Legal
Data Processing Agreement
Applies automatically to every customer. Scope, security measures, subprocessors, breach notification, deletion and international transfers.
Draft pending legal review. This document is written to be honest and readable, but it has not yet been reviewed by a lawyer. Questions in the meantime go to support@stacked.app.
Last updated
This Data Processing Agreement ("DPA") forms part of the Terms of Service and applies whenever Stacked processes personal data on your behalf as a processor under the UK GDPR, the EU GDPR, or comparable law.
It applies automatically. You do not need to sign anything or request a copy. If your organisation requires a signed counterpart, email support@stacked.app and you will get one within two business days.
1. Roles
You are the controller of the personal data you put into Stacked — your community members, subscribers, clients, guests, students and customers. Stacked is the processor of that data.
Stacked is a separate controller for your own account data: your email, your billing details, your usage of the product. That processing is covered by the Privacy Policy, not this DPA.
2. Scope of processing
Subject matter: provision of the Stacked service.
Duration: for as long as your account exists, plus the retention periods in section 8.
Nature and purpose: storing, organising, analysing, generating drafts from, and transmitting personal data so that the tools you enable can do what they say they do.
Categories of data subject (depending on which tools you enable): community members, email subscribers, coaching clients, course students, rental guests, customers, podcast guests, playlist curators, fans, and people who comment on or message your accounts.
Categories of personal data: identifiers and handles, email addresses, phone numbers where you provide them, message and comment content, engagement and activity metrics, purchase and subscription status, progress and attendance data, and any personal data contained in content you upload.
Special category data: not requested, not required, and you should not put it into the service. If it appears incidentally inside content you upload, it is processed under the same terms.
3. Our obligations
We will:
- Process personal data only on your documented instructions, which include your use of the product and its settings. If we are legally required to process otherwise, we will tell you first unless the law forbids it.
- Ensure everyone with access is bound by confidentiality.
- Implement the technical and organisational measures in section 5.
- Use subprocessors only as set out in section 6.
- Assist you with data subject requests, using the export and deletion tooling in the product, and directly where that is not enough.
- Assist you with data protection impact assessments and regulator consultations, so far as reasonable given the information available to us.
- Delete or return personal data at the end of the relationship, per section 8.
- Make available the information needed to demonstrate compliance, and allow audits per section 9.
4. Your obligations
You will:
- Have a lawful basis for the personal data you put into Stacked, and give the notices your own data subjects are owed.
- Configure the service appropriately — including which channels are ingested, which tools are enabled, and which are on autopilot.
- Not put special category data or payment card data into content fields.
- Respond to data subject requests directed to you; we will support you, but we do not have a relationship with your data subjects.
5. Security measures
- Encryption. TLS 1.2+ in transit. AES-256 at rest. Connected-account tokens encrypted with a separate key and never logged.
- Isolation. Row-level security enforced in the database so a workspace cannot read another's rows, independent of application logic.
- Access control. Least privilege, no shared accounts, MFA required on every administrative system. Production data access is logged and limited to support and incident response.
- Resilience. Daily encrypted backups with point-in-time recovery, retained 30 days. Restores are tested quarterly.
- Development. Code review on every change, automated dependency scanning, secrets held in a managed secret store.
- Vendor management. Every subprocessor is assessed before it processes data and is bound by equivalent terms.
We may update these measures, but not in a way that materially reduces overall security.
6. Subprocessors
You give general authorisation for the subprocessors listed at /subprocessors. Each is engaged under a written agreement imposing obligations no less protective than this DPA, and we remain liable for their performance.
We will give at least 30 days' notice before a new subprocessor starts processing, by email to workspace owners and by updating that page. If you reasonably object on data protection grounds within that window, we will work with you to find an alternative; if there is not one, you may cancel and receive a prorated refund of the unused period.
7. AI model providers
Model providers are subprocessors and are listed as such. Content sent to them is:
- Processed only to produce output for you;
- Not used to train the provider's models, under the terms we hold with each;
- Not retained beyond the short abuse-monitoring window the provider's terms require.
8. Deletion and return
- Deleting an object in the app deletes it from primary storage immediately and from backups as those backups age out, within 30 days.
- On cancellation, data remains recoverable for 90 days, then is deleted.
- Requesting account deletion starts the purge immediately, completing within 30 days.
- Export is available at any time from Settings → Data, as JSON plus original files.
- We retain what law requires us to retain, principally invoices, and nothing else.
9. Audits
On reasonable notice, no more than once a year unless a regulator or a breach requires otherwise, we will provide the information reasonably needed to verify compliance with this DPA. Where documentation is not sufficient, we will cooperate with an audit at your cost, scoped to avoid disclosing other customers' data.
10. Personal data breach
We will notify you without undue delay and in any case within 72 hours of becoming aware of a personal data breach affecting your data, with what we know at that point: nature, categories and approximate volumes, likely consequences, and the measures taken. Updates follow as the picture develops. We will not delay telling you in order to have a complete answer.
11. International transfers
Primary hosting is in the EU. Where a subprocessor processes data outside the UK or EEA, transfers rely on the UK International Data Transfer Addendum, the EU Standard Contractual Clauses, or an adequacy decision, as noted on the subprocessors page. We carry out transfer risk assessments and apply supplementary measures where needed.
12. Liability and precedence
Liability under this DPA is subject to the limitations in the Terms of Service. Where this DPA conflicts with the Terms of Service on the processing of personal data, this DPA wins.
13. Contact
Data protection queries: support@stacked.app, subject line "DPA".