← Back to StockSimple

Data Processing Agreement

Last updated: 3 October 2026

1. Scope and parties

This Data Processing Agreement ("DPA") forms part of the Terms & Conditions between StockSimple, operated by Ricardo Knight as a sole proprietor ("Processor"), and the business customer using the Service ("Controller"). It applies whenever StockSimple processes personal data on the customer's behalf, and is designed to meet Article 28 of the EU and UK GDPR, South Africa's POPIA (as "operator"), the California CCPA/CPRA (as "service provider") and comparable laws. It takes effect automatically on acceptance of the Terms.

2. Details of processing

  • Subject matter: providing the StockSimple inventory service.
  • Duration: the term of the customer's account plus the deletion period below.
  • Data subjects: the customer's staff, invited team members, suppliers and customers.
  • Data categories: names, business email addresses, phone numbers, addresses and order details entered by the customer. No special-category data is intended to be processed.
  • Purpose: hosting, storing, displaying and processing data solely to deliver the Service.

3. Processor obligations

  • Process personal data only on the Controller's documented instructions, including these Terms.
  • Ensure anyone with access is bound by confidentiality.
  • Never sell or share the Controller's personal data, or use it for our own purposes.
  • Assist the Controller in responding to data subject requests and with impact assessments where reasonably required.
  • Make available information reasonably necessary to demonstrate compliance, and allow reasonable audits on 30 days' notice, no more than once a year.

4. Security measures

We maintain appropriate technical and organisational measures, including encryption in transit (TLS), encrypted storage at our hosting provider, row-level isolation between businesses, role-based access controls, private storage for uploaded photos, and restricted administrative access.

5. Subprocessors

The Controller authorises the subprocessors listed on our Subprocessors page. We impose data protection terms on each subprocessor no less protective than this DPA, and give at least 14 days' notice of new subprocessors by updating that page. The Controller may object on reasonable data protection grounds by emailing us.

6. International transfers

Where personal data is transferred out of the EEA, UK, South Africa or another region with transfer restrictions, transfers rely on adequacy decisions, the EU Standard Contractual Clauses, the UK International Data Transfer Addendum or equivalent safeguards used by our subprocessors.

7. Personal data breaches

We will notify the Controller without undue delay, and within 72 hours where feasible, after becoming aware of a breach affecting the Controller's personal data, with the information reasonably available to help the Controller meet its own obligations.

8. Return and deletion

The Controller can export its data at any time. On written request after account closure, we delete the Controller's personal data within 30 days, except where retention is required by law. Backups roll off in the ordinary course.

9. Contact

Data protection requests and objections: StockSimpleSales@outlook.com.

Related: Terms · Privacy · Refunds · DPA · Subprocessors