Data Processing Addendum

Data-processing terms for customer engagements.

The Northstar Stack Data Processing Addendum forms part of a customer agreement whenever Northstar Stack processes personal data on the customer's behalf.

Execution copy

The signed DPA identifies the legal parties, customer instructions, systems, retention period, provider schedule, and technical measures for the engagement.

1. Scope and roles

This Addendum applies when Northstar Stack processes personal data for the customer in providing the services. The customer acts as controller or business, and Northstar Stack acts as processor or service provider, unless the executed agreement states otherwise.

Northstar Stack processes personal data only on documented customer instructions, including the instructions in the service agreement, order form, and this Addendum. Northstar Stack will tell the customer if an instruction appears to violate applicable data-protection law, unless the law prohibits that notice.

2. Core processing terms

Confidentiality and access

Access is limited to people and approved providers who need the data to perform the services. They are subject to confidentiality duties appropriate to their role.

Security measures

Northstar Stack maintains measures appropriate to the processing described in the executed agreement. The measures include separated engagement workspaces, limited access, declared source inventories, provider disclosure, human review, evidence checks, and a defined return or deletion path.

Subprocessors

The customer authorizes the subprocessors identified in the agreement and on the Subprocessors page. Northstar Stack remains responsible for each subprocessor's performance of its data-protection duties to the extent required by applicable law and the signed agreement.

Requests and regulatory assistance

Taking into account the nature of the processing, Northstar Stack will provide reasonable assistance with data-subject requests, security inquiries, impact assessments, and regulator consultations when the customer cannot complete the work without Northstar Stack.

Security incidents

Northstar Stack will notify the customer without undue delay after becoming aware of a confirmed personal-data breach affecting customer data. The notice will include the information reasonably available at the time and will be updated as material facts become known.

Return and deletion

At the end of the services, Northstar Stack will return or delete customer personal data as stated in the executed agreement, unless applicable law requires retention. Required retained data stays protected and is used only for the legally required purpose.

Audit information

Northstar Stack will make information reasonably necessary to demonstrate compliance with the executed Addendum available to the customer. Audit scope, timing, confidentiality, cost, and disruption limits are set in the signed agreement.

3. Processing details

Subject matterMarketing information-flow diagnostics, evidence analysis, reporting, and agreed implementation work
DurationThe service term plus the return or deletion period stated in the executed agreement
Nature and purposeCollection, organization, extraction, classification, comparison, reporting, and storage needed to provide the agreed services
Data subjectsCustomer personnel, contractors, prospects, customers, and other people present in supplied business records
Personal dataBusiness contact data, role information, communications, call recordings or transcripts, CRM records, support and churn records, work records, and related metadata
Sensitive dataNot required for the standard diagnostic. Any permitted sensitive-data processing must be stated in the executed agreement.
FrequencyAs needed during the service term and limited to the agreed source inventory

4. International transfers and U.S. state terms

If personal data is transferred from the European Economic Area, United Kingdom, or Switzerland to a country without an applicable adequacy decision, the parties will use the transfer mechanism stated in the executed agreement. This may include the applicable European Commission Standard Contractual Clauses and required local addenda.

For U.S. state privacy laws, Northstar Stack will not sell or share customer personal data for cross-context behavioral advertising. It will retain, use, and disclose the data only to provide the contracted services, meet legal duties, or follow another instruction permitted by the signed agreement and applicable law.

Reference frameworks: EU General Data Protection Regulation and European Commission Standard Contractual Clauses.

Request an execution copy

Submit the customer name and work email. Northstar Stack will provide the DPA for contract review.