Current Version: 2.0 • Last Updated: 2026-05-12

This is the current version of our data processing addendum. Previous versions are available for reference.

View History

Summary

This Data Processing Addendum ("DPA") sets out the parties' obligations when Noble Stark LLC ("Processor") processes Personal Data on behalf of a Customer ("Controller") in connection with the Services. It is designed to meet GDPR Article 28 obligations and incorporates EU/UK Standard Contractual Clauses where required.

A signature-ready PDF version is available on request from support@noblestark.com. The public text below is the reference version incorporated by reference into the applicable MSA.

1. Definitions

  • "Applicable Data Protection Law" means the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), and any other applicable law governing the protection of Personal Data.
  • "Personal Data" has the meaning given in Applicable Data Protection Law.
  • "Processing" has the meaning given in Applicable Data Protection Law.
  • "Sub-processor" means any third party engaged by Processor to process Personal Data on behalf of Controller.

2. Roles and scope

The parties acknowledge that, with respect to Personal Data submitted by Controller to the Services, Controller is the Controller and NobleStark is the Processor. Processor will process Personal Data only on documented instructions from Controller, as set out in the MSA, applicable SOW, and this DPA.

3. Categories of data and data subjects

The categories of Personal Data and data subjects processed are determined by the customer in the SOW. Typical categories include:

  • Authorized customer personnel contact information (name, work email, role)
  • Sample inputs and outputs provided by Customer for evaluation (which may incidentally contain Personal Data)
  • Account, authentication, and audit-log records

4. Processor obligations

  • Process Personal Data only per documented Controller instructions, unless required by law
  • Ensure that personnel authorized to process Personal Data are bound by confidentiality
  • Implement appropriate technical and organizational measures, as described in our Trust Center at /security
  • Engage Sub-processors only with prior general authorization (see Section 6) and impose data protection terms no less protective than this DPA
  • Assist Controller with data subject rights requests by appropriate technical and organizational measures
  • Assist Controller in meeting obligations under Articles 32–36 GDPR (security, breach notification, DPIA, prior consultation)
  • On termination of the Services, delete or return Personal Data per Controller's choice within 30 days, subject to legal retention requirements
  • Make available all information necessary to demonstrate compliance and contribute to audits, including inspections (see Section 8)

5. International transfers

Where Processor transfers Personal Data outside the EEA, UK, or Switzerland to a country without an adequacy decision, the parties agree the EU Standard Contractual Clauses (Module Two, Controller to Processor) and the UK International Data Transfer Addendum apply, and are incorporated by reference. The Annexes are completed as follows:

  • Annex I.A (Parties) — Controller and Processor as identified in the MSA
  • Annex I.B (Description of transfer) — as set out in the applicable SOW and Section 3 above
  • Annex I.C (Competent supervisory authority) — the supervisory authority of the EEA member state where the Controller is established
  • Annex II (Technical and organizational measures) — incorporates the Trust Center at /security
  • Annex III (Sub-processors) — see /subprocessors

6. Sub-processors

Controller grants Processor general authorization to engage Sub-processors, subject to Processor maintaining a current Sub-processor list at /subprocessors. Processor will notify Controller of intended additions or replacements no less than 30 days in advance. Controller may object on reasonable data-protection grounds within 15 days; Processor will work in good faith to resolve, and if unresolved, Controller may terminate the affected portion of the Services with prorated refund.

7. Security and breach notification

Processor maintains the technical and organizational measures set out in the Trust Center at /security. Processor will notify Controller without undue delay (and in any event within 72 hours of confirmation) of a Personal Data Breach affecting Controller\'s data, providing the information reasonably required for Controller to meet its own notification obligations.

8. Audit rights

  • Processor will make available, on Controller's written request, all information necessary to demonstrate compliance with this DPA, including the most recent third-party audit report (e.g., SOC 2) under NDA.
  • Controller may, no more than once per year and on no less than 30 days' written notice (or immediately in the event of a confirmed breach), audit Processor's compliance, either itself or through an independent auditor mutually acceptable to the parties.
  • Audits must be conducted during business hours, minimize disruption, and respect the confidentiality of other Processor customers.

9. Data subject rights and DSARs

Processor will, taking into account the nature of the processing, assist Controller by appropriate technical and organizational measures, insofar as possible, in fulfilling Controller\'s obligation to respond to requests for the exercise of data subject rights. Processor maintains a public DSAR intake at /dsar for individuals whose data is held directly by Processor.

10. CCPA / CPRA addendum

For Personal Information of California residents, Processor acts as a "service provider" as defined in the CCPA/CPRA. Processor will not (a) sell or share Personal Information; (b) retain, use, or disclose Personal Information for any purpose other than performing the Services; or (c) combine Personal Information received from Controller with Personal Information from other sources, except as permitted by the CCPA/CPRA.

11. Liability and term

Each party\'s liability under this DPA is subject to the limitations of liability set out in the MSA. This DPA remains in effect for as long as Processor processes Personal Data on behalf of Controller and survives termination as required by Applicable Data Protection Law.

Data Protection contact

Noble Stark LLC
131 Continental Dr Suite 305, Newark, DE 19713, US
Privacy: support@noblestark.com
Security: security@noblestark.com

Version 2.0 · Last updated: 2026-05-12