AI & Data Policy Agreement
Please read this agreement carefully before accessing XSparks AI applications. Your continued use constitutes acceptance of these terms.
About This Agreement
This AI & Data Policy Agreement ("Agreement") governs your access to and use of all artificial intelligence applications, tools, and services provided by XSparks ("we," "us," or "our"). It describes how we collect, process, store, share, and protect your personal data, and discloses how our AI systems operate.
This Agreement is a legally binding contract between you and XSparks, designed to comply with applicable data protection and AI governance laws across all regions where XSparks operates — including the EU, UK, USA, Canada, Brazil, China, India, Singapore, Japan, and Australia.
Who We Are (Data Controller)
XSparks is the data controller responsible for your personal data processed through our AI applications.
- Company: XSparks (xsparks.ai)
- Contact Email: privacy@xsparks.ai
- DPO / Privacy Contact: dpo@xsparks.ai
For users in the EEA and United Kingdom, XSparks acts as the data controller under GDPR and UK GDPR respectively. Where we engage third-party AI infrastructure providers, those providers act as data processors under signed Data Processing Agreements (DPAs).
AI System Disclosure
As required by the EU AI Act (Article 50, applicable from 2 August 2026), the UK AI governance framework, and equivalent regulations globally, we make the following disclosures:
What our AI does
Our AI applications use large language models to generate text-based responses to your inputs. The AI processes the content you submit and may use prior conversation context within a session to maintain continuity.
Limitations of AI
- AI responses are generated probabilistically and may contain errors or inaccuracies.
- AI outputs do not constitute professional advice (legal, medical, financial, or otherwise).
- The AI may reflect biases present in its training data.
- AI-generated content should always be reviewed by a human before use in consequential decisions.
Human oversight
XSparks maintains human oversight through regular audits, output monitoring, and feedback mechanisms. No AI output will be used to make significant automated decisions about you without human review.
AI-generated content labelling
In compliance with the EU AI Act Article 50, AI-generated content within XSparks applications is clearly identified as AI-generated.
Data We Collect
We collect only the minimum data necessary to provide and improve our services (data minimisation principle).
Account Data
- Name, email address, and password (hashed)
- Organisation name and role (if applicable)
- Billing information (processed by a PCI-DSS compliant provider; we do not store raw card data)
AI Interaction Data
- Prompts and inputs you submit to our AI applications
- AI-generated responses within your session
- Conversation history retained for session continuity
- Feedback you provide on AI outputs
Usage and Technical Data
- Device type, browser, and operating system
- IP address and approximate geographic region
- Session timestamps, feature usage, and error logs
Communications Data
- Support tickets, emails, and chat messages you send to XSparks
- Survey responses and product research participation (voluntary)
How We Use Your Data
- Service delivery: Processing your inputs through AI models; maintaining session continuity.
- Account management: Creating and maintaining your account; authentication and security.
- Safety and trust: Detecting and preventing abuse, fraud, and policy violations.
- Service improvement: Analysing aggregated, de-identified usage patterns. We do not use personal conversation data to train AI models without your explicit opt-in consent.
- Customer support: Responding to your enquiries and resolving issues.
- Legal compliance: Meeting our obligations under applicable laws.
- Communications: Sending service notifications and (where consented) marketing communications.
Lawful Basis for Processing
| Purpose | Lawful Basis |
|---|---|
| Providing the AI service | Contract Performance of contract |
| Account creation and management | Contract Performance of contract |
| Safety monitoring and abuse prevention | Legitimate Interests Protecting users and platform |
| Service analytics (aggregated, de-identified) | Legitimate Interests Improving our services |
| AI model training using your conversations | Consent Explicit opt-in only |
| Marketing communications | Consent Opt-in, withdrawable at any time |
| Legal obligations | Legal Obligation Compliance with law |
For California (USA) users, our processing is governed by CCPA/CPRA and we do not share personal information for cross-context behavioural advertising. For Canadian users, processing is based on meaningful consent under PIPEDA.
Automated Processing & Profiling
XSparks AI applications involve automated processing by nature — your inputs are processed by AI models without a human reviewing each message in real time.
Decisions affecting you
We do not use automated processing to make legally significant decisions about you (such as employment decisions, credit assessments, or denial of services) without human review.
Content safety
Automated classifiers may flag content that violates our Acceptable Use Policy. Human reviewers assess any resulting account actions.
Your right to object
You have the right to request human review of any automated decision that affects you. Contact privacy@xsparks.ai.
Data Sharing & Third Parties
We share your data only as described below and never sell it to third parties.
AI infrastructure providers
Your prompts may be transmitted to third-party LLM providers for processing. All providers are bound by DPAs and prohibited from using your data for their own model training.
Service providers
We engage vetted processors for: cloud hosting, payment processing, customer support tooling, email delivery, and security monitoring. These processors act only on our instructions.
Business transfers
In the event of a merger or acquisition, your data may be transferred to the successor entity under equivalent privacy protections. You will be notified in advance.
Legal disclosures
We may disclose data to law enforcement or courts when required by law. We will notify you unless legally prohibited from doing so.
International Data Transfers
Your data may be transferred to and processed in countries outside your country of residence. We ensure appropriate safeguards for all international transfers, including:
- EU/EEA data: Standard Contractual Clauses (SCCs) as approved by the European Commission.
- UK data: International Data Transfer Agreements (IDTAs) approved by the UK ICO.
- China (PIPL): Standard Contracts for cross-border transfers including required security assessments.
- Brazil (LGPD): Standard contractual clauses or equivalent mechanisms approved by the ANPD.
- Other regions: Equivalent appropriate safeguards required by local law.
You may request a copy of the transfer mechanisms applicable to your data by contacting dpo@xsparks.ai.
Data Retention
We retain your data only for as long as necessary for the purposes described in this Agreement or as required by law.
| Data Type | Retention Period |
|---|---|
| Account data | Duration of account + 2 years after closure |
| AI conversation history | 90 days by default; configurable in account settings |
| Usage and technical logs | 13 months |
| Payment records | 7 years (legal/tax obligation) |
| Support communications | 3 years from resolution |
| Safety incident records | 5 years |
| Deleted account data | Fully purged within 30 days of verified deletion request |
You can delete your conversation history at any time from account settings. Upon account deletion, your personal data is removed from active systems within 30 days and from backups within 90 days.
Your Rights
Depending on your location, you have the following rights regarding your personal data.
| Right | GDPR/UK | CCPA (CA) | LGPD (BR) | PIPL (CN) | PDPA (SG) |
|---|---|---|---|---|---|
| Access — obtain a copy of your data | ✓ | ✓ | ✓ | ✓ | ✓ |
| Rectification — correct inaccurate data | ✓ | – | ✓ | ✓ | ✓ |
| Erasure — request deletion | ✓ | ✓ | ✓ | ✓ | – |
| Portability — machine-readable format | ✓ | ✓ | ✓ | ✓ | – |
| Restriction — limit processing | ✓ | – | ✓ | ✓ | – |
| Object — object to processing | ✓ | ✓ | ✓ | ✓ | – |
| Withdraw consent | ✓ | ✓ | ✓ | ✓ | ✓ |
| Non-discrimination | – | ✓ | – | – | – |
| Automated decision review | ✓ | – | ✓ | ✓ | – |
| Lodge a complaint | ✓ | ✓ | ✓ | ✓ | ✓ |
How to exercise your rights: Submit a request to privacy@xsparks.ai. We respond within 30 days (GDPR: 1 month; CCPA: 45 days; PIPL: 15 days).
Children's Data
XSparks AI applications are not directed at children under the age of 18 (or the applicable age of digital consent in your jurisdiction, whichever is higher).
We do not knowingly collect personal data from minors. If we become aware we have inadvertently collected data from a minor, we will delete it promptly. Contact privacy@xsparks.ai immediately if you believe a minor has submitted data to our services.
Age thresholds: EU/UK (16), USA (13 under COPPA, 16 under CCPA), Brazil (12), China (14 with parental consent).
Security
We implement technical and organisational measures to protect your data, including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Access controls and role-based permissions for staff
- Regular security audits and penetration testing
- Incident response procedures and breach notification protocols
- Staff training on data protection and AI-specific security risks
In the event of a personal data breach posing risk to your rights, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay.
Applicable Laws by Jurisdiction
This Agreement is designed to comply with the following laws. Where local law provides greater protections, those protections apply to you.
Changes to This Agreement
When we make material changes, we will:
- Update the "Effective Date" at the top of this page
- Notify you by email at least 30 days before changes take effect
- Display a prominent notice in the XSparks application
- Require renewed acceptance for changes that significantly affect your rights
Your continued use after non-material changes constitutes acceptance. For material changes, your explicit re-acceptance will be required.
Contact & Data Protection Officer
For questions, concerns, or to exercise your rights, please contact us:
- General privacy enquiries: privacy@xsparks.ai
- Data Protection Officer (DPO): dpo@xsparks.ai
- Website: xsparks.ai
Supervisory Authorities
- EU: Your national Data Protection Authority — edpb.europa.eu
- UK: Information Commissioner's Office — ico.org.uk
- USA (CA): California Privacy Protection Agency (CPPA)
- Brazil: Autoridade Nacional de Proteção de Dados (ANPD)
- India: Data Protection Board of India
- Singapore: Personal Data Protection Commission (PDPC)