Controller and processor
For the people data your organisation stores in STU, you are the data controller and STU is your processor. We process that data only on your documented instructions, given through your configuration and use of the platform and through this DPA, and never for our own purposes.
Scope and duration of processing
We process personal data to provide and support the STU service: employee records, time off, documents, payroll-related data, and the other information you choose to store. Processing lasts for as long as your account is active, plus any period we are legally required to retain data.
Security measures
We maintain appropriate technical and organisational measures to protect personal data, including EU/UK hosting, encryption in transit and at rest, role-based access controls, and audit logging.
Sub-processors
We use a small number of vetted sub-processors, for hosting, email delivery, and analytics, under written contracts that impose equivalent data-protection obligations. We give notice before a new sub-processor begins processing your data, so you can object.
Your instructions and data-subject requests
You can access, export, correct, and delete personal data directly in the platform, which helps you respond to data-subject requests. Where you cannot action a request yourself, we assist you within the timeframes GDPR requires.
International transfers
Your data is hosted in the UK and EU. Where any limited processing involves a transfer outside that region, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or EU Standard Contractual Clauses.
Getting a signed copy
Need a countersigned DPA for your records or procurement? Email privacy@stu.solutions and we will send one over.