Stackie legal document
Stackie Security and Technical/Organizational Measures
- Document version
- 2026.07.29.1
- Document effective date
- 2026-07-29
Acceptance Evidence
- Acceptance mode
- Notice or acknowledgement
- Manifest version
2026.06.20- Rendered document hash
d1340d6ce8cfd5ce6a45dc548c28f5965e98adc751a1b60130753ed292b580ad- Public legal bundle hash
74145aaa10743e41788a22457265026c17e068b4009d61c102378f0c20945ade- Assent statement hash
68854b4304f0743a861f78ec8e59f6ee7a10212a7314ce6055c32bfcb2902638- Acceptance metadata hash
5c5be0aac5719aa008dfec90eeb9da49e426d26fa40bc1d0e2e0f8370e5fc92a- Required acceptance surfaces
- None
- Available publication surfaces
- Stackie Cloud, Stackie app, embedded dashboard
- Separate acceptance surfaces
- None
I acknowledge that Stackie made Stackie Security and Technical/Organizational Measures version 2026.07.29.1, effective 2026-07-29 available as the current notice or schedule for the applicable Stackie surface. I represent that I am acting for trade, business, professional, freelance, employment, or organizational development purposes and not for personal, household, or consumer use unless Stackie Ltd expressly permits that use in a signed agreement, checkout flow, or product-specific consumer schedule.
This document summarizes Stackie Ltd's administrative, technical, and organizational measures for Stackie systems, Customer Content, and Customer Personal Data. It applies where incorporated by the Terms, Cloud Service Agreement, DPA, EULA, order form, or other agreement.
Defined Terms
These Stackie-specific definitions supplement the document that embeds this section. If an incorporated Common Paper Standard Term, Cover Page, Key Terms, Order Form, signed agreement, or non-waivable law gives a capitalized term a different meaning for a specific agreement or notice, that more specific meaning controls for that agreement or notice.
| Term | Meaning |
|---|---|
| Customer | The individual acting for business or professional development purposes, business, enterprise, organization, or other entity that accepts, accesses, or uses Stackie under the applicable agreement or notice. |
| Customer Content | Data, code, packages, configuration, instructions, logs, support materials, and other materials submitted to, stored in, or processed through Stackie by or for Customer. |
| Dashboard | Embedded, local, or hosted Stackie dashboard experiences covered by the applicable agreement or notice. |
| Local Software | Stackie Software installed or run on Customer-controlled systems, including local command-line, daemon, embedded Dashboard, package, update, support, and integration components. |
| Personal Data | Information relating to an identified or identifiable individual. |
| Protected Persons | Stackie Ltd and its directors, officers, employees, contractors, affiliates, agents, successors, assigns, shareholders, and members. |
| Provider | Stackie Ltd, unless the applicable agreement or signed order form identifies a different provider for the covered offering. |
| Services | Stackie websites, applications, APIs, package delivery, documentation, support, hosted services, and related service components covered by the applicable agreement or notice. |
| Software | The software identified as Software in the applicable Cover Page, Key Terms, Order Form, EULA, signed agreement, or other accepted Stackie document. |
| Stackie | The Stackie products and services covered by the applicable agreement or notice, including Stackie websites, applications, command-line tools, daemon components, Dashboard experiences, cloud services, APIs, package delivery, documentation, support, and related services. |
| Stackie Cloud | Hosted Stackie services, including cloud APIs, package delivery, account management, billing workflows, subscriptions, support, hosted Dashboard experiences, and related hosted features. |
| Stackie Software | Stackie software provided by or for Stackie Ltd, including the stackie command-line application, the stackied daemon, embedded Dashboard components, local support components, update components, and related local software. |
| Usage Data | Operational, telemetry, diagnostics, analytics, provider-derived service metadata, and service-use data generated from access to or use of Stackie. This includes only bounded operational diagnostic categories disclosed in Stackie's current privacy and subprocessor materials and does not reclassify Customer Content as Usage Data merely because Customer Content appears in a diagnostic context. |
| User | An individual authorized by Customer to access or use Stackie, or an individual who otherwise accesses or uses Stackie under Customer's account, device, environment, authority, or control. |
Security Program
Stackie Ltd maintains a security program designed for a developer tooling business at Stackie's current scale. The generated Security Control Measures table below summarizes Stackie's current source-owned control categories, including access control, authentication, secure development, release governance, logging and monitoring, incident response, data minimization, transport security, backup and retention, and subprocessor governance.
Access Controls
Stackie Ltd limits access to production systems, administrative functions, customer data, billing data, legal acceptance evidence, and security logs to personnel and service providers with a business need. Access is removed when no longer required and protected by authentication controls described in the generated Security Control Measures.
Development and Release Controls
Stackie uses the secure-development and release-governance measures summarized in the generated Security Control Measures table to reduce security, privacy, and compliance drift. High-risk processing must be reviewed before activation.
Data Protection
The DPA annex below identifies processing categories, transfer mechanisms, safeguards, and current technical and organizational measure categories generated from Stackie's legal inventory and Security Control Measures table.
Technical Error-Reporting Controls
Sentry payloads pass through a source-owned, versioned, fail-closed boundary that accepts only approved typed fields and rejects unrestricted SDK enrichment. Named destinations use separate development, staff-only ppt, and live client keys and event environments, including isolated Cloud server-side destinations. Those keys and environments are routing controls, not authorization boundaries. Environment-specific credentials, runtime gates, sampling limits, bounded retention, least-privilege access, kill switches, negative privacy tests, provider-side scrubbing, and prevention of new-event IP storage provide defense in depth.
User-submitted reports, narrative feedback, unrestricted raw error content, logs, request or response data, customer content, identifiers, paths, arguments, local variables, environment values, screenshots, replay, attachments, profiling, source scraping or upload, and AI analysis are outside the approved reporting path. Development and staff-only ppt require internal or synthetic data, isolated Cloud runtimes and client destinations, no fallback into live resources or destinations, and an emergency kill switch. Approved dev, ppt, UK/US public-live, and separately enabled UK/US CLI/daemon technical-error events have a maximum 30-day active searchable window. Released CLI and daemon reporting is inert by default, requires a current per-machine report-once or automatic preference after the just-in-time notice, and stops after withdrawal. Temporary per-spec branches, EU/EEA launch reporting, customer-content diagnostics, and user-submitted reports remain disabled; any future expansion requires distinct legal, security, portal, deployment, and release approval.
Incident Response
Stackie Ltd investigates suspected security incidents and will notify affected customers or authorities where legally required. Customer must promptly notify Stackie of suspected compromise involving Stackie credentials, tokens, local installations, cloud accounts, or Customer systems.
Customer Responsibilities
Customer remains responsible for securing Customer devices, local networks, cloud accounts, credentials, device tokens, local APIs, local Dashboard endpoints, package sources, Customer Content, and User permissions. Customer must maintain backups and configurations appropriate to Customer's risk.
No Absolute Security
No security measure is perfect. This document does not promise uninterrupted or error-free operation, prevention of all incidents, or a particular certification unless expressly stated in a signed agreement.
Protected Persons and Document Errors
To the fullest extent allowed by applicable law, protections, disclaimers, liability limits, releases, defenses, correction rights, indemnities, and remedy limits in this Security/TOMs document benefit Stackie Ltd and its directors, officers, employees, contractors, affiliates, agents, successors, assigns, shareholders, and members as Protected Persons and intended third-party beneficiaries where law allows.
This document describes controls and contractual commitments only where incorporated into an agreement. It is not legal, tax, regulatory, security, audit, procurement, or compliance advice to Customer. Customer must not rely on it as advice about Customer's own obligations or risk position.
Stackie Ltd may correct drafting, typographical, formatting, translation, cross-reference, link, control description, publication, manifest, version, schedule, table, automated publication, or similar errors prospectively and may republish corrected materials. Corrections do not waive Stackie Ltd's rights or create liability for the original error to the fullest extent allowed by law.
To the fullest extent allowed by applicable law, this Security/TOMs document is descriptive except to the extent it is incorporated into an applicable agreement. Where incorporated, Security/TOMs commitments are subject to, and do not expand, the liability cap, exclusions, mandatory carveouts, DPA terms, SCC/UK Addendum terms, and non-waivable law in that applicable agreement. If no applicable agreement cap applies and a standalone statement in this document is held to create liability, Stackie Ltd's aggregate liability for that standalone statement is capped at the greater of GBP 100 or fees paid by Customer for the affected service in the 12 months before the event giving rise to the claim. Customer releases the Protected Persons from claims above enforceable caps and will indemnify, defend, and hold the Protected Persons harmless from claims arising from Customer systems, Customer instructions, Customer security configuration, Customer misuse, unlawful instructions, deficient notices or consents, or violation of third-party rights.
Stackie Ltd is not liable for indirect, incidental, special, consequential, exemplary, punitive, loss-of-profit, loss-of-revenue, loss-of-goodwill, business interruption, data loss, replacement service, procurement, or wasted expenditure damages to the fullest extent allowed by law.
Nothing in this Security/TOMs document limits liability where a limit is prohibited by law, including fraud, intentional misconduct, death or personal injury caused by negligence, non-waivable data-protection rights, non-waivable consumer statutory rights, unfair contract terms legislation, directors' personal wrongdoing, criminal liability, or regulatory exposure that cannot lawfully be limited.
Technical and Organizational Measures
Processor-Covered Categories of Personal Data
| Category | Processor Activity | Systems | Role Basis |
|---|---|---|---|
| organization user data | B2B customer workspace processing where Stackie processes organization user and workspace metadata for a business customer. | Stackie Cloud, hosted dashboard | Stackie acts as processor for the customer controller for this activity. |
| workspace metadata | B2B customer workspace processing where Stackie processes organization user and workspace metadata for a business customer. | Stackie Cloud, hosted dashboard | Stackie acts as processor for the customer controller for this activity. |
| service entitlement data | B2B customer workspace processing where Stackie processes organization user and workspace metadata for a business customer. | Stackie Cloud, hosted dashboard | Stackie acts as processor for the customer controller for this activity. |
Annex I Processing and Transfer Details
| Term | Value |
|---|---|
| Subject Matter | Processing Customer Personal Data received by or made accessible to Stackie Ltd to provide, secure, maintain, support, troubleshoot, improve, and administer covered Stackie Services. |
| Nature and Purpose | Hosting, authentication, account administration, package delivery, telemetry or diagnostics sent to Stackie Ltd, support, billing, security, legal acceptance, and customer instruction processing. |
| Duration | For the term of the applicable agreement and any lawful retention period needed for backups, security, dispute, audit, tax, or legal claim purposes. |
| Processing Instructions | Customer instructs Stackie Ltd through the applicable agreement, accepted configuration, account settings, support requests, and lawful written instructions. |
| Data Subjects | customer administrators, authorized users, individual developers, support contacts, billing contacts |
| Personal Data Categories | account data, authentication data, billing and subscription data, support and chat data, telemetry and diagnostics, legal acceptance evidence |
| Special Category Data | Stackie services are not intended for special category data unless Stackie Ltd expressly agrees in writing. |
| Special Category Safeguards | Special category data is prohibited unless expressly authorized in a signed agreement that identifies additional safeguards, restrictions, and lawful instructions. |
| Transfer Frequency | Continuous or on-demand for the term of the applicable agreement, depending on Customer configuration, user activity, support requests, telemetry settings, billing events, and service operation. |
| Transfer Description | Transfers occur when Customer or authorized users access Stackie Services, submit Customer Personal Data, trigger support, billing, telemetry, diagnostics, package delivery, authentication, or account workflows, or when approved subprocessors process Customer Personal Data for those workflows. |
| Processing Description | Processing Customer Personal Data for covered Stackie-hosted or Stackie-accessible flows, including account administration, authentication, package delivery, telemetry or diagnostics sent to Stackie Ltd, support, billing, security, legal acceptance, customer instructions, and local/cloud interoperability only when Stackie Ltd receives, accesses, or processes the data. |
| Deletion Procedure | Customer may delete Customer personal data using available service functionality; after DPA expiration Stackie Ltd will return or delete Customer personal data on Customer instruction unless legal, backup, security, dispute, audit, tax, or claim retention requires continued protection and restricted processing. |
EEA SCC and UK Addendum Variables
| Term | Value |
|---|---|
| Controller to Processor Module | EEA SCC Module Two applies where Customer is a controller and Stackie Ltd processes Customer personal data as processor. |
| Processor to Subprocessor Module | EEA SCC Module Three applies where Customer is a processor and Stackie Ltd processes Customer personal data as subprocessor. |
| Governing Member State | Ireland, unless the signed agreement names another EEA member state required by applicable law. |
| Competent Supervisory Authority | Irish Data Protection Commission, unless the signed agreement or non-waivable law names another competent supervisory authority. |
| Provider Security Contact | [email protected] |
| UK Addendum Details | UK Addendum Table 2 uses the same party, module, transfer, Annex I, Annex II, and Annex III information in this Cover Page and DPA annex; Table 4 is modified as stated in the unmodified DPA Standard Terms unless a signed agreement states otherwise. |
Transfer Mechanisms
| Recipient | Recipient Role | Regions | Primary Mechanism | Coverage | Safeguards | Notice Days |
|---|---|---|---|---|---|---|
| Paddle.com Market Limited - Merchant-of-record billing and tax services | independent controller | United Kingdom, European Union and EEA, United States | Data Privacy Framework or equivalent certified transfer basis | Data Privacy Framework or equivalent certified transfer basis, contractual transfer terms | recipient-specific written terms and transfer safeguards, contractual transfer terms, payment data minimization, recipient diligence and contractual safeguard review | 30 |
| Google LLC - Optional account sign-in provider | independent controller | United Kingdom, European Union and EEA, United States | Data Privacy Framework or equivalent certified transfer basis | Data Privacy Framework or equivalent certified transfer basis, contractual transfer terms | user opt-out where required, contractual transfer terms | 30 |
| Cloudflare, Inc. - Cloud application hosting and request handling | processor | United Kingdom, European Union and EEA, United States | EEA Standard Contractual Clauses | EEA Standard Contractual Clauses, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, Data Privacy Framework or equivalent certified transfer basis | contractual processor terms and transfer safeguards, EEA Standard Contractual Clauses, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, edge data minimization | 30 |
| Cloudflare, Inc. - Transactional email delivery | processor | United Kingdom, European Union and EEA, United States | EEA Standard Contractual Clauses | EEA Standard Contractual Clauses, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, Data Privacy Framework or equivalent certified transfer basis | contractual processor terms and transfer safeguards, EEA Standard Contractual Clauses, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, email data minimization | 30 |
| Cloudflare, Inc. - Package and encrypted infrastructure state storage | processor | United Kingdom, European Union and EEA, United States | EEA Standard Contractual Clauses | EEA Standard Contractual Clauses, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, Data Privacy Framework or equivalent certified transfer basis | contractual processor terms and transfer safeguards, EEA Standard Contractual Clauses, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, package artifact data minimization, infrastructure state data minimization, workspace-scoped least-privilege access | 30 |
| Neon, Inc. - Managed database hosting | processor | United Kingdom, European Union and EEA, United States | EEA Standard Contractual Clauses | EEA Standard Contractual Clauses, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, Data Privacy Framework or equivalent certified transfer basis | contractual processor terms and transfer safeguards, EEA Standard Contractual Clauses, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, database access minimization | 30 |
| Functional Software, Inc. d/b/a Sentry - Operational fault monitoring and private diagnostic release artifacts | processor | European Union and EEA, United States | EEA Standard Contractual Clauses | EEA Standard Contractual Clauses, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, Data Privacy Framework or equivalent certified transfer basis | contractual processor terms and transfer safeguards, EEA Standard Contractual Clauses, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, diagnostic data minimization and allowlisted collection, private JavaScript diagnostic artifacts are minimized and permanently deleted within thirty days, operational diagnostics and provider-derived metadata are enumerated in the private processing register, transfer impact assessment and safeguard review | 30 |
Provider Transfer Summary
| Provider Operation | Regions | Primary Mechanism | Coverage | Safeguards | Transfer Summary |
|---|---|---|---|---|---|
| Stackie Cloud first-party service | United Kingdom, European Union and EEA, United States | EEA Standard Contractual Clauses | EEA Standard Contractual Clauses, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, adequacy decision or equivalent lawful transfer basis | EEA Standard Contractual Clauses, adequacy decision or equivalent lawful transfer basis, UK Addendum to the EEA SCCs, UK International Data Transfer Agreement, transfer impact assessment and safeguard review | transfer safeguards maintained |
Technical and Organizational Measures
| Processing Type | Status | Safeguards | DPIA |
|---|---|---|---|
| session replay | disabled | mask passwords, secrets, and terminal content, support required privacy preference signals and regional consent rules for enabled surfaces where legally required, disable for minors, retention limited | required before activation |
| AI or model training on customer content | disabled | requires explicit consent and data protection impact assessment before activation, customer content excluded by default | required before activation |
| children or minors data | disabled | age-directed use prohibited, close accounts on knowledge of prohibited minors processing | required before activation |
| sensitive telemetry | disabled | requires express authorization and legal approval before activation, secrets and special-category data prohibited | required before activation |
| crash context diagnostics | enabled | only source-owned, enumerated technical-error fields are accepted, secrets, sensitive data, customer content, user identifiers, and arbitrary diagnostic context are prohibited, development reporting is restricted to staff use with internal or synthetic data, development events use exact destinations and the development environment without live fallback, active searchable technical-error events are available for up to 30 days, provider-side scrubbing and prevention of new-event IP address storage are required, user identity, session storage, replay, feedback, attachments, profiling, and AI analysis are disabled, reporting has an emergency kill switch and cannot fall back to live destinations, recorded impact screening covers the current minimized pre-production, UK/US public-live, and separately enabled UK/US CLI/daemon paths, released CLI and daemon reporting stays inert until a current report-once or automatic preference is recorded and stops after withdrawal, temporary specification branches have no standing reporting destination or shared reporting runtime | not required |
| bounded operational diagnostics | disabled | supplied fields and provider-derived metadata are exactly inventoried, only source-owned closed schemas survive final egress reconstruction, user, customer, account, device, and persistent session identifiers are excluded, customer content, free text, requests, responses, and automatic instrumentation are excluded, timing and metric data use coarse buckets, fixed dimensions, and bounded sampling, application release health is aggregate-only and contains no session identifier, live uptime uses credentialless bodyless probes and Workers use fixed check-ins, private JavaScript artifacts exclude source content, source paths, and native symbols, development, pre-production test, and live uploads use isolated credentials with a separate retention credential, diagnostic records and private release artifacts are limited to thirty days, availability is restricted to the United Kingdom and United States while EEA targeting, signup, acceptance, and availability remain blocked, public category wording is backed by exact private processing traceability, activation requires a fresh hash-bound owner approval | not required |
| customer chat | disabled | avoid secrets and sensitive data, support access controls, retention limited | not required |
| support desk processing | disabled | avoid secrets and sensitive data, support access controls, retention limited | not required |
| marketing analytics | disabled | support required privacy preference signals and marketing opt-outs for enabled surfaces where legally required, unsubscribe required, retention limited | not required |
Security Control Measures
| Control Category | Control Objective | Status | Public Measure |
|---|---|---|---|
| Access control | Limit access to production systems, customer data, billing records, legal acceptance evidence, and security logs to personnel or service providers with a documented business need. | Implemented | Stackie limits production and administrative access by business need and removes access when it is no longer required. |
| Authentication | Protect account authentication and session flows used for Stackie Cloud access and legal acceptance workflows. | Implemented | Stackie uses authentication and session controls for account access, security-sensitive workflows, and legal acceptance records. |
| Transport security | Protect customer-facing and provider-facing network traffic with transport security where Stackie controls the connection. | Implemented | Stackie uses transport security for customer-facing and provider-facing connections where Stackie controls the connection. |
| Data minimization | Minimize, redact, or exclude personal data and raw provider payload material that is not needed for declared service, billing, security, legal, or support purposes. | Implemented | Stackie limits retained data to what is needed for declared service, billing, security, legal, or support purposes and excludes unnecessary raw provider material. |
| Secure development | Use source review, schema validation, generated artifact freshness checks, and release gates to reduce security, privacy, and compliance drift before release. | Implemented | Stackie uses source review, automated checks, generated artifact validation, and release gates to reduce security and compliance drift. |
| Logging and monitoring | Record operational and security-relevant events needed to operate, troubleshoot, secure, and audit Stackie services without retaining unnecessary raw payload material. | Implemented | Stackie records operational and security-relevant events needed to operate, troubleshoot, secure, and audit the service while limiting unnecessary raw payload retention. |
| Incident response | Maintain a documented process for investigating suspected security incidents and notifying customers or authorities where legally required. | Implemented | Stackie investigates suspected security incidents and notifies affected customers or authorities where legally required. |
| Backup and retention | Apply documented retention, legal-hold, backup, deletion, and migration controls to personal-data and customer-data surfaces. | Implemented | Stackie applies documented retention, legal-hold, backup, deletion, and migration controls to relevant data surfaces. |
| Subprocessor governance | Maintain approved processor, subprocessor, third-party recipient, transfer, and vendor evidence records before production reliance. | Implemented | Stackie maintains processor, subprocessor, third-party recipient, transfer, and vendor evidence records for approved service providers. |
| Release governance | Block production legal reliance until required legal, security, privacy, processor, open-source notice, and release evidence is resolved or explicitly carried. | Implemented | Stackie uses release controls to keep legal, security, privacy, processor, open-source notice, and acceptance evidence current before release. |
Annex II Security Measures
| Term | Value |
|---|---|
| Security Policy | Stackie Security/TOMs document published at /legal/security-toms and DPA annex. |
| Security Control Source | Annex II Security Measures summarize 10 structured Stackie security-control categories maintained by Stackie. |
| Annex II Security Measures | The technical and organizational measures listed in the Security Control Measures table in this DPA annex, currently covering 10 source-owned control categories. |
| Audit Report Process | Security reports, due-diligence responses, and audit assistance are provided through Stackie support or legal contact under the DPA, subject to confidentiality, reasonable frequency limits, and protection of Stackie confidential information. |
Annex III Approved Subprocessors
| Term | Value |
|---|---|
| Subprocessor Authorization | General authorization applies only to approved subprocessors identified as processors, subprocessors, service providers, or contractors in Annex III and the Subprocessor List, with the notice periods recorded there; independent controllers and other third-party recipients are disclosed separately for transparency and are not approved subprocessors. |
| Annex III Approved Subprocessors | Approved subprocessors are only the recipients identified as processors, subprocessors, service providers, or contractors in Annex III and the Subprocessor List at /legal/subprocessors, including their processing tasks, regions, transfer mechanisms, and notice periods. Independent controllers and other third-party recipients are disclosed separately outside Annex III for transparency and are not approved subprocessors. |