This Data Processing Agreement ("DPA") forms part of the Terms & Conditions between StockSimple, operated by Ricardo Knight as a sole proprietor ("Processor"), and the business customer using the Service ("Controller"). It applies whenever StockSimple processes personal data on the customer's behalf, and is designed to meet Article 28 of the EU and UK GDPR, South Africa's POPIA (as "operator"), the California CCPA/CPRA (as "service provider") and comparable laws. It takes effect automatically on acceptance of the Terms.
We maintain appropriate technical and organisational measures, including encryption in transit (TLS), encrypted storage at our hosting provider, row-level isolation between businesses, role-based access controls, private storage for uploaded photos, and restricted administrative access.
The Controller authorises the subprocessors listed on our Subprocessors page. We impose data protection terms on each subprocessor no less protective than this DPA, and give at least 14 days' notice of new subprocessors by updating that page. The Controller may object on reasonable data protection grounds by emailing us.
Where personal data is transferred out of the EEA, UK, South Africa or another region with transfer restrictions, transfers rely on adequacy decisions, the EU Standard Contractual Clauses, the UK International Data Transfer Addendum or equivalent safeguards used by our subprocessors.
We will notify the Controller without undue delay, and within 72 hours where feasible, after becoming aware of a breach affecting the Controller's personal data, with the information reasonably available to help the Controller meet its own obligations.
The Controller can export its data at any time. On written request after account closure, we delete the Controller's personal data within 30 days, except where retention is required by law. Backups roll off in the ordinary course.
Data protection requests and objections: StockSimpleSales@outlook.com.
Related: Terms · Privacy · Refunds · DPA · Subprocessors