Network Privacy Policy
1. Introduction
Spark Rack respects the privacy of its customers, prospective customers, authorized users, website visitors, support contacts, business representatives, and other individuals whose Personal Information is processed in connection with Spark Rack’s products, services, websites, customer portal, infrastructure, and network.
This Privacy Policy explains how Spark Rack collects, receives, accesses, uses, stores, protects, discloses, retains, and deletes Personal Information.
This Privacy Policy also explains the privacy rights and choices that may be available to individuals under Applicable Law.
Spark Rack is a service operated by Grand Bay Collective. References in this Privacy Policy to “Spark Rack,” “we,” “us,” or “our” include Grand Bay Collective, Spark Rack, the Spark Rack Network, and their respective personnel, contractors, service providers, successors, and permitted assigns, as applicable to the processing activity being described.
By creating an Account, submitting an Order, accessing the Customer Portal, visiting a Spark Rack website, communicating with Spark Rack, or using the Services, you acknowledge the practices described in this Privacy Policy.
2. Scope of This Privacy Policy
This Privacy Policy applies to Personal Information processed through or in connection with:
- Spark Rack websites;
- The Spark Rack Customer Portal;
- Account registration and administration;
- Orders, invoices, payments, credits, and refunds;
- Hosting services;
- Server and infrastructure services;
- The Spark Rack Network;
- Domain registration and domain-management services;
- DNS services;
- Email and messaging services;
- Backup and storage services;
- Security, monitoring, and managed services;
- Customer support;
- Legal, abuse, copyright, and security reports;
- Service-status and incident communications;
- Sales, quotations, and proposals;
- Business communications;
- Surveys or feedback submitted directly to Spark Rack;
- Applications for employment or contractor relationships submitted directly to Spark Rack;
- Physical or remote service administration;
- Service logs and operational records;
- Fraud prevention and identity verification;
- Compliance with legal obligations; and
- Any other interaction that expressly references this Privacy Policy.
This Privacy Policy does not govern independent websites, applications, platforms, products, or services operated by third parties, even when they are linked from or integrated with the Services.
This Privacy Policy does not replace a separate written data-processing agreement, business-associate agreement, employment privacy notice, contractor agreement, or other specialized privacy notice where one applies.
3. Definitions
3.1 “Account”
The customer account, client profile, billing account, administrative login, support profile, or other record through which a person or entity purchases, receives, accesses, or manages the Services.
3.2 “Applicable Law”
Any applicable federal, state, local, provincial, national, or foreign privacy, data-protection, consumer-protection, communications, cybersecurity, breach-notification, records-retention, or similar law, regulation, rule, binding order, or legally enforceable requirement.
3.3 “Customer”
The individual or legal entity that creates an Account, submits an Order, receives an invoice, enters into an agreement with Spark Rack, or otherwise obtains or controls the Services.
3.4 “Customer Content”
All files, databases, websites, applications, software, messages, emails, media, backups, credentials, records, configurations, logs, communications, and other data submitted to, stored on, transmitted through, or processed by the Services at Customer’s direction.
3.5 “Customer Data”
Customer Content and other information submitted to or generated through Customer’s use of the Services, excluding Spark Rack’s own billing, security, legal, administrative, and operational records.
3.6 “Customer Portal”
The electronic client account, billing, support, service-management, or administrative interface made available by Spark Rack.
3.7 “End User”
Any person or entity that accesses, receives, interacts with, or uses the Services through Customer, including Customer’s employees, representatives, contractors, customers, subscribers, tenants, website visitors, application users, mailbox users, and reseller clients.
3.8 “Personal Information”
Information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with an identified or identifiable individual or household.
Depending on Applicable Law, Personal Information may also be referred to as personal data, personally identifiable information, or a similar term.
Personal Information does not include information that Applicable Law excludes from the definition, such as certain publicly available, aggregated, or de-identified information.
3.9 “Processing”
Any action performed on Personal Information, including collecting, receiving, accessing, organizing, storing, using, transmitting, disclosing, securing, retaining, deleting, or otherwise handling the information.
3.10 “Sensitive Personal Information”
Personal Information considered sensitive under Applicable Law, which may include government identifiers, financial-account credentials, precise geolocation, health information, biometric information, racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration information, contents of certain communications, and information concerning children.
3.11 “Service Provider”
A contractor, processor, subprocessor, vendor, professional adviser, or other third party that processes Personal Information for a defined business purpose on behalf of Spark Rack and subject to appropriate restrictions.
3.12 “Services”
All hosting, server, network, domain, DNS, email, storage, backup, security, monitoring, management, support, consulting, infrastructure, software, and related services supplied by Spark Rack.
3.13 “Spark Rack Network”
The infrastructure operated, administered, controlled, leased, licensed, or arranged by Spark Rack, including servers, routers, switches, firewalls, storage systems, Internet connections, address space, transit, peering, DNS systems, monitoring systems, security systems, data-center connectivity, and upstream or downstream provider relationships.
4. Spark Rack’s Role in Processing Information
4.1 Spark Rack as a Business or Controller
Spark Rack generally acts as a business, controller, or similar responsible entity when it determines why and how Personal Information is processed for its own legitimate business purposes.
This includes Personal Information processed for:
- Account administration;
- Billing and payment management;
- Customer support;
- Service delivery;
- Service security;
- Fraud prevention;
- Legal compliance;
- Business communications;
- Contract management;
- Service improvement that does not involve artificial intelligence or model training;
- Internal administration; and
- Protection of Spark Rack, Customers, End Users, and third parties.
4.2 Spark Rack as a Service Provider or Processor
Spark Rack may act as a service provider, contractor, processor, or subprocessor when it processes Customer Data solely to provide Services according to Customer’s documented instructions.
Examples may include:
- Hosting Customer websites;
- Storing Customer databases;
- Transmitting Customer email;
- Maintaining Customer backups;
- Providing managed infrastructure;
- Processing Customer application traffic;
- Providing DNS services;
- Providing storage services;
- Providing server administration; and
- Performing Customer-requested restoration or migration work.
When Spark Rack acts as a processor or service provider, Customer is generally responsible for determining the lawful basis, notices, permissions, and instructions governing the processing of Personal Information contained in Customer Data.
4.3 Customer Responsibilities
Customers are responsible for:
- Providing legally required privacy notices to End Users;
- Obtaining legally required consent;
- Responding to End User privacy requests;
- Ensuring Customer Data is collected and processed lawfully;
- Configuring the Services appropriately;
- Limiting access to Customer Data;
- Protecting Customer credentials;
- Using appropriate encryption and security controls;
- Determining appropriate retention periods;
- Maintaining independent backups where appropriate;
- Entering into required data-processing agreements; and
- Complying with privacy, data-protection, communications, and consumer-protection laws applicable to Customer’s activities.
5. Privacy Principles
Spark Rack’s privacy practices are guided by the following principles:
- Collect Personal Information only for defined and legitimate purposes;
- Limit collection to information reasonably necessary for those purposes;
- Use Personal Information consistently with the reason it was collected;
- Do not sell or rent Personal Information;
- Do not share Personal Information for cross-context behavioral advertising;
- Do not use Personal Information or Customer Data for artificial-intelligence or machine-learning training;
- Do not authorize Service Providers, partners, or other third parties to use Personal Information or Customer Data for artificial-intelligence or model training;
- Restrict access according to business need;
- Retain Personal Information only for as long as reasonably necessary or legally required;
- Use reasonable administrative, technical, and physical safeguards;
- Provide transparency concerning material processing practices;
- Respect privacy rights required by Applicable Law; and
- Review privacy and security practices as the Services evolve.
6. Absolute Prohibition on Artificial Intelligence and Model Training
6.1 No Artificial Intelligence in Spark Rack Products or Services
Spark Rack does not use artificial intelligence, generative artificial intelligence, large language models, machine-learning models, neural networks, or similar model-based technologies as part of any Spark Rack product or Service.
Spark Rack does not use artificial intelligence to operate:
- The Customer Portal;
- Customer support;
- Billing;
- Account administration;
- Hosting services;
- The Spark Rack Network;
- Security administration;
- Domain services;
- DNS services;
- Email services;
- Backup services;
- Monitoring services;
- Managed services;
- Fraud review;
- Content review;
- Customer communications; or
- Any other Spark Rack product or Service.
6.2 No Use of Information for AI or Model Training
Spark Rack does not use Personal Information, Customer Data, Customer Content, support communications, account information, service telemetry, network information, logs, metadata, billing information, website activity, or any other consumer or customer information to train, fine-tune, develop, test, evaluate, benchmark, validate, improve, operate, or supply an artificial-intelligence or machine-learning model.
This prohibition includes use for:
- Model pretraining;
- Model training;
- Fine-tuning;
- Reinforcement learning;
- Retrieval-augmented generation;
- Embedding generation for model-based retrieval;
- Prompt processing;
- Prompt storage for model development;
- Model evaluation;
- Model benchmarking;
- Model testing;
- Model validation;
- Model safety training;
- Human review for model improvement;
- Data labeling for artificial intelligence;
- Creation of synthetic training data;
- Automated profiling;
- Automated recommendation systems;
- Predictive scoring;
- Behavioral classification;
- Emotion recognition;
- Facial recognition;
- Voice-model training;
- Image-model training;
- Generative-content systems; and
- Any substantially similar use.
6.3 No Third-Party AI Training Authorization
Spark Rack does not authorize, permit, license, sell, disclose, transfer, or otherwise make Personal Information or Customer Data available to any Service Provider, contractor, partner, affiliate, data broker, advertising provider, technology provider, or other third party for artificial-intelligence or machine-learning training.
Third parties processing information on Spark Rack’s behalf are not authorized to:
- Use the information to train an artificial-intelligence model;
- Use the information to improve a third-party model;
- Retain the information for model development;
- Use the information as prompts or model input for unrelated purposes;
- Generate embeddings for unrelated model systems;
- Perform model evaluation using the information;
- Use the information for data labeling;
- Use the information to create synthetic training data;
- Combine the information with another dataset for AI development;
- Sell or license the information to an AI developer;
- Use the information to create profiles or predictions; or
- Use the information for any purpose outside the limited service being provided to Spark Rack.
Spark Rack requires Service Providers to process Personal Information only for authorized purposes and subject to applicable confidentiality, security, use-limitation, and deletion requirements.
6.4 No AI-Based Automated Decisions
Spark Rack does not use artificial intelligence or machine-learning models to make decisions concerning:
- Account approval;
- Account suspension;
- Account termination;
- Pricing;
- Creditworthiness;
- Payment eligibility;
- Employment;
- Access to Services;
- Customer support priority;
- Fraud determinations;
- Legal compliance;
- Consumer eligibility;
- Service availability;
- Content moderation; or
- Any decision producing legal or similarly significant effects.
6.5 Rule-Based Automation Is Not Artificial Intelligence
Spark Rack may use traditional, deterministic, rule-based software automation to perform routine operations such as:
- Generating invoices;
- Processing scheduled renewals;
- Sending service notices;
- Applying defined firewall rules;
- Identifying known malicious signatures;
- Monitoring service availability;
- Measuring resource usage;
- Executing backups;
- Applying configured rate limits;
- Detecting repeated failed logins according to fixed rules;
- Provisioning Services;
- Processing domain-renewal schedules;
- Routing support tickets according to selected categories; and
- Performing other predefined operational tasks.
Such deterministic automation does not train, learn from, profile, infer characteristics from, or generate content from customer or consumer information.
6.6 Customer-Controlled AI Services
A Customer may independently choose to install, operate, connect, or host third-party artificial-intelligence software using Customer-controlled infrastructure.
Any such Customer-controlled use:
- Is not a Spark Rack product or Service;
- Is not endorsed by Spark Rack;
- Is controlled by Customer;
- Is subject to Customer’s own privacy obligations;
- Must comply with the Spark Rack Acceptable Use Policy;
- Must not expose Spark Rack information without authorization; and
- Does not alter Spark Rack’s prohibition against using Personal Information or Customer Data for Spark Rack or third-party AI training.
7. Categories of Personal Information Collected
The categories of Personal Information Spark Rack may collect depend on the Services used and the nature of the interaction.
7.1 Account and Identity Information
Spark Rack may collect:
- Full name;
- Business or organization name;
- Job title or role;
- Username;
- Customer identification number;
- Account identifiers;
- Date of birth when reasonably required for verification;
- Government-issued identification when reasonably required for identity, fraud, or legal verification;
- Authorized-user information;
- Account ownership information;
- Security questions and responses;
- Multifactor-authentication settings;
- Recovery information; and
- Records of identity or authority verification.
7.2 Contact Information
Spark Rack may collect:
- Email address;
- Telephone number;
- Mobile telephone number;
- Billing address;
- Mailing address;
- Business address;
- Country, state, province, city, and postal code;
- Emergency contact information;
- Technical contact information;
- Administrative contact information;
- Abuse contact information; and
- Contact preferences.
7.3 Billing and Transaction Information
Spark Rack may collect:
- Orders;
- Invoices;
- Payment status;
- Payment method type;
- Partial payment-card information;
- Payment tokens;
- Transaction identifiers;
- Billing history;
- Refund records;
- Credit records;
- Chargeback information;
- Tax status;
- Tax-exemption documentation;
- Currency information;
- Promotional-code usage;
- Account balances;
- Collections records;
- Fraud indicators; and
- Information needed to reconcile or dispute a payment.
Spark Rack does not intentionally store complete payment-card numbers or card-security codes in its ordinary systems when payment information is processed by an authorized payment processor.
7.4 Service and Subscription Information
Spark Rack may collect:
- Services ordered;
- Service identifiers;
- Service status;
- Provisioning information;
- Renewal dates;
- Cancellation requests;
- Resource allocations;
- Service configurations;
- Assigned IP addresses;
- Hostnames;
- Server names;
- Domain names;
- DNS settings;
- Email-service settings;
- Licensing records;
- Support-plan information;
- Service-location information;
- Migration information;
- Backup configuration;
- Monitoring configuration;
- Administrative contacts; and
- Other information needed to provide the selected Service.
7.5 Technical and Device Information
Spark Rack may collect:
- IP address;
- Device type;
- Operating system;
- Browser type and version;
- Language settings;
- Time-zone settings;
- Screen or device characteristics;
- Referring URL;
- Requested URL;
- Date and time of access;
- Session identifiers;
- Cookie identifiers;
- Authentication events;
- Login history;
- Failed-login history;
- Customer Portal activity;
- API activity;
- User-agent information;
- Network connection information;
- Error reports;
- Diagnostic information;
- Security-event information; and
- Other technical data generated through use of the Services.
7.6 Network and Infrastructure Information
Spark Rack may collect or generate:
- Source and destination IP addresses;
- Source and destination ports;
- Protocol information;
- Connection timestamps;
- Connection duration;
- Traffic volume;
- Network-flow records;
- Routing information;
- Firewall events;
- Authentication logs;
- Mail-delivery logs;
- DNS query or response metadata where operationally available;
- DDoS-mitigation events;
- Rate-limit events;
- Security alerts;
- Resource-usage information;
- Server-health information;
- Storage-health information;
- Backup-job status;
- Service uptime and availability data;
- Administrative actions;
- Configuration-change history;
- System-event records; and
- Other information reasonably required to operate and secure the Spark Rack Network.
Spark Rack does not routinely inspect the content of network communications. Limited inspection or packet capture may occur when reasonably necessary to troubleshoot a problem, investigate Abuse, mitigate an attack, respond to a security incident, comply with law, or protect the Services.
7.7 Customer Support and Communication Information
Spark Rack may collect:
- Support-ticket content;
- Email communications;
- Chat communications;
- Telephone-call notes;
- Voicemail messages;
- Uploaded files;
- Screenshots;
- Diagnostic reports;
- Log files;
- Error messages;
- Remote-support session information;
- Service requests;
- Customer feedback;
- Complaint information;
- Survey responses submitted directly to Spark Rack;
- Communications concerning billing, security, legal, or abuse matters;
- Internal notes concerning the support request; and
- Records of actions taken in response.
7.8 Domain Registration Information
When Customer obtains domain-related Services, Spark Rack may collect:
- Registrant name;
- Registrant organization;
- Registrant address;
- Registrant email address;
- Registrant telephone number;
- Administrative contact information;
- Technical contact information;
- Billing contact information;
- Domain name;
- Registration and expiration dates;
- Registrar and registry identifiers;
- Authorization codes;
- Transfer records;
- Verification records;
- Nameserver information;
- DNSSEC information;
- Domain-lock status;
- Renewal preferences;
- Privacy or proxy-service status; and
- Other information required by the applicable registrar or registry.
7.9 Security, Fraud, and Abuse Information
Spark Rack may collect or generate:
- Fraud indicators;
- Risk-review notes;
- Identity-verification records;
- Security alerts;
- Abuse complaints;
- Malware indicators;
- Phishing indicators;
- Spam complaints;
- Compromise indicators;
- Threat-intelligence indicators;
- Sanctions-screening results;
- Payment-risk information;
- IP reputation information;
- Domain reputation information;
- Login-risk indicators based on predefined rules;
- Records of enforcement actions;
- Records of Account restrictions;
- Communications with affected providers or authorities;
- Evidence submitted in connection with a complaint; and
- Information reasonably necessary to protect people, systems, or property.
7.10 Legal and Compliance Information
Spark Rack may collect:
- Legal notices;
- Subpoenas;
- Court orders;
- Warrants;
- Preservation requests;
- Copyright notices;
- Trademark complaints;
- Privacy complaints;
- Government inquiries;
- Regulatory communications;
- Dispute notices;
- Arbitration records;
- Insurance records;
- Compliance certifications;
- Records concerning legal holds;
- Information submitted by a complainant;
- Information concerning affected Customers or End Users; and
- Records of Spark Rack’s response.
7.11 Business Contact Information
Spark Rack may collect information concerning representatives of vendors, contractors, data centers, carriers, professional advisers, registrars, registries, payment providers, and other business relationships, including:
- Name;
- Business contact information;
- Job title;
- Employer;
- Professional communications;
- Contract information;
- Access information;
- Billing information;
- Security-verification information; and
- Records relating to the business relationship.
7.12 Employment and Contractor Applicant Information
When an individual directly submits an employment or contractor application, Spark Rack may collect:
- Name;
- Contact information;
- Employment history;
- Education history;
- Professional qualifications;
- Licenses and certifications;
- References;
- Work authorization information;
- Resume or curriculum vitae;
- Portfolio information;
- Interview notes;
- Compensation expectations;
- Availability;
- Background-check information where lawful and authorized;
- Information voluntarily provided by the applicant; and
- Records concerning the selection process.
7.13 Sensitive Personal Information
Spark Rack does not seek to collect Sensitive Personal Information unless it is reasonably necessary for a specific purpose.
Sensitive Personal Information may be processed when:
- Customer submits government identification for verification;
- Financial credentials are processed by an authorized payment provider;
- Customer provides legally relevant information in a support or legal request;
- Precise location is required for a specific service request;
- Customer voluntarily includes sensitive information in Customer Content;
- Information is required to investigate fraud, Abuse, or security incidents;
- Information is required by law; or
- Processing is otherwise authorized by the individual or Customer.
Spark Rack does not use Sensitive Personal Information to infer characteristics about individuals for advertising, profiling, artificial intelligence, or model training.
8. Sources of Personal Information
Spark Rack may obtain Personal Information from:
- The individual;
- Customer;
- Authorized users;
- End Users;
- Customer representatives;
- Resellers;
- Payment processors;
- Fraud-prevention providers;
- Identity-verification providers;
- Domain registrars and registries;
- Data centers;
- Network providers;
- Software licensors;
- Security providers;
- Support providers;
- Professional advisers;
- Public records;
- Publicly accessible websites;
- Government agencies;
- Law-enforcement agencies;
- Courts;
- Complainants;
- Copyright or trademark owners;
- Security researchers;
- Other service providers;
- Devices used to access the Services;
- Servers and systems interacting with the Spark Rack Network;
- Cookies and similar first-party technologies;
- System logs;
- Customer applications and configurations;
- Customer-authorized integrations; and
- Other sources permitted by Applicable Law.
9. How Spark Rack Uses Personal Information
9.1 Providing the Services
Spark Rack may use Personal Information to:
- Create and maintain Accounts;
- Authenticate users;
- Provision Services;
- Manage hosting, network, domain, DNS, email, storage, backup, and security Services;
- Configure Services;
- Process changes and upgrades;
- Process cancellations;
- Manage renewals;
- Provide licenses;
- Perform migrations;
- Perform backups and restorations;
- Provide monitoring;
- Perform Customer-requested administration;
- Communicate service status;
- Fulfill contractual obligations; and
- Otherwise provide the Services requested by Customer.
9.2 Billing and Payment
Spark Rack may use Personal Information to:
- Generate invoices;
- Process payments;
- Apply account credits;
- Issue refunds;
- Calculate taxes;
- Validate tax exemptions;
- Reconcile transactions;
- Address failed payments;
- Manage chargebacks;
- Collect overdue balances;
- Prevent payment fraud;
- Maintain financial records; and
- Comply with accounting and tax obligations.
9.3 Customer Support
Spark Rack may use Personal Information to:
- Respond to questions;
- Investigate technical issues;
- Troubleshoot Services;
- Verify Account ownership;
- Restore access;
- Perform remote support;
- Review logs or screenshots provided by Customer;
- Document solutions;
- Communicate concerning incidents;
- Provide service guidance;
- Escalate support requests;
- Train personnel using internal procedures that do not involve artificial-intelligence or model training;
- Maintain support history; and
- Improve support procedures through human review and traditional administrative analysis.
9.4 Security and Fraud Prevention
Spark Rack may use Personal Information to:
- Authenticate users;
- Enforce multifactor authentication;
- Detect suspicious login activity using predefined rules;
- Identify known malicious traffic;
- Prevent unauthorized access;
- Investigate compromised Accounts;
- Investigate phishing, malware, Spam, or other Abuse;
- Mitigate denial-of-service attacks;
- Protect the Spark Rack Network;
- Block known malicious sources;
- Enforce security policies;
- Verify identity or authority;
- Prevent payment fraud;
- Protect Customer Data;
- Preserve evidence of security incidents;
- Coordinate with affected providers;
- Respond to emergencies;
- Enforce the Terms of Service and Acceptable Use Policy; and
- Protect the rights, safety, systems, and property of Spark Rack, Customers, End Users, and third parties.
9.5 Communications
Spark Rack may use Personal Information to send:
- Account notices;
- Authentication notices;
- Billing notices;
- Invoice notices;
- Payment notices;
- Renewal notices;
- Expiration notices;
- Service-status notices;
- Maintenance notices;
- Security notices;
- Abuse notices;
- Policy updates;
- Legal notices;
- Support responses;
- Product or Service announcements;
- Customer-requested information; and
- Other communications reasonably related to the Account or Services.
9.6 Legal and Compliance Purposes
Spark Rack may use Personal Information to:
- Comply with law;
- Respond to valid legal process;
- Respond to governmental requests;
- Comply with tax and accounting obligations;
- Enforce agreements;
- Resolve disputes;
- Establish, exercise, or defend legal claims;
- Investigate suspected violations;
- Respond to copyright or trademark complaints;
- Respond to privacy requests;
- Meet records-retention requirements;
- Comply with sanctions and export restrictions;
- Protect legal rights;
- Respond to emergencies involving danger of death or serious physical injury; and
- Cooperate with legally authorized authorities.
9.7 Business Administration
Spark Rack may use Personal Information to:
- Maintain business records;
- Manage vendor relationships;
- Manage contracts;
- Conduct financial planning;
- Perform internal audits;
- Maintain insurance;
- Evaluate operational performance using non-AI methods;
- Plan capacity;
- Improve traditional workflows;
- Document procedures;
- Manage personnel;
- Protect business continuity;
- Evaluate a merger, acquisition, financing, restructuring, or sale; and
- Operate Spark Rack’s business.
9.8 Service Improvement Without AI
Spark Rack may use limited operational information to improve reliability, usability, documentation, support procedures, security, and service performance through:
- Human review;
- Traditional statistical reporting;
- Rule-based analysis;
- Aggregate capacity measurement;
- Error counting;
- Performance testing;
- Manual quality assurance;
- Configuration review;
- Incident postmortems;
- Customer-request analysis;
- Service-availability measurement; and
- Other non-AI administrative methods.
Spark Rack does not use service-improvement information for artificial-intelligence training, model development, behavioral advertising, or consumer profiling.
10. Legal Bases for Processing
Where Applicable Law requires Spark Rack to identify a legal basis for Processing, Spark Rack may rely on one or more of the following:
10.1 Performance of a Contract
Processing may be necessary to enter into or perform a contract, including to:
- Create an Account;
- Process an Order;
- Provide Services;
- Process payment;
- Provide support;
- Manage renewals;
- Process cancellation; and
- Communicate concerning the contractual relationship.
10.2 Legitimate Interests
Processing may be necessary for legitimate interests, including:
- Protecting the Services;
- Preventing fraud;
- Securing Accounts;
- Managing the Spark Rack Network;
- Responding to support requests;
- Maintaining business records;
- Improving non-AI operational processes;
- Protecting legal rights;
- Managing business relationships;
- Preventing Abuse;
- Planning capacity;
- Ensuring service reliability; and
- Operating Spark Rack’s business.
Where required, Spark Rack considers whether those interests are overridden by the rights and interests of the affected individual.
10.3 Legal Obligation
Processing may be necessary to comply with:
- Tax obligations;
- Accounting requirements;
- Legal process;
- Regulatory requirements;
- Sanctions requirements;
- Export controls;
- Data-breach requirements;
- Records-retention requirements;
- Consumer-protection requirements; and
- Other Applicable Law.
10.4 Consent
Spark Rack may rely on consent where legally required or appropriate. An individual may withdraw consent at any time, subject to legal and contractual limitations and without affecting Processing performed before withdrawal.
10.5 Protection of Vital Interests
Spark Rack may process Personal Information when reasonably necessary to protect a person’s life, physical safety, or other vital interests.
10.6 Establishment or Defense of Legal Claims
Spark Rack may process Personal Information when reasonably necessary to establish, exercise, investigate, or defend legal rights or claims.
11. Customer Content
11.1 Customer Control
Customer generally determines what Customer Content is submitted to or processed through the Services.
Spark Rack does not determine the contents of Customer websites, databases, mailboxes, applications, backups, or other Customer-controlled systems.
11.2 Limited Access
Spark Rack personnel may access Customer Content only when reasonably necessary to:
- Provide Customer-requested support;
- Perform managed services;
- Perform migrations or restorations;
- Investigate a security incident;
- Address suspected Abuse;
- Protect the Services;
- Comply with law;
- Respond to an emergency;
- Enforce applicable agreements; or
- Perform another authorized operational function.
11.3 No Ownership Claim
Spark Rack does not claim ownership of Customer Content.
Customer grants Spark Rack only the limited rights reasonably necessary to host, store, transmit, secure, back up, restore, migrate, and otherwise process Customer Content for the purpose of providing and protecting the Services.
11.4 No AI Use of Customer Content
Customer Content is never authorized for use in artificial-intelligence training, machine-learning training, model development, model evaluation, prompt processing, data labeling, synthetic-data creation, or any other AI-related purpose.
11.5 Customer Privacy Requests
When Spark Rack processes Personal Information solely on Customer’s behalf, an individual should ordinarily direct a privacy request to the applicable Customer.
When legally required and reasonably possible, Spark Rack will assist Customer in responding to verified privacy requests.
12. Cookies and Similar Technologies
12.1 Types of Cookies
Spark Rack may use first-party cookies and similar technologies that are reasonably necessary to:
- Maintain secure sessions;
- Authenticate users;
- Prevent cross-site request forgery;
- Remember language or interface preferences;
- Maintain shopping-cart or checkout state;
- Remember cookie preferences;
- Protect against fraud;
- Balance traffic;
- Maintain service continuity;
- Measure basic first-party service performance;
- Diagnose errors; and
- Provide requested website and Customer Portal functionality.
12.2 No Advertising Cookies
Spark Rack does not use third-party advertising cookies, behavioral-advertising pixels, data-broker tags, or cross-site tracking technologies to create advertising profiles.
12.3 No AI Processing of Cookie Information
Cookie, session, device, and website-usage information is not used or disclosed for artificial-intelligence or machine-learning training.
12.4 Browser Controls
Users may control cookies through browser or device settings. Blocking strictly necessary cookies may prevent parts of the website or Customer Portal from functioning correctly.
12.5 Do Not Track
Because Spark Rack does not use Personal Information for cross-context behavioral advertising, Spark Rack does not build advertising profiles in response to browser activity.
Browser “Do Not Track” settings may not operate consistently across browsers and websites. Spark Rack nevertheless limits tracking to the operational and functional purposes described in this Policy.
12.6 Global Privacy Control
Spark Rack does not sell Personal Information or share it for cross-context behavioral advertising.
Where Spark Rack receives a legally recognized Global Privacy Control or similar preference signal, Spark Rack treats the signal consistently with its existing practice of not selling or sharing Personal Information for targeted advertising.
13. Payment Information
Payments may be processed by an authorized payment processor.
When a payment processor is used:
- Payment-card information may be submitted directly to the processor;
- Spark Rack may receive a payment token rather than a complete card number;
- Spark Rack may receive payment status, card type, expiration information, billing address, partial card information, and transaction identifiers;
- The payment processor processes information under its own applicable privacy and security terms; and
- Spark Rack uses the received information to administer billing, refunds, disputes, fraud prevention, and financial records.
Spark Rack does not authorize payment processors to use Personal Information for artificial-intelligence or machine-learning training.
14. Domain Registration and Public Registration Data
Domain registration is subject to requirements imposed by registrars, registries, dispute-resolution providers, and applicable Internet-governance authorities.
Information required to register or manage a domain may be transmitted to:
- The applicable registrar;
- The applicable registry;
- Registry operators;
- Domain privacy or proxy providers;
- Escrow providers;
- Domain-dispute providers;
- Internet-governance authorities;
- Lawful requestors; and
- Other parties required to complete or maintain the registration.
Some domain-registration information may be made publicly available where required by applicable registration rules or where privacy or proxy services are not available or selected.
Customer is responsible for supplying accurate registration information and determining whether domain privacy or proxy services are appropriate.
Spark Rack does not authorize registrars, registries, or domain partners to use domain-registration information for artificial-intelligence or model training.
15. Email and Messaging Information
Spark Rack may process email and messaging metadata necessary to provide and secure messaging Services, including:
- Sender and recipient addresses;
- Message identifiers;
- Delivery timestamps;
- Delivery status;
- Bounce information;
- Spam-filter results;
- Malware-filter results;
- Authentication results;
- Sending IP address;
- Receiving IP address;
- Mailbox usage;
- Message size;
- Queue status;
- Complaint information; and
- Other information required for message delivery and security.
Message content may be processed or temporarily stored as required to transmit, filter, deliver, quarantine, back up, restore, or troubleshoot messages.
Spark Rack does not use message content or metadata for advertising, profiling, artificial-intelligence training, or machine-learning model development.
16. Support and Remote Access
When Customer requests support, Customer may provide Spark Rack with temporary credentials, screenshots, logs, files, or remote access.
Spark Rack will use such access only for authorized support, security, administration, migration, restoration, or troubleshooting purposes.
Customer should:
- Avoid including unnecessary Personal Information in support tickets;
- Avoid sending passwords through ordinary email;
- Use secure credential-sharing methods where available;
- Revoke temporary credentials after support is complete;
- Rotate credentials when appropriate;
- Remove unrelated sensitive information from logs or screenshots;
- Notify affected users before remote access where appropriate; and
- Maintain backups before material administrative work.
Support communications and materials are not used for artificial-intelligence or model training.
17. Monitoring and Network Security
Spark Rack may monitor systems and network activity to:
- Maintain availability;
- Measure resource usage;
- Detect known threats;
- Enforce rate limits;
- Prevent unauthorized access;
- Mitigate denial-of-service attacks;
- Troubleshoot technical issues;
- Investigate Abuse;
- Protect Customer Data;
- Maintain routing and network integrity;
- Respond to security incidents;
- Comply with legal obligations;
- Manage capacity; and
- Provide managed or monitored Services.
Security monitoring may include traditional signature-based detection, predefined rules, firewall controls, rate limits, authentication monitoring, resource thresholds, and human review.
Spark Rack does not use artificial intelligence or machine-learning models to monitor, classify, profile, or make decisions concerning customer or consumer activity.
18. How Spark Rack Discloses Personal Information
Spark Rack discloses Personal Information only as reasonably necessary for the purposes described in this Privacy Policy, as directed by Customer, or as required or permitted by Applicable Law.
18.1 Service Providers
Spark Rack may disclose Personal Information to Service Providers that assist with:
- Payment processing;
- Data-center operations;
- Network connectivity;
- Domain registration;
- DNS infrastructure;
- Email delivery;
- Software licensing;
- Storage;
- Backup infrastructure;
- Security services;
- Identity verification;
- Fraud prevention;
- Accounting;
- Tax administration;
- Legal services;
- Insurance;
- Auditing;
- Customer support infrastructure;
- Business communications;
- Shipping or delivery where applicable; and
- Other functions reasonably necessary to operate Spark Rack.
Service Providers are authorized to process Personal Information only for the defined service being provided and are not authorized to use Spark Rack information for their own artificial-intelligence or model-training purposes.
18.2 Customer and Authorized Users
Spark Rack may disclose Account or Service information to:
- The Account owner;
- Authorized users;
- Authorized Customer contacts;
- Customer administrators;
- Resellers responsible for the applicable Account;
- A successor Account owner following reasonable verification; and
- Other persons Customer directs Spark Rack to communicate with.
18.3 Registrars, Registries, and Internet Infrastructure Providers
Spark Rack may disclose information as reasonably necessary to provide domain, DNS, network, address-space, routing, certificate, or Internet-infrastructure services.
18.4 Legal and Governmental Disclosures
Spark Rack may disclose Personal Information when it reasonably believes disclosure is necessary to:
- Comply with valid legal process;
- Respond to a lawful governmental request;
- Comply with a court order;
- Comply with a subpoena or warrant;
- Comply with tax or regulatory obligations;
- Respond to an emergency involving danger of death or serious physical injury;
- Investigate or prevent fraud;
- Investigate or prevent Abuse;
- Protect rights, safety, property, systems, or data;
- Enforce Spark Rack’s agreements;
- Establish or defend legal claims;
- Comply with sanctions or export controls;
- Respond to child-safety concerns;
- Respond to intellectual-property complaints; or
- Otherwise comply with Applicable Law.
18.5 Business Transfers
Personal Information may be disclosed in connection with an actual or proposed:
- Merger;
- Acquisition;
- Financing;
- Reorganization;
- Restructuring;
- Sale of assets;
- Sale of a business unit;
- Transfer of Services;
- Bankruptcy;
- Receivership; or
- Similar business transaction.
A recipient of Personal Information in such a transaction will be expected to process the information consistently with applicable law and contractual obligations.
18.6 Professional Advisers
Spark Rack may disclose Personal Information to attorneys, accountants, auditors, insurers, financial advisers, consultants, and other professional advisers subject to appropriate duties of confidentiality.
18.7 With Consent or Direction
Spark Rack may disclose Personal Information when the individual or Customer requests, directs, or consents to the disclosure.
19. No Sale, Rental, or Behavioral Advertising
Spark Rack does not sell Personal Information.
Spark Rack does not rent Personal Information.
Spark Rack does not share Personal Information for cross-context behavioral advertising.
Spark Rack does not disclose Personal Information to data brokers.
Spark Rack does not exchange Personal Information for advertising, marketing profiles, or artificial-intelligence development.
Spark Rack does not use Personal Information for targeted advertising based on activity across unrelated websites, applications, or services.
20. Categories of Third Parties Receiving Information
Depending on the Services and circumstances, categories of recipients may include:
- Payment processors;
- Banks and financial institutions;
- Fraud-prevention providers;
- Identity-verification providers;
- Data-center providers;
- Network carriers;
- Transit providers;
- Peering partners;
- Domain registrars;
- Domain registries;
- DNS providers;
- Certificate authorities;
- Software licensors;
- Storage and backup providers;
- Email-delivery providers;
- Security providers;
- Monitoring providers;
- Customer-support infrastructure providers;
- Accounting providers;
- Tax advisers;
- Auditors;
- Insurers;
- Attorneys;
- Consultants;
- Government agencies;
- Courts;
- Law-enforcement agencies;
- Intellectual-property claimants;
- Emergency-response organizations;
- Successors in a business transaction;
- Customer-authorized recipients; and
- Other recipients permitted or required by Applicable Law.
No recipient is authorized by Spark Rack to use Personal Information or Customer Data for artificial-intelligence or model training.
21. Service Provider Requirements
Where appropriate, Spark Rack requires Service Providers to:
- Process Personal Information only for defined purposes;
- Follow Spark Rack’s documented instructions;
- Maintain confidentiality;
- Use reasonable security measures;
- Limit access to authorized personnel;
- Notify Spark Rack of relevant security incidents;
- Assist with privacy requests where required;
- Delete or return information when no longer required;
- Comply with Applicable Law;
- Not sell Personal Information;
- Not share Personal Information for targeted advertising;
- Not combine information for unauthorized purposes;
- Not retain information beyond the authorized purpose;
- Not disclose information to unauthorized third parties;
- Not use information for artificial-intelligence training;
- Not use information for machine-learning development;
- Not use information for model evaluation or improvement;
- Not use information for profiling;
- Not use information to create synthetic datasets; and
- Apply equivalent restrictions to authorized subprocessors.
22. De-Identified and Aggregated Information
Spark Rack may create limited aggregate or de-identified operational information for purposes such as:
- Capacity planning;
- Availability reporting;
- Resource measurement;
- Security reporting;
- Financial reporting;
- Incident analysis;
- Service planning;
- Performance measurement; and
- Internal business administration.
Spark Rack will not attempt to re-identify information represented as de-identified except when reasonably necessary to test whether de-identification controls are effective or as otherwise permitted by law.
Spark Rack does not use aggregated or de-identified Customer or consumer information for artificial-intelligence or machine-learning training.
23. Data Minimization
Spark Rack seeks to limit Personal Information to information reasonably necessary to:
- Provide Services;
- Maintain Accounts;
- Process payments;
- Protect security;
- Prevent fraud and Abuse;
- Comply with law;
- Resolve disputes;
- Maintain business records;
- Communicate with Customers; and
- Operate Spark Rack’s business.
Customers and users should avoid submitting unnecessary Personal Information, credentials, or Sensitive Personal Information through support tickets, email, or other communications.
24. Data Retention
Spark Rack retains Personal Information only for as long as reasonably necessary for the purposes described in this Privacy Policy, to satisfy legal or contractual requirements, to resolve disputes, to maintain security, and to enforce agreements.
Retention periods vary depending on:
- The nature of the information;
- The Service involved;
- The length of the Customer relationship;
- Contractual requirements;
- Security needs;
- Fraud-prevention needs;
- Backup cycles;
- Legal limitation periods;
- Tax and accounting obligations;
- Legal holds;
- Pending disputes;
- Applicable Law; and
- Technical deletion schedules.
24.1 General Retention Framework
| Category | General Retention Considerations |
|---|---|
| Account records | Retained while the Account is active and afterward as reasonably necessary for administration, disputes, fraud prevention, legal compliance, and enforcement. |
| Billing and transaction records | Retained for the period reasonably necessary to satisfy tax, accounting, payment, chargeback, audit, and legal obligations. |
| Support records | Retained as reasonably necessary to maintain service history, resolve recurring issues, document authorization, address disputes, and improve non-AI support procedures. |
| Security and authentication logs | Retained according to operational, security, incident-response, fraud-prevention, and legal requirements. |
| Network-flow and infrastructure logs | Retained for limited periods appropriate to troubleshooting, capacity management, security, Abuse prevention, and legal requirements. |
| Customer Content | Retained while required to provide the Service and deleted according to cancellation, termination, backup, and technical-deletion schedules. |
| Backup copies | Retained according to the applicable backup plan, rotation schedule, legal hold, and technical overwrite cycle. |
| Domain-registration records | Retained as required by registrars, registries, contractual obligations, domain-dispute requirements, and Applicable Law. |
| Legal and abuse records | Retained as reasonably necessary to document investigations, comply with law, protect rights, prevent repeat Abuse, and address legal claims. |
| Privacy-request records | Retained as reasonably necessary to document the request, identity verification, response, appeal, and legal compliance. |
| Applicant records | Retained for the applicable selection process and afterward as reasonably necessary for legal compliance, recordkeeping, or future consideration where permitted. |
24.2 Account Closure
Closing an Account does not necessarily result in immediate deletion of every record.
Spark Rack may retain information after Account closure when reasonably necessary to:
- Complete billing;
- Process refunds;
- Address chargebacks;
- Comply with tax requirements;
- Comply with legal obligations;
- Resolve disputes;
- Enforce agreements;
- Prevent fraud;
- Prevent repeat Abuse;
- Maintain security;
- Respond to legal process;
- Preserve records subject to legal hold; or
- Complete ordinary backup and deletion cycles.
24.3 Backup Retention
Deleted information may remain temporarily in backups, disaster-recovery systems, system snapshots, caches, logs, or residual storage until overwritten or removed through ordinary retention cycles.
Backup copies are not restored for ordinary operational use after deletion unless needed for disaster recovery, security, legal compliance, or another authorized purpose.
25. Deletion and Disposal
When Personal Information is no longer reasonably necessary, Spark Rack may delete, destroy, anonymize, aggregate, overwrite, or otherwise dispose of it using methods appropriate to the nature of the information and the systems involved.
Deletion may occur through:
- Database deletion;
- Account-record deletion;
- Cryptographic erasure;
- Secure overwrite;
- Media destruction;
- Backup expiration;
- Log rotation;
- Token revocation;
- Credential invalidation;
- De-identification; or
- Another reasonable technical or physical method.
26. Data Security
Spark Rack uses reasonable administrative, technical, and physical safeguards appropriate to the nature of the information and the Services.
Safeguards may include:
- Access controls;
- Role-based permissions;
- Unique administrative credentials;
- Multifactor authentication;
- Password-security requirements;
- Encryption in transit where supported;
- Encryption at rest where appropriate and supported;
- Network segmentation;
- Firewalls;
- Rate limiting;
- Malware filtering;
- Spam filtering;
- Security logging;
- Authentication logging;
- Patch management;
- Vulnerability management;
- Backup controls;
- Physical data-center controls;
- Vendor review;
- Confidentiality obligations;
- Incident-response procedures;
- Business-continuity procedures;
- Credential rotation;
- Secure disposal practices;
- Administrative review;
- Traditional signature-based threat detection;
- Rule-based monitoring;
- Human security review; and
- Other safeguards reasonably appropriate to the Services.
No method of transmission, storage, or security can guarantee absolute security. Spark Rack cannot guarantee that Personal Information will never be accessed, disclosed, altered, lost, or destroyed through malicious activity, human error, software failure, hardware failure, or events outside Spark Rack’s reasonable control.
27. Customer Security Responsibilities
Customers are responsible for:
- Using strong and unique passwords;
- Enabling multifactor authentication where available;
- Protecting credentials;
- Restricting administrative access;
- Removing access when no longer required;
- Securing Customer applications;
- Installing security updates;
- Maintaining appropriate firewalls;
- Configuring access controls;
- Encrypting sensitive Customer Data where appropriate;
- Monitoring Customer systems;
- Maintaining independent backups;
- Testing restoration procedures;
- Responding promptly to security notices;
- Rotating compromised credentials;
- Securing endpoints and devices;
- Obtaining appropriate user consent;
- Limiting Customer Data to what is necessary;
- Reviewing Customer-authorized integrations;
- Securing API keys and private keys;
- Not transmitting passwords through insecure channels;
- Not storing unnecessary Sensitive Personal Information;
- Reporting suspected compromise promptly; and
- Complying with the Terms of Service and Acceptable Use Policy.
28. Security Incidents and Data Breaches
Spark Rack maintains procedures for evaluating and responding to suspected security incidents.
Incident-response activities may include:
- Identifying affected systems;
- Containing the incident;
- Preserving relevant evidence;
- Investigating the cause;
- Assessing affected information;
- Resetting credentials;
- Revoking tokens or keys;
- Removing malicious access;
- Restoring systems;
- Coordinating with Service Providers;
- Notifying affected Customers;
- Notifying individuals where required;
- Notifying regulators or authorities where required;
- Documenting the response;
- Implementing corrective measures; and
- Reviewing safeguards following the incident.
Notifications will be provided when and as required by Applicable Law or contractual obligations.
Customers must promptly notify Spark Rack of suspected unauthorized access involving an Account or the Services.
29. International Processing and Transfers
Spark Rack is based in the United States and primarily provides Services from the United States.
Personal Information may be processed in the United States or another location where an authorized Service Provider operates.
When Personal Information is transferred from a jurisdiction requiring specific transfer safeguards, Spark Rack may rely on:
- Contractual transfer provisions;
- Standard contractual clauses;
- Data-processing agreements;
- Adequacy decisions;
- Consent where legally permitted;
- Performance of a contract;
- Legal necessity;
- Other recognized transfer mechanisms; or
- Another lawful basis permitted by Applicable Law.
Regardless of processing location, Spark Rack does not authorize Personal Information or Customer Data to be used for artificial-intelligence or model training.
30. Privacy Rights
Depending on residence, relationship with Spark Rack, and Applicable Law, an individual may have one or more of the following rights:
- The right to know whether Personal Information is being processed;
- The right to request access to Personal Information;
- The right to request categories of Personal Information collected;
- The right to request categories of sources;
- The right to request purposes of Processing;
- The right to request categories of recipients;
- The right to request specific pieces of Personal Information;
- The right to correct inaccurate Personal Information;
- The right to delete Personal Information;
- The right to obtain a portable copy of certain Personal Information;
- The right to restrict certain Processing;
- The right to object to certain Processing;
- The right to withdraw consent;
- The right to opt out of sale;
- The right to opt out of sharing for cross-context behavioral advertising;
- The right to opt out of targeted advertising;
- The right to opt out of certain profiling or automated decisions;
- The right to limit certain uses of Sensitive Personal Information;
- The right to appeal a denial of a privacy request;
- The right to use an authorized agent;
- The right to receive information concerning a data breach where required;
- The right to complain to an appropriate privacy or data-protection authority; and
- The right not to receive unlawful discriminatory treatment for exercising a privacy right.
These rights are subject to exceptions, limitations, identity-verification requirements, and applicability thresholds under relevant law.
31. Rights Spark Rack Does Not Need to Offer as an Opt-Out
Because Spark Rack does not sell Personal Information, there is no sale from which a consumer must opt out.
Because Spark Rack does not share Personal Information for cross-context behavioral advertising, there is no such sharing from which a consumer must opt out.
Because Spark Rack does not use Personal Information for targeted advertising, there is no targeted-advertising activity from which a consumer must opt out.
Because Spark Rack does not use artificial intelligence for profiling or decisions producing legal or similarly significant effects, there is no AI-based decision-making activity from which a consumer must opt out.
Because Spark Rack does not use Personal Information or Customer Data for model training, no AI-training opt-out is required; the information is not used for that purpose in the first instance.
32. Submitting a Privacy Request
A privacy request may be submitted through the appropriate privacy, legal, account, or support channel in the Spark Rack Customer Portal.
A request may also be mailed to:
Spark RackAttn: Privacy Request
PO Box 2215
Valdosta, GA 31604
United States
A request should include:
- The individual’s full name;
- The email address associated with the Account or interaction;
- The applicable Customer or Account information;
- The state, province, or country of residence;
- The specific right being exercised;
- A clear description of the requested information or action;
- Information reasonably necessary to locate relevant records;
- The preferred response method; and
- Authorized-agent documentation where applicable.
A person should not submit unnecessary government identifiers, passwords, private keys, complete payment-card information, or other sensitive credentials with a privacy request.
33. Verification of Privacy Requests
Spark Rack may take reasonable steps to verify:
- The requester’s identity;
- The requester’s relationship with Spark Rack;
- Ownership or control of the relevant Account;
- The requester’s authority to act for another person;
- The authenticity of supporting documentation;
- The scope of the request; and
- Whether disclosure would adversely affect another person’s privacy or security.
Verification methods may include:
- Confirmation through the Customer Portal;
- Confirmation through an Account email address;
- Confirmation using existing Account information;
- Multifactor authentication;
- Security questions;
- Transaction or service information;
- A signed declaration;
- Proof of authority; or
- Another reasonable method proportionate to the request.
Spark Rack may deny or limit a request when identity or authority cannot be reasonably verified.
34. Responding to Privacy Requests
Spark Rack will respond to verified privacy requests within the period required by Applicable Law.
Spark Rack may extend the response period where permitted and reasonably necessary due to complexity or volume.
Spark Rack may deny, limit, or charge a reasonable fee for a request where permitted by law, including when the request is:
- Manifestly unfounded;
- Excessive;
- Repetitive;
- Fraudulent;
- Impossible to verify;
- Likely to impair another person’s rights;
- Likely to compromise security;
- Subject to legal privilege;
- Inconsistent with a legal obligation;
- Inconsistent with a lawful retention requirement;
- Directed to information Spark Rack processes solely for Customer; or
- Otherwise exempt under Applicable Law.
When Spark Rack denies a request, Spark Rack will provide an explanation where required by law.
35. Authorized Agents
Where permitted by Applicable Law, an individual may authorize an agent to submit a privacy request.
Spark Rack may require:
- Written and signed authorization;
- Verification of the individual’s identity;
- Verification of the agent’s identity;
- Proof of the agent’s authority;
- Direct confirmation from the individual; or
- A valid power of attorney or equivalent legal authority.
Spark Rack may deny an agent request when authority cannot be reasonably verified.
36. Appeals
Where Applicable Law provides a right to appeal, an individual may appeal a denied privacy request through the same channel used to submit the original request.
The appeal should identify:
- The original request;
- The date of the response;
- The reason the requester believes the decision was incorrect; and
- Any additional supporting information.
Spark Rack will review and respond to the appeal within the period required by Applicable Law.
37. Non-Discrimination
Spark Rack will not unlawfully discriminate against an individual for exercising an applicable privacy right.
Subject to legal and contractual limitations, Spark Rack will not unlawfully:
- Deny Services;
- Charge a different price;
- Provide a different quality of Service;
- Retaliate against an individual;
- Threaten an individual; or
- Otherwise penalize an individual
because the individual exercised a privacy right.
Spark Rack may be unable to continue providing a Service when the requested deletion or restriction removes information reasonably necessary to provide that Service.
38. California Privacy Disclosures
38.1 Categories Collected
Depending on the relationship and Services used, Spark Rack may collect categories of Personal Information described under California law, including:
- Identifiers;
- Customer-record information;
- Commercial information;
- Internet or other electronic-network activity information;
- Geolocation information at a general level based on IP address;
- Professional or employment-related information;
- Audio, electronic, visual, or similar information submitted through support or business communications;
- Sensitive Personal Information when reasonably necessary for verification, payment, security, legal compliance, or Customer-directed Services; and
- Other information linked or reasonably linkable to an individual or household.
38.2 Business Purposes
Spark Rack may collect, use, or disclose these categories for:
- Providing Services;
- Processing transactions;
- Maintaining Accounts;
- Providing support;
- Maintaining security;
- Preventing fraud and Abuse;
- Debugging and troubleshooting;
- Maintaining service quality;
- Performing internal administration;
- Complying with law;
- Protecting legal rights;
- Managing business relationships; and
- Other purposes described in this Privacy Policy.
38.3 No Sale or Sharing
Spark Rack has not sold Personal Information and does not sell Personal Information.
Spark Rack has not shared Personal Information for cross-context behavioral advertising and does not share Personal Information for cross-context behavioral advertising.
Spark Rack does not have actual knowledge that it sells or shares the Personal Information of consumers under sixteen years of age.
38.4 Sensitive Personal Information
Spark Rack uses Sensitive Personal Information only for permitted operational, security, payment, verification, legal, and Customer-directed purposes.
Spark Rack does not use Sensitive Personal Information to infer characteristics about consumers.
Spark Rack does not use Sensitive Personal Information for advertising, profiling, or artificial-intelligence training.
38.5 California Rights
Subject to applicable exceptions, California consumers may have rights to:
- Know categories of Personal Information collected;
- Know categories of sources;
- Know business or commercial purposes;
- Know categories of recipients;
- Access specific pieces of Personal Information;
- Correct inaccurate Personal Information;
- Delete Personal Information;
- Opt out of sale or sharing;
- Limit certain uses of Sensitive Personal Information; and
- Receive equal service and pricing.
Spark Rack does not sell or share Personal Information and does not use Sensitive Personal Information to infer characteristics.
39. Other United States State Privacy Rights
Residents of certain United States states may have rights concerning:
- Access;
- Confirmation of Processing;
- Correction;
- Deletion;
- Data portability;
- Opt-out of sale;
- Opt-out of targeted advertising;
- Opt-out of certain profiling;
- Consent for certain Sensitive Personal Information;
- Appeal of a denied request; and
- Non-discrimination.
Spark Rack applies these rights when the applicable law covers Spark Rack, the individual, and the relevant Processing.
Spark Rack does not sell Personal Information, use Personal Information for targeted advertising, or use artificial intelligence for profiling or significant decisions.
40. European Economic Area, United Kingdom, and Switzerland
Individuals located in the European Economic Area, United Kingdom, or Switzerland may have rights to:
- Access Personal Information;
- Correct inaccurate Personal Information;
- Request deletion;
- Restrict Processing;
- Object to Processing;
- Receive certain Personal Information in a portable format;
- Withdraw consent;
- Object to direct marketing;
- Receive information concerning international transfers;
- Not be subject to certain solely automated decisions; and
- Submit a complaint to an applicable supervisory authority.
Spark Rack does not use artificial intelligence or solely automated model-based decision-making to produce legal or similarly significant effects.
When Spark Rack acts solely as Customer’s processor, the individual should ordinarily direct the request to Customer as the relevant controller.
41. Canadian Privacy Rights
Individuals in Canada may have rights, subject to Applicable Law, to:
- Request access to Personal Information;
- Request correction;
- Withdraw consent subject to legal or contractual limitations;
- Request information concerning Spark Rack’s privacy practices;
- Challenge compliance with applicable privacy principles; and
- Submit a complaint to an applicable privacy authority.
42. Children’s Privacy
The Services are not directed to children under thirteen years of age.
Individuals under eighteen years of age may not create an Account or purchase Services unless legally authorized and supervised by a parent, guardian, school, business, or other responsible organization permitted to enter into the applicable agreement.
Spark Rack does not knowingly collect Personal Information directly from a child under thirteen through a child-directed Service.
Spark Rack does not:
- Sell children’s Personal Information;
- Share children’s Personal Information for behavioral advertising;
- Use children’s Personal Information for targeted advertising;
- Use children’s Personal Information for artificial-intelligence training;
- Use children’s Personal Information for machine-learning model development; or
- Use artificial intelligence to profile children.
If Spark Rack learns that it collected Personal Information directly from a child in a manner prohibited by law, Spark Rack will take reasonable steps to delete the information or obtain legally sufficient authorization.
A parent or guardian who believes a child has provided Personal Information directly to Spark Rack may submit a privacy request using the contact information in this Policy.
Customer is responsible for determining whether Customer’s own websites, applications, or Services are directed to children and for complying with all applicable parental-consent, notice, deletion, security, and data-minimization requirements.
43. Communications and Marketing Preferences
Spark Rack may send transactional and service-related communications that are necessary to administer an Account or provide Services.
These communications may include:
- Invoices;
- Payment notices;
- Renewal notices;
- Expiration notices;
- Security alerts;
- Authentication notices;
- Maintenance notices;
- Service-status notices;
- Legal notices;
- Policy changes;
- Support responses;
- Abuse notices;
- Domain notices;
- Account notices; and
- Other operational communications.
Because these communications are necessary for the relationship, an individual may not be able to opt out of them while maintaining an active Account or Service.
Where Spark Rack sends optional promotional communications, recipients may unsubscribe using the method included in the message or through available Account preferences.
Unsubscribing from optional promotional communications does not stop transactional or service-related communications.
Communication information is not used for artificial-intelligence or model training.
44. Telephone, SMS, and Call Information
When an individual communicates with Spark Rack by telephone or SMS, Spark Rack may process:
- Telephone number;
- Call or message date and time;
- Call duration;
- Message content;
- Voicemail content;
- Delivery status;
- Support notes;
- Consent records where applicable; and
- Other information voluntarily provided.
Calls are not recorded unless notice or consent required by Applicable Law is provided.
Telephone, SMS, and call information is not used for voice-model training, speech-model training, artificial intelligence, or machine learning.
45. Social Media and Public Communications
Information posted publicly on social media, public forums, public reviews, or other public channels may be visible to Spark Rack and the public.
Spark Rack may process public communications to:
- Respond to questions;
- Address support matters;
- Protect Spark Rack’s rights;
- Investigate Abuse;
- Respond to misinformation concerning a specific Account or incident;
- Maintain business records; or
- Engage with the public.
Public communications should not contain passwords, private keys, payment-card information, Account-recovery information, or other sensitive credentials.
Spark Rack does not collect public communications for artificial-intelligence or model training.
46. Third-Party Websites and Services
The Services may contain links to or integrations with third-party websites or services.
Spark Rack does not control the privacy, security, content, or practices of independent third parties.
Users should review the applicable privacy policies and terms before providing Personal Information to a third party.
A link or integration does not mean Spark Rack authorizes the third party to use Spark Rack Personal Information or Customer Data for artificial-intelligence or model training.
47. Information Submitted to Third Parties by Customer
Customer may independently configure the Services to transmit Customer Data to third parties.
Examples may include:
- External email providers;
- External backup destinations;
- Analytics services;
- Content-delivery networks;
- Payment providers;
- Customer relationship platforms;
- Remote monitoring services;
- Security services;
- Software integrations;
- Webhooks;
- APIs;
- External storage;
- Customer-selected artificial-intelligence services; and
- Other Customer-controlled destinations.
Customer is responsible for reviewing and authorizing such integrations and for determining how the third party processes Customer Data.
Spark Rack’s prohibition on artificial-intelligence training applies to Spark Rack and parties processing information on Spark Rack’s behalf. Spark Rack cannot control a third party independently selected, configured, or instructed by Customer.
48. Employee and Contractor Access
Spark Rack limits personnel access to Personal Information according to role, responsibility, and legitimate business need.
Personnel with access may be required to:
- Maintain confidentiality;
- Use unique credentials;
- Use multifactor authentication;
- Follow access-control requirements;
- Use approved systems;
- Protect devices;
- Report security incidents;
- Avoid unnecessary copying;
- Avoid unauthorized disclosure;
- Follow secure disposal procedures;
- Use information only for authorized duties;
- Not submit Personal Information or Customer Data to public or private AI systems;
- Not use Personal Information or Customer Data for model training;
- Not use AI tools to review support tickets or Customer Content;
- Not use AI tools to generate decisions concerning Customers; and
- Return or delete information when access is no longer required.
49. Government and Law-Enforcement Requests
Spark Rack reviews governmental and law-enforcement requests for legal sufficiency and appropriate scope.
Where legally permitted and reasonably appropriate, Spark Rack may:
- Require valid legal process;
- Seek clarification;
- Challenge an overbroad request;
- Limit disclosure to responsive information;
- Notify Customer;
- Preserve relevant information;
- Document the request and response; and
- Seek reimbursement of legally recoverable costs.
Spark Rack may delay or withhold notice when notice is legally prohibited, would create a risk of harm, would compromise an investigation, or would be otherwise inappropriate under the circumstances.
50. Legal Holds
Spark Rack may preserve Personal Information beyond ordinary retention periods when it reasonably believes the information is relevant to:
- Pending or anticipated litigation;
- Arbitration;
- A governmental investigation;
- A security incident;
- An Abuse investigation;
- A preservation request;
- A legal claim;
- An insurance matter;
- A contractual dispute; or
- Another legally significant matter.
A legal hold may delay deletion until the hold is released.
51. Business Continuity and Disaster Recovery
Personal Information may be copied to backup, redundancy, disaster-recovery, or business-continuity systems.
Such copies are used only to:
- Restore systems;
- Recover from failure;
- Maintain service continuity;
- Protect against data loss;
- Respond to security incidents;
- Meet legal obligations; and
- Support authorized backup Services.
Backup and disaster-recovery information is not used for artificial-intelligence or model training.
52. Privacy by Design
When developing or modifying Services and business processes, Spark Rack may consider:
- Purpose limitation;
- Data minimization;
- Access controls;
- Retention limits;
- Deletion procedures;
- Security safeguards;
- Customer control;
- Transparency;
- Service Provider restrictions;
- Incident response;
- Legal compliance;
- Human oversight;
- Traditional non-AI operational methods; and
- The prohibition against artificial-intelligence and model-training use.
53. Accuracy of Personal Information
Customers and authorized users are responsible for keeping Account and contact information accurate and current.
Information may be updated through the Customer Portal or by submitting an appropriate support or privacy request.
Spark Rack may request verification before changing:
- Account ownership;
- Primary email address;
- Billing information;
- Authorized contacts;
- Domain registrant information;
- Multifactor-authentication settings;
- Recovery information; or
- Other security-sensitive information.
54. Information Spark Rack Does Not Intentionally Collect
Unless specifically required for an authorized purpose, Spark Rack does not intentionally request or collect:
- Complete payment-card security codes;
- Passwords for unrelated third-party accounts;
- Unnecessary Social Security numbers;
- Unnecessary government identifiers;
- Genetic information;
- Biometric templates;
- Precise geolocation unrelated to a Service;
- Medical records unrelated to a legal or accessibility request;
- Information concerning religious beliefs;
- Information concerning sexual orientation;
- Information concerning political affiliation;
- Private communications unrelated to the Services;
- Children’s Personal Information;
- Information for advertising profiles;
- Information for data brokerage;
- Information for artificial-intelligence training; or
- Information for machine-learning model development.
Individuals should not submit such information unless it is necessary for a specific authorized purpose.
55. Accessibility and Accommodation Information
When an individual requests an accessibility accommodation, Spark Rack may process information reasonably necessary to understand and provide the requested accommodation.
Spark Rack will limit use of such information to:
- Providing the accommodation;
- Communicating concerning the request;
- Documenting compliance;
- Protecting legal rights; and
- Meeting Applicable Law.
Accessibility information is not used for advertising, profiling, artificial intelligence, or model training.
56. Changes to This Privacy Policy
Spark Rack may update this Privacy Policy to reflect:
- Changes to the Services;
- Changes to privacy practices;
- Changes to Applicable Law;
- Changes to security requirements;
- Changes to Service Providers;
- Changes to business operations;
- Clarifications;
- New privacy rights;
- New operational requirements; or
- Other developments affecting the Processing of Personal Information.
The updated Policy will display a revised “Last Updated” date.
Spark Rack will provide additional notice of material changes when required by Applicable Law or reasonably appropriate under the circumstances.
Spark Rack will not change this Privacy Policy to authorize the use of Personal Information or Customer Data for artificial-intelligence or model training without providing clear advance notice and obtaining any consent required by Applicable Law. Spark Rack’s current policy and practice prohibit such use entirely.
57. Conflicts with Other Agreements
If a signed data-processing agreement or other specialized privacy agreement conflicts with this Privacy Policy, the signed agreement controls for the specific Processing it governs.
No agreement, Order, integration, or Service Provider arrangement authorizes the use of Personal Information or Customer Data for artificial-intelligence or model training unless Spark Rack expressly agrees in a separately signed written amendment that specifically identifies and modifies the prohibition in this Privacy Policy.
58. Contact Information
Questions, concerns, privacy requests, or complaints concerning this Privacy Policy may be submitted through the appropriate privacy, legal, account, or support channel in the Spark Rack Customer Portal.
Written correspondence may be mailed to:
Spark RackAttn: Privacy
PO Box 2215
Valdosta, GA 31604
United States
59. Customer and User Acknowledgment
By creating an Account, submitting an Order, accessing the Customer Portal, visiting a Spark Rack website, communicating with Spark Rack, or using the Services, Customer and each authorized user acknowledge that:
- They have been provided this Privacy Policy;
- They understand the categories of information Spark Rack may process;
- They understand the purposes described in this Privacy Policy;
- They understand that Spark Rack does not sell Personal Information;
- They understand that Spark Rack does not share Personal Information for cross-context behavioral advertising;
- They understand that Spark Rack does not use artificial intelligence in its products or Services;
- They understand that Spark Rack does not use Personal Information or Customer Data for artificial-intelligence or machine-learning training;
- They understand that Spark Rack does not authorize any Service Provider, partner, contractor, or third party to use Personal Information or Customer Data for artificial-intelligence or model training;
- They understand their responsibility to protect Account credentials and Customer Data;
- They understand that Customer is responsible for privacy compliance concerning Customer-controlled websites, applications, and End Users;
- They understand that privacy rights may be subject to verification and legal exceptions; and
- They may contact Spark Rack using the methods provided in this Privacy Policy.