Privacy Policy

Privacy PolicyThis Privacy Policy explains how Sparki processes personal data across the marketing site, dashboard, portals, plugin, API, billing, support, and enabled integrations. It distinguishes the data for which Sparki is controller from customer-workflow data processed on an organisation's behalf. This document is version 2 and was last updated on July 28, 2026.

Our role in processing

Sparki is operated by Decoders B.V., Tragelwest 55, 4507 JD Schoondijke, KVK 84779179. Contact: support@sparki.app.


Sparki is controller for personal data we process for our own website, account management, billing, support, security, product improvement, and legal obligations.


For data that realtors, property professionals, or owners process in Sparki as part of customer and project workflows, Sparki acts as processor on behalf of the realtor or organisation using Sparki. That user is responsible for providing its own privacy notice or other legal information to customers, candidates, and other data subjects.


Data that gets processed

Sparki processes your data because you’re using our services or choosing to provide your data by filling out our appointment form, subscribing to our newsletter, or signing up for our service.


Below, you will find an overview of the personal data that gets processed:


  • First name and last name
  • Email address
  • Phone number
  • Address
  • IP address
  • Location
  • Internet browser and device type
  • Account, company, billing, support, and security data
  • Appointment details, messages, workflow answers, offers, requests, and project or customer interaction data
  • Documents and files uploaded by customers, candidates, realtors, or other users

Purposes and legal bases

For account management, access to the service, appointments, project delivery, billing, and service messages, we process personal data to perform a contract or to take steps at your request before entering into a contract.


For support, security, fraud prevention, troubleshooting, and proportionate product improvement, we process limited data based on our legitimate interests in keeping Sparki reliable, secure, and useful. We balance those interests against the rights and expectations of the people concerned and do not use customer-workflow content for advertising.


Where we must retain or share data to comply with laws and regulations, we process that data based on a legal obligation. We send newsletters and marketing messages based on consent, unless the law allows another basis; you can unsubscribe at any time.


Personal data in realtor-customer workflows, such as customer profiles, contact details, documents, messages, appointment data, workflow answers, offers, and requests, is processed on behalf of the realtor or organisation using Sparki. That realtor or organisation determines the purpose and legal basis for the processing and must inform data subjects accordingly.


How long we hold on to your data

Sparki retains personal data no longer than necessary for the purpose for which it was collected, unless a longer retention period is legally required or needed to establish, exercise, or support legal rights.


Sparki is designed as temporary operational storage for real-estate customer workflows, not as a long-term legal, tax, Wwft, notarial, accounting, or business administration archive. Customer-uploaded documents and files are assigned a scheduled deletion date 180 days after upload by default, unless another configured retention period applies. Closed, cancelled, or completed projects are assigned a scheduled cleanup date 180 days after reaching that status; identifying data and linked customer interactions are then deleted or anonymized while non-identifying archive shells may remain. Existing historical data may receive a 30-day grace period during rollout.


Customer profiles and contact details are assigned a default deletion or anonymisation date 24 months after creation, unless continued lawful use, another configured retention period, or a legal hold applies. Realtors and other Sparki users are responsible for exporting, downloading, and storing any records they must retain outside Sparki for legal, tax, Wwft, notarial, accounting, or business administration purposes before automatic cleanup. After cleanup, Sparki may keep limited non-identifying interaction history and operational metadata, while personal details and documents are removed where no longer needed.


Recipients and processors

Sparki does not sell your data. We may use trusted service providers for hosting and infrastructure, database and cache services, file storage, email and communication delivery, analytics, payments and billing, customer support, security, fraud prevention, error monitoring, and integrations that a customer enables or asks us to connect to, such as calendar, video meeting, mapping, captcha, real-estate, payment, and AI/customer workflow integrations.


Where a provider acts as Sparki's processor or subprocessor, it processes personal data under documented instructions and appropriate confidentiality, security, and data-processing terms. Providers acting as independent controllers, including Google Maps for map and query data and Mollie for regulated payment processing, process data under their own applicable terms and privacy notices. Google Fonts handles font requests under Google's applicable privacy notice. Customer-enabled integrations may also process data under their own terms or as instructed by that customer.


International transfers

Some service providers or integrations may process personal data outside the European Economic Area. Where this happens, Sparki uses appropriate safeguards, such as EU Standard Contractual Clauses, adequacy decisions, or equivalent protections required by applicable data protection law.


Automated decision-making

Sparki does not use solely automated decision-making that has legal or similarly significant effects on individuals.


Cookies and similar techniques that we use

Sparki uses necessary technical and functional cookies for security, session management, login, and remembering basic settings. These cookies are needed for the website and service to work properly and are not used for advertising profiles.



Sparki does not currently use advertising cookies or non-essential marketing analytics on the marketing website. Session cookies expire after a limited period or when you log out. If non-essential analytics or advertising technology is introduced, Sparki will update this Policy and request consent where required before setting it.


Reviewing, correcting or deleting your data

You have the right to access/review, correct/rectify, delete/erase, object to processing, request restriction of processing, and ask for data portability where the AVG/GDPR allows this. You can also withdraw consent. Requests can be sent to support@sparki.app. We may ask for extra information to verify your identity; do not send an unredacted copy of your ID unless we specifically request it. If an ID is needed, we will ask you to hide details such as your photo, MRZ, document number, and social security number.


We respond without undue delay and normally within one month. Where the GDPR permits an extension for a complex or numerous request, we will tell you within the first month and explain why. You also have the right to lodge a complaint with the Autoriteit Persoonsgegevens, the Dutch supervisory authority, at autoriteitpersoonsgegevens.nl.


How we protect your data

Sparki takes the protection of your data seriously and takes appropriate measures to prevent misuse, loss, unauthorised access, unwanted disclosure, and unauthorised modifications. If you feel that your data is not appropriately protected or see indications of misuse, please contact us at support@sparki.app.


Where the data comes from

We receive personal data directly from account users and visitors, from people who use a Sparki portal or plugin, from the realtor or organisation that uses Sparki, and from integrations that the organisation chooses to connect. Where Sparki processes customer-workflow data on behalf of an organisation, that organisation remains responsible for telling the data subject about the original source and legal basis.


Service providers and recipients

Sparki limits each provider to the data needed for its function. Customer documents, messages, workflow answers, and customer profiles are intended to remain in the core Heroku PostgreSQL database and protected Amazon S3 storage unless a user deliberately sends them through an enabled integration.


  • Salesforce/Heroku — API hosting, managed PostgreSQL, managed Redis, application operation, and infrastructure logs. PostgreSQL stores account, portal, customer, project, workflow, appointment, message, document-metadata, and billing records. Redis holds short-lived sessions, cache entries, and queued operational data.
  • Amazon Web Services — protected S3 object storage for uploaded files and generated documents, and Simple Email Service (SES) for sending service email. SES receives sender, recipient, subject, message content, and delivery metadata needed to deliver and troubleshoot email.
  • Vercel — hosting and delivery of the Sparki marketing site and customer-facing frontends. Vercel processes requests, IP addresses, device/browser information, and content returned in transit, and may retain limited access and deployment logs.
  • Sentry — error and reliability monitoring. Sparki sends only technical error information, stack traces, release/environment details, and UUID-based internal business identifiers. Names, email addresses, phone numbers, message or document content, payment details, request bodies, user context, breadcrumbs, and other personal data are stripped before an event is sent.
  • Google — reCAPTCHA fraud and abuse prevention, Google Maps/address functionality, and Google Fonts on the marketing site. For reCAPTCHA, Google processes customer data as a processor under the Google Cloud terms. For Google Maps, Google acts as an independent controller under its applicable terms and privacy notice. Google Fonts requests are handled under Google's applicable privacy notice. Google may receive IP address, browser/device data, challenge signals, and map, address, or font requests. Google Meet is used only when an organisation enables that integration.
  • Mollie — payment processing and subscription billing. Mollie receives customer, payment, mandate, invoice-reference, and transaction information needed to process payments and meet financial-law obligations. Mollie also acts under its own legal obligations as a regulated payment provider.
  • Better Stack — availability and operational-job monitoring. Monitoring requests are limited to operational status, authentication data, internal record identifiers, and error metadata needed to detect failures; they are not intended to contain document, message, or workflow content.

Optional customer-directed integrations may include Google Meet, Zoom, Realworks, Kolibri, Mollie payment connections, OpenAI-compatible AI services, or a customer-configured email provider. They are used only when an organisation enables or configures them. The organisation is responsible for deciding that the integration is appropriate; Sparki sends only the data needed to perform the requested action.


Retention by system

  • Heroku PostgreSQL: customer-uploaded document records are assigned a scheduled deletion date 180 days after upload; closed, cancelled, or completed projects are assigned a scheduled cleanup date 180 days after reaching that status; customer profiles are assigned a default deletion or anonymisation date 24 months after creation, unless continued lawful use, another configured retention period, or a legal hold applies.
  • Amazon S3: protected uploaded files and generated documents follow the linked document or project deletion schedule. Deleted data may remain in encrypted backups until the provider's normal backup-expiry cycle completes.
  • Heroku Redis: sessions expire after a limited period (normally no more than seven days); cache and queue data is short-lived and is not the system of record.
  • Sentry, Heroku, Vercel, AWS SES, and Better Stack: diagnostic, access, delivery, and monitoring records are kept only for the retention period configured with that provider and are not used as the permanent customer record.
  • Mollie and Sparki billing records: retained for the period needed for payment, dispute, accounting, tax, fraud-prevention, and other legal obligations.

An organisation can request export, deletion, or return of its customer-workflow data. When the service ends, the Data Processing Agreement in the Terms governs deletion and return. Data that must be retained by law is isolated from ordinary use and deleted when that obligation ends.


International transfers

Sparki selects European hosting regions for the core application database and protected file storage where configured. Some providers operate internationally or provide support from outside the EEA. For restricted transfers, Sparki relies on an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful transfer mechanism, together with supplementary safeguards where required. A copy of the relevant safeguard can be requested at support@sparki.app, subject to necessary redactions.


Is providing data mandatory?

Account, authentication, and billing information marked as required is needed to create and administer an account or paid subscription. Information marked as required in a realtor's portal is determined by that realtor and is needed to submit the relevant appointment, request, offer, or workflow. Other fields are optional. If required data is not provided, the relevant account, transaction, or request cannot be completed.


Sparki is not intended for special-category personal data or criminal-offence data unless the organisation has first established a lawful basis, documented necessity, and appropriate safeguards with Sparki.