Legale

Stack4Sec & the GDPR

How Stack4Sec supports compliance with the EU General Data Protection Regulation.

Ultimo aggiornamento: June 25, 2026 · Stack4Sec, LLCWyoming, USA

Language

This document is provided in English, which is the authoritative version; any translation is for convenience only and the English version prevails.

Overview

This document applies to all cybersecurity software-as-a-service solutions, websites, applications, platforms, APIs, software, modules, features, documentation, support, and related services made available by Stack4Sec, LLC, a Wyoming limited liability company.

For purposes of this document, "Stack4Sec," "Company," "we," "us," and "our" mean Stack4Sec, LLC. "Customer," "you," and "your" mean the person or entity accessing or using the Services.

This document is incorporated into and forms part of the Stack4Sec Terms of Service. Product-specific terms may supplement this document for particular products, modules, services, or features.

This document explains how Stack4Sec approaches the General Data Protection Regulation (GDPR) and related European data protection requirements. It is provided for transparency and does not constitute legal advice. Customers should consult their own counsel to determine how the GDPR applies to their organization and use of the Services.

Scope

This document applies where Stack4Sec processes personal data subject to the GDPR, UK GDPR, Swiss data protection law, or similar European data protection requirements.

Roles Under the GDPR

Depending on the processing activity, Stack4Sec may act as:

  • a controller for its own business operations, such as account administration, billing, marketing, website analytics, security, and customer relationship management;
  • a processor where Stack4Sec processes Customer Personal Data on behalf of a Customer through the Services;
  • a subprocessor where Customer is a processor for another controller.

The Data Processing Addendum governs Stack4Sec's processor obligations for Customer Personal Data.

Customer as Controller

Customer is responsible for determining the purposes and means of processing Customer Personal Data submitted to the Services. Customer is responsible for notices, lawful bases, consents, records of processing, data protection impact assessments, data subject requests, retention rules, and compliance with GDPR obligations applicable to Customer.

Legal Bases for Stack4Sec Controller Processing

When Stack4Sec acts as controller, it may rely on legal bases such as performance of a contract, legitimate interests, consent, compliance with legal obligations, establishment or defense of legal claims, and other lawful bases under the GDPR.

Data Processing Addendum

Stack4Sec offers a Data Processing Addendum for Customer Personal Data. The DPA includes processor commitments regarding instructions, confidentiality, security measures, subprocessors, assistance, deletion, audits, international transfers, and incident notification.

International Transfers

Stack4Sec is based in the United States. Where personal data subject to the GDPR is transferred internationally and a transfer mechanism is required, Stack4Sec may rely on appropriate safeguards, including EU Standard Contractual Clauses, UK transfer addendum, Swiss safeguards, adequacy decisions, or other lawful transfer mechanisms.

Subprocessors

Stack4Sec may use Subprocessors to provide hosting, infrastructure, security, analytics, support, communications, payment processing, AI functionality, and other service components. Stack4Sec imposes appropriate contractual obligations on Subprocessors and provides information about Subprocessors as required by the DPA.

Data Subject Rights

GDPR rights may include access, rectification, erasure, restriction, portability, objection, and rights relating to automated decision-making. Where Stack4Sec processes Customer Personal Data as processor, Customer is generally responsible for responding to data subject requests. Stack4Sec will provide reasonable assistance as required by the DPA.

Security Measures

Stack4Sec implements commercially reasonable technical and organizational measures designed to protect personal data. These may include access controls, authentication, encryption in transit, logging, monitoring, vulnerability management, incident response, vendor management, and confidentiality obligations.

Personal Data Breach Notification

If Stack4Sec confirms a Security Incident affecting Customer Personal Data, Stack4Sec will notify Customer in accordance with the DPA and applicable law. Customer is responsible for determining whether notification to supervisory authorities or data subjects is required.

Cookies and ePrivacy

Stack4Sec uses cookies and similar technologies as described in the Cookie Policy. Where required, Stack4Sec seeks consent for non-essential cookies or provides opt-out controls consistent with applicable law.

Data Protection Impact Assessments

Where required by the GDPR and reasonably related to processing by Stack4Sec, Stack4Sec will provide reasonable assistance to Customer with data protection impact assessments and prior consultations, taking into account the nature of processing and information available to Stack4Sec.

Retention and Deletion

Retention periods depend on the type of data, purpose of processing, contractual commitments, legal obligations, security requirements, and operational needs. Customer controls retention of Customer Content within the Services to the extent functionality permits. Stack4Sec deletes or returns Customer Personal Data in accordance with the DPA and Agreement.

Contact

GDPR-related inquiries may be sent to:

Stack4Sec, LLC 30 N Gould St, STE R Sheridan, WY 82801 United States Email: legal@stack4sec.com

Stack4Sec, LLC · Wyoming, USA · contact@stack4sec.com