Data processing agreement
Last updated 31 July 2026
This agreement satisfies Article 28 of the GDPR and forms part of the terms of service. It is published rather than kept behind a sales call, so you can read it before you buy and a grant assessor can read it without asking.
1. Parties and roles
Controller: the sauna business subscribing to Firespark.
Processor: Allais Labs, trading as Firespark.
You decide what personal data about your customers is collected and why. We process it only to provide the platform. If we ever determined the purposes of processing ourselves we would become a controller for that processing, and we do not do that.
2. Subject matter, duration and nature
Subject matter: providing booking, payment, customer record and reporting software.
Duration: the term of the subscription, plus the deletion period in section 10.
Nature and purpose: storage, retrieval, organisation, transmission of confirmations and reminders, and generating reports, all on your instructions.
3. Categories of data subject and personal data
| Data subjects | Personal data |
|---|---|
| Your customers and guests | Name, email address, phone number, booking and visit history, amounts paid, payment references, membership or credit balance, marketing consent state, and any notes your staff choose to add |
| Your staff and administrators | Name, email address, role and access logs |
Special category data. The platform is not designed to hold health data and we ask you not to put it in free-text notes. Saunas sometimes record a medical caution, so if you decide you need to, that processing is on your instruction and under your lawful basis, and you must tell your customers about it. We would rather say this plainly than pretend the field never gets used that way.
4. Our obligations
- Process personal data only on your documented instructions, including for any transfer.
- Tell you if we believe an instruction breaches data protection law, and not carry it out until it is resolved.
- Make sure everyone with access is bound by confidentiality.
- Apply the security measures in section 6.
- Assist you with data subject requests, impact assessments and consultations with regulators.
- Not engage a new sub-processor without giving you notice under section 7.
- Make available the information you need to demonstrate compliance with Article 28.
5. Your obligations
- Have a lawful basis for the data you ask us to process.
- Give your customers the privacy information the GDPR requires, including that you use a processor.
- Collect and record marketing consent properly. The platform records consent state; it cannot invent it.
- Keep your own account credentials secure and remove access promptly when staff leave.
6. Security measures
- TLS on every connection. HTTPS only, with HSTS.
- Encryption at rest for the database and backups.
- Tenant isolation enforced in the database by row level security, with every record carrying the organisation that owns it, so isolation does not depend on application code alone.
- Role-based access, with the runtime role unable to bypass isolation policies.
- Administrative access to customer environments limited to support purposes and logged.
- Automated backups with point in time recovery, and restores tested.
- Card data never stored on our systems. It goes directly to the payment provider.
- Automated tests on every change, weighted towards booking and payment paths.
The security overview gives more detail, including the certifications we do not hold.
7. Sub-processors
You give general authorisation for us to use sub-processors. The current list is published at firespark.ie/legal/sub-processorswith each one’s purpose and location.
We give at least thirty days’ notice by email before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, we will work with you to find a solution, and if we cannot, you may end the affected part of the service without penalty and receive a refund of the unused subscription.
Every sub-processor is bound by written terms at least as protective as this agreement.
8. International transfers
Personal data is stored and processed within the European Union. We do not transfer it outside the EEA except where a sub-processor named on the sub-processors page requires it, and then only under an adequacy decision or standard contractual clauses with appropriate supplementary measures.
9. Personal data breaches
We notify you without undue delay and in any case within 24 hours of becoming aware of a personal data breach affecting your data. The notification describes the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, and the measures taken. We assist you in meeting your own 72-hour obligation to the Data Protection Commission.
10. Return and deletion
On termination you may export all personal data in CSV at no charge, for thirty days. After that we delete it, or irreversibly anonymise it, within a further thirty days, including from backups on the next backup cycle, unless EU or Irish law requires us to keep it. We confirm deletion in writing on request.
11. Audits
We provide information demonstrating compliance with Article 28 on request. You may audit no more than once a year, on thirty days’ notice, at your cost, during business hours and without disrupting other customers. A regulator may audit at any time as the law allows.
12. Data subject requests
The platform lets you find, export and delete an individual’s record yourself, which is usually the fastest route. If a request needs our help we assist within five working days. If a request comes to us directly we forward it to you without responding on your behalf, unless the law requires otherwise.
13. Liability and precedence
The liability provisions in the terms of service apply. Where this agreement and the terms of service conflict on the processing of personal data, this agreement wins.
14. Contact
Data protection queries to privacy@firespark.ie. We have not appointed a statutory Data Protection Officer because we are not required to, and we will say so rather than invent a title.