Privacy Policy

Your privacy is important to us. This policy explains how we collect, use, and protect your personal data in compliance with the GDPR.

Last Updated: January 8, 2025

Effective Date: January 8, 2025

1. Introduction

Spark IT GmbH ("we", "our" or "Spark IT GmbH") is committed to protecting and respecting your privacy. This privacy policy explains how we collect, use, share and protect your personal information when you visit our website or use our services.

This policy complies with the EU General Data Protection Regulation (GDPR) and applicable data protection laws. We regularly update this policy to reflect any changes in our practices or applicable legal requirements.

Data Controller Contact Information:
Data Protection Officer: privacy@sparkit-gmbh.com
Address: Adam-Opel-Straße 12, 48480 Spelle, Niedersachsen, Germany

2. Data We Collect

Personal Information

Name, email address, phone number, business address and other contact information you voluntarily provide.

Période de rétention : Retained for 3 years after last contact or until consent is withdrawn

Usage and Analytics Data

Information about how you use our website, including IP address, browser type, pages visited and time spent on the site.

Période de rétention : Anonymous analytics data retained for 26 months, IP data for 14 months

Technical Data

Information about your device, operating system, browser and network settings used to access our services.

Période de rétention : Retained for the session duration or up to 12 months for optimization

Communication Records

Records of your communications with us, including emails, live chat and phone calls for customer support purposes.

Période de rétention : Retained for 5 years for legal purposes and service improvement

3. How We Use Your Information

Legal Basis for Processing

We process your personal data based on the following legal grounds under the GDPR:

  • Consent (Article 6(1)(a)): For analytics cookies, marketing communications and optional services.
  • Contract Performance (Article 6(1)(b)): To provide the services you have requested and fulfill contractual obligations.
  • Legitimate Interest (Article 6(1)(f)): For website security, fraud prevention and business operations.
  • Legal Obligation (Article 6(1)(c)): To comply with legal requirements and regulatory obligations.

Processing Purposes

  • Provide and maintain our services
  • Respond to your inquiries and support requests
  • Send you technical notices and security alerts
  • Analyze website usage and improve user experience
  • Detect and prevent fraud and security threats
  • Comply with legal obligations and enforce our terms
  • Send marketing communications (with your consent)

4. Data Sharing and Disclosure

We do not sell, trade or rent your personal information to third parties. We may share your information in the following limited circumstances:

Third-Party Service Providers

Google Analytics

Website analytics and performance monitoring (only with your consent)

Data processing agreement in place, GDPR compliant

Email Service Providers

Transactional emails and communication delivery

EU-based providers with adequate data protection

Cloud Infrastructure

Secure hosting and data storage services

EU/EEA data centers with GDPR compliance

Legal Requirements

We may disclose your information if required by law, court order or government regulation, or to protect our rights, property or safety.

5. Your Rights Under the GDPR

Right to access your personal data
Right to rectification of inaccurate data
Right to erasure ('right to be forgotten')
Right to restrict processing
Right to data portability
Right to object to processing
Right to withdraw consent at any time
Right to lodge a complaint with a supervisory authority

How to Exercise Your Rights

To exercise any of these rights, please contact our Data Protection Officer:

privacy@sparkit-gmbh.com
Response within 30 days

6. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure or destruction:

Technical Measures

  • SSL/TLS encryption for data transmission
  • Encrypted data storage and backups
  • Regular security updates and patches
  • Access controls and authentication
  • Network security and firewalls

Organizational Measures

  • Staff training on data protection
  • Data processing agreements
  • Regular security assessments
  • Incident response procedures
  • Privacy by design principles

7. International Data Transfers

Your personal data is primarily processed within the European Economic Area (EEA). When we transfer data outside the EEA, we ensure adequate protection through:

  • European Commission adequacy decisions
  • Standard Contractual Clauses (SCCs)
  • Binding Corporate Rules (BCRs)
  • Certification schemes and codes of conduct

Google Analytics: Google Analytics: Data may be transferred to the US under Google's compliance with the EU-US Data Privacy Framework and Standard Contractual Clauses.

8. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Data Protection Officer
privacy@sparkit-gmbh.com
Adam-Opel-Straße 12, 48480 Spelle,
Niedersachsen, Germany
Supervisory Authority

You have the right to lodge a complaint with your local data protection authority if you believe we have not handled your personal data in accordance with the law.