Skip to main content
Data Processing Agreement

The signable DPA enterprise counsel can start reviewing today.

This is the enterprise Data Processing Agreement StabilityLogic offers to every pilot and enterprise customer. It is published as a versioned PDF, not gated behind a form. Counsel can begin review before the first scoping call.

Effective February 16, 2026 Version v1.1 GDPR · CCPA / CPRA
Purpose

What the DPA does — and what it does not claim.

The Data Processing Agreement governs how StabilityLogic (as Processor) handles applicant and operator personal data on behalf of the customer (as Controller). It sits alongside the Master Services Agreement and the Enterprise Security Overview and is executed before any applicant data is exchanged.

The DPA is honest about the limits of a written agreement. It does not claim regulatory certifications that have not been formally achieved. Its enforceability begins on counter-signature.

What the DPA covers
  • Controller / Processor roles and definitions
  • GDPR provisions (including Article 28 processing terms)
  • CCPA / CPRA Service Provider posture — no sale, no sharing
  • Confidentiality and personnel obligations
  • Security measures aligned to the Enterprise Security Overview
  • Data retention windows tied to statutory reference
  • Subprocessor engagement, register, and 30-day change notice
  • International transfer mechanisms (SCCs, adequacy, additional safeguards)
  • Customer obligations (lawful basis, data-subject request handling)
  • Termination, return, and deletion of applicant data
  • Governing law, notices, and dispute-resolution posture
  • Two-party signature page ready for counter-signature
Version history

Every version. Signable and dated.

We keep prior versions available for counterparties who executed the earlier text. Every version is dated and downloadable directly.

VersionEffective dateStatusChange notesDownload
v1.1February 16, 2026CurrentClarified data-retention windows tied to statutory reference. Formalized subprocessor-monitoring cadence. Expanded international-transfer safeguards to reference SCC modules and transfer-impact-assessment posture. Retained honest execution language; no false certification or regulatory claims. PDF
v1.0February 12, 2026SupersededInitial enterprise template. Controller/Processor definitions, GDPR + CCPA provisions, confidentiality, security measures, data retention, subprocessors, international transfers, customer obligations, termination, governing law, and a two-party signature page. PDF
Counsel review

Send us your redlines. We'll turn them in one business day.

Enterprise counsel typically returns 5–15 clause-level comments. We turn redlines with a written response within one business day and hold the executed DPA on file with the customer's Master Services Agreement.