Agreement Composition
This agreement package consists of Common Paper Data Processing Agreement Standard Terms Version 1.1; this Cover Page and Variables; the Stackie addenda, policies, schedules, and notices referenced by this agreement.
Cover Page
Using the Framework Terms
To use this DPA, the parties must complete and sign or electronically accept this Cover Page. Capitalized and highlighted words used by the DPA Standard Terms have the meanings or descriptions given in this Cover Page; if this Cover Page omits or does not define a highlighted word, the default meaning is "none" or "not applicable". All other capitalized words have the meanings given in the DPA Standard Terms or the Agreement. This Cover Page is the operative Cover Page for the incorporated Standard Terms. Customer accepts this Cover Page, the incorporated Standard Terms, and the Stackie addenda, policies, schedules, annexes, and notices referenced by this DPA by signing or electronically accepting the agreement, order, checkout record, product flow, or other Stackie-approved acceptance flow that presents or links to this DPA before covered processing begins. Processing after that signature or electronic acceptance is governed by this DPA. The tables below are part of this Cover Page and supply the meanings, descriptions, processing details, transfer details, SCC and UK Addendum details, additional Cover Page terms, and other Variables used by the DPA Standard Terms. If this Cover Page, the Annex variables, the Additions, Supplements, and Modifications, or the Other Changes to Standard Terms conflict with the Standard Terms, this Cover Page controls to the fullest extent allowed by applicable data protection law. The incorporated versioned Standard Terms control as modified by this Cover Page, any applicable Order Form or Variables, the Other Changes to Standard Terms, and the incorporated Stackie addenda and schedules. Any reference copy of the Standard Terms in this document is provided for readability only and does not change the incorporated Standard Terms.
Cover Page Variable Index
The following index identifies the Cover Page sections that define Common Paper Variables and Stackie supplemental Cover Page terms. The detailed section tables below control if this index conflicts with a specific variable value.
| Cover Page Section | Legal Effect | Variables Defined |
|---|
| Agreement Variables | Identifies the agreement, Customer, and Service variables for this DPA Cover Page. | Agreement, Customer, Service |
| Legal Variables | Supplies governing law, court, notice, and DPA effective-date variables. | Provider, Company Number, DPA Effective Date, Governing Law, Chosen Courts, Registered Office, Notice Address, Notice Email |
| Definitions and Variables | Defines product, service, software, and other Stackie variables used by this Cover Page. | Product |
| Support Variables | Defines support channel, response, and support-posture variables. | Support Posture, Support Channel, Support Response |
| DPA Annex I Variables | Supplies processing, transfer, data-subject, data-category, and deletion variables. | Subject Matter, Duration of Processing, Nature and Purpose of Processing, Processing Instructions, Processing Description, Transfer Description, Frequency of Transfer, Categories of Data Subjects, Categories of Personal Data, Special Category Data, Special Category Data Restrictions or Safeguards, Security Measures, Security Policy, Provider Security Contact, Deletion Procedure, Subprocessor Authorization |
| DPA SCC and UK Addendum Variables | Supplies restricted-transfer, SCC, UK Addendum, audit, and subprocessor variables. | Controller to Processor Module, Processor to Subprocessor Module, Governing Member State, Competent Supervisory Authority, Report, Audit Report Process, Annex II Security Measures, Approved Subprocessors, UK Addendum Details |
Incorporated Standard Terms
Agreement Variables
| Term | Value |
|---|
| Agreement | The applicable Terms, Cloud Service Agreement, EULA, order form, or signed agreement that includes this DPA. |
| Customer | Customer acting as controller, business, processor, or similar role for Customer personal data processed through Stackie services. |
| Service | Stackie-hosted services and Stackie-accessible support, diagnostic, legal-acceptance, billing, account, package-delivery, and cloud interoperability flows where Stackie Ltd actually receives, accesses, or processes Customer Personal Data under the applicable agreement; purely local Customer-controlled processing is outside this DPA unless Customer sends it to Stackie Ltd or enables a connected Stackie processing flow. |
Legal Variables
| Term | Value |
|---|
| Provider | Stackie Ltd, a private limited company in England and Wales, United Kingdom |
| Company Number | 17240531 |
| DPA Effective Date | The date Customer signs or electronically accepts the agreement, order form, Terms, EULA, checkout record, or other Stackie-approved acceptance flow that includes this DPA. |
| Governing Law | England and Wales |
| Chosen Courts | courts of England and Wales |
| Registered Office | Stackie Ltd, 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ |
| Notice Address | Registered office and postal notice address for Stackie Ltd, registered in England and Wales: Stackie Ltd, 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ; electronic legal notices to [email protected]. |
| Notice Email | [email protected] |
Definitions and Variables
Support Variables
| Term | Value |
|---|
| Support Posture | Privacy, security, and data-rights support is provided as required by applicable law and the applicable agreement. |
| Support Channel | Stackie support desk, account support flow, or privacy contact published for the applicable plan. |
| Support Response | Reasonable cooperation within statutory or agreement-specific deadlines. |
DPA Annex I Variables
| Term | Value |
|---|
| Subject Matter | Processing Customer Personal Data received by or made accessible to Stackie Ltd to provide, secure, maintain, support, troubleshoot, improve, and administer covered Stackie Services. |
| Duration of Processing | For the term of the applicable agreement and any lawful retention period needed for backups, security, dispute, audit, tax, or legal claim purposes. |
| Nature and Purpose of Processing | Hosting, authentication, account administration, package delivery, telemetry or diagnostics sent to Stackie Ltd, support, billing, security, legal acceptance, and customer instruction processing. |
| Processing Instructions | Customer instructs Stackie Ltd through the applicable agreement, accepted configuration, account settings, support requests, and lawful written instructions. |
| Processing Description | Processing Customer Personal Data for covered Stackie-hosted or Stackie-accessible flows, including account administration, authentication, package delivery, telemetry or diagnostics sent to Stackie Ltd, support, billing, security, legal acceptance, customer instructions, and local/cloud interoperability only when Stackie Ltd receives, accesses, or processes the data. |
| Transfer Description | Transfers occur when Customer or authorized users access Stackie Services, submit Customer Personal Data, trigger support, billing, telemetry, diagnostics, package delivery, authentication, or account workflows, or when approved subprocessors process Customer Personal Data for those workflows. |
| Frequency of Transfer | Continuous or on-demand for the term of the applicable agreement, depending on Customer configuration, user activity, support requests, telemetry settings, billing events, and service operation. |
| Categories of Data Subjects | customer administrators, authorized users, individual developers, support contacts, billing contacts |
| Categories of Personal Data | account data, authentication data, billing and subscription data, support and chat data, telemetry and diagnostics, legal acceptance evidence |
| Special Category Data | Stackie services are not intended for special category data unless Stackie Ltd expressly agrees in writing. |
| Special Category Data Restrictions or Safeguards | Special category data is prohibited unless expressly authorized in a signed agreement that identifies additional safeguards, restrictions, and lawful instructions. |
| Security Measures | Security and Technical/Organizational Measures document and DPA annex. |
| Security Policy | Stackie Security/TOMs document published at /legal/security-toms and DPA annex. |
| Provider Security Contact | [email protected] |
| Deletion Procedure | Customer may delete Customer personal data using available service functionality; after DPA expiration Stackie Ltd will return or delete Customer personal data on Customer instruction unless legal, backup, security, dispute, audit, tax, or claim retention requires continued protection and restricted processing. |
| Subprocessor Authorization | General authorization applies only to approved subprocessors identified as processors, subprocessors, service providers, or contractors in Annex III and the Subprocessor List, with the notice periods recorded there; independent controllers and other third-party recipients are disclosed separately for transparency and are not approved subprocessors. |
DPA SCC and UK Addendum Variables
| Term | Value |
|---|
| Controller to Processor Module | EEA SCC Module Two applies where Customer is a controller and Stackie Ltd processes Customer personal data as processor. |
| Processor to Subprocessor Module | EEA SCC Module Three applies where Customer is a processor and Stackie Ltd processes Customer personal data as subprocessor. |
| Governing Member State | Ireland, unless the signed agreement names another EEA member state required by applicable law. |
| Competent Supervisory Authority | Irish Data Protection Commission, unless the signed agreement or non-waivable law names another competent supervisory authority. |
| Report | Security reports, due-diligence responses, and audit assistance are provided through Stackie support or legal contact under the DPA, subject to confidentiality, reasonable frequency limits, and protection of Stackie confidential information. |
| Audit Report Process | Security reports, due-diligence responses, and audit assistance are provided through Stackie support or legal contact under the DPA, subject to confidentiality, reasonable frequency limits, and protection of Stackie confidential information. |
| Annex II Security Measures | The technical and organizational measures listed in the Security Control Measures table in the DPA annex. |
| Approved Subprocessors | Approved subprocessors are only the recipients identified as processors, subprocessors, service providers, or contractors in Annex III and the Subprocessor List at /legal/subprocessors, including their processing tasks, regions, transfer mechanisms, and notice periods. Independent controllers and other third-party recipients are disclosed separately outside Annex III for transparency and are not approved subprocessors. |
| UK Addendum Details | UK Addendum Table 2 uses the same party, module, transfer, Annex I, Annex II, and Annex III information in this Cover Page and DPA annex; Table 4 is modified as stated in the unmodified DPA Standard Terms unless a signed agreement states otherwise. |
Additions, Supplements, and Modifications
Additional Stackie Terms and Schedules
| Supplement | Terms |
|---|
| Stackie Addendum | The Stackie-specific sections that follow this Cover Page in the same published document are attached to, incorporated into, and form part of this Cover Page as supplemental terms for the covered Stackie offering. |
| DPA Annex and Subprocessor List | The DPA annex, Annex I processing details, Annex II security measures, Annex III approved subprocessors, SCC and UK Addendum details, subprocessor list, and security/TOMs sections below are attached to, incorporated into, and form part of this Cover Page for the incorporated DPA Standard Terms, SCC, UK Addendum, and applicable data-protection-law purposes. |
| Policies and Schedules | The public policies, schedules, notices, DPA annexes, subprocessors list, security/TOMs, cookie notice, privacy policy, acceptable use policy, open-source notices, documentation, and order terms referenced by this agreement are incorporated only for their stated purpose and only to the extent applicable to the covered Stackie offering. |
| Precedence | For restricted transfers, applicable EEA SCCs, UK Addendum terms, and non-waivable data-protection law control first to the extent required for that transfer. Subject to that mandatory transfer-law order, signed agreements and accepted DPA acceptance records control first, then this Cover Page and Variables, then the Other Changes to Standard Terms, then the attached Stackie Addendum and incorporated schedules, then the unmodified Standard Terms. |
Other Changes to Standard Terms
| Change | Terms |
|---|
| Change 1 | Protected Persons. As an additional Cover Page term for this DPA, every protection, disclaimer, liability limitation, release, defense, correction right, indemnity, and remedy limit in this DPA benefits Stackie Ltd and its directors, officers, employees, contractors, affiliates, agents, successors, assigns, and shareholders/members as Protected Persons; each Protected Person may rely on and enforce those protections as an intended third-party beneficiary and, where English law applies, under the Contracts (Rights of Third Parties) Act 1999. The parties may vary, rescind, waive, amend, replace, or terminate this DPA or any protection without any Protected Person's consent, but customer-facing amendments remain subject to this DPA's modification, notice, acceptance, SCC, UK Addendum, and applicable data-protection-law requirements; no term creates duties owed by a Protected Person except where non-waivable law imposes them; and direct claims against Protected Persons are excluded to the fullest extent law allows. |
| Change 2 | Prospective updates. As additional Cover Page terms, Stackie Ltd may update public policies, schedules, notices, subprocessors, tracking disclosures, product documentation, legal notice publication methods, and DPA annexes prospectively by publication or notice where those updates are non-contractual, required by data-protection law, or legally permitted without affirmative acceptance; changes to the Standard Terms, Cover Page Variables, SCC/UK Addendum variables, liability allocations, or other contractual DPA terms that require signed or electronic acceptance take effect only through a Stackie-approved recorded acceptance flow, signed agreement, checkout/order flow, product gate, or other valid DPA Cover Page acceptance where applicable law allows. Affirmative consent is required where non-waivable law, a signed agreement, SCCs, the UK Addendum, or the applicable change classification requires it. |
| Change 3 | Correction and no-reliance. Stackie Ltd may correct non-substantive drafting, typographical, formatting, translation, cross-reference, link, publication, manifest, version, schedule, table, automated publication, or similar publication errors prospectively, and this DPA is not legal, tax, regulatory, security, audit, procurement, compliance, or professional advice to Customer. |
| Change 4 | Liability cap and mandatory carveouts. The liability cap, release, indemnity, warranty exclusions, exclusive remedies, and indirect-damages exclusions apply to the fullest extent allowed by applicable law, but nothing limits liability or rights that are non-waivable under fraud, intentional misconduct, death or personal injury caused by negligence, data-protection, consumer, unfair-terms, criminal, regulatory, or directors' personal wrongdoing law. |
| Change 5 | DPA liability fallback. To the fullest extent allowed by applicable law, inter-party DPA liability between Stackie Ltd and Customer is subject to the liability cap in the applicable agreement and this Cover Page and Variables. If no other cap applies, Stackie Ltd's aggregate inter-party DPA liability to Customer is capped at the greater of GBP 100 or fees paid by Customer for the affected service in the 12 months before the event giving rise to the claim. Customer releases the Protected Persons from claims above enforceable inter-party caps and will indemnify, defend, and hold the Protected Persons harmless from claims arising from Customer content, Customer systems, unlawful instructions, deficient notices or consents, Customer's breach of data protection obligations, or Customer's violation of third-party rights, in each case only to the fullest extent lawful. |
| Change 6 | DPA preservation. These changes apply only to the maximum extent permitted by Applicable Data Protection Laws and do not limit data subject rights, regulator powers, SCCs, the UK Addendum, Customer audit rights required by law, subprocessor notice or objection rights required by law, or any term that applicable privacy or transfer law makes non-waivable. |
| Change 7 | Audit reports and security due diligence. Section 5.2 (Security Reports) and the definition of Report are replaced so, notwithstanding the display copy, Stackie Ltd provides then-current independent third-party audit reports only to the extent Stackie Ltd has such reports available for the applicable Service; until such reports are available, Stackie Ltd will provide reasonable security summaries, due-diligence responses, and audit assistance through the Provider Security Contact, subject to confidentiality, reasonable frequency limits, and protection of Stackie confidential information, and this change does not limit audit rights required by Applicable Data Protection Laws, the EEA SCCs, or the UK Addendum. |
This Data Processing Addendum applies where Stackie Ltd processes Customer Content containing Personal Data for Customer as processor, subprocessor, service provider, contractor, or similar role under applicable data protection law. This DPA supplements the applicable Terms, Cloud Service Agreement, EULA, order form, checkout record, or signed agreement.
The unmodified Common Paper Data Processing Agreement Standard Terms, Version 1.1, at https://commonpaper.com/standards/data-processing-agreement/1.1 are incorporated for covered processing. The Cover Page, Variables, Other Changes to Standard Terms, DPA annexes, SCC and UK Addendum details, and incorporated Stackie addenda, policies, schedules, and notices supply the Stackie-specific terms that operate with those Standard Terms. The Cover Page and Variables above supply the Stackie variables for those Standard Terms. A reference copy and source attribution appear at the end of this DPA.
Stackie DPA Addendum
Defined Terms
These Stackie-specific definitions supplement the document that embeds this section. If an incorporated Common Paper Standard Term, Cover Page, Key Terms, Order Form, signed agreement, or non-waivable law gives a capitalized term a different meaning for a specific agreement or notice, that more specific meaning controls for that agreement or notice.
| Term | Meaning |
|---|
| Customer | The individual acting for business or professional development purposes, business, enterprise, organization, or other entity that accepts, accesses, or uses Stackie under the applicable agreement or notice. |
| Customer Content | Data, code, packages, configuration, instructions, logs, support materials, and other materials submitted to, stored in, or processed through Stackie by or for Customer. |
| Dashboard | Embedded, local, or hosted Stackie dashboard experiences covered by the applicable agreement or notice. |
| Local Software | Stackie Software installed or run on Customer-controlled systems, including local command-line, daemon, embedded Dashboard, package, update, support, and integration components. |
| Personal Data | Information relating to an identified or identifiable individual. |
| Protected Persons | Stackie Ltd and its directors, officers, employees, contractors, affiliates, agents, successors, assigns, shareholders, and members. |
| Provider | Stackie Ltd, unless the applicable agreement or signed order form identifies a different provider for the covered offering. |
| Services | Stackie websites, applications, APIs, package delivery, documentation, support, hosted services, and related service components covered by the applicable agreement or notice. |
| Software | The software identified as Software in the applicable Cover Page, Key Terms, Order Form, EULA, signed agreement, or other accepted Stackie document. |
| Stackie | The Stackie products and services covered by the applicable agreement or notice, including Stackie websites, applications, command-line tools, daemon components, Dashboard experiences, cloud services, APIs, package delivery, documentation, support, and related services. |
| Stackie Cloud | Hosted Stackie services, including cloud APIs, package delivery, account management, billing workflows, subscriptions, support, hosted Dashboard experiences, and related hosted features. |
| Stackie Software | Stackie software provided by or for Stackie Ltd, including the stackie command-line application, the stackied daemon, embedded Dashboard components, local support components, update components, and related local software. |
| Usage Data | Operational, telemetry, diagnostics, analytics, provider-derived service metadata, and service-use data generated from access to or use of Stackie. This includes only bounded operational diagnostic categories disclosed in Stackie's current privacy and subprocessor materials and does not reclassify Customer Content as Usage Data merely because Customer Content appears in a diagnostic context. |
| User | An individual authorized by Customer to access or use Stackie, or an individual who otherwise accesses or uses Stackie under Customer's account, device, environment, authority, or control. |
Role Boundary
Customer is controller or business for Customer Personal Data unless the parties agree otherwise. Stackie Ltd is processor, service provider, contractor, or subprocessor for Customer Personal Data processed only to provide the Services under Customer's instructions. Stackie Ltd remains controller for account, billing, security, product, support, marketing, legal acceptance, and business administration processing that Stackie Ltd determines, as described in the Privacy Policy.
Purely local Customer-controlled processing by stackie, stackied, or the embedded dashboard is outside this DPA unless Customer sends that Personal Data to Stackie Ltd, enables a connected Stackie processing flow, requests support or diagnostics involving that data, or otherwise makes the data available for Stackie Ltd to process.
Stackie Ltd ordinarily acts as controller for reliability and security diagnostics that Stackie determines for its own services and staff-development surfaces. Customer-machine or customer-instructed diagnostics containing Customer Personal Data are not enabled by this clause alone. Before that processing begins, the applicable controller or processor role, Customer instruction and authorization, purpose, lawful basis, retention, rights path, transfer posture, and subprocessor coverage must be recorded and approved.
Sentry receives only approved, source-owned technical-error fields through the validated Stackie Observability/Sentry Boundary. Because Sentry's DPA prohibits submission of Sensitive Data, the boundary excludes user-submitted feedback, unrestricted raw errors or messages, customer content, request or response data, user or customer identifiers, paths, arguments, local variables, environment values, logs, screenshots, replay, attachments, profiling data, and arbitrary context. User-submitted reports are outside the Services covered by this release.
Processing Details and Annexes
The DPA annex below describes processor-covered categories of personal data, data subjects, processing purposes, systems, transfer mechanisms, safeguards, retention, and technical and organizational measures reflected in Stackie's current data-processing records. Privacy Policy transparency records for purely local Customer-controlled software data, customer relationship and marketing records, session recording, Stackie-controlled reliability diagnostics, and Stackie's own account, billing, support, legal, and business administration records are not processor-covered DPA Annex I rows unless Customer sends that Personal Data to Stackie Ltd, enables a connected Stackie processing flow, requests support or diagnostics involving that data, or otherwise makes the data available for Stackie Ltd to process under documented instructions. The Subprocessor and Third-Party Recipient List below is the public list for approved subprocessors, third-party recipients, and notice evidence.
Customer gives Stackie Ltd general authorization to use approved subprocessors listed in the Subprocessor and Third-Party Recipient List. Blanket authorization does not turn independent controllers or other third-party recipients into subprocessors and does not eliminate any obligation to maintain a current subprocessor list where law or contract requires one.
U.S. State Privacy Terms
Where U.S. state privacy laws apply and Stackie Ltd acts as service provider, contractor, processor, or similar role, Stackie Ltd will process personal data for permitted purposes and will not sell or share personal data except as permitted by law and the applicable agreement.
Stackie Protective Terms
The Cover Page's Protected Persons, Prospective updates, Correction and no-reliance, Liability cap and mandatory carveouts, DPA liability fallback, and DPA preservation changes state the contractual modifications that protect Stackie Ltd and Protected Persons while preserving non-waivable data-protection obligations. This Stackie DPA Addendum is intended to supplement and point to those Cover Page changes, not to create separate undisclosed changes to the incorporated Standard Terms.
Those Cover Page changes identify Protected Persons as Stackie Ltd and its directors, officers, employees, contractors, affiliates, agents, successors, assigns, shareholders, and members; state that Customer must not rely on Stackie legal documents as professional advice; preserve mandatory-law carveouts for fraud, intentional misconduct, death or personal injury, data-protection, consumer statutory, unfair contract, directors' personal wrongdoing, criminal liability, and regulatory exposure; and address correction, liability cap, release, and indemnity concepts.
This DPA states contractual data processing instructions and related public notices. Customer remains responsible for its own legal, tax, regulatory, security, audit, procurement, compliance, and professional advice.
Document publication corrections are handled through the Cover Page Correction and no-reliance change and the legal changelog where applicable.
Customer content, Customer systems, unlawful instructions, deficient notices or consents, Customer's breach of data protection obligations, and Customer's violation of third-party rights are treated under the Cover Page DPA liability fallback and any applicable agreement liability and claim variables.
Mandatory-law carveouts are handled through the Cover Page Liability cap and mandatory carveouts and DPA preservation changes, the incorporated Standard Terms together with this Cover Page, SCCs, the UK Addendum, and non-waivable privacy or transfer law.
DPA Annex and Subprocessor List
Processor-Covered Categories of Personal Data
| Category | Processor Activity | Systems | Role Basis |
|---|
| organization user data | B2B customer workspace processing where Stackie processes organization user and workspace metadata for a business customer. | Stackie Cloud, hosted dashboard | Stackie acts as processor for the customer controller for this activity. |
| workspace metadata | B2B customer workspace processing where Stackie processes organization user and workspace metadata for a business customer. | Stackie Cloud, hosted dashboard | Stackie acts as processor for the customer controller for this activity. |
| service entitlement data | B2B customer workspace processing where Stackie processes organization user and workspace metadata for a business customer. | Stackie Cloud, hosted dashboard | Stackie acts as processor for the customer controller for this activity. |
Annex I Processing and Transfer Details
| Term | Value |
|---|
| Subject Matter | Processing Customer Personal Data received by or made accessible to Stackie Ltd to provide, secure, maintain, support, troubleshoot, improve, and administer covered Stackie Services. |
| Nature and Purpose | Hosting, authentication, account administration, package delivery, telemetry or diagnostics sent to Stackie Ltd, support, billing, security, legal acceptance, and customer instruction processing. |
| Duration | For the term of the applicable agreement and any lawful retention period needed for backups, security, dispute, audit, tax, or legal claim purposes. |
| Processing Instructions | Customer instructs Stackie Ltd through the applicable agreement, accepted configuration, account settings, support requests, and lawful written instructions. |
| Data Subjects | customer administrators, authorized users, individual developers, support contacts, billing contacts |
| Personal Data Categories | account data, authentication data, billing and subscription data, support and chat data, telemetry and diagnostics, legal acceptance evidence |
| Special Category Data | Stackie services are not intended for special category data unless Stackie Ltd expressly agrees in writing. |
| Special Category Safeguards | Special category data is prohibited unless expressly authorized in a signed agreement that identifies additional safeguards, restrictions, and lawful instructions. |
| Transfer Frequency | Continuous or on-demand for the term of the applicable agreement, depending on Customer configuration, user activity, support requests, telemetry settings, billing events, and service operation. |
| Transfer Description | Transfers occur when Customer or authorized users access Stackie Services, submit Customer Personal Data, trigger support, billing, telemetry, diagnostics, package delivery, authentication, or account workflows, or when approved subprocessors process Customer Personal Data for those workflows. |
| Processing Description | Processing Customer Personal Data for covered Stackie-hosted or Stackie-accessible flows, including account administration, authentication, package delivery, telemetry or diagnostics sent to Stackie Ltd, support, billing, security, legal acceptance, customer instructions, and local/cloud interoperability only when Stackie Ltd receives, accesses, or processes the data. |
| Deletion Procedure | Customer may delete Customer personal data using available service functionality; after DPA expiration Stackie Ltd will return or delete Customer personal data on Customer instruction unless legal, backup, security, dispute, audit, tax, or claim retention requires continued protection and restricted processing. |
EEA SCC and UK Addendum Variables
| Term | Value |
|---|
| Controller to Processor Module | EEA SCC Module Two applies where Customer is a controller and Stackie Ltd processes Customer personal data as processor. |
| Processor to Subprocessor Module | EEA SCC Module Three applies where Customer is a processor and Stackie Ltd processes Customer personal data as subprocessor. |
| Governing Member State | Ireland, unless the signed agreement names another EEA member state required by applicable law. |
| Competent Supervisory Authority | Irish Data Protection Commission, unless the signed agreement or non-waivable law names another competent supervisory authority. |
| Provider Security Contact | [email protected] |
| UK Addendum Details | UK Addendum Table 2 uses the same party, module, transfer, Annex I, Annex II, and Annex III information in this Cover Page and DPA annex; Table 4 is modified as stated in the unmodified DPA Standard Terms unless a signed agreement states otherwise. |
Transfer Mechanisms
| Recipient | Recipient Role | Regions | Primary Mechanism | Coverage | Safeguards | Notice Days |
|---|
| Paddle.com Market Limited - Merchant-of-record billing and tax services | independent controller | United Kingdom, European Union and EEA, United States | Data Privacy Framework or equivalent certified transfer basis | Data Privacy Framework or equivalent certified transfer basis, contractual transfer terms | recipient-specific written terms and transfer safeguards, contractual transfer terms, payment data minimization, recipient diligence and contractual safeguard review | 30 |
| Google LLC - Optional account sign-in provider | independent controller | United Kingdom, European Union and EEA, United States | Data Privacy Framework or equivalent certified transfer basis | Data Privacy Framework or equivalent certified transfer basis, contractual transfer terms | user opt-out where required, contractual transfer terms | 30 |
| Cloudflare, Inc. - Cloud application hosting and request handling | processor | United Kingdom, European Union and EEA, United States | EEA Standard Contractual Clauses | EEA Standard Contractual Clauses, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, Data Privacy Framework or equivalent certified transfer basis | contractual processor terms and transfer safeguards, EEA Standard Contractual Clauses, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, edge data minimization | 30 |
| Cloudflare, Inc. - Transactional email delivery | processor | United Kingdom, European Union and EEA, United States | EEA Standard Contractual Clauses | EEA Standard Contractual Clauses, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, Data Privacy Framework or equivalent certified transfer basis | contractual processor terms and transfer safeguards, EEA Standard Contractual Clauses, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, email data minimization | 30 |
| Cloudflare, Inc. - Package and encrypted infrastructure state storage | processor | United Kingdom, European Union and EEA, United States | EEA Standard Contractual Clauses | EEA Standard Contractual Clauses, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, Data Privacy Framework or equivalent certified transfer basis | contractual processor terms and transfer safeguards, EEA Standard Contractual Clauses, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, package artifact data minimization, infrastructure state data minimization, workspace-scoped least-privilege access | 30 |
| Neon, Inc. - Managed database hosting | processor | United Kingdom, European Union and EEA, United States | EEA Standard Contractual Clauses | EEA Standard Contractual Clauses, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, Data Privacy Framework or equivalent certified transfer basis | contractual processor terms and transfer safeguards, EEA Standard Contractual Clauses, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, database access minimization | 30 |
| Functional Software, Inc. d/b/a Sentry - Operational fault monitoring and private diagnostic release artifacts | processor | European Union and EEA, United States | EEA Standard Contractual Clauses | EEA Standard Contractual Clauses, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, Data Privacy Framework or equivalent certified transfer basis | contractual processor terms and transfer safeguards, EEA Standard Contractual Clauses, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, diagnostic data minimization and allowlisted collection, private JavaScript diagnostic artifacts are minimized and permanently deleted within thirty days, operational diagnostics and provider-derived metadata are enumerated in the private processing register, transfer impact assessment and safeguard review | 30 |
Provider Transfer Summary
| Provider Operation | Regions | Primary Mechanism | Coverage | Safeguards | Transfer Summary |
|---|
| Stackie Cloud first-party service | United Kingdom, European Union and EEA, United States | EEA Standard Contractual Clauses | EEA Standard Contractual Clauses, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, adequacy decision or equivalent lawful transfer basis | EEA Standard Contractual Clauses, adequacy decision or equivalent lawful transfer basis, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, transfer impact assessment and safeguard review | transfer safeguards maintained |
Technical and Organizational Measures
| Processing Type | Status | Safeguards | DPIA |
|---|
| session replay | disabled | mask passwords, secrets, and terminal content, support required privacy preference signals and regional consent rules for enabled surfaces where legally required, disable for minors, retention limited | required before activation |
| AI or model training on customer content | disabled | requires explicit consent and data protection impact assessment before activation, customer content excluded by default | required before activation |
| children or minors data | disabled | age-directed use prohibited, close accounts on knowledge of prohibited minors processing | required before activation |
| sensitive telemetry | disabled | requires express authorization and legal approval before activation, secrets and special-category data prohibited | required before activation |
| crash context diagnostics | enabled | only source-owned, enumerated technical-error fields are accepted, secrets, sensitive data, customer content, user identifiers, and arbitrary diagnostic context are prohibited, development reporting is restricted to staff use with internal or synthetic data, development events use exact destinations and the development environment without live fallback, active searchable technical-error events are available for up to 30 days, provider-side scrubbing and prevention of new-event IP address storage are required, user identity, session storage, replay, feedback, attachments, profiling, and AI analysis are disabled, reporting has an emergency kill switch and cannot fall back to live destinations, recorded impact screening covers the current minimized pre-production, UK/US public-live, and separately enabled UK/US CLI/daemon paths, released CLI and daemon reporting stays inert until a current report-once or automatic preference is recorded and stops after withdrawal, temporary specification branches have no standing reporting destination or shared reporting runtime | not required |
| bounded operational diagnostics | disabled | supplied fields and provider-derived metadata are exactly inventoried, only source-owned closed schemas survive final egress reconstruction, user, customer, account, device, and persistent session identifiers are excluded, customer content, free text, requests, responses, and automatic instrumentation are excluded, timing and metric data use coarse buckets, fixed dimensions, and bounded sampling, application release health is aggregate-only and contains no session identifier, live uptime uses credentialless bodyless probes and Workers use fixed check-ins, private JavaScript artifacts exclude source content, source paths, and native symbols, development, pre-production test, and live uploads use isolated credentials with a separate retention credential, diagnostic records and private release artifacts are limited to thirty days, availability is restricted to the United Kingdom and United States while EEA targeting, signup, acceptance, and availability remain blocked, public category wording is backed by exact private processing traceability, activation requires a fresh hash-bound owner approval | not required |
| customer chat | disabled | avoid secrets and sensitive data, support access controls, retention limited | not required |
| support desk processing | disabled | avoid secrets and sensitive data, support access controls, retention limited | not required |
| marketing analytics | disabled | support required privacy preference signals and marketing opt-outs for enabled surfaces where legally required, unsubscribe required, retention limited | not required |
Security Control Measures
| Control Category | Control Objective | Status | Public Measure |
|---|
| Access control | Limit access to production systems, customer data, billing records, legal acceptance evidence, and security logs to personnel or service providers with a documented business need. | Implemented | Stackie limits production and administrative access by business need and removes access when it is no longer required. |
| Authentication | Protect account authentication and session flows used for Stackie Cloud access and legal acceptance workflows. | Implemented | Stackie uses authentication and session controls for account access, security-sensitive workflows, and legal acceptance records. |
| Transport security | Protect customer-facing and provider-facing network traffic with transport security where Stackie controls the connection. | Implemented | Stackie uses transport security for customer-facing and provider-facing connections where Stackie controls the connection. |
| Data minimization | Minimize, redact, or exclude personal data and raw provider payload material that is not needed for declared service, billing, security, legal, or support purposes. | Implemented | Stackie limits retained data to what is needed for declared service, billing, security, legal, or support purposes and excludes unnecessary raw provider material. |
| Secure development | Use source review, schema validation, generated artifact freshness checks, and release gates to reduce security, privacy, and compliance drift before release. | Implemented | Stackie uses source review, automated checks, generated artifact validation, and release gates to reduce security and compliance drift. |
| Logging and monitoring | Record operational and security-relevant events needed to operate, troubleshoot, secure, and audit Stackie services without retaining unnecessary raw payload material. | Implemented | Stackie records operational and security-relevant events needed to operate, troubleshoot, secure, and audit the service while limiting unnecessary raw payload retention. |
| Incident response | Maintain a documented process for investigating suspected security incidents and notifying customers or authorities where legally required. | Implemented | Stackie investigates suspected security incidents and notifies affected customers or authorities where legally required. |
| Backup and retention | Apply documented retention, legal-hold, backup, deletion, and migration controls to personal-data and customer-data surfaces. | Implemented | Stackie applies documented retention, legal-hold, backup, deletion, and migration controls to relevant data surfaces. |
| Subprocessor governance | Maintain approved processor, subprocessor, third-party recipient, transfer, and vendor evidence records before production reliance. | Implemented | Stackie maintains processor, subprocessor, third-party recipient, transfer, and vendor evidence records for approved service providers. |
| Release governance | Block production legal reliance until required legal, security, privacy, processor, open-source notice, and release evidence is resolved or explicitly carried. | Implemented | Stackie uses release controls to keep legal, security, privacy, processor, open-source notice, and acceptance evidence current before release. |
Annex II Security Measures
| Term | Value |
|---|
| Security Policy | Stackie Security/TOMs document published at /legal/security-toms and DPA annex. |
| Security Control Source | Annex II Security Measures summarize 10 structured Stackie security-control categories maintained by Stackie. |
| Annex II Security Measures | The technical and organizational measures listed in the Security Control Measures table in this DPA annex, currently covering 10 source-owned control categories. |
| Audit Report Process | Security reports, due-diligence responses, and audit assistance are provided through Stackie support or legal contact under the DPA, subject to confidentiality, reasonable frequency limits, and protection of Stackie confidential information. |
Annex III Approved Subprocessors
| Term | Value |
|---|
| Subprocessor Authorization | General authorization applies only to approved subprocessors identified as processors, subprocessors, service providers, or contractors in Annex III and the Subprocessor List, with the notice periods recorded there; independent controllers and other third-party recipients are disclosed separately for transparency and are not approved subprocessors. |
| Annex III Approved Subprocessors | Approved subprocessors are only the recipients identified as processors, subprocessors, service providers, or contractors in Annex III and the Subprocessor List at /legal/subprocessors, including their processing tasks, regions, transfer mechanisms, and notice periods. Independent controllers and other third-party recipients are disclosed separately outside Annex III for transparency and are not approved subprocessors. |
Approved Subprocessors and Service Providers
| Vendor Legal Name | Service Category | Role | Purpose | Regions | Transfer Mechanism | Transfer Coverage | Transfer Notice Days | Change Notice Days | Notice/Objection Route | Replacement Notice |
|---|
| Cloudflare, Inc. | Package and encrypted infrastructure state storage | processor | Stores package artifacts and delivery metadata for Stackie downloads, plus encrypted infrastructure state needed to operate the service. | United Kingdom, European Union and EEA, United States | EEA Standard Contractual Clauses | EEA Standard Contractual Clauses, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, Data Privacy Framework or equivalent certified transfer basis | 30 | 30 | Email [email protected] for DPA, subprocessor, transfer, or objection notices. | Stackie will publish notice before material replacement where required by the DPA or applicable law. |
| Cloudflare, Inc. | Cloud application hosting and request handling | processor | Runs Stackie Cloud request handling, rate limiting, and service runtime operations. | United Kingdom, European Union and EEA, United States | EEA Standard Contractual Clauses | EEA Standard Contractual Clauses, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, Data Privacy Framework or equivalent certified transfer basis | 30 | 30 | Email [email protected] for DPA, subprocessor, transfer, or objection notices. | Stackie will publish notice before material replacement where required by the DPA or applicable law. |
| Cloudflare, Inc. | Transactional email delivery | processor | Sends account verification, password reset, and account lifecycle emails. | United Kingdom, European Union and EEA, United States | EEA Standard Contractual Clauses | EEA Standard Contractual Clauses, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, Data Privacy Framework or equivalent certified transfer basis | 30 | 30 | Email [email protected] for DPA, subprocessor, transfer, or objection notices. | Stackie will publish notice before material replacement where required by the DPA or applicable law. |
| Neon, Inc. | Managed database hosting | processor | Stores Stackie Cloud account, authentication, billing, audit, security, usage, and package metadata records. | United Kingdom, European Union and EEA, United States | EEA Standard Contractual Clauses | EEA Standard Contractual Clauses, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, Data Privacy Framework or equivalent certified transfer basis | 30 | 30 | Email [email protected] for DPA, subprocessor, transfer, or objection notices. | Stackie will publish notice before material replacement where required by the DPA or applicable law. |
| Functional Software, Inc. d/b/a Sentry | Operational fault monitoring and private diagnostic release artifacts | processor | Receives minimized operational telemetry and private JavaScript release artifacts needed to detect, diagnose, measure and remediate faults on approved Stackie surfaces. | European Union and EEA, United States | EEA Standard Contractual Clauses | EEA Standard Contractual Clauses, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, Data Privacy Framework or equivalent certified transfer basis | 30 | 30 | Email [email protected] for DPA, subprocessor, transfer, or objection notices. | Stackie will publish notice before material replacement where required by the DPA or applicable law. |
Independent Controllers and Payment Providers
| Vendor Legal Name | Service Category | Role | Purpose | Regions | Transfer Mechanism | Transfer Coverage | Transfer Notice Days | Change Notice Days | Notice/Objection Route | Replacement Notice |
|---|
| Google LLC | Optional account sign-in provider | independent controller | Provides Google account sign-in when a user chooses that method. | United States, European Union and EEA, United Kingdom | Data Privacy Framework or equivalent certified transfer basis | Data Privacy Framework or equivalent certified transfer basis, contractual transfer terms | 30 | 30 | Email [email protected] for third-party recipient privacy questions. | Independent controller sign-in provider entry; disclosed separately from subprocessor approvals. |
| Paddle.com Market Limited | Merchant-of-record billing and tax services | independent controller | Provides checkout, subscription management, invoicing, tax, and billing support as merchant of record. | United Kingdom, European Union and EEA, United States | Data Privacy Framework or equivalent certified transfer basis | Data Privacy Framework or equivalent certified transfer basis, contractual transfer terms | 30 | 30 | Email [email protected] for billing-recipient privacy questions. | Stackie will publish notice before material replacement where required by the DPA or applicable law. |
Notice and Transfer Evidence
| Recipient | Role | Notice Days | Recipient Terms Posture |
|---|
| Paddle.com Market Limited - Merchant-of-record billing and tax services | independent controller | 30 | Covered by recipient-specific written terms |
| Google LLC - Optional account sign-in provider | independent controller | 30 | Independent controller terms apply; no processor addendum is required for this disclosed role |
| Cloudflare, Inc. - Cloud application hosting and request handling | processor | 30 | Covered by written processor or subprocessor terms |
| Cloudflare, Inc. - Transactional email delivery | processor | 30 | Covered by written processor or subprocessor terms |
| Cloudflare, Inc. - Package and encrypted infrastructure state storage | processor | 30 | Covered by written processor or subprocessor terms |
| Neon, Inc. - Managed database hosting | processor | 30 | Covered by written processor or subprocessor terms |
| Functional Software, Inc. d/b/a Sentry - Operational fault monitoring and private diagnostic release artifacts | processor | 30 | Covered by written processor or subprocessor terms |
Common Paper Standard Terms and Attribution
Source and Attribution
Standard Terms Reference Copy
The following reference copy is included for readability only. It does not modify the incorporated Standard Terms and remains subject to the Cover Page, Variables, Additions, Supplements, and Other Changes to Standard Terms above. The Source and Attribution table identifies the versioned Standard Terms used by this agreement.
Data Processing Agreement
- Processor and Subprocessor Relationships
- Provider as Processor. In situations where Customer is a Controller of the Customer Personal Data, Provider will be deemed a Processor that is Processing Personal Data on behalf of Customer.
- Provider as Subprocessor. In situations where Customer is a Processor of the Customer Personal Data, Provider will be deemed a Subprocessor of the Customer Personal Data.
- Processing
- Processing Details. Annex I(B) on the Cover Page describes the subject matter, nature, purpose, and duration of this Processing, as well as the Categories of Personal Data collected and Categories of Data Subjects.
- Processing Instructions. Customer instructs Provider to Process Customer Personal Data: (a) to provide and maintain the Service; (b) as may be further specified through Customer’s use of the Service; (c) as documented in the Agreement; and (d) as documented in any other written instructions given by Customer and acknowledged by Provider about Processing Customer Personal Data under this DPA. Provider will abide by these instructions unless prohibited from doing so by Applicable Laws. Provider will immediately inform Customer if it is unable to follow the Processing instructions. Customer has given and will only give instructions that comply with Applicable Laws.
- Processing by Provider. Provider will only Process Customer Personal Data in accordance with this DPA, including the details in the Cover Page. If Provider updates the Service to update existing or include new products, features, or functionality, Provider may change the Categories of Data Subjects, Categories of Personal Data, Special Category Data, Special Category Data Restrictions or Safeguards, Frequency of Transfer, Nature and Purpose of Processing, and Duration of Processing as needed to reflect the updates by notifying Customer of the updates and changes.
- Customer Processing. Where Customer is a Processor and Provider is a Subprocessor, Customer will comply with all Applicable Laws that apply to Customer’s Processing of Customer Personal Data. Customer’s agreement with its Controller will similarly require Customer to comply with all Applicable Laws that apply to Customer as a Processor. In addition, Customer will comply with the Subprocessor requirements in Customer’s agreement with its Controller.
- Consent to Processing. Customer has complied with and will continue to comply with all Applicable Data Protection Laws concerning its provision of Customer Personal Data to Provider and/or the Service, including making all disclosures, obtaining all consents, providing adequate choice, and implementing relevant safeguards required under Applicable Data Protection Laws.
- Subprocessors.
- Provider will not provide, transfer, or hand over any Customer Personal Data to a Subprocessor unless Customer has approved the Subprocessor. The current list of Approved Subprocessors includes the identities of the Subprocessors, their country of location, and their anticipated Processing tasks. Provider will inform Customer at least 10 business days in advance and in writing of any intended changes to the Approved Subprocessors whether by addition or replacement of a Subprocessor, which allows Customer to have enough time to object to the changes before the Provider begins using the new Subprocessor(s). Provider will give Customer the information necessary to allow Customer to exercise its right to object to the change to Approved Subprocessors. Customer has 30 days after notice of a change to the Approved Subprocessors to object, otherwise Customer will be deemed to accept the changes. If Customer objects to the change within 30 days of notice, Customer and Provider will cooperate in good faith to resolve Customer’s objection or concern.
- When engaging a Subprocessor, Provider will have a written agreement with the Subprocessor that ensures the Subprocessor only accesses and uses Customer Personal Data (i) to the extent required to perform the obligations subcontracted to it, and (ii) consistent with the terms of Agreement.
- If the GDPR applies to the Processing of Customer Personal Data, (i) the data protection obligations described in this DPA (as referred to in Article 28(3) of the GDPR, if applicable) are also imposed on the Subprocessor, and (ii) Provider’s agreement with the Subprocessor will incorporate these obligations, including details about how Provider and its Subprocessor will coordinate to respond to inquiries or requests about the Processing of Customer Personal Data. In addition, Provider will share, at Customer’s request, a copy of its agreements (including any amendments) with its Subprocessors. To the extent necessary to protect business secrets or other confidential information, including personal data, Provider may redact the text of its agreement with its Subprocessor prior to sharing a copy.
- Provider remains fully liable for all obligations subcontracted to its Subprocessors, including the acts and omissions of its Subprocessors in Processing Customer Personal Data. Provider will notify Customer of any failure by its Subprocessors to fulfill a material obligation about Customer Personal Data under the agreement between Provider and the Subprocessor.
- Restricted Transfers
- Authorization. Customer agrees that Provider may transfer Customer Personal Data outside the EEA, the United Kingdom, or other relevant geographic territory as necessary to provide the Service. If Provider transfers Customer Personal Data to a territory for which the European Commission or other relevant supervisory authority has not issued an adequacy decision, Provider will implement appropriate safeguards for the transfer of Customer Personal Data to that territory consistent with Applicable Data Protection Laws.
- Ex-EEA Transfers. Customer and Provider agree that if the GDPR protects the transfer of Customer Personal Data, the transfer is from Customer from within the EEA to Provider outside of the EEA, and the transfer is not governed by an adequacy decision made by the European Commission, then by entering into this DPA, Customer and Provider are deemed to have signed the EEA SCCs and their Annexes, which are incorporated by reference. Any such transfer is made pursuant to the EEA SCCs, which are completed as follows:
- Module Two (Controller to Processor) of the EEA SCCs apply when Customer is a Controller and Provider is Processing Customer Personal Data for Customer as a Processor.
- Module Three (Processor to Sub-Processor) of the EEA SCCs apply when Customer is a Processor and Provider is Processing Customer Personal Data on behalf of Customer as a Subprocessor.
- For each module, the following applies (when applicable):
- The optional docking clause in Clause 7 does not apply;
- In Clause 9, Option 2 (general written authorization) applies, and the minimum time period for prior notice of Subprocessor changes is 10 business days;
- In Clause 11, the optional language does not apply;
- All square brackets in Clause 13 are removed;
- In Clause 17 (Option 1), the EEA SCCs will be governed by the laws of Governing Member State;
- In Clause 18(b), disputes will be resolved in the courts of the Governing Member State; and
- The Cover Page to this DPA contains the information required in Annex I, Annex II, and Annex III of the EEA SCCs.
- Ex-UK Transfers. Customer and Provider agree that if the UK GDPR protects the transfer of Customer Personal Data, the transfer is from Customer from within the United Kingdom to Provider outside of the United Kingdom, and the transfer is not governed by an adequacy decision made by the United Kingdom Secretary of State, then by entering into this DPA, Customer and Provider are deemed to have signed the UK Addendum and their Annexes, which are incorporated by reference. Any such transfer is made pursuant to the UK Addendum, which is completed as follows:
- Section 3.2 of this DPA contains the information required in Table 2 of the UK Addendum.
- Table 4 of the UK Addendum is modified as follows: Neither party may end the UK Addendum as set out in Section 19 of the UK Addendum; to the extent ICO issues a revised Approved Addendum under Section 18 of the UK Addendum, the parties will work in good faith to revise this DPA accordingly.
- The Cover Page contains the information required by Annex 1A, Annex 1B, Annex II, and Annex III of the UK Addendum.
- Other International Transfers. For Personal Data transfers where Swiss law (and not the law in any EEA member state or the United Kingdom) applies to the international nature of the transfer, references to the GDPR in Clause 4 of the EEA SCCs are, to the extent legally required, amended to refer to the Swiss Federal Data Protection Act or its successor instead, and the concept of supervisory authority will include the Swiss Federal Data Protection and Information Commissioner.
- Security Incident Response
- Upon becoming aware of any Security Incident, Provider will: (a) notify Customer without undue delay when feasible, but no later than 72 hours after becoming aware of the Security Incident; (b) provide timely information about the Security Incident as it becomes known or as is reasonably requested by Customer; and (c) promptly take reasonable steps to contain and investigate the Security Incident. Provider’s notification of or response to a Security Incident as required by this DPA will not be construed as an acknowledgment by Provider of any fault or liability for the Security Incident.
- Audit & Reports
- Audit Rights. Provider will give Customer all information reasonably necessary to demonstrate its compliance with this DPA and Provider will allow for and contribute to audits, including inspections by Customer, to assess Provider’s compliance with this DPA. However, Provider may restrict access to data or information if Customer’s access to the information would negatively impact Provider’s intellectual property rights, confidentiality obligations, or other obligations under Applicable Laws. Customer acknowledges and agrees that it will only exercise its audit rights under this DPA and any audit rights granted by Applicable Data Protection Laws by instructing Provider to comply with the reporting and due diligence requirements below. Provider will maintain records of its compliance with this DPA for 3 years after the DPA ends.
- Security Reports. Customer acknowledges that Provider is regularly audited against the standards defined in the Security Policy by independent third-party auditors. Upon written request, Provider will give Customer, on a confidential basis, a summary copy of its then-current Report so that Customer can verify Provider’s compliance with the standards defined in the Security Policy.
- Security Due Diligence. In addition to the Report, Provider will respond to reasonable requests for information made by Customer to confirm Provider’s compliance with this DPA, including responses to information security, due diligence, and audit questionnaires, or by giving additional information about its information security program. All such requests must be in writing and made to the Provider Security Contact and may only be made once a year.
- Coordination & Cooperation
- Response to Inquiries. If Provider receives any inquiry or request from anyone else about the Processing of Customer Personal Data, Provider will notify Customer about the request and Provider will not respond to the request without Customer’s prior consent. Examples of these kinds of inquiries and requests include a judicial or administrative or regulatory agency order about Customer Personal Data where notifying Customer is not prohibited by Applicable Law, or a request from a data subject. If allowed by Applicable Law, Provider will follow Customer’s reasonable instructions about these requests, including providing status updates and other information reasonably requested by Customer. If a data subject makes a valid request under Applicable Data Protection Laws to delete or opt out of Customer’s giving of Customer Personal Data to Provider, Provider will assist Customer in fulfilling the request according to the Applicable Data Protection Law. Provider will cooperate with and provide reasonable assistance to Customer, at Customer’s expense, in any legal response or other procedural action taken by Customer in response to a third-party request about Provider’s Processing of Customer Personal Data under this DPA.
- DPIAs and DTIAs. If required by Applicable Data Protection Laws, Provider will reasonably assist Customer in conducting any mandated data protection impact assessments or data transfer impact assessments and consultations with relevant data protection authorities, taking into consideration the nature of the Processing and Customer Personal Data.
- Deletion of Customer Personal Data
- Deletion by Customer. Provider will enable Customer to delete Customer Personal Data in a manner consistent with the functionality of the Services. Provider will comply with this instruction as soon as reasonably practicable except where further storage of Customer Personal Data is required by Applicable Law.
- Deletion at DPA Expiration.
- After the DPA expires, Provider will return or delete Customer Personal Data at Customer’s instruction unless further storage of Customer Personal Data is required or authorized by Applicable Law. If return or destruction is impracticable or prohibited by Applicable Laws, Provider will make reasonable efforts to prevent additional Processing of Customer Personal Data and will continue to protect the Customer Personal Data remaining in its possession, custody, or control. For example, Applicable Laws may require Provider to continue hosting or Processing Customer Personal Data.
- If Customer and Provider have entered the EEA SCCs or the UK Addendum as part of this DPA, Provider will only give Customer the certification of deletion of Personal Data described in Clause 8.1(d) and Clause 8.5 of the EEA SCCs if Customer asks for one.
- Limitation of Liability
- Liability Caps and Damages Waiver. To the maximum extent permitted under Applicable Data Protection Laws, each party’s total cumulative liability to the other party arising out of or related to this DPA will be subject to the waivers, exclusions, and limitations of liability stated in the Agreement.
- Related-Party Claims. Any claims made against Provider or its Affiliates arising out of or related to this DPA may only be brought by the Customer entity that is a party to the Agreement.
- Exceptions. This DPA does not limit any liability to an individual about the individual’s data protection rights under Applicable Data Protection Laws. In addition, this DPA does not limit any liability between the parties for violations of the EEA SCCs or UK Addendum.
- Conflicts Between Documents
- This DPA forms part of and supplements the Agreement. If there is any inconsistency between this DPA, the Agreement, or any of their parts, the part listed earlier will control over the part listed later for that inconsistency: (1) the EEA SCCs or the UK Addendum, (2) this DPA, and then (3) the Agreement.
- Term of Agreement
- This DPA will start when Provider and Customer agree to a Cover Page for the DPA and sign or electronically accept the Agreement and will continue until the Agreement expires or is terminated. However, Provider and Customer will each remain subject to the obligations in this DPA and Applicable Data Protection Laws until Customer stops transferring Customer Personal Data to Provider and Provider stops Processing Customer Personal Data.
- Definitions
- "Applicable Laws" means the laws, rules, regulations, court orders, and other binding requirements of a relevant government authority that apply to or govern a party.
- "Applicable Data Protection Laws" means the Applicable Laws that govern how the Service may process or use an individual’s personal information, personal data, personally identifiable information, or other similar term.
- "Controller" will have the meaning(s) given in the Applicable Data Protection Laws for the company that determines the purpose and extent of Processing Personal Data.
- "Cover Page" means a document that is signed or electronically accepted by the parties that incorporates these DPA Standard Terms and identifies Provider, Customer, and the subject matter and details of the data processing.
- "Customer Personal Data" means Personal Data that Customer uploads or provides to Provider as part of the Service and that is governed by this DPA.
- "DPA" means these DPA Standard Terms, the Cover Page between Provider and Customer, and the policies and documents referenced in or attached to the Cover Page.
- "EEA SCCs" means the standard contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the European Council.
- "European Economic Area" or "EEA" means the member states of the European Union, Norway, Iceland, and Liechtenstein.
- "GDPR" means European Union Regulation 2016/679 as implemented by local law in the relevant EEA member nation.
- "Personal Data" will have the meaning(s) given in the Applicable Data Protection Laws for personal information, personal data, or other similar term.
- "Processing" or "Process" will have the meaning(s) given in the Applicable Data Protection Laws for any use of, or performance of a computer operation on, Personal Data, including by automatic methods.
- "Processor" will have the meaning(s) given in the Applicable Data Protection Laws for the company that Processes Personal Data on behalf of the Controller.
- "Report" means audit reports prepared by another company according to the standards defined in the Security Policy on behalf of Provider.
- "Restricted Transfer" means (a) where the GDPR applies, a transfer of personal data from the EEA to a country outside of the EEA which is not subject to an adequacy determination by the European Commission; and (b) where the UK GDPR applies, a transfer of personal data from the United Kingdom to any other country which is not subject to adequacy regulations adopted pursuant to Section 17A of the United Kingdom Data Protection Act 2018.
- "Security Incident" means a Personal Data Breach as defined in Article 4 of the GDPR.
- "Service" means the product and/or services described in the Agreement.
- "Special Category Data" will have the meaning given in Article 9 of the GDPR.
- "Subprocessor" will have the meaning(s) given in the Applicable Data Protection Laws for a company that, with the approval and acceptance of Controller, assists the Processor in Processing Personal Data on behalf of the Controller.
- "UK GDPR" means European Union Regulation 2016/679 as implemented by section 3 of the United Kingdom’s European Union (Withdrawal) Act of 2018 in the United Kingdom.
- "UK Addendum" means the international data transfer addendum to the EEA SCCs issued by the Information Commissioner for Parties making Restricted Transfers under S119A(1) Data Protection Act 2018.