Data Processing Agreement
Version 1.2 · Effective 24 June 2026 · Sparrowhawk's processing of Customer Personal Data on Customer's behalf
1. Definitions
1.1 "Personal Data" means any information relating to an identified or identifiable natural person that is submitted to the Services by Customer or on its behalf, or that is collected through the Services on Customer's behalf. This includes, without limitation, names, email addresses, phone numbers, physical addresses, and any other data defined as "personal information," "personal data," or equivalent term under applicable Data Protection Laws.
1.2 "Data Protection Laws" means all applicable federal, state, and local laws and regulations relating to data privacy, data protection, and data security, including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), the Colorado Privacy Act, the Connecticut Data Privacy Act, the Virginia Consumer Data Protection Act, and any other US state privacy laws applicable to Customer's use of the Services.
1.3 "Processing" means any operation or set of operations performed on Personal Data, including collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction.
1.4 "Security Incident" means a confirmed unauthorized access to, or unauthorized acquisition, disclosure, or use of, Personal Data on Sparrowhawk's systems that results in loss, disclosure, or alteration of Personal Data.
1.5 "Subprocessor" means any third party engaged by Sparrowhawk to process Personal Data on behalf of Customer.
1.6 "Services" has the meaning given in the Agreement.
2. Scope and purpose of processing
2.1 Role of the parties. Customer is the Controller of Customer Data (including Personal Data). Sparrowhawk is the Processor, processing Personal Data solely on behalf of and under the documented instructions of Customer to provide the Services. Where Sparrowhawk processes data that has been de-identified and/or aggregated such that it no longer relates to an identified or identifiable natural person ("Aggregated Data", as defined in Section 9.2(b) of the Agreement), Sparrowhawk acts as Controller of that Aggregated Data; data protection laws that apply only to Personal Data do not apply to Aggregated Data.
2.2 Purpose of processing. Sparrowhawk will process Personal Data only for the following purposes:
- (a) Providing, operating, maintaining, and supporting the Services as described in the Agreement;
- (b) Providing customer support and resolving technical issues;
- (c) Detecting and preventing fraud, security threats, abuse, and violations of the Agreement;
- (d) Maintaining, improving, training, and developing the Services and related machine-learning models, security systems, and operational tooling (where Personal Data is used for internal training rather than Aggregated Data, subject to the access controls and audit logging in Section 4.4, and not subject to the de-identification standards in Section 2.4 which apply to external use only);
- (e) Generating Aggregated Data for use as permitted under Section 9.2 of the Agreement, including: cross-customer benchmarks and industry insights; training, tuning, and improving algorithms and machine-learning models that power the Services; and producing publishable market intelligence;
- (f) Complying with applicable law or valid legal process;
- (g) Establishing, exercising, or defending legal claims; and
- (h) Disclosing Contributory Data to Contributory Data Partners as permitted under Section 2.7 of this DPA and Section 9.3 of the Agreement, including for the generation of third-party credit, risk, or payment-performance scores and reports.
2.3 Customer instructions. Sparrowhawk will process Personal Data only in accordance with Customer's documented instructions, which are deemed to include the processing described in this DPA, the Agreement, and any Order. If Sparrowhawk believes an instruction from Customer infringes applicable Data Protection Laws, Sparrowhawk will notify Customer without undue delay.
2.4 De-identification standards. Scope. The de-identification standards in this Section 2.4 apply when Sparrowhawk uses Customer Data for external purposes: (i) publication of benchmarks, market intelligence, or industry insight reports made available to other customers, partners, or the public; and (ii) sharing with Subprocessors for purposes other than serving Customer. The standards do not apply to Sparrowhawk's internal use of Customer Data for model training, evaluation, improvement, security, fraud-prevention, or service operation; such internal use is governed by Section 4.4 and the Agreement's access-control and audit-logging requirements. Where the standards apply, Sparrowhawk will:
- (a) Remove direct identifiers (names, email addresses, phone numbers, postal addresses, account IDs, IP addresses, device identifiers, free-text notes that may contain identifiers, cannabis licence numbers tied to a specific operator, and any other field reasonably likely to identify an individual or Customer);
- (b) Apply minimum-cohort thresholds for any cross-customer aggregate that is published or made available to other customers or third parties: no metric will be reported for a cohort smaller than ten (10) distinct customers contributing data, except where mathematically further protected (e.g. differential-privacy techniques that bound disclosure risk);
- (c) Apply k-anonymity (k ≥ 5) or equivalent statistical protections to any quasi-identifier combinations (e.g. licence type × state × month) before publication or external sharing;
- (d) Maintain pipeline separation: per-customer service pipelines (which process identifiable Customer Data) are logically and access-control-separated from cross-customer analytics and model-training pipelines (which receive only de-identified inputs);
- (e) Document and review the de-identification process at least annually, and on each material change to the data model, with the documentation made available to Customer on reasonable request.
The current published de-identification standard is available at https://www.sparrowhawklabs.com/legal/deidentification-standards and may be updated from time to time, provided that updates do not materially weaken the safeguards in this Section 2.4.
2.5 Customer Non-Essential Analytics Opt-Out. Customer may, by written notice to privacy@sparrowhawklabs.com, opt out of being included in: (i) publishable benchmarks and external industry insights reports; and (ii) Aggregated Data made available to other Sparrowhawk customers, partners, or the public. The opt-out does not apply to: (a) Sparrowhawk's internal model training, tuning, evaluation, or improvement (which uses Personal Data under the access controls and audit logging in Section 4.4); (b) operating, securing, supporting, or improving the Services for Customer; (c) preventing fraud, security threats, and abuse; (d) complying with law; or (e) Aggregated Data already generated before the opt-out took effect (which by definition no longer relates to Customer or any individual). Sparrowhawk will implement an accepted opt-out within thirty (30) days of receipt and will confirm implementation in writing.
2.6 Re-identification prohibited. Sparrowhawk will not attempt to re-identify Aggregated Data, will not combine Aggregated Data with any other data set in a manner intended to enable re-identification of an individual or Customer, and will require its Subprocessors and any third-party recipient of Aggregated Data to comply with the same prohibition.
2.7 Contributory Data Partner disclosure. Sparrowhawk may disclose Contributory Data (as defined in Section 9.3(a) of the Agreement) to a Contributory Data Partner (as defined in Section 9.3(a) of the Agreement), solely for that partner's generation of credit scores, risk signals, suggested credit limits, or similar reports, as further described in Section 9.3 of the Agreement. Customer's continued non-exercise of the opt-out right in Section 9.3(f) of the Agreement constitutes Customer's documented instruction, for purposes of Section 2.3 of this DPA, authorizing this disclosure. This disclosure may constitute a "sale" or "sharing" of Personal Data under the CCPA/CPRA or other applicable Data Protection Law; Sparrowhawk does not contend otherwise. Sparrowhawk will: (a) limit Contributory Data to the minimized fields defined in Agreement Section 9.3(a); (b) impose the flow-down obligations in Agreement Section 9.3(d) on each Contributory Data Partner by written agreement; (c) maintain the published Contributory Data Partner registry described in Agreement Section 9.3(e) and list current Contributory Data Partners in Annex B to this DPA; and (d) implement Customer opt-outs under Agreement Section 9.3(f) within the timeframe stated there.
3. Categories of data subjects and Personal Data
3.1 Data subjects. Personal Data processed under this DPA may relate to the following categories of data subjects:
- Customer's employees, contractors, and authorized users of the Services;
- Customer's end-customers (cannabis retailers, cultivators, processors, distributors);
- Customer's business contacts, vendors, and partners; and
- Other individuals whose Personal Data is submitted to the Services by Customer.
3.2 Categories of Personal Data. The types of Personal Data processed may include:
- Contact information (names, email addresses, phone numbers, physical addresses);
- Account credentials (usernames, hashed passwords);
- Business information (job titles, company names, cannabis licence numbers);
- Transaction data (sales volumes, order history, pricing, inventory data);
- Communications (support tickets, in-app messages, notes);
- Usage data (log data, device information, IP addresses); and
- Any other Personal Data submitted to the Services by Customer.
3.3 Sensitive data. Sparrowhawk does not intentionally process sensitive personal information (as defined under applicable Data Protection Laws), including protected health information, biometric data, or financial account numbers. Customer shall not submit sensitive personal information to the Services unless expressly agreed in writing.
3.4 Cannabis-specific data. Customer acknowledges that certain data processed through the Services — including cannabis licence numbers, sales volumes, compliance records, and regulatory filings — may be subject to heightened regulatory requirements. Customer is solely responsible for ensuring that its submission of such data complies with applicable laws and regulations, including those relating to cannabis operations.
4. Data processing obligations
4.1 Confidentiality. Sparrowhawk will ensure that all personnel who process Personal Data are bound by appropriate confidentiality obligations (whether contractual or statutory) and are trained on applicable data protection requirements.
4.2 Processing limitations. Sparrowhawk will not:
- (a) Sell Personal Data or share it for cross-context behavioural advertising, except for disclosures of Contributory Data to Contributory Data Partners made in accordance with Section 2.7;
- (b) Process Personal Data for any purpose other than those specified in Section 2.2;
- (c) Combine Personal Data with personal information collected from other sources, except as necessary to provide the Services; or
- (d) Retain Personal Data longer than necessary to fulfil the purposes of processing or as required by applicable law.
4.3 Compliance certification. Sparrowhawk certifies that it understands the restrictions in this DPA and will comply with them.
4.4 Algorithm and model training scope. Where Sparrowhawk processes Personal Data for the development, training, tuning, or evaluation of algorithms or machine-learning models (Section 2.2(d) above):
- (a) Such processing is conducted within Sparrowhawk's controlled environments by personnel bound by confidentiality obligations under Section 4.1, and is subject to access controls and audit logging applied to internal use of Personal Data;
- (b) Personal Data is not used to train models that are made available to other customers in a form that exposes, memorises, or could reproduce identifiable Customer Data of any other customer;
- (c) Internal training, evaluation, and improvement. Sparrowhawk may use Customer Data to train, tune, evaluate, and improve the models, features, security systems, and operational tooling that power the Services. Internal use is subject to access controls, audit logging, and the prohibitions in Section 4.4(e). Sparrowhawk is not required to de-identify Customer Data prior to internal training, evaluation, or improvement.
- (d) External use and Subprocessor sharing. When Sparrowhawk uses Customer Data for purposes outside its internal product, security, and operational scope — including publication of benchmarks, sharing with Subprocessors for purposes other than serving Customer, or making data available to other customers, partners, or the public — Sparrowhawk applies the de-identification standards in Section 2.4 before such external use.
- (e) Prohibitions. Regardless of internal or external use, Sparrowhawk will not (i) memorise Customer Data in a way that allows verbatim regurgitation through the Services; (ii) leak Customer Data to third-party large-language-model providers; (iii) sell Customer Data; or (iv) disclose Customer Data identifiably to any other customer.
- (f) Sparrowhawk will not use Customer's Personal Data to train, tune, or improve any third-party model that is not under Sparrowhawk's contractual control as a Subprocessor under Section 5;
- (g) Outputs and model parameters that constitute Aggregated Data (Section 9.2(b) of the Agreement) are owned by Sparrowhawk; outputs that contain Personal Data remain Personal Data subject to this DPA.
5. Subprocessors
5.1 Authorization. Customer grants Sparrowhawk general written authorization to engage Subprocessors to process Personal Data, subject to the requirements of this Section 5.
5.2 Current Subprocessors. A list of Sparrowhawk's current Subprocessors is set out in Annex A to this DPA. Sparrowhawk will maintain an up-to-date list of Subprocessors at https://www.sparrowhawklabs.com/legal/subprocessors.
5.3 Notification of changes. Sparrowhawk will notify Customer at least thirty (30) days before engaging a new Subprocessor or making a material change to an existing Subprocessor. The notification will include the Subprocessor's name, the nature of processing, and the location of processing.
5.4 Objection. If Customer has a reasonable, documented objection to a new Subprocessor based on data protection grounds, Customer will notify Sparrowhawk within fifteen (15) days of receiving the notification. The parties will discuss the objection in good faith. If the parties cannot resolve the objection within thirty (30) days, Customer may terminate the affected Order(s) by providing written notice, and Sparrowhawk will refund any prepaid, unused fees for the terminated period.
5.5 Flow-down obligations. Sparrowhawk will enter into written agreements with each Subprocessor that impose data protection obligations no less protective than those in this DPA, including the de-identification standards in Section 2.4 and the re-identification prohibition in Section 2.6 to the extent applicable to the Subprocessor's role. Sparrowhawk will impose equivalent contractual restrictions on any third party to whom it discloses Aggregated Data (including a re-identification prohibition and, where the Aggregated Data is licensed for further use, restrictions on combining it with other data sets in a manner intended to enable re-identification). Sparrowhawk will be responsible for its Subprocessors' acts and omissions to the same extent as if performed by Sparrowhawk.
6. Data subject rights
6.1 Assistance. Sparrowhawk will assist Customer in responding to requests from data subjects to exercise their rights under applicable Data Protection Laws, including rights of access, correction, deletion, portability, and opt-out. Sparrowhawk will promptly notify Customer if it receives a data subject request directly, and will not respond to such request except on Customer's documented instructions or as required by law.
6.2 Capabilities. The Services provide Customer with self-service tools to access, export, correct, and delete Personal Data. Where a data subject request requires action beyond what is available through the Services' standard functionality, Sparrowhawk will provide commercially reasonable assistance at Customer's expense (at Sparrowhawk's then-current professional services rates).
6.3 Timeframe. Sparrowhawk will respond to Customer's assistance requests within ten (10) business days, or such shorter period as required by applicable Data Protection Laws.
7. Security measures
7.1 Technical and organizational measures. Sparrowhawk will implement and maintain appropriate technical and organizational measures designed to protect Personal Data against unauthorized access, alteration, disclosure, or destruction, including:
- (a) Encryption: Personal Data encrypted in transit (TLS 1.2+) and at rest (AES-256);
- (b) Access controls: Role-based access controls, multi-factor authentication for administrative access, principle of least privilege;
- (c) Network security: Firewalls, intrusion detection, DDoS mitigation, network segmentation;
- (d) Logical separation: Customer Data logically separated between customers;
- (e) Logging and monitoring: Access logging, security event monitoring, anomaly detection;
- (f) Vulnerability management: Regular vulnerability scanning and patching, periodic penetration testing;
- (g) Employee security: Background checks for personnel with access to Personal Data, security awareness training; and
- (h) Physical security: Hosting in SOC 2 Type II certified data centres (Google Cloud Platform).
7.2 Hosting location. Personal Data is hosted in data centres located in the United States, primarily on Google Cloud Platform (GCP). Customer Data will not be transferred outside the United States unless otherwise agreed in writing.
8. Security incident notification
8.1 Notification. Sparrowhawk will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Security Incident.
8.2 Contents of notification. The notification will include, to the extent reasonably available:
- (a) A description of the nature of the Security Incident, including the categories and approximate number of data subjects and Personal Data records affected;
- (b) The name and contact details of Sparrowhawk's point of contact for further information;
- (c) A description of the likely consequences of the Security Incident; and
- (d) A description of the measures taken or proposed to be taken to address the Security Incident and mitigate its effects.
8.3 Cooperation. Sparrowhawk will cooperate with Customer's reasonable requests for additional information and will take commercially reasonable steps to contain, investigate, and remediate the Security Incident.
8.4 Customer notification obligations. Customer is responsible for notifying affected data subjects and regulatory authorities as required by applicable Data Protection Laws. Sparrowhawk will provide reasonable assistance with such notifications at Customer's expense.
9. Data retention and deletion
9.1 During the term. During the term of the applicable Order, Sparrowhawk will retain Personal Data as necessary to provide the Services and as instructed by Customer.
9.2 Upon termination. Upon expiration or termination of an Order:
- (a) Customer may request an export of Personal Data within thirty (30) days of termination, as described in Section 7.4 of the Agreement;
- (b) Sparrowhawk will delete or anonymise Personal Data no earlier than ninety (90) days and no later than one hundred eighty (180) days after termination, subject to applicable legal obligations;
- (c) Sparrowhawk may retain Personal Data beyond the deletion window only where required by applicable law, provided that such retention is limited to the minimum necessary and that appropriate safeguards are maintained.
9.3 Certification. Upon Customer's written request, Sparrowhawk will certify in writing that it has deleted Personal Data in accordance with this Section 9.
10. International data transfers
10.1 US-only processing. As of the effective date of this DPA, Sparrowhawk processes Personal Data exclusively within the United States. No cross-border transfer mechanisms are currently required.
10.2 Future transfers. If Sparrowhawk determines that it is necessary to transfer Personal Data outside the United States, Sparrowhawk will: (a) notify Customer in advance; (b) ensure that appropriate safeguards are in place in accordance with applicable Data Protection Laws; and (c) update this DPA to reflect the transfer mechanism used.
11. Audit rights
11.1 Audit. Customer may audit Sparrowhawk's compliance with this DPA up to once per twelve (12) month period, upon at least thirty (30) days' prior written notice. Audits will be conducted during normal business hours, at Customer's expense, and will not unreasonably interfere with Sparrowhawk's business operations.
11.2 Scope. Audits will be limited to the processing of Personal Data under this DPA and may include review of Sparrowhawk's data processing records, security documentation, and Subprocessor agreements.
11.3 Alternatives. Sparrowhawk may satisfy an audit request by providing Customer with: (a) a copy of a relevant third-party audit report or certification (e.g., SOC 2 Type II); (b) responses to a reasonable data protection questionnaire; or (c) other documentation that reasonably demonstrates compliance with this DPA.
12. CCPA/CPRA specific provisions
12.1 Service provider. To the extent that the CCPA/CPRA applies to Sparrowhawk's processing of Personal Data, Sparrowhawk is a "service provider" (as defined in the CCPA/CPRA) and will process Personal Data solely for the business purposes specified in this DPA and the Agreement.
12.2 No sale or sharing; Contributory Data exception. Sparrowhawk will not sell Personal Data or share Personal Data for cross-context behavioural advertising purposes (as those terms are defined under the CCPA/CPRA), except for disclosures of Contributory Data to Contributory Data Partners made in accordance with Section 2.7, which the parties acknowledge may constitute a "sale" or "sharing" of Personal Data under the CCPA/CPRA. Where such a disclosure occurs, Sparrowhawk will provide the opt-out rights described in Section 2.7 and Agreement Section 9.3(f), and will honour opt-out requests submitted via Sparrowhawk's "Do Not Sell or Share My Personal Information" mechanism or a recognized Global Privacy Control (GPC) signal, consistent with Sparrowhawk's Privacy Policy.
12.3 Compliance. Sparrowhawk will comply with applicable obligations under the CCPA/CPRA and will assist Customer in responding to verifiable consumer requests.
12.4 GDPR / UK GDPR readiness statement. As of the effective date of this DPA, Sparrowhawk targets US-based Customers and processes Personal Data exclusively in the United States; Sparrowhawk does not currently accept Personal Data subject to the EU General Data Protection Regulation (GDPR) or the UK GDPR. The data-protection commitments in this DPA — including purpose limitation (§2.2), de-identification standards (§2.4), data-subject-rights assistance (§6), security (§7), 72-hour breach notification (§8), retention and deletion (§9), and audit rights (§11) — are designed to be substantially aligned with the principles of GDPR Article 5 and to support a future GDPR/UK-GDPR-compliant offering. Where Customer is established in, or processes Personal Data of data subjects in, the European Economic Area, the United Kingdom, or Switzerland, the parties will execute a separate UK/EU Addendum (incorporating the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, as applicable) before any such Personal Data is submitted to the Services.
13. Term and survival
13.1 Term. This DPA will remain in effect for the duration of the Agreement and any Orders thereunder.
13.2 Survival. Sections 4.2 (processing limitations), 8 (security incident notification), 9 (data retention and deletion), and 11 (audit rights) will survive expiration or termination of this DPA for as long as Sparrowhawk retains any Personal Data.
14. Contact
For data protection inquiries, contact:
Sparrowhawk Labs, Inc. 1605 NW Galveston Ave Bend, OR 97703 United States Email: privacy@sparrowhawklabs.com
Annex A: Subprocessors
Current as of 2026-07-05.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Google Cloud Platform (GCP) | Cloud hosting and infrastructure | All Customer Data | United States |
| FluidPay / PayRio | Cannabis-compliant payment processing | Billing information, transaction data | United States |
| Postmark / SendGrid | Transactional email delivery | Email addresses, notification content | United States |
| Sentry | Error monitoring and diagnostics | Technical logs, anonymised usage data | United States |
| ContentSquare | Product analytics | Anonymised usage/interaction data | United States |
Sparrowhawk will maintain an up-to-date list of Subprocessors at: https://www.sparrowhawklabs.com/legal/subprocessors
Annex B: Contributory Data Partners
Current as of 2026-07-08.
| Contributory Data Partner | Purpose | Contributory Data disclosed | Consideration received |
|---|---|---|---|
| None currently active. | — | — | — |
Per Section 2.7 and Agreement Section 9.3(e), Sparrowhawk will provide thirty (30) days' advance notice via this Annex and the published registry at https://www.sparrowhawklabs.com/legal/data-partners before any Contributory Data Partner disclosure begins.