Version: 1.0
Effective date: 1 June 2026
This Data Processing Addendum ("DPA") supplements the Terms of Service and governs the processing of personal data by Stactiq Inc. as a data processor on behalf of the Customer as data controller, where applicable under the GDPR, UK GDPR, or CCPA.
1. Roles
The Customer is the data controller. Stactiq Inc. is the data processor. Stactiq processes personal data only on the documented instructions of the Customer, as set out in the Terms of Service, this DPA, and any subsequent written instructions.
2. Subject matter of processing
| Element | Description |
|---|---|
| Subject matter | Football methodology documentation, coaching staff data, session outputs |
| Duration | For the term of the Customer's active subscription |
| Nature | Storage, retrieval, AI inference operations, display |
| Purpose | Delivery of the Football Methodology Operating System |
| Data types | Name, email, role title, Customer Content |
| Data subjects | Authorised Users (coaching staff) |
3. Customer instructions
Stactiq processes personal data only as necessary to deliver the contracted system functionality. Stactiq will inform the Customer if it believes any instruction violates applicable data protection law.
4. Confidentiality
Stactiq personnel with access to Customer personal data are bound by confidentiality obligations. Access is restricted to personnel with a need to know for purposes of system delivery and support.
5. Security
Stactiq maintains the technical and organisational security measures described at /security. In the event of a confirmed personal data breach, Stactiq will notify the Customer within 72 hours of becoming aware of the breach.
6. Sub-processing
Stactiq engages sub-processors in delivering the Services. A current list is available upon request to security@stactiq.com. Sub-processors are bound by data processing agreements imposing at least equivalent obligations to this DPA. Stactiq remains liable to the Customer for sub-processor performance.
7. Data subject rights
Stactiq will assist the Customer in responding to data subject rights requests within 5 business days of receiving a written request from the Customer.
8. Transfers
Where Customer Content or personal data is transferred to countries outside the EEA or UK, Stactiq relies on Standard Contractual Clauses (Controller to Processor, EU Commission Decision 2021/914) as the transfer mechanism. SCCs are available on request at legal@stactiq.ai.
9. Deletion and return
Upon termination, Stactiq deletes all Customer personal data within 90 days, unless legal retention obligations require otherwise. Customers may request data export before deletion at support@stactiq.ai.
10. Audit
Customers may request written evidence of compliance with this DPA once per calendar year. Enterprise Customers under a signed agreement may request an audit with 60 days' written notice.
11. Governing law
This DPA is governed by the laws of the State of Delaware, United States, or by EU law where required by applicable data protection regulation.
Execution
To execute this DPA as part of a formal enterprise agreement, contact legal@stactiq.ai.