Summary of Material Changes from Prior Version (July 2026)
- Adds Section 2.8 (Security, Integrity, and Metering), under which Customer instructs and authorizes Pancake to Process Personal Data as reasonably necessary to maintain the integrity and accuracy of usage metering and billing, to protect the security and operational integrity of the Services, and to detect and mitigate fraudulent, unlawful, or automated abusive use. The section confirms that such Processing is a permitted business purpose within the meaning of Section 2.6, creates no monitoring obligation on Pancake, and does not permit Processing for profiling or advertising.
- Adds Section 10.5 (Usage and Billing Records), confirming that aggregate usage counts and billing records are maintained independently of Customer Personal Data, contain no Customer Personal Data, and are not subject to the deletion obligations in Section 10.
- Restates Section 11.3.4 to recite the UK Extension to the EU-U.S. Data Privacy Framework alongside the EU-U.S. and Swiss-U.S. certifications, consistent with Section 13.2 and the Terms and Conditions; renames the subsection accordingly and updates the cross-reference in Section 11.3.5.
- Restates the Annex II network security measures as web application firewall and edge request filtering.
- Confirms in Annex II that the security documentation Pancake maintains and makes available to Customer on request governs its technical and organizational measures, and that the overview published at /security-faqs is provided for information only.
- Adds Section 10.6 (Deletion During the Term), stating that Customer Personal Data deleted through the Services — an entry, a list of entries, or files uploaded by entrants — is hidden immediately, deleted from production systems within thirty (30) days, and gone from backup copies within a further thirty (30) days, and that those periods apply to a deletion made to give effect to a data subject’s erasure request.
- Sets out the deletion timeline in Section 10.2. Customer Personal Data is deleted from production systems within thirty (30) days of Termination of Service, with backup copies expiring within a further thirty (30) days. The section now also describes residual copies in backups and operational logs, which age out on their own retention schedules and are not used to restore deleted data.
- Adds a carve-out preserving separately negotiated and executed data processing agreements, which continue to govern to the extent of any conflict (How This DPA Becomes Effective, and Section 12.6).
- Restates the Subprocessor obligation in Section 5.1 as data protection obligations appropriate to the Processing and meeting the requirements of Article 28(3) of the GDPR.
- Adds a narrow provision permitting immediate engagement of a Subprocessor where necessary to maintain security, integrity or availability of the Services or to comply with a legal obligation, with notice as soon as reasonably practicable afterwards and the objection right preserved (Section 5.3).
- Commits to a pro-rata refund of prepaid fees where a Customer terminates a Service following an unresolved Subprocessor objection (Section 5.5).
- Strengthens Section 4.1 to require personnel to be bound by written confidentiality obligations surviving their engagement, and narrows the Sensitive Data liability exclusion in Section 2.4 so that it applies to Customer's submission of Sensitive Data in breach of that Section and does not limit Pancake's security or breach obligations.
- States in Section 8.1 that the exclusion for incidents caused by Customer or its users applies to liability and does not limit Pancake's obligation to notify.
- Broadens the definition of Sensitive Data to match the prohibition in the Privacy Policy, and defines Customer Personal Data, replacing the previously undefined terms "Service Data" and "Customer Data".
- Adds Annex I.C (Competent Supervisory Authority) and completes Tables 1 to 4 of the UK Addendum, both required by the Standard Contractual Clauses and the Addendum respectively; states in Annex I.B that no special categories of data are transferred, consistent with the prohibition in Section 2.4; and records in Annex I.B the security, metering and fraud-prevention purposes added by Section 2.8.
- Narrows the transfer permission in Section 11.1 to the United States and the jurisdictions of the Subprocessors identified on the published Subprocessors page.
- Editorial: renumbers the definitions, removes a paragraph in the preamble duplicating Section 11.2, retitles Section 6, links the full text of the Standard Contractual Clauses, and standardizes the naming of Pancake Laboratories Inc., d/b/a ShortStack.
This Data Processing Addendum ("DPA") forms part of the Terms and Conditions of Service and Use of ShortStack.com between Pancake Laboratories Inc., d/b/a ShortStack, a Nevada corporation ("Pancake"), and the customer agreeing to those terms ("Customer"), together with any order form, Statement of Work, or other written agreement between them for the purchase of online services (the "Services") from Pancake (collectively, the "Agreement"), and reflects the parties' agreement with regard to the Processing of Personal Data. References to "ShortStack" are to the platform and services provided by Pancake.
How This DPA Becomes Effective
By executing the Agreement or by using the Services after the effective date of this DPA, Customer agrees to be bound by the terms of this DPA. If Customer has previously executed a DPA with Pancake, this DPA supersedes and replaces that prior DPA in its entirety as of the effective date, except where that prior DPA was separately negotiated and executed by both parties, in which case that agreement continues to govern to the extent of any conflict and this DPA applies to matters it does not address. For enterprise customers requiring a separately executed DPA, Customer may contact Pancake at support@shortstack.com.
Data Processing Terms
In the course of providing the Services to Customer pursuant to the Agreement, Pancake may Process Personal Data on behalf of Customer. Both Pancake and Customer agree to comply with the following provisions with respect to any Personal Data submitted by or for Customer to Pancake or collected and processed by or for Customer using Pancake Services.
1. Definitions
In this DPA, the following terms shall have the meanings set out below and cognate terms shall be construed accordingly:
1.1. "Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity. "Control," for purposes of this definition, means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity, or the power to direct or cause the direction of the management and policies of such entity, whether through ownership of voting securities, by contract, or otherwise.
1.2. "Applicable Data Protection Laws" means all laws, rules, regulations, and governmental requirements relating to the privacy, security, confidentiality, protection, or integrity of Personal Data that apply to either Party's performance under the Agreement, as amended, superseded, or replaced from time to time, including without limitation:
- (a) Regulation (EU) 2016/679 (the "GDPR");
- (b) the UK General Data Protection Regulation and the UK Data Protection Act 2018 (the "UK GDPR");
- (c) the Swiss Federal Act on Data Protection of 25 September 2020 and its implementing ordinances (the "nFADP");
- (d) the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq., as amended by the California Privacy Rights Act of 2020 (collectively, the "CPA");
- (e) the Canadian Personal Information Protection and Electronic Documents Act ("PIPEDA");
- (f) the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados), Federal Law No. 13,709/2018 ("LGPD");
- (g) the Privacy Act 1988 (Cth) of Australia, as amended; and
- (h) any other applicable federal, state, provincial, or local data protection or privacy law.
1.3. "Customer Group" means Customer and any of Customer's Affiliates.
1.4. "Controller" means the entity which determines the purposes and means of the Processing of Personal Data, or as otherwise defined under Applicable Data Protection Laws (including "Business" under the CPA).
1.5. "Customer Data Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise Processed by Pancake or its Subprocessors.
1.6. "Customer Personal Data" means Personal Data that Pancake Processes on behalf of Customer in the course of providing the Services, including Personal Data that Customer or its end users submit to, or that is collected through, the Services. Customer Personal Data does not include Personal Data that Pancake Processes as a controller in its own right — such as Customer's account registration, billing, and support information — which is described in the Privacy Policy.
1.7. "Data Subject" means the identified or identifiable person to whom the Personal Data relates.
1.8. "EU SCCs" means the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021 (Module Two: Controller to Processor), as set forth in Schedule 1 to this DPA.
1.9. "Party" means either the Data Processor or Data Controller, and "Parties" means both the Data Processor and Data Controller.
1.10. "Personal Data" means any information relating to an identified or identifiable natural person that Pancake will Process or have access to as part of providing the Services, including any such information that is created by means of the Services, and including data defined as "Personal Information" under the CPA or any other Applicable Data Protection Law.
1.11. "Processing" means any operation or set of operations which is performed upon Personal Data, including but not limited to collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction of Personal Data.
1.12. "Processor" means the entity which Processes Personal Data on behalf of the Controller, or as otherwise defined under Applicable Data Protection Laws (including "Service Provider" under the CPA).
1.13. "Sell" has the meaning given to it under the CPA.
1.14. "Share" has the meaning given to it under the CPA.
1.15. "Sensitive Data" means any (a) special categories of personal data as defined in Article 9 of the GDPR; (b) Personal Data relating to criminal convictions and offenses as defined in Article 10 of the GDPR; (c) "Sensitive Personal Information" as defined under the CPA; (d) social security numbers, tax file numbers, passport numbers, or driver's license numbers; (e) credit or debit card numbers, other than as required for billing purposes; (f) account passwords; or (g) any similar category under other Applicable Data Protection Laws.
1.16. "Subprocessor" means any third party engaged by Pancake or its Affiliates to Process Personal Data in connection with the Services.
1.17. "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under Section 119A of the UK Data Protection Act 2018, as may be revised from time to time.
2. Processing of Personal Data
2.1. Roles of the Parties
The parties acknowledge and agree that with regard to the Processing of Personal Data when using the Services provided by Pancake, Customer is the Controller, Pancake is the Processor, and that Pancake will engage Subprocessors pursuant to the requirements set forth in Section 5 "Subprocessors" below.
2.2. Customer's Processing of Personal Data
Customer shall, in its use of the Services, Process Personal Data in accordance with the requirements of Applicable Data Protection Laws. For the avoidance of doubt, Customer's instructions for the Processing of Personal Data shall comply with Applicable Data Protection Laws. Customer shall have sole responsibility for the accuracy, quality, and legality of Personal Data and the means by which Customer acquired Personal Data.
2.3. Pancake's Processing of Personal Data
Pancake shall treat Customer Personal Data as confidential and shall Process Personal Data in a manner compliant with Applicable Data Protection Laws. Pancake will only Process Personal Data to the extent necessary to perform the Services in accordance with the Agreement and in accordance with Customer's documented instructions, unless Processing is required by applicable law to which Pancake is subject, in which case Pancake shall (to the extent permitted by law) inform Customer of that legal requirement before the relevant Processing. Pancake shall immediately inform Customer if, in Pancake's opinion, an instruction from Customer infringes Applicable Data Protection Laws.
2.4. Prohibited Data
Customer will not provide (or cause to be provided) any Sensitive Data to Pancake for Processing under the Agreement. Pancake will have no liability arising from Customer's submission of Sensitive Data in breach of this Section. Nothing in this Section limits Pancake's obligations under Section 7 (Security) or Section 8 (Breach of Personal Data Security) in respect of Personal Data it Processes.
2.5. Details of the Processing
The subject-matter of Processing of Personal Data by Pancake is the performance of the Services pursuant to the Agreement. The duration of the Processing, the nature and purpose of the Processing, the types of Personal Data, and categories of Data Subjects Processed under this DPA are further specified in Annex I.B (Description of Transfer) to this DPA.
2.6. Restrictions on Use of Personal Data
Pancake shall not:
- (a) Sell or Share Customer Personal Data;
- (b) retain, use, disclose, or otherwise Process Customer Personal Data for any purpose other than for the specific business purposes of performing the Services under the Agreement;
- (c) retain, use, disclose, or otherwise Process Customer Personal Data outside of the direct business relationship between Pancake and Customer, except as permitted under Section 13 (Assignment); or
- (d) combine Customer Personal Data with personal data that Pancake receives from or on behalf of another person or that Pancake collects from its own interactions with individuals, except to the extent necessary to perform the Services.
2.7. Certification
Pancake certifies that it understands and will comply with the restrictions set forth in Section 2.6 and will notify Customer if it determines that it can no longer meet its obligations under this Section.
2.8. Security, Integrity, and Metering
Customer instructs and authorizes Pancake to Process Personal Data to the extent reasonably necessary to: (a) maintain and verify the integrity and accuracy of usage metering and billing under the Agreement; (b) protect the availability, security, and operational integrity of the Services, including detecting and responding to security incidents; and (c) detect, investigate, prevent, and mitigate fraudulent, unlawful, or automated abusive use of the Services. Processing under this Section constitutes a specific business purpose of performing the Services within the meaning of Section 2.6 and is a permitted business purpose under the CPA. Nothing in this Section obligates Pancake to undertake any monitoring, detection, or prevention activity. Pancake shall not Process Personal Data under this Section for profiling, advertising, or the development of profiles of Data Subjects for Pancake's own commercial purposes.
3. Rights of Data Subjects
3.1. Data Subject Request
Pancake shall promptly notify Customer if Pancake receives a request from a Data Subject to exercise their rights under Applicable Data Protection Laws with respect to Personal Data (including access, rectification, restriction, deletion, portability, or the right to correct, as applicable). Taking into account the nature of the request, Pancake shall assist Customer by appropriate technical and organizational measures, to the extent legally required, for the fulfillment of Customer's obligation to respond to a Data Subject Request under Applicable Data Protection Laws.
4. Pancake Personnel and Confidentiality
4.1. Confidentiality
Pancake shall ensure that its personnel engaged in the Processing of Personal Data are bound by written obligations of confidentiality that survive the termination of their engagement, and have received appropriate training on their responsibilities.
4.2. Reliability
Pancake shall take commercially reasonable steps to ensure the reliability of any Pancake personnel who may have access to Customer Personal Data or who may be engaged in the Processing of Personal Data.
4.3. Limitation of Access
Pancake shall ensure that Pancake's access to Personal Data is limited to those Pancake personnel who need to know or access the relevant Personal Data while performing Services in accordance with the Agreement.
4.4. Data Protection Officer
Pancake has appointed a data protection officer, who can be reached at support@shortstack.com.
5. Subprocessors
5.1. Appointment of Subprocessors
Customer acknowledges and agrees that Pancake may engage third-party Subprocessors in connection with the provision of the Services. Pancake has entered into a written agreement with each Subprocessor imposing on the Subprocessor data protection obligations appropriate to the Processing and meeting the requirements of Article 28(3) of the GDPR.
5.2. List of Current Subprocessors
Pancake maintains a current list of Subprocessors at /subprocessors/ (or such other URL as Pancake may designate). Pancake will notify all customers of any change to the Subprocessor list, including the addition or replacement of a Subprocessor, in-app and by email before authorizing the new Subprocessor to Process Personal Data.
5.3. Notification of New Subprocessors
Pancake shall provide notification of a new Subprocessor(s) before authorizing any new Subprocessor(s) to Process Personal Data in connection with the provision of the applicable Services. Notification will be supplied via the mechanism described in Section 5.2.
Where Pancake must engage a new Subprocessor immediately in order to maintain the security, integrity, or availability of the Services, or to comply with a legal obligation, Pancake may do so before providing notice and shall provide notice as soon as reasonably practicable thereafter. Customer's objection right under Section 5.4 applies from the date of that notice, and Sections 5.5 and 5.6 apply without modification.
5.4. Objection Right for New Subprocessors
Customer may object to Pancake's use of a new Subprocessor by notifying Pancake promptly in writing (via email to support@shortstack.com) within fifteen (15) business days after receipt of Pancake's notice. The objection must be based on reasonable grounds relating to data protection.
5.5. Resolution of Objections
In the event Customer objects to a new Subprocessor pursuant to Section 5.4, Pancake and Customer shall work together in good faith to find a mutually acceptable resolution. If the parties are unable to resolve such objection, either party may terminate the applicable Service by providing written notice to the other party. Following such termination, Pancake shall refund any prepaid fees covering the remainder of the then-current subscription term for the terminated Service, calculated on a pro-rata basis.
5.6. Liability
Where a Subprocessor fails to fulfill its data protection obligations under its agreement with Pancake, Pancake will remain liable to the Customer for the performance of such Subprocessor's data protection obligations.
6. Ownership of Customer Personal Data
As between Customer and Pancake, Customer retains all right, title, and interest in and to Customer Personal Data collected through use of the Services. For the avoidance of doubt, to the extent that the Agreement grants Pancake any license to use information submitted to ShortStack for the purpose of improving or modifying ShortStack, such license shall not apply to Personal Data, which is governed exclusively by this DPA.
7. Security
7.1. Controls for the Protection of Customer Data
Pancake will implement and maintain technical, physical, administrative, and organizational measures to protect Personal Data against theft, unauthorized or unlawful acquisition, access, or Processing, accidental loss, destruction, alteration, or damage as described in Annex II (Technical and Organisational Measures) of this DPA, as well as any other minimum security requirements required by Applicable Data Protection Laws. Pancake will not materially decrease the overall security of the Services during a subscription term.
7.2. Security Documentation
Upon Customer's written request at reasonable intervals (not more than once per twelve-month period), Pancake shall make available to Customer that is not a competitor of Pancake (or Customer's independent, third-party auditor that is not a competitor of Pancake) documentation reasonably necessary to demonstrate Pancake's compliance with its obligations under this DPA, including Pancake's then-current security practices and procedures, subject to reasonable confidentiality obligations.
7.3. Audit Rights
Pancake shall allow for and contribute to audits and inspections conducted by Customer or an independent auditor mandated by Customer, for the purpose of demonstrating Pancake's compliance with its obligations under this DPA and Applicable Data Protection Laws. Such audits shall be subject to the following conditions:
- (a) Customer shall provide at least thirty (30) days' prior written notice;
- (b) audits shall be conducted during normal business hours and shall not unreasonably disrupt Pancake's operations;
- (c) audits shall not be conducted more than once per twelve-month period, unless required by a supervisory authority or following a Customer Data Incident;
- (d) any third-party auditor shall not be a competitor of Pancake and shall be bound by appropriate confidentiality obligations; and
- (e) Customer shall bear its own costs associated with any such audit.
7.4. Customer Responsibilities
Customer agrees that except as provided by this DPA, Customer is responsible for its secure use of the Services, including securing its account authentication credentials.
8. Breach of Personal Data Security
8.1. Notification
After becoming aware of a Customer Data Incident, Pancake shall notify Customer without undue delay, and in any event within forty-eight (48) hours. Pancake shall make reasonable efforts to identify the cause of such Customer Data Incident and take those steps as Pancake deems necessary and reasonable in order to remediate the cause of such Customer Data Incident to the extent the remediation is within Pancake's reasonable control. Pancake shall take reasonable measures to mitigate the effects and to minimize any damage resulting from the Customer Data Incident. Nothing in this Section limits Pancake's obligation to notify Customer of a Customer Data Incident. Pancake shall have no liability for a Customer Data Incident to the extent it is caused by Customer or Customer's users.
8.2. Content of Notification
Pancake's notice shall include the following information to the extent it is reasonably available to Pancake at the time of the notice, and Pancake shall update its notice as additional information becomes reasonably available:
- (a) the dates and times of the Customer Data Incident;
- (b) the facts that underlie the discovery of the Customer Data Incident;
- (c) a description of the Personal Data involved in the Customer Data Incident; and
- (d) the measures planned or underway to remedy or mitigate the vulnerability giving rise to the Customer Data Incident.
8.3. Cooperation
Pancake shall cooperate with Customer and take commercially reasonable steps to assist Customer in complying with its obligations under Articles 33 and 34 of the GDPR (or equivalent provisions under other Applicable Data Protection Laws), including any obligation to notify a supervisory authority or communicate a breach to affected Data Subjects, taking into account the nature of the Processing and the information available to Pancake.
9. Data Protection Impact Assessments
Pancake shall provide reasonable assistance to Customer with any data protection impact assessments, and prior consultations with supervisory authorities or other competent data privacy authorities, which Customer reasonably considers to be required by Applicable Data Protection Laws, in each case solely in relation to Processing of Personal Data by, and taking into account the nature of the Processing and information available to, Pancake.
10. Data Return and Deletion
10.1. Duration of Processing
Pancake will Process Personal Data for the duration of the Agreement, unless otherwise agreed upon in writing.
10.2. Termination
Following termination or expiration of the Agreement ("Termination of Service"), Pancake shall delete Customer Personal Data from its production systems within thirty (30) days. Backup copies containing Customer Personal Data expire under Pancake's retention schedules within a further thirty (30) days. Residual copies may also persist in operational logs until those logs expire under those schedules. Copies held in backups and operational logs are not accessible to Customer, are not used to restore deleted data, and cannot be selectively deleted before they expire. Pancake may retain Personal Data to the extent and for such period required by Applicable Data Protection Laws.
10.3. Customer Request
Subject to Section 10.4, Customer may by written notice (via email) to Pancake at support@shortstack.com within seven (7) days of the Termination of Service require Pancake to (a) return a complete copy of all Customer Personal Data to Customer in a commonly used machine-readable format; and (b) delete and procure the deletion of all other copies of Customer Personal Data Processed by Pancake and any Subprocessor.
10.4. Legal Retention
Pancake and Subprocessors employed by Pancake may retain Customer Personal Data to the extent required by Applicable Data Protection Laws and only to the extent and for such period as required by such laws, provided that Pancake shall ensure the confidentiality of all such Customer Personal Data and shall ensure that such Customer Personal Data is only Processed as necessary for the purpose(s) specified in the applicable laws requiring its storage and for no other purpose. Upon expiration of any applicable legal retention period, Pancake shall delete or destroy all remaining Customer Personal Data within thirty (30) days.
10.5. Usage and Billing Records
Pancake maintains aggregate usage counts and billing records generated in the course of metering Customer's use of the Services. Such records are retained independently of Customer Personal Data, do not include the content of any Customer Personal Data, and are retained following deletion of Customer Personal Data for the purpose of substantiating charges, resolving billing disputes, and meeting Pancake's financial record-keeping obligations. Nothing in this Section 10 requires Pancake to delete such usage and billing records.
10.6. Deletion During the Term
Where Customer deletes Customer Personal Data through the Services during the term of the Agreement — including an individual entry, a list of entries, or files uploaded by entrants — that data is hidden from the Services immediately and deleted from Pancake’s production systems within thirty (30) days of deletion. Backup copies containing it expire under Pancake’s retention schedules within a further thirty (30) days. Copies held in backups and operational logs are not accessible to Customer, are not used to restore deleted data, and cannot be selectively deleted before they expire.
Where Customer deletes Customer Personal Data in order to give effect to a data subject’s request for erasure, the periods in this Section 10.6 apply to that deletion. Nothing in this Section 10.6 limits Section 10.2 or Section 10.4.
11. International Data Transfers
11.1. Data Center Locations
Customer acknowledges that Pancake may transfer and Process Customer Personal Data to and in the United States, and in the jurisdictions in which the Subprocessors identified at /subprocessors/ maintain data processing operations. Pancake shall at all times ensure that such transfers are made in compliance with the requirements of Applicable Data Protection Laws and this DPA.
11.2. Transfers Outside of Europe
In connection with the Services, the parties anticipate that Pancake will transfer outside of the European Economic Area ("EEA"), Switzerland, and the United Kingdom to Pancake's Services environment located in the United States, and Process Personal Data in respect of which the Customer or any member of the Customer Group may be a data controller under Applicable Data Protection Laws.
11.3. Transfer Mechanisms
With respect to transfers of Personal Data under this DPA from the EEA, Switzerland, and/or the United Kingdom to countries which do not ensure an adequate level of data protection within the meaning of Applicable Data Protection Laws, Pancake makes available the following transfer mechanisms:
11.3.1. EU SCCs
The EU SCCs set forth in Schedule 1 to this DPA shall apply to transfers subject to the GDPR.
11.3.2. Swiss Transfers
The EU SCCs set forth in Schedule 1 to this DPA shall apply to transfers subject to the nFADP, with the modifications required to comply with the nFADP, including that the competent supervisory authority shall be the Swiss Federal Data Protection and Information Commissioner, and disputes shall be resolved before the courts of Switzerland.
11.3.3. UK Transfers
The UK Addendum, completed with the relevant information set out in the Annexes to this DPA, shall apply to transfers subject to the UK GDPR. The UK Addendum shall be governed by the laws of England and Wales, and disputes shall be resolved before the courts of England and Wales.
11.3.4. Data Privacy Framework
Pancake has certified its adherence to the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Pancake will maintain such certifications for the term of the Agreement and will provide at least the level of privacy protection required by the DPF Principles. Details of Pancake's certifications are available at https://www.dataprivacyframework.gov/.
11.3.5. Order of Precedence
In the event that Services are covered by more than one transfer mechanism, the transfer of Personal Data will be subject to a single transfer mechanism in accordance with the following order of precedence: (a) the Standard Contractual Clauses (including the UK Addendum, as applicable); and (b) Pancake's Data Privacy Framework certifications.
12. Miscellaneous
12.1. Limitation of Liability
Any claims brought in connection with this DPA (including, where applicable, the SCCs) shall be subject to the Terms and Conditions, including but not limited to the exclusions and limitations set forth in the Agreement. In no event shall any party limit its liability with respect to any Data Subject rights under this DPA.
12.2. EU GDPR
Pancake will Process Personal Data in accordance with the GDPR requirements directly applicable to Pancake's provision of its Services.
12.3. Legal Effect
This DPA becomes legally binding upon Customer's execution of the Agreement or, where applicable, upon Customer's use of the Services following the effective date of this DPA.
12.4. Modification of DPA
This DPA may not be amended or modified except through a written agreement signed by both Parties hereto, or through Pancake's publication of an updated DPA to which Customer assents by continued use of the Services.
12.5. Duration
The DPA will remain in force as long as Pancake Processes Personal Data on behalf of Customer under the Agreement.
12.6. Entire DPA
This DPA, together with its Schedules and Annexes, constitutes the entire agreement between the Parties with respect to the subject matter hereof and supersedes all prior or contemporaneous data processing agreements or addenda between the Parties, except any data processing agreement or addendum separately negotiated and executed by both parties, which continues to govern to the extent of any conflict.
13. Assignment
13.1. Assignment to a Successor
Pancake may assign this DPA and the Agreement, in whole, to a successor in interest in connection with a merger, acquisition, corporate reorganization, or sale of all or substantially all of its assets or equity, provided that the successor assumes in writing all of Pancake's obligations under this DPA. Customer Personal Data may be transferred to such successor as part of that transaction so that Customer may continue to use the Services without interruption.
For the avoidance of doubt, a transfer permitted under this Section 13.1 does not constitute retaining, using, disclosing, or otherwise Processing Customer Personal Data outside of the direct business relationship between Pancake and Customer for the purposes of Section 2.6(c), because the direct business relationship transfers to the successor rather than terminating.
13.2. Data Privacy Framework Data
Where Customer Personal Data was received in reliance on the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, or the Swiss-U.S. Data Privacy Framework, the successor must continue to apply the Data Privacy Framework Principles to that Personal Data or provide a level of protection at least equivalent to that required by the Principles. Where the successor will not agree to do so, that Personal Data will not be transferred to it.
13.3. Notice
Pancake shall notify Customer of any assignment under this Section 13 without undue delay. Customer may not assign this DPA or the Agreement without Pancake's prior written consent, except to a successor in interest in connection with a transaction of the kind described in Section 13.1.
List of Schedules and Annexes
- Schedule 1: Standard Contractual Clauses (EU SCCs, Module Two: Controller to Processor)
- UK Addendum: International Data Transfer Addendum to the EU SCCs
- Annex I.A: List of Parties
- Annex I.B: Description of Transfer
- Annex I.C: Competent Supervisory Authority
- Annex II: Technical and Organisational Measures
- Annex III: List of Subprocessors
Annex I
A. List of Parties
Data Exporter
- Name: The Customer identified in the Agreement
- Address: As set forth in the Agreement
- Contact person: As set forth in the Agreement
- Activities: Use of the ShortStack platform and Services as described in the Agreement
- Role: Controller
Data Importer
- Name: Pancake Laboratories Inc., d/b/a ShortStack
- Address: 518 Pyramid Way, Sparks, Nevada 89431, USA
- Contact: Data Protection Officer, support@shortstack.com
- Activities: Data importer operates a cloud-based marketing services platform, including online forms, contests, and interactive marketing features. The data importer will host and Process Personal Data in the course of providing its cloud-based Services to data exporter pursuant to the Agreement.
- Role: Processor
B. Description of Transfer
Categories of Data Subjects
Data exporter may submit Personal Data to the Pancake Services, the extent of which is determined and controlled by the data exporter in its sole discretion, and which may include, but is not limited to, Personal Data relating to the following categories of data subjects: data exporter's contacts and other end users, including data exporter's collaborators, customers, prospects, employees, agents, advisors, freelancers, and suppliers (who are natural persons); and entrants in and participants in contests, sweepstakes, giveaways, quizzes, polls, and other campaigns created by the data exporter using the Services.
Categories of Personal Data Transferred
The Personal Data transferred may include, but is not limited to: first and last name; professional information (title, position, employer); contact information (email, phone, physical address); form submission data; social media interaction data (imported comments, posts collected through ShortStack Feeds); campaign interaction data (campaign views, entry storage records); application integration data; system usage data; and other electronic data submitted to the Services by the data exporter.
Special Categories of Data
None. The transfer of special categories of personal data (as defined in Article 9 of the GDPR), Personal Data relating to criminal convictions and offences (Article 10), and Sensitive Data as defined in this DPA is prohibited under Section 2.4 of this DPA. Customer shall not submit such data to the Services, and Pancake does not request, require, or knowingly Process it. Where Pancake becomes aware that such data has been submitted, Pancake reserves the right, but has no obligation, to delete it and/or notify Customer, and has no obligation to screen or monitor for its presence.
Frequency of Transfer
Continuous, for the duration of the Agreement.
Retention Period
For the duration of the Agreement, and thereafter in accordance with Section 10 of the DPA.
Nature of the Processing
The data importer will host and Process Personal Data in the course of providing its cloud-based Services to data exporter pursuant to the Agreement, including collection, storage, organization, structuring, retrieval, use, disclosure by transmission, and erasure or destruction.
Purpose of the Data Transfer
The purpose of the data transfer is the provision of the Services by Pancake to Customer, including the operation of interactive marketing campaigns, online forms, contests, data collection, social media integration, and related cloud-based marketing features. As set out in Section 2.8, the purposes also include maintaining the integrity and accuracy of usage metering and billing, protecting the availability, security, and operational integrity of the Services, and detecting and mitigating fraudulent, unlawful, or automated abusive use.
C. Competent Supervisory Authority
Identified in accordance with Clause 13 of the EU SCCs:
- Where the data exporter is established in an EU Member State: the supervisory authority of that Member State.
- Where the data exporter is not established in an EU Member State but falls within the territorial scope of the GDPR under Article 3(2) and has appointed a representative under Article 27(1): the supervisory authority of the Member State in which that representative is established.
- Where the data exporter is not established in an EU Member State but falls within the territorial scope of the GDPR under Article 3(2) without being required to appoint a representative: the supervisory authority of the Member State in which the Data Subjects whose personal data is transferred in relation to the offering of goods or services to them, or whose behaviour is monitored, are located.
For transfers subject to the nFADP, the competent authority is the Swiss Federal Data Protection and Information Commissioner. For transfers subject to the UK GDPR, the competent authority is the UK Information Commissioner's Office.
Annex II — Technical and Organisational Measures
Pancake observes the technical and organizational security measures described in the security documentation Pancake maintains and makes available to Customer on request. A general overview of Pancake's security practices is also published at /security-faqs; that overview is provided for information only, and the security documentation made available on request governs in the event of any inconsistency. Pancake reserves the right to modify or update these practices at its sole discretion provided that such modification and update does not result in a material degradation in the protection offered by these practices. These measures include, without limitation:
- Encryption of Personal Data in transit (TLS 1.2 or higher) and at rest
- Access controls and authentication measures, including role-based access and multi-factor authentication for administrative access
- Regular automated vulnerability scanning and web application security scanning. Pancake is amenable to customer-initiated penetration testing upon reasonable prior written notice.
- Network security measures including web application firewall and edge request filtering
- Employee security awareness training
- Physical security of the data processing facilities operated by Pancake's cloud infrastructure provider
- Regular backups and disaster recovery procedures
- Logging and monitoring of access to Personal Data
Annex III — List of Subprocessors
A current list of Subprocessors is maintained at /subprocessors and is incorporated herein by reference. Pancake will notify all customers of any change to the Subprocessor list in-app and by email.
Schedule 1 — Standard Contractual Clauses (EU SCCs)
The Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two (Controller to Processor), are incorporated herein by reference. The full text is available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj. The parties agree that:
Clause 7 (Docking clause): The optional docking clause is included.
Clause 9(a) (Use of sub-processors): OPTION 2 (general written authorization) is selected. Pancake shall inform the data exporter of any intended changes to the list of sub-processors through the mechanism described in Section 5 of the DPA, allowing the data exporter to object to such changes within fifteen (15) business days.
Clause 11(a) (Redress): The optional language regarding independent dispute resolution is not included.
Clause 13(a) (Supervision): The supervisory authority of the EU member state in which the data exporter is established, or, where the data exporter is not established in the EU, the supervisory authority of the EU member state where the data exporter's EU representative is established, shall act as the competent supervisory authority. Where neither applies, the supervisory authority of the member state where the Data Subjects most affected by the transfer are located shall act as competent supervisory authority.
Clause 17 (Governing law): The SCCs shall be governed by the laws of Ireland.
Clause 18(b) (Choice of forum and jurisdiction): Disputes shall be resolved before the courts of Ireland.
UK Addendum to the EU SCCs
For transfers subject to the UK GDPR, the UK Addendum (International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, Version B1.0, in force 21 March 2022, as issued by the UK Information Commissioner under Section 119A of the UK Data Protection Act 2018) is incorporated herein by reference, completed as follows:
Table 1 (Parties): Start date is the effective date of this DPA. The exporter is the Customer identified in the Agreement and the importer is Pancake Laboratories Inc., d/b/a ShortStack, each as set out in Annex I.A, with contact details and key contacts as set out in that Annex.
Table 2 (Selected SCCs, Modules and Selected Clauses): The Approved EU SCCs are those incorporated at Schedule 1 to this DPA — Implementing Decision (EU) 2021/914, Module Two (Controller to Processor) — with the option selections recorded in Schedule 1.
Table 3 (Appendix Information): Annex 1A is Annex I.A of this DPA; Annex 1B is Annex I.B; Annex II (Technical and Organisational Measures) is Annex II; and the list of sub-processors is Annex III.
Table 4 (Ending this Addendum when the Approved Addendum changes): Neither party may end this Addendum as set out in Section 19 of the Approved Addendum. In the event of any conflict between the UK Addendum and the EU SCCs, the UK Addendum shall prevail to the extent of the conflict for transfers subject to the UK GDPR.
Related Documents:
Have Questions?
Data Protection Officer available upon request
For questions or concerns about this Data Processing Addendum, get in touch with our team.
Contact Us