Last Updated: September 19, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Sparko Technologies Pte. Ltd., a private company limited by shares incorporated in Singapore (UEN 202642599C), with its registered office at 2 Fowlie Road, Sycamore Tree, Singapore 428505 ("Processor" or "Sparko"), and the entity agreeing to these terms ("Controller" or "Customer").
This DPA applies to the extent that Sparko processes Personal Data on behalf of Customer in connection with the Services.
Customer determines the purposes and means of Processing Personal Data and is responsible for:
Sparko processes Personal Data only on Customer's documented instructions and is responsible for:
| Subject matter | Provision of the Sparko platform to Customer: Sparko People (HRIS, including AI-assisted HR functionality) and, where Customer uses it, Sparko Legal (beta: AI-assisted contract and policy review) |
| Duration | Term of the underlying Agreement, plus the retention/deletion periods in Section 10 |
| Nature & purpose | Hosting, storage, and processing of Customer’s HR data to deliver recruiting, onboarding, performance, compensation, payroll, engagement, and career-development functionality, including AI-assisted features; and, where Customer uses Sparko Legal, hosting and AI-assisted review of contracts, playbooks, and policy documents Customer uploads, with proposed changes subject to Customer approval |
| Categories of data subjects | Customer’s employees; job applicants; contractors and consultants; where Customer uses Sparko Legal, representatives and signatories of counterparties named in documents Customer uploads; other individuals whose data Customer inputs |
| Categories of personal data | Contact information (name, email, phone, address); employment information (job title, department, salary); identity documents as uploaded by Customer; performance and feedback data; payroll and compensation data; where Customer uses Sparko Legal, contract, playbook, and policy documents and the names, roles, and contact details of individuals appearing in them; any other data Customer inputs into the Services |
| Special category data | Where Customer chooses to use optional EEO/diversity-reporting features, ethnicity and disability status may be collected on employee and candidate records. The applicable Article 9 legal basis for this processing is confirmed by Customer, as Controller, based on its own jurisdiction and use of these features. |
See our Trust Center and Trust Center pages for additional details.
Customer provides general authorization for Sparko to engage Sub-processors. Current Sub-processors include:
Integrations and webhook endpoints that Customer configures (for example Slack, Microsoft Teams, or custom webhook receivers) are engaged by Customer, receive data on Customer's instructions, and are not Sparko Sub-processors.
We will notify Customer of new Sub-processors at least 30 days before engagement. Customer may object within 14 days of notification.
All Sub-processors are bound by data protection obligations substantially similar to those in this DPA.
Sparko will assist Customer in responding to Data Subject requests including:
If Sparko receives a request directly from a Data Subject, we will redirect them to Customer unless legally required to respond directly.
In the event of a Personal Data breach, Sparko will:
As an internal operational target (not a contractual deadline), Sparko aims to provide initial notification within 48 hours of confirmed detection, to help Customer meet its own regulatory notification obligations (such as the 72-hour deadline that applies to Customer, as Controller, under GDPR Article 33).
Personal Data may be transferred to countries outside the EEA. Sparko ensures appropriate safeguards through:
Sparko is established in Singapore and hosts Personal Data on AWS in Singapore (ap-southeast-1). Singapore is not covered by a European Commission adequacy decision, so where Personal Data originating in the EEA, UK, or Switzerland is transferred to Sparko, the parties incorporate by reference the SCCs, Module Two (Controller to Processor), reflecting Customer’s role as Controller and data exporter and Sparko’s role as Processor and data importer under Section 2 of this DPA. Where Sparko transfers Personal Data out of Singapore, it does so on terms providing a standard of protection comparable to the PDPA, in line with the Transfer Limitation Obligation. Where Sparko engages a Sub-processor located outside the EEA/UK/Switzerland, Module Three (Processor to Processor) terms apply as between Sparko and that Sub-processor. Sparko will provide reasonably requested information, including Sub-processor location and safeguards in place, to support Customer’s completion of a Transfer Impact Assessment.
Upon reasonable request and subject to confidentiality obligations, Sparko will:
Upon termination of Services:
Each party's liability under this DPA is subject to the limitations set forth in the Terms of Service. Nothing in this DPA limits either party's liability for breaches of Data Protection Laws.
This DPA remains in effect for the duration of the Terms of Service and continues until all Personal Data has been deleted or returned.
This DPA is governed by the laws of the Republic of Singapore and the parties submit to the exclusive jurisdiction of the courts of Singapore, except that where the SCCs apply, the governing law and forum clauses of the SCCs prevail for matters arising under them. In the event of a conflict, the SCCs take precedence over this DPA, and this DPA takes precedence over the Terms of Service, in each case as to the subject matter of data protection.
For questions about this DPA or data protection matters, contact our Data Protection Officer:
Data Protection Officer
Sparko Technologies Pte. Ltd.
UEN 202642599C
2 Fowlie Road, Sycamore Tree, Singapore 428505
Email: [email protected]