Last updated: 28 June 2026 · Version 1.0
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between STEMHQ Ltd and each Operator, and governs the processing of tenant personal data under UK GDPR Article 28.
For tenant personal data entered into the Service, the Operator is the data controller and STEMHQ Ltd is the data processor. STEMHQ processes tenant data only on the Operator’s documented instructions, which the Terms of Service and this DPA constitute, unless required otherwise by law (in which case we will inform you unless the law prohibits it).
Data subjects:the Operator’s tenants, guarantors, and, where entered, other occupants. Personal data: names, contact details, National Insurance numbers, payment and arrears records, tenancy details, compliance documents, and case notes. Operators are responsible for not entering special-category data beyond what is genuinely necessary.
The Operator gives general authorisation for STEMHQ to engage the sub-processors below. We remain liable for their acts and omissions, and impose data protection terms equivalent to this DPA on each. We will give notice of any intended addition or replacement, allowing the Operator to object on reasonable data protection grounds.
| Sub-processor | Purpose | Location |
|---|---|---|
| Stripe Payments Europe Ltd | Subscription billing | EU / UK |
| Resend Inc. | Transactional email | USA (SCCs) |
| Infrastructure provider | Cloud hosting and database | EU |
STEMHQ will notify the Operator without undue delay after becoming aware of a personal data breach affecting the Operator’s tenant data, providing the information the Operator reasonably needs to meet its own Article 33 and 34 obligations. As controller, the Operator is responsible for any notification to the ICO or affected data subjects.
On termination, or on the Operator’s written request, STEMHQ will delete or return all tenant personal data and delete existing copies within 30 days, unless UK law requires continued storage. Operators can export their data at any time while the account is active.
Where a sub-processor is outside the UK or EU (for example Resend Inc. in the USA), transfers are made under Standard Contractual Clauses approved by the UK ICO or European Commission, with transfer impact assessments where appropriate.
STEMHQ will make available information reasonably necessary to demonstrate compliance with Article 28 and, on reasonable notice and no more than once a year (or following a breach), contribute to an audit conducted by the Operator or an independent auditor bound by confidentiality.
Liability under this DPA is subject to the limitations in the Terms of Service. Where this DPA conflicts with the Terms on the processing of tenant personal data, this DPA prevails to the extent of the conflict.
Data protection queries relating to this DPA can be sent to hello@stemhq.co.uk.