LEGAL
PlantStacks — Data Processing Addendum (DPA)
Last updated: 17 June 2026 · Version 2.0 (US / North Carolina)
This Data Processing Addendum ("DPA") forms part of the Terms of Service between PlantStacks, LLC ("we", "us") and the Customer, and reflects the parties' agreement on the processing of personal information under applicable US state privacy laws (e.g. the CCPA/CPRA and similar).
1. The key point: roles under a self-hosted model
PlantStacks runs on the Customer's own infrastructure. Personal information the Customer processes inside its installation (its own staff accounts, its customers/suppliers, inventory records, files) is stored and processed solely by the Customer, on the Customer's systems, and does not flow to us.
Accordingly:
- For data inside the Customer's installation, the **Customer is the business/controller and
- For the limited data we do handle to run our business (account, billing, trial, support, license
processor. We are not a service provider/processor** of that data because we never receive or have access to it.
data), we are an independent business/controller, governed by our Privacy Policy.
This is a deliberate, privacy-protective design and materially reduces the Customer's vendor-management burden.
2. When (and only when) we act as a service provider/processor
If the Customer enables an optional feature that intentionally transmits personal information to us or our sub-processors (for example, an opt-in support bridge, telemetry, or a hosted add-on), then for that specific data flow we act as the Customer's service provider/processor, and the terms in clauses 3–7 apply to it. Absent such an opt-in, no Customer personal information is processed by us.
3. Service-provider obligations (where clause 2 applies)
Where we act as a service provider/processor we will: (a) process personal information only for the limited, specified purpose of providing the opted-in feature and on the Customer's documented instructions; (b) not "sell" or "share" it and not retain, use, or disclose it for any other purpose or outside the direct business relationship; (c) ensure persons processing it are bound by confidentiality; (d) implement reasonable security measures; (e) engage sub-processors only under equivalent terms; (f) assist the Customer with consumer-rights requests and security-incident obligations; (g) notify the Customer without undue delay of a breach of that data; and (h) on termination, delete or return that data at the Customer's choice.
4. Sub-processors
Where clause 2 applies, our sub-processors may include our hosting and email providers (e.g. Resend) and Stripe. A current list is available on request.
5. Certification
We certify that we understand and will comply with the restrictions in clause 3 with respect to any personal information made available to us by the Customer.
6. Details of processing (where clause 2 applies)
- Duration: as long as the opted-in feature is used.
- Nature/purpose: providing the specific opted-in feature.
- Data types / subjects: as determined by the feature and the Customer's configuration.
7. International transfers (EEA / UK)
For the limited account, billing, trial, and support data we process as a controller (your operational data stays on your self-hosted install and never reaches us), data is processed in the United States. Where the EU GDPR or UK GDPR applies, transfers rely on appropriate safeguards (e.g. the Standard Contractual Clauses and the UK Addendum) where required. _Confirm SCCs, any transfer-impact assessment, and any EU/UK representative requirement with an attorney before selling into those regions._
8. General
In case of conflict between this DPA and the Terms regarding personal-information processing, this DPA prevails. Governing law: State of North Carolina.
Contact (data matters): support@plantstacks.com
_Template, not legal advice. Have a US privacy attorney review before relying on it._
Document version: dpa-d5c65b36