Legal
Data Processing Addendum (DPA)
Terms that apply when Stack4Sec processes personal data on a Customer's behalf.
Last updated: June 25, 2026 · Stack4Sec, LLC — Wyoming, USA
Language
This document is provided in English, which is the authoritative version; any translation is for convenience only and the English version prevails.
Overview
- Annex I - Details of Processing
- Annex II - Technical and Organizational Measures
- Annex III - Contact
This Data Processing Addendum, including its Annexes, applies where Stack4Sec, LLC processes Personal Data on behalf of Customer in connection with the Services. This DPA is incorporated into and forms part of the Stack4Sec Terms of Service and any applicable Order Form.
For purposes of this DPA, "Stack4Sec," "Company," "we," "us," and "our" mean Stack4Sec, LLC. "Customer," "you," and "your" mean the entity that has entered into the applicable agreement with Stack4Sec.
Definitions
"Applicable Data Protection Laws" means privacy, data protection, data security, breach notification, and similar laws applicable to the processing of Personal Data under the Agreement, which may include the GDPR, UK GDPR, Swiss data protection law, LGPD, CCPA/CPRA, Australia Privacy Act, and other applicable laws.
"Agreement" means the Stack4Sec Terms of Service, applicable Order Form, Product-Specific Additional Terms, and incorporated policies.
"Controller," "Processor," "Data Subject," "Personal Data," "Process," "Processing," "Subprocessor," and similar terms have the meanings given under Applicable Data Protection Laws.
"Customer Personal Data" means Personal Data processed by Stack4Sec on behalf of Customer under the Agreement.
"Security Incident" means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Stack4Sec.
Roles of the Parties
For Customer Personal Data, Customer is the Controller or Processor, and Stack4Sec is the Processor or Subprocessor, as applicable. Customer determines the purposes and means of processing Customer Personal Data. Stack4Sec processes Customer Personal Data only on behalf of Customer and in accordance with Customer's documented instructions.
Customer Instructions
Customer instructs Stack4Sec to process Customer Personal Data to provide, secure, maintain, support, and improve the Services; to comply with the Agreement; to respond to Customer requests; to prevent fraud, abuse, and security incidents; and as otherwise documented in the Agreement.
Stack4Sec will notify Customer if it believes an instruction violates Applicable Data Protection Laws, unless prohibited by law.
Customer Obligations
Customer is responsible for:
- complying with Applicable Data Protection Laws;
- providing required notices and obtaining required consents;
- establishing lawful bases for processing;
- ensuring Customer Personal Data is accurate, relevant, and lawful;
- configuring the Services appropriately;
- responding to Data Subject requests where Customer is responsible;
- ensuring that Customer's instructions are lawful.
Stack4Sec Processor Obligations
Stack4Sec will:
- process Customer Personal Data only in accordance with documented instructions;
- ensure personnel authorized to process Customer Personal Data are bound by confidentiality obligations;
- implement appropriate technical and organizational measures;
- assist Customer with Data Subject requests where required and reasonably possible;
- assist Customer with data protection impact assessments and regulator consultations where required and reasonably possible;
- notify Customer of Security Incidents as required by this DPA;
- delete or return Customer Personal Data as required by this DPA and the Agreement;
- make available information reasonably necessary to demonstrate compliance with this DPA.
Subprocessors
Customer provides general authorization for Stack4Sec to engage Subprocessors to provide the Services. Stack4Sec will maintain a list of Subprocessors or make such information available upon request.
Stack4Sec will impose written data protection obligations on Subprocessors that are substantially protective as those in this DPA, to the extent applicable to the services provided by the Subprocessor.
Customer may object to a new Subprocessor on reasonable data protection grounds by notifying Stack4Sec within the period specified in the Subprocessor notice or, if no period is specified, within 15 days after notice.
Security Measures
Stack4Sec will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data, including measures described in Annex II. Customer acknowledges that security measures may evolve and that Stack4Sec may update them, provided that overall protection is not materially reduced.
Security Incident Notification
Stack4Sec will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data. The notice will include information reasonably available to Stack4Sec, which may include the nature of the incident, affected data, mitigation measures, and recommended Customer actions.
Stack4Sec's notification is not an admission of fault or liability. Customer is responsible for determining whether notification to Data Subjects, regulators, customers, or other parties is required.
Data Subject Requests
If Stack4Sec receives a request from a Data Subject relating to Customer Personal Data, Stack4Sec may refer the requester to Customer, unless prohibited by law. Stack4Sec will provide reasonable assistance to Customer in responding to requests, taking into account the nature of processing and information available to Stack4Sec.
Return and Deletion
Upon termination or expiration of the Services, Stack4Sec will delete or return Customer Personal Data in accordance with the Agreement, unless retention is required by law, security, backup, dispute resolution, compliance, or legitimate business purposes. Backup copies may be retained for a limited period and protected from active processing except as required for restoration, security, or legal compliance.
Audits
Upon reasonable written request, Stack4Sec will provide information reasonably necessary to demonstrate compliance with this DPA. Any audit must be limited to once per year unless required by law or following a Security Incident, must avoid disruption to the Services, must protect Stack4Sec and third-party confidential information, and may be satisfied through security reports, questionnaires, certifications, or similar documentation.
International Transfers
Where Customer Personal Data is transferred internationally and Applicable Data Protection Laws require safeguards, the parties will use appropriate transfer mechanisms, which may include EU Standard Contractual Clauses, UK transfer addendum, Swiss safeguards, Brazil international transfer mechanisms, or other lawful transfer mechanisms.
For EEA transfers, the EU Standard Contractual Clauses are incorporated by reference where required, with Module Two applying to controller-to-processor transfers and Module Three applying to processor-to-processor transfers, as applicable.
For Brazil transfers, the parties will cooperate in good faith to implement appropriate mechanisms under the LGPD and applicable ANPD regulations, including standard contractual clauses where required.
CCPA/CPRA Service Provider Terms
Where the CCPA/CPRA applies and Stack4Sec processes Personal Information on behalf of Customer, Stack4Sec acts as a service provider or contractor, as applicable. Stack4Sec will not sell or share Customer Personal Data, retain, use, or disclose it outside the direct business relationship with Customer, or combine it with personal information from other sources except as permitted by the CCPA/CPRA and the Agreement.
Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except to the extent prohibited by Applicable Data Protection Laws.
Order of Precedence
If there is a conflict between this DPA and the Agreement regarding processing of Customer Personal Data, this DPA controls. If the Standard Contractual Clauses apply and conflict with this DPA, the Standard Contractual Clauses control to the extent of the conflict.
Annex I - Details of Processing
Annex II - Technical and Organizational Measures
Stack4Sec's technical and organizational measures may include:
- access control and authentication;
- role-based access controls;
- encryption in transit and, where applicable, encryption at rest;
- logging and monitoring;
- vulnerability management;
- backup and recovery practices;
- segregation of customer data using logical controls;
- personnel confidentiality obligations;
- vendor and Subprocessor management;
- incident response procedures;
- secure software development practices;
- administrative controls and least privilege principles.
Annex III - Contact
Stack4Sec, LLC 30 N Gould St, STE R Sheridan, WY 82801 United States Email: legal@stack4sec.com