Version 1.0
This Data Processing Agreement is between Stellafai Limited, company number 14052184 (“Stellafai”), and the organisation or individual subscribing to the Services under an agreement with Stellafai (“Customer”). The applicable subscription, order form or service agreement is referred to as the “Agreement”.
This DPA is incorporated into the Agreement where the Agreement refers to it or the parties otherwise agree to its incorporation in writing, including electronically. It takes effect when that incorporation becomes effective and applies to Stellafai’s processing of personal data on the Customer’s behalf. It does not require a separate customer-specific signature page.
Data protection enquiries: Tim Beattie, tim@stellafai.com.
1. Scope and interpretation
1.1 This Data Processing Agreement (“DPA”), including its schedules, forms part of the Agreement and governs Stellafai’s processing of Customer Personal Data in providing the Services. It prevails over inconsistent terms of the Agreement concerning that processing, including general permissions to use customer content, disclose information, appoint subcontractors or transfer data. Mandatory provisions of an applicable international transfer instrument prevail over conflicting provisions of this DPA.
1.2 “Data Protection Laws” means the UK GDPR and Data Protection Act 2018, as amended, including by applicable provisions of the Data (Use and Access) Act 2025 as brought into force, and the EU GDPR and other data protection legislation to the extent applicable to the processing. “Controller”, “processor”, “personal data”, “processing”, “data subject”, “personal data breach” and “supervisory authority” have their meanings under those laws.
1.3 “Customer Personal Data” means personal data processed by Stellafai on the Customer’s behalf in connection with the Services, including personal data within uploaded content, objectives, updates, coaching materials, AI inputs and outputs, stored conversations and derived records. Embeddings and pseudonymised records remain covered where they constitute personal data. “Subprocessor” means a processor engaged by Stellafai to process Customer Personal Data. “Services” means the platform and related services specified in Schedule 1.
1.4 Each party shall comply with its applicable obligations under Data Protection Laws. Ordinarily, the Customer is controller and Stellafai is processor. Where the Customer acts as processor, Stellafai acts as its subprocessor; the Customer shall identify the controller and ensure that its instructions and appointment of Stellafai are authorised by that controller. The parties’ actual activities determine their roles.
1.5 This DPA does not govern the limited personal data Stellafai independently processes as controller for its own billing, corporate administration and legal compliance, as described in its applicable privacy notice. That distinction does not permit Stellafai to repurpose Customer Personal Data or exclude service content, support records or logs processed on the Customer’s behalf from this DPA.
2. Customer instructions and responsibilities
2.1 The Agreement, this DPA, the schedules and subsequent written instructions from authorised Customer representatives constitute the Customer’s documented instructions. User actions within approved features are instructions only within that agreed scope. A user action cannot override an agreed restriction on AI use, providers, data categories or processing locations.
2.2 Stellafai shall process Customer Personal Data only on those instructions, including in relation to international transfers, unless required otherwise by applicable law binding on Stellafai. Where legally permitted, Stellafai shall inform the Customer of that requirement before processing.
2.3 Stellafai shall immediately inform the Customer if, in its opinion, an instruction infringes Data Protection Laws. It may suspend the affected processing while the parties resolve the issue, preserving and protecting the data during that period.
2.4 The Customer shall establish a lawful basis, provide required notices, ensure it has authority to supply the data and give instructions, and limit information and access to what is necessary for the agreed purpose. The Customer shall not submit special category or criminal offence data without the written agreement described in Schedule 1. These responsibilities do not reduce Stellafai’s own obligations.
3. Confidentiality and security
3.1 Stellafai shall restrict access to persons who need it to provide the Services. Persons authorised to process Customer Personal Data shall be subject to contractual confidentiality obligations or an appropriate statutory duty, and receive instructions appropriate to their responsibilities.
3.2 Stellafai shall maintain technical and organisational measures appropriate to the risk, taking account of the nature, scope, context and purposes of processing, implementation costs and the state of the art. Those measures shall address confidentiality, integrity, availability, resilience, restoration following incidents and regular evaluation of effectiveness. The agreed measures are set out in Schedule 2.
3.3 Stellafai shall maintain logical separation between customer environments and restrict support and administrative access. It shall not make Customer Personal Data available in another customer’s workspace, shared knowledge base or AI retrieval context without the Customer’s specific documented instruction and an appropriate lawful basis.
3.4 Stellafai may improve or replace security measures provided that the overall level of protection is not materially reduced. Material changes affecting agreed protections shall be notified to the Customer before implementation, except urgent protective changes, which shall be notified promptly afterwards.
4. Subprocessors
4.1 The Customer grants general written authorisation for the subprocessors identified in Stellafai’s subprocessor register made available to the Customer before this DPA takes effect, subject to the change procedure below. The register in Schedule 3 forms part of this DPA. Supplementary provider information is available by contacting tim@stellafai.com. It shall identify each subprocessor’s legal entity, service, processing activities, relevant data, locations and transfer arrangements. Authorisation applies only to the Services the Customer uses. AI processing is additionally subject to clause 6.
4.2 Stellafai shall give at least 30 days’ advance written notice of an intended addition or replacement, including enough information for the Customer to assess its effect. The Customer may object during that period on reasonable data protection grounds. Stellafai shall work with the Customer to resolve the objection and shall not disclose the affected data to the proposed subprocessor while the objection remains unresolved.
4.3 If no reasonable alternative can be agreed, either party may terminate the affected Services by written notice before the change takes effect. Stellafai shall refund prepaid fees for the unused terminated portion. Changes involving an AI provider also require the approval specified in clause 6.
4.4 Before permitting processing, Stellafai shall bind each subprocessor by a written agreement imposing data protection obligations equivalent in substance to those applicable to its processing under this DPA, including appropriate security, confidentiality, assistance and deletion obligations. Stellafai remains responsible to the Customer for its subprocessors’ performance of those obligations.
5. Locations and international transfers
5.1 The agreed storage and processing locations, including backup and remote support locations, shall be recorded in the subprocessor register. UK hosting of the core platform is not a representation that all service processing occurs exclusively in the UK.
5.2 Stellafai shall make a restricted international transfer only on documented instructions and in compliance with the applicable transfer requirements. Before a transfer begins, it shall identify and implement a valid mechanism, such as applicable adequacy arrangements, the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum where required. Where EU GDPR applies, the applicable EU transfer requirements shall also be satisfied.
5.3 Stellafai shall complete any required transfer assessment and supplementary protections, and make relevant compliance information available to the Customer. Naming a mechanism in this DPA does not execute that instrument: the appropriate parties, modules, annexes and safeguards must be completed and binding before reliance on it.
5.4 Access from another country shall be assessed as well as physical storage. A change to agreed locations or safeguards requires prior notice and any authorisation required under this DPA. If a mechanism becomes invalid or protection cannot be maintained, Stellafai shall suspend the affected transfer until lawful safeguards or an alternative arrangement are established.
6. Optional AI and Stan processing
6.1 AI use and ingestion into Stan shall be manually triggered and performed only with the subscriber’s documented authorisation. That authorisation shall identify the features, providers, data categories, routing and purposes approved through the Customer’s documented instructions, including an electronic authorisation or written variation. Where the subscriber acts for another controller, it shall obtain that controller’s required authority before authorising processing. A manual trigger by an authorised user implements only an already authorised scope; it does not authorise additional purposes, sources or providers. Approval of the core platform does not itself authorise AI processing. In this clause, authorisation is a contractual processing instruction, not a substitute for any lawful basis or data subject consent required under Data Protection Laws.
6.2 Until the required authorisation has been given, and whenever AI is disabled, Stellafai shall prevent Customer Personal Data from being sent for model inference or embedding generation, and shall disable ingestion, synchronisation and indexing into Stan for the affected Customer workspace. This obligation includes background jobs, webhooks and integrations, not only visible chat controls. Handling of any previously ingested data shall follow the Customer’s documented instructions and the deletion provisions below.
6.3 Where approved, AI processing may involve sending a user’s prompt, relevant conversation history and selected authorised context to the approved model provider. Separately approved knowledge-base processing may split content into passages, generate embeddings and store passages, metadata and embeddings for later retrieval. Conversation and operational logging shall be limited to the approved purposes and retention periods.
6.4 Stellafai shall minimise the data disclosed to what is reasonably necessary for the approved feature. It shall not represent data as anonymous merely because direct identifiers have been removed or embeddings generated. The information provided before authorisation shall identify any intermediary or gateway as well as the ultimate model provider, the processing locations, data categories and applicable retention arrangements.
6.5 Stellafai’s AI subprocessors (currently OpenAI) shall not use Customer Personal Data to train, fine-tune or otherwise improve their general-purpose AI models. Stellafai shall require contractual protections and maintain service configurations that give effect to this restriction.
6.5(a) OpenAI’s API data controls and enterprise privacy commitments state that data submitted through its API is not used to train or improve its models by default, unless the customer explicitly opts in. Stellafai confirms that it has not opted in to any OpenAI data-sharing or model-improvement programme and shall not opt in in respect of Customer Personal Data. OpenAI’s processing is subject to its applicable Data Processing Addendum. These no-training protections do not mean that data is never retained: any retention for abuse monitoring or service operation must be disclosed separately under this DPA.
6.5(b) Stellafai shall not use Customer Personal Data to train, fine-tune or develop any AI or machine learning model. Stellafai may use Customer Personal Data to maintain and improve the Services, including their AI functionality, only within the Customer’s documented instructions under clause 2 and in accordance with Data Protection Laws. Any such use must respect the agreed purposes, data categories, access restrictions and retention periods; it does not authorise model training, cross-customer evaluation or use beyond those instructions. Stellafai’s processing of personal data as an independent controller is described in its Privacy Policy, subject to the distinction in clause 1.5.
Provider references: OpenAI Enterprise Privacy, OpenAI Data Processing Addendum, and OpenAI API Platform Data Controls. Stellafai Privacy Policy.
6.6 Stellafai shall not silently switch to an unapproved model provider, gateway or processing location, including as a fallback. If an approved route is unavailable, the affected feature shall be suspended or use another route already expressly approved for that processing.
6.7 AI outputs may contain personal data and shall receive the same applicable protection as inputs. The Services are intended to assist human judgement. The Customer shall review outputs and shall not use the Services for solely automated decisions producing legal or similarly significant effects on individuals unless separately agreed with all legally required safeguards.
7. Personal data breaches
7.1 Stellafai shall notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Notification shall not be delayed until an investigation is complete.
7.2 As information becomes available, Stellafai shall describe the nature of the breach, affected data and data subjects and approximate numbers where possible, likely consequences, mitigation taken or proposed, and a contact for further information. It shall provide updates, preserve relevant evidence and cooperate with the Customer’s investigation, containment and recovery.
7.3 The Customer determines notifications to authorities and data subjects in its role as controller, or assists its controller where applicable. Stellafai shall provide the assistance needed to meet applicable deadlines and shall not communicate on the Customer’s behalf without instructions unless legally required to do so.
8. Assistance and accountability
8.1 Taking account of the nature of processing, Stellafai shall provide appropriate technical and organisational assistance to enable responses to data subject rights requests. It shall promptly forward requests relating to Customer Personal Data and shall not respond substantively except on instructions or as required by law.
8.2 Taking account of the processing and information available to it, Stellafai shall assist the Customer with security obligations, breach assessment and notifications, data protection impact assessments and prior consultation with supervisory authorities.
8.3 Stellafai shall make available information necessary to demonstrate compliance and allow and contribute to audits, including inspections, by the Customer or its mandated auditor. The parties shall use existing assurance material where sufficient and agree reasonable confidentiality, notice and access arrangements that protect other customers without preventing effective verification.
8.4 Routine audits should ordinarily occur no more than annually. This does not restrict additional audits reasonably required following a breach, credible evidence of non-compliance, a material processing change or a supervisory authority’s request. Urgency and statutory deadlines take precedence over routine notice arrangements.
8.5 Reasonable charges for exceptional assistance may be agreed in advance, but shall not apply to remedying Stellafai’s breach, prevent mandatory assistance or delay compliance with legal deadlines.
9. Retention, return and deletion
9.1 Stellafai shall retain Customer Personal Data only for the approved processing and periods specified in this DPA and the retention information provided for the applicable Services. At the end of the Services, the Customer may choose return followed by deletion, or deletion without return. Export content, recipients and a commonly usable format shall be agreed before closure.
9.2 Stellafai shall delete live Customer Personal Data within 30 days of termination, following any requested return within that period. Deletion shall cover relevant production systems and approved downstream providers, including Stan source records, content passages, embeddings, conversation records and associated files where used. Any different provider deletion interval must be expressly disclosed in the subprocessor register and agreed with the Customer before processing begins.
9.3 Backup copies shall be isolated from ordinary use and expire under the applicable backup retention schedule disclosed to the Customer before processing begins. If restored for recovery, outstanding deletion instructions shall be reapplied before the restored data is made available for ordinary use. This DPA continues to protect backup data until deletion.
9.4 Data required to be retained by law shall be limited to what that law requires, protected and used only for that purpose, and deleted when the requirement ends. Stellafai shall notify the Customer of the basis and period unless prohibited by law.
9.5 Stellafai shall confirm completion on request, identifying any lawful retained records or backups awaiting their agreed expiry. Switching AI off does not itself constitute deletion of previously processed information.
10. Duration and contractual effect
10.1 This DPA applies from the effective date and continues for as long as Stellafai or its subprocessors retain Customer Personal Data.
10.2 Subject to clause 1.1 and mandatory law, the Agreement’s provisions on liability apply to this DPA. No contractual restriction limits rights of data subjects, supervisory authority powers or liabilities that cannot lawfully be restricted.
10.3 The law of England and Wales and its courts apply, subject to mandatory rights and the requirements of any applicable transfer instrument. Stellafai may publish updated versions of this DPA. A revised version becomes binding on an existing Customer only through the amendment procedure in the Agreement or a written agreement between the parties. Publication alone does not change an existing Customer’s terms. The subprocessor change process in clause 4 continues to apply independently.
Schedule 1 — Description of processing
Subject matter: Provision of Stellafai’s outcome tracking, strategic alignment and coaching platform and the expressly agreed related services
Purpose: Manage objectives, key results, measures, ownership, progress updates, supporting activities and reporting; provide authorised support and exports; optional AI assistance only as authorised under clause 6
Nature: Collection, recording, organisation, storage, retrieval, display, access management, updating, reporting, export, transmission to approved subprocessors, and deletion; AI inference and indexing only where approved
Duration: Agreement term plus the defined return, deletion and backup-expiry periods
Data subjects: Customer personnel, authorised users, consultants and coaches; other business contacts only where necessary for the agreed Services
Personal data: Names, business contact details, roles, identifiers, access information, ownership and participation records, objectives and progress attributable to individuals, comments, blockers, activity and coaching notes, and agreed supporting material; necessary service and security metadata
Optional AI data: Approved prompts, conversation history, relevant workspace or coaching content, outputs, content passages, embeddings and source metadata, within the scope authorised under clause 6
Excluded by default: Special category data, criminal offence data, children's data, and detailed HR case files; no unrestricted permission to upload any category of information
Exceptional sensitive data: Requires a written variation specifying necessity, categories, lawful conditions, restrictions, safeguards and retention before submission
Controller, where Customer is processor: The Customer’s client or other controller on whose behalf the Customer is authorised to use the Services; the Customer shall identify that controller to Stellafai in its documented instructions
Authorised instructors and recipients: The Customer’s authorised representatives and users acting within their assigned permissions and the Customer’s instructions; consultants and coaches receive access only within that authorised scope
Schedule 2 — Technical and organisational measures
The following measures apply to the Services as described. Hosting locations for Stan differ from those of the core platform.
Core hosting: Microsoft Azure, UK South, United Kingdom
Stan application hosting: Vercel production functions in iad1, Washington, D.C., United States
Stan database: Supabase database hosted in AWS us-east-1, Northern Virginia, United States
Core platform encryption: TLS 1.2 or higher in transit; AES-256 encryption at rest within the Azure hosting environment; encrypted backups
Key management: Azure-managed encryption and Azure Key Vault infrastructure, with access restricted to authorised engineering personnel; customer-managed keys are not currently supported
Separation and permissions: Logical separation of customer spaces, role-based access and restriction of support and administrative access to authorised personnel who need it for service delivery
Sign-in: Microsoft Entra ID enterprise single sign-on can be enabled; Google sign-in is supported. Customers using single sign-on may enforce MFA through their identity provider
Local accounts: Local-account MFA is not currently enabled. Minimum password length is six characters; accounts lock after five unsuccessful attempts. Password history and expiry are not currently enforced
Personnel: Confidentiality obligations, information-handling responsibilities at onboarding, and access provisioning and removal processes
Assurance: Security review and vulnerability assessment activities; an independent technical review took place in May 2026. Stellafai does not hold ISO 27001 or other formal security certification; infrastructure-provider certifications do not certify Stellafai
Return and deletion: Customer-directed return or deletion under clause 9, including deletion of live Customer Personal Data within 30 days of termination and protection of backups until expiry
The hosting regions above identify core hosting, Stan production functions and the Stan database respectively. They do not describe every backup, support, model-provider, gateway or logging location. Those processing activities and locations shall be disclosed through the subprocessor register and applicable service information before the relevant processing is authorised.
Supabase’s API uses Cloudflare’s global edge network. The location of an API edge response does not change the US location of the underlying database. The applicable provider subprocessor chain and safeguards govern that edge processing.
Stellafai shall apply the risk-appropriate security obligations in clause 3 to all Customer Personal Data, including data handled by supplementary services and approved AI providers. Customers may request further security, retention and transfer information at tim@stellafai.com.
Schedule 3 — Subprocessor register
Provider use confirmed: 16 September 2026. The providers below are used by Stellafai. Each processes Customer Personal Data only where relevant to the Services provided to that Customer; listing a provider does not authorise every feature or data category. Optional AI and Stan processing remain subject to clause 6 and the subscriber’s documented authorisation.
Platform and optional AI services
Microsoft Azure — Core platform hosting. Hosting, database and storage services for platform records and associated service metadata. Core hosting region: UK South, United Kingdom.
Vercel — Stan application hosting. Hosting of Stan application functions and processing of requests, approved content and related operational metadata. Production functions run in iad1, Washington, D.C., United States. Any AI gateway use and routing must be disclosed within the authorisation for the relevant AI feature.
Supabase — Stan database. Storage of approved source content, content passages, embeddings, metadata and conversation records. Database location: AWS us-east-1, Northern Virginia, United States.
OpenAI — Optional AI inference and embeddings. Processing of approved prompts, relevant conversation history, selected context and source passages for AI responses and embedding generation. Use requires the authorisation in clause 6. Model-processing locations, retention and transfer arrangements must be disclosed for the approved service before processing begins.
Communications, support and service operations
Customer.io — Customer communications. Contact details and communication-related event data used to deliver and manage customer communications on the Customer’s behalf.
Mailjet — Email delivery. Recipient contact details, message content and delivery metadata used to send service-related emails.
Intercom — Customer support. User identification, contact details, support conversations and information supplied for support. Any AI processing of Customer Personal Data within support services remains subject to clause 6.
Hotjar — Usage and experience analytics. User, device and interaction information used for service analytics, to the extent it constitutes Customer Personal Data. Actual collection is subject to the applicable configuration and notices; this entry does not authorise unrestricted capture of customer content.
Loom — Video communications and support. Video, audio, screen content and associated participant or viewer information where used to provide the Services and containing Customer Personal Data.
Downstream infrastructure
Amazon Web Services (AWS) provides infrastructure for the Supabase database in Northern Virginia, United States. Cloudflare provides Supabase’s global API edge network. These are identified here as providers within Supabase’s supply chain, rather than as direct Stellafai appointments for those activities. A UK edge response does not establish UK database residency. The applicable provider agreements govern their onward appointment and safeguards.
Provider scope and supplementary details
The names above identify the services used. Exact contracting legal entities, additional processing and support countries, backup and log locations, retention periods and applicable transfer arrangements must be recorded in the supplementary provider information made available before the relevant processing is authorised. The regions expressly stated above describe the specified hosting functions only and do not imply that all processing occurs there. Clauses 4 and 5 apply to the register and its supplementary information.
Anthropic and xAI are not currently enabled for customer data and are not included as authorised subprocessors. Enabling either would require the subprocessor change procedure in clause 4 and the AI authorisation in clause 6.
See also: Privacy Policy and Terms of Service.