Spanwork operates this website and determines how the information described here is handled. Spanwork offers standard sales forms and a separate protected inquiry. They do not provide the same level of protection.

Two inquiry paths

Standard sales forms

The forms on the homepage and standard contact page collect the name, email address, company, role, engagement interest, timing, and decision context you provide. The shorter campaign response form collects your name, work email, company, timing, and decision context, and submits a fixed Product and Technology Review interest value. Your browser sends these fields over HTTPS. The Spanwork Worker processes them in readable form and delivers them as readable text to a controlled mailbox. These forms are not end to end encrypted.

The standard forms can also include referral information: the landing page, referring site, campaign source, medium, campaign name, content label, and call to action used. Campaign response links use only the fixed outbound email source and one approved, non-personal campaign code. The response page rejects missing, duplicated, additional, or unapproved query parameters and does not reuse stored attribution. The contact endpoint separately requires the fixed response-form attribution before delivering the inquiry. On the other standard pages, Spanwork site code keeps the first non-empty landing, referring, and campaign values in browser session storage so they survive navigation between pages in the same tab. Call to action context is placed directly in the open form and is not kept in session storage. These values are sent only if you submit a standard form.

When you use selected Review, sample, contact, or standard form controls, Spanwork sends a limited first-party interaction event to its own website endpoint. Each event contains only an approved event name, the page path, and an internal source label. The event payload does not contain form values, your name, email address, a visitor identifier, or a cross-site identifier. Spanwork does not use these events to build an individual visitor profile.

For abuse prevention, the standard contact endpoint derives separate opaque rate-limit keys from the connecting IP address and a lowercased version of the submitted email address using a server-held HMAC secret. It does not place either raw identifier in the rate-limit keys. An accepted-submission log records an inquiry ID, the selected engagement and timing, and whether referral fields were present. It does not record a rate-limit key, IP address, referral value, name, company, message text, or email address.

Protected inquiry

The separate protected inquiry collects your reply method, email address or Signal contact, optional name or alias, optional organization, optional note, and a submission timestamp. Those visitor fields are encrypted in your browser before upload.

The protected page does not load the standard attribution code, use browser session storage, include referral or campaign fields in the inquiry, or send funnel interaction events. Cloudflare still receives ordinary connection data, including an IP address and request timing, while serving the page and delivering the encrypted package.

For abuse prevention, the protected endpoint derives opaque, separately namespaced rate-limit keys from the connecting IP address using a server-held secret. The application's protected-inquiry logs can contain a fieldless honeypot event, an accepted event with an opaque inquiry ID, public encryption key ID, and bounded provider message ID, or a failed-delivery event with an allowlisted provider error code or fixed fallback. The application does not place readable visitor fields, the raw IP address, rate-limit keys, or exception messages in those logs. Cloudflare may attach its own platform metadata to stored log records and otherwise receives ordinary connection data as described below.

How protected inquiry encryption works

This protection applies only to the form at spanwork.net/confidential. It does not apply to the homepage form, standard contact form, campaign response form, direct email, or later email correspondence.

Encryption happens in your browser before the form is sent. For each submission, the browser creates a fresh AES-256-GCM key and uses it to encrypt the complete form payload. It then wraps that key to Spanwork's public RSA key with RSA-OAEP-256 and packages the result in a JWE-shaped envelope.

The Spanwork Worker and mailbox receive the encrypted envelope, not readable form fields. They do not have the private key needed to open it. The private key is kept outside those systems on an authorized Spanwork device, where an accepted inquiry can be decrypted for review.

This is a one-way intake channel. It does not create an account, inbox, or continuing encrypted conversation on the website.

What this protection does not cover

Browser encryption protects submitted form content after encryption from systems that do not hold the private key. It does not hide your IP address or request timing, and it does not make the browser or site code immune to compromise.

The envelope does not provide forward secrecy. If the matching private key is later obtained and unlocked while an encrypted inquiry is still retained, that historical inquiry could be opened.

Cloudflare serves the JavaScript and public key that perform encryption. Malicious or compromised site code, a compromised browser or device, or a hostile browser extension could capture content before encryption or replace the public key. No internet service can promise absolute security or anonymity.

How the information is used

Spanwork uses inquiry information to:

  • reply through the method you provide and assess whether Spanwork can help;
  • prepare or discuss a possible engagement;
  • use standard form attribution to understand which pages and outreach led to a relevant inquiry;
  • use limited interaction events to measure, in aggregate, whether the standard Review path and forms work; and
  • protect the form and website from misuse.

Where data protection law requires a legal basis, Spanwork relies on taking steps at your request before a possible contract, legitimate interests in responding to inquiries and understanding business demand, and compliance with legal obligations where applicable.

Spanwork does not sell personal information, use inquiry data for targeted advertising, or add you to marketing email lists through either inquiry path. Spanwork site code does not set analytics or advertising cookies and does not load a third-party analytics script.

Spanwork does not use solely automated processing to make engagement, pricing, or other decisions that produce legal or similarly significant effects. Automated validation, encryption checks on the protected path, security checks, honeypot logic, and rate limiting may reject or delay a submission.

Spanwork does not collect information about your activity over time across unrelated websites, so the site does not change its behavior in response to browser Do Not Track signals. Spanwork does not permit advertising networks or analytics providers to collect cross-site activity through this site.

Service providers, follow-up, and international processing

Cloudflare provides website hosting, security controls, rate limiting, email relay, and the Analytics Engine dataset used for limited interaction events. For a standard sales form, the Worker processes readable fields and the mailbox provider receives the inquiry as readable text.

For the protected inquiry, Cloudflare also serves the encryption code and Spanwork public key. The protected endpoint and mailbox receive the encrypted envelope and minimum routing information, not readable visitor fields. The mailbox stores ciphertext for local decryption by an authorized Spanwork operator.

If you request Signal follow-up, the website submission remains a separate one-way encrypted inquiry. If Spanwork can reach the Signal account you supplied, any later Signal-to-Signal message is end-to-end encrypted under Signal's service and privacy terms.

If you request email follow-up, the later email conversation is not end-to-end encrypted. Spanwork's mailbox provider, your mailbox provider, and other systems involved in email delivery can process that correspondence. Do not send secrets by email.

Providers may process information in countries other than your own. Where applicable law restricts an international transfer, Spanwork uses a lawful transfer mechanism. Contact Spanwork for current information about the providers and mechanisms relevant to your location.

Retention and security

A standard sales inquiry that does not become an engagement is retained in readable form for no longer than 24 months.

Spanwork keeps a protected inquiry and any decrypted working record only as long as needed to respond, evaluate fit, protect against misuse, or meet legal obligations. The matching private key must remain available while a retained envelope may still need to be opened. The mailbox copy remains ciphertext.

If Spanwork works with you, relevant decrypted records and later correspondence may be kept for up to seven years where needed for contractual, tax, insurance, or legal records. Later Signal or email conversations follow the settings and retention behavior of that channel as well as any applicable engagement recordkeeping duties.

Limited interaction events are retained in Cloudflare Analytics Engine for up to three months. Other infrastructure security, delivery, and rate limit data follows the applicable provider's retention schedule.

Share only what is needed to make contact

Keep the first note high level. Do not submit:

  • passwords, authentication codes, recovery codes, tokens, private keys, or access credentials;
  • payment card details, government identification, health records, financial records, or customer data;
  • source code, production data, malware, exploit code, or unpublished security vulnerabilities; or
  • trade secrets, restricted material, or anything you are not authorized to disclose.

If a written confidentiality agreement or another transfer method is needed, use the protected inquiry only to provide contact details and a general topic. Wait until the method and terms are agreed before sharing sensitive material.

Submitting an inquiry does not create a client relationship, engagement, nondisclosure agreement, legal privilege, or guaranteed duty of confidentiality. Neither path is an anonymous drop box, emergency channel, or vulnerability reporting service.

Your choices and rights

Clearing this site's browser storage can stop campaign fields used by the standard sales path from being reused on later pages. It does not remove attribution already placed in an open standard form, and the current landing page or referring site may be calculated again.

The protected page does not use that attribution storage or send funnel interaction events. Its connection still exposes ordinary network information to Cloudflare as described above. Interaction events from the standard site do not contain an identifier that Spanwork can use to connect an event record to a particular visitor.

You can ask for access, correction, deletion, restriction, portability, or an objection to processing. The rights available depend on where you live and may have legal exceptions. To make a request, email hello@spanwork.net or send a new protected inquiry without repeating sensitive details. Include the inquiry ID if you have it and the contact method used for the original inquiry. Spanwork may need to verify your identity. It may need to decrypt a protected inquiry on the operator device to locate the relevant record.

When a valid deletion request applies, Spanwork removes the relevant standard inquiry, or the protected inquiry and decrypted copies, within its control. Legal recordkeeping duties, provider backup cycles, and copies contained in later email or Signal correspondence can limit or delay deletion. You may also complain to the privacy or data protection authority where you live.

Spanwork notifies visitors of material changes by posting the updated notice on this page and changing the effective date above.