Privacy Policy
1. Who is responsible
The controller for this website and, where stated below, for the sparevoice service is:
Foth Group GmbHSeehofstraße 137, 14167 Berlin, Germany
Email: kontakt@fothgroup.de
For all privacy matters, including data subject requests, write to the address above with the subject line "Privacy".
2. Two things this policy covers
The website (sparevoice.com), which anyone can visit, and the service, the sparevoice application used by our customers to manage and answer messages on connected platforms. Section 3 covers the website, sections 4–9 the service.
3. Website
3.1 Hosting and server logs
The website is hosted by Hetzner Online GmbH, Gunzenhausen, Germany, on servers located in Germany. When you visit, the web server records the requested URL, date and time, transferred data volume, HTTP status, referrer, browser type and your IP address. These logs are used to operate the site securely and to diagnose faults (Art. 6 (1) (f) GDPR) and are deleted after 14 days.
3.2 No cookies, no tracking
This website sets no cookies and uses no analytics or advertising services. Fonts are served from our own server; no requests are made to third parties when you load the page.
3.3 Contact by email
If you write to us, we process your email address and the content of your message to answer you (Art. 6 (1) (b) or (f) GDPR). Messages are kept as long as needed to handle your request and any follow-up, then deleted, subject to statutory retention duties.
4. The service: roles
sparevoice is used by customers (creators, businesses, agencies) to receive and answer messages from end users (the people who write to them on Instagram, WhatsApp, Messenger, Telegram and other connected channels).
- For customer account data (login, billing, settings, usage, security) Foth Group GmbH is the controller.
- For end-user conversation data processed on behalf of a customer, the customer is the controller and Foth Group GmbH is the processor under a Data Processing Agreement (Art. 28 GDPR). End users can address requests to the customer they wrote to or to us; we forward and assist where required.
5. What data the service processes
| Category | Examples | Source |
|---|---|---|
| Customer account | Name, email, password hash, company details, billing data, plan | Provided by the customer |
| Platform connection | Access tokens, connected account IDs, permission scopes, webhook subscriptions | Issued by the platform after the customer's authorisation |
| Conversation data | Message and comment text, attachments the platform provides, sender username or ID, timestamps, read/reply state | Received from the platform APIs |
| Voice & rules | Tone description, boundaries, active hours, selectivity, per-contact settings | Configured by the customer |
| AI drafts and sends | Generated reply text, edits, approval, send time, disclosure marker | Generated by the service |
| Derived data | Conversation tags, running summaries, detected language | Generated by the service |
| Usage & security logs | Logins, API calls, error events, IP address | Generated by the service |
6. Data received from Meta platforms
When a customer connects an Instagram professional account, a Facebook Page or a WhatsApp Business account, sparevoice receives data from Meta Platforms through the official Instagram API, Messenger Platform and WhatsApp Business Platform, using Meta Business Login (OAuth). We never ask for or store platform passwords.
- What we receive: the connected account's ID and name, incoming and outgoing messages and comments for that account, sender IDs and public usernames, timestamps, and media the platform makes available for a message.
- Why: solely to display these conversations to the customer, draft replies, and send replies on the customer's instruction or according to the rules the customer has set.
- What we do not do: we do not sell platform data, do not use it for advertising, do not build profiles of end users beyond the conversation itself, and do not use it to train AI models.
- Retention: platform data is kept while the connection is active and for up to 30 days after the customer disconnects or deletes the account, then erased. Deletion requests received through Meta's deletion callback are honoured within 30 days; see Data deletion.
- Revoking access: customers can remove sparevoice at any time under Instagram or Facebook Settings → Apps and Websites, or in WhatsApp Business Manager. Removal invalidates our token and triggers deletion.
Our use of Meta platform data complies with the Meta Platform Terms and Developer Policies. Meta Platforms Ireland Ltd. is an independent controller for the processing that takes place on its own platforms; see Meta's privacy policy for details.
7. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the service to the customer (inbox, drafts, sending, alerts) | Art. 6 (1) (b) GDPR — contract; for end-user data: processing on the customer's documented instructions (Art. 28) |
| Billing and accounting | Art. 6 (1) (b) and (c) GDPR |
| Security, abuse prevention, fault diagnosis | Art. 6 (1) (f) GDPR — legitimate interest in a secure, reliable service |
| Service emails (account, invoices, incident notices) | Art. 6 (1) (b) GDPR |
| AI disclosure to end users at first contact | Art. 6 (1) (c) GDPR — legal obligation under Art. 50 EU AI Act |
8. Sub-processors and recipients
We use the following providers to run the service. Each is bound by a data processing agreement; transfers outside the EU rely on the EU Standard Contractual Clauses with a transfer impact assessment.
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting, storage, backups | Germany |
| Anthropic PBC | Generating reply drafts, summaries and classifications | USA (SCCs) |
| OpenAI, L.L.C. | Generating reply drafts (secondary model) | USA (SCCs) |
| Stripe Payments Europe, Ltd. | Payment processing (customers only) | Ireland / USA (SCCs) |
| Meta Platforms Ireland Ltd. | Platform APIs for Instagram, Messenger, WhatsApp — independent controller | Ireland |
Conversation text sent to AI providers is used only to generate the requested output. Under our agreements with these providers, that data is not used to train their models and is not retained beyond the request except for short-term abuse monitoring. We will update this list before adding a sub-processor; customers are notified under the DPA.
9. Retention
- Conversation data, drafts, tags and summaries: while the connected account is active, plus 30 days after disconnection or account deletion.
- Customer account data: while the account exists, plus 30 days.
- Invoices and accounting records: 10 years (§ 147 AO, § 257 HGB).
- Security and access logs: 30 days.
10. Security
Data is encrypted in transit (TLS 1.2+) and at rest. Platform access tokens are stored encrypted and separated per customer. Access to production systems is limited to named administrators with two-factor authentication and is logged. Backups are encrypted and stored in Germany. Details are set out in the technical and organisational measures annexed to the DPA.
11. Automated decisions
sparevoice generates reply drafts automatically. Whether and when a draft is sent is determined by the customer — either by explicit approval or by rules the customer has configured. The service makes no automated decisions that produce legal or similarly significant effects on end users within the meaning of Art. 22 GDPR.
12. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and to object to processing based on legitimate interests (Art. 15–21 GDPR). Where processing relies on consent, you may withdraw it at any time with effect for the future. You also have the right to lodge a complaint with a supervisory authority; the authority responsible for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin.
If you are an end user who wrote to a sparevoice customer, you may also direct your request to that customer as the controller. We assist them in answering it.
13. Changes
We update this policy when the service or the law changes. The current version is always available at sparevoice.com/privacy; material changes affecting customers are announced by email in advance.