Version 1.1 Effective date: 29 September 2026
This Data Processing Addendum (the "DPA") forms part of the StayCharted Terms of Service (the "Agreement") between StayCharted LLC, a Texas limited liability company ("StayCharted", "we", "us"), and the customer that agreed to those Terms ("Customer", "you").
It applies where, and only to the extent that, StayCharted processes Personal Data on your behalf and that processing is subject to European Data Protection Law or US State Privacy Law.
How this takes effect. This DPA is incorporated into the Agreement by reference and applies automatically from the date you accept the Agreement, with no signature required. If your organization requires a countersigned copy, email dpa@staycharted.com and we will provide one.
Precedence. In a conflict about the processing of Personal Data, this DPA prevails over the Agreement and over the Privacy Policy. In all other respects the Agreement continues unchanged.
No admission as to jurisdiction. We enter into this DPA so that you can meet your own obligations as a controller under Article 28 of the GDPR and equivalent provisions. Doing so is not an acknowledgement that European Data Protection Law applies to StayCharted directly under Article 3 of the GDPR, and it is not evidence that we offer goods or services to, or monitor the behaviour of, people in the European Union.
1. Definitions
"European Data Protection Law" — Regulation (EU) 2016/679 (the "GDPR"); the GDPR as incorporated into the law of the United Kingdom by the European Union (Withdrawal) Act 2018 (the "UK GDPR"); and the Swiss Federal Act on Data Protection, each as amended or replaced.
"US State Privacy Law" — the Texas Data Privacy and Security Act, the California Consumer Privacy Act as amended by the CPRA, and comparable comprehensive state privacy statutes, each to the extent it applies.
"Personal Data" — personal data, personal information, or the equivalent term under the applicable law, that is contained in Customer Content or otherwise processed by StayCharted on your behalf under the Agreement.
"Data Subject", "controller", "processor", "processing", "personal data breach" and "supervisory authority" have the meanings given in the GDPR. Where US State Privacy Law applies, "controller" includes a "business" and "processor" includes a "service provider" or "processor" as those terms are defined there.
"Subprocessor" — any third party engaged by StayCharted to process Personal Data on your behalf.
"SCCs" — the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914.
"UK Addendum" — the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
Terms defined in the Agreement — including Customer Content, Service, Organization, Workspace, Owner, Member, Authorised User, Plan and Output — carry the same meaning here. In particular: the Organization is the customer account and holds a database schema of its own; a Workspace is a compartment inside it that carries a Plan; and Customer Content belongs to a Workspace.
2. Roles of the parties
2.1 For Personal Data within Customer Content, you are the controller and StayCharted is the processor. Where you are yourself a processor for another controller, you are that controller's processor and StayCharted is a subprocessor; you confirm you have the authority you need to appoint us, and references to your instructions include instructions passed down from that controller.
2.2 StayCharted is an independent controller for the limited data it processes for its own business purposes — account administration, billing, security, fraud prevention, support, and its own legal obligations. That processing is described in the Privacy Policy and is outside this DPA.
2.3 Under US State Privacy Law, StayCharted acts as a service provider or processor and not as a third party. We do not sell or share Personal Data, do not retain, use or disclose it for any purpose other than performing the Service, do not use it outside our direct business relationship with you, and do not combine it with personal information received from anyone else except as that law permits.
3. Processing of Personal Data
3.1 Documented instructions. StayCharted processes Personal Data only on your documented instructions, which comprise: this DPA and the Agreement; the actions you and your Authorised Users take in the Service and through the Prediction API; and any further written instruction you give that we accept. We also process where required by law that applies to us, and in that case we will tell you first unless the law prohibits it.
3.2 Unlawful instructions. If we believe an instruction infringes European Data Protection Law, we will tell you and may suspend that processing until it is resolved.
3.3 Details of processing. The subject matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of Data Subject are set out in Annex I.
3.4 Your responsibilities. You are responsible for: the lawfulness of the Personal Data you submit and of your instructions; having a valid legal basis; giving Data Subjects the notices your own law requires; the accuracy of the data; and the decisions you make using Output. You must not submit the categories of data prohibited by section 7.2 of the Agreement unless we have agreed otherwise in writing, and this DPA is not that agreement.
3.5 Your data trains your models only. StayCharted does not use Personal Data to train base models, to train or tune anything for any other customer, or to improve the Service's general capabilities. Personal Data is used to operate the Service for you, and for nothing else.
4. Confidentiality and personnel
StayCharted ensures that anyone authorised to process Personal Data is bound by an obligation of confidentiality, receives access only to what their role requires, and is subject to the role separation described in Annex II.
5. Security
5.1 StayCharted implements appropriate technical and organizational measures to protect Personal Data, having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to Data Subjects. Those measures are described in Annex II.
5.2 We may update the measures in Annex II as the Service develops, provided the level of protection is not materially reduced.
5.3 You are responsible for your own side of the security boundary: the confidentiality of your credentials and API keys, the access you grant your Authorised Users, and your decisions about what to upload.
6. Subprocessors
6.1 General authorisation. You give StayCharted general authorisation to engage Subprocessors. The Subprocessors currently engaged are named in Annex III, which also identifies, separately, the providers that support our own business and do not receive Customer Content.
6.2 Terms. We impose on each Subprocessor data protection obligations no less protective than those in this DPA, and we remain fully liable to you for each Subprocessor's performance.
6.3 Changes. We will give you at least 30 days' notice before adding or replacing a Subprocessor, by email to the address on your account. If you have a reasonable data protection objection, tell us within that period and we will work with you in good faith to find an alternative. If we cannot, you may terminate the affected part of the Service without penalty and receive a refund of any prepaid fees for the unused portion of the current month.
7. Assistance with Data Subject rights
7.1 The Service gives you the means to access, correct, export and delete Personal Data within Customer Content yourself — in your datasets, your uploaded files, your stored predictions and your results — which is ordinarily how a request is satisfied.
7.2 Deletion of data used to train models. A Dedicated Model is produced by training on your dataset. Deleting a record from that dataset removes it from the corpus but does not remove its influence from a model that has already been trained on it, and no technique available to us can selectively remove one record from trained weights. The Service's mechanism for this is retraining: once the record is deleted from the dataset, retraining produces a new version that was never trained on it, and promoting that version makes it the one that answers. Until you retrain and promote, the previously trained version continues to carry the influence of the deleted record. A Classifier Model, AI Classifier Model or AI Image Classifier Model is not an adapter, but its stored weights and vocabulary are likewise derived from the dataset and are replaced on retrain.
7.2.1 The full erasure path. A record can survive in more places than the live dataset, and satisfying an erasure request means dealing with each of them. The Service provides for all of the following:
| Where a record can persist | How it is removed |
|---|---|
| The curated dataset | Delete the record in the Service |
| The original uploaded file, and the archived copy kept as provenance | Delete the model in the Service to remove its training files and archived uploads; these files cannot be deleted individually |
| Files submitted for filling, and filled results | Delete them in the Service |
| Stored predictions | Delete them in the Service |
| The live trained model | Retrain from the corrected dataset and promote the new version, as described above |
| Superseded model versions and their adapters | Delete the version in the Service; deleting a model deletes every version and adapter under it |
| A cancelled or archived workspace holding any of the above | Restore it and act as above, or ask us to delete the workspace outright |
| Backups | Overwritten on the ordinary rolling cycle — see section 10.5 |
Where any of these cannot be reached through the Service, or where you would rather we did it, ask us at dpa@staycharted.com and we will carry the deletion out on your instruction at no charge, and confirm when it is done.
7.2.2 Retraining is your decision. Whether and when to retrain in response to a Data Subject request is your decision as controller. A model trained before the deletion continues to carry that record's influence until you retrain, and we will not retrain unprompted. We make the mechanism available and do not charge a training fee for a retrain carried out to satisfy a verified erasure request.
7.3 Where you cannot satisfy a request through the Service, StayCharted will provide reasonable assistance, taking account of the nature of the processing and the information available to us.
7.4 If a Data Subject contacts us directly about Personal Data in your Customer Content, we will not respond on the substance. We will tell them to contact you, and tell you promptly unless the law prohibits it.
8. Personal data breach
8.1 StayCharted will notify you without undue delay after becoming aware of a personal data breach affecting Personal Data processed on your behalf.
8.2 The notification will describe, so far as we know it: the nature of the breach and the categories and approximate number of Data Subjects and records affected; the likely consequences; the measures taken or proposed; and a contact point for further information. Where we cannot provide all of it at once, we will provide it in stages as it becomes available.
8.3 We will assist you in meeting your own obligations to notify supervisory authorities and Data Subjects. Notifying a supervisory authority or a Data Subject is your decision and your responsibility as controller.
8.4 Our notification is not an admission of fault or liability.
9. Data protection impact assessments
StayCharted will provide reasonable assistance with data protection impact assessments and prior consultations under Articles 35 and 36 of the GDPR, taking account of the nature of the processing and the information available to us. Ordinarily this means answering reasonable written questions and providing the information in this DPA and the Privacy Policy.
10. Deletion and return
10.1 Return — self-service, at any time during the term. The Service provides export as a function the Customer runs, and it is available on every plan and throughout the term, in a structured, commonly used, machine-readable format. It is not an entitlement StayCharted can withhold, and it does not depend on any fee being paid or on the account being in good standing.
StayCharted does not perform exports on the Customer's behalf. Our personnel do not sign in to customer accounts and the Service provides no mechanism for us to act inside one (Annex II).
The Customer must export before closing the Organization or otherwise ending the provision of services. Cancellation of a paid subscription does not close the workspace or remove its content: it moves to Free as described in section 10.3, and self-service export remains available. An archived workspace must be restored before export. On closure of the Organization the content is deleted. Section 11.4 of the Agreement describes the same export arrangements.
Who may exercise it. Export is an Owner action within the Service. It is not a route by which an individual Member, or a Data Subject, obtains a workspace's contents — a Data Subject's own rights are dealt with in section 7 and are directed to you.
Deletion we do perform. Sections 10.2 to 10.4 are obligations we carry out on your instruction.
10.2 Deletion on closure. On closure of your Organization, StayCharted deletes Personal Data within Customer Content as described in section 11 of the Agreement: the database schema holding the content is dropped, API keys and sessions are deleted, and stored files are removed from object storage. Logins are deleted for those whose only connection to the Service was that Organization; a person who holds their own Organization or belongs to another keeps their login, losing only their membership of the closed one.
10.3 Archiving and subscription changes. Archiving hides a workspace and deletes nothing. An archived workspace is retained while the Organization is open and can be restored; archiving alone starts no deletion period.
Cancelling a paid subscription moves the workspace to Free at the end of the paid period. Paid access continues during payment retries. If those retries are exhausted and the subscription ends, the workspace moves to Free. The workspace remains visible unless separately archived, and its content is retained, subject to the applicable retention rules and deletion instructions. Free plan limits apply. Cancellation or unsuccessful payment does not start an automatic 30-day deletion period. You may instruct us to delete content under section 10.4.
10.4 Deletion on instruction. At any time you may instruct us to delete specified Personal Data, and we will do so. Where the Service cannot reach it, we will carry it out by hand — see section 7.2.1.
10.5 Backups. Deleted content persists in encrypted backups until the ordinary rolling backup cycle overwrites it, which is never more than 35 days and in practice much less. Backups exist for disaster recovery only and are not used for ordinary business purposes. Deleted content is not restored to the live Service, and while it persists it remains protected by this DPA.
10.6 Legal retention. We may retain Personal Data where the law requires, for the period it requires, and for that purpose only.
11. Audit and information
11.1 StayCharted will make available the information reasonably necessary to demonstrate compliance with this DPA, and will respond to reasonable written security and data protection questionnaires.
11.2 Where that is not sufficient to satisfy an audit obligation under Article 28(3)(h), you may audit us, subject to: not more than once in any 12-month period except following a personal data breach or where a supervisory authority requires it; at least 30 days' written notice; during business hours; without unreasonable disruption; under confidentiality obligations; excluding access to other customers' data, and to any premises, systems or information whose disclosure would compromise the security of another customer; and at your expense.
11.2A These conditions do not cut down Clause 8.9 of the SCCs. Where the SCCs apply, the audit and information rights in Clause 8.9 apply on their own terms, and the practical conditions in section 11.2 are how we will ordinarily arrange an audit rather than a limit on that right. If any condition in section 11.2 conflicts with Clause 8.9, or with what a supervisory authority requires, Clause 8.9 and that requirement prevail — as section 12.5 already provides.
11.3 An audit conducted by a third party requires that the third party is not a competitor of StayCharted and signs a confidentiality agreement with us.
12. International transfers
12.1 StayCharted processes Personal Data in the United States. Where you transfer Personal Data subject to European Data Protection Law to us, the following apply.
12.2 EU — which Module applies. The SCCs are incorporated into this DPA by reference and are entered into by the parties, with you as data exporter and StayCharted LLC as data importer. The Module depends on the capacity in which you act, as established by section 2.1:
- Module Two (controller to processor) applies where you are the controller of the Personal Data.
- Module Three (processor to processor) applies where you are yourself a processor acting for a third-party controller, and StayCharted is your subprocessor. In that case you confirm that your own contract with that controller permits you to engage us and to agree these terms, and that our processing is consistent with that controller's instructions as passed to you.
Only one Module applies to any given transfer, and where both could be read to apply, the one matching your capacity for that Personal Data prevails. The elections below apply to whichever Module applies:
- Clause 7 (docking clause): included;
- Clause 9 (subprocessors): Option 2, general written authorisation, with the notice period in section 6.3 of this DPA;
- Clause 11 (redress): the optional independent dispute resolution paragraph is not included;
- Clause 13 (supervisory authority): as identified in Annex I;
- Clause 17 (governing law): the law of Ireland;
- Clause 18(b) (forum): the courts of Ireland;
- Annex I of the SCCs: completed by Annex I of this DPA;
- Annex II of the SCCs: completed by Annex II of this DPA;
- Annex III of the SCCs (list of subprocessors): completed by Annex III of this DPA.
Under Module Three, our notifications under Clause 8.9, Clause 15 and section 8 of this DPA are made to you, and you are responsible for passing them to your controller.
12.3 UK. The UK Addendum is incorporated, with the SCCs as above, completed as follows:
- Table 1 (parties): the exporter is the Customer, with the contact details on its account; the importer is StayCharted LLC, Texas, United States, contact dpa@staycharted.com. Neither party's signature is required, since this DPA takes effect as described above.
- Table 2 (selected SCCs): the approved EU SCCs referred to in section 12.2, with the Module and elections there.
- Table 3 (appendix information): Annexes I, II and III of this DPA.
- Table 4 (ending the Addendum): the party that may end the Addendum when the Approved Addendum changes is the exporter only.
12.3A Transfer risk assessment. We will provide, on request and without charge, the information you reasonably need to carry out a transfer impact or transfer risk assessment — including the information in Annex II, our record of any government access request of the kind described in section 12.6, and a description of the legal regime applicable to us. Carrying out that assessment is your responsibility as exporter; providing the facts it rests on is ours.
12.4 Switzerland. The SCCs apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, references to supervisory authorities read as including the Swiss Federal Data Protection and Information Commissioner, and the protections extended to legal entities where Swiss law requires.
12.5 Precedence. If there is a conflict between the SCCs or the UK Addendum and any other part of this DPA or the Agreement, the SCCs or UK Addendum prevail.
12.6 Government access requests. If StayCharted receives a legally binding request from a public authority for Personal Data processed on your behalf, we will notify you unless prohibited by law; where prohibited, we will use reasonable efforts to obtain a waiver and will challenge requests we consider unlawful or overbroad.
13. Liability
13.1 The limitations and exclusions of liability in section 13 of the Agreement apply to claims under this DPA, and the caps are aggregate across the Agreement and this DPA together — entering into this DPA does not create a second cap.
13.2 Nothing in this DPA or the Agreement limits or excludes any liability that cannot lawfully be limited or excluded. This includes a Data Subject's direct right to compensation under Article 82 of the GDPR, which no contract between the parties can cap, and either party's liability to a supervisory authority.
13.3 Contribution. Where one party has paid full compensation for damage caused by processing, it may claim back from the other the part of that compensation corresponding to the other's responsibility, in accordance with Article 82(5) of the GDPR. Section 14 of the Agreement (Indemnity) continues to apply on its own terms.
13.4 Nothing in this section 13 affects the rights of Data Subjects under the SCCs or under European Data Protection Law. In particular, the caps in section 13.1 do not apply to, and cannot reduce, StayCharted's liability to a Data Subject under Clause 12 of the SCCs or under Article 82 of the GDPR; they operate only between the parties. Where the SCCs apply and any limitation in the Agreement would conflict with them, the SCCs prevail under section 12.5.
14. Term, changes and general
14.1 This DPA takes effect when you accept the Agreement and continues for as long as StayCharted processes Personal Data on your behalf, and thereafter for any obligation that by its nature survives.
14.2 We may update this DPA where a change in law, a supervisory authority decision, or a change to the Service requires it. We will give at least 30 days' notice of a material change by email to the address on your account, and will not make a change that materially reduces the protection of Personal Data.
14.3 Versions. Each version of this DPA carries a version number and an effective date, and remains available at its own permanent address after it is superseded, so that you can identify and retrieve the version that governed your account at any given time. The current version is always published at https://staycharted.com/legal/dpa.
14.4 Governing law and jurisdiction follow section 16.1 of the Agreement, except where the SCCs or the UK Addendum specify otherwise for the processing they cover.
14.5 If any provision is unenforceable, it is modified to the minimum extent needed or severed, and the rest stands.
Annex I — Details of the processing
Completes Annex I of the SCCs. Data exporter: Customer. Data importer: StayCharted LLC, Texas, United States — contact dpa@staycharted.com.
Roles. Customer is the controller (SCC Module Two) or a processor acting for a third-party controller (SCC Module Three). StayCharted is the processor or subprocessor accordingly.
Subject matter. Provision of the StayCharted service: training classification models on data the Customer supplies, applying those models to records the Customer supplies, and returning the results.
Duration. For the term of the Agreement, and thereafter as set out in section 10 of this DPA.
Nature and purpose of the processing. Receiving and storing uploaded files; parsing and validating them; deriving a curated dataset from the Customer's labelling and corrections; examining text for values that appear to be personal or secret information and, where the Customer so chooses, replacing those values with placeholders in the data used for training and prediction; training a model on that dataset; generating predictions for records the Customer submits, whether by file upload or through the Prediction API; storing predictions and results; and making all of the foregoing available to the Customer for retrieval, export and deletion.
Where the Customer uses Vision, the processing also includes: receiving pictures in a ZIP file, or fetching pictures from image links the Customer supplies; producing from each picture a checksum, a resized copy, a thumbnail and a numeric representation used for training and prediction; and removing the picture's embedded metadata in doing so, including EXIF (GPS position, camera serial number, time taken), XMP and the colour profile. The resized copy and thumbnail we retain carry none of that metadata. The original uploaded ZIP is also retained unchanged as the model's training file, including any location, camera or other embedded metadata in its pictures. Deleting the model removes its training files and archived uploads; individual training files cannot be deleted separately. You may also instruct us to delete Personal Data under section 10.4.
Categories of Data Subject. Determined by the Customer, since the Customer decides what to upload. Typically: individuals referred to in the Customer's own business records, and the Customer's Authorised Users — the Owner and the Members of the Organization.
Types of Personal Data. Determined by the Customer. Personal Data may appear in any free-text field of an uploaded file, and in any picture the Customer uploads or links to, so the types are not fixed in advance. For Authorised Users: name, email address, sign-in identifier, role, workspace memberships, and activity records.
Sensitive data. Not permitted as a purpose of the processing. Section 7.2 of the Agreement prohibits the Customer from using the Service to process health, biometric, genetic, financial-account, payment-card, government-identifier, precise-location, criminal-offence and under-18 data, or any other special category, absent a separate written agreement. This DPA does not authorise such processing, and the Customer must agree it separately if required.
Incidental occurrence is a different matter and is provided for. Values of some of those kinds — a card number, a national identifier, a telephone number — may appear by accident in ordinary business records. The Service detects a defined set of such values before training and offers the Customer the choice to mask them, exclude the rows or retain them; the choice, including a decision to retain, is the Customer's and is recorded. Masking applies to the data used for training and prediction. It does not apply to the archived copy of the Customer's original upload, nor to the filled file returned to the Customer, both of which retain the original values until the Customer deletes them or instructs us to.
Frequency. Continuous, for the duration of the Agreement.
Retention. As set out in section 8 of the Privacy Policy and section 11 of the Agreement, and in section 10 of this DPA. In outline: for as long as the Organization is open, unless content is deleted earlier under the applicable retention rules or on instruction; deleted on closure of the Organization. A workspace that moves to Free after cancellation or unsuccessful payment keeps its content. That change does not start an automatic 30-day deletion period.
Subprocessors. See Annex III. Processing by Subprocessors is for the duration of the Agreement and limited to what their category of service requires.
Competent supervisory authority (SCC Clause 13). Determined under Clause 13 as follows: the supervisory authority of the EEA Member State in which the Customer is established; or, where the Customer is not established in the EEA but has appointed an Article 27 representative, the supervisory authority of the Member State in which that representative is established; or, where the Customer is not established in the EEA and has appointed no representative, the supervisory authority of the Member State in which the Data Subjects whose Personal Data is transferred are located. For transfers under the UK Addendum, the Information Commissioner's Office.
Annex II — Technical and organizational measures
Completes Annex II of the SCCs. These describe measures in place at the effective date. They may be updated under section 5.2, provided protection is not materially reduced.
Tenant isolation. Each Organization's content is held in a dedicated database schema, and workspaces are separated from one another inside it by row-level security, which is enabled and forced on the content tables so that it applies even to the table owner. A request is bound to one Organization and one workspace for its lifetime; nothing is permitted by absence, so an unbound connection sees no rows at all, and work that outlives a request fails rather than writing to a shared schema. Isolation is tested adversarially in our test suite, from two different database roles.
No impersonation. The Service provides no mechanism by which StayCharted personnel can sign in as a Customer, act within a Customer's account, or use a Customer's API keys. This is a property of the application. It is not a representation that personnel with infrastructure access cannot read stored data; the access controls below address that.
Access control. Staff access is separated by role: staff who administer infrastructure cannot read customer accounts, and staff who support customers cannot change infrastructure. The most destructive operations are restricted to a single owner role and require typing the organization's name to confirm. Every administrative action is recorded in an audit log with actor, action, subject and timestamp.
Multi-factor authentication is required for operator accounts. Every account with administrative access to the deployment must present a second factor in addition to a password. Operator sessions are separate from customer sessions and expire after 12 hours.
Encryption. TLS in transit, with HSTS. Stored secrets are encrypted at rest and are never returned to a browser. Passwords are hashed with scrypt and verified in constant time.
Authentication. Sign-in responses are identical for an unknown address and a wrong password, so addresses cannot be enumerated. Credential routes are rate-limited. Sessions are stored server-side and expire — 30 days for customer sessions, 12 hours for operator sessions — and are invalidated on account closure.
Input handling. Uploaded files are verified against their actual contents rather than their declared type, and spreadsheet formulas are neutralised on export. Data files are refused if they carry macros, or if they are archives other than workbooks. Picture ZIP files are read by a separate reader that accepts only image files, skips and reports anything else, and enforces limits on individual file size, total uncompressed size and entry count. Decompression is measured against a budget in both paths rather than trusted. Database statements are parameterised throughout, checked by an automated gate.
Fail-closed behaviour. Errors do not return stack traces or database messages to a client. Uploads are scanned for malware, and an upload is refused rather than accepted if the scanner cannot be reached.
Encryption at rest. Customer Content is held in managed database and object storage with encryption at rest enabled at the storage layer: database storage encryption is enabled using a key held in our cloud provider's key management service, and default server-side encryption is enabled on every storage bucket holding Customer Content. Public access is blocked on those buckets.
Security checks. Our test suite includes automated checks for the security protections named in this Annex and scans of JavaScript dependencies. When run, these checks fail if a tested protection is removed or the dependency scan reports a high or critical advisory. An unreachable dependency registry causes the scan to fail rather than be skipped.
Deletion. Account closure drops the tenant schema, deletes credentials, API keys and sessions, and sweeps stored objects, including objects a failed deletion left behind.
Retention in trained models. A trained model derives from the Customer's dataset and retains its influence until the model is retrained. Deleting a record does not alter an already-trained model. See section 7.2 of this DPA.
Measures not currently in place.
- No automated alerting on security events. Events are recorded and reviewed on demand rather than raising an alert as they occur.
- Dependency scanning covers the JavaScript components only, and not the Python training and serving components.
- No Content-Security-Policy.
- No third-party penetration test, external assessment or certification has been performed against the deployment.
- Subscription changes do not trigger deletion. A workspace that moves to Free retains its content as described in section 10.3.
Annex III — Subprocessors
Subprocessors of Customer Content
These are the only third parties that process Personal Data within Customer Content on your behalf. This is the list contemplated by Clause 9 of the SCCs.
| Subprocessor | Function | Processing location |
|---|---|---|
| Amazon Web Services, Inc. | All hosting of Customer Content: application servers, the database holding the tenant schemas, object storage for uploaded and generated files, and the compute on which models are trained and predictions are generated | United States |
| Plus Five Five, Inc. (Resend) | Delivers service notifications containing recipient details and customer-provided file and model names; does not receive file contents, training datasets or trained models through these notifications | United States (primary processing and storage) |
Resend also processes customer-supplied file names and model names in file-ready and training-completion notifications, along with the recipient details needed for delivery. It does not receive file contents, training datasets or trained models through these notifications.
No AI or model provider outside our own cloud account receives any of it: training, inference and malware scanning all run on infrastructure we control, within our own account. If we engage a third party for any of them, it will be added to this table with the notice in section 6.3 before it processes anything.
Providers supporting our own business, which are not subprocessors
We use the following for our own purposes as a controller, as described in the Privacy Policy. They do not receive Customer Content:
| Provider category | What it handles | Why it is not a subprocessor |
|---|---|---|
| Payment processing | The Owner's billing details, subscriptions and invoices | Billing data is processed by us as controller; no Customer Content reaches it |
| Outbound email for our own business | Verification and billing messages | These messages contain account and billing information; processing of file names and model names in application notifications is described above as subprocessing of Customer Content |
| Website hosting and analytics | Our public marketing site and its cookieless visitor counting | Separate from the application; no Customer Content and no account data |
| Identity providers | Sign-in, only where a user chooses one | Receives authentication requests only |
| Operational tooling | Error reporting and support correspondence, where used | Configured to exclude Customer Content |
We will provide the named identity, location and role of any provider in either table on request to dpa@staycharted.com, without charge.
Version history
| Version | Effective | Change |
|---|---|---|
| 1.1 | 29 September 2026 | Corrects upload retention, deletion controls, subscription changes, security-check wording and notification email processing. |
| 1.0 | 28 September 2026 | First published. |