In plain words
- This addendum applies automatically when Stiro processes personal data for you. There is nothing to sign.
- We process End Users' personal data only on your instructions, to provide the Service, and never for our own purposes.
- We will tell you of a personal data breach without undue delay, and within 72 hours of confirming it.
- EU, UK and Swiss transfers are covered by the Standard Contractual Clauses, which are included by reference.
- The liability limits in the Terms apply to this addendum as well.
This summary helps you read the document. It is not part of it, and the full text below governs.
1. Scope and parties
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Stiro, run by a sole proprietorship based in India, and the Customer. It applies when Stiro processes personal data on the Customer’s behalf in providing the Service, and it takes effect when the Customer accepts the Terms. Words not defined here have the meanings given in the Terms or in the applicable Data Protection Law.
“Data Protection Law” means all laws that apply to the processing of Customer Personal Data under the Terms, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, India’s Digital Personal Data Protection Act, 2023, and US state privacy laws, in each case as amended. “Customer Personal Data” means personal data in Customer Data that Stiro processes as a processor.
2. Roles and instructions
- The Customer is the controller (or a processor acting for its own controller), and Stiro is the processor (or sub-processor) of Customer Personal Data.
- Stiro will process Customer Personal Data only on the Customer’s documented instructions. Those instructions are the Terms, this DPA, and the Customer’s use and configuration of the Service. Stiro will tell the Customer if it believes an instruction breaks Data Protection Law. Stiro may then decline to follow the instruction, without liability.
- If the law requires Stiro to process Customer Personal Data for another purpose, Stiro will tell the Customer first, unless the law forbids it.
- The Customer is responsible for the lawfulness of its instructions, and for providing notices to and obtaining any consents from End Users. It also remains responsible for the accuracy of Customer Personal Data and for how it was obtained.
- Stiro will not sell or share Customer Personal Data, or retain, use or disclose it outside the direct business relationship with the Customer, or combine it with personal data from other sources, except as Data Protection Law allows a service provider or processor to do.
3. Confidentiality
Stiro will ensure that everyone it authorises to process Customer Personal Data is bound by an appropriate duty of confidentiality.
4. Security
Stiro will implement and maintain appropriate technical and organisational measures to protect Customer Personal Data, including those in Annex II. Stiro may update them, provided the overall level of protection is not materially reduced.
5. Sub-processors
- The Customer gives Stiro general authorisation to engage sub-processors. The current list is on our Data Use page, which forms Annex III.
- Stiro will bind each sub-processor by a written contract to data protection obligations no less protective than this DPA, as far as they apply to its service. Stiro remains responsible to the Customer for each sub-processor’s performance of those obligations.
- Stiro will update the list before a new sub-processor starts processing Customer Personal Data, and will email Customers who have asked for notice at [email protected] at least 14 days in advance. Within that time the Customer may object on reasonable data protection grounds. The parties will then discuss the objection in good faith. If it is not resolved, the Customer may end the affected Service as its sole remedy, and will receive a refund of prepaid fees for the unused period, as our Refund and Cancellation Policy provides.
6. Assistance
Taking into account the nature of the processing and the information available to it, Stiro will give the Customer reasonable assistance:
- with requests from data subjects. Stiro will pass on any request it receives about Customer Personal Data and will not answer it except on the Customer’s instructions;
- with security, data protection impact assessments and consultations with supervisory authorities, where the law requires them; and
- with records, by providing the information in Annex I.
Assistance that goes beyond the Service’s normal features may be charged at reasonable cost.
7. Personal data breaches
Stiro will notify the Customer without undue delay, and in any event within 72 hours, after confirming a personal data breach affecting Customer Personal Data. As information becomes available, Stiro will describe the nature of the breach, the data and data subjects concerned, its likely consequences, and the measures taken or proposed. Stiro will take reasonable steps to contain the breach and reduce its effects. Notifying the Customer is not an admission of fault or liability.
8. Deletion and return
When the Terms end, or earlier at the Customer’s written request, Stiro will delete Customer Personal Data within 30 days, except where the law requires Stiro to keep it. Copies in encrypted backups are deleted as the backups expire, within a further 35 days. Until then they are protected and not processed further. On a request made before the Terms end, Stiro will provide an export of the Customer Personal Data it stores, in a common format.
9. Audits
Stiro will make available the information reasonably necessary to demonstrate compliance with this DPA. The Customer agrees to exercise its audit rights first by reviewing this information and Stiro’s written answers to a reasonable security questionnaire, no more than once a year. If a supervisory authority requires it, or this information is genuinely insufficient, the Customer may carry out an audit on 30 days’ written notice, during business hours, at its own cost, and under a duty of confidentiality. The audit may not access other customers’ data or compromise security, and may be carried out by an independent auditor who is not a competitor of Stiro.
10. International transfers
- Stiro processes Customer Personal Data in India and the United States, and its sub-processors in the locations listed in Annex III.
- EEA. For transfers of Customer Personal Data from the European Economic Area to a country without an adequacy decision, the parties incorporate the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 (“SCCs”): Module Two (controller to processor), or Module Three (processor to processor) where the Customer is a processor. For the SCCs:
- Clause 7 (docking) does not apply;
- under Clause 9, option 2 (general written authorisation) applies, with notice as described in section 5 of this DPA;
- the optional wording in Clause 11 does not apply;
- under Clause 13, the supervisory authority is the one competent for the Customer;
- under Clauses 17 and 18, the governing law and the courts are those of Ireland; and
- Annexes I to III of this DPA complete the SCCs’ Annexes.
- United Kingdom. For transfers from the UK, the SCCs apply as amended by the UK International Data Transfer Addendum (version B1.0), with Tables 1 to 3 completed from this DPA and either party able to end it under Section 19.
- Switzerland. For transfers from Switzerland, the SCCs apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, and the Swiss Federal Data Protection and Information Commissioner as the competent authority.
- If the SCCs conflict with this DPA or the Terms, the SCCs prevail.
11. Liability and precedence
Stiro’s liability under or in connection with this DPA and the SCCs is subject to the limitations and exclusions in the Terms, as far as Data Protection Law allows. If this DPA conflicts with the Terms, this DPA prevails as to the processing of Customer Personal Data. This DPA lasts as long as Stiro processes Customer Personal Data under the Terms.
Annex I: Details of processing
- Data exporter: the Customer, as identified in its account.
- Data importer: Stiro, run by a sole proprietorship based in India (postal address: available on request from [email protected]), contact [email protected].
- Subject matter and nature: an in-app AI agent that carries out End Users’ requests inside the Customer’s application: reading page content, deciding steps with AI models, and performing them in the End User’s browser.
- Purpose: to provide, secure and support the Service under the Terms.
- Duration: the term of the Terms, plus the deletion period in section 8.
- Frequency: continuous, whenever End Users make requests.
- Categories of data subjects: End Users of the Customer’s application, and any people whose data appears on the pages they use.
- Categories of personal data: request text, and audio when an End User speaks a request (transcribed, not stored); page content, including names, contact details and other data the Customer’s application shows; a keyed hash of the end-user id the Customer’s application passes, if any; IP addresses (transiently). The Customer determines what its pages contain.
- Special categories: none intended. The Customer must not enable the Service on pages showing special categories of data unless it has a lawful basis and appropriate safeguards (see the Terms).
- Retention: as described on the Data Use page.
- Sub-processors: see Annex III.
Annex II: Technical and organisational measures
- Encryption: TLS for all data in transit. Encryption at rest for the database and for backups (AES-256).
- Isolation: each Customer’s data is logically isolated from other Customers’ data.
- Minimisation: values of password fields, and of recognisable payment and ID fields, are never collected. Page content is not stored, and End User requests only as a summary with entered values replaced by placeholders, unless the Customer asks for full requests to be kept. Stored data about the Customer’s application is processed to remove identifiers and personal data. AI models are used only on terms that forbid training, with zero data retention wherever the provider offers it.
- Access control: production access is limited to authorised personnel with multi-factor authentication, on least-privilege terms. Customer site keys are restricted to allowed origins.
- Credentials: passwords are stored only as one-way hashes, and site secrets encrypted.
- Resilience: daily encrypted backups, kept separately and protected against deletion, and point-in-time recovery for the database.
- Monitoring: health checks and alerting, with rate limiting and abuse detection.
- Logging: server logs are designed to exclude request text, page content and tokens, and are kept in a small rolling buffer that overwrites the oldest entries.
- Vendor management: sub-processors are bound by contracts with data protection terms.
Annex III: Sub-processors
The current list is kept on our Data Use page.