Stereasoft
Home
Services
Mobile AppsWebsitesUX/UI DesignTesting & QAMVP DevelopmentSupport & Maintenance
Projects
Company
AboutBlogCareersContact
Contact Us
Navigation
  • Home
  • Services
    • Mobile Apps
    • Websites
    • UX/UI Design
    • Testing & QA
    • MVP Development
    • Support & Maintenance
  • Projects
  • Company
    • About
    • Blog
    • Careers
    • Contact
Contact Us
Stereasoft

Web and mobile engineering for production software

Remote-first

Ukraine

hello@stereasoft.ua

Services

  • Mobile Apps
  • Websites
  • UX/UI Design
  • Testing & QA
  • MVP Development
  • Support & Maintenance

Company

  • About
  • Blog
  • Careers
  • Contact

Get in Touch

Starting a web or mobile project? Tell us what you're building and we'll respond within one business day.

Start a Project
  • Privacy Policy
  • Cookie Policy
  • Data Processing Agreement

© 2026 Stereasoft

Data Processing Agreement

Last updated: 29 July 2026

This Data Processing Agreement ("DPA") describes how Stereasoft ("Processor") processes personal data on behalf of clients ("Controller") when providing web and mobile engineering services. It supplements a signed statement of work, master services agreement, or other commercial contract between the parties.

1.Scope and roles

This DPA applies where Stereasoft processes personal data on the Customer's behalf in connection with software design, development, testing, deployment, or support services.

The Customer is the Controller and determines the purposes and means of processing. Stereasoft is the Processor and processes personal data only on documented instructions from the Customer, unless required by law.

If Stereasoft acts as an independent Controller for its own business operations, for example billing contact details, that processing is covered by our Privacy Policy and not this DPA.

2.Subject matter and duration

Processing relates to the design, build, testing, hosting integration, maintenance, or improvement of software products for the Customer. Processing continues for the term of the applicable services agreement and until personal data is deleted or returned in accordance with this DPA.

3.Types of data and data subjects

Depending on the project, personal data may include end-user account details, customer personnel contact details, support tickets, logs, payment metadata integrated into the product, and technical identifiers such as device IDs or session tokens.

Data subjects may include the Customer's employees, contractors, end users, and other individuals whose data is processed in the Customer's systems.

4.Processor obligations

  • Process personal data only on documented instructions from the Customer, unless EU or UK law requires otherwise.
  • Ensure personnel authorised to process personal data are bound by confidentiality obligations.
  • Implement appropriate technical and organisational security measures.
  • Not engage another processor without the Customer's authorisation, subject to the subprocessor provisions below.
  • Assist the Customer with data subject requests and security incident notifications, taking into account the nature of processing and information available to us.
  • Delete or return personal data at the end of services, unless retention is required by law.
  • Make available information reasonably necessary to demonstrate compliance and allow audits agreed in writing, subject to confidentiality and security constraints.

5.Subprocessors

The Customer authorises Stereasoft to use subprocessors for hosting, source control, communication, monitoring, and other tooling necessary to deliver the services. A current list is available on request.

Stereasoft will impose data protection obligations on subprocessors that are substantially similar to those in this DPA and remains responsible for subprocessors' performance of their obligations.

6.International transfers

Personal data may be processed in Ukraine, the EEA, the UK, the United States, or other locations where subprocessors operate. Where transfers require safeguards under GDPR or UK GDPR, the parties will execute Standard Contractual Clauses or rely on another valid transfer mechanism.

7.Security incidents

Stereasoft will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data, and provide reasonable information to help the Customer meet its regulatory obligations.

8.Liability and precedence

This DPA forms part of the parties' services agreement. If there is a conflict between this DPA and the services agreement regarding data protection, this DPA prevails to the extent of the conflict.

Each party's liability under this DPA is subject to the limitations and exclusions set out in the main services agreement, unless mandatory law provides otherwise.

9.Contact

For DPA-related enquiries, contact:

  • Stereasoft
  • Remote-first
  • Ukraine
  • hello@stereasoft.ua