STEMHQ
Legal

Data Processing Agreement

Last updated: 28 June 2026 · Version 1.0

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between STEMHQ Ltd and each Operator, and governs the processing of tenant personal data under UK GDPR Article 28.

1. Roles of the parties

For tenant personal data entered into the Service, the Operator is the data controller and STEMHQ Ltd is the data processor. STEMHQ processes tenant data only on the Operator’s documented instructions, which the Terms of Service and this DPA constitute, unless required otherwise by law (in which case we will inform you unless the law prohibits it).

2. Subject matter, duration, nature and purpose

  • Subject matter: processing of tenant personal data to provide the STEMHQ property, compliance, arrears, and legal-readiness Service.
  • Duration:for as long as the Operator’s account is active, plus the retention periods in the Privacy Policy.
  • Nature:storage, organisation, retrieval, use, transmission to the Operator’s authorised recipients (such as a solicitor the Operator invites), and deletion.
  • Purpose: enabling the Operator to manage tenancies, track compliance, escalate arrears, and prepare possession cases.

3. Categories of data subject and personal data

Data subjects:the Operator’s tenants, guarantors, and, where entered, other occupants. Personal data: names, contact details, National Insurance numbers, payment and arrears records, tenancy details, compliance documents, and case notes. Operators are responsible for not entering special-category data beyond what is genuinely necessary.

4. Processor obligations (Article 28(3))

  • Process personal data only on the controller’s documented instructions.
  • Ensure persons authorised to process the data are bound by confidentiality.
  • Implement appropriate technical and organisational security measures (Section 6).
  • Respect the conditions for engaging sub-processors (Section 5).
  • Assist the controller, taking account of the nature of processing, to respond to data subject rights requests.
  • Assist the controller with security, breach notification, and data protection impact assessments.
  • Delete or return all personal data at the end of the engagement, per the controller’s choice (Section 8).
  • Make available the information necessary to demonstrate compliance, and allow for and contribute to audits.

5. Sub-processors

The Operator gives general authorisation for STEMHQ to engage the sub-processors below. We remain liable for their acts and omissions, and impose data protection terms equivalent to this DPA on each. We will give notice of any intended addition or replacement, allowing the Operator to object on reasonable data protection grounds.

Sub-processorPurposeLocation
Stripe Payments Europe LtdSubscription billingEU / UK
Resend Inc.Transactional emailUSA (SCCs)
Infrastructure providerCloud hosting and databaseEU

6. Security measures

  • Encryption in transit (TLS 1.2+) and field-level encryption of sensitive fields at rest.
  • Row-level data isolation so no Operator can access another Operator’s tenant data.
  • Role-based access control and least-privilege access to production systems.
  • An append-only audit trail of solicitor-portal access (invites, DPA acceptance, views, downloads, revocations).
  • Encrypted backups stored in a separate geographic region.

7. Personal data breaches

STEMHQ will notify the Operator without undue delay after becoming aware of a personal data breach affecting the Operator’s tenant data, providing the information the Operator reasonably needs to meet its own Article 33 and 34 obligations. As controller, the Operator is responsible for any notification to the ICO or affected data subjects.

8. Return and deletion

On termination, or on the Operator’s written request, STEMHQ will delete or return all tenant personal data and delete existing copies within 30 days, unless UK law requires continued storage. Operators can export their data at any time while the account is active.

9. International transfers

Where a sub-processor is outside the UK or EU (for example Resend Inc. in the USA), transfers are made under Standard Contractual Clauses approved by the UK ICO or European Commission, with transfer impact assessments where appropriate.

10. Audit

STEMHQ will make available information reasonably necessary to demonstrate compliance with Article 28 and, on reasonable notice and no more than once a year (or following a breach), contribute to an audit conducted by the Operator or an independent auditor bound by confidentiality.

11. Liability and precedence

Liability under this DPA is subject to the limitations in the Terms of Service. Where this DPA conflicts with the Terms on the processing of tenant personal data, this DPA prevails to the extent of the conflict.

12. Contact

Data protection queries relating to this DPA can be sent to hello@stemhq.co.uk.