Legal

Data Processing Agreement

Last updated: April 25, 2026 · Version 1 (draft)

1. Parties and roles

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Budstacks Lda ("BudStacks", "Processor") and the operator entity ("Operator", "Controller") that has accepted it. It governs the processing of personal data by BudStacks on behalf of the Operator in connection with the BudStacks platform.

Where applicable, the EU Standard Contractual Clauses (Module Two — Controller to Processor, Commission Implementing Decision (EU) 2021/914) and the UK International Data Transfer Addendum (B1.0) are incorporated by reference for transfers outside the EEA / United Kingdom.

2. Subject matter, duration, nature and purpose

  • Subject matter: processing of personal data by BudStacks to provide the platform services described in the Terms of Service.
  • Duration: for the term of the agreement and any post-termination period required for data export, return, or deletion.
  • Nature and purpose: hosting, storing, processing, and transmitting personal data submitted by the Operator or generated by end-customers using the Operator's storefront.
  • Categories of data subjects: Operator's employees, end-customers, patients, prospects, and authorised users of the Operator's storefront.
  • Categories of personal data: identifiers (name, email, phone), addresses, account credentials (hashed), order data, payment-method tokens, and — where the Operator chooses to upload it — health-related data (prescriptions, KYC, conditions) classified as special-category data under GDPR Article 9.

3. Controller instructions

BudStacks processes personal data only on the Operator's documented instructions (including the Terms of Service, this DPA, and the operating settings configured in the platform), unless required by Union or member-state law. BudStacks will inform the Operator of any such legal requirement before processing, unless that law prohibits such notification on important grounds of public interest.

4. Confidentiality

BudStacks ensures that personnel authorised to process personal data are bound by appropriate confidentiality obligations and trained in data protection.

5. Security measures (Article 32)

BudStacks implements appropriate technical and organisational measures including:

  • Encryption in transit (TLS 1.2 or higher) and at rest
  • Access control on the principle of least privilege; multi-factor authentication for administrative access
  • Network segmentation; isolation of tenant data partitions
  • Audit logging of administrative and security events
  • Regular dependency scanning, vulnerability management, and patching
  • Backups and tested restore procedures
  • Documented incident-response and business-continuity plans

Detailed security documentation is available to Operators on request under NDA.

6. Sub-processors (Article 28(2)(4))

The Operator grants general authorisation for BudStacks to engage sub-processors, subject to the following conditions:

  • The current list is published at /legal/subprocessors.
  • BudStacks notifies the Operator by email at least 30 days before adding or replacing a sub-processor.
  • The Operator may reasonably object to a new sub-processor within 14 days of notice. If the parties cannot agree a resolution, the Operator may terminate the affected services with a pro-rata refund of pre-paid fees.
  • BudStacks imposes data-protection obligations on each sub-processor that are no less protective than those in this DPA, and remains liable for the sub-processor's performance.

7. Assistance with data-subject rights (Article 28(3)(e))

BudStacks provides reasonable assistance, including via in-platform tooling, APIs, and support, to help the Operator respond to requests from data subjects exercising rights under Articles 15–22 GDPR (access, rectification, erasure, restriction, portability, objection).

8. Personal-data breach notification (Article 33)

BudStacks notifies the Operator without undue delay and in any event within 72 hours of becoming aware of a personal-data breach affecting the Operator's data, providing the information required by Article 33(3) GDPR to the extent then available, with subsequent updates as more information becomes known.

9. Data Protection Impact Assessments (Articles 35–36)

BudStacks provides reasonable assistance to the Operator in carrying out DPIAs and, where required, prior consultations with supervisory authorities.

10. Return or deletion of data (Article 28(3)(g))

On termination of the agreement, BudStacks will, at the Operator's choice, delete or return all personal data, and delete existing copies, unless retention is required by Union or member-state law. The platform provides export tooling accessible for 30 days post-termination; thereafter data is deleted within 90 days, subject to backup retention windows.

11. Audit rights (Article 28(3)(h))

BudStacks makes available to the Operator information necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Operator or another auditor mandated by the Operator. Audits are conducted at the Operator's expense, on at least 30 days' written notice, no more than once per year (unless required by a supervisory authority or following a confirmed breach), and subject to reasonable confidentiality, security, and operational-impact constraints.

12. International transfers

Where personal data is transferred outside the EEA / United Kingdom, the EU Standard Contractual Clauses (Module Two) and the UK Addendum apply, with the transfer details set out in the sub-processor list. BudStacks implements additional technical and organisational measures (including encryption and access controls) where required by the recipient jurisdiction's risk profile.

13. Liability

The liability of each party under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.

14. Acceptance

Operators accept this DPA as part of onboarding. A countersigned PDF copy is available on request from [email protected]. The current version of the DPA is recorded in the legal changelog.