Contents
Privacy Policy
Last updated: 16 April 2026
This document describes how SparkCore ("SparkCore", "we", "us") handles personal data in connection with our website, products and services (together: the "Services"). It is intended to be transparent. For legally binding advice regarding your specific situation, we recommend consulting an advisor.
1. Who is the data controller?
SparkCore acts as the data controller for the processing described in this policy, insofar as the GDPR applies. For certain processing where we act solely on the strict instructions of a customer (for example, purely as a processor in an enterprise engagement), additional or alternative arrangements apply under a data processing agreement.
For privacy questions and requests from data subjects, you can contact us via the details on our contact page. Clearly state that it is a privacy matter and, if applicable, provide the email address or account you use with us, so we can handle your request efficiently.
2. Scope and relation to other documents
This privacy policy applies when you visit our website, create an account, use our software, communicate with us, receive a newsletter, participate in a demo or pilot, or otherwise share data with us. The policy does not apply to third-party websites or services accessible via links from our site; those are governed by the terms of those third parties.
Additionally, general terms and conditions, product terms, a data processing agreement or a quote may contain specific provisions regarding data processing, retention periods or sub-processors. In case of conflicts between documents, we aim to clarify which document applies to which aspect; if in doubt, please contact us.
3. What categories of personal data do we process?
Depending on how you interact with us, the following categories may be processed. You are never required to provide more data than reasonably necessary for the purpose, but some fields are necessary to deliver a service.
- Identification and Contact Data: name, company name, position, email address, phone number, billing address and shipping address.
- Account and Authentication Data: login name, encrypted password representation or tokens, dashboard preferences, roles and permissions.
- Contract and Payment Data: order history, invoice numbers, payment status, bank or payment details as needed for collection or refunds (often through a payment processor).
- Technical and Usage Data: IP address (possibly shortened or anonymized), device and browser type, timestamps, log files, error reports, security signals, cookie IDs and similar identifiers.
- Communication Content: messages you send us via email, contact forms, support tickets or chat (if available), including attachments unless you include unnecessary personal data in attachments.
- Content you upload in demos or trials: for example, images or documents you provide in a test environment. These may contain personal data if you include images of people in them yourself; that remains your responsibility.
- Marketing and Preference Data: newsletter subscription, click behavior in emails where permitted, interest in specific products.
4. Purposes and legal bases (GDPR)
We process personal data only where it serves a concrete purpose and has a valid legal basis. In practice, these are primarily: performance of a contract, legitimate interest, legal obligation, and sometimes consent.
- Delivering and managing the Services (contract performance): account creation, billing, technical support, processing uploads within agreed functionality.
- Security and fraud prevention (legitimate interest and sometimes legal obligation): monitoring abuse, logging, rate limiting, integrity checks.
- Product improvement and development (legitimate interest): aggregation and analysis at group level, A/B testing where permitted, support quality. Where possible we use pseudonymized or aggregated data.
- Communication about the Services (contract performance or legitimate interest): service messages, incident notifications, changes to terms that affect you.
- Direct marketing (consent or legitimate interest, depending on context and local rules): for example newsletters. You can easily opt out where applicable.
- Compliance with laws and regulations (legal obligation): tax retention requirements, response to lawful orders from competent authorities, to the extent applicable.
When we rely on legitimate interest, we balance that interest against your privacy interests. You may object to processing based on legitimate interest; see further below under your rights.
5. Cookies and similar techniques
Our website may use cookies and similar techniques for essential functionality, security, statistics and marketing. Essential cookies are needed to make the site work properly from a technical perspective (for example, session management or security). For non-essential cookies, we request consent in advance where required via a cookie banner or similar provision.
You can configure your browser to refuse or delete cookies. Please note: some parts of the site or service may not work as well as a result. A current overview of which cookies we place, by category and with retention period, can be found in our cookie policy.
6. Retention Periods
We retain personal data no longer than necessary for the purposes for which it was collected, unless a longer retention obligation arises under law (for example, tax record keeping). Specific periods depend on the type of data:
- Account and contract data: during the term of the relationship and afterwards for a limited period for dispute resolution, collection or legal obligations.
- Billing data: in line with tax retention periods (often multiple years, depending on applicable law).
- Support tickets: as long as needed for quality and dispute resolution, then deletion or anonymization where possible.
- Logs and security: usually a shorter, technically determined period, unless longer retention is needed for incident response or legal obligation.
- Marketing: until withdrawal of consent or objection, and then within a limited suppression period to prevent accidental re-mailing.
7. Security
We implement appropriate technical and organizational measures to protect personal data against loss, unauthorized access, disclosure or alteration. Examples include encryption in transit where appropriate, access controls, segregation of environments, logging, backups, and limiting access to data on a need-to-know basis for staff and processors.
However, no method of transmission over the internet or electronic storage is completely secure. If you suspect a data breach affecting us, please report it as soon as possible via contact so we can investigate what steps are necessary, including any notification to supervisory authorities and affected individuals if required.
8. Processors, disclosure and international transfer
We use service providers (processors) such as hosting providers, email infrastructure, analytics (insofar as permitted), payment processors and support tools. We enter into contractual agreements with processors that comply with the GDPR, including obligations regarding security and confidentiality.
When personal data is processed outside the European Economic Area, we ensure appropriate safeguards, such as standard contractual clauses approved by the European Commission, or another mechanism permitted under the GDPR, unless a specific exemption applies.
9. Profiling and automated decision-making
We do not use automated decision-making that produces legal effects for you or similarly significantly affects you within the meaning of Article 22 GDPR, unless we explicitly announce that in the future and provide a legal basis and transparency. Analyses for product improvement and security typically take place at an aggregated level.
10. Your rights
Under the GDPR, you have, among others, the following rights, insofar as applicable: access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, objection to processing based on legitimate interest, and withdrawal of consent (insofar as processing was based on consent). You can also lodge a complaint with the Data Protection Authority or another competent supervisory authority in your country.
To prevent abuse, we may ask you to verify your identity before fulfilling a request. In some cases, we may not be able to fully comply with a request, for example when a legal retention obligation prevents deletion, or when data is needed to establish, exercise or substantiate a legal claim.
You exercise these rights by contacting us using the information on the contact page. We aim to respond within a reasonable timeframe; statutory deadlines may vary by jurisdiction.
11. Minors
Our Services are not directed to individuals under sixteen years of age (or another age according to local law). We do not knowingly collect personal data from children. If you are a parent or guardian and believe a child has provided us with data, please contact us so we can take appropriate steps.
12. Changes to this policy
We may update this privacy policy from time to time, for example due to new functionality, changes in legislation, or reorganization. The "Last updated" date at the top of this document will then be changed. For material changes, we will endeavor to inform you via an appropriate channel, such as email or a notification in the product, insofar as reasonable.
13. Data breaches and incidents
Despite precautions, it cannot be ruled out that a security breach of personal data may occur. When such an incident is likely to pose a risk to the rights and freedoms of individuals, there may in certain cases be a duty to notify the supervisory authority and, in serious cases, the affected individuals. SparkCore maintains internal procedures to detect, investigate, mitigate and document incidents.
If you suspect a vulnerability or data breach in our Services, we ask you to report it responsibly (for example via contact), without exploiting the vulnerability and without downloading data that is not yours.
14. Automated decision-making and profiles (supplementary)
For clarity: where we conduct analyses on product usage, we typically do so at an aggregated level, for example to plan capacity, find errors or improve the product. This does not automatically mean that individual profiles are built for behavior outside the product. Should SparkCore in the future make meaningful use of profiling with legal consequences, we will describe that and, where necessary, provide an appropriate legal basis and information obligation
15. Third parties and your own processing responsibility
If you act as a data controller yourself (for example because you run a webshop and collect customer data), you remain responsible for those processing activities. Using SparkCore does not release you from your own obligations towards your customers or visitors. In many cases, SparkCore will act as a processor for specific processing of content you provide; such relationships should be documented contractually in a data processing agreement as required by law
16. Contact
If you have questions about this privacy policy or about the processing of your data, you can contact us via the details on our contact page. Please clearly state the subject (for example "GDPR request: access") so that your message reaches the right people quickly.