StallWise

Professional Equestrian Facility Management

Last Updated: March 10, 2026

About This Agreement: This Data Processing Agreement ("DPA") is available to all StallWise customers and is automatically incorporated into Enterprise subscription agreements. Starter and Professional customers who require a DPA may request its inclusion by contacting [email protected].

1. Definitions

For the purposes of this Data Processing Agreement:

2. Scope and Purpose

2.1 Scope

This DPA applies to all Processing of Personal Data by the Processor on behalf of the Controller in connection with the provision of the StallWise service under the Service Agreement.

2.2 Purpose of Processing

The Processor shall process Personal Data solely for the purpose of providing the Service as described in the Service Agreement, including:

2.3 Categories of Data Subjects

Personal Data processed under this DPA may relate to the following categories of Data Subjects:

2.4 Types of Personal Data

Category Data Types
Identity Data Names, titles, roles, photographs
Contact Data Email addresses, phone numbers, physical addresses
Financial Data Invoice details, payment records, billing history (card details processed by Stripe)
Professional Data Business names, roles, certifications, license numbers
Operational Data Schedule information, task assignments, communication records
Technical Data IP addresses, browser data, device information, usage logs

3. Obligations of the Processor

3.1 Processing Instructions

The Processor shall:

3.2 Confidentiality

The Processor shall ensure that all persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

3.3 Security Measures

The Processor shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

Technical Measures

Organizational Measures

3.4 Assistance to the Controller

The Processor shall assist the Controller in:

3.5 Data Deletion and Return

Upon termination of the Service Agreement or upon request by the Controller:

4. Sub-Processors

4.1 Authorized Sub-Processors

The Controller provides general authorization for the Processor to engage Sub-Processors, subject to the requirements of this section. The current list of Sub-Processors is:

Sub-Processor Purpose Location Data Processed
Cloud Infrastructure Provider Hosting, compute, and data storage United States All Service data (encrypted)
Stripe, Inc. Payment processing United States Payment card details, billing addresses, transaction data
Email Service Provider Transactional email delivery United States Email addresses, names, email content
Cloudflare, Inc. CDN, security, DNS Global (edge locations) IP addresses, request metadata

4.2 New Sub-Processors

The Processor shall:

4.3 Objection to Sub-Processors

If the Controller objects to a new Sub-Processor on reasonable grounds related to data protection:

4.4 Sub-Processor Agreements

The Processor shall enter into written agreements with each Sub-Processor imposing data protection obligations no less protective than those set out in this DPA. The Processor remains fully liable to the Controller for the performance of each Sub-Processor's obligations.

5. International Data Transfers

5.1 Transfer Mechanisms

The Service is hosted and operated in the United States. For transfers of Personal Data from the EEA, UK, or Switzerland to the United States, the Processor relies on:

5.2 Transfer Impact Assessment

The Processor has conducted a transfer impact assessment and has determined that the implemented technical and organizational measures, combined with the applicable transfer mechanisms, provide an adequate level of protection for Personal Data transferred to the United States.

6. Security Incidents

6.1 Notification

The Processor shall notify the Controller without undue delay and in any event within 48 hours after becoming aware of a Security Incident involving Personal Data processed under this DPA. The notification shall include:

6.2 Cooperation

The Processor shall cooperate with and assist the Controller in:

6.3 Limitations

The Processor's obligation to notify does not extend to Security Incidents that are unlikely to result in a risk to the rights and freedoms of Data Subjects (e.g., encrypted data accessed without the decryption key).

7. Audits and Inspections

7.1 Audit Rights

The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations set out in this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.

7.2 Audit Procedures

7.3 Certifications and Reports

In lieu of an on-site audit, the Controller may accept:

8. Data Protection Impact Assessments

Where a data protection impact assessment (DPIA) is required under applicable law, the Processor shall provide the Controller with reasonable assistance in conducting the DPIA, including providing relevant information about the Processor's processing operations, security measures, and Sub-Processors.

9. Duration and Termination

9.1 Duration

This DPA shall remain in effect for as long as the Processor processes Personal Data on behalf of the Controller under the Service Agreement.

9.2 Survival

Provisions of this DPA relating to confidentiality, data deletion, liability, and governing law shall survive termination of this DPA and the Service Agreement.

10. Liability

Each party's liability under this DPA is subject to the limitations of liability set out in the Service Agreement (Terms of Service), except that neither party limits its liability for:

11. Governing Law

This DPA shall be governed by the laws specified in the Service Agreement (State of Delaware, United States), except where applicable data protection laws require otherwise. For Data Subjects in the EEA, disputes relating to the processing of their Personal Data may be brought before the courts of the EU member state in which the Data Subject resides.

12. Standard Contractual Clauses

Where the processing involves transfers of Personal Data from the EEA to countries that have not been deemed to provide an adequate level of data protection by the European Commission, the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) are incorporated by reference. In the event of any conflict between this DPA and the SCCs, the SCCs shall prevail.

Enterprise customers who require a signed, customized DPA with specific SCC annexes should contact [email protected] to request a tailored agreement.

13. Contact Information

For questions or requests related to this Data Processing Agreement: