Data Processing Addendum
A Data Processing Addendum (DPA) is available on request to Enterprise customers and to customers of the forthcoming Managed Email service (planned launch in 2027) where Stalwart Labs Ltd processes personal data of EU or UK data subjects on the customer’s behalf.
For the open-source self-hosted server, the customer remains the sole controller of any personal data stored in their own deployment; Stalwart Labs Ltd does not act as a processor and no DPA is required.
For data that Stalwart Labs Ltd collects directly from individuals through its own websites, including the Licensing Portal at license.stalw.art and the Support Portal at support.stalw.art, Stalwart Labs Ltd acts as the controller, and that processing is governed by the Privacy Policy rather than by this DPA.
Controller / processor relationship
For Enterprise license holders and Managed Email subscribers, the relationship is as follows:
- The customer (or the customer’s organisation) is the controller of the personal data.
- Stalwart Labs Ltd is the processor, acting only on the documented instructions of the controller.
- The DPA is supplementary to the Terms and Conditions and incorporates by reference: (a) the obligations of processors under Article 28 of the EU GDPR and the UK GDPR; (b) the European Commission’s Standard Contractual Clauses (SCCs) for transfers of personal data to third countries, where applicable; and (c) the UK International Data Transfer Addendum to the SCCs, where applicable.
- The DPA records the categories of data subjects and personal data processed, the duration of processing, the technical and organisational security measures in place, and the list of authorised sub-processors (see Sub-processor list).
Requesting the DPA
To request the current DPA template, please contact [email protected].