Data Processing Addendum
How StellarBase processes personal data on the Customer's behalf. This addendum forms Annex No. 1 to, and an integral part of, the Terms of Use.
Effective as of 17 July 2026
This Data Processing Addendum (“DPA”) is Annex No. 1 to the Terms of Use and forms an integral part of them. It governs the processing of personal data that StellarBase s.r.o. (“Provider”) carries out on the Customer’s behalf in connection with the Services. Capitalised terms not defined here have the meaning given in the Terms of Use.
1. Definitions
1.1. In this DPA, the terms below have the following meanings:
- 1.1.1. “GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
- 1.1.2. “Personal Data” means any personal data within the meaning of the GDPR and Act No. 110/2019 Coll., on Personal Data Processing, processed by the Provider on behalf of the Customer in accordance with or in connection with the Agreement.
- 1.1.3. “Applicable Personal Data Protection Regulations” mean all legal regulations and rules relating to personal data protection applicable to the processing of personal data, in particular the GDPR and Act No. 110/2019 Coll., on Personal Data Processing.
- 1.1.4. “Service” means the Solution and related services provided by the Provider to the Customer under the Agreement.
- 1.1.5. “Party” means the Provider or the Customer, collectively also referred to as the “Parties”.
- 1.1.6. “Data Subject” means an identified or identifiable natural person to whom the Personal Data relates.
- 1.1.7. “Sub-processor” means a third party engaged by the Provider in the Processing of Personal Data on behalf of the Customer.
- 1.1.8. “Controller” means the Customer as the entity that determines the purposes for which and the means by which Personal Data are processed.
- 1.1.9. “Processing” means any operation or set of operations performed on Personal Data within the meaning of Article 4 of the GDPR (e.g., collection, storage, disclosure, use, transfer, restriction, erasure).
- 1.1.10. “Processor” means the Provider as the entity acting on the instructions of the Controller and processing Personal Data on behalf of the Controller.
1.2. Terms defined in the Terms have the same meaning in this DPA as in the Terms.
2. Obligations Related to Processing
2.1. If the Provider Processes Personal Data on behalf of the Customer when performing the Agreement, the Customer acts as the Controller and the Provider as the Processor. In the event that the Customer acts as a processor towards a third party, the Provider acts as a sub-processor.
2.2. The Provider will Process Personal Data only on the basis of documented instructions of the Customer (including instructions regarding transfer to third countries or international organizations), unless it is obliged to other Processing under applicable legal regulations. In such a case, the Provider will inform the Customer of this fact in advance, unless prevented by legal regulations.
2.3. The Provider is entitled to refuse an instruction of the Customer that would violate applicable legal regulations, and will notify the Customer of such conflict.
3. Purpose, Nature, and Scope of Processing
3.1. Subject matter and duration of Processing: Processing takes place to the extent necessary to provide the Services under the Agreement for the duration of the Agreement.
3.2. Nature and purposes of Processing: Processing takes place for the purposes of providing the Services and purposes compatible therewith, in particular storage and hosting in a cloud environment, indexing and structuring of knowledge, AI-assisted retrieval and processing, disclosure, restriction, and backup.
3.3. Types of Personal Data: Processing takes place to the extent determined by the Customer’s use of the Services, typically identification, contact, user, operational, and authentication data; the Customer may also upload documents and structured data containing personal data of third parties (employees, clients, partners) as part of its knowledge base. Special categories of personal data under Article 9 of the GDPR (including health-related data) may be processed where the Customer explicitly enables such processing and, prior to any upload, ensures and documents a valid legal basis. The Customer bears sole responsibility for the lawful basis for such processing and compliance with applicable obligations in this regard. Continuous biometric data is not supported and must not be submitted.
3.4. Categories of Data Subjects: Users and other persons whose data the Customer enters into the Solution.
4. Place of Processing and Transfers to Third Countries
4.1. Personal Data are Processed primarily within the territory of the member states of the European Economic Area. For the Shared Cloud deployment, cloud infrastructure and database storage are located within the Czech Republic and/or the EEA.
4.2. Transfers outside the EEA may occur in the following scenarios:
- a. AI processing via third-party LLM providers: when AI features are used in the Shared Cloud deployment, Customer Data (or portions thereof) may be transmitted to LLM providers whose infrastructure may be located outside the EEA. The Provider applies appropriate safeguards (including Standard Contractual Clauses where applicable) and publishes the current list of LLM providers and applicable transfer mechanisms in the Subprocessors list referenced in Article 9 of this DPA.
- b. BYOK/BYO-LLM: when the Customer uses its own LLM API keys, data transmissions are governed by the Customer’s agreement with the respective LLM provider. The Provider does not control such transfers.
- c. Self-Hosted Environment - no transfer of Personal Data occurs via the Provider’s systems. The Customer bears full responsibility for data transfers within its own infrastructure.
4.3. The Provider will not process Personal Data outside the EEA for purposes other than those described in Article 4.2 without the prior consent of the Customer.
5. Technical and Organizational Security Measures
5.1. The Provider is obliged to maintain reasonable security standards for the protection of personal data, taking into account the nature of the processed Personal Data.
5.2. The Parties undertake to ensure appropriate standards of technical and organizational security against unauthorized handling of Personal Data, in particular their accidental loss, alteration, destruction, or damage.
5.3. The Provider shall ensure that persons authorized to process the Personal Data are bound by a contractual or statutory duty of confidentiality and are regularly trained in the field of information security.
6. Rights of Data Subjects and Mutual Cooperation
6.1. If a Data Subject contacts the Provider with a request to exercise their rights, the Provider shall (unless agreed otherwise) forward such request without undue delay to the Customer’s contact e-mail address available to the Provider for such purpose or provided to the Provider by the Customer for this purpose, and shall refrain from direct action unless expressly authorized by the Customer or required by legal regulations.
6.2. Taking into account the nature of the Processing, the Provider shall, upon the Customer’s written request, provide reasonable cooperation and technical and organizational measures to fulfill the Customer’s obligations under Chapter III of the GDPR (rights of Data Subjects), as well as under Articles 32–36 of the GDPR (security, notification, impact assessment, prior consultation), to the extent of the information available to the Provider.
6.3. If the Provider’s cooperation significantly exceeds the scope of the standard provision of Services, the Customer shall reimburse the Provider for the corresponding costs.
7. Personal Data Breach Notification
7.1. The Provider is obliged to immediately inform the Customer of any Personal Data breach. A breach of security means a breach of security leading to, or which may lead to, the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed. As part of this notification, the Provider shall provide the Customer with a description of the nature of the case, including, where possible, the approximate number of data subjects concerned and the approximate quantity of records concerned. The Provider also undertakes to provide all cooperation reasonably required by the Customer in investigating the Personal Data breach. The Provider is further obliged to take appropriate steps to minimize the harm caused by the breach and to discuss these steps with the Customer.
8. Audit
8.1. The Customer is entitled, either itself or through an authorized third party, to inspect the performance and compliance with any of the Provider’s obligations regarding the processing and security of Personal Data, subject to prior notice sent at least 10 business days in advance.
8.2. The Provider is obliged, at the Customer’s expense, to provide the Customer with all reasonably requested cooperation necessary to perform the inspection. The Customer is obliged to conduct the inspection in a manner that does not burden the Provider beyond the necessary extent.
8.3. The inspection under Article 8.1 may also take place at the Provider’s registered office or at other locations where the processing of Personal Data under the Agreement takes place.
9. Sub-processors
9.1. The Customer expressly consents to the involvement of Sub-processors. The Provider maintains a current list of its engaged sub-processors on the Subprocessors page and also provides it on request.
9.2. The Provider shall inform the Customer in writing of any intended addition or replacement of a sub-processor. The Customer shall have the right to object to such addition or replacement within seven (7) days from receipt of the notification. If the Customer raises a justified objection within this period and the Parties are unable to resolve the objection to the Customer’s reasonable satisfaction, the Customer may terminate the affected Services or the Agreement. If the Controller does not raise an objection within the period specified in Article 9.2, the engagement of the relevant Sub-processor shall be deemed approved.
9.3. The Provider shall ensure that Sub-processors are contractually bound by the same or equivalent data protection obligations as the Provider under this addendum.
10. Confidentiality
10.1. Information concerning the content of this addendum, the Service, and/or the business of the other Contracting Party, which is marked as confidential or can be considered confidential given its nature, shall be treated as confidential information, and each Contracting Party shall protect it at least to the same extent as its own confidential information. Data, including Personal Data, is always considered confidential information.
10.2. The confidentiality obligation does not apply to information that: a) is or becomes publicly available other than through a breach of this Agreement; b) was demonstrably known to the Contracting Party prior to its disclosure by the other Contracting Party; c) was obtained from a third party lawfully and without a confidentiality obligation; d) must be provided pursuant to law, a court decision, or a decision of another public authority; in such case, however, the Contracting Party is obliged, unless prevented by legal regulations, to inform the other Contracting Party of such requirement without undue delay and to provide it with reasonable cooperation in protecting its rights.
11. Duration
11.1. This DPA is effective for the duration of the Agreement.
11.2. Upon termination of the provision of Services (or upon the Customer’s instruction at any time during the term of the Agreement), the Provider shall, within 30 days, provide the Customer with the opportunity to download the Personal Data or return it to the Customer, and subsequently, unless agreed otherwise, delete all copies of the Personal Data; this is without prejudice to any statutory retention obligations.
11.3. If legal regulations require retention, the Provider shall retain the Personal Data only to the extent and for the period strictly necessary and shall ensure the restriction of its processing.
12. Miscellaneous
12.1. In the event of any conflict between this addendum and other provisions of the Agreement, this addendum shall prevail in matters concerning Personal Data.
