SPENDLE / LEGAL & PRIVACY

Privacy, made clear.

How personal data is handled on this website and in Spendle’s web, iOS and Android applications, including deployments operated by your organization.

LAST UPDATED / 9 October 2026

Who is responsible for your data?

Spendle is provided by M.T.D. TECHNOLOGY S.R.L. (MTD Technology), VAT number RO32665681, registered headquarters Priloage 2, Vâlcea, Romania. Contact us at contact@mtdtechnology.net.

MTD is responsible for personal data submitted to us through website enquiries and commercial communications. When your employer or another organization operates a Spendle workspace, that organization determines the purposes, access rules and retention of its expense data and is normally the data controller. MTD processes client workspace data only to the extent covered by the deployment, support and data processing agreement.

Data used by Spendle

  • Account and organization information, such as name, work email, user identifier, role and company configuration.
  • Expense reports and requests, including amounts, currencies, dates, business purposes, travel details, per diem details, status and reviewer comments.
  • Documents you choose to attach, including receipts and supporting evidence. These may contain personal or financial information.
  • Operational records, including audit events, authentication and server logs needed to operate and protect the service.
  • Messages and contact details you send to MTD when requesting a demo or support.

The exact data depends on what you submit and how your organization configures its deployment. Avoid attaching information that is unrelated to the expense or request.

Purposes and legal bases

Workspace data is used to authenticate users, administer accounts, process requests and expense reports, support approvals, maintain audit records and operate the service. Your organization determines the appropriate legal bases, which may include legal obligations and legitimate interests in expense administration. MTD uses enquiry data to respond and take steps before entering a contract, and uses necessary operational information for its legitimate interests in security and service support. Where an optional activity requires consent, the responsible controller must obtain it and allow it to be withdrawn.

Mobile permissions and website storage

Camera or photo access may be requested when you scan a company provisioning QR code or attach a receipt. Access is subject to your device’s permission controls. You can revoke permissions in system settings; features depending on them may then be unavailable. Mobile sign-in connects you to your organization’s configured identity provider and backend.

This landing website uses Vercel Web Analytics to understand traffic and improve the site. It provides aggregated statistics about page views, referrers, approximate location, browsers and devices without third-party analytics cookies. Vercel processes the analytics data; see its Web Analytics privacy information for details. We use these statistics for our legitimate interest in understanding and improving the public website. We do not send expense records, receipts or account details as custom analytics events. Hosting providers may separately process IP addresses and request logs for delivery and security. The separate Spendle web workspace uses session cookies for authentication. Any optional mobile analytics enabled by your organization must be explained in its deployment-specific privacy notice.

Access, providers and transfers

Workspace data is available to authorized users, reviewers and administrators according to their roles and permissions. Client deployments use PostgreSQL for application data, Keycloak for identity, and configured Google Cloud Storage for supporting documents. MTD may access relevant data when authorized to provide support. Provider contracts and access controls must protect personal data.

Hosting locations, subprocessors and any transfers outside the European Economic Area depend on the client’s deployment. The client’s data processing agreement and privacy notice should identify these arrangements and appropriate safeguards, such as an adequacy decision or standard contractual clauses where required. Contact your workspace administrator for the applicable details.

Retention and deletion

Your organization sets retention periods for expense records, attachments, audit events and backups according to its business and statutory accounting obligations. Account removal does not necessarily erase financial records that must legally be retained. Access to retained records should be limited to the applicable purpose.

MTD keeps enquiry and support communications for as long as needed to handle the enquiry, provide support and meet applicable obligations. Ask us or your organization about the period that applies to your record. Deletion from active systems and expiry from backups may follow different schedules, which the deployment operator should explain.

Your choices and rights

Depending on applicable law, you may request access, correction, erasure, restriction, portability or object to processing. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. We or your organization may need to verify your identity before handling a request.

For workspace records, contact your organization’s administrator or privacy contact. For data held by MTD, email contact@mtdtechnology.net. See account and data deletion for practical steps. You may complain to your local supervisory authority; in Romania this is the ANSPDCP.

Changes and contact

We may update this notice as the service changes. The date at the top identifies the latest version. Material changes to a client workspace’s processing should also be communicated by its operator. Contact contact@mtdtechnology.net with questions about this notice.