This Data Processing Agreement (DPA) governs how StalliQ processes personal data on behalf of stable operators. It forms part of the contract for the use of StalliQ for a stable, i.e. the trial period and the stable subscription (see Terms of Service, sections 4.3 and 4a).
1. Parties and Roles
- Controller ("stable operator"): the business that has created a stable in StalliQ or taken out a stable subscription.
- Processor ("StalliQ"): StalliQ Labs, owner Christian Sabel, Am Weyerbach 13, 56291 Norath, Germany, email: datenschutz@stalliq.de.
This DPA only concerns the data that the stable operator processes in the stable management. For the user accounts and the other data of individual users, StalliQ itself is the controller; the Privacy Policy applies to this.
2. Subject Matter, Nature and Purpose of the Processing
StalliQ provides the stable operator with stable management software (software as a service). In doing so, StalliQ processes the data listed in section 3 exclusively to provide these features: storage, display, calculation of statistics, sending notifications to members as well as technical operation, data backup and troubleshooting.
3. Types of Data and Categories of Data Subjects
Data subjects: members of the stable, riding students and livery clients, riding instructors and staff, managed persons (usually children of members) and guests without their own account.
Data:
- Name and display name, phone number (if provided)
- Membership, role and skill level
- Riding lessons, recurring bookings, waiting lists, attendance and cancellations
- Lesson cards, allowances and transactions
- Arena bookings and resource bookings
- Payments and receipts (receipt number, amount, date, name of the paying person) as well as outstanding amounts
- Statistics and financial reports of the stable
- Announcements of the stable
- for managed persons, optionally date of birth and notes
Special categories of personal data (Art. 9 GDPR) are not subject to the processing.
4. Duration
The DPA applies as long as StalliQ processes data for the stable, i.e. for the duration of the trial period or the stable subscription and beyond that as long as the stable exists (including in read-only mode).
5. Instructions
StalliQ processes the data only on documented instructions from the stable operator, unless StalliQ is required to process it by EU or German law; in such a case, StalliQ informs the stable operator of that legal requirement before processing, unless that law prohibits such information. The instructions result from the Terms of Service, this DPA and the stable operator's use of the features. The stable operator issues further instructions in text form. If StalliQ considers that an instruction infringes data protection law, StalliQ informs the stable operator without undue delay.
6. Confidentiality
StalliQ ensures that all persons who have access to the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
7. Technical and Organizational Measures
StalliQ takes the measures required under Art. 32 GDPR to ensure the security of processing. They are described in Annex 1. StalliQ may further develop the measures as long as the agreed level of protection is not undercut.
8. Sub-Processors
The stable operator grants StalliQ general authorization to engage sub-processors. The sub-processors engaged at the time the contract is concluded are listed in Annex 2.
StalliQ informs the stable operator by email at least four weeks in advance of any intended addition or replacement of a sub-processor. The stable operator may object to the change within this period for an important reason relating to data protection. If StalliQ cannot replace the sub-processor, either party may terminate the stable subscription as of the time of the change.
StalliQ contractually binds each sub-processor to data protection obligations that correspond to those of this DPA. For transfers to countries outside the EU or the EEA, StalliQ ensures appropriate safeguards, in particular an adequacy decision of the EU Commission or EU Standard Contractual Clauses.
9. Assistance to the Stable Operator
StalliQ assists the stable operator with appropriate technical and organizational measures in responding to requests from data subjects (Art. 12 to 23 GDPR) and in complying with the obligations under Art. 32 to 36 GDPR (security of processing, notification of personal data breaches, data protection impact assessment). If a data subject contacts StalliQ directly in a matter concerning the stable, StalliQ forwards the request to the stable operator without undue delay.
10. Personal Data Breaches
StalliQ notifies the stable operator of a personal data breach without undue delay after becoming aware of it and provides the information the stable operator needs for a notification under Art. 33 GDPR.
11. Deletion and Return after the End of the Contract
If the stable operator deletes the stable, StalliQ permanently deletes the stable's data. Beforehand, the stable operator can request that StalliQ hand over the data in a common, machine-readable format. Backups are overwritten after 7 days at the latest. Data that StalliQ must retain under EU or German law is excluded from deletion, in particular receipts for payments in the stable for the duration of the statutory retention periods.
12. Evidence and Audits
On request, StalliQ makes available to the stable operator all information necessary to demonstrate compliance with this DPA and allows for audits, including inspections, by the stable operator or an auditor mandated by the stable operator who is bound to confidentiality. Audits must be announced with reasonable notice, usually four weeks, and take place during normal business hours. Evidence is primarily provided through written information and documentation.
13. Liability and Final Provisions
Art. 82 GDPR applies to liability towards data subjects; between the parties, the liability provisions of the Terms of Service apply. In the event of contradictions between this DPA and the Terms of Service, this DPA takes precedence in matters of data protection. German law applies. The contractual language is German; the English and Dutch versions are provided for information only, and in the event of any discrepancy the German version prevails.
Annex 1: Technical and Organizational Measures
- Hosting: Database and files at Supabase in a data center in Frankfurt am Main; web portal on a server of Hetzner Online GmbH in Germany.
- Encryption: All data transmissions use HTTPS/TLS.
- Access control: Row-Level Security at the database level; users only see the data for which they are authorized in the stable (roles owner, manager, riding instructor, member).
- Authentication: Passwords only as cryptographic hashes (bcrypt); alternatively sign-in via Apple or Google.
- Input control: All inputs are validated server-side.
- Files: Documents are only accessible via time-limited, signed links.
- Availability: Daily data backup, backups retained for 7 days.
- Error monitoring: Sentry only receives a pseudonymous user ID, no names, email addresses or content.
- Server protection: Firewall and automatic detection and blocking of attacks (CrowdSec).
- Administration: Administrative access only for authorized persons with personal credentials.
Annex 2: Sub-Processors
| Sub-processor | Service | Place of processing |
|---|---|---|
| Supabase, Inc. (USA) | Database, authentication, file storage, server functions | Frankfurt, Germany (EU) |
| Hetzner Online GmbH | Hosting of the web portal | Germany (EU) |
| 650 Industries, Inc. (Expo) | Delivery of push notifications (via Apple or Google) | USA |
| Plus Five Five, Inc. (Resend) | Sending emails | USA |
| Functional Software, Inc. (Sentry) | Error monitoring | USA |