Legal
Data Processing Agreement
This DPA is incorporated into and forms part of the agreement between StickRate, Inc. (“StickRate”) and the entity using the Service (“Customer”) (the “Agreement”).
Effective date: May 8, 2026
1. Definitions
"Controller" means the entity that determines the purposes and means of processing Personal Data.
"Processor" means the entity that processes Personal Data on behalf of the Controller.
"Personal Data" means any information relating to an identified or identifiable natural person contained in Customer Data.
"Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
"Data Protection Laws" means all applicable laws relating to privacy and data protection, including the GDPR, UK GDPR, CCPA/CPRA, and their implementing regulations.
"Sub-processor" means any third party engaged by StickRate to process Personal Data in connection with providing the Service.
2. Roles and Responsibilities
The parties acknowledge that: (a) Customer is the Controller of Personal Data in Customer Data; (b) StickRate is the Processor acting on Customer's behalf; and (c) StickRate may engage Sub-processors subject to Section 5 of this DPA.
StickRate will process Personal Data only on documented instructions from Customer (including as set forth in this DPA and the Agreement) and not for any other purpose, except as required by applicable law.
StickRate will: (a) ensure that persons authorized to process Personal Data are subject to confidentiality obligations; (b) inform Customer if, in StickRate's opinion, an instruction infringes applicable Data Protection Laws; and (c) assist Customer with data protection impact assessments to the extent required by Data Protection Laws.
3. Details of Processing
Subject matter: Provision of the StickRate commitment intelligence platform.
Duration: The Subscription Term plus any post-termination data retention period specified in the Agreement.
Nature and purpose: Storage, analysis, and display of deal and customer engagement data to generate commitment intelligence outputs.
Types of Personal Data: Business contact information (names, email addresses, job titles, company names), buyer domain names, deal metadata (deal stage, close dates, deal values), contracting milestone dates, engagement signals, and audit log entries (user ID, IP address, timestamp).
Categories of Data Subjects: Customer's employees and authorized users; Customer's current and prospective business customers and their employees or representatives.
4. Security Measures
StickRate will implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized access, loss, or disclosure, as described in the Information Security Overview at stickrate.io/legal/security.
These measures include, at minimum: encryption at rest and in transit, access controls and least-privilege principles, security monitoring and logging, and regular security assessments.
5. Sub-processors
Customer grants StickRate general authorization to engage the Sub-processors listed at stickrate.io/legal/sub-processors. StickRate will impose data protection obligations on Sub-processors no less protective than those in this DPA.
StickRate will notify Customer of any intended addition or replacement of Sub-processors by updating the Sub-Processor List at stickrate.io/legal/sub-processors at least 30 days in advance. Customers may subscribe to sub-processor change notifications by emailing privacy@stickrate.io. Customer may object to a new Sub-processor within 14 days of notice; if Customer objects and StickRate cannot accommodate the objection, Customer may terminate the affected subscription without penalty.
6. Data Subject Rights
StickRate will assist Customer in fulfilling Data Subject rights requests (access, rectification, erasure, restriction, portability, and objection) to the extent technically feasible and as required by Data Protection Laws. Customer is responsible for responding to Data Subject requests; StickRate will promptly forward any requests it receives directly.
7. Data Breach Notification
StickRate will notify Customer of a confirmed breach of security leading to the unauthorized disclosure of Customer's Personal Data ("Security Incident") without undue delay. Notifications will be sent to the security contact designated by Customer. StickRate will provide sufficient information to allow Customer to meet its breach notification obligations under applicable Data Protection Laws.
8. Data Transfers
Where StickRate transfers Personal Data from the EEA, UK, or Switzerland to a country not recognized as providing an adequate level of data protection, StickRate will implement the EU Standard Contractual Clauses (Module 2: Controller to Processor) as the transfer mechanism. For transfers from the UK, StickRate will implement the UK International Data Transfer Addendum to the SCCs. The SCCs and UK Addendum are incorporated into this DPA by reference and are available upon request at privacy@stickrate.io.
9. Audit Rights
StickRate will make available to Customer, upon written request, information reasonably necessary to demonstrate compliance with this DPA. If StickRate maintains a SOC 2 Type II report or equivalent certification, StickRate may satisfy audit requests by providing a copy of the most recent report. Customer may conduct an audit not more than once per year upon 30 days' notice, subject to confidentiality obligations and at Customer's expense, and must coordinate with StickRate to minimize disruption to operations. Audit rights under this Section 9 extend only to StickRate and do not extend to StickRate's Sub-processors.
10. Return and Deletion
Upon termination of the Agreement, StickRate will delete Personal Data within a commercially reasonable period, except where retention is required by law. If Customer requests return of Personal Data prior to deletion, StickRate will make reasonable efforts to accommodate such request. StickRate will provide written confirmation of deletion upon request.
11. CCPA Obligations
To the extent StickRate processes Personal Information (as defined under the CCPA/CPRA) on Customer's behalf, StickRate acts as a "Service Provider." StickRate will not: (a) sell or share Personal Information; (b) retain, use, or disclose Personal Information outside the scope of this DPA; or (c) combine Personal Information received from Customer with Personal Information received from other sources, except as permitted by applicable law.
12. Conflict
In the event of a conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA will prevail.
Questions? Contact legal@stickrate.io