1. Definitions
Capitalized terms not defined here have the meaning given in the Agreement.
- "Data Protection Laws" means all laws applicable to the processing of Personal Data under the Agreement, including, as applicable, the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018 ("UK GDPR"), the Swiss Federal Act on Data Protection ("FADP"), and US state privacy laws such as the California Consumer Privacy Act as amended by the CPRA ("CCPA").
- "Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Personal Data Breach" have the meanings given in the GDPR (or their equivalents under other Data Protection Laws, including "business", "service provider", and "consumer" under the CCPA).
- "Customer Personal Data" means Personal Data contained within Your Content that we process on your behalf to provide the Service, as described in Annex A.
- "Sub-processor" means any third party engaged by us to process Customer Personal Data.
- "Standard Contractual Clauses" ("SCCs") means the clauses approved by the European Commission in Decision 2021/914, and, for the UK, the UK International Data Transfer Addendum issued by the ICO.
- "Authorized Affiliate" means an entity that controls, is controlled by, or is under common control with you and is permitted to use the Service under your workspace.
2. Roles & scope of processing
The parties acknowledge that, with respect to Customer Personal Data, you are the Controller (or a Processor acting on behalf of a third-party Controller) and StellarReach is the Processor. Where you act as a Processor for a third-party Controller, you warrant that your instructions and actions, including engaging us as a Sub-processor, are authorized by that Controller.
For Personal Data relating to your own account and the administration of your workspace (for example, the names and emails of your workspace users, and billing data), StellarReach acts as an independent Controller, as described in the Privacy Notice. This DPA governs only our processing of Customer Personal Data as a Processor.
The subject matter, duration, nature and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex A.
3. Processing instructions
We will process Customer Personal Data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law (in which case we will, where legally permitted, inform you of that requirement before processing). Your instructions are set out in the Agreement, this DPA, and your configuration and use of the Service (for example, which prospects you target, what you send, and which integrations you enable). We will inform you if, in our opinion, an instruction infringes Data Protection Laws; we are not obliged to monitor the lawfulness of your instructions generally.
You are responsible for the accuracy, quality, and legality of Customer Personal Data and for having a valid legal basis to collect it, load it into the Service, and conduct your outreach — including consent where required, suppression and unsubscribe handling, and compliance with anti-spam and marketing laws (such as CAN-SPAM, CASL, and GDPR/PECR), as further described in the Agreement and the Privacy Notice.
4. Confidentiality
We ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and process the data only as necessary to provide the Service and support, on a need-to-know basis.
5. Security of processing
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to Data Subjects, we implement appropriate technical and organizational measures to protect Customer Personal Data, as described in Annex B. We may update those measures over time provided the level of protection is not materially reduced. You are responsible for your own use of the Service, including the security of the credentials and API keys you connect and the choices you make in your configuration.
6. Sub-processors
You provide a general authorization for us to engage Sub-processors to process Customer Personal Data to provide the Service. Our current Sub-processors are listed in Annex C. We impose data protection obligations on each Sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance of those obligations.
We will give you notice of any intended addition or replacement of a Sub-processor (for example, by updating Annex C and, where you have subscribed to notifications, by email) with a reasonable opportunity to object on legitimate data protection grounds. If you object and we cannot reasonably accommodate your concern, your remedy is to stop using the affected feature or to terminate the Agreement as permitted therein.
When you optionally connect a CRM or other third-party integration, that provider acts under your own agreement with it and is not a StellarReach Sub-processor for that data flow.
7. Data subject requests
Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures, insofar as possible, to respond to requests from Data Subjects to exercise their rights (such as access, correction, deletion, restriction, objection, and portability). The Service provides functionality to access, edit, export, and delete Customer Personal Data within your workspace, which you can use to fulfil such requests directly. If we receive a request relating to Customer Personal Data, we will, unless legally prohibited, promptly inform you and direct the Data Subject to you as the responsible Controller.
8. Personal data breaches
We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to us to help you meet your own breach-notification obligations. We will take reasonable steps to mitigate and remediate the breach. Our notification is not an acknowledgement of fault or liability.
9. Impact assessments & prior consultation
Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance to you with data protection impact assessments and any prior consultation with a supervisory authority that you are required to carry out under Data Protection Laws — for example, by making available the information in this DPA, the Privacy Notice, and our Security overview.
10. International data transfers
StellarReach is operated from the United States, and we and our Sub-processors may process Customer Personal Data in the United States and other countries. Where our processing involves a transfer of Customer Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, the parties agree that the Standard Contractual Clauses are incorporated into this DPA by reference and apply to that transfer, with StellarReach as "data importer" and you as "data exporter":
- the EU SCCs (Module Two, Controller-to-Processor, or Module Three, Processor-to-Processor, as applicable), completed using the details in Annexes A–C, with the optional docking clause and, for Clause 11, the optional language omitted;
- for UK transfers, the UK International Data Transfer Addendum, with the EU SCCs as its Approved Addendum; and
- for Swiss transfers, the EU SCCs as adapted by the Swiss Federal Data Protection and Information Commissioner.
Where applicable, the governing-law and forum options in the SCCs follow the data exporter's place of establishment, and the supervisory authority is the competent authority for that establishment. If a transfer mechanism is held invalid, the parties will work in good faith to implement an alternative lawful mechanism.
11. Return & deletion of data
You may access, export, and delete Customer Personal Data within your workspace at any time during the term. Following termination or expiry of the Agreement, we will delete or, at your request, return Customer Personal Data within a reasonable period, and delete existing copies, except to the extent we are required to retain it by applicable law (for example, billing records), in which case we will continue to protect it under this DPA.
12. Audits & information
We will make available to you information reasonably necessary to demonstrate our compliance with this DPA and Article 28 of the GDPR, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. To the extent permitted by Data Protection Laws, audits will be satisfied first by our providing relevant documentation (such as this DPA, the Security overview, and any third-party attestations we hold). Where that is insufficient, audits will be conducted on reasonable prior notice, no more than once per year (except where required by a supervisory authority or following a Personal Data Breach), during business hours, subject to confidentiality, and in a manner that does not disrupt our operations or compromise other customers' data.
13. US state privacy laws
To the extent the CCPA or a similar US state privacy law applies, StellarReach acts as a service provider (or "processor"/"contractor") and processes Customer Personal Data solely to provide the Service and for the business purposes set out in the Agreement. We will not:
- sell or share Customer Personal Data (as those terms are defined under the CCPA);
- retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in the Agreement, or outside the direct business relationship with you; or
- combine Customer Personal Data with personal information from other sources, except as permitted for a service provider under the CCPA.
We certify that we understand and will comply with these restrictions. You may take reasonable steps to ensure we use Customer Personal Data consistent with your obligations under applicable US state privacy laws.
14. Liability & precedence
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. This DPA does not create obligations or rights for the benefit of anyone other than the parties and their permitted successors and assigns, except as expressly stated. Except as amended by this DPA, the Agreement remains in full force and effect.
15. Term
This DPA takes effect when you accept the Agreement and continues until the Agreement terminates or expires and we have completed our deletion or return obligations under Section 11. Provisions that by their nature should survive termination will survive.
Annex A — Details of processing
Parties. Data exporter / Controller: the Customer, as identified in its workspace account. Data importer / Processor: StellarReach.app LLC, reachable at support@stellarreach.app.
Subject matter. Provision of the StellarReach outreach and prospecting platform under the Agreement.
Duration. For the term of the Agreement, plus the period until deletion or return of Customer Personal Data under Section 11.
Nature & purpose of processing. Hosting, storage, retrieval, organization, analysis, and transmission of Customer Personal Data to: discover and score prospect businesses (including capturing public website content and screenshots), generate demo sites, draft and send outreach and follow-up email from the Customer's connected inbox, track email engagement, meter usage, and optionally sync to a CRM the Customer connects.
Types of Personal Data. Business contact details (such as names, business email addresses, phone numbers, and websites of prospects and their representatives); content captured from prospects' public websites; AI-generated scores, notes, and demo content; and email-engagement events (sends, opens, and clicks). Customers are instructed not to load special categories of Personal Data into the Service.
Categories of Data Subjects. The Customer's prospects and their owners, employees, and representatives; and recipients of the Customer's outreach.
Frequency. Continuous, for the duration of the Agreement.
Annex B — Technical & organizational measures
We maintain technical and organizational measures appropriate to the risk, which currently include:
- Encryption in transit — TLS/HTTPS for connections to the Service and to our providers' APIs.
- Encryption at rest for secrets — connected OAuth tokens and API keys are encrypted with AES-256-GCM before storage.
- Credential protection — account passwords are stored only as salted, memory-hard scrypt hashes; we cannot recover them.
- Tenant isolation — data is partitioned per workspace and every request is scoped to the authenticated workspace, so one customer cannot access another's data.
- Access controls — role-based authorization (workspace admin vs. platform administrator), authenticated sessions, and cross-site request forgery protections; administrative access on a least-privilege, need-to-know basis.
- Abuse protection — brute-force throttling on authentication and an audit log of sensitive administrative actions.
- Sub-processor diligence — we use established providers (Annex C) and flow down data protection obligations.
- Resilience — managed, hosted infrastructure with provider-level redundancy and backups.
See our Security overview for more detail. These measures may evolve; we will not materially reduce the overall level of protection during the term.
Annex C — Sub-processors
We engage the following Sub-processors to process Customer Personal Data in providing the Service:
| Sub-processor | Purpose | Processing location |
|---|---|---|
| Netlify | Application hosting and content delivery | United States |
| Managed PostgreSQL host | Primary application database | United States |
| Anthropic | AI scoring, demo generation, and email drafting | United States |
| Maps Platform (business discovery) and Gmail / OAuth (sending email you authorize) | United States | |
| SendGrid (Twilio) | Transactional and outreach email delivery | United States |
| Stripe | Subscription and usage billing | United States |
When you use bring-your-own-keys, AI and Maps requests run against your provider accounts under their terms rather than ours. Any CRM or webhook you connect is governed by your agreement with that provider and is not a StellarReach Sub-processor.
Contact
Questions about this DPA, or to request a counter-signed copy:
StellarReach.app LLC
Email: support@stellarreach.app
See also: Terms of Service · Privacy Notice · Security · Home