Data Processing Addendum
1. Purpose and Application
This Data Processing Addendum governs Spark Rack’s processing of Personal Data on behalf of a Customer when Customer acts as a controller or business and Spark Rack acts as a processor, service provider, or contractor under applicable Data Protection Law.
This Addendum forms part of the Terms of Service and applicable Order. It applies only to processing that falls within the described controller-processor relationship.
Spark Rack may act as an independent controller for Account administration, billing, fraud prevention, security, legal compliance, service improvement through non-AI methods, and other purposes described in the Privacy Policy.
2. Definitions
2.1 Customer Personal Data
Personal Data contained in Customer Data that Spark Rack processes on Customer’s behalf to provide the Services.
2.2 Data Protection Law
Applicable privacy, data-protection, and security laws governing the relevant processing, including the GDPR, UK GDPR, and applicable United States state privacy laws where they apply.
2.3 Data Subject
An identified or identifiable natural person to whom Personal Data relates.
2.4 Processing
Any operation performed on Personal Data, including collection, storage, transmission, access, organization, alteration, retrieval, disclosure, deletion, or destruction.
2.5 Subprocessor
A third party engaged by Spark Rack to process Customer Personal Data on Customer’s behalf.
2.6 Security Incident
A confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.
3. Roles of the Parties
Customer determines the purposes and essential means of processing Customer Personal Data and is the controller or business.
Spark Rack processes Customer Personal Data on Customer’s documented instructions and is the processor, service provider, or contractor for that processing.
Customer is responsible for determining whether these roles are accurate for Customer’s use of the Services.
4. Customer Instructions
Customer instructs Spark Rack to process Customer Personal Data as necessary to:
- Provide, maintain, secure, monitor, support, and administer the Services;
- Process Orders and Customer-requested changes;
- Transmit data according to Customer configuration;
- Create and restore backups where included;
- Prevent fraud and Abuse;
- Respond to support requests;
- Comply with applicable law; and
- Perform other processing documented in the Order or Customer’s lawful use of Service features.
Customer’s use and configuration of the Services constitute documented instructions. Additional instructions must be lawful, technically feasible, within scope, and agreed in writing.
5. Lawfulness of Instructions
Customer represents that Customer has all rights, notices, consents, contracts, and legal bases necessary for Customer Personal Data and instructions.
Spark Rack may suspend an instruction that Spark Rack reasonably believes violates Data Protection Law, the Terms of Service, security requirements, or another person’s rights, while the parties seek clarification.
Spark Rack will inform Customer when Spark Rack believes an instruction infringes applicable Data Protection Law unless prohibited from doing so.
6. Processing Details
The general processing details are:
| Element | Description |
|---|---|
| Subject matter | Provision of hosting, network, server, storage, backup, email, domain, DNS, support, monitoring, managed, and related Services selected by Customer. |
| Duration | For the Service term and any limited retention period required for deletion, backup rotation, legal compliance, security, or dispute resolution. |
| Nature | Collection, reception, hosting, storage, organization, transmission, retrieval, access, backup, restoration, deletion, security monitoring, and support. |
| Purpose | Providing and protecting the Services according to Customer’s instructions. |
| Data subjects | Customer personnel, users, customers, visitors, contacts, subscribers, recipients, senders, contractors, and other persons whose data Customer processes. |
| Data categories | Account and contact data, identifiers, communications, content, logs, device and network data, authentication data, transaction data, and other data Customer chooses to process. |
| Sensitive data | Only data Customer lawfully chooses to process and that the selected Service is appropriate and authorized to handle. |
7. Purpose Limitation
Spark Rack will process Customer Personal Data only to provide and protect the Services, follow documented instructions, exercise legal rights, or comply with law.
Spark Rack will not sell Customer Personal Data, share it for cross-context behavioral advertising, or retain, use, or disclose it outside the business relationship except as permitted by law and this Addendum.
8. Absolute Prohibition on AI and Model Training
Spark Rack will not use Customer Personal Data, Customer Content, support communications, logs, metadata, backups, or derived information to train, fine-tune, develop, test, evaluate, benchmark, improve, or operate artificial-intelligence or machine-learning models.
Spark Rack will not authorize Subprocessors to use Customer Personal Data for AI or model training.
De-identification, aggregation, tokenization, or pseudonymization does not create an AI-training exception.
9. Confidentiality
Spark Rack will ensure that persons authorized to process Customer Personal Data are subject to confidentiality obligations or an appropriate statutory duty of confidentiality.
Access will be limited according to role, need, authorization, and the Services provided.
10. Security Measures
Spark Rack will implement reasonable technical and organizational measures appropriate to the risk, nature of processing, available technology, cost, and applicable Service.
- Access controls and role-based permissions;
- Unique authentication credentials;
- Multifactor authentication where appropriate and supported;
- Encryption in transit and at rest where appropriate and supported;
- Network and system segmentation;
- Firewalls, rate limits, and protective filtering;
- Logging and monitoring;
- Patch and vulnerability management within Spark Rack’s scope;
- Backup and recovery processes where included;
- Incident-response procedures;
- Vendor review and contractual restrictions;
- Data minimization and retention controls;
- Personnel confidentiality and security practices; and
- Other measures appropriate to the Service.
No measure guarantees absolute security, availability, or data preservation. Customer must select, configure, and use Services appropriate to Customer’s risk.
11. Customer Security Responsibilities
Customer is responsible for:
- Secure Service configuration;
- User and administrator access;
- Password and key management;
- Multifactor authentication;
- Application security;
- Software updates within Customer’s scope;
- Data classification;
- Encryption choices;
- Independent backups;
- End User training;
- Lawful data collection;
- Privacy notices;
- Consent and legal basis;
- Data-subject request processes; and
- Compliance obligations specific to Customer’s industry and location.
12. Subprocessors
Customer provides general written authorization for Spark Rack to engage Subprocessors necessary to provide the Services.
Subprocessor categories may include data centers, network providers, cloud and storage providers, domain and certificate providers, payment processors, support systems, email delivery providers, security providers, monitoring providers, backup providers, software licensors, and professional advisers.
Spark Rack will impose data-protection obligations appropriate to the Subprocessor’s role and will remain responsible to Customer for Subprocessor performance to the extent required by applicable law.
13. Subprocessor Changes and Objections
Where required by applicable Data Protection Law, Spark Rack will provide reasonable notice of a new Subprocessor that will materially process Customer Personal Data.
Customer may object on reasonable documented data-protection grounds within the stated period.
The parties will attempt to resolve the objection through configuration, alternative Service, or other reasonable means. If no reasonable solution exists, Customer may discontinue the affected Service according to the applicable contract.
14. Data Subject Requests
Taking into account the nature of processing, Spark Rack will provide reasonable assistance through available Service features and support processes for Customer to respond to valid Data Subject requests.
If Spark Rack receives a request concerning Customer Personal Data, Spark Rack may direct the requester to Customer unless law requires Spark Rack to respond directly.
Customer is responsible for verifying requests, determining legal applicability, and providing instructions.
15. Security Incident Notice
Spark Rack will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data when notification is required by applicable Data Protection Law or this Addendum.
Notice may be provided in phases as information becomes available and may include:
- The nature of the incident;
- The affected Service and known data categories;
- The approximate time period;
- Known or likely consequences;
- Containment and remediation measures;
- Recommended Customer actions; and
- A contact method for follow-up.
Notice does not constitute an admission of fault or liability.
16. Customer Breach Responsibilities
Customer is responsible for determining whether Customer must notify Data Subjects, regulators, business partners, insurers, or other parties and for completing those notices.
Spark Rack will provide reasonable available information to support Customer’s assessment, subject to confidentiality, security, legal, and third-party restrictions.
17. Assistance With Compliance
Taking into account the nature of processing and information available, Spark Rack will provide reasonable assistance with Customer obligations concerning security, breach response, data-protection impact assessments, and prior consultation where required by applicable law.
Assistance beyond standard documentation and Service features may be billable and subject to a separate scope.
18. Deletion and Return
During the Service term, Customer may access, export, or delete Customer Personal Data through available Service features.
After termination, Spark Rack will delete or return Customer Personal Data according to the Terms of Service, Service capabilities, retention schedules, legal obligations, backup rotation, security needs, and Customer instructions.
Customer must export required data before cancellation. Spark Rack does not guarantee selective deletion from immutable or disaster-recovery backups before ordinary expiration where law permits delayed deletion.
19. Audits and Information
Spark Rack will make available information reasonably necessary to demonstrate compliance with applicable processor obligations.
Customer may request an audit when required by Data Protection Law, subject to:
- Reasonable advance notice;
- Confidentiality;
- Use of qualified independent auditors;
- No access to other Customers’ data;
- No interference with security or operations;
- Review of existing reports before intrusive inspection;
- Reasonable scope and frequency;
- Customer responsibility for costs unless a material breach is found; and
- Compliance with data-center and provider restrictions.
20. International Data Transfers
Customer acknowledges that processing may occur in the United States and other locations used to provide the Services.
When Customer Personal Data subject to the GDPR, UK GDPR, or similar law is transferred to a country requiring a transfer mechanism, the parties will use an applicable lawful mechanism, which may include adequacy decisions, approved standard contractual clauses, or another permitted safeguard.
Customer is responsible for identifying transfer requirements applicable to Customer’s use and requesting any required supplemental documentation.
21. Government and Legal Requests
Spark Rack will evaluate governmental requests according to applicable law and the Law Enforcement and Legal Request Guidelines.
Where legally permitted, Spark Rack may notify Customer before disclosure and may challenge or narrow requests that appear invalid, overbroad, or inconsistent with law.
Spark Rack may be prohibited from notifying Customer.
22. United States State Privacy Requirements
To the extent Spark Rack acts as a service provider, contractor, or processor under applicable state privacy law, Spark Rack will:
- Process Personal Data for the limited and specified purposes described in the contract;
- Not sell or share Personal Data for cross-context behavioral advertising;
- Not retain, use, or disclose Personal Data outside the direct business relationship except as permitted by law;
- Not combine Personal Data with unrelated information except as permitted by law;
- Provide the same level of privacy protection required by applicable law;
- Permit reasonable steps to verify compliance;
- Notify Customer if Spark Rack determines it can no longer meet an applicable obligation; and
- Allow Customer to take reasonable steps to stop and remediate unauthorized use.
23. Sensitive and Regulated Data
Customer must not process protected health information, payment-card data, criminal-justice data, government-classified information, export-controlled data, biometric templates, highly sensitive student data, or other specially regulated information unless the selected Service and written agreement expressly permit it.
This Addendum alone does not create HIPAA, PCI DSS, CJIS, FedRAMP, FERPA, GLBA, or other specialized compliance.
24. Data Accuracy and Minimization
Customer is responsible for the accuracy, relevance, proportionality, and minimization of Customer Personal Data.
Spark Rack does not review all Customer Content and cannot determine which data Customer should collect or retain.
25. Records of Processing
Each party will maintain records required by applicable Data Protection Law for its role.
Customer is responsible for documenting purposes, legal bases, Data Subjects, retention, recipients, and risk assessments for Customer’s processing.
26. Liability
Liability under this Addendum is subject to the limitations, exclusions, and remedies in the Terms of Service unless applicable Data Protection Law prohibits such limitation.
Nothing in this Addendum relieves either party of direct statutory obligations that cannot be contractually excluded.
27. Conflict and Order of Precedence
If this Addendum conflicts with the Terms of Service concerning processor obligations for Customer Personal Data, this Addendum controls for that subject.
A separately executed standard contractual clause or specialized data agreement controls only for the processing and transfer it addresses.
28. Termination
This Addendum remains in effect while Spark Rack processes Customer Personal Data on Customer’s behalf.
Confidentiality, deletion, security, liability, and other provisions that by nature should survive will continue after termination.
29. Contact
Data-protection questions and requests should be submitted through the privacy or legal channel in the Customer Portal.
Spark RackAttn: Data Protection and Privacy
PO Box 2215
Valdosta, GA 31604
United States
30. Acknowledgment
By using Spark Rack to process Personal Data on Customer’s behalf, Customer acknowledges that:
- Customer determines the purpose and legality of Customer processing.
- Spark Rack processes Customer Personal Data only for the Services, documented instructions, security, and legal compliance.
- Spark Rack does not sell Customer Personal Data or use it for AI or model training.
- Customer generally authorizes necessary Subprocessors subject to contractual protections.
- Security is shared and no measure guarantees absolute protection.
- Customer is responsible for Data Subject requests and legally required notifications.
- Specially regulated data requires a Service and agreement expressly designed for it.
- Customer must export needed data before termination.
- Additional audits, compliance assistance, or transfer documents may require separate scope and fees.