GDPR and Data Hosting
Last updated: June 4, 2026
This page explains how JWP, LLC ("we," "us," or "our") handles personal data of users in the European Economic Area ("EEA"), United Kingdom, and Switzerland under the EU General Data Protection Regulation ("GDPR") and the UK GDPR, and where the Sparkbooth AI platform ("Service") is hosted. It supplements our Privacy Policy, which describes our overall data practices.
1. Data Controller
For personal data we collect to operate the Service, JWP, LLC is the data controller:
- JWP, LLC
- 400 Spear Street, San Francisco, California, United States
- Contact: hello@sparkbooth.com
We have not appointed a Data Protection Officer because we are not required to under Article 37 GDPR. For privacy questions, contact us at the email address above with the subject line "GDPR Request."
2. Where the Service Is Hosted
The Service runs on Amazon Web Services (AWS) infrastructure in the US East (Ohio) region (us-east-2). All application servers, databases, and S3 storage buckets for the Sparkbooth AI platform are provisioned in this single region. Database backups are encrypted at rest and remain in the same region.
Some processing happens outside us-east-2 by sub-processors we rely on (payments, AI transformation, authentication providers). Section 5 below lists each one and where it processes data.
3. International Data Transfers
Because our infrastructure is hosted in the United States, using the Service from the EEA, UK, or Switzerland necessarily involves a transfer of your personal data to a third country under Chapter V of the GDPR. We rely on the following transfer mechanisms:
- EU-U.S. Data Privacy Framework (DPF), including the UK Extension and the Swiss-U.S. DPF, where the sub-processor is certified. AWS, Stripe, Google, and Meta are certified under the DPF as of the "Last updated" date.
- Standard Contractual Clauses (SCCs) approved by the European Commission, where a sub-processor is not DPF-certified or where the DPF is unavailable for the relevant data category.
JWP, LLC itself is a small US-based company and does not currently self-certify under the DPF; we rely on SCCs in our user agreement for transfers from the EEA/UK/Switzerland to us, together with the safeguards described in Sections 4 and 5.
4. Lawful Bases for Processing
We process personal data on the following GDPR Article 6 bases, depending on the context:
- Performance of a contract (Art. 6(1)(b)) — account creation, authentication, processing transformations you submit, billing, and customer support.
- Legitimate interests (Art. 6(1)(f)) — fraud and abuse prevention, security monitoring, debugging, and improving the Service. We balance these interests against your rights and freedoms before relying on this basis.
- Compliance with legal obligations (Art. 6(1)(c)) — retention of payment records for tax and accounting, response to lawful requests from authorities.
- Consent (Art. 6(1)(a)) — where you have given consent for a specific purpose, you may withdraw it at any time without affecting prior processing.
We do not use personal data for automated decision-making or profiling that produces legal or similarly significant effects on you (Art. 22 GDPR).
5. Sub-processors
We engage the following sub-processors to deliver the Service. Each processes personal data only on documented instructions from us and under contractual confidentiality and security obligations.
| Sub-processor | Purpose | Processing Location |
|---|---|---|
| Amazon Web Services, Inc. | Application hosting, database, S3 storage | United States (us-east-2, Ohio) |
| Stripe, Inc. | Payment processing and subscription management | United States and Ireland |
| Google LLC (Gemini) | AI photo transformation | United States and other Google regions, per the Gemini API terms |
| Replicate, Inc. | AI photo transformation (alternative provider) | United States |
| Google LLC, Meta Platforms, Inc., LinkedIn Corporation | Social login (account authentication only) | United States and other regions, per each provider's terms |
We will update this list when we add or remove a sub-processor. Material changes are reflected in the "Last updated" date above.
6. Data Retention
Retention is summarized in our Privacy Policy §6 and Data Deletion page. In particular:
- Uploaded photos are automatically deleted within 7 days per our S3 lifecycle policy.
- Account data is retained for the life of your account; you can request deletion at any time.
- Payment records may be retained for up to 7 years for tax and accounting compliance.
- Server logs are retained for 30 days for security and debugging.
7. Your Rights as a Data Subject
Under the GDPR and UK GDPR you have the right to access, rectify, erase, restrict processing of, object to processing of, and port your personal data. To exercise any of these rights, contact us at hello@sparkbooth.com with the subject line "GDPR Request" and include the email address associated with your account so we can verify your identity. We will respond within one month of receipt, extendable by up to two further months for complex requests as permitted by Art. 12(3) GDPR.
For account deletion specifically, see our Data Deletion page.
8. Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority in the EEA, UK, or Switzerland — typically the authority in your country of residence, place of work, or where the alleged infringement occurred. A list of EEA supervisory authorities is maintained at edpb.europa.eu. We would appreciate the opportunity to address your concerns directly first; please reach out to us at the address in Section 1.
9. Changes to This Page
We may update this page from time to time — for example, when we add a sub-processor or change transfer mechanisms. Updates are reflected in the "Last updated" date at the top. Material changes will also be reflected in our Privacy Policy.
JWP, LLC · 400 Spear Street, San Francisco, California