Specky
Why Specky How it works FAQ Pricing

Data Processing Agreement (DPA)

Specky — operated by Spark IT Mariusz Iskra (sole proprietorship, Poland)

Version: 1.1 · Last updated: 16 August 2026

On this page

  1. 1. Roles and scope
  2. 2. Description of processing
  3. 3. Processor obligations
  4. 4. International transfers
  5. 5. Liability and miscellaneous
  6. Annex 1 — Description of processing
  7. Annex 2 — Technical and organizational measures
  8. Annex 3 — Approved sub-processors

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Spark IT Mariusz Iskra, sole proprietorship registered in Poland, ul. Malownicza 9, 72-006 Mierzyn, Poland, Tax ID (NIP): 8581726552 ("Processor", "we") and the Customer ("Controller", "you"). It is accepted electronically together with the Terms of Service at registration and applies whenever Customer Content uploaded to Specky contains personal data of third parties within the meaning of the EU General Data Protection Regulation (GDPR).

1. Roles and scope

1.1. With respect to personal data contained in Customer Content (the "Customer Personal Data"), the Customer acts as controller (or as processor on behalf of its own clients, in which case we act as sub-processor and the Customer warrants its instructions are consistent with its own controller's instructions), and we act as processor.

1.2. This DPA does not apply to account and organization data for which we act as an independent controller — that processing is described in our Privacy Policy.

1.3. In case of conflict between this DPA and the Terms of Service regarding the processing of Customer Personal Data, this DPA prevails.

2. Description of processing

The subject matter, duration, nature, purpose of processing, types of personal data, and categories of data subjects are described in Annex 1.

3. Processor obligations

We shall:

3.1. Documented instructions. Process Customer Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by EU or Member State law (in which case we will inform the Customer before processing, unless the law prohibits this). The Terms of Service, this DPA, and the Customer's use of the Service's features (e.g., starting an AI analysis) constitute the documented instructions.

3.2. Confidentiality. Ensure that persons authorized to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

3.3. Security. Implement and maintain the technical and organizational measures described in Annex 2 (TOM), taking into account the state of the art, costs, and the nature, scope, context and purposes of processing, pursuant to Article 32 GDPR. We may update the TOM provided the level of protection is not materially reduced.

3.4. Sub-processors. The Customer grants a general authorization for the engagement of sub-processors. The current list is maintained in Annex 3 and published at https://specky.app/legal/subprocessors. We will notify the Customer of intended additions or replacements at least 30 days in advance (via the subprocessor page and in-app or email notice). The Customer may object on reasonable data-protection grounds within 14 days of notice; if the objection cannot be resolved, the Customer may terminate the affected subscription with a pro-rata refund of prepaid, unused fees as its sole remedy. We impose data protection obligations on each sub-processor by way of a contract providing at least the level of protection set out in this DPA, and remain liable for their performance.

3.5. Data subject rights. Taking into account the nature of the processing, assist the Customer by appropriate technical and organizational measures in fulfilling its obligation to respond to data subject requests (access, rectification, erasure, restriction, portability, objection). In practice, the Service provides in-app deletion and export; requests we receive directly from data subjects regarding Customer Personal Data will be forwarded to the Customer without undue delay.

3.6. Assistance. Assist the Customer in ensuring compliance with Articles 32–36 GDPR (security, breach notification, data protection impact assessments, prior consultation), taking into account the nature of processing and the information available to us.

3.7. Personal data breach. Notify the Customer without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting Customer Personal Data, providing at minimum: the nature of the breach, categories and approximate numbers of data subjects and records concerned, likely consequences, measures taken or proposed, and a contact point. We will document breaches and cooperate with the Customer's own notification obligations. Notification is not an acknowledgment of fault or liability.

3.8. Deletion and return. Upon termination of the Service or upon the Customer's choice, delete or return all Customer Personal Data as described in the Terms of Service (Section 9) and the Privacy Policy (Section 7): deletion within 30 days of account deletion, with backup rotation completing physical deletion within the backup window stated there — unless EU or Member State law requires longer storage. In-app export functions allow the Customer to retrieve Customer Personal Data in a structured, commonly used format before deletion.

3.9. Audits. Make available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits. Audit process: (a) first, we provide documentation, completed security questionnaires, and our TOM; (b) if reasonably insufficient, the Customer (or an independent auditor bound by confidentiality, not a competitor of ours) may conduct an audit upon at least 30 days' written notice, during business hours, no more than once per 12 months (except after a personal data breach or where required by a supervisory authority), without access to other customers' data, and at the Customer's cost.

4. International transfers

4.1. Customer Personal Data is stored at rest exclusively within the EU (see Annex 1 and 3).

4.2. Where processing by a sub-processor involves a transfer to a third country (in particular, AI providers in the USA), the transfer is carried out: (a) on the basis of an adequacy decision, including the EU–US Data Privacy Framework where the sub-processor is certified; and/or (b) on the basis of the Standard Contractual Clauses (SCC) (Commission Implementing Decision (EU) 2021/914), Module 3 (processor → processor) or Module 2 as applicable, incorporated into our agreements with those sub-processors, together with supplementary measures where appropriate (TLS encryption in transit, minimization of transferred content, transient processing without persistent storage by AI providers beyond abuse-monitoring windows).

4.3. To the extent required, the Customer hereby authorizes us to enter into the SCC with sub-processors on its behalf for the purpose of such onward transfers.

5. Liability and miscellaneous

5.1. Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service (Section 11), except where mandatory data protection law provides otherwise (including Article 82 GDPR).

5.2. This DPA is governed by the law specified in the Terms of Service. It terminates automatically upon deletion of all Customer Personal Data.

5.3. If any supervisory authority or change in law requires amendments to this DPA (including new SCC versions), the parties will implement them in good faith; we may update this DPA with 30 days' notice where the update does not reduce the level of protection.

Annex 1 — Description of processing

Subject matter: provision of the Specky platform — centralization and AI-assisted analysis of project specifications, requirements, and tasks.

Duration: the term of the Terms of Service, plus the deletion periods described in Section 3.8.

Nature and purpose of processing: hosting, storage, structuring, display, transmission to AI providers for analysis (requirement extraction, task generation, semantic embeddings, chat answers), backup, and deletion — solely to provide the Service.

Categories of data subjects:

  • Customer's employees and contractors (named in documents, tasks, comments, recordings)
  • Customer's clients and their personnel (named in specifications, agreements, correspondence uploaded to the Service)
  • other third parties mentioned in Customer Content

Types of personal data:

  • identification and contact data (names, business email addresses, phone numbers, roles) appearing in uploaded documents and project data
  • professional data (assignments, responsibilities, work products)
  • voice recordings and their transcriptions, where the Customer uses recording features
  • any other personal data the Customer chooses to include in Customer Content

Special categories of data: the Service is not intended for special-category data (Article 9 GDPR) or data relating to criminal convictions (Article 10). The Customer instructs that such data not be uploaded and is responsible for ensuring its content complies with this instruction.

Annex 2 — Technical and organizational measures (TOM)

Access control and authentication

  • Role-based access control at organization and project level (owner/admin/member; owner/client/developer/viewer)
  • Tenant isolation enforced at the application and database query level (organization-scoped access to all resources)
  • Passwords stored as salted hashes (bcrypt/argon2); session/token invalidation on deactivation
  • MFA for administrative/operator access to infrastructure
  • Principle of least privilege for internal and operational access; production access limited to the operator

Encryption

  • TLS 1.2+ for all data in transit (user ↔ service, service ↔ sub-processors)
  • Encrypted backups; encrypted storage volumes where supported by the infrastructure provider
  • Secrets (API keys, credentials) stored in environment configuration on the production server, outside code repositories, with access limited to the operator; automated secret scanning (gitleaks) runs in the development pipeline to prevent accidental commits

Infrastructure and operations

  • Hosting in ISO 27001-certified data centers (Hetzner, Germany)
  • Network firewalls; service exposure limited to required ports; SSH key-based access only
  • Separation of production and development environments; no Customer Personal Data in development environments
  • Logging and monitoring of application and security events; logs retained up to 12 months
  • Regular application of security updates to system components and dependencies

Data lifecycle

  • Automated, encrypted backups with defined rotation (35 days); offsite backup copy within the EU
  • Deletion procedures as described in Section 3.8; deletion propagated to primary storage, vector database, and object storage
  • Upload validation (file type and size restrictions, malware-oriented handling of uploads)

Organizational measures

  • Confidentiality obligations for any personnel/contractors with data access
  • Documented incident response procedure including breach notification per Section 3.7
  • Sub-processor due diligence: DPA executed with every sub-processor; list maintained per Section 3.4
  • Periodic review of AI providers' data-use terms (training exclusions, retention windows)

Annex 3 — Approved sub-processors

The authoritative, current list is published at https://specky.app/legal/subprocessors and includes for each sub-processor: entity name, purpose, and location of processing. As of the date of this version:

Sub-processorPurposeLocation
Hetzner Online GmbHapplication hosting, databases, file storage, embeddings, backupsGermany (EU)
Anthropic Ireland, Limited / Anthropic, PBCLLM API — document analysis, requirement extraction, chatEU contracting entity; processing may occur in USA (DPF / SCC)
OpenAILLM / embeddings APIUSA (DPF / SCC)
PaddleMerchant of Record — payments, invoicing, taxUK / EU / USA
cal.pltransactional (system) email deliveryPoland (EU)

Changes to this list follow the 30-day notice procedure in Section 3.4.

Specky

The specification layer for AI-built software. Describe it, resolve it, ship it — with history.

Product
Why Specky How it works FAQ Pricing
Legal
Privacy Policy Terms of Service DPA AI-Act Refunds
© 2026 Specky. All rights reserved. Spark IT Mariusz Iskra · Mierzyn, Poland