Effective Date: December 01, 2025
Privacy Policy
This Privacy Policy explains how TAAI Labs Inc., doing business as Sparkle (“Sparkle,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects personal information when you:
Visit sparkle.security or related Sparkle websites that link to this Privacy Policy;
Request a demonstration or information;
Communicate or interact with Sparkle;
Attend a Sparkle event or meeting; or
Engage with us in connection with a potential or existing business relationship.
This Privacy Policy primarily applies to Sparkle’s public website and business interactions.
Customer data processed through the Sparkle software platform may also be governed by the applicable customer agreement, data-processing agreement, security documentation, or other contractual terms.
Where Sparkle processes personal information on behalf of a customer, the customer generally determines the purposes and means of that processing.
1. Who We Are
The organization responsible for the personal information described in this Privacy Policy is:
TAAI Labs Inc., doing business as Sparkle
Website: sparkle.security
Privacy contact: privacy@sparkle.security
Depending on the context and applicable law, Sparkle may act as a data controller, business, organization, or data processor/service provider.
2. Personal Information We Collect
The personal information we collect depends on how you interact with us.
2.1 Information You Provide
We may collect information you provide directly, including:
Name;
Business email address;
Telephone number;
Job title;
Employer or organization;
Country or general location;
Information submitted through contact or demo-request forms;
Meeting availability and calendar information;
Communications, questions, feedback, and correspondence;
Event registration information;
Commercial and procurement information;
Information supplied during security, legal, compliance, or vendor assessments; and
Any other information you choose to provide.
Please do not submit credentials, secrets, source code, production data, sensitive personal information, regulated data, or confidential customer information through the public Website unless Sparkle has provided an approved secure method.
2.2 Website and Technical Information
When you access the Website, we or our service providers may receive limited technical information, such as:
IP address;
Browser and device type;
Operating system;
Referring page;
Pages visited;
Approximate geographic region;
Date and time of access;
Website performance information;
Diagnostic and error information; and
Security-related logs and events.
We use this information to operate, secure, troubleshoot, measure, and improve the Website.
2.3 Business Relationship Information
If you represent a customer, prospect, partner, supplier, investor, advisor, or other business contact, we may collect:
Professional contact details;
Communications and meeting notes;
Relationship history;
Contract and transaction information;
Procurement and billing contacts;
Support and service information; and
Security, legal, and compliance correspondence.
2.4 Information From Other Sources
We may receive information from:
Your employer or colleagues;
Referral partners;
Publicly available professional sources;
Event organizers;
Business-information providers;
Integration and technology partners; and
Service providers acting on our behalf.
We may combine this information with information you provide directly where permitted by law.
3. How We Use Personal Information
We may use personal information to:
Respond to questions and requests;
Schedule and conduct demonstrations;
Evaluate potential business relationships;
Provide requested information, materials, or communications;
Operate, maintain, secure, and improve the Website;
Diagnose technical issues and prevent misuse;
Communicate about Sparkle’s products, events, and services;
Manage customers, prospects, partners, suppliers, and advisors;
Conduct proofs of concept, pilots, or evaluations;
Prepare proposals, contracts, and commercial documentation;
Perform security, fraud-prevention, and threat-monitoring activities;
Comply with legal, regulatory, audit, and contractual obligations;
Establish, exercise, or defend legal claims;
Conduct internal analytics, planning, research, and product development;
Manage corporate transactions; and
Carry out other purposes described when information is collected.
Where required by law, we rely on one or more of the following legal bases:
Your consent;
Performance of a contract or steps taken at your request before entering a contract;
Compliance with a legal obligation;
Our legitimate interests, including operating and securing our business, responding to business inquiries, improving our services, and developing customer relationships; or
Other grounds permitted by applicable law.
Where we rely on legitimate interests, we consider whether those interests are balanced against your rights and reasonable expectations.
4. Website Analytics, Cookies, and Similar Technologies
At the Effective Date, Sparkle uses Framer’s built-in analytics on the Website.
Framer Analytics is designed to provide aggregate website-usage information without using cookies or generating persistent identifiers. We therefore do not currently use a cookie-consent banner solely for Framer Analytics.
We do not currently use the Website to place advertising or cross-site behavioral-tracking cookies.
The Website may still use technologies necessary to:
Deliver pages and assets;
Maintain security;
Prevent abuse;
Process submitted forms;
Balance traffic; or
Remember essential technical settings.
If we introduce non-essential analytics, advertising, personalization, or marketing technologies in the future, we will update this Privacy Policy and implement consent or preference controls where required.
You can configure your browser to restrict cookies and similar technologies. Restricting essential technologies may affect Website functionality.
5. Marketing Communications
We may send business-to-business communications about Sparkle where permitted by law.
You may opt out of marketing communications by:
Using the unsubscribe link in the message; or
Contacting privacy@sparkle.security.
Even after you opt out of marketing, we may continue sending non-promotional messages relating to an existing business relationship, transaction, security matter, legal notice, or service request.
We may retain a limited suppression record to ensure that your opt-out preference is respected.
6. How We Disclose Personal Information
We may disclose personal information to the following categories of recipients.
6.1 Service Providers
We may use service providers that support:
Website hosting and delivery;
Cloud infrastructure;
Email and business communications;
Forms and meeting scheduling;
Customer relationship management;
Analytics;
Security monitoring;
Document management;
Technical support;
Legal, accounting, audit, insurance, and compliance activities; and
Other business operations.
These providers may process personal information only as necessary to provide services to Sparkle and subject to applicable contractual and confidentiality obligations.
6.2 Business Partners
We may disclose limited information to implementation partners, referral partners, integration providers, or other business partners where necessary to respond to your request or manage an authorized relationship.
We will not authorize a partner to use your information for unrelated purposes unless you have been informed or have provided consent where required.
6.3 Legal and Safety Disclosures
We may disclose information where we reasonably believe disclosure is necessary to:
Comply with applicable law, regulation, court order, or legal process;
Respond to a lawful request from a regulator or governmental authority;
Protect the rights, safety, security, or property of Sparkle, our customers, users, or others;
Investigate fraud, abuse, security incidents, or violations;
Enforce agreements and policies; or
Establish, exercise, or defend legal claims.
6.4 Corporate Transactions
Personal information may be disclosed or transferred in connection with an actual or proposed:
Merger;
Financing;
Investment;
Acquisition;
Reorganization;
Sale of assets;
Insolvency proceeding; or
Similar corporate transaction.
Where appropriate, recipients will be required to handle the information consistently with this Privacy Policy or provide notice of materially different practices.
7. Sale and Behavioral Advertising
Sparkle does not sell personal information for monetary consideration.
Sparkle does not currently share personal information for cross-context behavioral advertising or use the Website to serve targeted advertising based on activity across unrelated websites.
If these practices change, we will update this Privacy Policy and provide any choices required by applicable law.
8. International Data Transfers
Sparkle and its service providers may process personal information in the United States, Singapore, and other countries where Sparkle, its affiliates, or its service providers operate.
These countries may have privacy and data-protection laws that differ from those in your jurisdiction.
Where required, we use appropriate safeguards for international transfers, which may include:
Contractual data-protection terms;
Standard contractual clauses;
Transfer-impact assessments;
Vendor security and privacy assessments; and
Other legally recognized transfer mechanisms.
You may contact us for additional information about safeguards relevant to your personal information.
9. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including legal, security, accounting, audit, dispute-resolution, and contractual requirements.
Unless a different period is required by law or an applicable agreement, our general retention periods are:
Contact and demo inquiries: up to 24 months after the last substantive interaction;
Prospect and business relationship records: for the duration of the relationship and generally up to 24 months afterward;
Customer, contract, procurement, accounting, and transaction records: generally up to seven years after the relevant transaction or termination;
Website security, diagnostic, and access logs: generally up to 12 months, unless required for an active security investigation;
Marketing preferences and suppression records: for as long as necessary to respect your communication preferences;
Legal claims and dispute records: until the matter is resolved and applicable limitation periods have expired; and
Unsuccessful job-applicant information, where applicable: according to applicable recruitment requirements and separately communicated retention periods.
We may retain anonymized or aggregated information that can no longer reasonably identify an individual.
When information is no longer required, we take reasonable steps to delete, anonymize, or securely dispose of it.
10. Data Security
We maintain administrative, organizational, physical, and technical safeguards designed to protect personal information against:
Unauthorized access;
Loss;
Misuse;
Alteration;
Destruction; and
Unauthorized disclosure.
These measures may include access controls, encryption, logging, monitoring, secure-development practices, vendor assessments, incident-response procedures, and personnel confidentiality obligations.
No website, network, transmission method, or storage system can be guaranteed to be completely secure. You should use appropriate caution when submitting information online.
If you believe information you provided to Sparkle may have been compromised, contact privacy@sparkle.security promptly.
11. Your Privacy Rights
Depending on your location and applicable law, you may have rights to:
Request confirmation that we process your personal information;
Access or obtain a copy of your personal information;
Correct inaccurate or incomplete information;
Request deletion of personal information;
Restrict or object to certain processing;
Withdraw consent where processing is based on consent;
Request data portability;
Opt out of direct marketing;
Appeal a decision concerning a privacy request; and
Submit a complaint to an appropriate privacy or data-protection authority.
These rights are not absolute and may be subject to legal exceptions.
To exercise a privacy right, contact privacy@sparkle.security and describe your request. We may need to verify your identity and authority before completing it.
Authorized agents may submit requests where permitted by law. We may request evidence of authorization and may need to verify the request directly with the individual.
We will not discriminate against you for exercising an applicable privacy right.
Singapore
Individuals covered by Singapore’s Personal Data Protection Act may request access to or correction of personal data and may withdraw consent, subject to applicable requirements and exceptions.
Concerns may also be raised with Singapore’s Personal Data Protection Commission.
European Economic Area and United Kingdom
Individuals in the European Economic Area or United Kingdom may have rights under applicable data-protection laws, including rights of access, correction, deletion, restriction, objection, portability, and withdrawal of consent.
You may also lodge a complaint with the data-protection authority in the country where you live or work.
United States
Residents of certain US states may have additional rights regarding access, correction, deletion, portability, sale, sharing, targeted advertising, profiling, or appeals.
Because Sparkle does not currently sell personal information or use it for cross-context behavioral advertising, there may be no sale or targeted-advertising activity from which to opt out.
12. Global Privacy Control and Do Not Track
Some browsers provide Global Privacy Control or Do Not Track signals.
Because Sparkle does not currently use the Website for cross-site behavioral advertising or the sale of personal information, these signals do not materially change the Website’s current tracking behavior.
If our practices change, we will evaluate and honor legally recognized preference signals as required.
13. Children’s Privacy
The Website and Sparkle’s services are intended for business and professional audiences and are not directed to children.
We do not knowingly collect personal information through the Website from individuals under 18 years of age. If you believe a child has provided personal information to us, contact privacy@sparkle.security, and we will take appropriate steps to investigate and delete it where required.
14. Third-Party Websites and Services
The Website may link to third-party websites, services, platforms, or social networks.
This Privacy Policy does not govern those third parties. Their collection and use of personal information are governed by their own policies and practices.
We encourage you to review the privacy information of third-party services before providing information to them.
15. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in:
Our services;
Technology;
Legal or regulatory requirements;
Service providers; or
Data-processing practices.
We will publish the updated Privacy Policy on the Website and change the Effective Date.
Where required by law, we will provide additional notice or obtain consent for material changes.
16. Contact Us
Questions, concerns, complaints, and privacy-rights requests may be sent to:
TAAI Labs Inc., doing business as Sparkle
Attn: Privacy
Email: team@sparkle.security
Website: sparkle.security
Please include sufficient information for us to understand and respond to your request. Do not include passwords, secrets, or unnecessary sensitive information in your email.