Stable SolutionCommercial
Legal

Data Processing Addendum

Last updated July 3, 2026

This DPA describes how Stable processes personal data on your behalf. It forms part of the agreement between your organization and Stable.

This Data Processing Addendum (“DPA”) supplements the Terms of Service between the customer organization (“Controller”) and Stable Solution LLC (“Processor”). Where Stable processes personal data to provide the Services, the Controller determines the purposes and means, and Stable acts as processor on the Controller's documented instructions.

1. Processing details

  • Subject matter & duration: processing for the term of the agreement plus any legally required retention.
  • Nature & purpose: operating the facilities-management Services — intake, approval, dispatch, verification, billing, support, and the audit record.
  • Categories of data subjects: Controller's staff and site contacts, and vendor contacts.
  • Categories of personal data: names, business contact details, job roles, site associations, work-order content, and usage/log data. The Services are not intended for special-category data.

2. Processor obligations

  • Process personal data only on the Controller's documented instructions, including for international transfers, unless required by law (in which case we notify the Controller unless prohibited).
  • Ensure personnel authorized to process data are bound by confidentiality.
  • Implement appropriate technical and organizational security measures (Section 5).
  • Assist the Controller, taking into account the nature of processing, with data-subject requests and with security, breach-notification, and impact-assessment obligations.
  • At the Controller's choice, delete or return personal data at the end of the services, except where retention is required by law.

3. Subprocessors

The Controller authorizes Stable to engage subprocessors to provide the Services. Stable imposes data-protection obligations on each subprocessor no less protective than this DPA and remains responsible for their performance. Our current subprocessors are listed at /subprocessors. We will provide a mechanism to receive notice of new subprocessors and a reasonable window to object.

4. Data-subject requests

Stable will, to the extent legally permitted, promptly notify the Controller of a request from a data subject and will assist the Controller in responding, taking into account the nature of the processing and the information available to Stable.

5. Security measures

  • Encryption of personal data in transit; access to production data restricted and authenticated.
  • Tenant isolation and role-scoped access controls so an organization's data is separated from others'.
  • Least-privilege service credentials and audit logging of significant actions on a tamper-evident ledger.
  • Secure software-development practices, dependency and vulnerability management, and monitoring.
  • Regular review of access, backups, and business-continuity measures appropriate to the Services.

6. Personal-data breach

Stable will notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's data, and will provide information reasonably available to help the Controller meet its notification obligations.

7. International transfers

Where processing involves transfer of personal data from the EEA, UK, or Switzerland to a country without an adequacy decision, the parties agree that the applicable Standard Contractual Clauses (and the UK Addendum, where relevant) are incorporated by reference and apply to that transfer.

8. Audit

Stable will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable confidentiality and security conditions and notice. Stable may satisfy audit requests by providing third-party certifications or reports where available.

9. Return & deletion

On termination, and on the Controller's request, Stable will delete or return the Controller's personal data within a reasonable period, except where retention is legally required. Because the audit ledger is append-only and tamper-evident, deletion against that record is achieved by cryptographic means (destroying keys) rather than by rewriting history.

10. Precedence

In case of conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA controls. A signed copy is available for enterprise agreements — contact privacy@stablesvc.com.