Introduction
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Sparko ("Processor" or "Sparko") and the entity agreeing to these terms ("Controller" or "Customer").
This DPA applies to the extent that Sparko processes Personal Data on behalf of Customer in connection with the Services.
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on Personal Data, including collection, storage, use, and deletion.
- "Data Subject" means the individual to whom Personal Data relates.
- "Sub-processor" means any third party engaged by Sparko to process Personal Data.
- "Data Protection Laws" means applicable laws relating to data protection, including GDPR and CCPA.
2. Roles and Responsibilities
2.1 Customer as Controller
Customer determines the purposes and means of Processing Personal Data and is responsible for:
- Ensuring lawful basis for Processing
- Providing required notices to Data Subjects
- Obtaining necessary consents
- Ensuring data accuracy
- Responding to Data Subject requests
2.2 Sparko as Processor
Sparko processes Personal Data only on Customer's documented instructions and is responsible for:
- Processing data according to this DPA and Customer instructions
- Ensuring personnel are bound by confidentiality
- Implementing appropriate security measures
- Assisting with Data Subject requests
- Deleting or returning data upon termination
3. Scope of Processing
3.1 Categories of Data Subjects
- Customer's employees
- Job applicants
- Contractors and consultants
- Other individuals whose data Customer inputs
3.2 Categories of Personal Data
- Contact information (name, email, phone, address)
- Employment information (job title, department, salary)
- Identity documents (as uploaded by Customer)
- Performance and feedback data
- Payroll and compensation data
- Any other data Customer inputs into the Services
3.3 Purpose of Processing
To provide the HR management Services as described in our Terms of Service.
4. Security Measures
Sparko implements and maintains appropriate technical and organizational measures including:
- Encryption of Personal Data at rest (AES-256) and in transit (TLS 1.3)
- Access controls and authentication mechanisms
- Regular security assessments using industry-standard tools
- Incident detection and response procedures
- Data backup and recovery procedures
- AWS infrastructure with enterprise-grade physical security
See our Security page for additional details.
5. Sub-processors
5.1 Authorization
Customer provides general authorization for Sparko to engage Sub-processors. Current Sub-processors include:
- Amazon Web Services (infrastructure hosting)
- Anthropic (AI processing for AI-powered features)
- Polar (payment processing and billing, acting as Merchant of Record)
- SendGrid (email delivery)
- DocuSign (e-signature workflows, Business plan)
Integrations and webhook endpoints that Customer configures (for example Slack, Microsoft Teams, or custom webhook receivers) are engaged by Customer, receive data on Customer's instructions, and are not Sparko Sub-processors.
5.2 Notification
We will notify Customer of new Sub-processors at least 30 days before engagement. Customer may object within 14 days of notification.
5.3 Sub-processor Obligations
All Sub-processors are bound by data protection obligations substantially similar to those in this DPA.
6. Data Subject Rights
Sparko will assist Customer in responding to Data Subject requests including:
- Access requests
- Rectification requests
- Erasure requests
- Data portability requests
- Objection to processing
- Restriction of processing
If Sparko receives a request directly from a Data Subject, we will redirect them to Customer unless legally required to respond directly.
7. Data Breach Notification
In the event of a Personal Data breach, Sparko will:
- Notify Customer without undue delay (within 72 hours where feasible)
- Provide details of the breach including categories and volume of data affected
- Describe likely consequences and mitigation measures
- Cooperate with Customer's investigation and notification obligations
8. International Transfers
Personal Data may be transferred to countries outside the EEA. Sparko ensures appropriate safeguards through:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Additional technical and organizational measures
9. Audits
Upon reasonable request and subject to confidentiality obligations, Sparko will:
- Provide documentation of our security practices
- Respond to reasonable security questionnaires
- Cooperate with reasonable audit requests
10. Data Retention and Deletion
Upon termination of Services:
- Customer may export their data for 30 days
- Sparko will delete Personal Data within 90 days
- Backup copies will be deleted within 180 days
- Some data may be retained as required by law
11. Liability
Each party's liability under this DPA is subject to the limitations set forth in the Terms of Service. Nothing in this DPA limits either party's liability for breaches of Data Protection Laws.
12. Term
This DPA remains in effect for the duration of the Terms of Service and continues until all Personal Data has been deleted or returned.
13. Contact
For questions about this DPA or data protection matters:
Email: [email protected]