1. Parties and how this fits together
This Data Processing Agreement (the "DPA") is entered into between STACKD of Dubai, United Arab Emirates ("STACKD", "we", "us") and the organisation that holds the STACKD account ("Customer", "you").
It forms part of the Terms of Service and applies whenever we process personal data on your behalf. It takes effect when you accept it during sign-up or when you first use the platform, whichever is earlier, and it runs for as long as your account exists.
Where this DPA and the Terms of Service conflict on the processing of personal data, this DPA wins. Words defined in the UK GDPR and the EU GDPR — controller, processor, personal data, processing, personal data breach, supervisory authority — carry those meanings here.
Nothing in this DPA displaces the Privacy Policy, which describes the personal data we process as a controller in our own right, such as your account and billing records.
2. Roles: who is the controller
For everything you do through STACKD — the journalists you contact, the pitches you send, the content you publish, the contacts you upload, the monitoring you configure — you are the controller and we are the processor.
This matters more here than in most software. STACKD contacts third parties on your behalf. When a pitch reaches a journalist who never asked to hear from you, that journalist's personal data is being processed because you decided to contact them, for your purposes, to your brief. The decision is yours, the lawful basis is yours, and the accountability is yours.
We act only on your documented instructions. Configuring the platform, running a search, approving a send and publishing a post are all instructions for this purpose. If we believe an instruction breaks data protection law we will tell you, and we may decline to carry it out.
We are an independent controller for a narrow set of processing described in the Privacy Policy: your account, security and billing records, platform telemetry, and aggregate usage statistics that identify no individual. That processing is outside this DPA.
3. Subject matter, duration, nature and purpose
Subject matter. Our provision of the STACKD platform to you: media monitoring, journalist research and contact management, drafting and sending pitches and press material, social content scheduling and publishing, SEO and coverage reporting, and the AI operators that produce drafts for your approval.
Duration. From the moment your account is created until it is closed, plus the deletion window in section 13.
Nature of the processing. Collection, recording, organisation, structuring, storage, retrieval, enrichment, analysis by automated means including large language models, transmission by email and to social platforms, erasure and destruction.
Purpose. To run public relations, communications and social media activity for your organisation, as directed by you through the platform.
Automated decision-making. STACKD scores stories and suggests journalists. These are suggestions to a human; nothing is sent, published or decided without a person in your workspace approving it. The platform performs no automated decision-making producing legal or similarly significant effects on any individual.
4. Personal data and data subjects
Categories of data subject:
- journalists, editors, producers and other media contacts you research, store or contact;
- your own people — employees, spokespeople, press contacts and anyone you name in content;
- the users you invite into your workspace;
- individuals named in third-party content we monitor for you, such as authors of articles and social posts;
- your legal reviewers and any external approver you send content to.
Categories of personal data:
- name, job title, employer or outlet, country and time zone;
- professional contact details: work email address, phone number, social handles, published profile links;
- beats, topics covered, published work and other professional interests;
- correspondence: the pitches and emails you send, and message metadata such as send, open and reply events;
- content you supply or generate that happens to name a person, including quotes, biographies and headshots;
- workspace user records: name, email address, role, authentication and access logs.
Special category data. STACKD is not built for special category personal data or criminal offence data, and you must not upload it. If your communications work genuinely requires it, contact us first at hello@stackd.bot; without a written agreement, sending it to the platform breaches this DPA.
5. Your obligations as controller
You warrant and undertake that:
- you have a lawful basis for every instruction you give us, including for outreach to journalists and for any contact list you upload;
- you comply with the direct marketing rules that apply to you and to each recipient, including UK PECR and the UK GDPR, the EU ePrivacy Directive and the EU GDPR, the US CAN-SPAM Act, and the anti-spam rules of the UAE Telecommunications and Digital Government Regulatory Authority;
- you provide the transparency information data subjects are entitled to, and can explain why any given person was contacted about any given story;
- you honour objections, opt-outs and erasure requests promptly, and suppress that contact across your workspace;
- you do not upload data you obtained unlawfully, including purchased, rented or indiscriminately scraped lists;
- your instructions do not require us to break data protection law;
- you keep your own records of processing, and carry out a data protection impact assessment where one is required.
You are responsible for what the people in your workspace do with it, including agencies and contractors you invite.
6. Our obligations as processor
We will:
- process personal data only on your documented instructions, including for international transfers, unless we are required to do otherwise by law — in which case we will tell you first, unless that law forbids it on important grounds of public interest;
- ensure that everyone authorised to process personal data is under a duty of confidentiality;
- apply the technical and organisational measures in section 7;
- engage sub-processors only as set out in section 8;
- assist you, taking account of the nature of the processing, with data subject requests (section 10), with breach notification, with data protection impact assessments and with prior consultation of a supervisory authority;
- delete or return personal data at the end, as set out in section 13;
- make available the information you reasonably need to demonstrate our compliance, and allow for audits as set out in section 11;
- not sell personal data, and not use it to train our own models or for our own marketing.
We do not use your content to train foundation models. Our AI sub-processors are contracted on terms that exclude training on data submitted through their APIs.
7. Security measures
We maintain technical and organisational measures appropriate to the risk, including:
- encryption in transit (TLS 1.2 or higher) and encryption at rest for the database, file storage and backups;
- strict tenant isolation: every record carries the account it belongs to, and every query is scoped to the signed-in user's account at the data layer;
- credentials and third-party tokens stored encrypted, never in plain text, and never exposed in the interface once saved;
- role-based access inside a workspace, with owner, admin and member roles, and two-factor authentication available to every user;
- least-privilege access for our own staff, granted only where needed for support or operations, logged, and reviewed;
- a private-network database with no public address, hosted in the European Union;
- automated backups with tested restores, and version control and code review for every change we deploy;
- audit trails for approvals, sends, publishes and administrative actions;
- vulnerability patching on a defined cadence, and dependency scanning in our build.
We may change these measures, but not in a way that materially reduces the overall level of security.
8. Sub-processors
You give general authorisation for us to engage the sub-processors below. Each is bound by a written contract imposing data protection obligations no less protective than this DPA, and we remain fully liable to you for their performance.
| Sub-processor | What it does for us | Where it processes data |
|---|---|---|
| Anthropic | AI text generation for drafts, analysis and the operators. | United States |
| OpenAI | AI text and image generation. | United States |
| Google Cloud | Application hosting, database, file storage, and Gemini AI generation. | European Union for hosting, database and storage; United States for AI generation. |
| Replicate | Image generation. | United States |
| Firecrawl | Web and news content retrieval for monitoring and research. | United States |
| Hunter.io | Verification of professional email addresses for media contacts. | European Union and United States |
| Apollo | Enrichment of professional contact records for media research. | United States |
| Stripe | Payment processing and subscription billing. | United States and European Union |
We also use the delivery, monitoring and mailbox providers listed in section 7 of the Privacy Policy, which forms part of the authorised list.
We will give you at least 30 days' notice before adding or replacing a sub-processor, by updating this page and, if you ask us to, by email to the address you nominate. If you reasonably object on data protection grounds within that period, tell us at hello@stackd.bot; if we cannot offer a workable alternative you may terminate the affected part of the service and receive a pro-rata refund of fees paid in advance.
Where you connect your own mailbox or a social account, that provider processes your data under your own agreement with them, not as our sub-processor.
9. Personal data breaches
We will notify you without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting personal data we process for you.
The notification will describe, so far as we know at the time: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for more information. Where we cannot provide all of it at once we will provide it in phases, without further undue delay.
We will help you meet your own notification duties to a supervisory authority and to affected individuals. Notifying regulators and data subjects is your decision as controller; we will not do it on your behalf without your instruction.
10. Data subject requests
If a data subject contacts us directly about personal data we process for you — a journalist asking what you hold about them, or asking to be erased — we will not respond substantively. We will pass the request to you without undue delay and tell the individual that you are the controller.
Taking account of the nature of the processing, we will help you respond, by appropriate technical and organisational measures. In practice the platform lets you find, export, correct and delete a contact's data yourself, and we will assist where a request cannot be met through the interface.
A workspace owner can request deletion of an individual's data through the tools described on the Data Deletion page.
11. Audits and information
We will make available to you the information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR and the EU GDPR, and will contribute to audits and inspections conducted by you or an auditor you appoint.
Audits are limited to once in any 12-month period unless a personal data breach or a regulator requires otherwise, must be on at least 30 days' written notice, must take place during business hours, must not disrupt our operations or the confidentiality of other customers' data, and are subject to confidentiality. Your auditor must not be a competitor of ours.
Where we hold current third-party certifications, audit reports or completed security questionnaires, providing those first is an acceptable way of meeting a request, and we will answer follow-up questions they do not cover. You bear your own costs, and our reasonable costs where an audit goes beyond one visit a year.
12. International transfers
STACKD is operated from the United Arab Emirates and hosted in the European Union. Several of the sub-processors in section 8 operate in the United States, so personal data may be transferred outside the UK and the EEA.
Where that happens we rely on:
- the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), module two (controller to processor) between you and us, and module three (processor to processor) between us and our sub-processors, which are incorporated into this DPA by reference and completed with the details in sections 1, 3, 4 and 8;
- the UK International Data Transfer Addendum to those clauses, for transfers subject to the UK GDPR, with the tables completed by the same details and no additional safeguards selected;
- an adequacy decision, where one covers the destination;
- supplementary measures: encryption in transit and at rest, access control, minimisation of the personal data actually sent to AI providers, and contractual limits on what a sub-processor may do with it.
For UAE processing we comply with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data.
Where the clauses require a choice: the governing law and the supervisory forum follow the jurisdiction whose law applies to the transfer, docking is permitted, and the optional clause on liability to data subjects applies.
13. Return and deletion at the end
You can export your data at any time while the account is open. On termination, you have 30 days to export it.
After that, we delete personal data we process for you from live systems within a further 30 days, and from encrypted backups within 90 days of termination, when the backup cycle rotates. Until they rotate, backups stay encrypted and are not used for any other purpose.
We keep only what law requires us to keep — billing and tax records, and records needed to establish or defend a legal claim — and only for as long as that requires. Aggregate statistics that identify no individual may be retained.
We will confirm deletion in writing if you ask.
14. Liability, changes and law
The liability provisions of the Terms of Service apply to this DPA. Nothing here limits liability that cannot lawfully be limited, including liability to data subjects under Article 82 of the UK GDPR and the EU GDPR.
We may update this DPA to reflect changes in the platform, our sub-processors or the law. Material changes are announced in the app and by email to workspace owners before they take effect. The version and date at the top of this page tell you which text is in force.
This DPA is governed by the laws of England and Wales, except where the Standard Contractual Clauses or the UK Addendum require otherwise for a particular transfer.
Questions, objections to a sub-processor, audit requests and breach correspondence all go to hello@stackd.bot, or by post to STACKD, Dubai, United Arab Emirates.
This document is a first draft prepared for review by STACKD's legal advisers. It is not legal advice to you.