Contents
- 1Definitions
- 2Roles and Scope
- 3Processing Instructions
- 4Special Categories of Personal Data
- 5Confidentiality and Personnel
- 6Security of Processing
- 7Privacy Contact
- 8Subprocessors
- 9International Data Transfers
- 10Data Subject Rights
- 11Personal Data Breach Notification
- 12Data Protection Impact Assessments and Prior Consultation
- 13Audits and Information Rights
- 14AI Model Training
- 15Return and Deletion of Client Personal Data
- 16Exclusions from Scope
- 16AUS State Privacy Laws
- 17AI Act Compliance
- 18Liability
- 19Term and Termination
- 20Amendments to this DPA
- 21Precedence
- 22Miscellaneous
- Annex I - Description of the Processing
- Annex II - Technical and Organizational Measures
- Annex III - Authorized Subprocessors
- Annex IV - Jurisdiction-Specific Terms
This Data Processing Agreement (the "DPA") forms part of the Master SaaS Agreement (the "Main Agreement") and the applicable Order Form entered into between:
STACKBOOSTER CORPORATION, a corporation organized and existing under the laws of the State of Delaware, United States of America, with its registered address at 8 The Green #12146, Dover, DE 19901, United States of America ("StackBooster", "we", "us");
and
the entity identified as the "Client" in the Main Agreement or the Order Form (the "Client", "you");
each a "Party" and together the "Parties", and is incorporated into the Main Agreement by reference.
This DPA governs the Processing of Personal Data by StackBooster on behalf of the Client in connection with the provision of the Services under the Main Agreement and the applicable Order Form. Its purpose is to ensure compliance with the Applicable Data Protection Laws, with the EU GDPR and UK GDPR machinery set out in this DPA applied as the universal contractual baseline of protection for all Clients, regardless of the Client's jurisdiction.
1Definitions
Capitalized terms used in this DPA have the meanings set out below. Terms not defined in this DPA have the meanings given to them in the Main Agreement, the Order Form or the Applicable Data Protection Laws.
"Agent Action", "AI Agent", "Approval Controls", "Client Cloud Environment", "Hosted Application", "Outputs" and "Third-Party Platforms" have the meanings given to them in the Main Agreement.
"Applicable Data Protection Laws" means all data protection and privacy laws applicable to the Processing of Client Personal Data under this DPA, including: (a) the EU GDPR; (b) the UK GDPR and the UK Data Protection Act 2018; (c) the Swiss Federal Act on Data Protection (the "FADP"); (d) US State Privacy Laws; and (e) where applicable to the Client or the relevant Data Subjects, the data protection laws of the Client's jurisdiction.
"Client Personal Data" means Personal Data Processed by StackBooster on behalf of the Client under the Main Agreement or the Order Form, excluding data processed by StackBooster as an independent controller in accordance with Section 16 (Exclusions from Scope).
"Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing" and "Special Categories of Personal Data" have the meanings given to them in the Applicable Data Protection Laws; with respect to jurisdictions whose data protection laws use different terminology, these terms include the corresponding concepts under such laws (including "business", "service provider", "contractor", "personal information" and "sensitive personal information" under US State Privacy Laws).
"End User" means a natural person who interacts with an AI Agent, a Hosted Application or any communication sent through the Services on the Client's behalf.
"EU GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council.
"EU SCCs" means the standard contractual clauses approved by the European Commission pursuant to Implementing Decision (EU) 2021/914 of 4 June 2021, together with any subsequent replacing or amending decisions.
"High-Risk AI Use Case" has the meaning given to it in the Main Agreement.
"Instructions" means the documented instructions issued by the Client to StackBooster regarding the Processing of Client Personal Data, including the Main Agreement, this DPA, the Order Form, the Client's configuration of the Services (including Approval Controls, connected accounts and AI Agent tasks), requests and approvals made by Authorized Users through the Platform, and any subsequent instructions issued by the Client in writing (email being sufficient) in a manner reasonable within the scope of the Services.
"Lead Data" means Personal Data relating to leads, prospects, recipients, customers or potential customers, imported, transmitted, uploaded, synchronized, collected or otherwise made available by or on behalf of the Client for use in connection with the Services, including for inbound or outbound communication.
"Order Form" has the meaning given to it in the Main Agreement.
"Outbound Communication" means any marketing, sales, commercial, email, SMS, messaging, social media publishing, advertising or other outbound communication initiated, automated, assisted or supported through the Services.
"Platform" means the StackBooster technology platform, including the App, used to provide the Services.
"Security Annex" means the StackBooster Security Annex - an internal document describing in detail the technical and organizational measures implemented by StackBooster, made available to the Client upon request subject to appropriate confidentiality obligations.
"Services" means the services provided by StackBooster to the Client under the Main Agreement and the applicable Order Form.
"Subprocessor" means any third party or affiliate engaged by StackBooster to Process Client Personal Data on the Client's behalf.
"Subprocessor List" means the list of authorized Subprocessors published and maintained by StackBooster at https://stackbooster.io/legal/subprocessors.
"Suppression Data" means opt-out records, unsubscribe records, objection records, exclusion lists, communication preferences, do-not-contact designations and similar data used to prevent or limit communication with Data Subjects.
"UK Addendum" means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner's Office (version B1.0) under section 119A of the Data Protection Act 2018.
"US State Privacy Laws" has the meaning given to it in the Main Agreement.
2Roles and Scope
2.1Roles of the Parties
The Parties acknowledge and agree that, with respect to the Processing of Client Personal Data under this DPA, the Client acts as Controller and StackBooster (StackBooster Corporation) acts as Processor established in a third country (the United States of America) within the meaning of Chapter V of the EU GDPR. Where the Client itself acts as a processor on behalf of a third-party controller, StackBooster is deemed a sub-processor, and the obligations set out in this DPA apply accordingly.
2.2Scope of this DPA
This DPA applies solely to the Processing of Client Personal Data carried out by StackBooster on the Client's behalf in connection with the Services, including Personal Data processed by AI Agents, stored in Hosted Applications operated on StackBooster infrastructure, or accessed in Client Cloud Environments and connected accounts. It does not apply to the categories of Processing activities described in Section 16 (Exclusions from Scope), with respect to which StackBooster acts as an independent controller in accordance with its own privacy notice.
2.3Description of the Processing
The subject matter, nature, purpose, duration, categories of Data Subjects and categories of Personal Data processed under this DPA are set out in Annex I.
2.4Joint controllership on Third-Party Platforms
The Client acknowledges that certain integrations with Third-Party Platforms (including social media pages and advertising accounts operated by Meta, LinkedIn and other providers) may give rise to joint controllership arrangements between the Client and such third parties under Article 26 EU GDPR, in accordance with the platform terms of the relevant provider. StackBooster is not a party to such joint controllership arrangements.
2.5Client acting as processor
Where the Client acts as a processor on behalf of a third-party controller (for example, where an agency uses the Services for its own customers), the Client represents that it is authorized to appoint StackBooster as a sub-processor and to issue the Instructions set out in this DPA.
2.6Universal protection baseline
The protections, technical and organizational measures, cooperation machinery, transfer safeguards, subprocessor regime, breach notification obligations and AI-training safeguards set out in this DPA - designed to the standard of the EU GDPR and the UK GDPR - are applied by StackBooster as the universal contractual baseline to the Client Personal Data of all Clients, regardless of whether the EU GDPR or the UK GDPR applies to the Client as a matter of law. Jurisdiction-specific supplements are set out in Section 16A and Annex IV.
3Processing Instructions
3.1Lawfulness and Instructions
StackBooster Processes Client Personal Data only on the Client's documented Instructions, including with regard to any transfer of Client Personal Data to a third country or an international organization, unless required to do so by applicable law to which StackBooster is subject. In such a case, StackBooster will inform the Client of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.
3.2Agent Actions as Instructions
The Client acknowledges that AI Agents act within the tasks, permissions, connected accounts and Approval Controls configured by or for the Client. Agent Actions that are requested or approved by an Authorized User, or that fall within the autonomy and limits configured in the Approval Controls, constitute the Client's documented Instructions for the purposes of this DPA.
3.3Unlawful Instructions
StackBooster will promptly inform the Client if, in its opinion, an Instruction infringes the Applicable Data Protection Laws. StackBooster is entitled to suspend performance of the relevant Instruction until it is confirmed or modified by the Client.
3.4Controller Obligations
The Client represents and warrants that: (a) it has a valid legal basis under Article 6 EU GDPR and, where applicable, Article 9 EU GDPR - or the equivalent provisions of the Applicable Data Protection Laws of the Client's jurisdiction - for the Processing of Client Personal Data by StackBooster; (b) it has provided all required information notices and obtained all consents required under the Applicable Data Protection Laws, including privacy notices and cookie consent mechanisms for its Hosted Applications; and (c) its Instructions to StackBooster comply with the Applicable Data Protection Laws.
Where Client Personal Data includes Lead Data, contact lists, recipient data, phone numbers, email addresses, social media identifiers, Suppression Data or other data used for Outbound Communication, the Client represents and warrants that such data has been collected, sourced, imported, transmitted and used lawfully and that the Client has obtained and will maintain all legal bases, information notices, consents, permissions, opt-in records, opt-out records, exclusion lists and other records required for the relevant Processing activity, communication channel and jurisdiction.
3.5Prohibited Processing purposes
StackBooster will not Process Client Personal Data for its own marketing purposes, for the sale or sharing of data, for unrelated product analytics, for profiling independent of the Services, for training or fine-tuning AI models, or for any purpose independent of the documented Instructions applicable to the Services, subject to the activities described in Section 16 (Exclusions from Scope), with respect to which StackBooster acts as an independent controller.
4Special Categories of Personal Data
The Services are not specifically designed for the Processing of Special Categories of Personal Data within the meaning of Article 9 EU GDPR or of equivalent sensitive-data categories under other Applicable Data Protection Laws. The Client shall not submit such data to the Platform, or configure AI Agents or Hosted Applications to collect such data, unless all of the following conditions are met:
- the Client has a valid legal basis under Article 9(2) EU GDPR and, where applicable, the equivalent provisions of the UK GDPR, of national law or of the Applicable Data Protection Laws of the Client's jurisdiction;
- the Client has informed the relevant Data Subjects and obtained all consents required under the Applicable Data Protection Laws;
- the scope of the Services agreed in the Order Form or in a separate written arrangement expressly covers such Processing, to the extent the relevant functionality is offered by StackBooster; and
- the Parties have entered into any additional provisions, addenda or technical and organizational measures reasonably required by StackBooster in connection with the processing of such data.
The Client shall not use the Services to infer, target, segment or conduct Outbound Communication on the basis of Special Categories of Personal Data unless the conditions of this Section 4 are met and the Parties have agreed additional provisions. Hosted Applications operated on StackBooster infrastructure are not designed for the storage of protected health information within the meaning of HIPAA or payment card data within the scope of PCI DSS, and the Client shall not use them for such purposes.
5Confidentiality and Personnel
StackBooster will ensure that its personnel and any other persons authorized to Process Client Personal Data:
- Process Client Personal Data only on the Client's Instructions and only to the extent necessary (need-to-know);
- have committed themselves to confidentiality, by contract or statutory obligation, surviving the end of their engagement with StackBooster;
- have received appropriate training on their Personal Data protection obligations; and
- are subject to user access management practices limiting access to Client Personal Data to the extent strictly necessary for the performance of their duties.
6Security of Processing
6.1Technical and organizational measures
StackBooster will implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk of the Processing, in accordance with Article 32 EU GDPR and the equivalent provisions of the UK GDPR. A summary of such measures is set out in Annex II. A more detailed description is contained in the Security Annex, made available to the Client upon request subject to appropriate confidentiality obligations.
6.2Updates to security measures
StackBooster may update the technical and organizational measures from time to time, provided that such updates do not materially reduce the overall level of protection of Client Personal Data.
6.3Client-side security
The Client is responsible for the security of its own accounts, credentials, Client Cloud Environments and connected accounts, for granting permissions to the Services on a least-privilege basis, and for the security configuration of Hosted Applications to the extent such configuration is under the Client's control.
6.4Diagnostic and monitoring tools
Where session replay, error monitoring or diagnostic tools are used in connection with the Services, StackBooster will configure masking, scrubbing or equivalent controls for sensitive form fields and user-entered content, to the extent technically supported by the relevant tool.
7Privacy Contact
StackBooster has designated a privacy point of contact for matters concerning the Processing of Personal Data under this DPA, reachable at privacy@stackbooster.io. StackBooster has not appointed a Data Protection Officer, as it is not required to do so under Article 37 EU GDPR; should StackBooster appoint one, it will publish the contact details in this DPA and in the Privacy Policy.
8Subprocessors
8.1General authorization
The Client grants StackBooster a general written authorization to engage Subprocessors in connection with the provision of the Services. The current list of authorized Subprocessors is set out in the Subprocessor List published at https://stackbooster.io/legal/subprocessors.
8.2Obligations imposed on Subprocessors
StackBooster will enter into a written contract, including in electronic form (Article 28(9) EU GDPR), with each Subprocessor, containing data protection obligations substantially equivalent to those set out in this DPA. Where a Subprocessor is located outside the European Economic Area or the United Kingdom, StackBooster will ensure that an appropriate transfer mechanism under Chapter V of the EU GDPR or the UK GDPR is implemented, including, as applicable, the EU SCCs, the UK Addendum, the EU-U.S. Data Privacy Framework (where the Subprocessor is certified) or a relevant adequacy decision.
8.3Notice of changes
StackBooster will give the Client written notice at least thirty (30) days in advance of any intended change consisting of the addition or replacement of a Subprocessor. Such notice will be given by sending an email to the Client's privacy or administrative contact, or by a notice in the App, and by updating the Subprocessor List. Where a replacement is urgently required for reasons of security or service continuity, StackBooster may give shorter notice and will inform the Client as soon as reasonably practicable.
8.4Right to object
The Client may object to a proposed change within thirty (30) days of receiving the notice, on reasonable grounds relating to data protection. The Parties will use good-faith efforts to reach a mutually acceptable solution within thirty (30) days of the Client's objection. If no solution is reached, the Client may terminate the affected Services with a pro rata refund of prepaid and unused fees attributable to them.
8.5Liability for Subprocessors
StackBooster remains liable to the Client for the acts and omissions of its Subprocessors to the same extent as if such acts or omissions had been performed by StackBooster itself, subject to the limitations of liability set out in the Main Agreement.
8.6Client-controlled platforms
Third-Party Platforms whose accounts are owned and controlled by the Client and which the Client connects to the Services (for example, its own cloud accounts, code repositories, CRM, email, social media and advertising accounts) are not Subprocessors of StackBooster. The provider of such a platform acts as the Client's processor or as an independent controller under the Client's own agreement with that provider, and StackBooster accesses such platform solely within the permissions granted by the Client.
9International Data Transfers
9.1Primary Processing location
The primary Processing of Client Personal Data within the Platform takes place on the cloud infrastructure of the hosting providers identified in the Subprocessor List. Information on the hosting region applicable to the Client's deployment is available upon request. Hosted Applications and AI Agent workloads that the Client elects to run in a Client Cloud Environment are processed in the region selected by the Client. Certain Subprocessors, including AI model providers, may process Client Personal Data in other locations, as indicated in the Subprocessor List. Any transfers of Client Personal Data outside the European Economic Area or the United Kingdom are carried out on the basis of a valid transfer mechanism under Chapter V of the EU GDPR or the UK GDPR.
9.2Transfers to StackBooster
To the extent Client Personal Data is transferred to StackBooster in the United States, or is accessed by StackBooster personnel and contractors located outside the European Economic Area and the United Kingdom for the purposes of operating, supporting and securing the Services, such transfer is safeguarded by the EU SCCs, in particular Module Two (Controller-to-Processor), entered into between the Client as data exporter (controller) and StackBooster as data importer (processor), and, where the Client acts as a processor in accordance with Section 2.1, Module Three (Processor-to-Processor). With respect to Client Personal Data subject to the UK GDPR, the transfer is additionally safeguarded by the UK Addendum, entered into between the Client as exporter and StackBooster as importer.
9.3EU Standard Contractual Clauses
Where StackBooster or its Subprocessor Processes Client Personal Data subject to the EU GDPR outside the European Economic Area in circumstances requiring a transfer mechanism under Chapter V of the EU GDPR, the EU SCCs are incorporated into this DPA by reference and deemed entered into between the relevant parties to the transfer. For the purposes of Clause 7, the docking clause does not apply. For the purposes of Clause 9, Option 2 (general written authorization) applies, with the notice period set out in Section 8.3. For the purposes of Clause 11, the optional language does not apply. For the purposes of Clause 17, the Parties select Option 1 and the law of Ireland as the governing law. For the purposes of Clause 18(b), the Parties select the courts of Ireland. Annex I and Annex II to this DPA serve as Annex I and Annex II to the EU SCCs, respectively. Annex III to the EU SCCs is completed by reference to the Subprocessor List.
For the avoidance of doubt, the selection of Irish law and Irish courts in this Section 9.3 operates solely within and for the purposes of the EU SCCs, as required by Clauses 17 and 18 of the EU SCCs, and does not affect the governing law and dispute resolution provisions of the Main Agreement.
9.4UK International Data Transfer Addendum
Where StackBooster or its Subprocessor Processes Client Personal Data subject to the UK GDPR outside the United Kingdom in circumstances requiring a transfer mechanism under Chapter V of the UK GDPR, the UK Addendum is incorporated into this DPA by reference and applies as a supplement to the EU SCCs, whereby for transfers between the Client and StackBooster the Client is the exporter and StackBooster is the importer. The tables of the UK Addendum are deemed completed with the information contained in Annex I and Annex II to this DPA and in the EU SCCs incorporated under Section 9.3; for Table 4, either Party may end the UK Addendum as set out in its Section 19.
9.5Transfer impact assessment
Where Client Personal Data is transferred to a country not covered by an adequacy decision, StackBooster has carried out or will carry out a transfer impact assessment, taking into account the law and practice of the destination country and identifying appropriate supplementary technical, contractual and organizational measures where necessary. A summary of the transfer impact assessment is made available to the Client upon reasonable request, subject to appropriate confidentiality obligations.
9.6Conflict
In the event of any conflict or inconsistency between this DPA and the EU SCCs or the UK Addendum with respect to a given transfer of Client Personal Data, the provisions of the EU SCCs or the UK Addendum prevail.
9.7Subprocessor locations and transfer mechanism
The Subprocessor List indicates, where available, the location of and the transfer mechanism applicable to each Subprocessor.
10Data Subject Rights
10.1Assistance to the Client
Taking into account the nature of the Processing, StackBooster will assist the Client by appropriate technical and organizational measures, insofar as this is possible, in the fulfillment of the Client's obligation to respond to requests from Data Subjects exercising their rights under Chapter III of the EU GDPR or Chapter III of the UK GDPR, or the corresponding data subject or consumer rights provisions of other Applicable Data Protection Laws.
10.2Requests received from Data Subjects
If StackBooster receives a request from a Data Subject concerning Client Personal Data, it will not respond to it directly, other than to acknowledge receipt or redirect the Data Subject to the Client, and will forward such request to the Client without undue delay.
10.3Response time
StackBooster will respond to the Client's request for assistance in connection with a Data Subject request within fourteen (14) days of receiving the Client's request.
10.4Costs
Assistance with Data Subject requests is provided at no additional cost to the Client and is covered by the fees due under the Main Agreement, provided that the volume and frequency of such requests are reasonable.
11Personal Data Breach Notification
11.1Notification deadline
StackBooster will notify the Client without undue delay, and in any event within forty-eight (48) hours, of becoming aware of a Personal Data Breach affecting Client Personal Data.
11.2Content of the notification
The notification will include, to the extent reasonably available at the time of notification: (a) a description of the nature of the Personal Data Breach, including, where possible, the categories and approximate number of Data Subjects and records concerned; (b) the contact details of StackBooster's privacy contact point at privacy@stackbooster.io or another designated contact point; (c) a description of the likely consequences of the Breach; and (d) a description of the measures taken or proposed to be taken by StackBooster, including measures to mitigate its possible adverse effects.
11.3Further cooperation
StackBooster will cooperate in good faith with the Client in connection with the Client's own obligations to notify competent supervisory authorities and, where applicable, Data Subjects, including under US state data breach notification laws and other Applicable Data Protection Laws of the Client's jurisdiction.
11.4No admission of liability
Notification of a Personal Data Breach by StackBooster does not constitute an admission by StackBooster of any fault or liability.
12Data Protection Impact Assessments and Prior Consultation
Taking into account the nature of the Processing and the information available to it, StackBooster will provide the Client with reasonable assistance in carrying out data protection impact assessments in accordance with Article 35 EU GDPR and in consultations with supervisory authorities in accordance with Article 36 EU GDPR - or the corresponding provisions of other Applicable Data Protection Laws - where the Client reasonably considers that such assessments or consultations are required.
Where the Client uses the Services for Outbound Communication, large-scale lead activation, audience targeting, profiling or similar processing, the Client remains responsible for determining whether a data protection impact assessment, a legitimate interest assessment, an ePrivacy assessment or an equivalent assessment is required for its specific use case.
13Audits and Information Rights
13.1Information rights
StackBooster will make available to the Client all information necessary to demonstrate compliance with the obligations set out in this DPA and in the Applicable Data Protection Laws, including responses to reasonable written security and privacy questionnaires, relevant external audit reports, certificates and attestations where available, subject to appropriate confidentiality obligations.
13.2On-site audits
Where the information made available under Section 13.1 is not sufficient to demonstrate compliance, the Client or an independent auditor appointed by the Client may carry out an audit of the processing activities carried out by StackBooster under this DPA, no more than once per calendar year (unless required by a supervisory authority or following a Personal Data Breach), upon at least thirty (30) days' prior written notice, during normal business hours, without unreasonable disruption to StackBooster's operations, at the Client's expense and subject to appropriate confidentiality obligations. Audits may be conducted remotely where reasonably practicable.
13.3Audit reports
The Client will promptly provide StackBooster with a copy of the audit report and will treat the report and any information obtained in the course of the audit as StackBooster's confidential information.
14AI Model Training
14.1No use of Client Personal Data for training
StackBooster does not use Client Personal Data, Client Data or Outputs to train, fine-tune or otherwise improve AI models, whether its own or those of third parties, unless the Client has expressly opted in through the Order Form or another written instruction specifying the scope of such use.
14.2Foundation models
StackBooster uses third-party foundation models through commercial API or enterprise cloud services on contractual terms under which the relevant provider does not use customer data submitted through those services to train, fine-tune or improve its models. Client Personal Data submitted to such providers is processed solely to generate responses for the Client and is retained by the provider only as necessary for the provision of the service, abuse monitoring and legal compliance, in accordance with the provider's terms and the Subprocessor List.
14.3Client-specific memory
Client-specific memory, knowledge bases, embeddings and context maintained by the Platform for the Client's AI Agents constitute Client Data, are logically separated per Client, are used solely to provide the Services to that Client and are subject to Section 15.
14.4Service analytics
StackBooster may generate aggregated or de-identified usage statistics and performance metrics (for example, counts of tasks, error rates, latency and resource consumption) that do not identify the Client, its Authorized Users or any natural person, and may use them to operate, secure, maintain and improve the Services. Such data does not constitute Client Personal Data.
15Return and Deletion of Client Personal Data
15.1Retention during the term
StackBooster will retain Client Personal Data for the duration of the subscription under the Main Agreement or until earlier deletion on the Client's Instruction. The Client may delete Client Data, AI Agent memory, Hosted Applications and connected accounts through the App at any time, to the extent such functionality is available, or by written request.
15.2Return or deletion upon termination
Upon termination or expiration of the Main Agreement, StackBooster will - at the Client's election made within thirty (30) days of the effective date of termination - return (in accordance with Section 17.2 of the Main Agreement) or delete all Client Personal Data in its possession, and will delete such data from active systems within thirty (30) days after the end of that period and from backup systems within a further ninety (90) days, unless applicable law requires further retention. If the Client makes no election, StackBooster will delete the Client Personal Data within the same periods.
15.3Confirmation
Upon the Client's written request, StackBooster will provide written confirmation of the performance of the obligations set out in this Section 15.
16Exclusions from Scope
This DPA does not govern the following Processing activities, with respect to which StackBooster acts as an independent controller in accordance with its Privacy Policy:
- Processing of account, billing, payment and administrative data of the Client and its Authorized Users for the purposes of account management, contract performance, invoicing and compliance with financial and tax obligations;
- Processing of support communications initiated by the Client or its Authorized Users for the purposes of providing support, troubleshooting and service quality improvement;
- Processing of security telemetry, access logs, audit logs and related operational data for the purposes of protecting the security, integrity and availability of the Services, preventing and detecting abuse and fraud, and complying with StackBooster's legal and regulatory obligations; and
- Processing of aggregated, de-identified or technical product analytics for the purposes of operating, maintaining and improving the Services.
To the extent such Processing involves Personal Data, StackBooster Processes such data in accordance with the Applicable Data Protection Laws and on the basis of an appropriate legal basis under Article 6 EU GDPR or the equivalent provisions of other Applicable Data Protection Laws.
16AUS State Privacy Laws
To the extent Client Personal Data is subject to US State Privacy Laws, StackBooster acts as the Client's "service provider", "contractor" or "processor" (as applicable), and StackBooster:
- will not sell or share (as those terms are defined under US State Privacy Laws) Client Personal Data;
- will not retain, use or disclose Client Personal Data for any purpose (including any commercial purpose) other than the business purposes specified in the Main Agreement and this DPA, or outside the direct business relationship between StackBooster and the Client, except as permitted by US State Privacy Laws;
- will not combine Client Personal Data with personal information it receives from or on behalf of another person or collects from its own interactions with consumers, except as permitted by US State Privacy Laws;
- will comply with the obligations applicable to it under US State Privacy Laws and provide the same level of privacy protection as is required by such laws;
- will notify the Client if it determines that it can no longer meet its obligations under US State Privacy Laws; and
- grants the Client the right, upon notice, to take reasonable and appropriate steps to stop and remediate unauthorized use of Client Personal Data.
StackBooster certifies that it understands and will comply with the restrictions set out in this Section 16A. The business purposes for which Client Personal Data is processed are those described in Annex I.
17AI Act Compliance
17.1Scope of AI Act references
References to Regulation (EU) 2024/1689 (the "EU AI Act") in this DPA apply only to the extent the relevant use, deployment, output, placing on the market or legal obligation falls within the territorial or extraterritorial scope of the EU AI Act.
17.2Provider and deployer roles
To the extent the EU AI Act applies, StackBooster acts as the "provider" of the AI system vis-a-vis the Client, and the Client acts as the "deployer" of the AI system within the meaning of the EU AI Act. The Services are classified in their default configuration as a limited-risk AI system under the EU AI Act.
17.3AI transparency and disclosure
Where an AI Agent interacts directly with End Users in a conversational channel, the Services provide an AI-interaction disclosure to the extent required by law. The Client may not disable or weaken it to the extent the disclosure is required by law, platform rules or the contractual documents. The Client is responsible for its own context of use, its own deployer obligations, the labeling of AI-generated content it publishes where required by law or platform rules, and for ensuring that End Users receive the legally required information notices and disclosures, unless the Parties expressly agree otherwise in the Order Form.
17.4High-Risk AI Use Cases
The Client shall not use the Services for any High-Risk AI Use Case, except in accordance with the Main Agreement and an Enterprise High-Risk AI Addendum entered into by the Parties.
18Liability
18.1Limitation of liability
Each Party's liability arising out of or relating to this DPA, of any kind, whether in contract, tort or otherwise, is subject to the aggregate limitations of liability set out in the Main Agreement, except to the extent such limitation is prohibited by the EU SCCs or Applicable Data Protection Laws with respect to the rights of Data Subjects.
18.2Administrative fines
Administrative fines imposed on a Party by a competent supervisory authority under the Applicable Data Protection Laws are borne by the Party on which they are imposed, except to the extent the other Party caused or materially contributed to the circumstances giving rise to the fine.
19Term and Termination
This DPA takes effect on the effective date of the Main Agreement or the applicable Order Form and remains in force for the term of the Main Agreement and for such further period during which StackBooster Processes Client Personal Data after termination, including the retention periods set out in Section 15.
20Amendments to this DPA
StackBooster may update this DPA from time to time, provided that non-material amendments may be made by publication of an updated version, and material amendments take effect no earlier than thirty (30) days after StackBooster gives notice to the Client. Amendments required to comply with Applicable Data Protection Laws or a decision of a competent authority may take effect earlier where so required. All versions of this DPA are maintained in a version control system, and previous versions remain available to the Client upon request.
21Precedence
In the event of any conflict or inconsistency: (a) between this DPA and the Main Agreement - this DPA prevails in matters concerning privacy, data protection and the Processing of Personal Data; (b) between this DPA and the EU SCCs or the UK Addendum with respect to a transfer governed by those instruments - the EU SCCs or the UK Addendum prevail; (c) between this DPA and any other document incorporated by reference - this DPA prevails, unless expressly provided otherwise.
22Miscellaneous
22.1Governing law
This DPA is governed by and construed in accordance with the law governing the Main Agreement or the applicable Order Form. Notwithstanding the foregoing, the mandatory provisions of the Applicable Data Protection Laws of the Client's jurisdiction apply where required, and the governing law and jurisdiction of the EU SCCs and the UK Addendum are as set out in those instruments and in Section 9 of this DPA.
22.2Severability
If any provision of this DPA is held invalid, unlawful or unenforceable, the remaining provisions remain in full force and effect.
22.3Notices
Notices under this DPA are given in accordance with the notice provisions of the Main Agreement. In matters concerning data protection, notices to StackBooster are sent to privacy@stackbooster.io, with a copy to legal@stackbooster.io.
22.4Electronic acceptance
The Client accepts this DPA by entering into the Main Agreement or the Order Form into which this DPA is incorporated by reference. A signed counterpart of this DPA may be executed by the Parties upon the Client's request.
Annex I - Description of the Processing
AList of Parties
Data Exporter / Controller: the Client, as identified in the Main Agreement or the Order Form. Activities relevant to the transfer: use of the Services.
Data Importer / Processor: StackBooster Corporation, 8 The Green #12146, Dover, DE 19901, United States of America. Activities relevant to the transfer: provision of the Services.
Contact point for data protection matters: privacy@stackbooster.io.
BDescription of the transfer / Processing
Categories of Data Subjects:
- Employees, contractors and other authorized personnel of the Client who access the Services through an App account.
- Customers, prospects, leads and other End Users interacting with the Client's AI Agents, Hosted Applications or communications.
- Visitors and users of the Client's websites and applications built or hosted through the Services.
- Contacts, correspondents and other persons identified in Client Cloud Environments, code repositories and systems integrated with the Services in accordance with the Client's configuration.
- Recipients of Outbound Communication and audiences of the Client's published content and advertising, including leads, prospects, customers, business contacts and other persons whose contact details or identifiers are submitted by or on behalf of the Client to the Services.
- Persons whose publicly available information is collected by AI Agents for research tasks at the Client's instruction.
Categories of Personal Data:
- Identification and contact data, including name, job title, company, email address, phone number, postal address and similar identifiers.
- Communication content, including messages, emails, comments, chat conversations with AI Agents and conversation history.
- Authentication and account data, including hashed credentials, session identifiers and account configuration data.
- Technical data, including IP address, user agent, device information and log data generated as a result of the use of the Services and Hosted Applications.
- Data submitted by End Users through Hosted Applications, including form submissions and data stored in databases created for the Client.
- Content, files, documents, source code, repositories, infrastructure configuration and telemetry provided by or for the Client, to the extent they contain Personal Data.
- Client-specific memory, knowledge base content and embeddings, to the extent they contain Personal Data.
- Data from systems integrated with the Services, for example CRM records, email content, calendar events, social media account data, comments and direct messages, and advertising account data, in accordance with the Client's configuration.
- Lead Data, prospect data, recipient data, contact list data, social media identifiers, messaging identifiers, communication preferences, consent metadata, opt-in records, opt-out records, exclusion lists, do-not-contact designations and Campaign metadata.
- Images, video and audio provided by the Client or generated for the Client, to the extent they depict or identify natural persons.
Special Categories of Personal Data: Not normally processed. Where the Client submits Special Categories of Personal Data, the conditions of Section 4 of this DPA apply.
Frequency of the Processing: Continuous for the term of the Main Agreement or the Order Form.
Nature and purpose of the Processing:
- Provision of the Platform and AI Agents performing tasks for the Client, including research, planning, content and code generation, software development, design and reporting.
- Building, deploying, hosting and operating Hosted Applications, websites and databases for the Client.
- Management, monitoring, optimization and automation of Client Cloud Environments and infrastructure.
- Retrieval-augmented generation and memory processing of Client-provided content for the purposes of AI Agent responses and tasks.
- Integration with the Client's communication, productivity, social media, advertising, CRM, code hosting and cloud systems in accordance with the Client's configuration.
- Processing of Lead Data and recipient data to enable the Client to conduct, manage, automate, monitor and analyze inbound and outbound communication, publishing and advertising through the Services.
- Operational support, Professional Services and other purposes reasonable and necessary to deliver the Services.
- Platform maintenance, logging, backups, ensuring availability, reliability and business continuity, security, monitoring, technical support, incident response and cloud and infrastructure operations.
Duration of the Processing: For the term of the Main Agreement or the Order Form and for the post-termination retention and deletion periods set out in Section 15 of this DPA.
CCompetent supervisory authority
For the purposes of Clause 13 of the EU SCCs, the competent supervisory authority is the supervisory authority of the Member State of the European Economic Area in which the Client is established or, where the Client is not established in the European Economic Area, the supervisory authority of the Member State in which the relevant Data Subjects are located. With respect to Clients subject to the UK GDPR, the competent supervisory authority is the UK Information Commissioner's Office. With respect to Clients subject to the FADP, the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner.
Annex II - Technical and Organizational Measures
StackBooster has implemented and maintains the following technical and organizational measures designed to ensure an appropriate level of security of Client Personal Data, in accordance with Article 32 EU GDPR and the equivalent provisions of the UK GDPR. The measures described below are presented in summary form; a more detailed description is contained in the StackBooster Security Annex, made available to the Client upon request subject to appropriate confidentiality obligations.
1Access control and authentication
Access to systems processing Client Personal Data is restricted on a need-to-know basis through role-based access control (RBAC), least-privilege principles and logical tenant-level separation. Administrative access to production environments requires multi-factor authentication (MFA).
2Encryption
Client Personal Data is encrypted in transit using industry-standard transport layer encryption (TLS 1.2 or higher) and at rest using industry-standard symmetric encryption (AES-256 or equivalent).
3Secrets and credential management
API keys, OAuth tokens, cloud credentials and other secrets provided by the Client or used to access connected accounts are stored in an encrypted secrets store, are injected into workloads at runtime rather than stored in code, are not exposed to AI Agents in plain text where technically avoidable, and can be revoked by the Client.
4AI Agent controls
AI Agents operate within scoped permissions and the Approval Controls configured by or for the Client. Agent Actions that publish, send, spend or change production systems can be made subject to human approval, spending and sending caps, and a pause or stop control. Agent Actions are logged.
5Network and application security
Production systems are separated from non-production environments and protected by network-layer security controls, including firewalls, traffic filtering and monitoring. Client workloads run in isolated containers or namespaces. Applications are subject to secure development practices, code review, dependency management and vulnerability scanning.
6Logging, monitoring and audit trails
Security-relevant events, including access to Client Personal Data, authentication events, administrative actions and Agent Actions, are logged and retained in accordance with StackBooster's internal retention policies. Logs are monitored for anomalies.
7Backups, retention and business continuity
Client Personal Data stored on StackBooster infrastructure is subject to regular, encrypted backups stored with StackBooster's infrastructure hosting provider. StackBooster maintains business continuity and disaster recovery procedures.
8Incident management
StackBooster maintains an incident response procedure covering detection, triage, containment, eradication, recovery, notification and post-incident review.
9Personnel security, confidentiality and training
Personnel are subject to confidentiality commitments surviving the end of their engagement and receive data protection and information security training appropriate to their roles. Access rights are revoked promptly upon the end of engagement.
10Subprocessor management
Subprocessors are subject to risk-based due diligence before engagement and ongoing monitoring. Each Subprocessor is bound by data protection obligations substantially equivalent to those set out in this DPA.
11Physical security
Physical security of data processing facilities is provided by StackBooster's infrastructure hosting providers, which maintain industry-recognized physical security measures for their data centers.
12Data minimization and deletion
StackBooster applies data minimization principles in the design of the Services, provides deletion functionality for Client Data, AI Agent memory and Hosted Applications, and applies pseudonymization or de-identification techniques where appropriate.
13Controls for communication content and outbound channels
Specific controls are applied to email content, messages, comments, published content, advertising data and communication logs generated through the Services, including access restrictions, retention controls and deletion flows.
14Diagnostic, error monitoring and session replay tools
Where session replay, error monitoring or diagnostic tools are used in connection with the Services, StackBooster configures masking, scrubbing or equivalent controls for sensitive form fields and user-entered content.
Annex III - Authorized Subprocessors
The Subprocessor List published by StackBooster at:
https://stackbooster.io/legal/subprocessors
The Subprocessor List is deemed - by reference - to constitute Annex III to the EU SCCs and the equivalent subprocessor list under the UK Addendum.
Annex IV - Jurisdiction-Specific Terms
IV.1 Switzerland
Where Client Personal Data is subject to the FADP, references in this DPA to the EU GDPR are read as references to the FADP to the extent applicable; the EU SCCs apply to transfers subject to the FADP with the adjustments required by the Swiss Federal Data Protection and Information Commissioner, including that the term "Member State" does not exclude Data Subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence, and that the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner.
IV.2 United Kingdom
Where Client Personal Data is subject to the UK GDPR, references in this DPA to the EU GDPR are read as references to the corresponding provisions of the UK GDPR, and references to supervisory authorities are read as references to the Information Commissioner's Office.
IV.3 Other jurisdictions
Where the data protection laws of another jurisdiction apply to Client Personal Data, StackBooster applies to such data the protections, technical and organizational measures (Annex II), subprocessor regime (Section 8), transfer safeguards (Section 9), assistance and cooperation machinery (Sections 10-13) and AI-training safeguards (Section 14) set out in this DPA, and reasonably cooperates with the Client's registration, notification and record-keeping duties under such laws to the extent they concern the Services. The Client remains responsible for confirming that its submission of Client Personal Data to the Services complies with any cross-border transfer conditions and data localization requirements of its own jurisdiction.
© StackBooster Corporation. Legal document version 1.0.
Questions about this document: legal@stackbooster.io

