDPR-aligned draft, available on request - currently in legal review.
Sub-processor notification list
Get email updates when we add or change a sub-processor.
Security overview
Architecture, encryption, access control, vulnerability management.
AI data processing policy
Which AI vendors, what data they see, no-training commitment.
Incident response policy
Detection, containment, customer notification timelines.
Acceptable Use Policy
What is permitted on Spun and the basis for enforcement.
Have a security questionnaire?
We respond to standard security questionnaires (SIG, CAIQ, custom enterprise) within 5 business days. Email [email protected] with your timeline.