Data Processing Addendum
Data-processing terms for customer engagements.
The Northstar Stack Data Processing Addendum forms part of a customer agreement whenever Northstar Stack processes personal data on the customer's behalf.
Execution copy
The signed DPA identifies the legal parties, customer instructions, systems, retention period, provider schedule, and technical measures for the engagement.
1. Scope and roles
This Addendum applies when Northstar Stack processes personal data for the customer in providing the services. The customer acts as controller or business, and Northstar Stack acts as processor or service provider, unless the executed agreement states otherwise.
Northstar Stack processes personal data only on documented customer instructions, including the instructions in the service agreement, order form, and this Addendum. Northstar Stack will tell the customer if an instruction appears to violate applicable data-protection law, unless the law prohibits that notice.
2. Core processing terms
Confidentiality and access
Access is limited to people and approved providers who need the data to perform the services. They are subject to confidentiality duties appropriate to their role.
Security measures
Northstar Stack maintains measures appropriate to the processing described in the executed agreement. The measures include separated engagement workspaces, limited access, declared source inventories, provider disclosure, human review, evidence checks, and a defined return or deletion path.
Subprocessors
The customer authorizes the subprocessors identified in the agreement and on the Subprocessors page. Northstar Stack remains responsible for each subprocessor's performance of its data-protection duties to the extent required by applicable law and the signed agreement.
Requests and regulatory assistance
Taking into account the nature of the processing, Northstar Stack will provide reasonable assistance with data-subject requests, security inquiries, impact assessments, and regulator consultations when the customer cannot complete the work without Northstar Stack.
Security incidents
Northstar Stack will notify the customer without undue delay after becoming aware of a confirmed personal-data breach affecting customer data. The notice will include the information reasonably available at the time and will be updated as material facts become known.
Return and deletion
At the end of the services, Northstar Stack will return or delete customer personal data as stated in the executed agreement, unless applicable law requires retention. Required retained data stays protected and is used only for the legally required purpose.
Audit information
Northstar Stack will make information reasonably necessary to demonstrate compliance with the executed Addendum available to the customer. Audit scope, timing, confidentiality, cost, and disruption limits are set in the signed agreement.
3. Processing details
| Subject matter | Marketing information-flow diagnostics, evidence analysis, reporting, and agreed implementation work |
|---|---|
| Duration | The service term plus the return or deletion period stated in the executed agreement |
| Nature and purpose | Collection, organization, extraction, classification, comparison, reporting, and storage needed to provide the agreed services |
| Data subjects | Customer personnel, contractors, prospects, customers, and other people present in supplied business records |
| Personal data | Business contact data, role information, communications, call recordings or transcripts, CRM records, support and churn records, work records, and related metadata |
| Sensitive data | Not required for the standard diagnostic. Any permitted sensitive-data processing must be stated in the executed agreement. |
| Frequency | As needed during the service term and limited to the agreed source inventory |
4. International transfers and U.S. state terms
If personal data is transferred from the European Economic Area, United Kingdom, or Switzerland to a country without an applicable adequacy decision, the parties will use the transfer mechanism stated in the executed agreement. This may include the applicable European Commission Standard Contractual Clauses and required local addenda.
For U.S. state privacy laws, Northstar Stack will not sell or share customer personal data for cross-context behavioral advertising. It will retain, use, and disclose the data only to provide the contracted services, meet legal duties, or follow another instruction permitted by the signed agreement and applicable law.
Reference frameworks: EU General Data Protection Regulation and European Commission Standard Contractual Clauses.
Request an execution copy
Submit the customer name and work email. Northstar Stack will provide the DPA for contract review.