Data Processing Addendum.
Legal

Data Processing Addendum.

This addendum applies where Sterdam processes personal data on your behalf, and forms part of your engagement agreement.

Last updated: 2026-08-24

1. Roles

Where you determine the purposes and means of processing, you are the controller and Sterdam is the processor. Sterdam processes personal data only on your documented instructions.

2. Scope of processing

Subject matter, duration, nature, and purpose of processing are defined by the engagement. Data subjects typically include your users, staff, and contacts.

3. Confidentiality

Personnel with access to personal data are bound by confidentiality obligations and access is granted on a least-privilege basis.

4. Security measures

  • Encryption in transit and at rest where supported.
  • Role-based access control and audit logging.
  • Environment separation and least-privilege service accounts.
  • Regular review of access and dependencies.

5. Sub-processors

We use a limited set of sub-processors, including hosting and database infrastructure, payment processing, and email delivery. We remain responsible for their performance and will give notice of material changes.

6. International transfers

Transfers outside your region rely on Standard Contractual Clauses or equivalent safeguards under GDPR, UK GDPR, and POPIA.

7. Assistance and breach notification

We assist with data subject requests, impact assessments, and regulator queries, and notify you without undue delay after becoming aware of a personal data breach.

8. Deletion and return

On termination we delete or return personal data, except where retention is required by law.

9. Audit

We make available the information reasonably needed to demonstrate compliance and support audits scoped to the processing under the engagement.