# Data Processing Agreement

Our commitment to protecting your data under GDPR Article 28

Last updated: February 2026

## GDPR Article 28

Compliant

### EU Data Hosting

Frankfurt, Germany

### Standard Contractual Clauses

Included

## 1. Parties and Scope

This Data Processing Agreement ("DPA") forms part of the Terms of Service between:

- **Data Controller:** You, the Customer using Stish services  
- **Data Processor:** Sociably Digital Services, VAT ID: EL077034367, Athens 15342, Greece

This DPA applies to all processing of personal data that Stish performs on behalf of the Customer in connection with the Stish platform services.

## 2. Subject Matter and Duration

**Subject Matter:** Processing of personal data as necessary to provide the Stish campaign management platform.

**Duration:** This DPA is effective for the duration of your Stish subscription and continues until all personal data has been deleted or returned.

**Nature of Processing:** Collection, storage, organization, retrieval, use, and erasure of campaign-related personal data.

## 3. Types of Personal Data

The following categories of personal data may be processed:

- Contact information (names, email addresses)  
- Account credentials (encrypted passwords)  
- Campaign data (targeting parameters, audience segments)  
- Asset metadata (file names, upload dates)  
- Usage data (IP addresses, browser information)  
- Payment information (processed via Stripe)

## 4. Categories of Data Subjects

- Customer employees and team members  
- Customer clients (marketing agencies' end clients)  
- Individuals referenced in campaign targeting or creative assets

## 5. Processor Obligations

Stish, as Data Processor, commits to:

- **Instructions:** Process personal data only on documented instructions from the Controller  
- **Confidentiality:** Ensure all personnel processing data are bound by confidentiality  
- **Security:** Implement appropriate technical and organizational measures (see our [Security Page](/content/security/index.html))  
- **Sub-processors:** Only engage sub-processors with prior authorization (see our [Subprocessors List](/content/subprocessors/index.html))  
- **Data Subject Rights:** Assist the Controller in responding to data subject requests  
- **Breach Notification:** Notify the Controller of any personal data breach within 72 hours  
- **Deletion:** Delete or return all personal data upon termination of services  
- **Audits:** Allow for and contribute to audits conducted by the Controller

## 6. Security Measures

We implement the following technical and organizational measures:

- 256-bit AES encryption for data at rest  
- TLS 1.3 encryption for data in transit  
- EU-based servers (Frankfurt, Germany)  
- Regular security audits and penetration testing  
- Role-based access controls  
- Automated backup systems  
- 24/7 infrastructure monitoring

Full details are available on our [Security Page](/content/security/index.html).

## 7. Sub-processors

The Controller grants general authorization for Stish to engage sub-processors. A current list of sub-processors is maintained at:

[View Subprocessors List](/content/subprocessors/index.html)

We will notify the Controller of any intended changes to sub-processors, providing an opportunity to object.

## 8. International Transfers

All primary data processing occurs within the European Union. Where transfers outside the EU are necessary (e.g., for certain sub-processors), we ensure appropriate safeguards including:

- EU Standard Contractual Clauses (SCCs)  
- Adequacy decisions where applicable  
- Additional technical measures as required

## 9. Data Subject Rights

Stish will assist the Controller in fulfilling obligations to respond to data subject requests, including:

- Right of access  
- Right to rectification  
- Right to erasure ("right to be forgotten")  
- Right to restriction of processing  
- Right to data portability  
- Right to object

Data export functionality is available in Settings → Export Data.

## 10. Termination and Data Return

Upon termination of services, Stish will, at the Controller's choice:

- Return all personal data in a commonly used format, or  
- Delete all personal data and certify deletion

Data deletion occurs within 30 days of account termination, unless retention is required by law.

## DPA Inquiries

For questions about this DPA or to request a signed copy, please contact us:

[Contact Us](/content/contact/index.html)  
[Privacy Policy](/content/privacy/index.html)  
[Security](/content/security/index.html)  
[Subprocessors](/content/subprocessors/index.html)  
[Terms of Service](/content/terms/index.html)
