আইনি
Stack4Sec & the GDPR
How Stack4Sec supports compliance with the EU General Data Protection Regulation.
সর্বশেষ আপডেট: June 25, 2026 · Stack4Sec, LLC — Wyoming, USA
Language
This document is provided in English, which is the authoritative version; any translation is for convenience only and the English version prevails.
Overview
This document applies to all cybersecurity software-as-a-service solutions, websites, applications, platforms, APIs, software, modules, features, documentation, support, and related services made available by Stack4Sec, LLC, a Wyoming limited liability company.
For purposes of this document, "Stack4Sec," "Company," "we," "us," and "our" mean Stack4Sec, LLC. "Customer," "you," and "your" mean the person or entity accessing or using the Services.
This document is incorporated into and forms part of the Stack4Sec Terms of Service. Product-specific terms may supplement this document for particular products, modules, services, or features.
This document explains how Stack4Sec approaches the General Data Protection Regulation (GDPR) and related European data protection requirements. It is provided for transparency and does not constitute legal advice. Customers should consult their own counsel to determine how the GDPR applies to their organization and use of the Services.
Scope
This document applies where Stack4Sec processes personal data subject to the GDPR, UK GDPR, Swiss data protection law, or similar European data protection requirements.
Roles Under the GDPR
Depending on the processing activity, Stack4Sec may act as:
- a controller for its own business operations, such as account administration, billing, marketing, website analytics, security, and customer relationship management;
- a processor where Stack4Sec processes Customer Personal Data on behalf of a Customer through the Services;
- a subprocessor where Customer is a processor for another controller.
The Data Processing Addendum governs Stack4Sec's processor obligations for Customer Personal Data.
Customer as Controller
Customer is responsible for determining the purposes and means of processing Customer Personal Data submitted to the Services. Customer is responsible for notices, lawful bases, consents, records of processing, data protection impact assessments, data subject requests, retention rules, and compliance with GDPR obligations applicable to Customer.
Legal Bases for Stack4Sec Controller Processing
When Stack4Sec acts as controller, it may rely on legal bases such as performance of a contract, legitimate interests, consent, compliance with legal obligations, establishment or defense of legal claims, and other lawful bases under the GDPR.
Data Processing Addendum
Stack4Sec offers a Data Processing Addendum for Customer Personal Data. The DPA includes processor commitments regarding instructions, confidentiality, security measures, subprocessors, assistance, deletion, audits, international transfers, and incident notification.
International Transfers
Stack4Sec is based in the United States. Where personal data subject to the GDPR is transferred internationally and a transfer mechanism is required, Stack4Sec may rely on appropriate safeguards, including EU Standard Contractual Clauses, UK transfer addendum, Swiss safeguards, adequacy decisions, or other lawful transfer mechanisms.
Subprocessors
Stack4Sec may use Subprocessors to provide hosting, infrastructure, security, analytics, support, communications, payment processing, AI functionality, and other service components. Stack4Sec imposes appropriate contractual obligations on Subprocessors and provides information about Subprocessors as required by the DPA.
Data Subject Rights
GDPR rights may include access, rectification, erasure, restriction, portability, objection, and rights relating to automated decision-making. Where Stack4Sec processes Customer Personal Data as processor, Customer is generally responsible for responding to data subject requests. Stack4Sec will provide reasonable assistance as required by the DPA.
Security Measures
Stack4Sec implements commercially reasonable technical and organizational measures designed to protect personal data. These may include access controls, authentication, encryption in transit, logging, monitoring, vulnerability management, incident response, vendor management, and confidentiality obligations.
Personal Data Breach Notification
If Stack4Sec confirms a Security Incident affecting Customer Personal Data, Stack4Sec will notify Customer in accordance with the DPA and applicable law. Customer is responsible for determining whether notification to supervisory authorities or data subjects is required.
Cookies and ePrivacy
Stack4Sec uses cookies and similar technologies as described in the Cookie Policy. Where required, Stack4Sec seeks consent for non-essential cookies or provides opt-out controls consistent with applicable law.
Data Protection Impact Assessments
Where required by the GDPR and reasonably related to processing by Stack4Sec, Stack4Sec will provide reasonable assistance to Customer with data protection impact assessments and prior consultations, taking into account the nature of processing and information available to Stack4Sec.
Retention and Deletion
Retention periods depend on the type of data, purpose of processing, contractual commitments, legal obligations, security requirements, and operational needs. Customer controls retention of Customer Content within the Services to the extent functionality permits. Stack4Sec deletes or returns Customer Personal Data in accordance with the DPA and Agreement.
Contact
GDPR-related inquiries may be sent to:
Stack4Sec, LLC 30 N Gould St, STE R Sheridan, WY 82801 United States Email: legal@stack4sec.com