Last updated: 11 September 2026
This Data Processing Addendum (“DPA”) forms part of the Basestack Terms of Service. It applies when Basestack processes Personal Data on behalf of a customer through the hosted Service at https://www.basestack.co.
This DPA is incorporated into the Terms. Customers do not need to countersign it; using the hosted Service or entering into a paid subscription constitutes acceptance.
Customer must not send special categories of Personal Data (as defined in Article 9 GDPR), payment card data, health data, biometric data, data relating to children under 16, or other prohibited data except where expressly permitted in writing by Basestack and allowed by the Acceptable Use Policy.
Automated processing and AI. To help Customer manage spam, Forms submissions may be processed by an automated classifier through the third-party AI gateway OpenRouter, which is listed on the Sub-processors page and may route the data to an underlying model provider. Only submission field values and the customer account identifier are sent for this purpose; uploaded files are not sent. This processing is carried out on Customer's behalf to return a spam assessment and does not produce legal or similarly significant effects on data subjects.
Basestack will process Customer Personal Data only on Customer's documented instructions: the Terms, this DPA, in-product configuration, customer-enabled integrations, support requests, and other written instructions agreed by the parties. Basestack will inform Customer if, in Basestack's opinion, an instruction infringes Data Protection Laws.
Basestack ensures that personnel authorised to process Customer Personal Data are bound by confidentiality obligations and access Customer Personal Data only as needed to provide and protect the Service.
Basestack implements appropriate technical and organisational security measures, including but not limited to:
Customer gives Basestack general authorisation to engage the Sub-processors listed at /legal/sub-processors. Basestack will impose data protection obligations on each Sub-processor that are no less protective than this DPA in substance and remains responsible for Sub-processor acts and omissions to the same extent as its own.
Basestack will give at least 30 days' notice before adding or replacing a Sub-processor that processes Customer Personal Data by updating the Sub-processors page and, where available, by email to customers subscribed to such notices. Customer may object on reasonable data protection grounds within the 30-day notice period. If the parties cannot resolve the objection, Customer may terminate the affected paid subscription and receive a pro-rata refund of prepaid, unused fees.
Basestack is operated from Portugal. Where Customer Personal Data is transferred outside the EEA, United Kingdom, or Switzerland to a country that is not subject to an adequacy decision, the parties rely on the appropriate safeguards set out in this Section.
EU Standard Contractual Clauses. The SCCs are incorporated into this DPA by reference and apply to such transfers as follows:
SCC annexes. For the purposes of the SCCs: Annex I.A (list of parties) is populated with Customer as data exporter and Basestack as data importer, using the account, billing, and contact details held by each party; Annex I.B (description of the transfer) is set out in Section 3 of this DPA; Annex I.C (competent supervisory authority) is as stated above; Annex II (technical and organisational measures) is set out in Section 6 of this DPA; and Annex III (list of sub-processors) is the list maintained at /legal/sub-processors. The parties agree that the SCCs are deemed executed upon Customer's use of the Service.
United Kingdom and Switzerland. For transfers subject to UK data protection law, the UK International Data Transfer Addendum to the SCCs applies and is incorporated by reference. For transfers subject to Swiss law, the SCCs apply with the adjustments described by the Swiss Federal Data Protection and Information Commissioner (FDPIC), including references to the Swiss FADP and to the FDPIC as supervisory authority. Where another lawful transfer mechanism is required, the parties will rely on it.
Taking into account the nature of the Service, Basestack will assist Customer with reasonable requests Customer cannot fulfil through the product, including data subject requests, security obligations, breach notification, data protection impact assessments, and prior consultation with supervisory authorities. Basestack provides this assistance at no additional cost where the request is reasonable and relates to standard Service functionality; for extraordinary or unusually burdensome assistance, Basestack may charge its reasonable costs after telling Customer in advance.
Customer can delete forms, submissions, uploaded files, projects, and flags through the product where controls are available, and can request deletion of account data by contacting Basestack. On termination, Basestack will make reasonable efforts to delete or return Customer Personal Data within 60 days, except where retention is required by law or needed for a security, fraud, or legal matter. Backups are overwritten on the normal backup rotation and are not retained beyond 30 days after the corresponding production data is deleted.
Basestack will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will include the information then available about the nature of the breach, affected data, likely consequences, and measures taken or proposed, and Basestack will provide further information as it becomes available.
Basestack will make available information reasonably necessary to demonstrate compliance with this DPA. No more than once per 12-month period, or after a Personal Data Breach or supervisory-authority request, Customer may submit a reasonable written audit questionnaire. On-site audits are not included in the standard hosted Service unless agreed separately in writing.
Liability under this DPA is subject to the limitations in the Terms, except where Data Protection Laws require otherwise. If this DPA conflicts with the Terms on processing Customer Personal Data, this DPA controls. If the SCCs apply and conflict with this DPA, the SCCs control for that transfer.
Basestack may update this DPA to reflect legal, operational, or service changes. We will not materially reduce the protections for Customer Personal Data without reasonable notice.
Basestack Data Processing Addendum
[email protected]