§ Data Processing Addendum

The terms your counsel is looking for.

Last updated: August 13, 2026

You do not need to ask for this one. This addendum applies automatically to every customer, and it forms part of the Terms of Service. Most vendors make you request a DPA and then send a PDF; there is no reason for that, so it is just published.

If your procurement process needs it signed on paper, email support@getstocksafe.com and we will sign this document as it is written here, unchanged. If you need changes, send them and we will answer honestly about what a one-person company can actually commit to.

1. Who is who

This addendum is between you (the "Customer") and Nextgen Wellness LLC, a Florida limited liability company trading as StockSafe ("we", "us"). It covers personal data we handle on your behalf when you use the Service.

You are the controller (under GDPR and UK GDPR) and the business (under the CCPA/CPRA). We are the processor and the service provider. You decide what goes into StockSafe and why. We act on your instructions.

Where you are yourself acting on someone else's behalf, you confirm you have the authority to give us these instructions.

2. What we process, and why

Subject matterProviding the StockSafe inventory compliance service.
DurationFor as long as your account is active, plus the retention window in section 8.
Nature and purposeStoring, organising, alerting on, reporting on, and transmitting the records you enter, so that you can track inventory and meet your own compliance obligations.
Categories of data subjectYour staff and the users you invite. Your suppliers' contacts, where you enter them.
Categories of personal dataName, work email address, role, and optionally a mobile number for SMS alerts. Authentication data. Records of actions taken in the application (the audit log). Supplier contact details you enter. Whatever you choose to type into a free-text note.
Special category dataNone is requested and none is required. The Service has no field for health information about an identified person. See section 10.

3. We act only on your instructions

We process personal data only to provide and support the Service, as described in the Terms and the Privacy Policy, and on any further written instruction you give us. We do not sell personal data, we do not share it for cross-context behavioural advertising, we do not use it to build a profile of anyone, and we do not use your data to train AI models or to improve the Service for other customers.

If we are ever legally required to process your data in a way you have not instructed, we will tell you before doing it unless the law forbids us from saying so.

If we think one of your instructions breaks data protection law, we will say so rather than quietly comply.

4. Confidentiality

Everyone with access to your data is bound by confidentiality obligations. At our current size that means one person, the founder, whose access is described plainly on the Security page rather than dressed up as an access-control programme.

5. Security

We maintain technical and organisational measures appropriate to the risk, described in full and in plain language on the Security page: encryption in transit and at rest, hashed passwords, tenant isolation enforced in every query, an append-only audit log, and a stated vulnerability-response window. That page is the specification; if it changes materially, this addendum changes with it.

We are not SOC 2 certified and we do not claim to be. The Security page says so too.

6. Sub-processors

You give us general authorisation to engage the sub-processors listed on the Security page, which names each one, what it holds, and where. That list is the canonical one and it is kept current.

Before adding a new sub-processor that will handle your personal data, we will update that page and email account administrators at least 30 days beforehand. If you object on reasonable data protection grounds within those 30 days, tell us; if we cannot offer you a way to keep using the Service without that sub-processor, you may cancel and we will refund the unused portion of anything you have paid.

Each sub-processor is bound by terms no less protective than these, and we remain responsible to you for what they do with your data.

7. Helping you meet your own obligations

8. Breach notification

If we confirm a personal data breach affecting your data, we will notify the administrators on your account without undue delay and within 72 hours of confirming it. The notice will say what happened, what data was involved, what we have done, and what we recommend you do. We will not wait until we have a complete picture to make the first contact; you will get an incomplete but honest notice quickly, then updates.

9. Deletion and return

You can export your data yourself at any time, in CSV and PDF, without asking us.

When your account ends, we keep your data for 30 days so you can reactivate without losing your history, then delete it. You can ask us to delete it sooner: email us from your account address and it is done within 7 business days, records and uploaded files together, with a confirmation when it is finished. The only exceptions are records we are legally required to keep, which in practice means Stripe transaction records for tax purposes.

Files uploaded for an AI feature are not retained at all. They are deleted as soon as the model has read them, normally within seconds.

10. Health information

StockSafe is an inventory system, not a clinical system. Inventory data (products, lot numbers, expiry dates, counts) is not Protected Health Information under 45 CFR 160.103, and nothing in the product asks you to identify a patient.

Because the adjustment note is a free-text box, the server checks any note before it is sent to our AI provider and refuses to send anything that looks like it names a person. It refuses rather than editing your text. Your note still saves to your own records. If you would rather no note ever left your account, ask us and we will disable the AI features for your organisation.

We will sign a Business Associate Agreement where your counsel requires one. Read section 10 alongside it: a BAA and an AI feature that transmits free text are in tension, and the way we resolve it is the refusal described above plus, if you want it, switching the AI features off entirely.

11. Audit

To demonstrate compliance we will provide the documentation on this site, answer your written questions, and complete your security questionnaire. Given the size of the company, on-site or third-party audits are not something we can honestly offer, and we would rather say that than promise it and fail you at the worst moment. If a regulator with the authority to inspect requires it, we will cooperate.

12. International transfers

All processing and storage takes place in the United States. If you are in the EEA, the UK, or Switzerland and transfer personal data to us, the transfer relies on the Standard Contractual Clauses, which are incorporated into this addendum by reference, with us as data importer, module two (controller to processor). Where the UK Addendum or the Swiss amendments apply, they apply too.

13. California

We are a service provider under the CCPA/CPRA. We do not sell or share personal information, we do not retain, use, or disclose it for any purpose other than performing the Service, and we do not combine it with personal information from any other source. We certify that we understand these restrictions and will comply with them.

14. Precedence and term

This addendum forms part of the Terms of Service and applies for as long as we process personal data on your behalf. Where it conflicts with the Terms on the subject of personal data, this addendum wins. Where it conflicts with the Standard Contractual Clauses, the Clauses win.

Contact

Data protection questions, requests, and questionnaires: support@getstocksafe.com. A person reads that inbox.