Commitment to Privacy: Spark ATS is committed to safeguarding the privacy and integrity of your corporate recruitment data and the personal information of candidates who apply to job openings hosted on our platform.
Section 01
Introduction & Scope
This Privacy Policy describes how Comspark Innovinfra ("Spark ATS", "we", "us") collects, stores, uses, and protects personal data in connection with the Spark ATS applicant tracking platform, related web pages, and customer recruitment portals.
This policy applies to:
- Workspace Administrators: Individuals who register or administer organization accounts.
- Recruiter Users: Authorized team members operating recruiter desks within a workspace.
- Job Applicants: Candidates who submit job applications, resumes, and credentials.
- Website Visitors: Individuals browsing public informational pages, pricing, and documentation.
Section 02
Data Controller vs. Data Processor Roles
Clarity on Data Roles:
• Candidate Data: The hiring Customer is the Data Controller. Spark ATS operates strictly as the Data Processor carrying out processing in accordance with the Customer's configuration.
• Customer Account & Billing Data: Spark ATS is the Data Controller for account registration, administrative credentials, and billing records required to service the subscription.
If you are a job applicant with questions regarding how your resume or application is evaluated, you should direct your inquiry directly to the employer or recruitment agency to whom you applied.
Section 03
Information We Collect
We collect only information reasonably necessary to provide and secure the ATS platform:
- Account & Workspace Information: Company name, workspace slug, administrator full name, business email address, bcrypt password hash, and contact phone.
- Recruitment & Candidate Data: Candidate names, email addresses, phone numbers, resumes (PDF/DOCX/TXT), cover letters, application timestamps, interview notes, and pipeline status assignments.
- Billing & Subscription Records: Plan tier, payment transaction identifiers (PayPal Order ID), billing amounts, currency, subscription status, and start/expiration dates. We do NOT store full credit card numbers or banking passwords.
- Technical Telemetry & Log Data: Internet Protocol (IP) address, browser user-agent, operating system details, referring URLs, access timestamps, and error diagnostic logs.
- Inquiries & Support Data: Name, email, and inquiry messages submitted through public contact forms.
Section 04
Methods of Data Collection
Information is collected through three primary channels:
- Direct User Input: When an administrator registers a workspace, when recruiters configure vacancies or enter candidate notes, and when candidates complete online application forms.
- File Uploads & Imports: When resumes are uploaded by applicants, or bulk-imported via spreadsheet/ZIP files by authorized recruiters.
- Automated Platform Logs: When users interact with the web application, web servers log IP addresses, browser headers, and session tokens for security, rate-limiting, and audit compliance.
Section 05
Legal Bases for Processing
Under applicable data privacy regulations, our processing of personal data is justified under the following legal bases:
- Contractual Performance: Processing necessary to fulfill our SaaS agreement with the Customer and provision the recruitment workspace.
- Legitimate Interests: Securing the application against fraud, enforcing usage quotas, diagnosing platform defects, and logging legal acceptance records.
- Legal Compliance: Maintaining financial transaction records, tax invoices, and responding to lawful legal processes.
- Consent: Where affirmative consent is obtained directly from candidates or subscribers.
Section 06
Purposes of Data Processing
Personal data processed by Spark ATS is utilized exclusively for:
- Operating, maintaining, and delivering the multi-tenant applicant tracking system.
- Enabling recruiters to review applications, schedule interviews, and transition candidates through pipeline stages.
- Extracting text from resumes to assist recruiters in evaluating applicant qualifications.
- Enforcing subscription limits, active vacancy quotas, and candidate quotas.
- Preventing duplicate applications and mitigating spam submissions.
- Processing subscription renewals, billing receipts, and administrative notifications.
Section 07
AI & Automated Resume Parsing Disclosures
Algorithmic Text Extraction Disclosure: Spark ATS employs automated resume parsing routines that extract text (such as contact info, skills, education, and work history) to organize profile fields.
These algorithmic tools are assistive only. Spark ATS does NOT perform autonomous profiling or automated disqualification of candidates. Final evaluation of applicant suitability, shortlist decisions, and hiring determinations are made exclusively by human recruiters.
Section 08
Multi-Tenant Segregation & Confidentiality Guarantees
Every organization operates in a logically segregated tenant partition bounded by its company_id. Database queries strictly scope read and write operations to the authenticated user's organization.
One customer's recruiters cannot view, search, export, or access another customer's candidate pool or vacancy data.
Section 09
Sharing & Disclosure of Information
Spark ATS does not sell, rent, or trade personal data or candidate resumes to third parties, data brokers, or advertisers. We disclose data solely under the following limited circumstances:
- With Sub-processors: Trusted cloud hosting providers and payment processors required to deliver core functionality (see Section 10).
- Compliance with Legal Orders: When compelled by subpoena, search warrant, court order, or applicable government regulation.
- Business Reorganization: In the event of a merger, acquisition, or sale of platform assets, where the successor entity remains bound by this Privacy Policy.
Section 10
Sub-processors & Infrastructure Partners
Spark ATS engages select third-party service providers and technology infrastructure to support platform operations:
- Web & Database Server Infrastructure: Managed Apache web server and MySQL relational database hosting storing application data within partitioned tenant schemas.
- PayPal: Payment processing for online subscription transactions and plan activations.
- SMTP Relay & Delivery Services: Transactional SMTP email delivery and web contact inquiry routing.
Section 11
International Data Transfers
When Customer Data or telemetry is transferred across international boundaries, Spark ATS implements appropriate technical, administrative, and contractual protections to ensure personal information remains subject to a level of security comparable to applicable data protection standards.
Section 12
Technical Security Safeguards
Spark ATS implements multi-layered security controls to protect personal data against unauthorized disclosure, interception, or destruction:
- Password Protection: Passwords are cryptographically hashed using standard Bcrypt with salted rounds; plain text passwords are never stored.
- Transport Layer Security: All data transmitted between browsers and the platform is protected via TLS/HTTPS encryption.
- SQL Injection Prevention: Database operations utilize parameterized queries and prepared statements.
- Tenant Partition Scoping: Strict access verification ensures administrative actions execute only within the authenticated company context.
- Audit Trails: Acceptance of Terms and Privacy is recorded with exact server timestamp, IP address, and browser user agent.
Section 13
Data Retention Schedules
Personal data is retained in accordance with operational necessity:
- Active Workspaces: Candidate and vacancy data is retained during the active lifecycle of the customer's subscription.
- Expired or Inactive Workspaces: Customer data remains stored within the inactive tenant partition to permit account reinstatement or administrative data export. Automated permanent deletion is not currently executed; data is deleted upon manual deletion by the administrator, written decommissioning request by the customer, or periodic maintenance.
- Transactional & Audit Logs: Subscription records, legal acceptance records, and system security logs are retained for audit and compliance purposes.
Section 14
Candidate Data Rights Channel
Because Spark ATS acts as a Data Processor on behalf of the hiring organization (the Data Controller), candidates seeking to inspect, update, or delete their application records should submit requests directly to the employer or agency managing the job vacancy.
Organization Administrators possess administrative tools within the platform to edit candidate details, update recruitment status, or delete candidate profiles upon request.
Section 15
Data Subject Rights
Depending on your geographic location and applicable data privacy laws, you may hold rights regarding your personal data:
- Right of Access: To request confirmation and a copy of personal data held about you.
- Right to Rectification: To request correction of inaccurate or incomplete personal data.
- Right to Erasure ("Right to be Forgotten"): To request deletion of your personal data under certain conditions.
- Right to Restrict Processing: To request limitation of processing activities.
- Right to Data Portability: To receive your data in a structured, commonly used machine-readable format.
- Right to Object: To object to data processing based on legitimate interests.
Section 16
Cookies & Tracking Technologies
Spark ATS uses strictly necessary session cookies and CSRF tokens essential for user authentication, session persistence, and preventing cross-site request forgery attacks.
We do not employ third-party behavioral advertising cookies, cross-site trackers, or marketing pixels within the authenticated recruitment workspace.
Section 17
Children's Privacy
Spark ATS is intended solely for recruitment by commercial organizations and adult job seekers of legal employment age. We do not knowingly solicit or collect personal information from individuals under the age of sixteen (16).
Section 18
Incident & Security Breach Notification Procedures
In the unlikely event of a confirmed security incident resulting in unlawful unauthorized disclosure or destruction of Customer Data, Spark ATS will notify affected Customer Administrators without undue delay, providing available details on the scope of the incident and corrective remediation actions taken.
Section 19
Policy Amendments & Version Tracking
We may periodically update this Privacy Policy. All revisions are cataloged in our versioned document database with explicit effective dates. Material revisions will be accompanied by prominent notifications on the website or via administrative email.
Section 20
Privacy Inquiries & Compliance Contact
For questions concerning this Privacy Policy, your personal data, or to exercise applicable privacy rights, contact our compliance team:
Section 21
Regulatory Authority & Complaints Recourse
If you believe our processing of your personal data infringes applicable data protection legislation, you may have the right to lodge a complaint with your competent national or state data protection supervisory authority.
Section 22
Effective Date & Document Versioning
This document represents Spark ATS Privacy Policy Version 1.0, effective as of September 19, 2026.