Last updated: May 29, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between Iron Stratos LLC ("Iron Stratos," "Processor") and the customer ("Customer," "Controller") that subscribes to IronStratos Pro Web (the "Service"). It governs the processing of personal data and Customer Data that Iron Stratos processes on Customer's behalf. IronStratos is the trade name of Iron Stratos LLC. Capitalized terms not defined here have the meaning given in the IronStratos Pro Subscription Agreement.
For Customer Data and personal data processed through the Service, Customer is the controller (or business) and Iron Stratos is the processor (or service provider). Iron Stratos processes such data only on Customer's documented instructions, including as set out in this DPA and the Subscription Agreement, and does not sell Customer's personal data.
Iron Stratos processes Customer Data — which may include quality and operational records and the contact details of Customer's authorized users — solely to provide, secure, support, and improve the Service. The duration of processing is the subscription term plus the retention period described below.
Customer authorizes Iron Stratos to engage the following sub-processors to provide the Service; each is bound by data-protection obligations consistent with this DPA:
Iron Stratos will give Customer notice of any intended addition or replacement of a sub-processor and remains responsible for its sub-processors' performance.
Iron Stratos maintains appropriate technical and organizational measures to protect Customer Data, including encryption in transit, access controls and least-privilege administration, row-level security isolating each organization's data, and logging. Access is restricted to personnel who need it to deliver the Service and who are bound by confidentiality.
Iron Stratos will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide information reasonably available to help Customer meet its own notification obligations.
Taking into account the nature of the processing, Iron Stratos will provide reasonable assistance to Customer in responding to requests from individuals exercising their rights (e.g., access, correction, deletion, portability) and in meeting Customer's security, breach-notification, and impact-assessment obligations.
On termination or expiration of the subscription, Iron Stratos will, at Customer's request, make Customer Data available for export for a limited period, and will then delete or anonymize Customer Data within 90 days, except where retention is required by law.
To the extent the GDPR applies, Iron Stratos acts as processor under Article 28 and will support lawful transfer mechanisms where required. To the extent the CCPA/CPRA applies, Iron Stratos acts as a service provider, processes personal information only to perform the Service, and does not sell or share it or retain, use, or disclose it for any purpose other than performing the Service.
This DPA is governed by the laws of the State of Alabama and is subject to the limitation of liability set out in the Subscription Agreement.
Privacy and data-protection inquiries: privacy@ironstratos.com, or write to Iron Stratos LLC, [BUSINESS ADDRESS].