Legal and privacy
Privacy Policy
This policy applies to the Sparkdemy website, enquiry forms, and the optional Facebook Messenger and Instagram messaging integrations enabled by our clients.
Last updated: 30 August 2026
01
Data we collect
- Enquiry data: your name, company, role, industry, company size, email, phone or WhatsApp number, and the message you submit.
- Meta connection data: Facebook Page or Instagram professional account IDs, names, usernames, permissions, connection status and access tokens.
- Customer-service conversation data: customer IDs, message content, attachments or related links, timestamps, processing status, drafts and sent replies.
- Technical data: necessary security logs, request times, IP address, browser information, and website analytics or Meta Pixel event data.
02
Where data comes from
- Information you submit directly through an enquiry form or service configuration.
- Facebook Pages, Instagram professional accounts and Meta webhooks that you authorise us to connect.
- People who message a connected business account.
03
How we use data
- To answer enquiries, provide the service, authenticate authorised business accounts and handle support requests.
- To receive and route customer messages and generate drafts or replies from client-approved knowledge and rules.
- To enforce human approval, messaging windows, escalation rules and duplicate-reply protection.
- To secure accounts and systems and investigate faults, misuse or unauthorised access.
- To understand website and service usage. We do not sell personal data.
04
Disclosures and processors
- Meta Platforms processes Facebook, Messenger, Instagram, login, permissions and message delivery.
- Cloudflare and our cloud-hosting providers process website, network, security, backup and service-operation data.
- The AI model provider selected for a client processes the minimum conversation content needed to generate a customer-service draft or reply.
- Authorised Sparkdemy personnel and administrators of the relevant client company access data only as needed for operations, support, approval or compliance.
05
Retention and deletion
- We retain data only as long as needed for its collection purpose, service delivery, disputes, legal obligations or security.
- Disconnecting a Meta account deletes its active access token and live connection record and stops new events from being collected.
- Conversation events, drafts and operational records are cleared according to operational need; verified full-deletion requests are normally completed within 30 days.
- Copies in backups are removed through the normal backup rotation, except for limited records required by law or a security investigation.
- Deleting Sparkdemy data does not automatically delete the original messages held by Meta, Facebook, Messenger or Instagram.
06
Security
- Meta access tokens are encrypted at rest and network traffic uses HTTPS.
- Webhooks are checked against Meta signatures, and each client uses separate signed authentication with the central service.
- Access is limited by operational role, and each client's data is separated from other clients.
- No system is risk-free. If an incident occurs, we will contain and investigate it and provide notices where applicable.
07
Your rights and choices
- You can disconnect Facebook or Instagram to stop new processing.
- You can ask whether we hold your personal data and request access, correction or deletion.
- We verify authority over the relevant Page, account or data before acting, to prevent unauthorised deletion.
- You can also revoke Sparkdemy's permissions in your Facebook or Instagram settings.
08
International processing, children and updates
- Service providers may process data outside Hong Kong. We require them to process it only for the service purpose and with appropriate safeguards.
- The service is for business users and is not directed to anyone under 18.
- If this policy changes materially, we will update the date on this page and notify connected clients where appropriate.