This is a standard template, published so business customers don't need a sales call to get a copy — it has not been reviewed by a lawyer for your specific situation, and the bracketed fields below need to be completed before it is signed by either party. Have qualified counsel review it before relying on it as a binding agreement.
Data Processing Agreement
Last updated 2026-08-26. Version 1.0 (template).
1. Parties
This Data Processing Agreement ("DPA") is entered into between the customer identified in the applicable order form or account registration (the "Controller") and [Company name to complete], publisher of Stelyo, registered at [address to complete] (the "Processor"), and forms part of the agreement under which the Processor provides the Stelyo service to the Controller (the "Agreement").
2. Subject matter and duration
The Processor processes Personal Data on behalf of the Controller solely to provide the Stelyo service — generating, hosting, redirecting, and reporting analytics for dynamic QR codes. This DPA remains in effect for as long as the Processor processes Personal Data on the Controller's behalf under the Agreement.
3. Nature and purpose of processing
Resolving scans of QR codes created by the Controller to their configured destination, recording scan metadata for the Controller's own analytics, and — where the Controller has configured them — delivering webhooks and API responses containing that metadata.
4. Categories of data subjects and personal data
- Data subjects: end users who scan a QR code created by the Controller.
- Personal data: approximate country (derived from IP at the edge, raw IP never stored), browser user agent, referring page, scan timestamp, and a one-way, daily-rotating visitor hash used only to distinguish unique from repeat scans.
5. Processor obligations
The Processor shall:
- Process Personal Data only on the Controller's documented instructions, including as set out in this DPA;
- Ensure persons authorized to process the Personal Data are bound by confidentiality;
- Implement appropriate technical and organizational security measures, including encryption in transit, row-level access control scoped per customer account, and no storage of raw IP addresses;
- Not engage a sub-processor without the general authorization described in Section 6;
- Assist the Controller, to the extent reasonably possible, in responding to data subject rights requests;
- Assist the Controller with its obligations regarding security, breach notification, and data protection impact assessments;
- Notify the Controller without undue delay after becoming aware of a Personal Data breach affecting the Controller's data;
- At the Controller's choice, delete or return all Personal Data at the end of the Agreement, except where retention is required by law; and
- Make available information necessary to demonstrate compliance with this DPA and allow for reasonable audits.
6. Sub-processors
The Controller provides general authorization for the Processor to engage the following sub-processors, each bound by data protection terms materially equivalent to this DPA:
- Supabase (database, authentication, file storage) — hosted in the EU (Ireland)
- Vercel (web application hosting)
The Processor will give the Controller reasonable advance notice before adding or replacing a sub-processor, via [notification channel to complete, e.g. email or changelog], so the Controller may object on reasonable data-protection grounds.
7. International transfers
Personal data is hosted within the European Union. Should a future sub-processor require a transfer outside the EU/EEA, the Processor will rely on an adequate transfer mechanism (such as the European Commission's Standard Contractual Clauses) before doing so.
8. Liability
Each party's liability arising out of this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
9. Signatures
Controller: [Name, company, date, signature] — Processor: [Name, company, date, signature]