The signable DPA enterprise counsel can start reviewing today.
This is the enterprise Data Processing Agreement StabilityLogic offers to every pilot and enterprise customer. It is published as a versioned PDF, not gated behind a form. Counsel can begin review before the first scoping call.
What the DPA does — and what it does not claim.
The Data Processing Agreement governs how StabilityLogic (as Processor) handles applicant and operator personal data on behalf of the customer (as Controller). It sits alongside the Master Services Agreement and the Enterprise Security Overview and is executed before any applicant data is exchanged.
The DPA is honest about the limits of a written agreement. It does not claim regulatory certifications that have not been formally achieved. Its enforceability begins on counter-signature.
- •Controller / Processor roles and definitions
- •GDPR provisions (including Article 28 processing terms)
- •CCPA / CPRA Service Provider posture — no sale, no sharing
- •Confidentiality and personnel obligations
- •Security measures aligned to the Enterprise Security Overview
- •Data retention windows tied to statutory reference
- •Subprocessor engagement, register, and 30-day change notice
- •International transfer mechanisms (SCCs, adequacy, additional safeguards)
- •Customer obligations (lawful basis, data-subject request handling)
- •Termination, return, and deletion of applicant data
- •Governing law, notices, and dispute-resolution posture
- •Two-party signature page ready for counter-signature
Every version. Signable and dated.
We keep prior versions available for counterparties who executed the earlier text. Every version is dated and downloadable directly.
| Version | Effective date | Status | Change notes | Download |
|---|---|---|---|---|
| v1.1 | February 16, 2026 | Current | Clarified data-retention windows tied to statutory reference. Formalized subprocessor-monitoring cadence. Expanded international-transfer safeguards to reference SCC modules and transfer-impact-assessment posture. Retained honest execution language; no false certification or regulatory claims. | |
| v1.0 | February 12, 2026 | Superseded | Initial enterprise template. Controller/Processor definitions, GDPR + CCPA provisions, confidentiality, security measures, data retention, subprocessors, international transfers, customer obligations, termination, governing law, and a two-party signature page. |
The rest of the procurement packet.
Enterprise Security Overview
Architecture, encryption, IAM, logging, incident response, DR, vendor management, and roadmap.
Subprocessors register
Company · Purpose · Jurisdiction · Data category for every vendor that processes data on our behalf.
Trust Center
SLA, support hours, incident response, business continuity, DR, security contacts, vendor risk, audit timeline.
Send us your redlines. We'll turn them in one business day.
Enterprise counsel typically returns 5–15 clause-level comments. We turn redlines with a written response within one business day and hold the executed DPA on file with the customer's Master Services Agreement.