Privacy and compliance

Sub-processors

Last updated: September 2026

When we deliver our services, our partners may have access to your personal data. They act as (sub)processors of personal data as defined in the General Data Protection Regulation (GDPR). At i-spark we take a range of measures to make sure this data is processed safely and responsibly. Where possible, we keep data within the European Union. We have data processing agreements in place with all our partners. When we work with a partner outside the EU, personal data is transferred on the basis of a valid transfer mechanism under the GDPR, such as the EU-U.S. Data Privacy Framework or the Standard Contractual Clauses (SCCs).

(Sub)processors

Who may process your data

Google Workspace

Processor

Data processing agreement active

We use Google Workspace for user administration (Admin), collaborative office work (Docs, Sheets, Slides), and cloud storage (Drive) for our team. Because this data can contain personal data, we have a data processing agreement in place with Google Workspace.

Google's data centres meet: ISO/IEC 27001, SOC 1, SOC 2, SOC 3.

Google LLC is certified under the EU-U.S. Data Privacy Framework.

Slack

Processor

Data processing agreement active

We use Slack as an internal communication tool. We keep the sharing of personal data through Slack to a minimum. Because personal data may still pass through Slack for internal communication, we have a data processing agreement in place with Slack for completeness.

Slack meets: ISO/IEC 27001, SOC 2, SOC 3.

Slack is part of Salesforce. Salesforce, Inc. is certified under the EU-U.S. Data Privacy Framework.

Microsoft Office365

Processor

Data processing agreement active

We use Office365 for office work (Word, Excel), email (Outlook), meetings (Teams), and calendar scheduling (Outlook) for our team. Because communication with the i-spark team can contain personal data, we have a data processing agreement in place with Microsoft.

Microsoft's data centres meet: ISO/IEC 27001, SOC 1, SOC 2, SOC 3.

Microsoft Corporation is certified under the EU-U.S. Data Privacy Framework.

Simplicate

Processor

Data processing agreement active

Project management, time tracking, quotes, and invoices are handled through Simplicate. To draw up quotes and invoices correctly, we use the name and address details you have provided for your organisation. For this reason, we have a data processing agreement in place with Simplicate.

Simplicate B.V. is a Dutch company and therefore falls fully under European regulation by default.

Claude (Anthropic)

Processor

Data processing agreement active

We use Claude to support project work, such as analysis and quote preparation. Because personal data may be processed in the process, we have a data processing agreement in place with Anthropic.

Anthropic meets: ISO 27001:2022, ISO/IEC 42001:2023, SOC 2 Type I & II.

Anthropic PBC is based in the United States. For transfers of personal data to the US, Anthropic relies on the Standard Contractual Clauses (SCCs), which are included in the data processing agreement.

Freelance pool

Sub-processors

Data processing agreements active

To support projects, we occasionally use a flexible pool of specialised freelancers in Data Engineering, Data Analysis, and/or Data Science. On request, we can provide a list of the freelancers assigned to your project.

See also our Privacy Policy. Questions about this list or about how we handle your data? Contact us.