Data Processing Agreement
Last updated June 2026
A summary of how we process customer personal data as a processor, with EU/UK residency by default. A full signable DPA is available on request.
1. Roles
Where we process personal data on your behalf during a paid engagement, you are the controller and we are the processor. We process data only on your documented instructions.
2. Subject matter & duration
Processing covers the personal data necessary to deliver the engagement, for its duration plus any agreed retention.
3. Security measures
- Encryption in transit (TLS 1.3) and at rest.
- Role-based access control, SSO and audit logging.
- Data minimisation and purpose limitation.
4. Sub-processors
We use the EU-domiciled sub-processors listed in our Trust Center. We give notice of changes and you may object on reasonable grounds.
5. International transfers
Customer personal data is stored and processed within the EU/EEA and UK. We do not transfer it to US-jurisdiction infrastructure.
6. Data-subject requests & breach
We assist you in responding to data-subject requests and will notify you without undue delay on becoming aware of a personal-data breach.
7. Deletion
On termination we delete or return personal data at your choice, subject to legal retention requirements.
8. Request the full DPA
For a signable copy, email info@sovereignstack.org.uk.
This is a template provided for illustration on a demonstration site. Replace with counsel-reviewed terms before relying on it in production.