Data Processing Agreement
Our commitment to protecting your data under GDPR Article 28
Last updated: February 2026
GDPR Article 28
Compliant
EU Data Hosting
Frankfurt, Germany
Standard Contractual Clauses
Included
1. Parties and Scope
This Data Processing Agreement ("DPA") forms part of the Terms of Service between:
- Data Controller: You, the Customer using Stish services
- Data Processor: Sociably Digital Services, VAT ID: EL077034367, Athens 15342, Greece
This DPA applies to all processing of personal data that Stish performs on behalf of the Customer in connection with the Stish platform services.
2. Subject Matter and Duration
Subject Matter: Processing of personal data as necessary to provide the Stish campaign management platform.
Duration: This DPA is effective for the duration of your Stish subscription and continues until all personal data has been deleted or returned.
Nature of Processing: Collection, storage, organization, retrieval, use, and erasure of campaign-related personal data.
3. Types of Personal Data
The following categories of personal data may be processed:
- Contact information (names, email addresses)
- Account credentials (encrypted passwords)
- Campaign data (targeting parameters, audience segments)
- Asset metadata (file names, upload dates)
- Usage data (IP addresses, browser information)
- Payment information (processed via Stripe)
4. Categories of Data Subjects
- Customer employees and team members
- Customer clients (marketing agencies' end clients)
- Individuals referenced in campaign targeting or creative assets
5. Processor Obligations
Stish, as Data Processor, commits to:
- Instructions: Process personal data only on documented instructions from the Controller
- Confidentiality: Ensure all personnel processing data are bound by confidentiality
- Security: Implement appropriate technical and organizational measures (see our Security Page)
- Sub-processors: Only engage sub-processors with prior authorization (see our Subprocessors List)
- Data Subject Rights: Assist the Controller in responding to data subject requests
- Breach Notification: Notify the Controller of any personal data breach within 72 hours
- Deletion: Delete or return all personal data upon termination of services
- Audits: Allow for and contribute to audits conducted by the Controller
6. Security Measures
We implement the following technical and organizational measures:
- 256-bit AES encryption for data at rest
- TLS 1.3 encryption for data in transit
- EU-based servers (Frankfurt, Germany)
- Regular security audits and penetration testing
- Role-based access controls
- Automated backup systems
- 24/7 infrastructure monitoring
Full details are available on our Security Page.
7. Sub-processors
The Controller grants general authorization for Stish to engage sub-processors. A current list of sub-processors is maintained at:
We will notify the Controller of any intended changes to sub-processors, providing an opportunity to object.
8. International Transfers
All primary data processing occurs within the European Union. Where transfers outside the EU are necessary (e.g., for certain sub-processors), we ensure appropriate safeguards including:
- EU Standard Contractual Clauses (SCCs)
- Adequacy decisions where applicable
- Additional technical measures as required
9. Data Subject Rights
Stish will assist the Controller in fulfilling obligations to respond to data subject requests, including:
- Right of access
- Right to rectification
- Right to erasure ("right to be forgotten")
- Right to restriction of processing
- Right to data portability
- Right to object
Data export functionality is available in Settings → Export Data.
10. Termination and Data Return
Upon termination of services, Stish will, at the Controller's choice:
- Return all personal data in a commonly used format, or
- Delete all personal data and certify deletion
Data deletion occurs within 30 days of account termination, unless retention is required by law.
DPA Inquiries
For questions about this DPA or to request a signed copy, please contact us:
Contact Us
Privacy Policy
Security
Subprocessors
Terms of Service