← StellarcPrivacy Policy

Legal

Data Processing Agreement

Last updated 2026-08-04 · Beta template — a signed, customer-specific version is issued on request during onboarding.

This Data Processing Agreement ("DPA") forms part of the agreement between Stellarc ("Processor") and the customer organization ("Controller") for the processing of personal data in connection with the Stellarc service. It reflects the requirements of Article 28 of the GDPR.

1. Subject matter and duration

Stellarc processes data on the Controller's behalf for the purpose of building and serving a per-brand knowledge graph accessible via AI assistants and the Stellarc dashboard. Processing continues for the duration of the underlying service agreement and ceases on termination, subject to Section 6 (deletion).

2. Nature and purpose of processing

  • Ingesting and storing marketing/SEO performance data connected by the Controller (Search Console, GA4, DataForSEO, Plausible).
  • Crawling and indexing the Controller's own site and specified competitor sites for analysis.
  • Serving grounded, source-cited answers to the Controller's authorized users via their AI assistant of choice.
  • Operating account, organization, and access-control records.

3. Categories of data subjects and data

Primarily business contact data (names, work email addresses) of the Controller's personnel and, incidentally, third parties referenced in connected analytics/search data (e.g. search query strings). Stellarc does not intentionally process special categories of data (GDPR Art. 9) and the Controller warrants it will not submit such data through the service.

4. Subprocessors

Stellarc uses the following subprocessors to provide the service:

SubprocessorPurposeLocation
NeonPrimary application database (EU region)European Union
VercelApplication hosting and serverless computeGlobal (per configured region)
Google (Search Console, GA4, Cloud)Connected data sources, at the Controller's direction; sign-inGlobal
DataForSEOKeyword, ranking, and competitor dataEU / Global
Anthropic (via the Controller's own Claude account)The Controller's chosen AI assistant connects to Stellarc as an MCP client; the Controller is the data controller for that connection, Stellarc does not route data through Anthropic independentlyGlobal

We will notify customers of any change to this list with the opportunity to object, per standard practice.

5. Security measures

  • Per-organization data isolation, adversarially tested — a token issued to one organization cannot read another organization's data.
  • Per-brain access scoping within an organization for teammates, in addition to the organization boundary.
  • Encrypted credentials for connected third-party data sources.
  • Authenticated, rate-limited API access; no unauthenticated access paths in production.

6. Deletion and return of data

On termination, or on request at any time, Stellarc will permanently delete all data associated with the Controller's organization — including all connected brain(s) and every table referencing them — or provide a complete export prior to deletion, at the Controller's choice. Deletion is verified mechanically: after deletion, zero rows referencing the organization or brain remain in any table.

7. Assistance and audits

Stellarc will reasonably assist the Controller in responding to data subject requests and, during beta, provides direct founder support for such requests same-day. The Controller may request evidence of the security measures described above.

Need a countersigned copy?

Contact contact@stellarc.ai and we'll issue a customer-specific version during onboarding.