Last Updated: August 2, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Sparko ("Processor" or "Sparko") and the entity agreeing to these terms ("Controller" or "Customer").
This DPA applies to the extent that Sparko processes Personal Data on behalf of Customer in connection with the Services.
Customer determines the purposes and means of Processing Personal Data and is responsible for:
Sparko processes Personal Data only on Customer's documented instructions and is responsible for:
| Subject matter | Provision of the Sparko HRIS platform, including AI-assisted HR functionality, to Customer |
| Duration | Term of the underlying Agreement, plus the retention/deletion periods in Section 10 |
| Nature & purpose | Hosting, storage, and processing of Customer’s HR data to deliver recruiting, onboarding, performance, compensation, payroll, engagement, and career-development functionality, including AI-assisted features |
| Categories of data subjects | Customer’s employees; job applicants; contractors and consultants; other individuals whose data Customer inputs |
| Categories of personal data | Contact information (name, email, phone, address); employment information (job title, department, salary); identity documents as uploaded by Customer; performance and feedback data; payroll and compensation data; any other data Customer inputs into the Services |
| Special category data | Where Customer chooses to use optional EEO/diversity-reporting features, ethnicity and disability status may be collected on employee and candidate records. The applicable Article 9 legal basis for this processing is confirmed by Customer, as Controller, based on its own jurisdiction and use of these features. |
See our Security and Trust Center pages for additional details.
Customer provides general authorization for Sparko to engage Sub-processors. Current Sub-processors include:
Integrations and webhook endpoints that Customer configures (for example Slack, Microsoft Teams, or custom webhook receivers) are engaged by Customer, receive data on Customer's instructions, and are not Sparko Sub-processors.
We will notify Customer of new Sub-processors at least 30 days before engagement. Customer may object within 14 days of notification.
All Sub-processors are bound by data protection obligations substantially similar to those in this DPA.
Sparko will assist Customer in responding to Data Subject requests including:
If Sparko receives a request directly from a Data Subject, we will redirect them to Customer unless legally required to respond directly.
In the event of a Personal Data breach, Sparko will:
As an internal operational target (not a contractual deadline), Sparko aims to provide initial notification within 48 hours of confirmed detection, to help Customer meet its own regulatory notification obligations (such as the 72-hour deadline that applies to Customer, as Controller, under GDPR Article 33).
Personal Data may be transferred to countries outside the EEA. Sparko ensures appropriate safeguards through:
Where Personal Data originating in the EEA, UK, or Switzerland is transferred to a country without an applicable adequacy decision, the parties incorporate by reference the SCCs, Module Two (Controller to Processor), reflecting Customer’s role as Controller and Sparko’s role as Processor under Section 2 of this DPA. Where Sparko engages a Sub-processor located outside the EEA/UK/Switzerland, Module Three (Processor to Processor) terms apply as between Sparko and that Sub-processor. Sparko will provide reasonably requested information, including Sub-processor location and safeguards in place, to support Customer’s completion of a Transfer Impact Assessment.
Upon reasonable request and subject to confidentiality obligations, Sparko will:
Upon termination of Services:
Each party's liability under this DPA is subject to the limitations set forth in the Terms of Service. Nothing in this DPA limits either party's liability for breaches of Data Protection Laws.
This DPA remains in effect for the duration of the Terms of Service and continues until all Personal Data has been deleted or returned.
For questions about this DPA or data protection matters:
Email: [email protected]