Data Processing Addendum
The agreement that covers other people's personal details when you put them into StackDesign: what we may do with them, what we may never do, which companies touch them, what happens if something goes wrong, and how you get them back.
Every clause below was written against the code that actually runs, not copied from a template. It binds us and you once we have both signed a copy, which is what section 16 sets out. Until a copy is signed, the Privacy Policy and the Terms of Service govern what we do with your data, and section 11 of the Terms already sets out the controller and processor split this document makes formal.
To ask for a copy to sign, email support@stackdesign.app.
The short version
A plain-words summary for orientation only. It is not the agreement, and the full text below governs.
- If you type someone's details into a StackDesign project, a note or the AI Designer, you decide what goes in and why. We only hold it for you.
- We use it to run the Service for you and for nothing else. We do not sell it, we do not market to anyone in it, and it is never used to train an AI model.
- Other companies help us run the product. Annex C points at the standing list that names every one of them and says what each one touches.
- You can edit, delete and export the whole lot yourself, from inside your account, without asking us.
- We are a small California company. We are not certified under the EU-US Data Privacy Framework, we hold no SOC 2 or ISO 27001 report, and this document says so rather than implying otherwise.
1. What this addendum covers, and what it does not
This covers other people's details that you put into StackDesign. It does not cover your own account or your billing record, because those are ours to decide about, and the Privacy Policy describes them.
StackDesign is operated by Bespoke Woodcraft Studio LLC, a California limited liability company, whose registered business address is 688 N Rimsdale Ave, Covina, CA 91722, United States. In this addendum, "we" and "us" mean that company. "You" means the business that holds the StackDesign account.
This addendum applies to one kind of information, which it calls Customer Personal Data: personal details about people other than you that you choose to put into the Service.
Where that can happen in StackDesign. The planner has no contact book and no customer fields, so nothing asks you for a person's details. What can carry them is free text: the name you give a project, the notes you write on it, and anything you type or photograph into the AI Designer. If you also use CabDesign, which the same account opens, that account's workspace can hold the CabDesign customer directory as well, and this addendum covers those records too, wherever they were entered.
It does not apply to the information we hold to run the business, which is the email address on your account, your sign-in records, your subscription and billing record, our own log of when you sign in and which pages you open, and our server logs. We decide what happens to those, so for those we are the controller rather than your processor, and the Privacy Policy is the document that describes them.
One account opens both StackDesign and CabDesign, so one copy of this addendum covers your use of both products. The CabDesign wording of the same document is at cabdesign.app/dpa.html.
This addendum takes effect between us when it is signed, which is the promise section 11 of the Terms of Service already makes: we have it signed before your customers' details are covered by it rather than after. Section 16 says how.
2. The words we use
Six terms, defined once, used the same way everywhere below.
- Customer Personal Data means what section 1 describes: personal details about other people that you put into the Service.
- Controller means whoever decides what personal data is collected and why. Processor means whoever holds and handles it on the controller's instructions.
- Data Subject means the living person the data is about. For Customer Personal Data that is usually one of your customers.
- Sub-processor means a company we use that processes Customer Personal Data on our behalf. Annex C is the list.
- Data Protection Law means whichever privacy laws apply to the processing, including the General Data Protection Regulation in the European Economic Area, the UK GDPR and the Data Protection Act 2018 in the United Kingdom, and the California Consumer Privacy Act as amended.
- Security Incident means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data that we hold.
3. Who is the controller, and who is the processor
For other people's details, you are the controller and we are your processor. For your own account, we are the controller.
You are the controller of Customer Personal Data. You decide what to collect, why, and how long to keep it. You are responsible for having a lawful basis for it and for telling those people what you do with their information. We are your processor, and we hold it so that the Service works for you.
We are the controller of the account, billing, sign-in and usage information described in section 1. Nothing in this addendum makes you our processor, and nothing in it makes us a controller of Customer Personal Data.
The companies in Annex C are our sub-processors for Customer Personal Data. We remain responsible to you for what they do with it.
4. Your instructions, and what we never do
We do what you tell us and nothing else. Using the Service is how you tell us.
We process Customer Personal Data only on your documented instructions. Your instructions are this addendum, the Terms of Service, and the things you do inside the Service: saving a project, writing a note on it, printing a plan or a cut list, syncing your work between your devices, and asking the AI Designer a question about a project. If you want us to do something outside that, ask us in writing and we will tell you whether we can and what it would cost.
If we believe an instruction from you breaks Data Protection Law, we tell you, and we may pause that part of the processing until it is sorted out. If a law we are subject to requires us to process Customer Personal Data for some other reason, we tell you before we do it unless that law forbids us from telling you.
- We never sell Customer Personal Data, and we never share it for cross-context behavioural advertising.
- We never market to the people in it.
- We never use Customer Personal Data for our own purposes, including improving our products, beyond what is needed to provide and secure the Service to you.
- We never use it to train an AI model, and neither does our AI provider.
- We never combine it with personal data we hold from another source.
On the AI Designer specifically. When you use the assistant, your message and the project context needed to answer it go from our server to Anthropic, which generates the reply. If you attach a photo, that photo goes too. The call is made server side, so your browser never talks to the AI provider and no provider key reaches you. Under Anthropic's commercial API terms, the content sent and the replies received are not used to train models, and Anthropic deletes its own operational logs on a short rolling window, currently around seven days. Those are Anthropic's terms rather than ours, so we re-read them whenever we publish a new version of the Privacy Policy and change what we say rather than leave a stale promise standing. The assistant's memory of your projects is kept in your own workspace in our database, not at the AI provider, and it is deleted when your account is.
There is a second AI provider connected on our server, Google, reachable only by one of our own platform administrator accounts while we test. No customer conversation is sent to it. It is named on the sub-processor list Annex C points at, because the connection exists, and if we ever make it available to you we will say so before any of your data reaches it.
5. Our people
Few people can reach it, and the ones who can are bound to keep it quiet.
Access to Customer Personal Data on our side is limited to the people who need it to run and support the Service. Everyone with that access is bound to keep it confidential, and that duty continues after they stop working with us. We are a small company, so that group is small, and we would rather tell you that than describe a department we do not have.
6. How we protect it
Annex B is the actual list of what we do, and it describes the software as it runs today.
We keep technical and organisational measures appropriate to the risk, and Annex B sets out what they are. We may change them as the product changes, and we do not make a change that lowers the protection Annex B describes.
No system is perfectly secure and we do not promise that a determined attacker will never succeed. What we promise is the measures in Annex B, the notice in section 11, and the honesty about what we do not have in section 13.
7. The other companies that touch it
You agree to the list in Annex C. If we want to add one, we tell you first, and you can object.
You give us general authorisation to use the sub-processors listed in Annex C and published at cabdesign.app/sub-processors.html, which is the one list covering both products. Each of them is under a written contract with us that carries data protection obligations at least as protective as the ones in this addendum. If a sub-processor fails to meet its obligations, we remain liable to you for that failure.
Before a new sub-processor starts handling Customer Personal Data, we update the Privacy Policy and the sub-processor list, and we tell account holders by email or by a notice inside the product. An automated check in our build fails if the two lists stop matching, so the published list cannot quietly fall behind the policy.
We give you at least 30 days' notice before a new sub-processor starts handling Customer Personal Data, and you may object in that window on reasonable data protection grounds. Tell us what the objection is and we try to answer it, which can mean keeping your data away from that sub-processor where the product allows it. If we cannot settle it, you may cancel the part of the Service the change affects, and we refund what you have already paid for time you will not use.
8. Where it goes, and what protects it on the way
We run from the United States, so your data is processed there. We are not certified under the EU-US Data Privacy Framework and we do not pretend to be. We also hold no Standard Contractual Clauses for the step from you to us, and this section says what that leaves you relying on.
We operate from the United States. Customer Personal Data is processed there and, depending on the provider, in other countries where that provider operates. If you send us data from outside the United States, you are sending it to the United States.
We are not certified under the EU-US Data Privacy Framework, its UK Extension or the Swiss-US Data Privacy Framework. We do not appear on the participant list the US Department of Commerce publishes, and you will not find a claim on this site that we do. The full statement is on International Data Transfers.
Each of our providers publishes its own data processing contract. Those agreements rely on the European Commission's Standard Contractual Clauses for transfers out of the European Economic Area, and in most cases on the United Kingdom's international transfer addendum alongside them.
Those clauses protect the step from us to each provider. They do not cover the step from you to us. For that step we hold no Standard Contractual Clauses and no adequacy decision, so an organisation in the EEA or the UK sending us personal data is relying on its own assessment, and usually on Article 49(1)(b) of the GDPR, a transfer necessary to perform the contract it asked us to perform. That is a narrow route and we would rather name it than leave the gap unstated.
We do not sign those clauses with you directly. We have not signed them with any customer, which is what the International Data Transfers page linked above already says. If your organisation needs us to sign them with you as the exporter, write to us at the address in section 16. Signing them is a package and not a paragraph, and we have not built it, so today the honest answer is that our software is not a fit for you yet. We would rather tell you that here than have you find it out during a procurement review.
9. Helping you answer a request from one of your customers
Most of it you can do yourself, in the product, without asking us. Where you cannot, we help.
If someone whose details are in your account asks you to see, correct, delete or hand over what you hold, you can do it yourself inside StackDesign. You can edit or remove the text in any project, and you can download everything on the account as a JSON file from Account settings, using the "Download my data (JSON)" button.
Where the product does not let you do it yourself, we help you, using appropriate technical and organisational measures, at no charge for a reasonable number of requests.
If one of those people comes to us directly, we do not answer for you. We tell them to contact you, and we tell you that they got in touch, unless the law says we must do something else.
10. Impact assessments and regulators
If you have to write an impact assessment or answer a regulator, we give you what we have.
We give you reasonable help with a data protection impact assessment, or with a prior consultation with a supervisory authority, so far as it concerns our processing of Customer Personal Data and the information is information we hold.
A good deal of it is already published, and pointing you at a page is usually faster than answering a questionnaire: who processes data for us, where the data lives and how it is protected, Security and your data, Sub-processors, International Data Transfers and AI Transparency.
11. If there is a security incident
We tell you quickly, we tell you what we know, and we keep telling you as we learn more.
If we become aware of a Security Incident affecting Customer Personal Data, we tell you without undue delay, and in any case within 72 hours of becoming aware of it. That is the number the law itself uses for a controller's report to a regulator, and your own 72 hours start when we tell you.
The notice tells you what we know at the time: what happened, the categories of data and the approximate number of records involved, the likely consequences as we understand them, what we are doing about it and what we suggest you do, and a contact who can answer follow-up questions. If we do not have all of that at once, we send what we have and follow up rather than waiting until the picture is complete.
We keep a record of the incident and what we did, and we give you a copy on request so you can meet your own notification duties.
An unsuccessful attempt, a blocked scan, a bounced sign-in attempt or a wave of spam is not a Security Incident, and telling you about a breach is not us accepting fault for it.
12. Getting it back, and having it deleted
Take the JSON export whenever you want. Deleting your account deletes the live data immediately, and it ages out of backups within a week.
At any time while your account is open, you can download a JSON copy of everything on it from Account settings. That file holds the same data the deletion would erase, so it is the export to take before you go.
You can delete your account yourself from Account settings. If you cannot sign in, you can ask by email on the Delete my data page: we send a single-use link to the address on the account, that link shows you what is about to go, and nothing is removed until you confirm it there. One account covers both products, so one deletion removes it everywhere.
Deleting removes your account and the project data attached to it, including Customer Personal Data and the AI Designer's memory of your projects, from the live database straight away. Our database runs on the Supabase Pro plan, which takes one backup a day and keeps each for seven days, so a deleted record is out of the last backup copy within a week. We do not restore deleted data from a backup except to recover from a genuine system failure.
What we keep after deletion is the billing and tax record of what you paid, and the record of your consent to a recurring charge that California's automatic renewal law requires us to keep. Neither of those holds any Customer Personal Data.
If this addendum ends but your account stays open, we keep processing Customer Personal Data only as far as needed to keep running the Service for you under the Terms of Service.
13. Checking that we do what this says
Ask us and we answer. We do not hold an SOC 2 or an ISO certificate, and we say so instead of pointing you at one.
We give you the information you reasonably need to show that we meet the obligations in this addendum, and we answer a written security questionnaire once a year at no charge.
Beyond that questionnaire, you may ask for a review once a year, on 30 days' written notice and at your own cost. It covers the measures in Annex B and how we meet this addendum, and it runs remotely, as a document review and a call. We do not offer an on-site inspection: the address in section 16 is a small business address, and offering a visit we would then resist is worse than saying plainly that we do not offer one. That is our standing practice, not a limit on your rights. Where Article 28(3)(h) of the GDPR or a supervisory authority requires an inspection we cannot satisfy remotely, we will not refuse it, and we will agree reasonable arrangements with you. After a Security Incident we have confirmed affected your data, you may ask for one more review on the same terms without waiting for the next year.
What we do not have. We hold no SOC 2 report, no ISO 27001 certificate and no third-party penetration test report, and we do not claim one. Where one of the providers on the sub-processor list publishes its own certifications, we point you at theirs, which is a different thing from having our own, and we will not describe it as ours.
14. If you are a business under California privacy law
We act as your service provider, and we hold ourselves to that even though the law does not yet reach us by size.
Where the California Consumer Privacy Act applies to you, we act as your service provider for Customer Personal Data. We do not sell it and we do not share it for cross-context behavioural advertising. We do not keep, use or disclose it for any purpose other than performing the Service for you under this addendum, and we do not combine it with personal information from another source. We tell you if we determine that we can no longer meet those obligations, and you may take reasonable and appropriate steps to stop and remediate any unauthorised use.
StackDesign itself is below the revenue and volume thresholds that make a business a covered business under that law, so we are not one today. These commitments bind us anyway, and the Privacy Policy says the same thing about our own practices.
15. How this fits with the Terms of Service
The Terms still govern. Where the two disagree about data protection, this document wins.
This addendum forms part of the Terms of Service. Everything in the Terms that is not about data protection continues to apply unchanged. If a term of this addendum conflicts with the Terms on the handling of Customer Personal Data, this addendum governs, and only on that point.
This addendum is governed by the laws of the State of California, without regard to its conflict of laws rules, and a dispute goes to the state or federal courts in Los Angeles County, California, which is the same choice section 18 of the Terms makes. There is no arbitration clause and no class action waiver here either.
The limit on liability in section 14 of the Terms of Service applies to this addendum too. One agreement, one cap, and a claim about Customer Personal Data sits inside it rather than beside it. Two things that cap does not reach, and this addendum does not change either one: a right under California consumer protection law that cannot be waived, which the Terms already preserve, and a penalty a regulator imposes on us directly.
If any part of this addendum is unenforceable, the rest stays in force and the unenforceable part is limited to the minimum extent necessary. We may update this addendum so it stays accurate about how the Service works, and we tell you before an update takes effect. An update that would reduce the protection you have under it needs your agreement.
16. Signing it, and how to reach us
Email us and ask. We will send you the current version to sign.
This addendum is entered into by signing a copy of it. Ask us for it at support@stackdesign.app and we send you the current version as a document to sign. You sign it, we countersign it, and you get the signed copy back. A person reads that inbox. That order is the promise section 11 of the Terms of Service already makes: we have it signed before your customers' details are covered by it rather than after.
The signature block asks for three things and nothing else: your legal entity name, its address, and the name and title of the person signing for you. We do not ask you for anything we would then have to hold.
Formal notices under this addendum go to the postal address below, and reach us fastest if you email a copy at the same time:
Bespoke Woodcraft Studio LLC688 N Rimsdale Ave
Covina, CA 91722
United States
Email: support@stackdesign.app
We have not appointed an Article 27 representative in the European Union or the United Kingdom. The privacy rights section of the Privacy Policy explains why and what we will do if that changes. You can reach us directly at the address above, and you keep every right you have under Data Protection Law, including the right to complain to your local supervisory authority.
Annex A: what is processed
The detail a data protection officer asks for, in one table.
| Item | What it is |
|---|---|
| Subject matter | Providing the StackDesign storage and cabinet planning service to you, including storing your projects and the text and photos you put in them, and producing the plans and cut lists you print from them. |
| Duration | For as long as your account is open, and then as described in section 12. |
| Nature and purpose | Storing, organising, retrieving, copying between your devices, displaying, printing and deleting Customer Personal Data on your instructions. Sending a question you ask the AI Designer, with the project context needed to answer it, to our AI provider and returning the reply. Sending you email about your account. Keeping the Service running and secure. |
| Types of personal data | Whatever you choose to enter. StackDesign has no contact fields, so this is free text: project names, notes, and what you type or photograph into the assistant. If the same account also uses CabDesign, its customer directory can hold a name, a phone number, an email address, a mailing address, a shipping address, an invoice address and notes. |
| Categories of data subjects | Your customers, and anyone else you name in a project or a note, such as a site contact, an installer or an architect. |
| Sensitive data | None is asked for and none is wanted. The Service has no field for government identifiers, health data, precise location or biometric data, and the Privacy Policy asks you not to enter them. |
Annex B: what we do to keep it safe
This is the software as it runs today, not a wish list.
- Separation between accounts is enforced by the database itself. Row level security policies mean one workspace cannot read another workspace's projects, materials or customer records, whatever the application code does.
- Encryption. Traffic between your browser, our servers and our providers is encrypted in transit with TLS, and data is encrypted at rest by our providers.
- Sign-in. You can sign in with Google, with an email sign-in link, or with an email and password. If you set a password we store only a salted hash of it, so nobody here can read it. Sessions are held by one shared authentication client per page, and we email you when your account is signed into from a browser it has not been used on before.
- A security check in front of the risky pages. Creating an account, signing in and asking to delete an account all sit behind a challenge that sees the connection and its IP address and nothing you typed.
- Rate limiting. Each endpoint counts requests against the caller's IP address for a short window so one caller cannot flood it. The counter holds no name, no email and no account id, and it deletes itself within hours.
- Deletion is verified before it runs. An email deletion request is proved by a single-use link sent to the address on the account, the link expires, and the account is removed only after a confirmation page shows what is about to go.
- Administrative actions are recorded. An account deletion writes an audit row before the deletion runs, and the row survives the deletion, so an account cannot be closed without a record of it.
- The AI provider is called server side. No AI provider key ever reaches your browser, and your browser never talks to the AI provider directly.
- Backups. One a day, each kept for seven days, encrypted by our database provider.
- Access control on our side. Administrative access is limited to the people who need it to run and support the Service, as section 5 describes.
Annex C: sub-processors
The companies that help us run the product are listed on a page of its own, with what each one handles. That page is the one to read.
Our sub-processors are the companies named at cabdesign.app/sub-processors.html, as that page stands from time to time, and that list is what this annex means. It covers both products, it is the same list the Privacy Policy carries in the section on who processes data for us, it names every company, and it says what each one handles for us and what reaches it.
We point at that list rather than copy it into this annex, because a copy inside a contract goes stale on the day the list changes and then the contract states something untrue. Section 7 says how we tell you before that list changes and what you can do about it.