Privacy Policy
Last updated: May 8, 2026
This Privacy Policy describes how Waybound AS (organization number 937 496 184), operating the SpaceMD service ("we," "us," or "our"), collects, uses, and protects your personal data when you use our website and services. It is intended to satisfy our transparency obligations under the EU/EEA General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the revised Swiss Federal Act on Data Protection (nFADP), the U.S. state privacy laws listed below, Canadian PIPEDA and Quebec Law 25, and the Australian Privacy Act 1988.
1. Data Controller
The data controller responsible for your personal data is:
Waybound AS
Organization number: 937 496 184
0763 Oslo, Norway
Email: privacy@spacemd.ai
Quebec Law 25 — The Person in Charge of the Protection of Personal Information may be reached at privacy@spacemd.ai.
2. Data We Collect
2.1 Account Information
When you create an account we collect your email address, display name, and authentication credentials (or, if you sign in with a third-party identity provider, the profile information that provider authorizes).
2.2 Content Data
We store the notes, documents, and other content you create, edit, or upload to SpaceMD, including text, images, attachments, comments, and metadata such as timestamps and collaboration history.
2.3 Usage and Device Data
We automatically collect technical information including IP address, browser type, operating system, referring URLs, pages visited, and interaction patterns. This data is collected through our own servers, through Google Analytics (Google LLC), and through PostHog (PostHog Inc.) for product analytics and error tracking. Where required, this collection is subject to your cookie preferences (see our Cookie Policy).
2.4 Billing Data
If you purchase a paid plan, payment data is collected and processed by Stripe, Inc. on our behalf. We receive only limited information from Stripe (last four digits of the card, billing country, subscription status) and do not store full payment instrument data.
2.5 Cookies and Similar Technologies
We use cookies and similar storage technologies as described in our Cookie Policy.
3. Purpose & Legal Basis
We process your personal data for the following purposes under the GDPR Article 6 legal bases (and equivalent provisions in other regimes):
- Performance of a contract — Providing and maintaining SpaceMD, including account management, content storage, and collaboration features.
- Legitimate interests — Improving our services, analyzing aggregated usage patterns, preventing abuse and fraud, ensuring security, and communicating service-related updates. We balance these interests against your rights and you may object at any time.
- Consent — Sending marketing communications, setting non-essential cookies, and other processing where consent is required (Norwegian markedsføringsloven §15, ePrivacy, PECR, CASL).
- Legal obligation — Complying with applicable laws (including bookkeeping retention under bokføringsloven §13), regulations, court orders, and lawful requests.
4. Recipients & Sub-Processors
We do not sell your personal data and we do not "share" it for cross-context behavioural advertising as defined in the CCPA. We disclose personal data only to the categories of recipients below, each engaged under a written data processing agreement.
- Hosting and database — Supabase Inc. (United States / EU regions) for application hosting, authentication, and database services.
- Edge/CDN — Cloudflare, Inc. (global) for edge delivery and DDoS protection.
- Payment processing — Stripe, Inc. (United States) for subscriptions, invoices, and customer portal.
- Product analytics and error tracking — PostHog Inc. (United States or EU regions, depending on configuration).
- Web analytics — Google LLC (Google Analytics 4) on the public marketing website.
- AI features (first-party) — Where you use AI features powered by SpaceMD-managed providers, content may be sent to OpenAI, L.L.C., Anthropic PBC, and/or Google LLC (Gemini / Vertex AI). See our AI Transparency Policy for details.
- AI features (BYOK) — If you supply your own provider keys, content is sent to that provider under their terms; we have no contract with such providers.
- Transactional email — Our email delivery provider for account, notification, and billing emails.
- Legal authorities — When required by law, regulation, or valid legal process.
An up-to-date list of sub-processors, including their locations and processing purposes, is available at /sub-processors. We notify customers of material changes to that list.
5. Data Retention
We retain personal data only as long as is necessary for the purposes for which it was collected, plus the periods required by law:
- Account and content data — Retained while your account is active. When you delete your account, your content is deleted immediately from our primary stores; encrypted backups are purged within 30 days.
- Deletion audit metadata — A small audit record (user id, deletion timestamp, request origin) is retained for up to 24 months for fraud-prevention and incident-response purposes.
- Billing and tax records — Retained for 5 years following the end of the financial year, as required by Norwegian bokføringsloven §13.
- Security and abuse logs — Retained for up to 13 months and then deleted or anonymised.
6. Security Measures
We implement technical and organizational measures appropriate to the risk, including TLS 1.2+ encryption in transit, AES-256 encryption at rest, role-based access controls and multi-factor authentication for administrative access, logging and monitoring, regular vulnerability scanning, and an incident-response procedure. No method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.
7. Your Rights (GDPR / EEA, UK, Switzerland)
Under the GDPR, the UK GDPR, and the nFADP, you have the right to:
- Access — Obtain a copy of the personal data we hold about you.
- Rectification — Request correction of inaccurate or incomplete data.
- Erasure — Request deletion of your personal data in certain circumstances.
- Restriction — Request limitation of processing.
- Portability — Receive your data in a structured, machine-readable format.
- Objection — Object to processing based on our legitimate interests, including profiling.
- Withdraw consent — Withdraw any consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Lodge a complaint — Lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet), the UK Information Commissioner's Office (ICO), the Swiss Federal Data Protection and Information Commissioner (FDPIC), or your local supervisory authority.
To exercise these rights contact us at privacy@spacemd.ai. We respond without undue delay and in any event within one month under the GDPR (extendable by two further months for complex requests).
8. International Transfers
Your personal data may be processed outside your country of residence, including in the United States and elsewhere, by the recipients listed in section 4 and at /sub-processors. Where personal data is transferred outside the EEA, the UK, or Switzerland, we rely, in order, on:
- An adequacy decision (including the EU–US Data Privacy Framework, the UK Extension to the DPF, and the Swiss–US DPF) where the recipient is certified under that framework;
- The European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), supplemented by the UK International Data Transfer Addendum and the Swiss FDPIC's recognised version where applicable;
- Other Article 46 GDPR safeguards, including supplementary technical, organisational, and contractual measures identified in our transfer impact assessments.
9. U.S. Residents — CCPA/CPRA and Other State Privacy Laws
This section applies to residents of California, Virginia, Colorado, Connecticut, Utah, Texas, Montana, Oregon, and other U.S. states with comprehensive privacy laws.
9.1 Categories of personal information collected (CCPA §1798.110)
In the past 12 months we have collected: identifiers (name, email, account id, IP), commercial information (subscription status, billing country), internet/network activity (usage logs, cookies, device fingerprint metadata), professional information (workspace role, where provided), and the contents of communications you create in SpaceMD (account-protected user content). We do not knowingly collect government identifiers, biometric identifiers, precise geolocation, racial or ethnic origin, religious beliefs, union membership, genetic data, sex life or sexual orientation data, or health information.
9.2 Sources, purposes, and disclosures
We collect this information from you, from your use of the service, and from the third-party services listed in section 4. We use it for the purposes listed in section 3 and disclose it to the categories of recipients listed in section 4. We retain it for the periods set out in section 5.
9.3 No sale or share for cross-context behavioural advertising
We do not sell personal information for money and we do not "share" personal information for cross-context behavioural advertising as those terms are defined in the CCPA/CPRA. We honour Global Privacy Control (GPC) signals as a valid opt-out request from your browser. See Do Not Sell or Share My Personal Information.
9.4 Sensitive personal information
The only category of "sensitive personal information" under the CPRA that we process is account log-in credentials. We use these solely to authenticate you and to maintain account security; we do not use or disclose them for purposes beyond those permitted by §1798.121. You are not required to ask us to limit this use.
9.5 Your rights
- Right to know — Request the categories and specific pieces of personal information we have collected, the sources, purposes, and recipients, over the previous 12 months.
- Right to delete — Request that we delete personal information we have collected from you.
- Right to correct — Request correction of inaccurate personal information.
- Right to opt out of sale or sharing — As stated in 9.3, we do not sell or share. You may submit a request anyway, including via a GPC signal.
- Right to opt out of targeted advertising and profiling for decisions producing legal or similarly significant effects — We do not engage in either, but you may submit a request to confirm.
- Right to limit use of sensitive personal information — Available where applicable.
- Right to non-discrimination — We will not deny service, charge a different price, or provide a different level of quality because you exercised these rights.
- Right to appeal — If we deny a request, you may appeal by replying to our decision email; we will respond to appeals within 60 days as required by VCDPA, CPA, CTDPA, and other state laws.
- Authorized agent — You may use an authorized agent to submit a request, subject to verification.
To exercise these rights, email privacy@spacemd.ai or use Do Not Sell or Share My Personal Information. We respond within 45 days where required by state law (extendable by an additional 45 days for complex requests).
10. Canadian Residents — PIPEDA and Quebec Law 25
If you are in Canada, our processing is governed by PIPEDA and, for residents of Quebec, the Act respecting the protection of personal information in the private sector (as amended by Law 25). You may contact our Person in Charge of the Protection of Personal Information at privacy@spacemd.ai. We do not use personal information to render decisions based exclusively on automated processing that produce legal or similarly significant effects on you. You may file a complaint with the Office of the Privacy Commissioner of Canada or, in Quebec, the Commission d'accès à l'information.
11. Swiss Residents — nFADP
If you are in Switzerland, the revised Swiss Federal Act on Data Protection (nFADP) applies. The categories of data, purposes, recipients, retention periods, and your rights are set out in this Policy. Cross-border disclosures rely on the safeguards described in section 8. Where Swiss law requires us to designate a Swiss representative, we will do so and will name them here.
12. UK Residents — UK GDPR
If you are in the United Kingdom, the UK GDPR and Data Protection Act 2018 apply alongside this Policy. Your rights are equivalent to those described in section 7. You may lodge a complaint with the UK Information Commissioner's Office (ICO). Where required, we will designate a UK Article 27 representative and name them here.
13. Australian Residents — Privacy Act 1988
If you are in Australia, our handling of personal information is governed by the Australian Privacy Principles (APPs). The kinds of personal information we collect, how we collect and hold it, the purposes for which we use and disclose it, and how you may access or correct your information are described in this Policy. We are likely to disclose personal information overseas to recipients in the United States and the European Union (see section 4). You may make a complaint to us at privacy@spacemd.ai; if you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC).
14. Children's Privacy
SpaceMD is not directed to children. We do not knowingly collect personal information from children under 16 in the EEA / UK / Norway, or under 13 in the United States (consistent with COPPA). If you believe a child has provided us with personal data, please contact us and we will delete it.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website with a revised "Last updated" date and, where appropriate, by email. Your continued use of SpaceMD after such changes constitutes acceptance of the updated policy.
16. Contact Us
For questions about this Privacy Policy or our data practices, contact us at:
Waybound AS
Organization number: 937 496 184
0763 Oslo, Norway
Email: privacy@spacemd.ai
You also have the right to lodge a complaint with your local supervisory authority. In Norway this is the Norwegian Data Protection Authority (Datatilsynet, datatilsynet.no).
