Data Processing Agreement

Last updated: 21 September 2026 — Version 1.0

1. Scope and purpose

This Data Processing Agreement ("DPA") forms part of the agreement governing access to and use of the SparkList service, including the SparkList Terms of Service, any applicable subscription agreement, order form, or other agreement between the parties (together, the "Agreement").

This DPA applies where:

  • a professional user or organization using SparkList ("Customer") processes Personal Data through the Service as a Controller; and
  • Deployed OÜ, operating the SparkList service ("SparkList", "we", "our", or "us"), processes that Personal Data on behalf of the Customer as a Processor.

The Service is operated by:

  • Deployed OÜ
  • Private limited company registered in Estonia
  • Registry code: 14566662
  • VAT number: EE102098871
  • Registered office: Sauna 4-6, Muraste, 76905 Harju maakond, Estonia
  • Website: https://sparklist.io
  • Email: [email protected]

By entering into the Agreement or using the Service in circumstances where SparkList processes Personal Data on the Customer's behalf, the parties agree to this DPA.

This DPA is intended to satisfy the requirements applicable to controller–processor relationships under Article 28 of Regulation (EU) 2016/679 ("GDPR").

2. Definitions

For the purposes of this DPA:

Applicable Data Protection Law means the GDPR and any other data protection or privacy law applicable to the processing covered by this DPA.

Controller, Processor, Data Subject, Personal Data, Processing, Personal Data Breach, and Supervisory Authority have the meanings given to them under the GDPR.

Customer Personal Data means Personal Data processed by SparkList on behalf of the Customer through the Service.

Service means the SparkList applications, website, platform, APIs, features and associated services made available by Deployed OÜ.

Subprocessor means another processor engaged by SparkList to process Customer Personal Data on behalf of the Customer.

Capitalized terms not defined in this DPA have the meanings given to them in the Agreement.

3. Roles of the parties

3.1 Customer as Controller

For Customer Personal Data processed through SparkList on the Customer's behalf, the Customer acts as Controller and determines the purposes and essential means of the processing.

This may include Personal Data concerning:

  • employees;
  • cleaners;
  • contractors;
  • service providers;
  • property managers;
  • property owners;
  • guests;
  • occupants;
  • Customer representatives;
  • other individuals whose Personal Data is entered into or incidentally captured through the Service.

3.2 SparkList as Processor

SparkList acts as Processor when it processes Customer Personal Data on behalf of the Customer for the purpose of providing the Service.

3.3 SparkList as independent Controller

This DPA does not apply to processing for which SparkList acts as an independent Controller.

SparkList may act as a Controller for certain processing relating to, for example:

  • Customer account administration;
  • subscription and billing management;
  • accounting and tax obligations;
  • Service security and fraud prevention;
  • management of its own business relationship with the Customer;
  • compliance with legal obligations;
  • certain analytics or Service improvement activities where SparkList independently determines the purposes and means of processing.

Such processing is governed by the SparkList Privacy Policy and applicable law.

4. Customer instructions

SparkList shall process Customer Personal Data only on documented instructions from the Customer, unless processing is required by European Union or Member State law applicable to SparkList.

The parties agree that the following constitute documented instructions from the Customer:

  • the Agreement;
  • this DPA;
  • the Customer's configuration and use of the Service;
  • actions performed by authorized Customer users through the Service;
  • written instructions provided by the Customer and accepted by SparkList.

These instructions include processing Customer Personal Data as reasonably necessary to:

  • host and store Customer Personal Data;
  • operate the Service;
  • create and manage properties, checklists, tasks and workflows;
  • manage Customer teams and access permissions;
  • assign work;
  • record task and checklist activity;
  • process photo proof and uploaded media;
  • process issue reports;
  • provide on-site and geolocation-based functionality configured by the Customer;
  • record work-related timestamps and job duration;
  • create operational reports;
  • provide Customer-selected AI-assisted functionality;
  • provide support and troubleshoot technical issues;
  • maintain backups;
  • maintain the security, availability and integrity of the Service;
  • comply with other documented instructions provided through use of the Service.

If SparkList believes that an instruction from the Customer infringes Applicable Data Protection Law, SparkList shall inform the Customer without undue delay, unless prohibited from doing so by law.

5. Customer responsibilities

The Customer is responsible for ensuring that its collection and processing of Customer Personal Data through SparkList complies with Applicable Data Protection Law.

In particular, the Customer is responsible for:

  • determining an appropriate lawful basis for processing;
  • providing legally required privacy notices;
  • informing employees, cleaners, contractors and other Data Subjects about the use of SparkList;
  • informing relevant Data Subjects about the collection of photos, timestamps, work activity and geolocation information where applicable;
  • obtaining consent where consent is legally required;
  • determining whether another lawful basis may be relied upon where consent is not required;
  • complying with applicable employment and workplace monitoring laws;
  • configuring geolocation features lawfully and proportionately;
  • ensuring that only authorized individuals have access to the Service;
  • removing access when an individual is no longer authorized;
  • minimizing unnecessary Personal Data contained in photos and other uploaded content;
  • ensuring its instructions to SparkList are lawful;
  • responding to requests from Data Subjects where the Customer acts as Controller.

The Customer shall not instruct SparkList to process Personal Data in violation of Applicable Data Protection Law.

6. Confidentiality

SparkList shall ensure that persons authorized to process Customer Personal Data:

  • process such data only as necessary to perform their duties;
  • are subject to appropriate confidentiality obligations; and
  • receive access to Customer Personal Data only where reasonably necessary.

SparkList shall restrict access to Customer Personal Data to personnel and service providers that require such access for the provision, security, maintenance or support of the Service.

7. Security

Taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, as well as the risks to Data Subjects, SparkList shall implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data.

Such measures include, as appropriate, the measures described in Annex II — Technical and Organizational Measures.

SparkList may update its security measures from time to time, provided that such updates do not materially reduce the overall level of protection afforded to Customer Personal Data.

The Customer acknowledges that no system or method of electronic storage or transmission can guarantee absolute security.

8. Personal Data Breaches

SparkList shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

To the extent reasonably available, such notification shall include information necessary to assist the Customer in complying with its obligations under Articles 33 and 34 of the GDPR, including:

  • the nature of the breach;
  • the categories of Personal Data affected;
  • the categories of Data Subjects affected;
  • the likely consequences of the breach;
  • measures taken or proposed to address or mitigate the breach.

Where all information is not immediately available, SparkList may provide information progressively as it becomes available.

SparkList shall take reasonable steps to contain, investigate and mitigate a Personal Data Breach affecting Customer Personal Data.

Notification of a Personal Data Breach does not constitute an admission of fault or liability by SparkList.

9. Subprocessors

9.1 General authorization

The Customer grants SparkList general authorization to engage Subprocessors where reasonably necessary to provide the Service.

SparkList shall require each Subprocessor processing Customer Personal Data to be subject to data protection obligations that provide an appropriate level of protection for the relevant processing and that are consistent with SparkList's obligations under this DPA where required by Applicable Data Protection Law.

SparkList remains responsible for the performance of its Subprocessors to the extent required under Applicable Data Protection Law.

9.2 Subprocessor list

SparkList maintains information regarding the principal Subprocessors used to process Customer Personal Data.

The current list is available at: https://sparklist.io/en/subprocessors/.

9.3 Changes to Subprocessors

SparkList may add or replace Subprocessors.

Where required by Applicable Data Protection Law, SparkList shall provide the Customer with reasonable advance notice of material additions or replacements of Subprocessors by email, through the Service, through the Subprocessor page, or another reasonable communication method.

The Customer may object to a new Subprocessor on reasonable grounds relating specifically to the protection of Personal Data.

Any objection must be submitted to SparkList promptly after the Customer receives notice of the change and must explain the Customer's reasonable data-protection concerns.

The parties shall work in good faith to attempt to resolve the objection.

If no reasonable solution can be found, the Customer may discontinue use of the affected part of the Service or terminate the applicable Service in accordance with the Agreement.

10. International transfers

SparkList aims to store and process Customer Personal Data within the European Economic Area where reasonably possible.

Certain Subprocessors or technical providers may nevertheless process Personal Data outside the European Economic Area.

Where Customer Personal Data is transferred to a country outside the European Economic Area and Applicable Data Protection Law requires a transfer mechanism, SparkList shall ensure that an appropriate legal mechanism is used.

Such mechanisms may include:

  • an adequacy decision adopted by the European Commission;
  • the EU-U.S. Data Privacy Framework where valid and applicable;
  • the European Commission's Standard Contractual Clauses;
  • another lawful transfer mechanism permitted under Applicable Data Protection Law.

Where Standard Contractual Clauses are used, SparkList shall implement supplementary measures where required based on the circumstances of the relevant transfer.

11. Data Subject requests

Taking into account the nature of the processing, SparkList shall provide reasonable assistance to the Customer, insofar as possible, to enable the Customer to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law.

These may include requests concerning:

  • access;
  • rectification;
  • erasure;
  • restriction of processing;
  • data portability;
  • objection;
  • rights relating to automated decision-making where applicable.

Where SparkList receives a request directly from a Data Subject concerning Customer Personal Data for which the Customer is the Controller, SparkList may refer the Data Subject to the Customer or forward the request to the Customer where reasonably possible.

SparkList shall not independently respond to such a request on behalf of the Customer unless instructed or legally required to do so.

12. Data protection impact assessments and regulatory assistance

Taking into account the nature of the processing and the information available to SparkList, SparkList shall provide reasonable assistance to the Customer with:

  • data protection impact assessments required under Article 35 GDPR; and
  • prior consultations with a Supervisory Authority under Article 36 GDPR,

to the extent that such obligations relate to Customer Personal Data processed by SparkList.

SparkList may provide information about the Service, its security measures, relevant Subprocessors and the nature of the processing for this purpose.

13. Government and legal requests

If SparkList is legally required to disclose Customer Personal Data to a public authority or other third party, SparkList shall, where legally permitted, inform the Customer before making the disclosure.

SparkList shall disclose only the Personal Data that it reasonably believes it is legally required to disclose.

Nothing in this DPA requires SparkList to violate applicable law or a legally binding order.

14. Return and deletion of Customer Personal Data

During the term of the Service, the Customer may delete certain Customer Personal Data using functionality provided by the Service where available.

Upon termination of the relevant Service, and at the Customer's choice, SparkList shall delete or return Customer Personal Data in accordance with Applicable Data Protection Law, unless applicable law requires SparkList to retain the data.

Where the Customer requests return of Customer Personal Data, SparkList may provide the data using the export functionality or reasonably available technical format applicable to the Service.

Customer Personal Data remaining in backups may be deleted according to SparkList's normal backup retention and deletion cycle, provided that such data remains protected under this DPA until deletion.

SparkList may retain Personal Data where required by applicable tax, accounting, legal, security, fraud-prevention or dispute-resolution obligations, provided that SparkList acts as Controller for such retention where appropriate and limits processing to the applicable purpose.

15. Demonstrating compliance and audits

SparkList shall make available to the Customer information reasonably necessary to demonstrate compliance with the processor obligations applicable under Article 28 GDPR.

The Customer should first use documentation, information and responses provided by SparkList to assess compliance.

Where such information is reasonably insufficient, the Customer may request an audit relating specifically to SparkList's processing of Customer Personal Data.

Unless otherwise required by a Supervisory Authority or Applicable Data Protection Law:

  • audits must be requested with reasonable advance written notice;
  • audits should normally occur no more than once in any twelve-month period;
  • audits must take place during normal business hours;
  • audits must not unreasonably interfere with SparkList's operations;
  • audits must not compromise the security, confidentiality or privacy of other customers;
  • any auditor must be bound by appropriate confidentiality obligations;
  • the scope must be limited to systems and information relevant to Customer Personal Data.

The Customer shall bear its own audit costs.

SparkList may charge reasonable costs for substantial assistance required for an audit initiated by the Customer, unless the audit reveals a material breach of this DPA by SparkList or such charging would be prohibited by Applicable Data Protection Law.

Nothing in this section limits the powers of a competent Supervisory Authority.

16. Special categories of Personal Data

SparkList is not designed for the intentional storage of special categories of Personal Data under Article 9 GDPR unless such processing is expressly supported by the relevant Service functionality.

The Customer shall avoid uploading sensitive Personal Data that is unnecessary for the use of the Service.

Because photos, issue reports, free-text fields or other content uploaded by users may incidentally contain sensitive information, such data may nevertheless be processed as part of Customer Personal Data.

Where the Customer chooses to process special categories of Personal Data through the Service, the Customer is responsible for ensuring that an appropriate lawful basis and any additional safeguards required by Applicable Data Protection Law are in place.

17. AI-assisted features

Certain SparkList features may use artificial intelligence or machine-learning service providers to process information submitted to those features.

Depending on the feature, this may include:

  • photos;
  • checklist content;
  • task descriptions;
  • property instructions;
  • issue information;
  • other Customer-provided content.

Where an AI provider processes Customer Personal Data on behalf of SparkList in connection with providing the Service, that provider shall be treated as a Subprocessor where required by Applicable Data Protection Law.

AI-assisted features are designed to assist users and do not replace the Customer's own review, judgment or decision-making.

The Customer is responsible for determining whether Customer Personal Data submitted to an optional AI feature may lawfully be processed for that purpose.

18. Geolocation and workforce-related data

SparkList may process geolocation and work-activity information when the Customer enables or requires relevant Service functionality.

SparkList processes such information on behalf of the Customer according to the configuration and use of the Service.

The Customer is responsible for determining whether and under what conditions such functionality may lawfully be used in relation to its employees, cleaners, contractors or other team members.

This includes responsibility for:

  • providing required notices;
  • establishing an appropriate legal basis;
  • complying with applicable employment and workplace-monitoring rules;
  • ensuring that the use of location information is necessary and proportionate;
  • configuring SparkList appropriately for the Customer's intended use.

Further information about how SparkList's on-site location functionality operates — including that location is used in connection with active jobs and that managers see on-site status rather than a continuous GPS trail — is available in the SparkList Privacy Policy.

19. Liability

The liability provisions, exclusions and limitations contained in the Agreement apply to this DPA to the maximum extent permitted by Applicable Data Protection Law.

Nothing in this DPA limits any liability that cannot legally be limited or excluded.

20. Order of precedence

If there is a conflict between this DPA and another part of the Agreement concerning the processing of Customer Personal Data as Processor, this DPA shall prevail to the extent of that conflict.

If applicable European Commission Standard Contractual Clauses governing an international transfer conflict with this DPA, those Standard Contractual Clauses shall prevail in relation to that transfer.

Except as modified by this DPA, the Agreement remains in full force and effect.

21. Duration

This DPA becomes effective when the Agreement becomes applicable to the Customer and continues for as long as SparkList processes Customer Personal Data on behalf of the Customer.

Provisions that by their nature are intended to continue after termination, including confidentiality, deletion, liability and applicable data-protection obligations, shall survive termination for as long as necessary.

22. Changes to this DPA

SparkList may update this DPA where reasonably necessary to:

  • reflect changes to the Service;
  • reflect changes to Applicable Data Protection Law;
  • implement new regulatory guidance;
  • update security, technical or organizational practices;
  • address changes to processing activities.

SparkList shall provide reasonable notice of material changes that adversely affect the protection of Customer Personal Data.

Changes shall not materially reduce the level of data protection required by Applicable Data Protection Law.

23. Governing law

Unless Applicable Data Protection Law requires otherwise, this DPA is governed by the same governing law and jurisdiction provisions as the Agreement.

The SparkList Terms of Service are governed by the laws of Estonia.

24. Contact

For questions relating to this DPA or the processing of Personal Data through SparkList, contact:

SparkList / Deployed OÜ

Email: [email protected]

Website: https://sparklist.io

Annex I — Details of processing

A. Subject matter

Processing of Customer Personal Data as necessary to provide, operate, maintain, secure and support the SparkList Service according to the Customer's instructions.

B. Duration

For the duration of the Agreement and for any limited period afterward during which SparkList retains Customer Personal Data in accordance with this DPA, the Agreement, the Privacy Policy or applicable law.

C. Nature and purpose of processing

Processing operations may include:

  • collection;
  • receipt;
  • hosting;
  • organization;
  • storage;
  • retrieval;
  • consultation;
  • display;
  • transmission;
  • analysis;
  • modification;
  • backup;
  • deletion;
  • other processing necessary to provide the Service.

Purposes may include:

  • visual checklist management;
  • property and site management;
  • work assignment;
  • team management;
  • task completion;
  • proof-of-work collection;
  • photo-based verification;
  • issue reporting;
  • job timing;
  • on-site verification;
  • geolocation-based workflow functionality;
  • operational reporting;
  • Customer-selected AI-assisted functionality;
  • technical support;
  • security;
  • backup and Service continuity.

D. Categories of Data Subjects

Depending on the Customer's use of SparkList, Customer Personal Data may concern:

  • Customer employees;
  • cleaners;
  • contractors;
  • freelancers;
  • service providers;
  • team members;
  • property managers;
  • property owners or landlords;
  • Customer representatives;
  • guests or occupants incidentally represented in Customer-provided content;
  • other persons whose Personal Data is submitted to the Service by or on behalf of the Customer.

E. Categories of Personal Data

Depending on the Customer's use of the Service, Customer Personal Data may include:

Identification and contact information

  • name;
  • email address;
  • telephone number;
  • role;
  • team membership;
  • account identifiers.

Property and operational information

  • property names;
  • addresses;
  • rooms;
  • checklist information;
  • assignments;
  • task descriptions;
  • instructions;
  • issue reports;
  • property-related content.

Work activity

  • checklist activity;
  • task completion information;
  • timestamps;
  • job start and finish times;
  • work duration;
  • operational status;
  • activity records.

Photos and media

  • proof-of-work photographs;
  • reference photographs;
  • issue photographs;
  • other media uploaded through the Service;
  • Personal Data incidentally visible within uploaded media.

Geolocation-related information Where location functionality is enabled:

  • device latitude and longitude;
  • estimated location accuracy;
  • distance from a property;
  • on-site or off-site validation status;
  • time of location checks;
  • information relating to job start or finish;
  • activity or motion signals used in connection with on-site detection where applicable.

Technical information Where processed on behalf of the Customer:

  • device information;
  • application version;
  • IP address;
  • event logs;
  • technical and diagnostic information.

Customer-provided content

  • free-text content;
  • communications;
  • notes;
  • property instructions;
  • other information submitted by the Customer or its authorized users.

F. Special categories

The Service is not intended for routine processing of special categories of Personal Data.

Such information may nevertheless be incidentally included in photos, text, issue reports or other Customer-provided content.

The Customer determines whether such information may lawfully be processed through the Service.

G. Frequency

Processing occurs on a continuous or recurring basis according to the Customer's use of the Service during the term of the Agreement.

Annex II — Technical and organizational measures

SparkList maintains technical and organizational safeguards appropriate to the nature of the Service and the Personal Data processed.

These may include the following measures.

1. Data transmission security

  • HTTPS/TLS encryption for transmission of data between supported clients and SparkList systems;
  • secure communication protocols for production services;
  • controls intended to reduce unauthorized interception of information.

2. Access control

  • authentication mechanisms;
  • account-based access controls;
  • role-based permissions within the Service;
  • restriction of production-system access to authorized personnel;
  • removal or modification of access where no longer required.

3. Infrastructure security

  • professional cloud hosting infrastructure;
  • network and infrastructure security controls;
  • production environment access restrictions;
  • server and system monitoring;
  • security and software updates where appropriate.

4. Application security

  • authorization controls;
  • account and permission management;
  • technical measures designed to prevent unauthorized access to Customer accounts;
  • monitoring and remediation of technical errors and security issues.

5. Monitoring and diagnostics

  • server and application monitoring;
  • error and crash monitoring;
  • operational logs where appropriate;
  • investigation of suspicious or abnormal technical events.

6. Backup and availability

  • backup procedures appropriate to the Service;
  • measures intended to support recovery following technical failures;
  • infrastructure designed to support reasonable Service availability and continuity.

7. Organizational controls

  • access to Personal Data limited according to operational necessity;
  • confidentiality obligations applicable to authorized personnel;
  • internal handling procedures for Personal Data;
  • security awareness appropriate to personnel roles;
  • incident management and escalation procedures.

8. Data minimization and retention

  • Personal Data processed only where reasonably necessary for the relevant Service functionality;
  • ability to delete or remove certain Customer content through the Service where available;
  • retention and deletion procedures appropriate to the type of data and processing purpose.

9. Incident response

SparkList maintains procedures intended to:

  • identify potential security incidents;
  • investigate incidents;
  • limit unauthorized access where reasonably possible;
  • remediate identified vulnerabilities;
  • notify affected Customers where required by Applicable Data Protection Law.

10. Review of measures

SparkList may modify or improve these measures as technologies, risks and the Service evolve, provided that the overall level of protection is not materially reduced.