Trust
CalcStack Data Processing Addendum (DPA)
This addendum forms part of the CalcStack Terms of Service between you and CalcStack Ltd, registered in England and Wales at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. It is written in plain language on purpose: the commitments below are the ones the product actually enforces.
The CalcStack Data Processing Addendum (DPA) is the contract under which CalcStack Ltd processes lead data as a processor on behalf of its customers, the data controllers. It forms part of the Terms of Service, references the EU Standard Contractual Clauses, lists every subprocessor, and can be countersigned on request.
Last updated: July 2026
Who is who: controller and processor
When a visitor completes a tool embedded on your website, the email address and answers they submit are your visitor's personal data, collected under your brand, on your site, for your business. That makes you the data controller and CalcStack your processor for that lead data: we store it, compute results from it, and deliver it where you tell us to, and we do nothing else with it. For your own account data (your name, email, and billing details), CalcStack acts as an independent controller, which the Privacy Policy covers.
What processing this addendum covers
| Detail | Description |
|---|---|
| Subject matter | Lead capture and delivery through interactive tools embedded on your website. |
| Duration | The life of your account, plus the wind-down retention periods described below. |
| Nature and purpose | Storing tool submissions, computing and generating results (including AI-generated explanations where a tool uses them), and delivering leads to the destinations you connect. |
| Data subjects | Visitors to your website who interact with an embedded tool. |
| Personal data | Email address where lead capture is enabled, the inputs a visitor enters, the results generated, and basic technical data such as IP address and browser type. |
What CalcStack commits to as your processor
- Process lead data only to provide the service and only on your documented instructions, which are the settings, integrations, and configurations you set in your dashboard.
- Keep access to lead data limited to what operating the service requires, under confidentiality obligations.
- Apply the technical measures described on the security page, including database row-level security and encrypted transport.
- Help you answer data subject requests: export and deletion are self-serve from your dashboard, and privacy@calcstack.net handles anything a request needs beyond that.
- Notify you without undue delay after becoming aware of a personal data breach affecting your lead data.
- Delete or return personal data when the service ends, on the retention schedule below.
- Email account holders at least 14 days before a new subprocessor begins handling lead data, so you can object or raise concerns before the change takes effect.
The deletion commitment here is not just policy text. The export and erasure endpoints share one table list, pinned equal by an automated test: anything the export can show you, a deletion request also removes. We built that parity check because a deletion promise that silently skips a table is exactly the gap a processor review exists to find.
Subprocessors
CalcStack uses the following subprocessors to deliver the service. Each is bound by its own data processing terms with us.
| Subprocessor | Role |
|---|---|
| Supabase | Database, authentication, and edge functions; primary storage of account and lead data |
| Vercel | Application hosting and content delivery |
| Stripe | Payment processing for customer subscriptions |
| Resend | Transactional email delivery |
| Anthropic | AI generation for AI-powered tools and result explanations |
| OAuth sign-in, plus website analytics where enabled |
International transfers
Primary data storage is in EU and UK data centers, as described in the Privacy Policy. Where processing involves transferring personal data protected by the GDPR or UK GDPR to a country without an adequacy decision, the transfer relies on the European Commission's Standard Contractual Clauses, supplemented by the UK International Data Transfer Addendum where UK data protection law applies. Our subprocessors incorporate the same clauses into their own data processing terms for their onward transfers.
Retention, return, and deletion
Lead data is retained for 12 months after capture, or until you delete it from your dashboard, whichever comes first. You can export the data CalcStack holds for your account at any time, self-serve. If you cancel a subscription, your data is kept for 90 days so you can reactivate, then permanently deleted. If you delete your account, personal data is removed within 30 days. These periods match the Terms of Service and Privacy Policy, so there is one retention story across all three documents.
Getting a countersigned copy
Nothing needs to be signed for this addendum to apply; it is part of the Terms of Service from the moment an account is created. If your compliance process requires an executed document, email privacy@calcstack.net with your company name and the account email, and we will return a countersigned PDF. Redline requests are reviewed case by case; we keep amendments to what the product genuinely enforces.
Most processor addendums run to dozens of pages of defined terms. This one is short because the person who answers your procurement questionnaire also wrote the code that enforces it, and plain commitments that map to real product behavior are easier to keep than boilerplate.
Questions
Frequently Asked Questions
Do I need to sign the CalcStack DPA before it applies?
No. This addendum is incorporated into the Terms of Service and applies automatically to every account from signup, so the processor protections are in force even if your team never asks about them. If your procurement or legal process requires an executed copy, email privacy@calcstack.net and we will return a countersigned PDF, usually within a few business days.
Which subprocessors handle the lead data my tools capture?
Six vendors sit under CalcStack in the processing chain: Supabase runs the Postgres database, authentication, and edge functions where lead data lives; Vercel hosts and serves the application; Stripe processes subscription payments; Resend sends transactional email; Anthropic generates output for AI-powered tools; and Google provides OAuth sign-in plus website analytics where enabled. Each is bound by its own data processing terms.
Where is the lead data captured by my embedded tools stored?
Primary storage is the Postgres database in EU and UK data centers, consistent with the Privacy Policy. Where processing involves a transfer of GDPR-protected or UK GDPR-protected personal data to a country without an adequacy decision, the transfer relies on the European Commission's Standard Contractual Clauses, with the UK International Data Transfer Addendum applied where UK law governs.
What happens to captured lead data if I cancel my account?
You can export everything first, self-serve, at any time. After cancellation your data is retained for 90 days so you can reactivate, then permanently deleted, matching the Terms of Service. Deleting the account outright removes personal data within 30 days, and an automated test keeps the deletion plan's table list equal to the export plan's, so erasure covers everything the export covers.
The rest of the trust pack: