Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the Terms & Conditions (the “Agreement”) between StreamPros LLC (“StreamPros,” “we,” “us”) and the customer that accepted the Agreement (“Customer,” “you”). It applies to the extent StreamPros processes personal data contained in your Customer Data on your behalf and that processing is subject to the EU General Data Protection Regulation 2016/679 (“GDPR”), the GDPR as incorporated into United Kingdom law (“UK GDPR”), or the Swiss Federal Act on Data Protection (together, “Data Protection Law”). It is incorporated into the Agreement by reference; no signature is required. In the event of a conflict between this DPA and the Agreement with respect to the processing of personal data, this DPA controls.
1. Roles and scope
For personal data in Customer Data, you are the controller (or a processor acting on behalf of your own controller) and StreamPros is your processor. This DPA does not apply to information StreamPros processes as a controller (for example, your account, billing, and usage information), which is described in our Privacy Policy. Terms such as “controller,” “processor,” “data subject,” “personal data,” and “processing” have the meanings given in Data Protection Law.
2. Details of processing
- Subject matter and duration— the provision of the Service for the term of the Agreement, plus the deletion window described in Section 9.
- Nature and purpose— hosting, storage, analysis, display, transmission, backup, and related processing needed to provide the Service as described in the Agreement, including the sharing you direct or consent to under the Agreement.
- Categories of data subjects— your customers and buyers, your employees and team members, and other individuals whose personal data you choose to include in Customer Data.
- Categories of personal data— determined by you; typically identifiers (names, usernames, email addresses), transaction and order records, employment records (wages, hours, time-clock entries, schedules), and media you upload. The Service is not designed for, and you agree not to submit, special categories of data (Article 9 GDPR) or data subject to sector-specific regimes such as health or payment-card data.
3. Processing on your instructions
We will process personal data in Customer Data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by law (in which case we will inform you of that legal requirement before processing, unless the law prohibits it). The Agreement, this DPA, and your use and configuration of the Service (including the features you enable, the data you import, and the sharing you direct or consent to under the Agreement) constitute your complete documented instructions. We will inform you if, in our opinion, an instruction infringes Data Protection Law.
4. Confidentiality
We ensure that persons authorized to process personal data in Customer Data are bound by contractual or statutory obligations of confidentiality, and that access is limited to personnel who need it to provide the Service.
5. Security
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, we implement and maintain appropriate technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as required by Article 32 GDPR. Our current measures — including encryption in transit and at rest, role-based access controls, database-layer tenant isolation, least-privilege access, and audit logging — are described on our Security page. We may update these measures from time to time, provided the updates do not materially reduce the overall protection of Customer Data.
6. Sub-processors
You provide general written authorization for us to engage sub-processors to help provide the Service. Our current sub-processors are listed in Section 5.1 of the Privacy Policy. We will provide reasonable advance notice (through the Service or our website) of any new sub-processor that materially affects the processing of Customer Data. If you reasonably object to a new sub-processor on data-protection grounds and we cannot offer a reasonable alternative, you may terminate the affected subscription and Section 5.4 of the Agreement (cancellation) applies. We impose data-protection obligations on each sub-processor that are materially equivalent to those in this DPA, and we remain liable for their performance.
7. Assistance
Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures, insofar as possible, in fulfilling your obligations to respond to data subject requests (access, rectification, erasure, restriction, portability, objection). If a data subject contacts us directly about Customer Data, we will refer them to you. We will also provide reasonable assistance with your obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of the processing and the information available to us. We may charge a reasonable fee for assistance that goes materially beyond the Service’s built-in capabilities.
8. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting personal data in your Customer Data, and will provide information reasonably available to us about the nature of the breach, the categories and approximate volume of data and data subjects concerned, the likely consequences, and the measures taken or proposed to address it — supplemented as further information becomes available. Our notification is not an admission of fault or liability.
9. Deletion and return
You can export Customer Data through the Service’s export features during the term. Upon termination or expiry of the Agreement, we will delete personal data in Customer Data in accordance with the retention timelines in Section 6 of the Privacy Policy(deletion from production systems within 90 days of account closure, with encrypted backups overwritten in the normal backup rotation — currently about 7 days, and never more than 35 days), unless applicable law requires longer storage.
10. Audits
We will make available to you information reasonably necessary to demonstrate compliance with this DPA, including summaries of relevant third-party audits or certifications of our sub-processors and responses to reasonable written security questionnaires. Where Data Protection Law grants you a mandatory audit right that cannot be satisfied by documentation, you (or an independent auditor that is not our competitor) may audit our compliance with this DPA no more than once in any 12-month period, on at least 30 days’ written notice, during business hours, without disrupting our operations, subject to confidentiality obligations, and at your expense.
11. International transfers
We are based in the United States and process personal data there and in the other regions described in the Privacy Policy. For transfers of personal data from the EEA, the United Kingdom, or Switzerland to countries without an adequacy decision, the parties enter into the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914), Module Two(controller to processor), which are incorporated into this DPA by reference, completed as follows: Clause 7 (docking) is included; Clause 9(a) Option 2 (general authorization, notice per Section 6 above); Clause 11 optional language is not included; Clause 17 Option 1 with Irish law governing; Clause 18(b) courts of Ireland; Annex I is completed by Section 2 of this DPA and the parties’ details in the Agreement; Annex II is completed by Section 5 of this DPA; Annex III is completed by Section 6 of this DPA. For transfers from the United Kingdom, the SCCs apply as amended by the UK Information Commissioner’s International Data Transfer Addendum (version B1.0), with the tables deemed completed by the information above. For transfers from Switzerland, the SCCs apply with the adjustments required by the Swiss Federal Data Protection and Information Commissioner. If we adopt an alternative valid transfer mechanism, it will apply instead upon notice to you.
12. Liability and general
Each party’s liability arising out of or related to this DPA (including the incorporated Standard Contractual Clauses, to the extent permitted) is subject to the limitations of liability in the Agreement. This DPA terminates automatically when we no longer process personal data in your Customer Data. Except as amended by this DPA, the Agreement remains in full force and effect.
13. Contact
Questions about this DPA can be sent to StreamPros LLC, Alabama, at [email protected].
© 2026 StreamPros LLC. All rights reserved.