Data Processing Agreement.
Last updated September 15th, 2026
Article 28 UK GDPR and EU GDPR
This Data Processing Agreement (this "DPA") is entered into between:
- Spark Layer Ltd, a company registered in England and Wales with company number 12881913, whose registered office is at Trimbridge House, First Floor, Trim Street, Bath, BA1 1HB, United Kingdom ("SparkLayer", "we", "us"); and
- the merchant that holds a SparkLayer account and on whose behalf SparkLayer processes personal data (the "Customer", "you"),
each a "party" and together the "parties".
This DPA supplements and forms part of the agreement between the parties for the provision of the SparkLayer B2B ordering service (the "Agreement"). It records the terms on which SparkLayer processes personal data on the Customer's behalf, and is intended to satisfy Article 28(3) of the UK GDPR and of Regulation (EU) 2016/679 (the "EU GDPR").
How this DPA applies to you
This is SparkLayer's standard Data Processing Agreement. It is incorporated into our Terms of Service and applies automatically to every merchant whose customer data we process - there is nothing to sign. The effective date is the date you first installed SparkLayer or, if later, the date shown at the top of this page.
If your own compliance process needs a countersigned copy naming your legal entity, email contact@sparklayer.io with your company name, registered address, company number, SparkLayer site ID and a data protection contact, and we will return a signed PDF.
1. Definitions and interpretation
1.1 "Data Protection Law" means the UK GDPR, the EU GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and any other data protection or privacy law applicable to a party in respect of the Processing carried out under this DPA, in each case as amended or replaced from time to time.
1.2 The terms "controller", "processor", "data subject", "personal data", "personal data breach", "processing" and "supervisory authority" have the meanings given to them in Data Protection Law, and cognate terms are construed accordingly.
1.3 "Customer Personal Data" means personal data that SparkLayer processes on behalf of the Customer in the course of providing the Services, as described in Annex 1.
1.4 "Services" means the SparkLayer B2B ordering service provided under the Agreement.
1.5 "Sub-processor" means any third party engaged by SparkLayer to process Customer Personal Data.
1.6 References to "UK GDPR" are to Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018.
1.7 Where a provision of this DPA conflicts with a provision of the Agreement, this DPA prevails in respect of the subject matter of this DPA.
2. Roles of the parties
2.1 The Customer is the controller of the Customer Personal Data and SparkLayer is the Customer's processor in respect of it.
2.2 SparkLayer acts as a controller in respect of personal data relating to the Customer's own account holders, administrators and staff, and to the Customer's dealings with SparkLayer's sales and support teams. That processing is governed by the SparkLayer Privacy Policy and is outside the scope of this DPA.
2.3 Each party will comply with its own obligations under Data Protection Law in respect of the Processing described in this DPA.
3. Processing instructions
3.1 SparkLayer will process Customer Personal Data only on the Customer's documented instructions, including in relation to transfers of Customer Personal Data to a third country, unless required to process it by law to which SparkLayer is subject. Where SparkLayer is so required, it will inform the Customer of that legal requirement before processing, unless the law prohibits it from doing so on important grounds of public interest.
3.2 The Agreement, this DPA (including Annex 1) and the Customer's use of the configuration options made available within the Services constitute the Customer's complete documented instructions to SparkLayer. Any additional or alternative instruction must be agreed in writing between the parties.
3.3 SparkLayer will inform the Customer if, in its opinion, an instruction infringes Data Protection Law. SparkLayer is not obliged to carry out a legal review of the Customer's instructions.
3.4 SparkLayer will not sell Customer Personal Data, will not use it for its own purposes, and will not use it to build marketing or advertising profiles.
4. Confidentiality of personnel
4.1 SparkLayer will ensure that persons authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality, whether contractual or statutory, and that access is limited to those personnel who require it in order to provide the Services.
5. Security measures
5.1 Taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risks to individuals, SparkLayer will implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 of the UK GDPR and the EU GDPR.
5.2 The measures in place as at the date of this DPA are described in Annex 2. SparkLayer may update those measures from time to time, provided that it does not materially reduce the overall level of security of the Services.
6. Sub-processors
6.1 The Customer gives SparkLayer general written authorisation to engage Sub-processors in connection with the provision of the Services. The Sub-processors engaged as at the date of this DPA are listed in Annex 3.
6.2 SparkLayer will give reasonable prior notice of any intended addition or replacement of a Sub-processor by email to the Customer's registered account contact or through another notification mechanism made available within the Services, giving the Customer a reasonable opportunity to object on reasonable grounds relating to data protection.
6.3 Where the Customer objects on reasonable grounds and the parties cannot agree a resolution within thirty (30) days, the Customer may terminate the affected Services on written notice, without penalty, and SparkLayer will refund any prepaid fees for the period after termination.
6.4 SparkLayer will impose on each Sub-processor, by written contract, data protection obligations that are no less protective than those set out in this DPA, and remains fully liable to the Customer for the performance of each Sub-processor's obligations.
7. International transfers
7.1 Customer Personal Data stored within SparkLayer's primary production infrastructure is hosted in the United Kingdom, in Google Cloud's europe-west2 (London) region. Where Customer Personal Data is processed by an authorised Sub-processor outside those territories, the safeguards in clauses 7.2 to 7.4 apply.
7.2 Where SparkLayer or a Sub-processor transfers Customer Personal Data to a country outside the United Kingdom or the EEA, SparkLayer will ensure that an appropriate transfer mechanism is in place, being one or more of:
- (a) an adequacy decision or adequacy regulations covering the recipient country;
- (b) the standard contractual clauses approved by the European Commission under Implementing Decision (EU) 2021/914, for transfers subject to the EU GDPR;
- (c) the International Data Transfer Agreement, or the International Data Transfer Addendum to the EU standard contractual clauses, issued by the Information Commissioner under section 119A of the Data Protection Act 2018, for transfers subject to the UK GDPR; or
- (d) another transfer mechanism recognised under Data Protection Law,
in each case together with any supplementary measures required following a transfer risk assessment.
7.3 The transfer mechanism relied on for each Sub-processor is identified in Annex 3. SparkLayer will provide details of the safeguards in place on the Customer's written request.
7.4 Where the standard contractual clauses apply, the Customer is the data exporter and SparkLayer or the relevant Sub-processor is the data importer, Module Two or Module Three applies as appropriate, and Annexes 1, 2 and 3 to this DPA serve as the corresponding annexes to those clauses.
8. Assistance with data subject requests
8.1 SparkLayer will, taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests from data subjects exercising their rights under Chapter III of the UK GDPR or the EU GDPR.
8.2 If SparkLayer receives a request directly from a data subject in respect of Customer Personal Data, it will not respond to the substance of that request other than to direct the data subject to the Customer, and will promptly forward the request to the Customer.
9. Assistance with the Customer's wider obligations
9.1 SparkLayer will assist the Customer in ensuring compliance with the obligations set out in Articles 32 to 36 of the UK GDPR and the EU GDPR (security of processing, personal data breach notification, data protection impact assessments and prior consultation), taking into account the nature of the processing and the information available to SparkLayer.
10. Personal data breaches
10.1 SparkLayer will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.
10.2 The notification will describe, to the extent then known to SparkLayer, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Where the information cannot be provided at the same time, it will be provided in phases without undue further delay.
10.3 SparkLayer will take reasonable steps to contain and investigate the breach, and will cooperate with the Customer so that the Customer can meet its own notification obligations to supervisory authorities and data subjects.
10.4 SparkLayer's notification of a breach is not an acknowledgement of fault or liability.
11. Return and deletion
11.1 On termination or expiry of the Agreement, and at the Customer's choice, SparkLayer will delete or return all Customer Personal Data to the Customer, and will delete existing copies, unless the law to which SparkLayer is subject requires it to retain the data.
11.2 The Customer must make its choice within thirty (30) days of termination or expiry. In the absence of a choice within that period, SparkLayer will delete the Customer Personal Data.
11.3 Customer Personal Data held in routine backups will be deleted in accordance with SparkLayer's backup retention cycle, and will remain subject to the terms of this DPA until it is deleted.
12. Information and audit
12.1 SparkLayer will make available to the Customer all information reasonably necessary to demonstrate compliance with the obligations set out in Article 28 of the UK GDPR and the EU GDPR.
12.2 SparkLayer will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. The Customer will give at least thirty (30) days' written notice, will conduct any audit during normal business hours, and will not unreasonably disrupt SparkLayer's business. Audits are limited to once in any twelve (12) month period, save where required by a supervisory authority or following a personal data breach affecting Customer Personal Data.
12.3 SparkLayer may satisfy an audit request by providing its current security documentation, the results of any independent security assessment or penetration test, and written responses to the Customer's reasonable questions. Where that documentation reasonably addresses the Customer's request, no on-site inspection is required.
12.4 The Customer and its auditors must treat all information obtained through an audit as confidential, and must be bound by appropriate confidentiality obligations before the audit begins.
13. Customer obligations
13.1 The Customer warrants that it has a lawful basis for the processing it instructs SparkLayer to carry out, that it has provided all privacy information required by Data Protection Law to its own customers and other data subjects, and that its instructions to SparkLayer comply with Data Protection Law.
13.2 The Customer is responsible for the accuracy and quality of the Customer Personal Data it makes available to SparkLayer, and for the configuration choices it makes within the Services.
14. Liability
14.1 The liability of each party under or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Agreement.
15. Term
15.1 This DPA takes effect on the effective date (clause 17) and continues for as long as SparkLayer processes Customer Personal Data on the Customer's behalf. Clauses that by their nature should survive termination will do so.
16. Governing law and jurisdiction
16.1 This DPA is governed by the law that governs the Agreement, and the courts identified in the Agreement have exclusive jurisdiction, save that where the EU standard contractual clauses apply to a transfer, the governing law and forum provisions of those clauses apply to that transfer.
17. Acceptance
17.1 This DPA is accepted by the Customer on installing SparkLayer or otherwise entering into the Agreement, and by SparkLayer on publication. No signature is required for it to take effect.
17.2 Where the Customer requires a countersigned copy, the parties may execute this DPA in writing; the countersigned copy has the same terms and the same effective date as the published version, and the version published at www.sparklayer.io/data-processing-agreement/ on that date prevails in the event of any difference.
Annex 1 - Details of the processing
Subject matter. The provision of the SparkLayer B2B ordering service to the Customer under the Agreement.
Duration. For as long as the Customer uses the Services, and thereafter as set out in clause 11.
Nature and purpose of the processing. Collection, storage, retrieval, use and transmission of Customer Personal Data in order to provide B2B ordering functionality, including:
- (a) linking a customer record to its customer-specific pricing;
- (b) creating and managing orders;
- (c) enabling the Customer's sales agents to search for and view customer records on the Customer's behalf; and
- (d) providing customer service in connection with the Services.
Types of personal data.
| Field | What it covers |
|---|---|
| Name | First and last name |
| Email address | |
| Phone | Default and billing phone numbers |
| Address | Shipping and billing addresses |
| Customer and order records | Customer and order records available through the ecommerce platform's APIs |
On Shopify, these fields are approved under Shopify's protected customer data requirements. No special category personal data as defined in Article 9, and no criminal offence data as defined in Article 10, is knowingly processed under this DPA.
Categories of data subject. The Customer's business customers, including the individual contacts at those business customers, and the Customer's sales agents where they use the Services.
Source of the data. The ecommerce platform on which the Customer's store runs (for example Shopify, Wix, BigCommerce, WooCommerce or Magento), accessed under the Customer's own agreement with that platform, and data entered directly into the Services by the Customer or its sales agents.
Frequency of transfer. Continuous, for the duration of the Services.
Annex 2 - Technical and organisational measures
SparkLayer maintains the following measures. Full detail is set out in the SparkLayer Security Policy.
| Area | Measures |
|---|---|
| Encryption | Personal data is encrypted in transit using TLS, and encrypted at rest. |
| Access control | Access follows the principle of least privilege. Multi-factor authentication is required for access to production systems. Access is reviewed periodically and revoked promptly when personnel leave or change role. |
| Authentication | Account credentials are stored hashed. Payment card details are handled by the relevant payment provider and are not stored by SparkLayer. |
| Logging and monitoring | Access to and activity within production systems is logged and monitored. |
| Network and infrastructure security | Services are hosted on Google Cloud in the europe-west2 (London) region, and benefit from the physical and environmental security controls operated by that provider. |
| Resilience and availability | Data is backed up, and business continuity arrangements are maintained. See the SparkLayer Business Continuity Plan. |
| Incident management | A documented incident management policy governs the identification, escalation, containment and notification of security incidents and personal data breaches. |
| Personnel | Personnel with access to personal data are subject to confidentiality obligations and receive data protection and security awareness guidance. |
| Sub-processor management | Due diligence is carried out on each Sub-processor, and each is bound by written data protection terms no less protective than those in this DPA. |
| Secure development | Changes to the Services are reviewed before release, and environments are segregated. |
| Deletion | Customer Personal Data is deleted or returned in accordance with clause 11. |
Annex 3 - Sub-processors
The following Sub-processors are engaged as at the date of this DPA. The current list is maintained in the SparkLayer Privacy Policy. Providers that process only data for which SparkLayer is the controller (our own website analytics, cookie management and marketing tools) are not Sub-processors and are listed separately there.
| Sub-processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Google Cloud | Hosting and storage | UK - europe-west2 (London) | Not applicable |
| Amazon Web Services | Transactional email and DNS | EU / US | EU SCCs / UK IDTA |
| Stripe | Billing and payments | US / EU | EU SCCs / UK IDTA |
| HubSpot | CRM | US | EU SCCs / UK IDTA |
| Intercom | Customer support | US / EU | EU SCCs / UK IDTA |
The ecommerce platform on which the Customer's store runs is the source of the Customer Personal Data processed under this DPA. That platform is not a SparkLayer Sub-processor, and the Customer's relationship with it is governed by the Customer's own agreement with that platform.