Data Processing Agreement
Last updated 10 August 2026
This DPA applies to organizations using Stackly to store or process data on behalf of their own users, customers, or employees — particularly organizations that flagged handling sensitive data during setup. It supplements our Terms of Service and Privacy Policy.
Roles
For data your organization uploads to Stackly, your organization is the data controller and Fullhold is the data processor, processing that data only to provide the service — storage, AI-assisted organization, and search — and only as instructed by your organization through the product.
Subprocessors
- Supabase — database, authentication, and file storage infrastructure.
- Your organization's chosen AI provider (Anthropic, OpenAI, or Google) — receives data only when a member has configured a BYOK key, and only the specific content sent with that request. Because keys are bring-your-own, your organization effectively chooses and contracts with this subprocessor directly.
- Your organization's chosen cloud storage provider (e.g. Google Drive), if connected during org setup.
We'll notify organizations of any change to our core subprocessor list (currently just Supabase) before it takes effect.
Access control commitment
Data belonging to your organization is isolated from every other organization on the platform, and within your organization, access is restricted by branch hierarchy — a member sees their branch and everything below it, never above it or sideways into another team's branch. This is enforced at the database level, not only in application code.
Data deletion
When your organization is deleted, or a member is removed, their access is revoked immediately. Full data deletion on request currently goes through privacy@[your-domain] — placeholder until Fullhold has a registered domain — while a self-service deletion flow is still being built.
Security incidents
We will notify affected organizations without undue delay if we become aware of a security incident affecting their data, and provide the information reasonably available to us to help your organization meet its own notification obligations.
Status
This DPA is a founder-drafted starting point, written to be honest about current architecture rather than aspirational. If your organization requires a signed, negotiated DPA (common for larger contracts), contact us — we expect to formalize this further as Stackly takes on enterprise customers.