Spark Studio Ltd
Data Processing Agreement
Last updated: 27 July 2026 · Effective date: 27 July 2026
The short version
This summary is here so you know what you are agreeing to without reading the whole thing. It is not part of the agreement, and if it ever conflicts with the terms below, the terms below win.
- Your members' data is yours. You decide what happens to it, and we only do what you tell us.
- We never use it for our own purposes, we never sell it, and we never train AI models on it.
- We use a short list of other companies to help run Spark. They are named at sparkloyalty.co.uk/subprocessors, and you get 30 days' notice before that list changes.
- If member data is ever exposed, we tell you within 48 hours of finding out.
- If a member asks you for their data, or asks you to delete it, you can do both from your dashboard.
- When you leave, we keep everything for 90 days so you can come back or export it, then we delete it.
1. About this agreement
1.1 What it is
This Data Processing Agreement ("DPA") sets out the terms on which Spark Studio Ltd, trading as Spark Loyalty ("Spark", "we", "us", "our"), a company registered in England and Wales with company number 17267086 and registered office at 48 Crowestones, Buxton, England, SK17 6NZ, processes personal data on behalf of a merchant ("Merchant", "you", "your") who uses the Service.
1.2 How it fits with the Terms
This DPA forms part of the Terms of Service between you and Spark (the "Terms"), as clause 9.2 of the Terms provides. By accepting the Terms you accept this DPA. It takes effect on the date you first accept the Terms or, if later, the date you first use the Service, and it continues for as long as we process Member Data on your behalf.
Words and expressions defined in the Terms have the same meaning in this DPA unless this DPA says otherwise.
1.3 Which document takes precedence
Where this DPA conflicts with the Terms on any matter concerning the processing of Member Data, this DPA prevails. On every other matter the Terms prevail.
Where an Approved Transfer Mechanism conflicts with this DPA, the Approved Transfer Mechanism prevails to the extent of the conflict.
1.4 Signature
No signature is required for this DPA to bind both parties. If your own records or those of a client require a countersigned copy, email support@sparkloyalty.co.uk and we will provide one on these same terms.
2. Definitions
"Approved Transfer Mechanism" means a transfer mechanism recognised under Data Protection Laws as providing an adequate level of protection for a Restricted Transfer, including the IDTA, the UK Addendum, or a finding of adequacy in respect of the destination country.
"Data Protection Laws" means all laws relating to data protection and privacy that apply to a party, including the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications (EC Directive) Regulations 2003 ("PECR"), in each case as amended or replaced.
"IDTA" means the International Data Transfer Agreement issued by the Information Commissioner under section 119A of the Data Protection Act 2018.
"Member Data" means personal data relating to your Members that we process on your behalf through the Service, as described in Annex I.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Member Data.
"Restricted Transfer" means a transfer of Member Data to a country outside the United Kingdom, or an onward transfer within a chain of processing, which is subject to restriction under Data Protection Laws.
"Sub-processor" means any third party engaged by us to process Member Data on your behalf.
"UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, issued by the Information Commissioner.
"controller", "processor", "data subject", "personal data", "processing", "special category data" and "supervisory authority" have the meanings given to them in the UK GDPR.
3. Roles and responsibilities
3.1 Member Data
For Member Data, you are the controller and we are your processor. This DPA governs that processing.
3.2 Merchant account data
For personal data relating to you, your team and your business account, including your name, email address, business details, billing records and how you use the Service, we are the controller. That processing is not governed by this DPA. It is described in our Privacy Policy at sparkloyalty.co.uk/privacy.
3.3 Your obligations as controller
You confirm that, in relation to Member Data:
- you have a lawful basis under Data Protection Laws for the collection and use of the data, and for every instruction you give us;
- you have given your Members the privacy information required by Articles 13 and 14 of the UK GDPR, including telling them that a processor issues and maintains their card on your behalf;
- you have obtained any consent required under Data Protection Laws or PECR for the messages you send through the Service, and you honour withdrawals of consent and objections promptly;
- the data is accurate, and you have the right to transfer it to us for processing under this DPA; and
- your instructions to us will not put us in breach of Data Protection Laws.
3.4 Special category data and children
You must not submit special category data, criminal offence data, or payment card data to the Service. The Service is not designed for it and we do not apply the additional safeguards such data requires.
You are responsible for your own obligations towards Members under the age of 18, including any obligation to obtain consent from a person with parental responsibility.
3.5 Apple and Google
Apple and Google act as independent controllers in respect of what happens on a Member's own device, including whether a card is displayed on a lock screen and how wallet notifications are presented. They are not our Sub-processors for that activity, and their own terms and privacy policies apply to it.
3.6 No joint controllership
Nothing in this DPA makes the parties joint controllers in respect of Member Data.
4. Our obligations as processor
4.1 Documented instructions
We process Member Data only on your documented instructions, including in relation to Restricted Transfers, unless we are required to process it by law that applies to us.
Your documented instructions are:
- the Terms and this DPA;
- your use of the features of the Service, including creating cards, recording stamps, visits and points, selecting audiences, and sending messages;
- your configuration of the Service, including the settings you choose in your dashboard; and
- any further written instruction we agree with you in writing.
4.2 Instructions that would break the law
If we consider that an instruction from you infringes Data Protection Laws, we will tell you without undue delay, and we may suspend the processing concerned until the instruction is withdrawn, amended or confirmed.
4.3 Processing required by law
If we are required by law to process Member Data other than on your instructions, we will tell you before we do so unless that law prohibits us from telling you on important grounds of public interest.
4.4 Confidentiality
We ensure that every person we authorise to process Member Data is subject to a binding duty of confidentiality, whether contractual or statutory, and receives training appropriate to their role. That duty survives the end of their engagement with us.
4.5 We do not use Member Data for our own purposes
We do not use Member Data for any purpose other than providing the Service to you and meeting our obligations under this DPA. In particular we do not:
- sell, rent or licence Member Data to anyone;
- use Member Data for our own marketing, or contact your Members on our own initiative;
- combine Member Data with data we hold for another merchant; or
- use Member Data, or permit any Sub-processor to use it, to train, fine-tune or improve any artificial intelligence or machine learning model, whether ours or anyone else's.
4.6 Aggregated and anonymised data
We may create aggregated and anonymised statistical data from the operation of the Service, and use it to operate, secure, analyse and improve the Service and to produce industry insights. We only do this where the resulting data is genuinely anonymous, meaning that neither you, a Member nor any other individual can be identified from it, directly or indirectly, by us or by anyone else, taking account of all means reasonably likely to be used. Anonymous data of that kind is not personal data and is not Member Data.
We do not publish or share statistical data that identifies your business without your written permission, as clause 10.3 of the Terms provides.
5. Security
5.1 Technical and organisational measures
We implement and maintain the technical and organisational measures set out in Annex III, which are appropriate to the risk presented by our processing, having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing.
5.2 Changes to those measures
We may update the measures in Annex III as the Service and the threat landscape change. We will not make a change that materially reduces the overall level of security we provide.
5.3 Your own responsibilities
You are responsible for the security of the credentials used to access your account, for removing access when a member of your team leaves, and for the security of any Member Data once you have exported it from the Service.
6. Sub-processors
6.1 Your authorisation
You give us general written authorisation to engage Sub-processors to process Member Data, subject to this clause 6.
6.2 The current list
Our current Sub-processors, what each of them does, and where each of them processes Member Data, are published at sparkloyalty.co.uk/subprocessors. The Sub-processors authorised as at the effective date of this DPA are also set out in Annex II. Where the published list and Annex II differ, the published list is the current one.
6.3 Changes to the list
Before we add a Sub-processor, or replace one, we will give you at least 30 days' notice by updating the published list and by emailing the address on your account.
You may object to a change on reasonable grounds relating to data protection by emailing support@sparkloyalty.co.uk within 30 days of the notice. We will work with you in good faith to find a solution, which may include making the relevant feature available in a different way or not applying the change to your account.
If we cannot resolve your objection within 30 days, you may terminate the affected part of the Service, or the Terms in their entirety, by written notice, without penalty. We will refund any fees you have paid for a period after termination takes effect.
6.4 Terms with Sub-processors
We enter into a written contract with each Sub-processor that imposes obligations no less protective than those in this DPA, including the obligations required by Article 28(3) of the UK GDPR, and we only disclose the Member Data that Sub-processor needs to perform its role.
6.5 Our responsibility
We remain fully liable to you for the performance of each Sub-processor's data protection obligations.
7. Members' rights
7.1 Requests made to you
You can respond to a Member's request through the Service. Your dashboard allows you to search for a Member, view the data held for them, export your Member Data in a structured, commonly used and machine-readable format, correct a Member's details, and delete a Member and the data held for them.
7.2 Requests made to us
If a Member contacts us directly to exercise a right in respect of Member Data, we will not respond substantively. We will tell them that the business whose card they hold is the controller, forward their request to the email address on your account within five working days, and confirm to the Member that we have done so.
7.3 Further assistance
Taking into account the nature of the processing, we will provide reasonable assistance by appropriate technical and organisational measures, insofar as this is possible, to help you fulfil your obligation to respond to requests to exercise rights under Chapter III of the UK GDPR.
We provide this assistance at no charge, unless a request is manifestly unfounded or excessive, or requires significant engineering work beyond the tools described in clause 7.1, in which case we may charge a reasonable fee. We will tell you the fee before we do the work and give you the chance to withdraw the request.
8. Personal Data Breaches
8.1 Telling you
We will notify you of a Personal Data Breach without undue delay, and in any event within 48 hours of becoming aware of it, by emailing the address on your account.
8.2 What we will tell you
Our notification will describe, so far as we know at the time:
- the nature of the breach, including the categories and approximate number of Members and records concerned;
- the likely consequences of the breach;
- the measures we have taken or propose to take to address it and to mitigate its effects; and
- a contact point at Spark for further information.
Where we cannot provide all of that information at once, we will provide it in phases without undue delay.
8.3 Assistance
We will provide reasonable assistance to help you meet your own obligations under Articles 33 and 34 of the UK GDPR, including any obligation to notify the Information Commissioner or your Members.
8.4 Notification is not an admission
We will not notify the Information Commissioner or any Member on your behalf unless you instruct us to, or unless we are required to do so by law. Our notification to you is not an acknowledgement of fault or liability.
9. Data protection impact assessments
Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance to help you comply with your obligations under Articles 32 to 36 of the UK GDPR, including any data protection impact assessment and any prior consultation with the Information Commissioner.
We may charge a reasonable fee for assistance that goes beyond providing the information we already hold about the Service, on the same basis as clause 7.3.
10. International transfers
10.1 When we transfer
We may transfer Member Data outside the United Kingdom, including to the Sub-processors identified at sparkloyalty.co.uk/subprocessors, only where an Approved Transfer Mechanism is in place for that transfer, together with an assessment of the risks of that particular transfer and any supplementary measures that assessment shows to be necessary.
10.2 Mechanism between you and us
Where our processing of Member Data on your behalf involves a Restricted Transfer between you and us, the IDTA is incorporated into this DPA and takes effect between you as exporter and us as importer. Annex I completes the tables of the IDTA that describe the parties and the transfer, Annex II completes those that describe Sub-processors, and Annex III completes those that describe security measures.
10.3 Mechanism between us and Sub-processors
You authorise us, and appoint us as your agent for this limited purpose, to enter into an Approved Transfer Mechanism with each Sub-processor on your behalf, and to agree the details of the transfer described in it, in each case consistently with this DPA.
10.4 Copies
For the safeguards that apply to a particular Sub-processor or transfer, email support@sparkloyalty.co.uk and we will provide them.
11. Information and audits
11.1 Demonstrating compliance
We will make available to you all information reasonably necessary to demonstrate our compliance with Article 28 of the UK GDPR and this DPA.
11.2 How we do it first
You agree to rely, in the first instance, on the information we publish about the Service, on this DPA and its annexes, on our written responses to your reasonable questions, and on any third party audit reports, certifications or security documentation we or our Sub-processors make available.
11.3 On-site audits
If that information is not sufficient, you may audit our processing of Member Data, or appoint an independent auditor to do so, subject to the following:
- no more than once in any twelve month period, unless required by a supervisory authority or following a Personal Data Breach affecting your Member Data;
- on at least 30 days' written notice;
- during our normal business hours, and in a manner that does not disrupt the Service or the confidentiality of other merchants' data;
- the auditor must not be a competitor of ours, and must enter into a confidentiality agreement with us before the audit begins; and
- you bear your own costs and ours, unless the audit reveals a material breach of this DPA by us, in which case we bear our own.
11.4 Confidentiality of findings
Everything disclosed during an audit is our confidential information, and may be used only to assess our compliance with this DPA.
12. Return and deletion
12.1 While your account is open
You may export your Member Data from your dashboard at any time.
12.2 When your account closes
We retain Member Data for 90 days after your account closes, so that you can return to the Service or export your data, and we then delete it. This is the retention period described in clause 12.4 of the Terms and in our Privacy Policy.
12.3 Earlier deletion
You may instruct us in writing to delete Member Data earlier, and we will do so within 30 days of your instruction.
12.4 Backups
Member Data may persist in encrypted backups after deletion from our live systems. It remains subject to this DPA and is not restored or otherwise processed, and it is deleted in the ordinary course of our backup rotation, within 90 days of deletion from the live systems.
12.5 Where we must keep it
We may retain Member Data where we are required to do so by law that applies to us. Where we do, we will tell you what we are retaining and why, we will retain only what that law requires, and we will continue to protect it in accordance with this DPA.
12.6 Certification
On your written request, we will confirm in writing that deletion has taken place.
13. Liability
This DPA is subject to clause 13 of the Terms. The limits and exclusions of liability in clause 13 of the Terms apply to all claims arising out of or in connection with this DPA, and to claims under the Terms and this DPA in aggregate rather than separately.
Nothing in this DPA limits or excludes either party's liability to a data subject or to a supervisory authority, or affects a data subject's rights under Data Protection Laws.
14. Term
This DPA takes effect as described in clause 1.2 and continues until we no longer process Member Data on your behalf. Clauses 4.4, 4.5, 11, 12 and 13 survive its termination.
15. Changes to this DPA
We may update this DPA to reflect a change in Data Protection Laws, in guidance from the Information Commissioner, in our Sub-processors, or in the Service.
Where a change is material we will email the address on your account at least 30 days before it takes effect. If you do not accept the change, you may cancel before it takes effect and clause 11.5 of the Terms applies. If you keep using the Service after that date, the updated DPA applies.
Changes to the list of Sub-processors are governed by clause 6.3 rather than this clause.
16. General
16.1 Governing law and jurisdiction
This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction over any dispute arising out of or in connection with it.
16.2 Severability
If any part of this DPA cannot be enforced, the rest of it still applies.
16.3 Third party rights
Nobody other than you and us has any right to enforce this DPA, except where an Approved Transfer Mechanism incorporated into it confers rights on a data subject, in which case those rights are enforceable as that mechanism provides.
17. Contact
Spark Studio Ltd, trading as Spark Loyalty
48 Crowestones, Buxton, England, SK17 6NZ
Annex I — Details of the processing
A. The parties
Controller (data exporter): the Merchant, being the business that holds the Spark account under which the Member Data is processed. The Merchant's identity and contact details are those recorded in its Spark account.
Processor (data importer): Spark Studio Ltd, trading as Spark Loyalty, 48 Crowestones, Buxton, England, SK17 6NZ. Contact: support@sparkloyalty.co.uk.
B. Description of the processing
Subject matter. The provision of the Service, being digital loyalty cards issued to Apple Wallet and Google Wallet on the Merchant's behalf, together with the recording of progress towards rewards, reporting on that progress, and the sending of wallet notifications that the Merchant approves.
Duration. For as long as the Merchant's account is open, and for the 90 day period after it closes described in clause 12.2.
Nature of the processing. Collection, recording, organisation, structuring, storage, retrieval, consultation, use, alteration, disclosure by transmission to Apple and Google for delivery of the card to a Member's wallet, restriction, erasure and destruction, in each case by automated means.
Purpose of the processing. To issue and maintain the Merchant's loyalty cards, to record stamps, visits, points, rewards earned and rewards claimed, to show the Merchant how often its Members return, to group Members into audiences the Merchant selects, and to send wallet notifications the Merchant has composed or approved.
Categories of data subject. Members, being customers of the Merchant who hold one of the Merchant's Spark loyalty cards.
Types of personal data.
- A random, unguessable identifier for the card, which is not derived from and cannot be reversed into a name, an email address or a device identifier.
- The identifier assigned to the card by Apple or Google, used to keep the card up to date.
- Stamps, visits or points collected, rewards earned, rewards claimed, and the date of the most recent visit.
- A first name, where the Merchant holds one and has chosen to use it. Not required to hold a card.
- An email address, where the Merchant holds one and has chosen to use it. Not required to hold a card.
- Technical and security logs relating to the issue, update and scanning of the card.
Special category data. None. The Merchant must not submit special category data, criminal offence data or payment card data to the Service.
Location data. None. Spark does not collect, receive or store any Member's location. Where the Merchant enables lock screen relevance, the Merchant's own trading locations are included in the card and the decision whether to display it is made on the Member's device by Apple or Google.
Payment data. None. Spark is not a payment system and does not receive transaction, spend or payment method data. Where the Merchant operates a points card, the Merchant or its team enters an amount and only the resulting points figure is stored.
Frequency of the transfer. Continuous, for the duration of the processing.
Retention period. As set out in clause 12 of this DPA.
Processing by Sub-processors. As set out in Annex II, for the duration of this DPA unless the relevant Sub-processor is removed from the published list.
Annex II — Authorised Sub-processors
The Sub-processors authorised to process Member Data as at the effective date of this DPA are set out below. The current list, which prevails over this Annex, is published at sparkloyalty.co.uk/subprocessors.
| Sub-processor | What it does with Member Data | Where it processes |
|---|---|---|
| Vercel Inc. | Hosts the Spark dashboard and the application layer through which Member Data passes | United States |
| Supabase Inc. | Provides the database, file storage and authentication in which Member Data is stored | European Union |
| PassKit Limited | Issues loyalty cards to Apple Wallet and Google Wallet, and keeps them up to date | United States |
| Anthropic PBC | Drafts Push Agent message copy from the Merchant's instruction, chosen tone and business details. Does not receive Member records, names or email addresses, and does not train models on any data submitted | United States |
Suppliers who process personal data for which Spark is the controller, including Stripe for payments, Resend for email to Merchants, Google for website analytics and Microsoft for website analytics and session recording, are not Sub-processors of Member Data. They are described in our Privacy Policy and listed at sparkloyalty.co.uk/subprocessors.
Annex III — Technical and organisational measures
Access control
- Access to Member Data is granted on a least privilege basis, only to personnel who need it to perform their role, and is reviewed periodically and removed promptly when a role changes or ends.
- Administrative access to production systems requires multi-factor authentication.
- Merchant passwords are stored only as salted hashes and cannot be read by anyone at Spark.
- Database access is governed by row level security policies that isolate each Merchant's data from every other Merchant's data.
- Production credentials are held in a managed secrets store, are not committed to source control, and are rotated on personnel change and on suspicion of compromise.
Encryption
- All Member Data is encrypted in transit using TLS 1.2 or above.
- All Member Data is encrypted at rest using AES-256 or an equivalent standard.
- Card identifiers are random and unguessable, contain no personal data in themselves, and cannot be reversed into an identifier of any other kind.
System security
- Production, staging and development environments are separated, and Member Data from production is not used in development or testing.
- Dependencies are monitored for known vulnerabilities and patched on a risk-prioritised basis.
- Application and infrastructure logs are retained for 12 months and monitored for anomalous access.
- Server side rate limiting and abuse controls are applied to card scanning and to authentication endpoints.
Resilience and recovery
- Member Data is backed up automatically, and backups are encrypted at rest.
- Point in time recovery is available for the production database.
- Restoration procedures are tested periodically.
Organisational measures
- Every person authorised to process Member Data is bound by a written duty of confidentiality that survives the end of their engagement.
- Personnel receive data protection and security training appropriate to their role, on joining and periodically afterwards.
- Sub-processors are assessed before engagement and are bound by written terms no less protective than this DPA.
- A documented incident response procedure governs the identification, containment, assessment and notification of Personal Data Breaches, including the notification obligations in clause 8.
- Data protection by design and by default is applied to new features, including collecting the minimum data a feature needs and defaulting to the least intrusive setting.
Deletion
- Deletion of a Member removes the Member Data from live systems, and from backups within 90 days in the ordinary course of backup rotation.
- Account closure triggers the retention and deletion process described in clause 12.
Change log
- 27 July 2026. First published.