Sub-Processor Disclosure
Customer data does not reach Sparcle infrastructure.
This disclosure satisfies the sub-processor transparency requirements in GDPR Art. 28, CCPA / CPRA, Quebec Law 25, PIPEDA, Singapore PDPA, UAE Federal Decree-Law No. 45 of 2021, and equivalent regimes. The asymmetric structure below reflects the operative reality: in every shipping topology, customer data is processed in the customer's own infrastructure by services the customer has selected.
At a glance
The asymmetric topology, visualized.
Customer data is processed by sub-processors the customer configures, inside the customer's perimeter. Sparcle's own sub-processors handle only Sparcle's own business operations, not customer data. The two sets do not touch, and the only flow that crosses the boundary is from Sparcle outward, in the form of container images, Helm charts, and advisories.
Scope
Who this disclosure is for.
This disclosure covers data-processing roles in Sparcle's standard deployment topologies. It is required reading for any customer subject to GDPR Art. 28, CCPA or CPRA, Quebec Law 25, PIPEDA, Singapore PDPA, UAE Federal Decree-Law No. 45 of 2021, or equivalent personal-data legislation.
If your contract requires Sparcle to use only sub-processors that you have approved in writing, this list is the starting point for that approval process.
Deployment topology
Topology determines who processes what.
Sparcle's role under data-protection law depends on which deployment topology you operate. In every shipping topology, customer data does not reach Sparcle-controlled infrastructure.
| Topology | Customer data path | Sparcle's role |
|---|---|---|
| Single-user (sidecar or desktop) | All data stays on the end-user's machine. No network egress to Sparcle. | Sparcle is not a data processor. |
| Production (Helm in customer infra) | All data stays inside the customer's Kubernetes cluster. The bolt-api binary runs on customer compute, reads from customer-provided Postgres and Redis, and calls customer-configured LLM endpoints. | Sparcle is not a data processor for customer data. Sparcle is the software vendor. |
| Hosted Bolt | Not applicable. Sparcle does not offer hosted Bolt today. | Not applicable. |
Sub-processors of the customer
Configured by you, inside your environment.
These are services the customer configures inside their Bolt deployment. They process customer data only because the customer points Bolt at them. Sparcle does not select them, hold credentials for them, or have access to them.
| Sub-processor | Typical providers | Purpose | Customer action |
|---|---|---|---|
| Large Language Model API | Anthropic (Claude), OpenAI (GPT), Azure OpenAI, AWS Bedrock, Google Vertex, Ollama (self-hosted), vLLM (self-hosted), and others | Generates LLM completions from masked prompts | Customer signs DPA or BAA directly with chosen LLM provider. Anthropic, OpenAI, and the major cloud providers all offer BAAs for HIPAA. |
| Identity Provider | Google Workspace, Microsoft Entra ID, Okta, Auth0, Keycloak, AWS IAM Identity Center, custom OIDC or SAML | Authenticates users; provides directory data via SCIM | Customer-owned IdP relationship. |
| Cloud Compute | AWS, Azure, GCP, on-premises Kubernetes, private cloud | Hosts the customer's bolt-api pods and managed Postgres and Redis | Customer-owned cloud account. |
| Managed Database | RDS, Cloud SQL, Aurora, Azure Database, on-prem Postgres | Stores audit logs, sessions, encrypted MCP tokens, encrypted PII vault | Customer-owned, customer-encrypted at rest. |
| Managed Cache | ElastiCache, Memorystore, Azure Cache, on-prem Redis | Session ephemera; PII tokenization map for in-flight requests | Customer-owned. |
| Object Storage (optional) | S3, GCS, Azure Blob | Backup target and audit-chain WORM archive | Customer-owned, customer-encrypted. |
| MCP Integrations | Customer-chosen (Jira, Salesforce, Slack, GitHub, internal services) | Tool execution endpoints the customer's agents call | Customer-owned credentials; OAuth tokens stored encrypted in the customer's bolt-api Postgres. |
| SIEM or Logging | Splunk, Sentinel, Datadog, Elastic, customer-deployed forwarder | Receives bolt-api stdout JSON for retention | Customer-owned SIEM relationship. |
| KMS | Local file-backed (production-tested; pilots, dev, air-gap). AWS KMS and HashiCorp Vault Transit reference implementations in the aeira-rs trait library; cloud-service integration testing in flight. PKCS#11 HSM, Azure Key Vault, and GCP KMS reference implementations on the roadmap. | Wraps per-tenant Customer Master Keys | Customer-owned; Sparcle has no access. |
Sub-processors of Sparcle
Sparcle's own business operations only.
Bolt processes no customer data on Sparcle infrastructure. The vendors below handle only Sparcle's own business operations (contact details, support email and internal documents).
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| GitHub, Inc. (Microsoft) | Source code hosting, container registry (GHCR), CI / CD | Sparcle source code; published container images; build telemetry | United States (with global edge) |
| Anthropic, PBC | LLM API used internally by Sparcle engineers to author and review code (NOT in customer data path) | Sparcle's own development queries; never customer data | United States |
| Cloudflare, Inc. | DNS, domain registration, marketing-site hosting (Cloudflare Pages), DDoS and bot protection, edge functions for the contact form | DNS records, marketing-site requests, contact-form submissions | United States (with global edge) |
| Zoho Mail (Zoho Corporation) | Sparcle internal email | Sparcle internal correspondence; never customer data | United States (zoho.com US data centre) |
| Google Workspace (Google LLC) | Internal document collaboration (Docs, Drive) | Sparcle internal documents; never customer data | United States |
| Accounting, payroll, business operations | To be disclosed on first contract requiring it. Anticipated providers include Mercury, Gusto, and Stripe. | Sparcle's own financial and employment records | United States |
What Sparcle does not do
The boundary, stated plainly.
- Operate a multi-tenant hosted version of Bolt for production customers.
- Hold customer encryption keys, KMS material, or PII master values.
- Process customer audit logs on Sparcle-controlled infrastructure.
- Access customer Postgres, Redis, or LLM-provider API keys.
- Receive telemetry, analytics, or usage data from production customer installations (no phone-home; verifiable via NetworkPolicy egress deny).
- Sub-process any customer data via affiliates, contractors, or acquirers without prior notice and the customer's right-to-object.
Notice of changes
30-day advance notice for sub-processor changes.
Sparcle will notify the customer (via the email on file with the account) at least 30 calendar days before adding or replacing a sub-processor that handles customer data. The customer has the right to object in writing within that window; if Sparcle cannot reasonably accommodate the objection, the customer may terminate the affected service for cause.
For sub-processors that handle only Sparcle's own internal data (the Sub-processors of Sparcle table above), no advance notice is required. That table is refreshed when changes are made. A planned change of Sparcle's email provider will be announced the same way, by updating that table when the change is made.
Customers who want active notification can subscribe by emailing [email protected] with the subject line "subprocessor notifications".
Cross-border transfers
Mechanisms we rely on.
When sub-processors operate outside the customer's data-residency jurisdiction, Sparcle relies on the following transfer mechanisms.
| Jurisdiction | Mechanism |
|---|---|
| EU and UK | EU Standard Contractual Clauses (2021/914) plus UK IDTA addendum where applicable. |
| Switzerland | Swiss-FADP-equivalent SCCs. |
| United States (HIPAA) | BAA where applicable. (We do not hold a SOC 2 Type II report today.) |
| Canada | PIPEDA-compliant data-handling commitments. |
| Other jurisdictions | Case-by-case. Contact [email protected]. |
Questions about a specific sub-processor or transfer mechanism?
Version 0.2. Counsel review pending; this page is updated on any material change.