Last Updated: March 10, 2026
About This Agreement: This Data Processing Agreement ("DPA") is available to all StallWise customers and is automatically incorporated into Enterprise subscription agreements. Starter and Professional customers who require a DPA may request its inclusion by contacting
[email protected].
1. Definitions
For the purposes of this Data Processing Agreement:
- "Controller" (also "Data Controller") means the entity that determines the purposes and means of processing Personal Data. In the context of this DPA, the Controller is you, the customer.
- "Processor" (also "Data Processor") means the entity that processes Personal Data on behalf of the Controller. In the context of this DPA, the Processor is Showsafe LLC.
- "Personal Data" means any information relating to an identified or identifiable natural person, as defined by applicable data protection laws including the GDPR.
- "Processing" means any operation performed on Personal Data, including collection, recording, storage, retrieval, use, disclosure, alteration, or destruction.
- "Sub-Processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
- "Data Subject" means the identified or identifiable natural person to whom Personal Data relates.
- "GDPR" means Regulation (EU) 2016/679, the General Data Protection Regulation.
- "Applicable Data Protection Laws" means all laws and regulations applicable to the processing of Personal Data, including the GDPR, UK GDPR, CCPA/CPRA, and any other applicable privacy laws.
- "Service Agreement" means the Terms of Service and any applicable subscription agreement between the Controller and the Processor.
- "Security Incident" means any unauthorized or unlawful processing, access, disclosure, alteration, loss, or destruction of Personal Data.
2. Scope and Purpose
2.1 Scope
This DPA applies to all Processing of Personal Data by the Processor on behalf of the Controller in connection with the provision of the StallWise service under the Service Agreement.
2.2 Purpose of Processing
The Processor shall process Personal Data solely for the purpose of providing the Service as described in the Service Agreement, including:
- Storing and managing equestrian facility data, horse records, client information, and staff information.
- Processing financial transactions and maintaining billing records.
- Delivering notifications, alerts, and communications within the Service.
- Generating reports and analytics as requested by the Controller.
- Providing technical support and maintaining the Service.
- Ensuring the security and integrity of the Service.
2.3 Categories of Data Subjects
Personal Data processed under this DPA may relate to the following categories of Data Subjects:
- The Controller's employees and staff members
- The Controller's clients and their employees
- Horse owners and riders
- Trainers and instructors
- Veterinarians, farriers, and other service providers
- Event participants and attendees
2.4 Types of Personal Data
| Category |
Data Types |
| Identity Data |
Names, titles, roles, photographs |
| Contact Data |
Email addresses, phone numbers, physical addresses |
| Financial Data |
Invoice details, payment records, billing history (card details processed by Stripe) |
| Professional Data |
Business names, roles, certifications, license numbers |
| Operational Data |
Schedule information, task assignments, communication records |
| Technical Data |
IP addresses, browser data, device information, usage logs |
3. Obligations of the Processor
3.1 Processing Instructions
The Processor shall:
- Process Personal Data only on documented instructions from the Controller, including with respect to transfers of Personal Data to a third country, unless required to do so by applicable law.
- Immediately inform the Controller if, in the Processor's opinion, an instruction infringes applicable data protection laws.
- Not process Personal Data for any purpose other than as specified in this DPA and the Service Agreement.
3.2 Confidentiality
The Processor shall ensure that all persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
3.3 Security Measures
The Processor shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
Technical Measures
- Encryption in Transit: All data transmitted between clients and servers uses TLS 1.2 or higher.
- Encryption at Rest: All stored Personal Data is encrypted using AES-256.
- Access Controls: Role-based access controls with least-privilege principles.
- Authentication: Strong password requirements, hashed password storage (bcrypt), and session management.
- Network Security: Firewalls, intrusion detection systems, and DDoS protection (Cloudflare).
- Vulnerability Management: Regular security scanning and patching of systems.
- Logging and Monitoring: Comprehensive access logging and anomaly detection.
- Backup and Recovery: Regular encrypted backups with tested recovery procedures.
- Data Isolation: Logical separation of customer data with user-scoped queries.
Organizational Measures
- Confidentiality agreements for all employees and contractors with access to Personal Data.
- Access to Personal Data limited to authorized personnel on a need-to-know basis.
- Regular security awareness training for staff.
- Documented security policies and procedures.
- Incident response plans and procedures.
- Regular review and testing of security measures.
3.4 Assistance to the Controller
The Processor shall assist the Controller in:
- Responding to requests from Data Subjects exercising their rights under applicable data protection laws (access, rectification, erasure, restriction, portability, objection).
- Ensuring compliance with obligations regarding security of processing, notification of Security Incidents, data protection impact assessments, and prior consultation with supervisory authorities.
- Providing information necessary to demonstrate compliance with the obligations set out in this DPA.
3.5 Data Deletion and Return
Upon termination of the Service Agreement or upon request by the Controller:
- The Processor shall, at the Controller's choice, return all Personal Data to the Controller in a structured, commonly used, machine-readable format or delete all Personal Data.
- Data export is available in CSV and PDF formats through the Service interface.
- Following confirmed deletion, Personal Data may persist in encrypted backups for up to 90 days, after which it will be permanently removed through backup rotation.
- The Processor shall certify deletion upon request.
4. Sub-Processors
4.1 Authorized Sub-Processors
The Controller provides general authorization for the Processor to engage Sub-Processors, subject to the requirements of this section. The current list of Sub-Processors is:
| Sub-Processor |
Purpose |
Location |
Data Processed |
| Cloud Infrastructure Provider |
Hosting, compute, and data storage |
United States |
All Service data (encrypted) |
| Stripe, Inc. |
Payment processing |
United States |
Payment card details, billing addresses, transaction data |
| Email Service Provider |
Transactional email delivery |
United States |
Email addresses, names, email content |
| Cloudflare, Inc. |
CDN, security, DNS |
Global (edge locations) |
IP addresses, request metadata |
4.2 New Sub-Processors
The Processor shall:
- Notify the Controller at least 30 days in advance before engaging a new Sub-Processor or replacing an existing one.
- Provide the Controller with information about the new Sub-Processor, including its identity, location, and the processing activities to be performed.
- Allow the Controller to object to the new Sub-Processor within 14 days of notification.
4.3 Objection to Sub-Processors
If the Controller objects to a new Sub-Processor on reasonable grounds related to data protection:
- The Processor shall make reasonable efforts to provide an alternative solution that does not involve the objected-to Sub-Processor.
- If no alternative is available and the Sub-Processor is necessary for the provision of the Service, either party may terminate the affected portion of the Service Agreement with 30 days' notice, and the Controller shall receive a pro-rated refund for any prepaid fees.
4.4 Sub-Processor Agreements
The Processor shall enter into written agreements with each Sub-Processor imposing data protection obligations no less protective than those set out in this DPA. The Processor remains fully liable to the Controller for the performance of each Sub-Processor's obligations.
5. International Data Transfers
5.1 Transfer Mechanisms
The Service is hosted and operated in the United States. For transfers of Personal Data from the EEA, UK, or Switzerland to the United States, the Processor relies on:
- Standard Contractual Clauses (SCCs): The European Commission's Standard Contractual Clauses (Module Two: Controller to Processor) are incorporated into this DPA by reference and shall apply to relevant data transfers.
- UK International Data Transfer Agreement (IDTA): For transfers from the UK, the UK IDTA addendum to the EU SCCs is incorporated.
- Supplementary Measures: The Processor implements technical supplementary measures including encryption in transit and at rest, access controls, and data minimization.
5.2 Transfer Impact Assessment
The Processor has conducted a transfer impact assessment and has determined that the implemented technical and organizational measures, combined with the applicable transfer mechanisms, provide an adequate level of protection for Personal Data transferred to the United States.
6. Security Incidents
6.1 Notification
The Processor shall notify the Controller without undue delay and in any event within 48 hours after becoming aware of a Security Incident involving Personal Data processed under this DPA. The notification shall include:
- A description of the nature of the Security Incident, including the categories and approximate number of Data Subjects and records affected.
- The name and contact details of the Processor's point of contact for further information.
- A description of the likely consequences of the Security Incident.
- A description of the measures taken or proposed to be taken to address the Security Incident and mitigate its effects.
6.2 Cooperation
The Processor shall cooperate with and assist the Controller in:
- Investigating and remediating the Security Incident.
- Fulfilling the Controller's obligations to notify supervisory authorities and Data Subjects as required by applicable law.
- Documenting the Security Incident and the response measures taken.
6.3 Limitations
The Processor's obligation to notify does not extend to Security Incidents that are unlikely to result in a risk to the rights and freedoms of Data Subjects (e.g., encrypted data accessed without the decryption key).
7. Audits and Inspections
7.1 Audit Rights
The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations set out in this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.
7.2 Audit Procedures
- Audit requests must be submitted in writing with at least 30 days' advance notice.
- Audits shall be conducted during normal business hours and shall not unreasonably disrupt the Processor's operations.
- The Controller shall bear the costs of audits unless the audit reveals material non-compliance by the Processor.
- Audits are limited to once per calendar year, unless a Security Incident or regulatory requirement necessitates an additional audit.
- The auditor must agree to reasonable confidentiality obligations.
7.3 Certifications and Reports
In lieu of an on-site audit, the Controller may accept:
- Relevant third-party certifications or audit reports (e.g., SOC 2 Type II, ISO 27001) held by the Processor.
- Completed security questionnaires or assessment documentation provided by the Processor.
8. Data Protection Impact Assessments
Where a data protection impact assessment (DPIA) is required under applicable law, the Processor shall provide the Controller with reasonable assistance in conducting the DPIA, including providing relevant information about the Processor's processing operations, security measures, and Sub-Processors.
9. Duration and Termination
9.1 Duration
This DPA shall remain in effect for as long as the Processor processes Personal Data on behalf of the Controller under the Service Agreement.
9.2 Survival
Provisions of this DPA relating to confidentiality, data deletion, liability, and governing law shall survive termination of this DPA and the Service Agreement.
10. Liability
Each party's liability under this DPA is subject to the limitations of liability set out in the Service Agreement (Terms of Service), except that neither party limits its liability for:
- Breaches of confidentiality obligations.
- Willful or grossly negligent violations of this DPA.
- Liability that cannot be limited under applicable data protection laws.
11. Governing Law
This DPA shall be governed by the laws specified in the Service Agreement (State of Delaware, United States), except where applicable data protection laws require otherwise. For Data Subjects in the EEA, disputes relating to the processing of their Personal Data may be brought before the courts of the EU member state in which the Data Subject resides.
12. Standard Contractual Clauses
Where the processing involves transfers of Personal Data from the EEA to countries that have not been deemed to provide an adequate level of data protection by the European Commission, the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) are incorporated by reference. In the event of any conflict between this DPA and the SCCs, the SCCs shall prevail.
Enterprise customers who require a signed, customized DPA with specific SCC annexes should contact
[email protected] to request a tailored agreement.
13. Contact Information
For questions or requests related to this Data Processing Agreement: