Privacy Policy

VEPATime - Email Automation for Microsoft 365

Table of Contents

  1. Introduction
  2. Data Controller
  3. Data We Collect
  4. Legal Basis for Processing
  5. How We Use Your Data
  6. Data Sharing and Third Parties
  7. Data Security
  8. Your Rights Under GDPR
  9. Data Retention
  10. International Data Transfers
  11. Contact Us

1. Introduction

VEPATime is an email automation service that helps Microsoft 365 users organize calendar event emails automatically. We are committed to protecting your privacy and ensuring transparent data practices compliant with the General Data Protection Regulation (GDPR).

This Privacy Policy explains what data we collect, how we use it, your rights, and how we protect it.

2. Data Controller

Organization: SparkEros, Inc.
Address: [BUSINESS ADDRESS]
Contact Email: privacy@sparkeros.com
Support Contact: kent@sparkeros.com
Response Time: 5 business days

SparkEros is the data controller for personal data processed by VEPATime. When you use VEPATime, you authorize us to process your email and calendar data as described in this policy.

3. Data We Collect

Email Data

Important: We do NOT collect email bodies, attachments, or non-calendar emails. Only metadata from calendar event emails (meeting responses) is processed.

Calendar Data

User Profile Data

Authentication Data

Service Configuration

5. How We Use Your Data

Core Service Functions

Service Improvement

Security and Legal Compliance

Communication

6. Data Sharing and Third Parties

Data Sharing Policy

VEPATime does NOT sell, rent, trade, or share your personal data with third parties for marketing purposes.

Microsoft Services

Your data is processed by Microsoft services only:

All data remains within Microsoft's infrastructure and is not transferred to external vendors.

Legal Requirements

We may disclose your data if required by law (court order, law enforcement, government request) and will notify you of such requests when legally permitted to do so.

Data Processor Agreement

Microsoft (our data processor for infrastructure services) has agreed to protect your data and comply with GDPR requirements.

7. Data Security

Encryption in Transit

Encryption at Rest

Key Vault Security

Access Controls

Application Security

8. Your Rights Under GDPR

You have the following rights regarding your personal data. To exercise any of these rights, contact us at privacy@sparkeros.com.

Right to Access (Article 15)

You have the right to obtain confirmation that we process your data, and to receive a copy of your personal data in a machine-readable format. Response time: 30 days

Right to Rectification (Article 16)

You have the right to correct inaccurate or incomplete data. We will update your information upon verification of your request. Response time: 30 days

Right to Erasure (Article 17 - "Right to be Forgotten")

You have the right to request deletion of your personal data, subject to legal obligations. Upon request, we will:

Response time: 30 days

Right to Restrict Processing (Article 18)

You have the right to restrict processing of your data while we verify your request or handle a dispute. We will stop processing but retain data for legal compliance. Response time: 30 days

Right to Data Portability (Article 20)

You have the right to receive your data in a structured, machine-readable format (e.g., CSV, JSON) and transmit it to another service. Response time: 30 days

Right to Object (Article 21)

You have the right to object to specific data processing activities. We will stop processing unless we have compelling legitimate interests. Response time: 30 days

Right to Withdraw Consent

You can revoke OAuth permissions at any time via:

Revocation is immediate. VEPATime stops processing within 60 seconds.

Right to Lodge a Complaint

If you believe we have violated your privacy rights, you have the right to lodge a complaint with your national data protection authority (Supervisory Authority).

9. Data Retention

We retain data only as long as necessary to provide the service and comply with legal obligations.

Active User Data

Deleted User Data

Trial User Data

Backup Data

Telemetry and Logs

Legal Hold

If required by law, we may retain data beyond normal retention periods to comply with court orders or regulatory requirements.

10. International Data Transfers

Data Residency

All data is processed and stored within Microsoft Azure East US 2 region only. No data is transferred to other geographic locations without explicit consent.

GDPR Compliance for International Transfers

If you are in the European Union:

Sub-processors

Microsoft is our only sub-processor. No other third parties have access to your data.

11. Contact Us

If you have questions about this Privacy Policy or your data, please contact us:

Email: privacy@sparkeros.com
Support: kent@sparkeros.com
Phone: [BUSINESS PHONE NUMBER] (Business hours: 9 AM - 5 PM Central Time, Monday-Friday)
Response Time: 5 business days for privacy inquiries

Changes to This Privacy Policy

We may update this policy as needed to reflect changes in our practices or legal requirements. We will notify you of significant changes via email at least 30 days in advance. Your continued use of VEPATime after updates constitutes acceptance of the new policy.