Legal · Stoj IT
Data Processing Addendum
Processor terms for Customer Personal Data in HubOps.
Last updated: 15 August 2026
1. Role of the parties
This Data Processing Addendum ("DPA") forms part of the HubOps Terms (or other written agreement) between Stoj IT ("Processor") and the customer organization ("Controller") that uses HubOps.
When HubOps processes personal data on the Controller's instructions inside a workspace (for example client contacts visible in delivery tools, portal members, or synced CRM metadata), Stoj IT acts as Processor and the customer organization acts as Controller.
These documents apply to HubOps operated by Stoj IT. They are product policies for the HubOps platform, not legal advice. For a signed contract or enterprise DPA schedule, contact us.
2. Subject matter and duration
Subject matter: hosting and processing Customer Personal Data to provide HubOps features the Controller enables. Duration: for the term of the service agreement and any post-termination retention required for backups or law.
3. Nature and purpose
Processing includes storage, retrieval, transmission, display, deletion, and related technical operations needed to run portals, implementations, CMS jobs, agents, reporting, and integrations the Controller connects.
4. Types of data and data subjects
May include identifiers, contact details, role/membership data, support content, and CRM-related metadata for employees, contractors, and end customers of the Controller, as determined by what the Controller submits or syncs. HubOps is not intended as a system of record for special-category data unless agreed in writing.
5. Processor obligations
Stoj IT will:
- Process Customer Personal Data only on documented instructions from the Controller, including via product configuration, unless required by law.
- Ensure persons authorized to process the data are bound by confidentiality.
- Implement appropriate technical and organizational security measures.
- Engage subprocessors only under written terms imposing data-protection obligations no less protective than this DPA, and remain responsible for their performance. Core subprocessors include infrastructure providers listed in the Privacy Policy.
- Assist the Controller with data-subject requests, security incidents, and DPIAs where reasonably required, taking into account the nature of processing.
- Notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.
- Delete or return Customer Personal Data after end of services, subject to legal retention and backup cycles, when the Controller requests it.
- Make available information reasonably necessary to demonstrate compliance and allow audits under agreed scope, frequency, and confidentiality.
6. Controller obligations
The Controller warrants it has a lawful basis and required notices/consents for Customer Personal Data it submits to HubOps, and that its instructions comply with applicable data-protection law.
7. International transfers
Where Customer Personal Data is transferred outside the EEA/UK, the parties rely on appropriate safeguards (including SCCs with subprocessors where applicable). Details are available on request.
8. Hierarchy
If there is a conflict between this DPA and the Terms for data-protection matters, this DPA prevails. A signed enterprise agreement may replace or supplement this public DPA.
9. Contact
DPA and privacy contact: privacy@hubops.net.