General information
This Widget Privacy Policy explains what data are processed when you use the AvatarSpark player (“Widget”) embedded on a website or in an application.
The Widget is provided by: NovumSpark Sp. z o.o., registered office in Łódź, ul. Okopowej 113 lok. 19, 91-849 Łódź, KRS: 0001220718, NIP: 7262718050 (“AvatarSpark”, the “Company”, “we”).
1. Who is the data controller? (important – two roles)
Depending on the type of data, two controllers may apply:
A) The website/app owner you visit (“Site Operator”)
The Site Operator is the controller of End User data in the scope of:
- data collected within their website/app (e.g., store accounts, orders, the Operator’s analytics, forms),
- any data related to your interaction with content on the site (including via the Widget), if the Operator records it on their side.
Information on how the Site Operator processes your data can be found in its privacy policy.
B) AvatarSpark as controller
AvatarSpark is the controller of:
- security logs and technical data collected to protect the Widget and the Service (section 2),
- data processed within the Notice & Takedown function (section 4).
C) AvatarSpark as processor – when this applies
If the Widget transmits to the System data necessary to provide the Service to the Site Operator (e.g., technical playback parameters or the content of an avatar interaction, if such a function is available), AvatarSpark acts as a processor on behalf of the Site Operator. In that case, the controller of those data is the Site Operator and AvatarSpark acts under a data processing agreement (DPA).
2. Data we automatically collect (AvatarSpark as controller) and why
When you use the Widget, we may record technical data in security logs, in particular:
- IP address (or its shortened form), request identifiers, event time,
- error information, basic browser/device data (user-agent),
- security events (e.g., detected abuse, attacks, abnormal requests).
Purpose: security, abuse prevention, service integrity, diagnostics.
Legal basis: legitimate interest (Article 6(1)(f) GDPR).
Retention: typically up to 90 days, unless longer to defend claims or investigate incidents.
3. Browser storage and device technologies
The Widget may use cookies and/or localStorage/sessionStorage strictly for technical purposes, e.g.:
- maintaining sessions necessary for operation,
- remembering the player state (e.g., volume, settings),
- caching data for faster loading,
- storing an anonymous session/playback identifier (if enabled) – without identifying data.
These technologies:
- are not used for advertising profiling,
- are not used for cross-site tracking,
- are limited to the technical minimum.
Important: The Site Operator is responsible for displaying a cookie banner / consent panel and obtaining consent where required by law (especially for optional technologies).
4. Data within the Notice & Takedown function
The Widget may include a button to report potentially unlawful content (e.g., copyright infringement, personal rights violations, impersonation, disinformation). If you use this function, we collect (provided voluntarily):
- email address (for contact),
- report category and description,
- content identifier/URL the report concerns,
- technical metadata of the report (time, request identifier).
Purpose: handling the report, protecting third‑party rights, preventing abuse, evidentiary purposes, and fulfilling obligations related to content‑reporting mechanisms.
Legal basis: legitimate interest (Article 6(1)(f) GDPR).
Retention: generally 3 years (evidence/claims defense), unless a longer period is required by law.
5. Data recipients
Data may be disclosed to:
- technical service providers (hosting, infrastructure, email) as subprocessors – list: https://avatarspark.com/en/legal/processors,
- the Site Operator – if necessary to handle a report or explain an incident,
- public authorities – when required by law.
6. Transfers outside the EEA
If data are transferred outside the EEA, we apply appropriate safeguards (e.g., SCC). Details: https://avatarspark.com/en/legal/processors.
7. Your rights
Where AvatarSpark acts as the controller of your data (sections 2 and 4), you have the right to:
- access, rectification, erasure, restriction,
- object to processing based on legitimate interest,
- lodge a complaint with a supervisory authority – in Poland: the President of the Personal Data Protection Office (UODO).
To exercise rights with respect to AvatarSpark, contact: [email protected]. We will respond within 30 days as a rule. If your request concerns data controlled by the Site Operator, please contact them directly (see their privacy policy).
8. Contact
NovumSpark Sp. z o.o.
Address: ul. Okopowej 113 lok. 19, 91-849 Łódź
Email (data protection): [email protected]
Email (abuse reports): [email protected]
DPO (if appointed): not appointed
9. Changes
We may update this Widget Privacy Policy, in particular due to changes in technology or law. Material changes will be communicated to Site Operators using the Widget.
Document version: 1.3