Data Processing Agreement

Last updated: June 2026

This Data Processing Agreement (“DPA”) applies where Sproker(“Sproker”, the processor) processes personal data on behalf of a business customer (the controller) and forms part of our Terms of Service. For individual consumer accounts, Sproker is the controller and our Privacy Policy applies instead. To request a countersigned copy, email privacy@sproker.com.

1. Roles and scope

The customer is the controller and Sproker is the processor for personal data the customer submits to the service. Sproker processes that data only to provide the service and only on the customer's documented instructions, including the Terms and this DPA.

2. Subject matter and details

  • Duration: the term of the service agreement.
  • Nature and purpose: hosting and operating the storytelling, publishing and marketplace features.
  • Types of data: account and profile data, submitted content, communications, and usage data.
  • Categories of data subjects: the customer's authorised users, contributors and end users.

3. Processor obligations

Sproker will:

  • process personal data only on documented instructions, including for transfers;
  • ensure persons authorised to process the data are bound by confidentiality;
  • implement appropriate technical and organisational security measures (Article 32);
  • assist the controller with data subject requests and with security, breach and DPIA obligations;
  • delete or return the personal data at the end of the service, unless storage is legally required;
  • make available the information needed to demonstrate compliance and allow for audits.

4. Sub-processors

The controller gives general authorisation for Sproker to engage the sub-processors listed on our Sub-processors page. Sproker imposes equivalent data-protection obligations on each sub-processor, will give notice of intended changes, and gives the controller the opportunity to object.

5. International transfers

Data is hosted in the EU. Where a sub-processor processes data outside the EEA, transfers are covered by the EU Standard Contractual Clauses or an adequacy mechanism such as the EU-US Data Privacy Framework, as set out on the Sub-processors page.

6. Security and breach notification

Sproker applies encryption in transit and at rest, access controls, and EU-based hosting. In the event of a personal data breach affecting the customer's data, Sproker will notify the controller without undue delay after becoming aware of it.

7. Contact

CommRs (Sproker) · Witrugspecht 24, 7827 RC Emmen, Netherlands · privacy@sproker.com. This DPA is not legal advice; binding terms should be reviewed by your legal counsel.