Legal
Last updated 2026-08-04 · Beta template — a signed, customer-specific version is issued on request during onboarding.
This Data Processing Agreement ("DPA") forms part of the agreement between Stellarc ("Processor") and the customer organization ("Controller") for the processing of personal data in connection with the Stellarc service. It reflects the requirements of Article 28 of the GDPR.
Stellarc processes data on the Controller's behalf for the purpose of building and serving a per-brand knowledge graph accessible via AI assistants and the Stellarc dashboard. Processing continues for the duration of the underlying service agreement and ceases on termination, subject to Section 6 (deletion).
Primarily business contact data (names, work email addresses) of the Controller's personnel and, incidentally, third parties referenced in connected analytics/search data (e.g. search query strings). Stellarc does not intentionally process special categories of data (GDPR Art. 9) and the Controller warrants it will not submit such data through the service.
Stellarc uses the following subprocessors to provide the service:
| Subprocessor | Purpose | Location |
|---|---|---|
| Neon | Primary application database (EU region) | European Union |
| Vercel | Application hosting and serverless compute | Global (per configured region) |
| Google (Search Console, GA4, Cloud) | Connected data sources, at the Controller's direction; sign-in | Global |
| DataForSEO | Keyword, ranking, and competitor data | EU / Global |
| Anthropic (via the Controller's own Claude account) | The Controller's chosen AI assistant connects to Stellarc as an MCP client; the Controller is the data controller for that connection, Stellarc does not route data through Anthropic independently | Global |
We will notify customers of any change to this list with the opportunity to object, per standard practice.
On termination, or on request at any time, Stellarc will permanently delete all data associated with the Controller's organization — including all connected brain(s) and every table referencing them — or provide a complete export prior to deletion, at the Controller's choice. Deletion is verified mechanically: after deletion, zero rows referencing the organization or brain remain in any table.
Stellarc will reasonably assist the Controller in responding to data subject requests and, during beta, provides direct founder support for such requests same-day. The Controller may request evidence of the security measures described above.
Contact contact@stellarc.ai and we'll issue a customer-specific version during onboarding.