Data Processing Agreement
This Data Processing Agreement (DPA) is part of the Terms of Service between you (the Customer) and Stockisto. You act as controller: you decide why and how personal data is used. Stockisto acts as processor: we handle that data only on your behalf. This DPA applies wherever Stockisto processes personal data for you. It sets out how we process that data and which security measures we apply. It also lists our sub-processors (other companies that help us deliver the service) and explains how we support your GDPR duties.
1. Roles & scope
2. Processing on documented instructions
We must process personal data only on your documented instructions. This includes instructions about international transfers. Your documented instructions are:
- your use of the platform's features,
- the Terms, and
- this DPA.
One exception applies: EU or member-state law may require us to process differently. If it does, we must inform you, unless that law prohibits it. We must also tell you if we believe an instruction infringes the GDPR.
3. Confidentiality
4. Security of processing (Art 32)
5. Sub-processors
A sub-processor is another company we engage to process personal data on your behalf. You give us general permission to use the sub-processors listed in Annex 3. We must bind each sub-processor to data-protection obligations at least as protective as this DPA. We remain fully liable to you for their work. If we intend to add or replace a sub-processor:
- we must give you at least 30 days' notice, and
- you may object on reasonable data-protection grounds.
If we must replace a sub-processor urgently to keep the service secure or running, we may act first. We must then notify you promptly, and your right to object still applies.
6. Assisting with data-subject rights
Data subjects are the people the personal data is about. Under Chapter III of the GDPR, they may ask you to:
- give them access to their data (access),
- correct it (rectification),
- delete it (erasure),
- limit how it is used (restriction),
- hand it over in a portable format (portability), and
- stop certain processing (objection).
We must help you respond to those requests, with appropriate technical and organisational measures, as far as possible. Our help takes account of the nature of the processing. The platform provides self-service data export (Art 20) and a deletion request flow (Art 17). Where self-service is not enough, our support team must assist. If a data subject contacts us directly about your data, we must refer them to you.
7. Assisting with your Art 32-36 obligations
You have duties of your own under Articles 32 to 36 of the GDPR. They cover:
- security of processing,
- notifying personal data breaches,
- data-protection impact assessments, and
- prior consultation.
We must help you meet those duties. Our help takes account of the nature of the processing and the information available to us.
8. Personal data breach notification
9. Return & deletion of data (Art 28(3)(g))
10. Audits (Art 28(3)(h))
11. International transfers
Primary processing takes place in the EU. Where a sub-processor in Annex 3 processes personal data outside the EEA, we make the transfer under:
- the European Commission's Standard Contractual Clauses (SCCs), a pre-approved contract for transfers outside the EEA,
- the EU-US Data Privacy Framework, where it applies, and
- any supplementary measures the transfer requires.
12. Liability, term & governing law
Annex 1: Details of the processing
- Subject-matter & duration: processing personal data to provide the Stockisto record of the channel, for the term of the agreement.
- Nature & purpose: hosting, storage, retrieval, structuring, analysis and transmission of data to operate the Locator, Widget, admin apps, Installer Portal and related communications.
- Categories of data subjects: the Customer's account users; retailer business contacts in the Customer's network; installers; and consumers who submit a “reserve & collect” request.
- Categories of personal data: names, work contact details (email, phone), business addresses, roles, authentication identifiers, and consumer reservation details (name, email, phone, free-text notes).
- Special categories: none are required or intended; the platform is not designed to process special-category data (Art 9).
Annex 2: Technical & organisational measures
- Encryption in transit: all traffic served over TLS 1.2+ with HSTS; TLS terminated at the edge (Azure Front Door) with a managed web application firewall.
- Encryption at rest: the PostgreSQL database and object storage use Azure-managed storage encryption.
- Tenant isolation: enforced in the data layer via global query filters plus an insert-time guard, and continuously regression-tested by a dedicated cross-tenant test suite in CI.
- Access control: role-based access control with scoped roles; every authorisation decision is enforced server-side.
- Authentication: short-lived JWT access tokens with a rotating refresh token in an HttpOnly, Secure cookie (reuse detection); Google OAuth and single-use magic links.
- Audit logging: privileged tenant actions recorded to an append-first audit log retained for 7 years.
- Secrets management: credentials held in Azure Key Vault; the application fails fast at startup if security-critical configuration is missing.
- Network hardening: restrictive security headers on every response, per-tenant/per-client rate limiting, and automatic abuse blocking.
- Data minimisation in logs: direct identifiers (e.g. email) are kept out of application logs and telemetry; client IPs are not persisted in analytics.
- Backups & resilience: point-in-time backups retained up to 35 days, geo-redundant within the EU, with defined recovery objectives.
- Vulnerability management: dependency scanning and static analysis in CI, and a responsible-disclosure channel at security@stockisto.com.
Annex 3: Approved sub-processors
| Sub-processor | Purpose | Location | Transfer basis |
|---|---|---|---|
| Microsoft Azure | Cloud hosting and infrastructure: application compute, the PostgreSQL database, object storage, the message bus, monitoring and key management. This is where all primary personal data lives. | EU (Sweden Central) | Within the EU: no third-country transfer |
| Microsoft Azure OpenAI Service ★ | Optional AI assistance that drafts supplier-to-retailer outreach text. It processes retailer business-contact data, never consumer reservation data. | EU (within the Azure tenancy) | Within the EU: no third-country transfer |
| TypeSafe AI, Inc. ★ | Optional automated checks and suggestions on catalogue data, business records and text submitted through forms. Structured contact fields of a person are never sent, and email addresses and phone numbers are removed from free text first. Stockisto keeps each answer with the record it concerns and does not store what was sent. We assume TypeSafe processes data in the USA and keeps it for an unknown time. | USA | SCCs only: the Commission's Standard Contractual Clauses, without reliance on the EU-US Data Privacy Framework |
| OpenAI ★ | Optional reading of public web pages, such as retailer lists and company sites, to build the retailer directory and the catalogue. The cleaned text of the page goes to OpenAI's API, and so does any feedback a supplier types when they reject a sample. The page can include business contact details published on it. It never includes data from customer accounts or reservations. | USA | SCCs, and the EU-US Data Privacy Framework where the recipient is certified |
| Twilio (incl. SendGrid) ★ | Delivery of transactional and lifecycle email via SendGrid (invitations, confirmations and notifications) and of SMS phone-verification codes via Twilio's messaging API, which receives the account user's phone number when they verify it. | USA | SCCs, and the EU-US Data Privacy Framework where the recipient is certified |
| Stripe | Subscription billing and card-payment processing for paying suppliers. Stripe acts as an independent controller for the payment data it collects, under its own terms. | EU / USA | SCCs, and the EU-US Data Privacy Framework where the recipient is certified |
| Google (Google Ireland Ltd) | "Sign in with Google" authentication for account users who choose it. Google acts as an independent controller for the authentication data under its own terms. | EU / USA | SCCs, and the EU-US Data Privacy Framework where the recipient is certified |
| Mapbox | Rendering map tiles in the browser on the consumer Locator, the embeddable Widget and the Installer Portal. Receives the coarse map view and the requesting IP inherent to serving tiles, never reservation contact details. | USA | SCCs, and the EU-US Data Privacy Framework where the recipient is certified |
| Cloudflare, Inc. ★ | Bot protection on the public sign-up, contact and newsletter forms (Cloudflare Turnstile). The check receives the visitor's IP address and signals from the browser, never what was typed into the form. | EU / USA | SCCs, and the EU-US Data Privacy Framework where the recipient is certified |
| OpenStreetMap / Nominatim | Server-side geocoding of retailer business addresses into map coordinates during catalogue import. | EU | Within the EU: business address data only |
| Kartverket | Server-side geocoding of Norwegian business addresses into map coordinates. © Kartverket. | Norway (EEA) | Within the EEA: business address data only |
★ Engaged only where the corresponding feature (AI drafting / automated checks and suggestions / page reading / outbound email / SMS phone verification / form bot protection) is enabled and configured.