This Data Processing Agreement (DPA) is part of the Terms of Use between the organisation accepting the Terms (Controller) and Decoders B.V., trading as Sparki, Tragelwest 55, 4507 JD Schoondijke, the Netherlands, KVK 84779179 (Processor). It applies whenever Sparki processes personal data on behalf of the Controller. It takes effect with the Agreement and continues until Sparki has deleted or returned the personal data. If this DPA conflicts with another part of the Agreement about processing personal data, this DPA prevails.
The Controller determines the purposes and means of processing customer-workflow data. Sparki processes that data only on documented instructions from the Controller, including instructions expressed through the Agreement, account configuration, enabled features and integrations, support requests, and documented use of the API, portal, dashboard, or plugin.
Sparki will not process the data for its own advertising, sell it, or combine it to create advertising profiles. Sparki may process limited account, billing, security, support, and service-usage data as an independent controller as described in the Privacy Policy.
If Union or Member State law requires processing beyond the Controller's instructions, Sparki will inform the Controller before processing unless the law prohibits that notice. Sparki will promptly tell the Controller if, in its opinion, an instruction infringes the GDPR or other applicable data-protection law and may suspend that instruction while the parties resolve the issue.
Sparki ensures that persons authorised to process personal data are bound by confidentiality obligations, receive access only where needed for their role, and are informed of applicable data-protection and security duties. Access is removed when no longer required.
Taking account of the state of the art, implementation cost, processing context, and risks to individuals, Sparki maintains appropriate technical and organisational measures, including:
Sparki may update these measures as technology and risk change, provided it does not materially reduce the overall level of protection. Current security information can be requested at support@sparki.app, subject to confidentiality and security restrictions.
The Controller gives Sparki general written authorisation to use the subprocessors listed below and in the current Privacy Policy. Sparki will give reasonable advance notice, normally at least 30 days, before adding or replacing a subprocessor that will process customer-workflow personal data. The Controller may object on reasonable data-protection grounds during that period. The parties will work in good faith on a reasonable solution; if none is available, the Controller may stop the affected feature or terminate the affected Service without penalty for the unused prepaid period.
Mollie processes regulated payment data under its own legal obligations. Customer-enabled providers such as Google Meet, Zoom, Realworks, Kolibri, Mollie connections, OpenAI-compatible services, or custom email providers receive data only when the Controller enables and instructs that integration. Where Sparki engages a provider as a subprocessor, Sparki imposes data-protection obligations offering materially equivalent protection and remains responsible for that subprocessor's performance of those obligations.
Sparki will not transfer personal data outside the EEA except on the Controller's documented instructions or under a lawful transfer mechanism. Where required, Sparki or its subprocessor will use an adequacy decision, the applicable European Commission Standard Contractual Clauses, or another mechanism permitted by Chapter V GDPR, and will implement supplementary measures where the transfer assessment requires them.
Taking account of the nature of processing, Sparki will provide reasonable technical and organisational assistance so the Controller can respond to requests for access, rectification, erasure, restriction, portability, objection, and rights concerning automated decisions. If Sparki receives a request relating to Controller data, it will direct the requester to the Controller and will not respond substantively unless authorised or legally required.
Sparki will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Controller data. The notice will, as information becomes available, describe the nature of the breach, affected data and data subjects, likely consequences, measures taken or proposed, and a contact point. Sparki will take reasonable steps to contain, investigate, mitigate, and document the breach and will assist the Controller with notifications required under Articles 33 and 34 GDPR. Notification is not an admission of fault or liability.
Taking account of the nature of processing and information available to it, Sparki will provide reasonable assistance with the Controller's obligations concerning security, data-protection impact assessments, and prior consultation with a supervisory authority under Articles 32 to 36 GDPR.
During the Agreement, the Controller may use available deletion functions and may contact support@sparki.app to coordinate an export, deletion, or return request. At the Controller's choice, after termination Sparki will delete or return customer-workflow personal data and delete remaining copies, unless Union or Member State law requires retention. The Controller must communicate its choice before or promptly after termination; absent a return request, Sparki will delete the data under its documented retention process. Deleted data may remain inaccessible in encrypted backups until the normal backup-expiry cycle completes and will not be restored except for disaster recovery, after which the deletion schedule will be reapplied.
Sparki will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR. No more than once per year, unless a breach, regulator request, or substantiated compliance concern justifies more, the Controller may request relevant policies, third-party reports, or a remote audit. If those materials are insufficient, the Controller may conduct or appoint an independent auditor for a proportionate inspection on at least 30 days' notice, during business hours, subject to confidentiality, security, and protection of other customers. The Controller bears its audit costs unless the audit identifies a material breach by Sparki.
The Controller is responsible for the lawfulness, fairness, accuracy, and transparency of its processing; for its instructions and legal bases; for providing notices to data subjects; for configuring appropriate access and retention; for responding to data-subject requests; and for avoiding unnecessary or unlawful data. The Controller will not instruct Sparki to process data in violation of applicable law.
Privacy and DPA questions can be sent to support@sparki.app. Sparki may update the subprocessor list, security measures, or this DPA where needed to reflect the Service or law, but will not materially reduce protection without notice. Material changes take effect under the change provisions in the Terms and applicable law.