Data Processing Agreement

Art. 28 GDPR DPA for Sparks for Teams — Digitalzeit GmbH

This DPA is an integral part of the Terms and applies upon contract formation (registration, joining an organisation, or concluding a paid subscription). The German version is authoritative.

§ 1 Parties and subject matter

The processor is Digitalzeit GmbH, Speditionstraße 15a, 40221 Düsseldorf, Germany (HRB 29604), brand Sparks for Teams (“Processor”). The controller is the customer under the Terms (“Controller”).

The Processor processes personal data on behalf of the Controller insofar as it operates SaaS services (chat, meetings, files, calendar, account, optional AI) for the Controller. For self-host, this DPA applies only to the extent the Processor still sees personal data (in particular support, billing, telemetry, where agreed).

§ 2 Instructions

The Processor processes personal data only on documented instructions from the Controller, including with regard to transfers to a third country, unless required to do so by Union or Member State law. The Terms, this DPA, product configuration (organisation settings, integrations) and support tickets constitute instructions. Oral instructions must be confirmed by the Controller in text form without delay.

§ 3 Nature, purpose and duration

Nature: hosting and operating a collaboration platform (transmission, storage, display, optional recording, transcription and AI analysis). Purpose: performance of the Terms. Duration: term of the main contract plus statutory retention and the periods in § 3a.

§ 3a Retention (collaboration)

Where Digitalzeit stores data as processor, the following SaaS default periods apply. The Controller may instruct shorter or longer periods in text form where technically feasible. Sparks is not a medical archive; healthcare statutory periods are set by the Controller. Account, payment and website periods are in the privacy policy (controller role, not this DPA).

Category SaaS default Enforcement
Live audio/video Not stored In transit only (LiveKit)
Recordings Until Controller deletes, otherwise contract end; backups +30 days Delete by host/org. Automatic day-limit job only on separate instruction (enterprise).
Transcripts / AI summaries Until deleted or contract end Only if enabled by the Controller. No model training.
Chat Until deleted/redacted, otherwise contract end Instance Matrix homeserver; E2EE keys on devices
Files Until deleted; otherwise connected-store policy Controller WebDAV/Nextcloud: their DPA and periods
Metadata (attendance, call log) Until contract end or entry deleted Consent enforcement 180 minutes; audit until contract end
Calendar (Sparks Cloud) 3 years after event end; invitation tokens 30 days Automated job, configurable

Special categories (Art. 9 GDPR, e.g. health data in meetings) are processed only insofar as the Controller places them in the service and has an Art. 9 legal basis. A supplementary agreement (TOMs, access logging, shorter retention) may be concluded. Sparks is not a medical record.

§ 4 Data types and data subjects

  • User master data (name, business email, organisation, roles)
  • Communication content (chat, files, calendar entries)
  • Meeting data (audio/video, attendance, optional recordings and transcripts)
  • Technical logs (IP address, device/session data where required)
  • Organisation billing data (via the payment provider)

Data subjects: the Controller’s employees and contractors, meeting guests, and other persons whose data the Controller places in the services.

§ 5 Processor obligations

  • Confidentiality: persons authorised to process the data are committed to confidentiality (Art. 28(3)(b) GDPR).
  • Security: appropriate TOMs under § 6 and Art. 32 GDPR.
  • Assistance with data-subject rights (Art. 15–22) to the extent reasonable and technically feasible.
  • Assistance with Art. 32–36 GDPR (security, breach notification, DPIA), against evidence of effort unless already included in the plan.
  • No processing for the Processor’s own purposes and no training of general AI models on customer data.

§ 6 Technical and organisational measures

  • TLS 1.2/1.3 in transit; encryption at rest where the respective system supports it
  • Production access limited to authorised staff with 2FA
  • ISO 27001-certified data centres of the hosting providers
  • Daily encrypted backups, 30-day retention, for SaaS
  • Optional end-to-end encryption for chat/meetings per organisation settings
  • Privacy by default: camera and microphone off when joining a meeting

§ 7 Sub-processors

The Controller authorises the sub-processors below. Material changes will be notified with reasonable notice in text form (website or email). The Controller may object on important data-protection grounds; in that case the Processor may terminate the main contract ordinarily.

Provider Service Location
IONOS SEHosting, optional AIEU/DE
OVH GmbH / OVHcloudHosting, AI endpointsEU
Hetzner Online GmbHHostingDE
Stripe Payments Europe Ltd. / Stripe, Inc.Payments, invoices, taxIE / US if applicable (SCC/DPF)

The Processor operates LiveKit, Keycloak and the Matrix homeserver itself on the EU infrastructure above; they are not separate sub-processors. Microsoft 365/Graph and mobile push (APNs/FCM) are optional customer services described in the privacy policy and are not automatically sub-processors under this DPA.

§ 8 Third countries

Core processing takes place in the EU/EEA. Where sub-processors or optional services transfer data to third countries (in particular Stripe group, Apple, Google), this is based on appropriate safeguards under Art. 46 GDPR (EU standard contractual clauses) and, where applicable, an adequacy decision or the EU-US Data Privacy Framework. Details: privacy policy.

§ 9 Breaches and deletion

The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach. Deletion and anonymisation follow § 3a, the Controller’s instructions and statutory retention. Export features, where offered in the product, remain available for a reasonable transition period.

§ 10 Evidence and audits

The Processor shall make available the information necessary to demonstrate compliance with Art. 28(3)(h) GDPR (in particular these TOMs and the sub-processor list). On-site audits are permitted with reasonable notice, during business hours and without disrupting operations where documentation is insufficient; costs are borne by the Controller unless a material defect attributable to the Processor is found.

§ 11 Liability, term, final provisions

Liability follows the Terms unless mandatory data-protection law requires otherwise. This DPA lasts for the main contract and thereafter for as long as data is still processed. Amendments require text form unless effected under the change mechanism in the Terms. German law applies. Venue as in the Terms. German prevails over the translation.

Last updated: 22 August 2026 · Digitalzeit GmbH

Terms · Privacy policy

← Back to home