Legal

DATA PROCESSING AGREEMENT

Version 1.0 — Effective May 2, 2026

Download PDF version

This Data Processing Agreement ("DPA") is entered into between SALESZ LLC, a Florida limited liability company doing business as Stratalize ("Processor"), and the Customer identified in the applicable Order Form or subscription agreement ("Controller").

This DPA is incorporated into and forms part of the Stratalize Terms of Service. Capitalized terms not defined herein have the meanings given in the Terms of Service.

ARTICLE 1 — DEFINITIONS

"Applicable Data Protection Law" means all laws and regulations applicable to the processing of Personal Data under this DPA, including without limitation the GDPR, UK GDPR, CCPA/CPRA, and other applicable state and international privacy laws.

"Data Subject" means an identified or identifiable natural person to whom Personal Data relates.

"EEA" means the European Economic Area.

"GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council.

"Personal Data" means any information relating to an identified or identifiable natural person that is processed by Processor on behalf of Controller in connection with the Platform.

"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.

"Processing" has the meaning given under the GDPR and "process" and "processed" shall be construed accordingly.

"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries pursuant to Commission Decision (EU) 2021/914.

"Sub-processor" means any third party engaged by Processor to process Personal Data on behalf of Controller.

ARTICLE 2 — ROLES AND SCOPE

2.1 Controller and Processor

The parties acknowledge that Controller is the data controller and Processor is the data processor with respect to Personal Data processed under the Platform.

2.2 Processor's Obligations

Processor shall process Personal Data only:

(a) On behalf of and in accordance with Controller's documented instructions, including as set out in this DPA and the Terms of Service;

(b) For the purposes of providing the Platform and related services; and

(c) As otherwise required by Applicable Data Protection Law, in which case Processor shall notify Controller before such processing unless prohibited by law.

2.3 Controller's Instructions

Controller's instructions are documented in the Terms of Service and this DPA. Controller may provide additional instructions in writing, which Processor shall follow if technically and legally feasible.

2.4 Details of Processing

The subject matter, duration, nature, purpose, type of Personal Data, and categories of Data Subjects processed under this DPA are described in Schedule 1 (Description of Processing Activities).

ARTICLE 3 — PROCESSOR'S OBLIGATIONS

3.1 Confidentiality

Processor shall ensure that persons authorized to process Personal Data are under appropriate obligations of confidentiality.

3.2 Security

Processor shall implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, or disclosure, as further described in Schedule 2 (Technical and Organizational Measures).

3.3 Sub-processors

Processor shall:

(a) Not engage Sub-processors without general written authorization from Controller (which Controller provides by entering into this DPA with respect to the Sub-processors listed in Schedule 3);

(b) Impose data protection obligations on Sub-processors substantially equivalent to those in this DPA;

(c) Notify Controller of any intended addition or replacement of Sub-processors with at least 30 days' advance notice, providing Controller the opportunity to object on reasonable grounds related to data protection;

(d) Remain fully liable to Controller for the acts and omissions of Sub-processors to the same extent as if Processor had performed the processing directly.

3.4 Data Subject Rights

Processor shall promptly notify Controller of any Data Subject requests received directly by Processor and shall not respond to such requests without Controller's authorization, except to inform the Data Subject that the request has been received and is being handled by Controller.

3.5 Assistance

Processor shall provide reasonable assistance to Controller in fulfilling its obligations under Applicable Data Protection Law with respect to:

(a) Responding to Data Subject rights requests;

(b) Conducting Data Protection Impact Assessments (DPIAs);

(c) Prior consultation with supervisory authorities;

(d) Data breach notification.

3.6 Breach Notification

Processor shall notify Controller without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach. Such notification shall describe: (a) the nature of the breach; (b) the categories and approximate number of Data Subjects and Personal Data records concerned; (c) the likely consequences; and (d) measures taken or proposed to address the breach.

3.7 Deletion or Return

Upon termination of the Platform subscription or upon Controller's request, Processor shall delete or return all Personal Data within 90 days, unless retention is required by Applicable Data Protection Law. Processor shall provide written certification of deletion upon request.

3.8 Audits

Upon written request (with at least 30 days' notice and no more than once per 12-month period), Processor shall make available to Controller information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits conducted by Controller or an independent auditor appointed by Controller, subject to reasonable confidentiality obligations.

ARTICLE 4 — INTERNATIONAL DATA TRANSFERS

4.1 EEA Transfers

If Controller is subject to GDPR and Personal Data is transferred from the EEA to a third country that has not been deemed to provide adequate protection, such transfers shall be subject to Standard Contractual Clauses (Module Two: Controller to Processor) as set out in Commission Decision (EU) 2021/914, which are hereby incorporated by reference.

4.2 UK Transfers

For transfers from the United Kingdom, the International Data Transfer Addendum (IDTA) issued by the UK Information Commissioner's Office shall apply.

4.3 Transfer Impact Assessments

Processor shall cooperate with Controller in conducting Transfer Impact Assessments as required by Applicable Data Protection Law.

ARTICLE 5 — GOVERNING LAW

This DPA shall be governed by the laws of the State of Florida, unless otherwise required by Applicable Data Protection Law with respect to GDPR-related obligations, in which case EU law shall apply to those obligations.

SCHEDULE 1 — DESCRIPTION OF PROCESSING ACTIVITIES

Subject matter: Provision of AI governance and intelligence services via the Stratalize platform.

Duration: For the term of the Subscription and for such period thereafter as required by Applicable Data Protection Law or as needed to fulfill post-termination obligations.

Nature of Processing:

Purpose: To provide the Customer with AI-powered intelligence, governance, and compliance capabilities for business decision-making in regulated industries.

Types of Personal Data:

Special Categories: Processor does not intentionally process special categories of personal data. Customer is responsible for not submitting special category data unless expressly permitted and documented.

Categories of Data Subjects:

SCHEDULE 2 — TECHNICAL AND ORGANIZATIONAL MEASURES

Processor implements the following technical and organizational security measures:

Encryption

Access Controls

Audit and Logging

Operational Security

Organizational Measures

Data Minimization

SCHEDULE 3 — APPROVED SUB-PROCESSORS

Controller provides general authorization to Processor's engagement of the following Sub-processors:

Sub-processorPurposeData ProcessedLocation
Supabase, Inc.Database and authentication infrastructureAll platform data including Personal DataUS (EU region available on request)
Anthropic PBCAI model inference via APIPrompts containing org-context and user queriesUnited States
OpenAI, LLCEmbedding generation (RAG pipeline)Text content from uploaded documents and dataUnited States
OpenRouterAI model gatewayPrompts routed to third-party modelsUnited States
Vercel, Inc.Application hosting and serverless computeHTTP traffic, logs, execution environmentUnited States
Stripe, Inc.Payment processingBilling identifiers and payment metadataUnited States
Resend, Inc.Transactional emailEmail addresses, message contentUnited States
PostHog, Inc.Product analyticsUser ID, org ID, subscription tier, usage eventsUnited States
Sentry (Functional Software, Inc.)Error monitoringError contexts, request metadata (credentials scrubbed)United States
Inngest, Inc.Background job orchestrationJob metadata including org_id and integration_idUnited States
Upstash, Inc.Redis cachingCached synthesis bundles and rate-limit dataUnited States
Plaid, Inc.Financial account linkingFinancial account metadata (where Customer uses Plaid integration)United States
Tavily AIWeb search enrichmentSearch queries for market data enrichmentUnited States
xpay.shx402 payment settlementTransaction hashes and settlement metadataUnited States

Processor shall provide 30 days' advance notice of any additions or replacements to this list.

CONTACT

To execute this DPA or request a countersigned copy, contact: privacy@stratalize.com

SALESZ LLC dba Stratalize
205 N Michigan Ave Suite 810, Chicago, IL 60601