Privacy policy
Version 2026-08-05 — last updated 4 August 2026
Controller
The controller for the processing described here, within the meaning of Art. 4(7) GDPR, is:
- Konstantinos Lamprakis
- --
- 74076 Heilbronn
- Germany
- Email: info@spark.hn
- Phone: +30 210 440 3105
What this policy covers
This policy describes what personal data we process when you visit our website and when you use the Spark platform, why we process it, what we base it on in law, who else sees it, and how long we keep it.
Where a section describes a processing of its own, it names the provision of Art. 6(1) GDPR we rely on for it. Other sections only explain how a processing described elsewhere is carried out — who is involved in it, where data goes, what is stored on your device — and rest on the basis given in the section that describes it.
You are not required by law to give us any of this data. It is, however, necessary in order to create an account and take part in the vetting process: without it we cannot provide the service and no contract between us can come about.
Account, sign-in and email verification
When you register we store your email address, your password, your account type, and the times at which your account was created, its email address confirmed, and — where applicable — activated, deactivated or deleted. We also record which version of this policy you accepted and when.
Your password is stored only as an argon2id hash. We never hold it in readable form and cannot recover it.
To confirm your email address and to let you reset a forgotten password we send you a one-time link. We store only a hash of the token in that link, together with its purpose and its expiry. Email confirmation links expire after 24 hours, password reset links after one hour.
Legal basis: Art. 6(1)(b) GDPR. The processing is necessary to create and operate the account you asked for.
Signing in with Google
You can create an innovator account with "Continue with Google" instead of a password. In that case Google Ireland Limited carries out the sign-in and tells us your email address. We receive nothing else from your Google account, and we never see your Google password.
If you register with an email address and a password instead, no data reaches Google.
Legal basis: Art. 6(1)(b) GDPR — the sign-in method you chose in order to create your account.
Innovator profile
If you apply as an innovator we ask you for your first and last name, your phone number, where you are based, your current situation (studying, working, both, or something else you describe in your own words), your date of birth and your gender, and optionally a short introduction, a list of your skills and a profile picture.
We use this to assess your application, to identify you at the on-site check-ins, and to contact you about the programme.
We do not process any special category of data within the meaning of Art. 9 GDPR. Neither a date of birth nor a gender is such a category.
Legal basis: Art. 6(1)(b) GDPR — taking part in the vetting process is the pre-contractual relationship you entered into.
Company profile and challenges
If you register as a company we store your company name, your VAT number, a phone number, a description of what your company does, and optionally an image. Challenges you publish are stored with their description, status and any files you attach.
Legal basis: Art. 6(1)(b) GDPR.
The vetting assessments
The vetting process has three stages: a set of knowledge questions, an analytical case study conducted as a written conversation, and check-ins on site in Heilbronn.
For each attempt we store when it started, when it finished, its deadlines, the text of the questions you were shown, the answers you selected, any comments you wrote, the messages you wrote during the case study, and the score, recommendation and summary reached about you.
Legal basis: Art. 6(1)(b) GDPR.
Behavioural signals during the assessments
While you write your case study answers, the page counts your keystrokes, how many times you paste text, how many characters you paste, the size of the largest single insertion of text, and how long you spend typing. Across the assessments we also count how often the assessment window loses focus.
These counts describe how a piece of text came into being, not what you were doing elsewhere. We cannot see your other windows, your other tabs, your clipboard contents or anything outside the assessment page.
Purpose: keeping the vetting process honest towards the candidates who complete it themselves.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is the integrity of the vetting process, and we consider it not to be overridden by your interests because the signals are aggregate counts, are limited to the assessment page, and are never used for any other purpose. You may object to this processing under Art. 21 GDPR.
AI-assisted grading and how we decide
Your case study answers are graded with the help of an AI model operated by OpenAI, which produces a score, a recommendation and a short summary. See "Transfer to the United States" for what leaves our servers.
That output is a recommendation, not a decision. A person at Spark reviews it together with the rest of your application and makes the admission decision. There is no decision about you based solely on automated processing within the meaning of Art. 22 GDPR.
You may contest the decision, put your own point of view, and ask for it to be reviewed by a person. Write to the email address given under "Controller".
Because your case study text is processed outside our own servers, please do not write personal details about yourself or about anyone else into your answers.
This section is our information under Art. 13(2)(f) GDPR.
Location data at the on-site check-ins
The commitment stage requires you to be at a specified place at a specified time. When you check in, your browser asks for your permission and, if you allow it, sends us the latitude and longitude it has determined together with the accuracy your device reports. We store those values, the distance from the check-in location, and the time of the check-in.
Legal basis: Art. 6(1)(a) GDPR — your consent. We ask for it explicitly before your first check-in and record when you gave it. Our servers refuse to verify a check-in for which no consent is recorded.
You may withdraw your consent at any time with effect for the future (Art. 7(3) GDPR). Withdrawing it does not affect the lawfulness of the processing carried out beforehand. Without this consent a check-in cannot be verified and the commitment stage cannot be completed.
Contact form
The contact form asks for your name, your email address, your message, and optionally the organisation you are writing from. We forward the message to ourselves by email. It is not stored in our database.
The form is protected against automated abuse by ALTCHA, which asks your browser to solve a small computational puzzle. It sets no cookie, stores nothing on your device, and does not identify you.
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in answering enquiries addressed to us, and in not having the form abused for spam.
Server logs and abuse prevention
Delivering any web page necessarily involves processing the IP address the request comes from, the time of the request, the address requested, and what your browser says about itself.
To slow down automated abuse we count requests over short windows. For signed-in users the counter is keyed to the account; otherwise it is keyed to the requesting IP address. These counters live in memory for the length of the window only and are never written to the database.
Application and server logs are written to rotating files on our servers in Germany and are overwritten as they rotate. We do not combine them with your account and we do not use them to profile you. One case does put an identifier in them: when an outgoing email fails to send, the log records the recipient address so the failure can be traced.
When something goes wrong in the software we record a technical fault report: the type of error, its message, and the trace showing where in our code it happened. Email addresses and access tokens are removed from that text before it is stored, so the report describes a defect in our software rather than a person. We keep one report per distinct fault, counting how often it has occurred, until we have fixed it.
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in operating the service, finding and fixing faults in it, and protecting it from abuse.
Measuring how the site is used
We count visits so we can see which pages people actually use and whether the site works on phones. This happens entirely on our own servers in Germany. No script runs in your browser for it, nothing is stored on or read from your device, and no analytics provider is involved at any point.
We do not store your IP address, and we do not store the description your browser sends about itself. Each day we generate a random value, combine it with those two things and the site you are on, and keep only the irreversible fingerprint that comes out of that. The random value is then destroyed after two days, after which the fingerprints from that day can no longer be traced back to anything by anyone, including us and including from a copy of our database.
What that means in practice: we can tell how many separate visitors a given day had, and we cannot tell whether someone who visited on Monday is the same person who visited on Tuesday. We do not build profiles, we cannot recognise you across days, and we cannot connect a visit to your account.
For each page view we record the page requested, which of our two sites it was on, the language shown, and whether the device is a phone, a tablet or a computer. Page views are deleted after 90 days.
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in understanding how our own site is used. Because nothing is stored on or read from your device, § 25 TDDDG does not apply and no consent is required for it.
Service providers
We use the following providers to run the service. Each acts as a processor on our behalf and processes personal data only for the purposes we set, only on our instructions, and never for its own purposes:
- Contabo GmbH, Germany — servers and hosting. The application, the database and the files you upload are stored in Germany.
- OpenAI, L.L.C., United States — grading the case study answers, see the next section.
- Google Ireland Limited, Ireland — only if you choose "Continue with Google", and only for that sign-in.
- The operator of our outgoing mail server — sending confirmation, password reset, notification and contact emails.
Transfer to the United States
Grading the case study involves OpenAI, L.L.C. in the United States, which is a third country within the meaning of Chapter V GDPR. It is the only processing in which data of yours leaves the European Union. The knowledge questions and the on-site check-ins involve no such transfer.
What is transferred: our fixed instructions to the model, and the text you wrote in the case study. What is not transferred: your user id, your email address, your name, your phone number, the identifier of your assessment attempt, or any other identifier. The outgoing request carries nothing but the model name, those messages, and the requested response format. Automated tests assert this and fail the build if an identifier is ever added.
Legal basis for the transfer: the European Commission adequacy decision of 10 July 2023 on the EU-U.S. Data Privacy Framework (Art. 45 GDPR), under which OpenAI, L.L.C. is certified. Should that decision cease to apply, we would additionally rely on the Standard Contractual Clauses (Art. 46(2)(c) GDPR) that OpenAI’s data processing addendum incorporates.
Write to the email address given under "Controller" and we will tell you where the adequacy decision and those clauses have been made available, and send you a copy of what we hold. This is our information under Art. 13(1)(f) GDPR.
According to OpenAI, data submitted through its API is not used to train its models, and API inputs and outputs are retained only briefly for abuse monitoring.
How long we keep your data
We keep personal data only as long as the purpose it was collected for lasts.
- Account, profile, assessments, evaluations, check-ins and uploaded files: for as long as your account exists.
- After you delete your account: access ends immediately, and everything belonging to it — account, profile, assessment attempts, answers, case study messages, behavioural counts, check-in coordinates, evaluations, and the pictures and files you uploaded — is erased completely within 30 days at the latest. A job runs daily to carry that out. The window exists so an accidental or coerced deletion can still be reversed; an administrator can erase everything sooner if you ask.
- Email confirmation and password reset tokens: stored only as a hash. The links expire after 24 hours and one hour respectively; the records are erased with your account.
- The record of your consent — which version of this policy you accepted and when, and when you consented to location capture: kept with your account as the evidence Art. 7(1) GDPR requires of us, and erased with it.
- Contact form messages: kept in our mailbox for as long as dealing with your enquiry requires, then deleted.
- Server and application logs: rotating files, overwritten automatically.
- Page views: deleted after 90 days. The daily random value that would make their fingerprints traceable is destroyed after 2 days, so they stop being personal data long before that.
- Technical fault reports: kept until the fault they describe has been fixed.
Storage on your device
The following is an exhaustive list of what we store on, or read from, your device. Every item is strictly necessary to provide the service you have asked for, which under § 25(2)(2) TDDDG needs no consent — and there is nothing else. That, and nothing else, is why you will not see a cookie banner here.
- A session cookie, set when you sign in. It holds a signed token containing your user id and your account type, and expires after one hour.
- A cross-site request forgery token and a return address cookie, set by the sign-in flow so that a sign-in cannot be triggered from another site.
- One short-lived cookie during "Continue with Google", holding the PKCE verifier that ties the sign-in you started to the response Google sends back. It expires after 15 minutes.
- ALTCHA on the contact form computes a proof of work in your browser and stores nothing on your device.
No tracking, and no third-party content you did not ask for
We use no advertising, no tracking pixels, no cross-site identifiers and no third-party analytics service, and we store nothing in your browser’s local or session storage. The visit counting described above runs on our own servers and never touches your device.
Content from third parties is loaded only when you ask for it: the map on the check-in page shows a placeholder until you press the button that loads it, and the walkthrough video loads the YouTube player only when you press play, and then from the no-cookie host. Until you do, no request reaches OpenStreetMap or Google.
Neither of these stores anything on your device, so neither is a § 25 TDDDG question. Loading them does disclose your IP address to the provider, which is a processing we would base on Art. 6(1)(f) GDPR — so we would rather not do it behind your back at all.
Your rights
You have the following rights in respect of your personal data. Exercising them is free of charge and we answer within one month. Write to the email address given under "Controller".
- Access, Art. 15 GDPR: a copy of the data we hold about you. Ask us and we will send it to you as a JSON file, free of charge and within one month.
- Rectification, Art. 16 GDPR: correction of inaccurate data. You can edit your profile yourself.
- Erasure, Art. 17 GDPR: deletion of your data. You can delete your account yourself from your dashboard; see "How long we keep your data" for what follows.
- Restriction of processing, Art. 18 GDPR.
- Data portability, Art. 20 GDPR: the copy we send is machine-readable JSON and is what this right entitles you to.
- Objection, Art. 21 GDPR: you may object at any time to the processing we base on legitimate interests — the behavioural signals, the handling of your enquiry, and abuse prevention.
- Withdrawal of consent, Art. 7(3) GDPR: you may withdraw your consent to location capture at any time with effect for the future.
What the copy of your data deliberately leaves out
The copy contains your own data: your account, your profile, your attempts, the questions you were shown, the answers you gave, the messages you wrote, and the score, recommendation and summary reached about you.
It leaves out the question bank itself, the correct answers and their scoring weights, the instructions given to the grading model, and the raw model output. Those are not your personal data, and Art. 15(4) GDPR protects the rights of others, including trade secrets. If you want to understand how you were assessed, ask us.
It records the files you uploaded — their identifier, and for challenge attachments also the file name, type and size — but not the contents of the files themselves. Your profile picture and your attachments stay available to you in the application, and we will send you a copy of them on request.
Complaint to a supervisory authority
You may lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, your place of work, or the place of the alleged infringement (Art. 77 GDPR).
The authority responsible for us is der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Stuttgart.
Changes to this policy
If we change this policy materially we publish it as a new version with a new date. We keep a record of the version you accepted when you registered, so it stays clear which text you agreed to. The version currently in force is shown at the top of this page.
