(a) Definitions.
European Data Protection Laws means European Data Protection Laws of the EU (including the United Kingdom), including the GDPR;
Controller Has the meaning given in applicable Data Protection Laws from time to time
Customer Means the Subscriber to Supplier
Data Protection Laws Means, as binding on either party or the services: All applicable worldwide data protection legislation which applies to the respective party in their role as a Data Processor, including but not limited to the European Data Protection Laws, the CCPA and similar such laws; in each case as amended, repealed, consolidated, or replaced from time to time.
Data Subject Has the meaning given in applicable Data Protection Laws from time to time
GDPR means the General Data Protection Regulation, Regulation (EU) 2016/679;
International Organization Has the meaning in the GDPR
Personal Data Has the meaning given in applicable Data Protection Laws from time to time
Personal Data Breach Has the meaning given in Applicable Data Protection Laws from time to time;
Processing Has the meaning given in applicable Data Protection Laws from time to time (and related expressions, including process, processed, processing, and processes shall be construed accordingly)
Processor Has the meaning given in applicable Data Protection Laws from time to time
Protected Data Means personal data received from or on behalf of the Customer in connection with the performance of the Supplier’s obligations under this Agreement
Sub-Processor Means any Processor engaged by the Supplier (or by any other Sub-Processor) for carrying out any processing activities in respect of the Protected Data on behalf of the Customer.
Supplier means Stacker Solutions, LLC
(b) Customer’s Compliance with Data Protection Laws.
The parties agree that the Customer is a controller and that the Supplier is a processor for the purposes of processing protected data pursuant to this Agreement. The Customer shall at all times comply with all Data Protection Laws in connection with the processing of protected data. The Customer shall ensure all instructions given by it to the Supplier in respect of protected data (including the terms of this Agreement) shall at all times be in accordance with all Data Protection Laws.
(c) Supplier's Compliance with Data Protection Laws.
The Supplier shall process protected data in compliance with the obligations placed on it under Data Protection Laws and the terms of this Agreement.
(d) Indemnity
The Customer shall indemnify and keep indemnified the Supplier against all losses, claims, damages, liabilities, fines, sanctions, interest, penalties, costs, charges, expenses, compensation paid to Data Subjects, demands, and legal and other professional costs (calculated on a full indemnity basis and in each case whether or not arising from any investigation by, or imposed by, a supervisory authority) arising out of or in connection with any breach by the Customer of its obligations under this Agreement.
(e) Instructions.
(f) Security.
The Supplier shall implement and maintain the technical and organizational measures set out in Section (b) of Part 2 of this Agreement to protect the protected data against accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure, or access.
(g) Sub-Processing and Personnel.
(h) List of Authorized Sub-Processors and Further Sub-Processors.
The Customer authorizes the appointment of the Sub-Processors listed here: AWS, Google Maps, Google Geocoding, Places API, Google Calendar, Google Captcha, Google Time Zones, Google People API, Google Workspace, Stream, Firebase, Twilio, SendGrid, PayPal, Stripe, Auth0, Quickbooks, Currency Converter, Outscrapper, Bitly, Microsoft Azure, Microsoft 365, Email Engine, Frola.
The Customer shall reply to any communication from the Supplier requesting any further prior specific authorization of a Sub-Processor promptly and in any event within 10 Business Days of request from time to time. The Customer shall not unreasonably withhold, delay or condition any such authorization. An email with an update to this Agreement that is not protested by the Customer will assume the Customer has accepted the new terms of this Agreement.
(i) Assitance.
(j) International Transfers.
The Supplier shall not process and/or transfer, or otherwise directly or indirectly disclose, any Protected Data in or to any country or territory outside the United States or to any International Organization without the prior written authorization of the Customer, except where required by Data Protection Laws (in which case the provisions of paragraph (f) of this Part 1 shall apply).
(k) Audits and Processing.
The Supplier shall, in accordance with Data Protection Laws, make available to the Customer on request such information that is in its possession or control as is necessary to demonstrate the Supplier’s compliance with the obligations placed on it under this Agreement and to demonstrate compliance with the obligations on each party imposed by Article 28 of the GDPR, and allow for and contribute to audits, including inspections, by the Customer (or another auditor mandated by the Customer) for this purpose (subject to a maximum of one audit request in any 12 month period under this paragraph (k)). To the extent consistent with the forgoing, the Supplier shall, however, be entitled to withhold information where it is commercially sensitive or confidential to it or its other Customers.
(l) Breach.
The Supplier shall notify the Customer without undue delay and in writing on becoming aware of any Personal Data Breach in respect of any Protected Data.
(m) Deletion/Return.
(n) Survival.
This section shall survive termination or expiry of this Agreement:
2. Data Processing and Security Details.
Customers may submit Personal Data the extent of which is full governed by the Customer and controlled by the Customer at their sole discretion.
This Personal Data may include:
a) Contact Information
b) Any other personal data uploaded, sent, received or submitted by Customer or Customer’s end users
ii. Duration of the Processing:
Continuous
iii. Nature and purpose of the Processing:
Personal Data will be Processed in accordance with the Privacy Policy and this Agreement and may be subject to the following Processing activities:
(iv) Type of Personal Data:
The Parties do not anticipate the transfer of sensitive data
b. Minimum Technical and Organizational Security Measures.
The Supplier shall implement and maintain the following technical and organizational security measures to protect the protected data:
BaseStation is a single system that takes care of everything your business needs - for everyone on your entire team - all in one place. It's easy to use, affordable, and backed by our team, who is there every step of the way to ensure that you achieve and exceed your goals.
FEATURES
COMPANY
Copyright © 2025 BaseStation. All Rights Reserved.