Skip to content

Sparset Privacy Policy

Effective date: September 9, 2026
Last updated: September 9, 2026
Company: Ora Holdings Corporation, doing business as Sparset

Ora Holdings Corporation, doing business as Sparset ("Sparset," "we," "us," or "our"), provides autonomous AI inference infrastructure services for businesses and teams. Our services help customers plan, optimize, test, deploy, monitor, and maintain supported AI models in customer-controlled or agreed hosted environments.

This Privacy Policy explains how we handle personal information in connection with our websites, business accounts, management interfaces, software agents, APIs, deployment services, support, and business communications (the "Services"). It also explains how processing inside a customer's deployment differs from information sent to Sparset's management systems.

1. Who is responsible for your information

Ora Holdings Corporation is responsible for personal information for which we determine the purposes and means of processing, including business contact information, billing records, website information, and information used to administer and secure our own Services. In applicable laws, this role may be called a controller or business.

When we process personal information on an organization's instructions to provide its deployment, monitoring, or support services, we act as its processor, subprocessor, or service provider, as applicable. This can include processing within a hosted environment or authorized remote access, even if we do not retain a separate copy. Our customer agreement and Data Processing Addendum govern that processing. Where we only supply software and do not process information on the customer's behalf, supplying that software alone does not make us its processor.

The organization operating an application or workspace is responsible for its own privacy notice and lawful use of personal information. If your information is in that organization's model, application, or inference workload, direct your request to that organization. We assist our customers as required by our agreements and applicable law.

Privacy contact: privacy@sparset.ai
Person responsible for privacy: Marcel Slowikowski, CEO and Founder
Mailing address: Ora Holdings Corporation, Attn: Privacy, 16192 Coastal Hwy, Lewes, DE 19958

2. Our approach to customer content

Customer Content means customer models and weights, prompts, inputs, outputs, datasets, files, application data, and other workload content processed through the Services. Customer Content may or may not contain personal information.

Our standard service configuration keeps Customer Content inside the customer's Deployment Environment: the customer's own infrastructure or the hosted infrastructure expressly selected for that customer. Our management systems receive the operational information needed to manage that deployment, rather than routine copies of Customer Content.

Under this standard configuration:

  • We do not routinely collect Customer Content into our management systems or use it as product analytics.
  • Customer Content is processed within the Deployment Environment to perform authorized inference, evaluation, optimization, and recovery tasks. Model files, caches, temporary files, customer-configured logs, and backups may exist there as required by the deployment.
  • We do not use Customer Content to train or fine-tune our own or third parties' AI models, build shared training datasets, or improve models for other customers. Customer-specific model training is outside the standard service and requires a separate written agreement.
  • We do not transmit Customer Content to an external AI planning or model API as part of the standard service. Connecting such a service requires a separately agreed data flow and appropriate contractual protections before transmission begins.
  • Human access to Customer Content for support is separately authorized, limited to the agreed purpose, and subject to access controls and confidentiality obligations. Approving a deployment or recovery action does not by itself authorize content export or unrestricted human inspection.

Keeping content inside the Deployment Environment does not mean no processing occurs, that no content is stored there, or that hosting providers have no role. A provider hosting the customer's model necessarily provides infrastructure on which content is processed. Its role, access arrangements, storage, and backup practices must be assessed for that deployment. We do not describe the whole service as having "zero retention" unless a separate written commitment identifies the exact data, systems, and exceptions covered.

3. Information we collect or process

The following categories depend on your interactions and enabled Services. Operational information can be personal information even when it does not contain prompts or outputs.

CategoryExamples and sourceWhy we use it
Business account and contact informationName, work email, organization, role, account identifiers, and authentication information provided by you, your administrator, or your sign-in providerAccount access, customer administration, identity verification, and communications
Commercial and billing informationBilling contacts, billing address, tax details, orders, invoices, payment status, and payment-reference information from you and payment providersContract administration, payment processing, accounting, and tax compliance
Deployment and operational informationDeployment identifiers, selected model identifier, software and driver versions, hardware configuration, resource utilization, request counts, token counts where used for metering, latency, throughput, error codes, and cost measurements from deployed softwarePlanning, compatibility, testing, performance analysis, billing, monitoring, and recovery
Access, security, and action recordsIP addresses, timestamps, authentication events, administrator identifiers, approval records, agent action summaries, configuration changes, and incident recordsAccess control, accountability, security, troubleshooting, and incident response
Integration and infrastructure access informationScoped credentials, secret references, resource identifiers, and configuration information made available through authorized connectionsCarrying out authorized infrastructure actions; credentials are not treated as analytics
Website and device informationBrowser and device type, IP address, pages requested, referrer, approximate region, and cookie or similar identifiers generated when you visit our websitesDelivering and securing the site and, subject to applicable choices, understanding website use
Communications and support informationInquiries, correspondence, feedback, and diagnostic information intentionally supplied by youResponding to requests and resolving issues; content-bearing diagnostics require the authorization described in Section 4
Customer Content processed on instructionsContent processed inside the Deployment Environment or through a separately authorized support workflowOnly the customer's instructed service, support, or other separately agreed purpose

We obtain information directly from you; from your organization and its administrators; from the software and infrastructure connected to the Services; and from service providers such as identity, payment, security, and hosting providers used for your service. We may also receive business contact information through a referral or a public professional source for a relevant business inquiry. Where required, we provide notice when collecting information indirectly.

Information described as necessary for authentication, billing, security, or an enabled service is needed to provide that function. If it is not provided, we may be unable to provide the function. Optional analytics and marketing choices do not determine access to the core paid service.

4. Deployment, monitoring, and support data flows

4.1 Customer-managed infrastructure

For deployments on the customer's servers, private cloud, or data-center infrastructure, inference and content-bearing evaluation run there. The customer controls its network, underlying infrastructure, and local retention except for responsibilities expressly assigned to Sparset. Our management connection processes the operational information and scoped access information needed for authorized management.

Remote management requires connectivity and is not an air-gapped service. Any offline or air-gapped arrangement must be separately specified, including which management and monitoring functions will be unavailable.

4.2 Hosted infrastructure

For a hosted deployment, the agreed host processes and may store Customer Content within the selected Deployment Environment. The customer agreement identifies whether the host contracts directly with the customer or is engaged by Sparset. Providers engaged by Sparset to process customer personal information are subject to the applicable Data Processing Addendum.

A region selected for inference does not automatically place account administration, operational metadata, support, backups, or every provider in that same region. Any residency commitment must identify the data categories and processing locations it covers.

4.3 Monitoring and autonomous actions

Agents use operational information to assess service health and performance, propose optimizations, and perform authorized tasks. Our standard authorization model requires customer approval for production optimizations and permits only recovery actions covered by a preapproved recovery runbook to occur without a fresh approval. We process approval and action records to document those activities.

Routine diagnostics are configured to exclude prompt and output bodies, model weights, datasets, secret values, and unredacted content-bearing traces. A label such as "log" or "metadata" does not make content non-sensitive. If a diagnostic would contain Customer Content, it must be excluded or handled through the separately authorized support process.

4.4 Support access and accidental submissions

Before content-bearing support access or transfer, we agree the scope, personnel or providers, purpose, permitted location, and retention or deletion conditions with the customer. We use that information to resolve the specific issue and meet related security or legal obligations, not for unrelated product research or model training.

Do not send production content or secrets through ordinary contact forms. If content is unintentionally included in a ticket or diagnostic, we restrict its use and access, assess whether it is a security incident, and arrange appropriate deletion or a properly authorized support workflow. Sending content accidentally does not authorize model training or unrelated reuse. Information subject to a legal preservation duty remains protected and restricted to that duty.

We use personal information to provide and administer the Services; communicate with customers; process payments; evaluate compatibility and performance; maintain security; investigate faults; respond to requests; maintain business records; and comply with legal obligations. We may use aggregated or properly de-identified operational statistics for capacity planning and service improvement without exposing Customer Content or identifying a customer or person.

Where the GDPR or UK GDPR applies to processing for which we are controller, our grounds are:

PurposeLegal ground, where applicable
Providing a service requested by an individual who is personally party to our contractPerformance of that contract or requested pre-contractual steps
Managing an organizational contract and communicating with its staffLegitimate interests in providing and administering business services, balanced against individuals' rights
Authentication, abuse prevention, infrastructure reliability, and incident investigationLegitimate interests in protecting the Services and users; legal obligation where a specific duty applies
Billing, tax, accounting, and responding to legally binding requestsLegal obligation; legitimate interests for related contract administration where appropriate
Optional website analytics and marketing communicationsConsent where required; otherwise a permitted legitimate interest subject to applicable communications rules and objection rights
Establishing or defending legal claimsLegitimate interests in protecting legal rights, subject to applicable safeguards

We obtain any additional condition required to process special-category information; ordinary acceptance of our terms is not that condition. When we act as processor, we follow the customer's documented instructions rather than choosing a separate legal basis for its workload.

Where Canadian law applies, we obtain meaningful consent where required and otherwise process information only on a basis permitted by the applicable law. Withdrawing consent may limit a function that depends on the information; we explain relevant consequences and legal or contractual restrictions.

6. Cookies, analytics, and communications

We use cookies or similar technologies needed for functions such as authentication, security, and remembering privacy choices. We do not use optional analytics, advertising, or other non-essential cookies.

Where consent is required, optional technologies remain disabled until you consent. You can withdraw consent through the provided controls. Where a lawful exception permits limited use without consent, we provide the information and objection controls required for that exception.

You can unsubscribe from marketing emails using the link in the message or by contacting us. We may continue to send necessary service, security, billing, and legal communications. We do not treat accepting the Terms of Service as consent to optional marketing.

We do not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising. We honor legally required opt-out preference signals, including Global Privacy Control, for processing to which those signals apply. A browser's older "Do Not Track" setting does not otherwise change our processing; this does not limit applicable consent or opt-out rights.

7. When we disclose information

We disclose personal information only as relevant to the purposes described above:

  • Service providers: Providers of hosting, infrastructure, authentication, payments, communications, security, and support receive information needed for their assigned functions under appropriate restrictions. A provider's access to Customer Content remains subject to the deployment and support limits in this Policy and the customer agreement.
  • Customer administrators: An organization's authorized administrators may access account, usage, approval, and security information for their workspace. Access to workload content depends on that organization's deployment and permissions.
  • Customer-selected integrations: Information is exchanged only within the enabled integration's authorized scope. An integration is not permission to export unrelated Customer Content.
  • Professional advisers: Legal, accounting, insurance, and similar advisers may receive necessary information under appropriate confidentiality duties.
  • Legal and security matters: We may disclose information where required by law or reasonably necessary and legally permitted to protect rights, investigate abuse, or address a security threat. Where permitted, we notify the affected customer of a binding request for its information and limit disclosure to what is required.
  • Corporate transactions: Necessary information may be disclosed during a proposed or completed merger, acquisition, financing, or sale of relevant assets, subject to confidentiality and applicable law. A recipient must respect the applicable privacy commitments or provide the notices and obtain the permissions required for a lawful change.
  • At your direction: We may disclose information for another purpose you specifically authorize.

The current providers engaged to process customer personal information, their functions, and locations are available from our privacy contact. Customers receive subprocessor change notices as provided in the Data Processing Addendum. A host engaged directly by the customer is governed by the customer's own agreement with that host; this does not excuse Sparset's obligations for its own processing.

8. Retention and deletion

We keep personal information only as long as needed for the disclosed purpose and applicable legal obligations. The following schedule applies to information in systems controlled by Sparset; a customer's Deployment Environment has its own agreed retention settings.

InformationRetention period or determining criteria
Account and business contact recordsDuring the active relationship, then 3 years after the account is closed, unless a longer period is required for a dispute or legal obligation
Billing, tax, and contract records7 years from the date of the record, restricted to accounting, legal, and related administrative purposes
Operational telemetry and routine technical logs12 months from collection
Security, approval, and agent action records3 years from the date of the record, longer where an incident investigation or legal hold requires it
Ordinary support correspondence3 years from ticket closure
Separately authorized content-bearing diagnosticsThe shorter scope and period specified in the support authorization or applicable customer agreement; no routine content collection is authorized by this table
Credentials and integration accessOnly while needed for the authorized connection; revoked or removed when access ends, subject to the agreed disconnection procedure
Marketing contact recordsUntil withdrawal, objection, or 24 months of inactivity; minimal suppression records may be kept to honor an opt-out
Backup copies of information held by SparsetRemoved through a backup cycle no longer than 90 days; inaccessible for ordinary business use after deletion from active systems
Customer Content inside a Deployment EnvironmentThe customer's configuration and the agreed deployment retention and backup schedule; this includes any host-managed storage

We may retain a limited record longer where a specific legal obligation, dispute, security investigation, or preservation requirement makes that necessary. We restrict its use and delete it when that reason ends. If a backup is restored, applicable deletion instructions are reapplied before ordinary processing resumes.

Aggregated or de-identified information that no longer identifies a person may be retained for lawful business purposes. We maintain safeguards against re-identification and do not attempt it except for legally permitted testing of those safeguards. We do not classify information as anonymous merely because names were removed.

9. Security

We maintain technical and organizational safeguards appropriate to the information and risks involved. These include access restrictions, confidentiality obligations, protected communications, credential controls, and incident-response procedures. Deployment-specific safeguards and responsibilities are set out in the customer agreement and security schedule.

No system is completely secure. Customers also need to secure their own infrastructure, accounts, backups, and downstream applications. These shared responsibilities do not reduce our contractual or legal obligations. We provide incident notifications as required by law and the applicable customer agreement.

Security contact: security@sparset.ai

10. International processing

Ora Holdings Corporation is based in the United States. Information handled by our business and management systems is processed in the United States. The location of a customer's inference deployment is specified separately.

Where information is transferred from the EEA or UK to a country without an applicable adequacy arrangement, we use an appropriate lawful safeguard, such as completed European Commission Standard Contractual Clauses and, for relevant UK transfers, the applicable UK transfer instrument, together with required assessments and supplementary measures. These arrangements must be in place before the restricted transfer occurs. We do not claim participation in a certification or transfer framework merely by mentioning it in this Policy.

You may contact us for information about the safeguards applicable to your personal information and, where applicable, a copy, with necessary redactions to protect confidential information.

For Canadian information processed abroad, we use contractual and other appropriate safeguards. Information processed in another country may be accessible to courts, law enforcement, or national security authorities under that country's laws. We remain responsible for the protections required of us under applicable Canadian law.

11. Your choices and rights

Depending on the law that applies and relevant exceptions, you may request access to, correction of, or deletion of your personal information; a portable copy; restriction of processing; or information about how it has been used or disclosed. You may also object to certain processing, withdraw consent, opt out of sale, sharing, targeted advertising, or covered profiling, and appeal a denied request where applicable.

Submit a request by emailing privacy@sparset.ai or by mail to the address in Section 1. Explain the right you wish to exercise without sending unnecessary sensitive information. We verify identity and authority proportionately and respond within applicable legal deadlines. Authorized agents may submit requests where permitted; we may request evidence of their authority. We do not discriminate or retaliate for exercising a privacy right.

If a request is refused or limited, we explain the reason and any applicable appeal process. You may appeal by replying to the decision with "Privacy appeal" in the subject or by contacting our privacy contact. You may also complain to the competent authority without first completing an internal process where the law permits.

11.1 EEA and United Kingdom

Where applicable, your rights include access, rectification, erasure, restriction, portability, and objection. You can object to direct marketing at any time. Withdrawal of consent does not affect processing lawfully undertaken before withdrawal. You may complain to the data-protection authority where you live or work or where the alleged infringement occurred; UK individuals may contact the Information Commissioner's Office.

No EEA or UK representative has been appointed. Use the privacy contact in Section 1.

11.2 United States, including California

Where applicable, state privacy laws provide rights described in this section. Coverage depends on statutory thresholds, exemptions, residency, and processing context; business use does not automatically exclude an individual's privacy rights.

For California notices, the categories in Section 3 correspond to identifiers; customer-record information; commercial information; internet or network activity; approximate geolocation derived from IP address; professional or employment-related information; and sensitive personal information consisting of account-access credentials. Support submissions may contain additional categories, including audio or visual information when deliberately provided. The sources, purposes, recipient categories, and retention rules appear in Sections 3 through 8.

As of the effective date of this Policy, we collect the categories described in Section 3 and disclose them for business purposes to the recipient categories in Section 7. We do not sell personal information or share it for cross-context behavioral advertising.

We use sensitive personal information only for permitted functions such as authentication, security, or specifically requested services, rather than to infer sensitive traits. Where a separate right to limit its use applies, we provide the required mechanism. We do not knowingly sell or share the personal information of individuals under 16.

11.3 Canada

Where applicable, you may request access, correction, and information about our practices; withdraw consent subject to lawful restrictions; and challenge our compliance through our privacy contact. Additional provincial rights, including portability or rights concerning automated decisions, apply where their legal conditions are met. You may complain to the Office of the Privacy Commissioner of Canada or the relevant provincial commissioner, including Québec's Commission d'accès à l'information, as applicable.

12. Automated decisions

Sparset's infrastructure agents make technical recommendations and perform authorized infrastructure actions. They are not provided to make decisions about an individual's employment, credit, healthcare, or similar rights. In our controller activities covered by this Policy, we do not use solely automated processing to make decisions about individuals that produce legal or similarly significant effects.

Customers are responsible for explaining automated decisions made by their own applications and providing legally required review and other safeguards. If Sparset introduces covered automated decision-making in its own activities, we will provide the required notice, explanation, and rights before that processing begins.

13. Children and other notices

The Services are offered to businesses and adult authorized users, not directly to children. We do not knowingly collect personal information directly from children under 13 through our websites or account registration. Contact us if you believe a child has provided information in that way so we can investigate and take appropriate action.

This statement does not authorize customers to process children's data without an appropriate legal basis and agreed safeguards. Recruiting and personnel information may be covered by a separate notice. Third-party websites and services have their own notices; our use of a provider does not eliminate our responsibilities for information entrusted to it.

14. Changes and contact

We update this Policy when our practices or applicable requirements change and revise the dates above. We give prominent or direct notice of material changes and obtain consent where required. We do not retroactively expand our rights to use previously collected Customer Content by changing this Policy. A privacy notice update does not amend an existing customer's negotiated data-processing commitments.

For questions, complaints, or requests, contact Ora Holdings Corporation, doing business as Sparset, using the privacy contact and mailing address in Section 1.

Related document: Terms of Service.