Effective September 5, 2026
Data Processing Addendum.
This Data Processing Addendum (“DPA”) forms part of the Actually Agentic terms between SparkGap LLC (“Processor”) and the customer organization that accepts those terms (“Customer”). It applies when SparkGap processes personal data on Customer’s behalf in providing the service.
1. Roles and instructions
Customer is the controller or business and SparkGap is the processor or service provider for Customer Data. SparkGap will process Customer Data only to provide, secure, support, and improve the contracted service; comply with documented instructions in the agreement and approved campaign configuration; or comply with law. Customer is responsible for lawful instructions, notices, permissions, and a valid basis for its outreach.
2. Processing details
- Subject: account administration, campaign planning, business-contact sourcing and verification, managed-domain and mailbox provisioning, message delivery, reply and complaint handling, billing, support, and security.
- Duration: the subscription term plus the deletion, safety, dispute, and legal-retention periods described in the agreement and Privacy Notice.
- Data subjects: Customer users, personnel at organizations selected by Customer, message recipients, correspondents, and support contacts.
- Data: identifiers and business contact details, account and role data, campaign instructions and content, source provenance, verification and engagement status, message and delivery metadata, replies, suppression signals, and billing identifiers.
- Operations: collection from Customer-authorized sources, validation, organization, storage, retrieval, transmission, suppression, restriction, deletion, and security monitoring.
3. Confidentiality and security
SparkGap will ensure personnel authorized to process Customer Data are bound by confidentiality obligations and will maintain appropriate technical and organizational measures. These include access control, least-privilege workload identities, encrypted transport and storage, hashed session and reset tokens, tenant isolation using PostgreSQL row-level security, protected backups, audit logging, dependency and image scanning, incident controls, and tested recovery procedures. Customer is responsible for its users, credentials, agent prompts, approved content, recipient selection, and endpoint security.
4. Subprocessors
Customer authorizes the subprocessors listed on the subprocessor page. SparkGap remains responsible for their processing to the extent required by applicable law and will impose data-protection obligations appropriate to the services they perform. SparkGap will post material additions before they begin processing Customer Data where required. Customer may object on reasonable data-protection grounds by emailing [email protected]; if the parties cannot resolve an objection, either may terminate the affected service.
5. Requests and assistance
Taking into account the nature of processing, SparkGap will reasonably assist Customer with verified data-subject requests, security obligations, impact assessments, and regulator consultations. If SparkGap receives a request concerning Customer Data, it will direct the requester to Customer unless law requires a direct response. Customer remains responsible for responding and for deciding whether data must be corrected, restricted, exported, suppressed, or deleted.
6. Security incidents
SparkGap will notify Customer without undue delay after confirming a breach of Customer Data, provide information reasonably available about its nature and likely consequences, describe mitigation, and cooperate with Customer’s legally required response. Notice is not an admission of fault or liability.
7. Return and deletion
On termination or a verified instruction, SparkGap will delete or return Customer Data within the documented offboarding process unless law permits or requires retention. Suppression, complaint, bounce, reply, billing, security, backup, and audit records may be isolated and retained only for safety, dispute, fraud-prevention, and legal purposes, then deleted under the applicable schedule. Data in protected backups ages out through the backup lifecycle and is not restored except for disaster recovery.
8. Territory and international transfers
The service is offered only to organizations in the United States and Canada, and only for outreach to recipients in those countries. Customer authorizes processing in the United States and Canada and in the locations listed for subprocessors, including address verification in the European Economic Area.
If a restricted transfer requires safeguards — including any transfer to a subprocessor outside those countries, or if SparkGap later agrees in writing to serve a Customer subject to such rules — the applicable controller-to-processor Standard Contractual Clauses are incorporated by reference, with Customer as exporter and SparkGap as importer; the processing description above and the security measures in this DPA form the relevant annexes. Any legally required UK addendum or successor mechanism also applies. A conflicting mandatory transfer term controls only for that transfer.
9. Demonstrating compliance
SparkGap will provide information reasonably necessary to demonstrate compliance and, no more than annually unless required after an incident or by a regulator, support an appropriately scoped audit. Audits must protect other customers, security, and confidential information, use existing independent reports first, avoid production disruption, and be at Customer’s cost unless an audit identifies a material breach by SparkGap.
10. Order of precedence
If this DPA conflicts with the general terms on processing Customer Data, this DPA controls. Liability and dispute terms in the agreement apply to this DPA except where applicable data-protection law prohibits them. Privacy questions and signed-DPA requests may be sent to [email protected].
