AI & Data Policy Agreement

Please read this agreement carefully before accessing XSparks AI applications. Your continued use constitutes acceptance of these terms.

📅 Effective: 28 June 2026 🌍 Scope: Global 📝 Version: 2.0

AI & Data Policy Agreement

By accessing XSparks AI applications, you agree to the collection and processing of your data as described below. This agreement complies with applicable data protection laws across all regions where XSparks operates.

1

About This Agreement

This AI & Data Policy Agreement ("Agreement") governs your access to and use of all artificial intelligence applications, tools, and services provided by XSparks ("we," "us," or "our"). It describes how we collect, process, store, share, and protect your personal data, and discloses how our AI systems operate.

This Agreement is a legally binding contract between you and XSparks, designed to comply with applicable data protection and AI governance laws across all regions where XSparks operates — including the EU, UK, USA, Canada, Brazil, China, India, Singapore, Japan, and Australia.

Important: If you do not agree to this Agreement, you may not access or use XSparks AI applications. Accepting this Agreement does not waive any rights you hold under applicable law.
2

Who We Are (Data Controller)

XSparks is the data controller responsible for your personal data processed through our AI applications.

For users in the EEA and United Kingdom, XSparks acts as the data controller under GDPR and UK GDPR respectively. Where we engage third-party AI infrastructure providers, those providers act as data processors under signed Data Processing Agreements (DPAs).

3

AI System Disclosure

You are interacting with AI. XSparks applications use generative AI powered by large language models (LLMs). You are not communicating with a human unless explicitly stated.

As required by the EU AI Act (Article 50, applicable from 2 August 2026), the UK AI governance framework, and equivalent regulations globally, we make the following disclosures:

What our AI does

Our AI applications use large language models to generate text-based responses to your inputs. The AI processes the content you submit and may use prior conversation context within a session to maintain continuity.

Limitations of AI

  • AI responses are generated probabilistically and may contain errors or inaccuracies.
  • AI outputs do not constitute professional advice (legal, medical, financial, or otherwise).
  • The AI may reflect biases present in its training data.
  • AI-generated content should always be reviewed by a human before use in consequential decisions.

Human oversight

XSparks maintains human oversight through regular audits, output monitoring, and feedback mechanisms. No AI output will be used to make significant automated decisions about you without human review.

AI-generated content labelling

In compliance with the EU AI Act Article 50, AI-generated content within XSparks applications is clearly identified as AI-generated.

4

Data We Collect

We collect only the minimum data necessary to provide and improve our services (data minimisation principle).

Account Data

  • Name, email address, and password (hashed)
  • Organisation name and role (if applicable)
  • Billing information (processed by a PCI-DSS compliant provider; we do not store raw card data)

AI Interaction Data

  • Prompts and inputs you submit to our AI applications
  • AI-generated responses within your session
  • Conversation history retained for session continuity
  • Feedback you provide on AI outputs
Sensitive Data Warning: Do not submit health, biometric, financial credentials, passwords, government ID numbers, or data about children to our AI applications unless we have explicitly enabled a feature for that purpose.

Usage and Technical Data

  • Device type, browser, and operating system
  • IP address and approximate geographic region
  • Session timestamps, feature usage, and error logs

Communications Data

  • Support tickets, emails, and chat messages you send to XSparks
  • Survey responses and product research participation (voluntary)
5

How We Use Your Data

  • Service delivery: Processing your inputs through AI models; maintaining session continuity.
  • Account management: Creating and maintaining your account; authentication and security.
  • Safety and trust: Detecting and preventing abuse, fraud, and policy violations.
  • Service improvement: Analysing aggregated, de-identified usage patterns. We do not use personal conversation data to train AI models without your explicit opt-in consent.
  • Customer support: Responding to your enquiries and resolving issues.
  • Legal compliance: Meeting our obligations under applicable laws.
  • Communications: Sending service notifications and (where consented) marketing communications.
No selling of data: XSparks does not sell your personal data to third parties and does not use your data for third-party advertising targeting.
6

Lawful Basis for Processing

PurposeLawful Basis
Providing the AI serviceContract Performance of contract
Account creation and managementContract Performance of contract
Safety monitoring and abuse preventionLegitimate Interests Protecting users and platform
Service analytics (aggregated, de-identified)Legitimate Interests Improving our services
AI model training using your conversationsConsent Explicit opt-in only
Marketing communicationsConsent Opt-in, withdrawable at any time
Legal obligationsLegal Obligation Compliance with law

For California (USA) users, our processing is governed by CCPA/CPRA and we do not share personal information for cross-context behavioural advertising. For Canadian users, processing is based on meaningful consent under PIPEDA.

7

Automated Processing & Profiling

XSparks AI applications involve automated processing by nature — your inputs are processed by AI models without a human reviewing each message in real time.

Decisions affecting you

We do not use automated processing to make legally significant decisions about you (such as employment decisions, credit assessments, or denial of services) without human review.

Content safety

Automated classifiers may flag content that violates our Acceptable Use Policy. Human reviewers assess any resulting account actions.

Your right to object

You have the right to request human review of any automated decision that affects you. Contact privacy@xsparks.ai.

8

Data Sharing & Third Parties

We share your data only as described below and never sell it to third parties.

AI infrastructure providers

Your prompts may be transmitted to third-party LLM providers for processing. All providers are bound by DPAs and prohibited from using your data for their own model training.

Service providers

We engage vetted processors for: cloud hosting, payment processing, customer support tooling, email delivery, and security monitoring. These processors act only on our instructions.

Business transfers

In the event of a merger or acquisition, your data may be transferred to the successor entity under equivalent privacy protections. You will be notified in advance.

Legal disclosures

We may disclose data to law enforcement or courts when required by law. We will notify you unless legally prohibited from doing so.

Sub-processors: A current list of our sub-processors and AI infrastructure providers is available at privacy@xsparks.ai upon request.
9

International Data Transfers

Your data may be transferred to and processed in countries outside your country of residence. We ensure appropriate safeguards for all international transfers, including:

  • EU/EEA data: Standard Contractual Clauses (SCCs) as approved by the European Commission.
  • UK data: International Data Transfer Agreements (IDTAs) approved by the UK ICO.
  • China (PIPL): Standard Contracts for cross-border transfers including required security assessments.
  • Brazil (LGPD): Standard contractual clauses or equivalent mechanisms approved by the ANPD.
  • Other regions: Equivalent appropriate safeguards required by local law.

You may request a copy of the transfer mechanisms applicable to your data by contacting dpo@xsparks.ai.

10

Data Retention

We retain your data only for as long as necessary for the purposes described in this Agreement or as required by law.

Data TypeRetention Period
Account dataDuration of account + 2 years after closure
AI conversation history90 days by default; configurable in account settings
Usage and technical logs13 months
Payment records7 years (legal/tax obligation)
Support communications3 years from resolution
Safety incident records5 years
Deleted account dataFully purged within 30 days of verified deletion request

You can delete your conversation history at any time from account settings. Upon account deletion, your personal data is removed from active systems within 30 days and from backups within 90 days.

11

Your Rights

Depending on your location, you have the following rights regarding your personal data.

RightGDPR/UKCCPA (CA)LGPD (BR)PIPL (CN)PDPA (SG)
Access — obtain a copy of your data
Rectification — correct inaccurate data
Erasure — request deletion
Portability — machine-readable format
Restriction — limit processing
Object — object to processing
Withdraw consent
Non-discrimination
Automated decision review
Lodge a complaint

How to exercise your rights: Submit a request to privacy@xsparks.ai. We respond within 30 days (GDPR: 1 month; CCPA: 45 days; PIPL: 15 days).

California residents (CCPA/CPRA): You have the right to opt out of the sharing of personal information for cross-context behavioural advertising. Contact privacy@xsparks.ai. We do not sell personal information.
12

Children's Data

XSparks AI applications are not directed at children under the age of 18 (or the applicable age of digital consent in your jurisdiction, whichever is higher).

We do not knowingly collect personal data from minors. If we become aware we have inadvertently collected data from a minor, we will delete it promptly. Contact privacy@xsparks.ai immediately if you believe a minor has submitted data to our services.

Age thresholds: EU/UK (16), USA (13 under COPPA, 16 under CCPA), Brazil (12), China (14 with parental consent).

13

Security

We implement technical and organisational measures to protect your data, including:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Access controls and role-based permissions for staff
  • Regular security audits and penetration testing
  • Incident response procedures and breach notification protocols
  • Staff training on data protection and AI-specific security risks

In the event of a personal data breach posing risk to your rights, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay.

14

Applicable Laws by Jurisdiction

This Agreement is designed to comply with the following laws. Where local law provides greater protections, those protections apply to you.

🇪🇺
GDPR + EU AI Act
European Union
General Data Protection Regulation & EU Artificial Intelligence Act (2024/1689)
🇬🇧
UK GDPR + DUA Act
United Kingdom
UK GDPR, Data Protection Act 2018 & Data (Use and Access) Act 2026
🇺🇸
CCPA / CPRA
California, USA
California Consumer Privacy Act & California Privacy Rights Act
🇨🇦
PIPEDA
Canada
Personal Information Protection and Electronic Documents Act
🇧🇷
LGPD
Brazil
Lei Geral de Proteção de Dados
🇨🇳
PIPL
China
Personal Information Protection Law (2021)
🇮🇳
DPDP Act
India
Digital Personal Data Protection Act 2023
🇸🇬
PDPA
Singapore
Personal Data Protection Act 2012 (amended 2021)
🇯🇵
APPI
Japan
Act on the Protection of Personal Information (amended 2022)
🇦🇺
Privacy Act 1988
Australia
Privacy Act 1988 (Cth) and Australian Privacy Principles
🌏
PDPA (TH/MY)
Thailand & Malaysia
Thailand PDPA (2019) and Malaysia PDPA (2010, amended 2025)
🌍
Additional
144+ Countries
We monitor and comply with emerging data protection laws across all jurisdictions we operate in.
15

Changes to This Agreement

When we make material changes, we will:

  • Update the "Effective Date" at the top of this page
  • Notify you by email at least 30 days before changes take effect
  • Display a prominent notice in the XSparks application
  • Require renewed acceptance for changes that significantly affect your rights

Your continued use after non-material changes constitutes acceptance. For material changes, your explicit re-acceptance will be required.

16

Contact & Data Protection Officer

For questions, concerns, or to exercise your rights, please contact us:

Supervisory Authorities

  • EU: Your national Data Protection Authority — edpb.europa.eu
  • UK: Information Commissioner's Office — ico.org.uk
  • USA (CA): California Privacy Protection Agency (CPPA)
  • Brazil: Autoridade Nacional de Proteção de Dados (ANPD)
  • India: Data Protection Board of India
  • Singapore: Personal Data Protection Commission (PDPC)
Response times: We aim to respond to all privacy enquiries within 5 business days and will resolve data subject requests within statutory deadlines (GDPR: 30 days; CCPA: 45 days; PIPL: 15 days).

Summary

Effective 28 June 2026 · Version 2.0 · Applies globally. For questions or to exercise your data rights, contact privacy@xsparks.ai or our DPO at dpo@xsparks.ai.