Data Processing Addendum
Version 1 · Effective 2 October 2026
1. About this addendum
This addendum forms part of our Terms of Service between you and Stuart Wilson trading as CompanyStack. It applies where we process personal data on your behalf, and sets out the terms required by Article 28 of the UK GDPR.
2. When we are a controller
We are the controller, not your processor, for:
- the public register data we publish, such as directors and people with significant control from Companies House. We decide what is published and why. Once you take that data out of the Service, you are a separate controller of your copy (see clause 16 of the Terms);
- your account, billing and usage data, which we use to run our business; and
- our website analytics.
Our Privacy Notice covers this data.
3. When we are your processor
We process the following on your behalf and on your instructions:
- names and email addresses of team members you add to your account;
- watchlists, alert rules and other content you create, to the extent they contain personal data; and
- webhook destinations and the alerts we send to them.
The processing lasts as long as your account. Its purpose is to provide the Service. The data subjects are your staff and contacts, and people named in your watchlists.
4. Our processor commitments
When we act as your processor, we will:
- process the data only on your documented instructions, which are these terms and your use of the Service, unless the law requires otherwise (in which case we will tell you unless the law forbids it);
- make sure everyone who can access the data is bound by confidentiality;
- keep appropriate technical and organisational security measures in place, including encryption in transit, hashed credentials, access controls and backups;
- use sub-processors only as described in section 5;
- help you respond to requests from individuals exercising their rights;
- help you with security, breach notification, data protection impact assessments and consultation with the ICO, taking into account the information available to us;
- delete or return the data at the end of the service, as described in section 7; and
- give you the information you reasonably need to show compliance with Article 28, and allow reasonable audits on reasonable notice, normally by written questionnaire.
5. Sub-processors
You authorise us to use the sub-processors on our sub-processors page. We will update that page before adding or replacing a sub-processor, and you may object on reasonable data protection grounds. If we cannot address your objection, you may cancel the affected subscription and we will refund any prepaid fees for the rest of the period. We put data protection terms in place with each sub-processor that are no less protective than these, and we remain responsible for them.
6. Personal data breaches
We will tell you without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting data we process for you. We will give you the information you need to meet your own obligations, and keep you updated as we learn more.
7. End of the service
Before your account closes, you can ask us for a copy of the personal data we process for you. We then delete it within 30 days of closure, unless the law requires us to keep it.
8. Full DPA
This page summarises our processing terms. A full Data Processing Agreement is available on request through our contact page or at support@companystack.co.uk.