Privacy Policy
Last Updated:
1. Welcome
SparkLearn, Inc. (“SparkLearn,” “we,” “us,” or “our”) operates the website located at https://www.sparklearn.com (the “Website”) and provides SparkLearn’s cloud-based learning platform and mobile application(s) (collectively, the “Services”). SparkLearn’s Services include, among other things, employee training, mobile learning, AI-assisted content creation, AI-assisted search and chat, content recommendations, xAPI-based analytics, integrations, and related support services.
This Privacy Policy describes how we collect, use, disclose, and protect your personal information in compliance with applicable privacy laws and applies to personal information we collect from visitors to our Website; users of our Services, prospective, current, and former customers; and individuals who otherwise contact us.
By using our Services, you consent to the collection, use, and storage of information as outlined in this Privacy Policy. If you do not agree, please do not use our Services.
When SparkLearn processes personal information on behalf of a customer in connection with the customer’s use of the Services (“Customer Data”), SparkLearn acts as a processor or service provider. The customer is the controller or business with respect to such Customer Data and is responsible for its lawful collection, use, and disclosure. SparkLearn processes Customer Data in accordance with the SparkLearn® License Agreement (or other applicable customer service agreement), applicable data processing terms, and the customer’s documented instructions. If you are an end user of a customer’s SparkLearn-powered learning platform or course, and have questions about how your data is processed, please contact that customer directly.
2. Information We Collect
We collect information to provide, operate, secure, and improve the Services. The categories below describe the information we collect directly from you, automatically through your use of the Services, and from our customers and third parties.
2.1 Account and User Information
We collect information used to create and manage accounts and user profiles, including:
Name, email address, username, and password or other credentials
Company name, organization, role, title, group membership, and permissions
Language preferences, notification preferences, and account settings
Information provided via single sign-on (SSO), HRIS, LMS, or other customer systems
2.2 Demo, Contact, and Business Inquiry Information
When you request a demo, submit a contact form, or otherwise inquire about the Services, we collect:
Name, business email address, and phone number
Company name, job title, and industry
Training needs, team size, and the contents of your message
2.3 Learning Activity and Analytics Information
When you or your users access the Services, we collect information about learning activity, including:
Course enrollment, assigned content, and completed content
Quiz and assessment results, certificates, and learning history
Any user-generated content, searches, AI chat questions, and content recommendations
Clickstream events, xAPI statements, learning record store data, and usage reports
2.4 Customer Content and Training Materials
Customers and their authorized users may upload or create content within the Services, including:
Standard operating procedures, policies, manuals, and job instructions or guidance
Documents, presentations, spreadsheets, PDFs, audio, video, and images
Quizzes, flashcards, checklists, discussion posts, and other files
Authorized users may also connect certain third-party content providers (such as Open Sesame) to the Services; content accessed through these integrations is subject to that provider's own terms.
2.5 AI Feature Inputs and Outputs
When you or your users use SparkLearn’s AI-assisted features, including, but not limited to, AI course creation, AI image generation, AI quizzes, AI flashcards, AI search, and AI chat, we collect:
Prompts, questions, and uploaded files or source materials
Generated outputs and associated metadata
Related usage information necessary to deliver, monitor, and improve the AI features and the Service
2.6 Payment and Subscription Information
When a customer purchases or renews a subscription, we collect:
Billing name, billing address, and subscription plan details
User counts, invoicing information, and tax information
Payment status and transaction history
Payment card information is processed directly by our third-party payment processors (Stripe) and is not stored on SparkLearn’s systems.
2.7 Automatically Collected Information
When you access or use the Services, we automatically collect certain information, including:
IP address, browser and device characteristics, operating system, device type, and device identifiers
Referring URLs, pages viewed, features used, and dates and times of access
Session information, approximate location derived from IP address, crash logs, server logs, and security logs
For mobile applications: app usage, push notification tokens, offline content access, and sync activity
2.8 Information From Customers and Third Parties
We receive information about you from our customers (and their administrators) and from third parties that customers choose to integrate with the Services, such as HRIS, LMS, SSO providers, learning record stores (LRS), payment processors, app stores, content providers, and analytics providers. This information may include:
Employee or contractor identifiers, organization, role, and attributes
Permissions and course assignments
Completion records, progress data, and similar learning information
2.9 Communications
When you contact us, we collect information necessary to respond and provide support, including support tickets, email, and live chat contents; contact information; issue descriptions; screenshots and attachments; diagnostic information; and a history of your communications with us.
3. How We Use Your Information
We use the information we collect for the purposes described in this Privacy Policy, which may include to:
Provide, operate, maintain, secure, and improve the Services
Create and manage customer accounts, domains, teams, user roles, permissions, and subscriptions
Deliver learning content, mobile access, offline content, assignments, reminders, push notifications, badges, and certificates
Provide AI-assisted content creation, AI search, and AI chat functionality
Process subscriptions, invoices, taxes, payments, renewals, and cancellations
Respond to demo requests, inquiries, support tickets, and other communications
Integrate with SSO, HRIS, LMS, LRS, business intelligence, API, and other customer-selected systems
Generate analytics, reports, dashboards, xAPI statements, and records
Monitor, detect, prevent, and investigate security incidents, fraud, and misuse
Send administrative communications, product updates, notices, and security alerts
Send marketing communications where permitted by law
Enforce our agreements and policies
Comply with legal, regulatory, tax, accounting, and contractual obligations
Establish, exercise, or defend legal claims
4. Legal Bases for Proceeding
When we process your personal data, we will only do so where at least one of the following applies:
Performance of Contract. We process your personal data to provide the Services under our agreement with you or the customer for which you use the Services, including account creation, authentication, content delivery, billing, and support.
Legitimate Interests. We process personal data where we have legitimate interests, including operating and improving the Services, securing our systems, performing analytics, preventing fraud, and conducting business-to-business communications.
Consent. Where required by law, we obtain your consent – for example, for certain marketing communications and non-essential cookies. You may withdraw your consent at any time.
Legal Compliance. We process personal data as necessary to comply with applicable legal, regulatory, tax, accounting, and contractual obligations.
Customer Instructions. We process Customer Data on behalf of our customers pursuant to their documented instructions and the applicable customer agreement or data processing addendum.
5. Disclosure and Sharing of Information
We do not sell, rent, or trade your personal information. We share information only as described in this Privacy Policy.
5.1 Service Providers
We share information with third-party service providers that perform services on our behalf, including cloud hosting, security, analytics, support and ticketing, communications, payment processing, subscription billing, AI services, content and media delivery, app distribution, and professional advisors. These service providers are contractually required to use your information only to provide services to us and to comply with appropriate confidentiality and security obligations.
5.2 Customers, Administrators, and Authorized Users
Where a user accesses the Services through a customer account (for example, an employer or organization), we share information with that customer and its authorized administrators and users as needed to provide the Services, including account information, learning activity, analytics, completion records, and uploaded content.
5.3 Integrations and Customer-Selected Systems
Customers may choose to integrate the Services with third-party systems, including SSO, HRIS, LMS, LRS, business intelligence tools, APIs, content providers, media providers, and app stores. When a customer enables an integration, we share information with those systems as configured by the customer.
5.4 AI, Content, Media, and Learning Tools
We work with AI and related service providers, such as OpenAI, to deliver AI-assisted features. SparkLearn also uses AWS Bedrock for certain chat functionality. Inputs and outputs are handled in accordance with our contracts and published position regarding customer content. For more information about our use of AI, please see our AI Use Policy.
5.5 Payment and Subscription Providers
We share payment and subscription information with our third-party payment, invoicing, and tax providers as needed to process your subscription and related transactions.
5.6 Analytics and Website Technology Providers
We use third-party analytics and website technology providers to operate and improve our Website and Services. Some of these disclosures may constitute “sharing” or “sale” under certain state privacy laws. Where required, we provide an opt-out mechanism and honor applicable opt-out preference signals.
5.7 Legal Requirements
We may disclose personal information if required to do so by law (including in response to a subpoena or request from law enforcement, a court, a government agency, or another public authority) or in the good-faith belief that such action is necessary to (i) comply with a legal obligation, (ii) protect or defend our rights, interests, or property or those of our customers or users, (iii) act in urgent circumstances to protect the personal safety of users of the Services or the public, or (iv) protect against legal liability or potential fraud.
5.8 Business Transfers
In the event of a merger, acquisition, financing, reorganization, bankruptcy, sale of all or a portion of our assets, or similar transaction, personal information may be transferred as part of the transaction. We will notify affected users consistent with applicable law.
5.9 With Your Consent
We may share personal information for other purposes with your consent or at your direction.
6. International Data Transfers
SparkLearn is headquartered in the United States, and our Services are provided from the United States. When you use the Services, your personal information may be transferred to and processed in the United States and other jurisdictions that may have data protection laws different from those in your country of residence.
Where we transfer personal data originating from the European Economic Area (“EEA”), the United Kingdom, or Switzerland to countries that have not been deemed to provide an adequate level of protection, we implement appropriate safeguards, including the Standard Contractual Clauses approved by the European Commission and the UK International Data Transfer Addendum, together with supplementary technical and organizational measures where required. For transfers from other jurisdictions that impose cross-border transfer requirements, we comply with applicable local transfer mechanisms and safeguards as required by applicable law.
7. Data Retention
We retain personal information only for as long as necessary to provide the Services and for other legitimate legal or business purposes. These may include retention periods (i) mandated by law, contract, or similar obligations; (ii) for preserving, resolving, defending, or enforcing our legal or contractual rights; or (iii) needed to maintain adequate and accurate business and financial records.
Specific retention periods include:
Account and user information: Life of the account plus 90 days after closure
Learning records and activity data: Life of the account plus 90 days after closure
Customer content and training materials: Per the applicable customer agreement, 90 days post-termination for Enterprise plans unless otherwise agreed
Financial and transactional records: Up to 7 years for tax and accounting compliance
Marketing and communication data: Up to 2 years unless you opt out sooner
Analytics data: Anonymized and aggregated indefinitely
8. Your Privacy Rights
8.1 Rights for All Users
Regardless of your location, you have the following rights, subject to applicable law and any exceptions:
Access. Request confirmation of whether we process your personal information and access to such information.
Correction. Request correction of inaccurate personal information.
Deletion. Request deletion of your personal information, subject to legal exceptions.
Opt-Out of Marketing. Unsubscribe from marketing communications using the link in our emails or by adjusting your account settings.
Non-Discrimination. We will not discriminate against you for exercising your privacy rights.
8.2 U.S. State Residents
If you are located in the United States, this Privacy Policy describes how we collect, use, and disclose your personal data under the comprehensive privacy laws of California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia, as well as other U.S. states as their respective privacy statutes become effective. Although we are not yet subject to all U.S. state privacy laws, our Privacy Policy maintains a unified standard that provides rights similar to those afforded under these statutes.
California residents have the following rights under CCPA/CPRA:
Right to Know. Request disclosure of the categories of personal information collected, the categories of sources, the business or commercial purposes for collecting or sharing personal information, the categories of third parties to whom we disclose personal information, and the specific pieces of personal information we have collected about you.
Right to Delete. Request deletion of personal information we have collected from you, subject to certain exceptions (e.g., completing transactions, detecting security incidents, complying with legal obligations, and internal uses reasonably aligned with your expectations).
Right to Correct. Request correction of inaccurate personal information we maintain about you.
Right to Opt-Out of Sale or Sharing. Opt out of the sale or sharing of personal information. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
Right to Limit Use of Sensitive Personal Information. Limit our use and disclosure of sensitive personal information to permitted purposes. We do not intentionally use or disclose sensitive personal information for purposes that would require a right-to-limit notice.
Right to Non-Discrimination. We will not discriminate against you for exercising your CCPA/CPRA rights.
8.3 Authorized Agents
California residents and residents of other U.S. states may designate an authorized agent to submit requests on their behalf by providing written authorization to privacy@sparklearn.com. We may require you to verify your identity directly with us and to confirm that you authorized the agent to submit the request.
8.4 Response Time and Verification
We will confirm receipt of your request within 10 business days and respond within 45 days (extendable by an additional 45 days with notice) for U.S. state privacy requests. For GDPR and UK GDPR requests, we will respond within 30 days, extendable by up to an additional 60 days for complex or numerous requests, with notice. We will verify your identity before fulfilling your request by comparing the information you provide with the information we maintain.
8.5 Categories of Personal Information Collected (Last 12 Months)
Category | Examples | Collected | Business Purposes |
|---|---|---|---|
Identifiers | Name, email, phone, username, team name, organization, IP address, device identifiers, account identifiers | Yes | Provide Services, manage accounts, authenticate users, respond to inquiries, security, support, analytics |
Customer and account information | Company, organization, industry, role/title, permissions, group membership, SSO/HRIS/LMS attributes, domain/team configuration | Yes | Provide Services, configure accounts, manage customer relationships, support integrations |
Commercial information | Subscription plan, user counts, payment status, transaction history, invoices, billing records | Yes | Process subscriptions, payments, taxes, invoicing, renewals, and accounting records |
Internet or network activity | Browsing activity, pages viewed, app usage, feature use, logs, session data, search activity, clickstream events, xAPI statements | Yes | Operate Services, analytics, reporting, product improvement, security, troubleshooting |
Education/training and professional information | Course assignments, progress, completions, quiz/assessment results, certificates, badges, goals, notes, learning history, job role, department | Yes | Deliver training, reporting, recommendations, analytics, customer administration |
User-generated and customer content | Uploaded documents, SOPs, policies, manuals, presentations, images, videos, audio, discussion posts, prompts, AI outputs, support attachments | Yes | Provide content authoring, AI features, search, support, training delivery, analytics |
Geolocation data | Approximate location based on IP address | Yes | Security, analytics, service optimization |
Payment information | Billing name/address, payment method metadata, tax info, transaction identifiers; card data processed by payment processors | Yes | Process payments, subscriptions, taxes, fraud prevention, accounting |
Sensitive personal information | Account credentials; additional information only if included by customer or user in Customer Data | Varies | Provide Services, authenticate users, secure accounts, process Customer Data under customer instructions |
8.6 No Sale or Sharing
We do not sell personal information. We have not sold personal information in the preceding 12 months. We do not share personal information for cross-context behavioral advertising purposes as those terms are defined under applicable U.S. state privacy laws.
8.7 EEA, Switzerland, and UK Residents (GDPR/UK GDPR)
If you are located in the EEA, Switzerland, or the UK, the GDPR and its Swiss and UK counterparts provide you the following rights, subject to any exemptions provided by law:
Right to Access. Request access to your personal data.
Right to Correction. Request correction of inaccurate or incomplete personal data.
Right to Erasure. Request deletion of your personal data.
Right to Restrict Processing. Request that we limit our use and processing of your personal data.
Right to Data Portability. Request portability of your personal data in a structured, commonly used, and machine-readable format.
Right to Withdraw Consent. Where processing is based on consent, you have the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before withdrawal.
Right to Object. Object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or for the establishment, exercise, or defense of legal claims.
Right to Lodge a Complaint. Lodge a complaint with a competent supervisory authority in the EEA, UK, or Switzerland.
8.8 Additional Regional Privacy Rights
Depending on your jurisdiction, you may have additional privacy rights under local law. The following provisions supplement this Privacy Policy for users located in the jurisdictions described below.
8.8.1 Australia (Privacy Act 1988)
If you are located in Australia, we handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (“APPs”). We may disclose personal information to overseas recipients, including service providers located in the United States and other jurisdictions. Before doing so, we take reasonable steps to ensure that overseas recipients do not breach the APPs in relation to your information. You may request access to, or correction of, personal information we hold about you. If you believe we have breached the APPs or wish to make a complaint, please contact us at privacy@sparklearn.com. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
8.8.2 Brazil
If you are located in Brazil, you may have rights under Brazil’s Lei Geral de Proteção de Dados (“LGPD”), Law No. 13,709/2018, including the right to confirm the existence of processing activities, access personal data, correct incomplete or inaccurate information, request anonymization, blocking, or deletion of unnecessary or excessive personal data, request portability of personal data to another service provider, request deletion of personal data processed with your consent, obtain information about public and private entities with which we have shared your data, and be informed about the possibility of denying consent and the consequences thereof. We process personal data under the LGPD based on one or more of the following legal bases: consent, performance of a contract, compliance with a legal or regulatory obligation, legitimate interests, or protection of credit. You may exercise your rights by contacting us at privacy@sparklearn.com.
8.8.3 Canada
If you are located in Canada, we process personal information in accordance with the Personal Information Protection and Electronic Documents Act (“PIPEDA”) and applicable provincial privacy legislation. We obtain meaningful consent for the collection, use, and disclosure of personal information, except where permitted or required by law without consent. You may withdraw your consent at any time, subject to legal or contractual restrictions and reasonable notice. We may transfer personal information to service providers located outside Canada, including in the United States, which may be subject to lawful access requirements under the laws of those jurisdictions. You may request access to, or correction of, your personal information, or file a complaint regarding our privacy practices, by contacting us at privacy@sparklearn.com. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada or the applicable provincial privacy commissioner.
8.8.4 China
If you are located in the People’s Republic of China, we process personal information in accordance with the Personal Information Protection Law of the People’s Republic of China (“PIPL”) and other applicable Chinese laws and regulations. We process personal information based on lawful grounds including your separate consent (where required), contractual necessity, legal obligations, protection of vital interests, and other grounds permitted by law. Where we transfer personal information outside China, we comply with applicable legal requirements, which may include obtaining your separate consent for cross-border transfers, conducting a personal information protection impact assessment, and implementing Standard Contractual Clauses approved by the Cyberspace Administration of China or other approved transfer mechanisms. Subject to applicable law, you have the right to access, copy, correct, supplement, delete, and request portability of your personal information, as well as the right to withdraw consent and to request an explanation of processing rules. You may exercise these rights by contacting us at privacy@sparklearn.com.
8.8.5 India
If you are located in India, we process personal data in accordance with applicable Indian privacy laws, including the Digital Personal Data Protection Act, 2023 (“DPDPA”). We provide clear notice of the purposes for which we collect and process your personal data and obtain your consent where required. You may have rights relating to access, correction, erasure, and nomination of a representative, subject to applicable law. For questions, concerns, or grievances regarding our processing of personal data, or to exercise your rights, please contact our Grievance Officer at privacy@sparklearn.com.
8.8.6 Indonesia
If you are located in Indonesia, we process personal data in accordance with applicable Indonesian law, including Law No. 27 of 2022 on Personal Data Protection (“PDP Law”). We process personal data based on lawful grounds, including consent, contractual necessity, legitimate interests, and legal obligations. Subject to applicable law, you have rights to access, correct, update, and delete your personal data, to withdraw consent, to object to processing, and to request restriction or suspension of processing. You may exercise these rights by contacting us at privacy@sparklearn.com.
8.8.7 Israel
If you are located in Israel, we process personal information in accordance with the Protection of Privacy Law, 5741-1981, the Protection of Privacy Regulations (Data Security), 5777-2017, and applicable regulations. Subject to applicable law, you may request access to, or correction of, personal information we hold about you. You may exercise these rights by contacting us at privacy@sparklearn.com.
8.8.8 Japan
If you are located in Japan, we process personal information in accordance with the Act on the Protection of Personal Information (“APPI”). We clearly identify the purposes of use of personal information and process it within the scope of those purposes. Where we provide personal data to third parties located outside Japan, we do so in accordance with applicable APPI requirements, including by confirming that the recipient country has an adequate personal information protection system or that the recipient has implemented appropriate safeguards. You may request disclosure, correction, addition, deletion, cessation of use, or cessation of provision to third parties of your personal information by contacting us at privacy@sparklearn.com.
8.8.9 Mexico
If you are located in Mexico, we process personal data in accordance with the Federal Law on Protection of Personal Data Held by Private Parties (“LFPDPPP”). You have the right to access, rectify, cancel, or object to the processing of your personal data (“ARCO Rights”), as well as the right to revoke consent previously granted. To exercise your ARCO Rights or to revoke consent, please submit a request to privacy@sparklearn.com including your name, contact information, a clear description of the personal data at issue, and documentation establishing your identity. We will respond within 20 business days of receiving a complete request.
8.8.10 Philippines
If you are located in the Philippines, we process personal information in accordance with the Data Privacy Act of 2012 (“DPA”) and its implementing rules and regulations. Subject to applicable law, you have the right to be informed, to access, to object, to erasure or blocking, to rectification, to data portability, and to file a complaint with the National Privacy Commission. You may exercise these rights by contacting us at privacy@sparklearn.com.
8.8.11 South Korea
If you are located in South Korea, we process personal information in accordance with the Personal Information Protection Act (“PIPA”). We collect and use personal information only for the purposes disclosed in this Privacy Policy and with your consent where required by law. We do not process personal information beyond the period necessary for the purposes of collection. When the retention period expires or the purpose of processing has been achieved, we promptly destroy personal information in a manner that prevents recovery or reproduction. Where we transfer personal information overseas, we do so in compliance with PIPA requirements, including providing notice of the recipient, purpose, and items of personal information transferred. You may request access to, correction of, deletion of, or suspension of processing of your personal information by contacting us at privacy@sparklearn.com.
8.8.12 Taiwan
If you are located in Taiwan, we process personal information in accordance with Taiwan’s Personal Data Protection Act (“PDPA”). We collect and process personal information within the scope of our specified purposes and with appropriate notice. Subject to applicable law, you may request access to, correction of, cessation of collection, processing, or use of, or deletion of your personal information by contacting us at privacy@sparklearn.com.
8.8.13 Thailand
If you are located in Thailand, we process personal data in accordance with Thailand’s Personal Data Protection Act B.E. 2562 (“PDPA”). We process personal data based on lawful bases including consent, contractual necessity, legitimate interests, and legal obligations. Subject to applicable law, you may have rights relating to access, correction, deletion, restriction of processing, objection, data portability, and withdrawal of consent. You may exercise these rights by contacting us at privacy@sparklearn.com.
8.8.14 Turkey
If you are located in Turkey, we process personal data in accordance with the Turkish Law on the Protection of Personal Data No. 6698 (“KVKK”) and the 2024 Amendments thereto by Law No. 7499. We process personal data based on the conditions set forth in Articles 5 and 6 of the KVKK, and where we transfer personal data outside Turkey, we implement appropriate safeguards in compliance with the amended KVKK requirements regarding adequacy and contractual standards. Subject to applicable law, you have the right to learn whether your personal data has been processed, request information regarding processing, learn the purpose of processing, know third parties to whom data has been transferred, request correction of incomplete or inaccurate data, request deletion or destruction of personal data, object to automated processing, and claim compensation for damages arising from unlawful processing. You may exercise these rights by contacting us at privacy@sparklearn.com.
8.8.15 Vietnam
If you are located in Vietnam, we process personal data in accordance with applicable Vietnamese law, including the Decree on Personal Data Protection (Decree 13/2023/ND-CP). We obtain consent for the processing of personal data where required and provide notice of the purposes, methods, and scope of processing. Where we transfer personal data outside Vietnam, we do so in compliance with applicable requirements, including impact assessments where required. You may exercise rights of access, correction, deletion, restriction, objection, and withdrawal of consent by contacting us at privacy@sparklearn.com.
8.8.16 Other Jurisdictions
Depending on your jurisdiction of residence, you may have additional privacy rights under applicable local law. We will honor applicable legal rights requests in accordance with the requirements of your jurisdiction. If your jurisdiction is not specifically listed above but provides data protection rights, you may contact us at privacy@sparklearn.com to exercise those rights.
8.9 Automated Decision-Making
SparkLearn uses limited automated processing, including AI-assisted content recommendations, adaptive learning features, and AI search. We do not rely solely on automated decisions that produce legal effects concerning you or that significantly affect you in a similar manner. You have the right to request human review, share your viewpoint, and contest automated decisions by contacting us using the information below.
8.10 Contacts to Exercise Privacy Rights
Data Protection Officer. For GDPR and UK GDPR inquiries, you may contact our Data Protection Officer at privacy@sparklearn.com.
EU Representative (Article 27 GDPR) Data Protection Representative Limited (trading as “DataRep”), The Cube, Monahan Road, Cork, T12 H1XY, Ireland. Tel: +353 (1) 919-8899. Email: sparklearn@datarep.com
UK Representative (Article 27 UK GDPR) Data Protection Representative Limited (trading as “DataRep”), The Cube, Monahan Road, Cork, T12 H1XY, Ireland. Tel: +353 (1) 919-8899. Email: sparklearn@datarep.com
8.11 How to Exercise Your Rights
You can access, correct, or delete your personal data by contacting us at privacy@sparklearn.com. Please include:
Your name and the email address associated with your account
A description of your request
Your jurisdiction (if applicable)
The subject line “Privacy Rights Request – [Type of Request]”
9. Cookies and Tracking Technologies
9.1 Overview
Cookies are small text files transferred to your computer or mobile device when you visit a website or use an application. We use cookies and similar technologies to remember your preferences, authenticate users, enhance your user experience, and understand how people use our Services so we can improve them. Cookies may be session cookies, which expire when you close your browser, or persistent cookies, which remain on your device for a specified period or until you delete them.
9.2 Types of Cookies We Use
SparkLearn uses the following types of cookies:
Necessary Cookies. These cookies are required to enable core site functionality and to remember your preferences and choices, such as language preferences or customized settings. They are always active.
Performance and Analytics Cookies. These cookies provide quantitative measures of website visitors, including visit counts and traffic sources, to help us improve the performance of our site. Off by default.
Advertising Cookies. These cookies are used by advertising companies to serve ads relevant to your interests. Off by default.
You can manage your preferences for Performance and Analytics and Advertising cookies at any time using the cookie preferences tool described in Section 9.3.
9.3 Cookie Preferences Tool
You can manage your preferences for optional cookies at any time using the “Manage Cookies” tool available on our website.
9.4 Managing Cookies
You can use our Services without accepting non-essential cookies. You can disable the storage of cookies in your browser, restrict them to certain websites, or configure your browser to notify you when a cookie is sent. You can also delete cookies from your device at any time. Please note that doing so may result in limited functionality or a reduced experience. To learn more about cookies, including how to see what cookies have been set and how to manage and delete them, visit http://www.allaboutcookies.org.
9.5 Do Not Track
“Do Not Track” is a feature enabled on some browsers that sends a signal requesting a web application to disable its tracking or cross-site user tracking. SparkLearn currently does not respond to or change its practices when a Do Not Track signal is received. Where required by law, we honor recognized opt-out preference signals.
9.6 ePrivacy Compliance
For users in the EEA and UK, we adhere to ePrivacy Directive requirements. Consent is required for storing information on a device (such as cookies or local storage) or accessing existing information on the device, other than for strictly necessary purposes. We use a cookie consent mechanism to obtain and record your consent where required.
10. Security Measures
We implement reasonable administrative, technical, and physical security measures designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. Our security program includes:
Technical Measures:
Encryption of personal data in transit using TLS 1.2 or higher
Encryption of personal data at rest
Secure authentication mechanisms with password hashing and support for SSO
Regular security testing and vulnerability assessments
Intrusion detection, logging, and monitoring
Organizational Measures:
Access controls limiting employee access on a need-to-know basis
Confidentiality obligations for employees and contractors
Security awareness training
Incident response and business continuity plans
Vendor management to confirm third-party processors implement appropriate security
Physical Measures:
Use of secure cloud data center facilities with restricted access
Environmental controls and redundancy
No security system can ever be 100% secure. You are responsible for maintaining the confidentiality of your account credentials and for any activity conducted under your account.
11. Children's Privacy
The Services are intended for business and organizational training use and are not directed to children. We do not knowingly collect personal information from children under 13 (or under 16 in the EEA and UK) without appropriate parental or guardian consent. We comply with the Children’s Online Privacy Protection Act (COPPA), including the regulatory updates effective April 22, 2026, regarding heightened consent, data minimization, and transparency. If you believe we have collected information from a child without appropriate consent, please contact us at privacy@sparklearn.com, and we will delete such information from our records within a reasonable time.
12. Third-party Links and Services
The Services may contain links to, and integrations with, third-party websites, applications, and services that are not operated by SparkLearn. This Privacy Policy does not cover the activities of third parties when they collect or use data for their own purposes or on behalf of others. We are not responsible for the privacy practices or content of third-party services. We recommend reviewing their privacy policies before sharing your information.
13. Data Breach Notification
In the event of a personal data breach, SparkLearn will notify affected individuals without undue delay where such notification is required under applicable law, including the GDPR, UK GDPR, and U.S. state statutes, and, where feasible, within 72 hours of becoming aware of a breach that poses a significant risk to individual rights and freedoms. For GDPR and UK GDPR compliance, we will notify the relevant supervisory authority within 72 hours of discovery, unless the breach is unlikely to pose a risk to individuals. Additionally, we will notify the Attorney General or the equivalent state regulatory authority in each U.S. jurisdiction where a personal data breach meets or exceeds the specific statutory notification thresholds established by that state’s data breach notification laws (e.g., California Civil Code § 1798.82). All such regulatory notifications will be submitted in the form and within the timeframes mandated by the laws of the affected jurisdictions. Where SparkLearn acts as a processor or service provider on behalf of a customer, we will notify the affected customer without undue delay in accordance with the applicable service agreement or data processing addendum.
14. Changes to This Privacy Policy
If SparkLearn makes material changes to this Privacy Policy, we will notify you by: (i) updating the “Last Updated” date at the top of this Privacy Policy; (ii) sending an email to the address associated with your account; and/or (iii) posting a notice on the Website or within the Services. Material changes include:
New categories of personal information collected
New purposes for processing personal information
New categories of third parties with whom we share personal information
Substantial changes to your rights or to the way you can exercise them
Your continued use of the Services after notice of a change indicates your acceptance of the updated Privacy Policy.
15. Contact Information
If you have any questions about this Privacy Policy or our privacy practices, please contact us using the information below.
For Privacy Inquiries and Rights Requests:
Email: privacy@sparklearn.com
For General Inquiries:
Email: info@sparklearn.com
Phone: (309) 263-9228
Mailing Address:
SparkLearn, Inc.
PO Box 289
Morton, Illinois 61550-0289
United States
Data Protection Officer (GDPR/UK GDPR Inquiries):
Email: privacy@sparklearn.com
EU Representative (Article 27 GDPR):
Data Protection Representative Limited (trading as “DataRep”), The Cube, Monahan Road, Cork, T12 H1XY, Ireland. Tel: +353 (1) 919-8899. Email: sparklearn@datarep.com
UK Representative (Article 27 UK GDPR):
Data Protection Representative Limited (trading as “DataRep”), The Cube, Monahan Road, Cork, T12 H1XY, Ireland. Tel: +353 (1) 919-8899. Email: sparklearn@datarep.com
Supervisory Authorities.
For UK GDPR matters:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow, Cheshire SK9 5AF, United Kingdom.
+44 (303) 123-1113
For EEA supervisory authorities:


