Last updated: 29 July 2026
This Data Processing Agreement ("DPA") describes how Stereasoft ("Processor") processes personal data on behalf of clients ("Controller") when providing web and mobile engineering services. It supplements a signed statement of work, master services agreement, or other commercial contract between the parties.
This DPA applies where Stereasoft processes personal data on the Customer's behalf in connection with software design, development, testing, deployment, or support services.
The Customer is the Controller and determines the purposes and means of processing. Stereasoft is the Processor and processes personal data only on documented instructions from the Customer, unless required by law.
If Stereasoft acts as an independent Controller for its own business operations, for example billing contact details, that processing is covered by our Privacy Policy and not this DPA.
Processing relates to the design, build, testing, hosting integration, maintenance, or improvement of software products for the Customer. Processing continues for the term of the applicable services agreement and until personal data is deleted or returned in accordance with this DPA.
Depending on the project, personal data may include end-user account details, customer personnel contact details, support tickets, logs, payment metadata integrated into the product, and technical identifiers such as device IDs or session tokens.
Data subjects may include the Customer's employees, contractors, end users, and other individuals whose data is processed in the Customer's systems.
The Customer authorises Stereasoft to use subprocessors for hosting, source control, communication, monitoring, and other tooling necessary to deliver the services. A current list is available on request.
Stereasoft will impose data protection obligations on subprocessors that are substantially similar to those in this DPA and remains responsible for subprocessors' performance of their obligations.
Personal data may be processed in Ukraine, the EEA, the UK, the United States, or other locations where subprocessors operate. Where transfers require safeguards under GDPR or UK GDPR, the parties will execute Standard Contractual Clauses or rely on another valid transfer mechanism.
Stereasoft will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data, and provide reasonable information to help the Customer meet its regulatory obligations.
This DPA forms part of the parties' services agreement. If there is a conflict between this DPA and the services agreement regarding data protection, this DPA prevails to the extent of the conflict.
Each party's liability under this DPA is subject to the limitations and exclusions set out in the main services agreement, unless mandatory law provides otherwise.
For DPA-related enquiries, contact: