StackyapperLegal center

Effective 2026-07-27

Data Processing Addendum

This DPA forms part of the agreement between Customer and StackYapper when StackYapper processes personal data for Customer through the Service.

1. Definitions and roles

“Customer Personal Data” means personal data processed by StackYapper on Customer’s behalf. “Data Protection Law” means privacy and data-protection law applicable to that processing. Customer is controller and StackYapper is processor, except when each acts as an independent controller for its own account, billing, security, and legal-compliance data.

2. Processing instructions

StackYapper will process Customer Personal Data only on documented instructions in the agreement, Customer’s configuration and authorized use, and as required by law. If an instruction appears to violate Data Protection Law, StackYapper will inform Customer unless prohibited. Customer is responsible for lawful instructions, notices, consents, data accuracy, and responding to data-subject requests.

3. Processing details

Subject: operating the hosted integration control plane. Duration: the agreement plus deletion and backup periods. Nature and purpose: authentication, tenant and access control, encrypted credential storage, routing authorized requests to connected services, returning results to Customer-selected clients, billing, support, security, usage reporting, and MSP/customer audit and accountability. Data subjects: Customer personnel, administrators, clients, end users, and people represented in connected business systems. Data: account identifiers, professional contact data, authentication and authorization data, connection configuration, administrative actions, connector/tool/client/session identifiers, risk class, status, timing, confirmation and policy events, security/audit metadata, and content Customer routes through enabled tools. Customer should not intentionally submit sensitive or regulated data unless the agreement expressly covers it and the workflow is configured appropriately.

4. Confidentiality and security

StackYapper will ensure personnel authorized to process Customer Personal Data are bound by confidentiality and will maintain risk-appropriate technical and organizational measures, including access control, tenant isolation, encrypted transport, cryptographic protection for stored credentials, and security and administrative logging. Customer remains responsible for securing and administering its endpoints, identity provider, authenticators, users, AI clients, workflows, connected vendors, credentials, permission scopes, backups, and recovery procedures. Customer will promptly notify StackYapper of a suspected compromise that may affect the Service and will revoke or disable affected access.

5. Subprocessors

Customer authorizes the providers on the Subprocessors page. StackYapper will impose data-protection obligations materially consistent with this DPA and remains responsible for subprocessors to the extent required by law. A customer may object to a new subprocessor on reasonable documented data-protection grounds within 15 days of notice; the parties will seek a practical resolution, and if none exists Customer may terminate the affected Service.

6. Assistance

Taking into account the nature of processing, StackYapper will reasonably assist Customer with verified data-subject requests, security obligations, breach notifications, impact assessments, and regulator consultations. Additional work beyond standard Service functionality may be charged at agreed rates.

7. Security incidents

StackYapper will notify Customer without undue delay after confirming a breach of Customer Personal Data within systems controlled by StackYapper and provide available information reasonably needed for Customer’s obligations. Notice is not an admission of fault. Customer is responsible for investigating and making legally required notifications concerning compromise of its identity provider, authenticators, endpoints, connected systems, AI clients, workflows, credentials, permissions, or configurations, unless and to the extent the incident was caused by StackYapper’s breach of this DPA, the agreement, applicable law, or StackYapper-controlled safeguards.

8. Return and deletion

On termination or verified request, StackYapper will delete or return Customer Personal Data, unless law requires retention. Data may remain temporarily in protected backups and legal, billing, fraud-prevention, or security records and will remain subject to this DPA until deleted.

9. Transfers and audits

Where Data Protection Law restricts international transfer, the parties will use an applicable transfer mechanism, including the then-current EU Standard Contractual Clauses or UK Addendum where required. StackYapper will provide available security and compliance information needed to demonstrate compliance. Audits must be proportionate, protect other customers and confidential systems, occur no more than annually unless required after an incident or by a regulator, and use independent reports first when available.

10. Priority and contact

This DPA controls over conflicting agreement terms for processing Customer Personal Data. Liability remains subject to the agreement unless Data Protection Law requires otherwise. Privacy inquiries: legal@stackyapper.dev. If a restricted international transfer requires terms not incorporated into the agreement, the parties will execute the applicable transfer mechanism before that transfer begins.


Symao Systems, doing business as StackYapper
2106 Morthland Drive #1079, Valparaiso, IN 46383, United States
legal@stackyapper.dev