Data Processing Agreement

Our commitment to protecting your data under GDPR Article 28

Last updated: February 2026

GDPR Article 28

Compliant

EU Data Hosting

Frankfurt, Germany

Standard Contractual Clauses

Included

1. Parties and Scope

This Data Processing Agreement ("DPA") forms part of the Terms of Service between:

  • Data Controller: You, the Customer using Stish services
  • Data Processor: Sociably Digital Services, VAT ID: EL077034367, Athens 15342, Greece

This DPA applies to all processing of personal data that Stish performs on behalf of the Customer in connection with the Stish platform services.

2. Subject Matter and Duration

Subject Matter: Processing of personal data as necessary to provide the Stish campaign management platform.

Duration: This DPA is effective for the duration of your Stish subscription and continues until all personal data has been deleted or returned.

Nature of Processing: Collection, storage, organization, retrieval, use, and erasure of campaign-related personal data.

3. Types of Personal Data

The following categories of personal data may be processed:

  • Contact information (names, email addresses)
  • Account credentials (encrypted passwords)
  • Campaign data (targeting parameters, audience segments)
  • Asset metadata (file names, upload dates)
  • Usage data (IP addresses, browser information)
  • Payment information (processed via Stripe)

4. Categories of Data Subjects

  • Customer employees and team members
  • Customer clients (marketing agencies' end clients)
  • Individuals referenced in campaign targeting or creative assets

5. Processor Obligations

Stish, as Data Processor, commits to:

  • Instructions: Process personal data only on documented instructions from the Controller
  • Confidentiality: Ensure all personnel processing data are bound by confidentiality
  • Security: Implement appropriate technical and organizational measures (see our Security Page)
  • Sub-processors: Only engage sub-processors with prior authorization (see our Subprocessors List)
  • Data Subject Rights: Assist the Controller in responding to data subject requests
  • Breach Notification: Notify the Controller of any personal data breach within 72 hours
  • Deletion: Delete or return all personal data upon termination of services
  • Audits: Allow for and contribute to audits conducted by the Controller

6. Security Measures

We implement the following technical and organizational measures:

  • 256-bit AES encryption for data at rest
  • TLS 1.3 encryption for data in transit
  • EU-based servers (Frankfurt, Germany)
  • Regular security audits and penetration testing
  • Role-based access controls
  • Automated backup systems
  • 24/7 infrastructure monitoring

Full details are available on our Security Page.

7. Sub-processors

The Controller grants general authorization for Stish to engage sub-processors. A current list of sub-processors is maintained at:

View Subprocessors List

We will notify the Controller of any intended changes to sub-processors, providing an opportunity to object.

8. International Transfers

All primary data processing occurs within the European Union. Where transfers outside the EU are necessary (e.g., for certain sub-processors), we ensure appropriate safeguards including:

  • EU Standard Contractual Clauses (SCCs)
  • Adequacy decisions where applicable
  • Additional technical measures as required

9. Data Subject Rights

Stish will assist the Controller in fulfilling obligations to respond to data subject requests, including:

  • Right of access
  • Right to rectification
  • Right to erasure ("right to be forgotten")
  • Right to restriction of processing
  • Right to data portability
  • Right to object

Data export functionality is available in Settings → Export Data.

10. Termination and Data Return

Upon termination of services, Stish will, at the Controller's choice:

  • Return all personal data in a commonly used format, or
  • Delete all personal data and certify deletion

Data deletion occurs within 30 days of account termination, unless retention is required by law.

DPA Inquiries

For questions about this DPA or to request a signed copy, please contact us:

Contact Us
Privacy Policy
Security
Subprocessors
Terms of Service