Data Processing Agreement
Art. 28 GDPR DPA for Sparks for Teams — Digitalzeit GmbH
This DPA is an integral part of the Terms and applies upon contract formation (registration, joining an organisation, or concluding a paid subscription). The German version is authoritative.
§ 1 Parties and subject matter
The processor is Digitalzeit GmbH, Speditionstraße 15a, 40221 Düsseldorf, Germany (HRB 29604), brand Sparks for Teams (“Processor”). The controller is the customer under the Terms (“Controller”).
The Processor processes personal data on behalf of the Controller insofar as it operates SaaS services (chat, meetings, files, calendar, account, optional AI) for the Controller. For self-host, this DPA applies only to the extent the Processor still sees personal data (in particular support, billing, telemetry, where agreed).
§ 2 Instructions
The Processor processes personal data only on documented instructions from the Controller, including with regard to transfers to a third country, unless required to do so by Union or Member State law. The Terms, this DPA, product configuration (organisation settings, integrations) and support tickets constitute instructions. Oral instructions must be confirmed by the Controller in text form without delay.
§ 3 Nature, purpose and duration
Nature: hosting and operating a collaboration platform (transmission, storage, display, optional recording, transcription and AI analysis). Purpose: performance of the Terms. Duration: term of the main contract plus statutory retention and the periods in § 3a.
§ 3a Retention (collaboration)
Where Digitalzeit stores data as processor, the following SaaS default periods apply. The Controller may instruct shorter or longer periods in text form where technically feasible. Sparks is not a medical archive; healthcare statutory periods are set by the Controller. Account, payment and website periods are in the privacy policy (controller role, not this DPA).
| Category | SaaS default | Enforcement |
|---|---|---|
| Live audio/video | Not stored | In transit only (LiveKit) |
| Recordings | Until Controller deletes, otherwise contract end; backups +30 days | Delete by host/org. Automatic day-limit job only on separate instruction (enterprise). |
| Transcripts / AI summaries | Until deleted or contract end | Only if enabled by the Controller. No model training. |
| Chat | Until deleted/redacted, otherwise contract end | Instance Matrix homeserver; E2EE keys on devices |
| Files | Until deleted; otherwise connected-store policy | Controller WebDAV/Nextcloud: their DPA and periods |
| Metadata (attendance, call log) | Until contract end or entry deleted | Consent enforcement 180 minutes; audit until contract end |
| Calendar (Sparks Cloud) | 3 years after event end; invitation tokens 30 days | Automated job, configurable |
Special categories (Art. 9 GDPR, e.g. health data in meetings) are processed only insofar as the Controller places them in the service and has an Art. 9 legal basis. A supplementary agreement (TOMs, access logging, shorter retention) may be concluded. Sparks is not a medical record.
§ 4 Data types and data subjects
- User master data (name, business email, organisation, roles)
- Communication content (chat, files, calendar entries)
- Meeting data (audio/video, attendance, optional recordings and transcripts)
- Technical logs (IP address, device/session data where required)
- Organisation billing data (via the payment provider)
Data subjects: the Controller’s employees and contractors, meeting guests, and other persons whose data the Controller places in the services.
§ 5 Processor obligations
- Confidentiality: persons authorised to process the data are committed to confidentiality (Art. 28(3)(b) GDPR).
- Security: appropriate TOMs under § 6 and Art. 32 GDPR.
- Assistance with data-subject rights (Art. 15–22) to the extent reasonable and technically feasible.
- Assistance with Art. 32–36 GDPR (security, breach notification, DPIA), against evidence of effort unless already included in the plan.
- No processing for the Processor’s own purposes and no training of general AI models on customer data.
§ 6 Technical and organisational measures
- TLS 1.2/1.3 in transit; encryption at rest where the respective system supports it
- Production access limited to authorised staff with 2FA
- ISO 27001-certified data centres of the hosting providers
- Daily encrypted backups, 30-day retention, for SaaS
- Optional end-to-end encryption for chat/meetings per organisation settings
- Privacy by default: camera and microphone off when joining a meeting
§ 7 Sub-processors
The Controller authorises the sub-processors below. Material changes will be notified with reasonable notice in text form (website or email). The Controller may object on important data-protection grounds; in that case the Processor may terminate the main contract ordinarily.
| Provider | Service | Location |
|---|---|---|
| IONOS SE | Hosting, optional AI | EU/DE |
| OVH GmbH / OVHcloud | Hosting, AI endpoints | EU |
| Hetzner Online GmbH | Hosting | DE |
| Stripe Payments Europe Ltd. / Stripe, Inc. | Payments, invoices, tax | IE / US if applicable (SCC/DPF) |
The Processor operates LiveKit, Keycloak and the Matrix homeserver itself on the EU infrastructure above; they are not separate sub-processors. Microsoft 365/Graph and mobile push (APNs/FCM) are optional customer services described in the privacy policy and are not automatically sub-processors under this DPA.
§ 8 Third countries
Core processing takes place in the EU/EEA. Where sub-processors or optional services transfer data to third countries (in particular Stripe group, Apple, Google), this is based on appropriate safeguards under Art. 46 GDPR (EU standard contractual clauses) and, where applicable, an adequacy decision or the EU-US Data Privacy Framework. Details: privacy policy.
§ 9 Breaches and deletion
The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach. Deletion and anonymisation follow § 3a, the Controller’s instructions and statutory retention. Export features, where offered in the product, remain available for a reasonable transition period.
§ 10 Evidence and audits
The Processor shall make available the information necessary to demonstrate compliance with Art. 28(3)(h) GDPR (in particular these TOMs and the sub-processor list). On-site audits are permitted with reasonable notice, during business hours and without disrupting operations where documentation is insufficient; costs are borne by the Controller unless a material defect attributable to the Processor is found.
§ 11 Liability, term, final provisions
Liability follows the Terms unless mandatory data-protection law requires otherwise. This DPA lasts for the main contract and thereafter for as long as data is still processed. Amendments require text form unless effected under the change mechanism in the Terms. German law applies. Venue as in the Terms. German prevails over the translation.
Last updated: 22 August 2026 · Digitalzeit GmbH
← Back to home