1. Subject matter and structure
This Data Processing Agreement ("DPA") forms part of, and is incorporated into, every venue agreement, partner agreement and franchise agreement concluded between {{LEGAL_ENTITY}} ("SparqX") and the counterparty ("Counterparty"). It governs the processing of personal data that arises from operating SparqX powerbank rental stations, the SparqX app and web client, and the associated administrative back office. It is concluded pursuant to Article 28(3) of Regulation (EU) 2016/679 ("GDPR") and, where applicable, the equivalent provisions of national implementing law. Where this DPA conflicts with the commercial agreement it supplements, this DPA prevails in respect of data protection matters only. Nothing in this DPA varies the commercial terms, which remain set out in the commercial annex to the relevant agreement.
2. Roles of the parties and documented instructions
SparqX is the controller of end-user personal data collected through the SparqX app, web client and stations: account data, rental history, payment tokens and support correspondence. SparqX determines the purposes and means of that processing and is responsible for the end-user-facing privacy notice. The Counterparty acts as a processor on behalf of SparqX where it accesses end-user data through the SparqX back office — for example, when handling a rental dispute at its own location or assisting an end user at a station. In that capacity the Counterparty processes such data solely on documented instructions from SparqX. SparqX acts as a processor on behalf of the Counterparty only where it processes personal data that the Counterparty supplies for its own purposes, such as contact details of the Counterparty's staff configured as back-office users. Each party is an independent controller of its own personnel, accounting and tax records. The parties are not joint controllers unless a separate arrangement under Article 26 GDPR is signed by both. The processor party shall process personal data only on the documented instructions of the controller party, including with regard to transfers to third countries, unless required to do otherwise by Union or Member State law to which the processor is subject. In that case the processor shall inform the controller of that legal requirement before processing, unless the law prohibits such notification on important grounds of public interest. This DPA, the commercial agreement it supplements, the configuration of access rights in the SparqX back office and any written instruction issued to {{LEGAL_EMAIL}} or to the Counterparty's designated contact together constitute the complete documented instructions in force at any given time. The processor shall immediately inform the controller if, in its opinion, an instruction infringes the GDPR or other applicable data protection law, and may suspend execution of that instruction until it is confirmed or withdrawn.
3. Categories of data, data subjects, purpose and duration
Categories of data subjects: end users who register a SparqX account or rent a powerbank; visitors to a venue who interact with a station; employees, contractors and authorised representatives of the Counterparty who hold back-office credentials; and individuals who contact support. Categories of personal data: identifiers (account identifier, name where provided, email address, telephone number); authentication data (hashed credentials, session and device tokens); transaction data (rental start and end, station of pickup and return, tariff applied, amount charged, balance and bonus movements, revenue split attribution); payment data limited to tokens, card brand, last four digits and payment status, with full card numbers held only by the payment service provider; technical data (device model, operating system, app version, IP address, diagnostic logs); location data limited to the station used and, where the end user has enabled it in the app, approximate device location for the purpose of finding nearby stations; and support correspondence. No special categories of personal data within the meaning of Article 9 GDPR and no criminal-offence data are intentionally processed. Neither party shall introduce such data into the SparqX platform. Data relating to children is processed only in accordance with the age threshold stated in the SparqX Terms of Service and the applicable national age of digital consent. Processing consists of collection, storage, structuring, retrieval, consultation, use, disclosure to sub-processors, restriction, erasure and destruction, carried out by automated means within the SparqX platform and by manual means where staff handle a support case. The purposes are: providing and operating the powerbank rental service; authenticating end users; taking payment, placing and releasing deposits, and issuing refunds; calculating and settling revenue shares and payouts to venues, partners and franchisees; preventing fraud and abuse of the network; maintaining and securing station and platform infrastructure; providing customer support; and complying with accounting, tax and other statutory retention duties. Processing continues for the term of the underlying commercial agreement. Thereafter it continues only to the extent required to complete final settlement and to satisfy statutory retention obligations, after which the data is deleted or anonymised in accordance with section 11.
4. Obligations of the parties
Each party warrants that it will comply with applicable data protection law in respect of the processing carried out under this DPA. The processor party shall: ensure that persons authorised to process the personal data are bound by an appropriate statutory or contractual duty of confidentiality; grant access strictly on a need-to-know basis using the role-based access controls of the SparqX back office; not use the personal data for its own marketing, profiling, analytics or any purpose other than performing the agreement; not copy, export or retain personal data outside the SparqX platform except where expressly instructed in writing; and provide the controller with the information reasonably necessary to demonstrate compliance with Article 28 GDPR. The controller party shall: ensure that it has a valid legal basis for the processing it instructs; provide the required transparency information to data subjects; and not instruct processing that would place the processor in breach of applicable law. The Counterparty shall not install, connect or operate any camera, sensor, beacon, network capture device or analytics tool that records individuals at or around a SparqX station without the prior written agreement of SparqX and its own lawful basis for doing so.
5. Sub-processors
The controller party grants the processor party a general written authorisation to engage sub-processors, subject to the conditions in this section. SparqX maintains a current list of the sub-processors it engages — covering cloud hosting and storage, payment processing, transactional email and messaging, error monitoring and analytics, and customer support tooling — and makes it available on request to {{PRIVACY_EMAIL}} and through the SparqX website. Before engaging a new sub-processor or replacing an existing one, the processor party shall give the controller party notice with a reasonable objection period. The controller party may object on reasonable, documented data protection grounds; if the parties cannot agree on a remedy, the controller party may terminate the affected part of the commercial agreement without penalty, subject to the notice provisions of that agreement. The processor party shall impose on each sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the controller party for the performance of that sub-processor's obligations. The Counterparty shall not engage any sub-processor in respect of SparqX end-user data without the prior specific written authorisation of SparqX.
6. Technical and organisational security measures
Each party shall implement appropriate technical and organisational measures under Article 32 GDPR, having regard to the state of the art, the costs of implementation and the nature, scope, context and purposes of processing. SparqX measures include, as a minimum: encryption of personal data in transit using current TLS and encryption at rest for databases, backups and object storage; role-based access control with least-privilege roles reflecting the distributor, franchise and station hierarchy, with multi-factor authentication required for back-office and administrative accounts; segregation of production, staging and development environments, with production personal data not used for development or testing except in pseudonymised or synthetic form; tamper-evident audit logging of administrative and financial actions with defined retention; secure software development practices, dependency scanning and timely patching; regular backups with tested restoration procedures and documented recovery objectives; storage of payment credentials as tokens with a PCI DSS compliant payment service provider, so that full card data never reaches SparqX systems; and periodic review and testing of the effectiveness of these measures. Counterparty measures include, as a minimum: keeping back-office credentials confidential and personal to each named user, never shared or reused; enabling multi-factor authentication where offered; promptly requesting revocation of credentials for staff who leave or change role; using up-to-date, access-protected devices with full-disk encryption and screen locking to access the back office; not exporting or storing SparqX end-user data on personal devices, personal accounts or unmanaged storage; and physically securing the station and its power supply against tampering as set out in the venue or partner agreement. Measures may be updated to reflect technical developments, provided the level of protection is not reduced.
7. Personal data breaches
The processor party shall notify the controller party without undue delay, and in any event within 24 hours, after becoming aware of a personal data breach affecting personal data processed under this DPA. Notification shall be sent to {{PRIVACY_EMAIL}} in the case of SparqX, and to the Counterparty's designated data protection contact. The notification shall describe, to the extent known: the nature of the breach, including the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address the breach and mitigate its adverse effects; and the name and contact details of a point of contact for further information. Where the information cannot be provided at once, it shall be supplied in phases without undue further delay. The processor party shall not communicate with data subjects, regulators, the press or any third party about a breach affecting the controller party's data without the controller party's prior written approval, unless it is independently required to do so by law. The parties shall cooperate in good faith on containment, investigation, remediation, notification to the competent supervisory authority under Article 33 GDPR and communication to data subjects under Article 34 GDPR, and shall each preserve relevant logs and evidence. The Counterparty shall report suspected credential compromise, station tampering or unauthorised back-office access to {{SUPPORT_EMAIL}} and {{PRIVACY_EMAIL}} immediately upon becoming aware of it.
8. Data subject rights and assistance
Taking into account the nature of the processing, the processor party shall assist the controller party by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the controller party's obligation to respond to requests for the exercise of data subject rights under Chapter III GDPR, including access, rectification, erasure, restriction, portability and objection. The processor party shall not respond to a data subject request itself unless expressly instructed to do so in writing. It shall forward any request it receives to the controller party without undue delay and in any event within 3 working days. A request received by the Counterparty from a SparqX end user shall be forwarded to {{PRIVACY_EMAIL}}. The processor party shall also assist the controller party in ensuring compliance with the obligations under Articles 32 to 36 GDPR, including security of processing, breach notification, data protection impact assessments and prior consultation with the supervisory authority, taking into account the information available to it.
9. Records, audit and inspection
Each party shall maintain a record of the processing activities carried out under this DPA in accordance with Article 30 GDPR and shall make it available to the competent supervisory authority on request. The processor party shall make available to the controller party all information necessary to demonstrate compliance with the obligations in Article 28 GDPR and shall allow for and contribute to audits, including inspections, conducted by the controller party or another auditor mandated by it. Audits shall take place on reasonable prior written notice, during normal business hours, no more than once in any twelve-month period except where a personal data breach has occurred or a supervisory authority so requires, and shall be conducted so as to minimise disruption to normal operations. The auditor shall be bound by confidentiality and shall not be a competitor of the audited party. The audited party may satisfy an audit request by providing an up-to-date third-party audit report, certification or security questionnaire response where these adequately address the controller party's questions. Costs are borne as set out in the commercial annex to the relevant agreement.
10. International transfers
Personal data processed under this DPA is stored and processed primarily within the European Economic Area. Neither party shall transfer personal data processed under this DPA to a country outside the EEA, or grant access to it from such a country, unless a valid transfer mechanism under Chapter V GDPR is in place. Where a transfer is necessary, it shall be based on: an adequacy decision of the European Commission covering the destination country and, where the decision is framework-based, the recipient's certification under that framework; or the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, incorporated into this DPA by reference and completed with the module appropriate to the roles of the parties, the details in section 3 as Annexes I and II, the sub-processor list in section 5, and the security measures in section 6; or another mechanism recognised under Article 46 GDPR. Where the transfer is subject to UK or Swiss law, the corresponding UK International Data Transfer Addendum or Swiss adaptations apply. Where the Standard Contractual Clauses apply, the parties shall carry out and document a transfer impact assessment, apply supplementary technical measures such as encryption and pseudonymisation where the assessment indicates they are required, and notify each other if they become unable to comply with the clauses. In the event of a conflict between the Standard Contractual Clauses and this DPA, the Standard Contractual Clauses prevail.
11. Return and deletion of data
On termination or expiry of the underlying commercial agreement, or earlier on the controller party's written instruction, the processor party shall cease processing the personal data and shall, at the controller party's choice, return it or delete it together with all existing copies. Access of the Counterparty's users to the SparqX back office is revoked on termination, and any personal data extracted or exported by the Counterparty during the term shall be deleted from its systems. The processor party may retain personal data where and for as long as Union or Member State law requires storage, in particular accounting, tax and invoicing records relating to revenue shares and payouts. Retained data shall be kept only for that purpose, with access restricted accordingly, and deleted at the end of the statutory period. Backup copies are deleted in accordance with the ordinary backup rotation cycle. On request the processor party shall certify deletion in writing.
12. Liability, term and contact
Liability under this DPA is governed by Article 82 GDPR and, as between the parties, by the liability provisions of the commercial agreement it supplements, save that no limitation of liability may operate to restrict a data subject's rights or a party's statutory liability towards a supervisory authority. This DPA takes effect on the effective date of the commercial agreement it supplements and remains in force for as long as personal data is processed under it. Sections 4, 7, 9, 11 and this section survive termination. If a provision of this DPA is held invalid, the remainder continues in force and the parties shall replace the invalid provision with a valid one of equivalent effect. This DPA is governed by {{JURISDICTION}}, without prejudice to the mandatory application of the GDPR and national data protection law. Data protection enquiries and requests under this DPA: {{PRIVACY_EMAIL}}. Contractual notices: {{LEGAL_EMAIL}}. Registered address: {{LEGAL_ADDRESS}}. Operational and station incidents: {{SUPPORT_EMAIL}}.