STILLHAVEN DATA PROCESSING ADDENDUM
Last updated: July 15, 2026 · Version: 1.3
1. Application of this DPA
1.1 This Data Processing Addendum ("DPA") forms part of the Stillhaven Terms of Use (the "Terms") between the Customer and B Side Solutions, LLC ("Stillhaven") and applies to Stillhaven's Processing of Customer Personal Data on the Customer's behalf in connection with the Services.
1.2 For the purposes of this DPA, and with respect to Customer Personal Data, the Customer is the Controller (or a processor acting on behalf of a third-party controller) and Stillhaven is the Processor. Where the Customer is itself a processor, the Customer warrants it has the third-party controller's authority to enter into this DPA and to give the instructions in it.
1.3 If there is a conflict between this DPA and the rest of the Terms on the subject of data protection, this DPA controls. The Standard Contractual Clauses (Section 10) prevail over this DPA to the extent of any conflict.
2. Definitions
2.1 "Data Protection Laws" means all laws applicable to the Processing of Customer Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018 ("UK GDPR"), and US state privacy laws including the California Consumer Privacy Act as amended by the CPRA ("CCPA").
2.2 "Customer Personal Data" means personal data contained in Customer Content or otherwise Processed by Stillhaven on the Customer's behalf under the Terms — for example, personal data of individuals appearing in videos and viewer/delivery data.
2.3 "Controller," "Processor," "Data Subject," "Personal Data," "Processing," "Sub-processor," and "Personal Data Breach" have the meanings given in the Data Protection Laws. "Standard Contractual Clauses" or "SCCs" means the clauses in Commission Implementing Decision (EU) 2021/914, as completed in Annex 1–3 and Section 10.
3. Scope and roles
3.1 Stillhaven will Process Customer Personal Data only as a Processor, for the purposes and in the manner set out in this DPA and Annex 1 (Details of Processing), and as necessary to provide the Services.
3.2 The subject matter, duration, nature and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are described in Annex 1.
4. Customer obligations
4.1 The Customer is responsible for the accuracy, quality, and legality of Customer Personal Data and for the lawfulness of its collection and its provision to Stillhaven.
4.2 The Customer warrants that it has a valid legal basis for the Processing, has provided all required notices, and has obtained all required consents from Data Subjects (including individuals depicted in Customer Content and viewers), and that its instructions to Stillhaven will comply with Data Protection Laws.
5. Stillhaven's processing obligations
Stillhaven will:
5.1 Instructions. Process Customer Personal Data only on the Customer's documented instructions (including as set out in this DPA and the Terms), unless required to do otherwise by law — in which case Stillhaven will inform the Customer of that legal requirement before Processing, unless the law prohibits it.
5.2 Notify unlawful instructions. Inform the Customer if, in Stillhaven's opinion, an instruction infringes Data Protection Laws (without obligation to provide legal advice).
5.3 Confidentiality. Ensure that persons authorized to Process Customer Personal Data are bound by appropriate confidentiality obligations.
5.4 Security. Implement and maintain the technical and organizational measures set out in Annex 2, appropriate to the risk, in accordance with GDPR Article 32.
5.5 Sub-processors. Engage Sub-processors only in accordance with Section 8.
5.6 Data-subject requests. Taking into account the nature of the Processing, assist the Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights (Section 9).
5.7 Assistance. Assist the Customer in ensuring compliance with its obligations regarding security, Personal Data Breach notification, data protection impact assessments, and prior consultation with supervisory authorities (GDPR Articles 32–36), taking into account the nature of Processing and the information available to Stillhaven.
5.8 Deletion or return. On termination of the Services, delete or return Customer Personal Data as described in Section 12 and the Terms.
5.9 Records and audits. Make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, in accordance with Section 11.
6. Personal data breach
6.1 Stillhaven will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to help the Customer meet its own breach-notification obligations.
6.2 Stillhaven will take reasonable steps to mitigate and remediate the breach. Stillhaven's notification is not an acknowledgment of fault or liability.
7. [Reserved]
8. Sub-processors
8.1 The Customer provides general authorization for Stillhaven to engage Sub-processors to Process Customer Personal Data, provided Stillhaven: (a) maintains a current list of Sub-processors (Annex 3 / the sub-processor list); (b) imposes data-protection obligations on each Sub-processor that are no less protective than those in this DPA; and (c) remains responsible for its Sub-processors' performance.
8.2 Changes. Stillhaven will give the Customer notice (for example, by updating the list and, where the Customer subscribes, by email) before adding or replacing a Sub-processor. The Customer may object on reasonable data-protection grounds within 14 days; the parties will work in good faith to resolve the objection, and if they cannot, the Customer may terminate the affected Services as its exclusive remedy.
9. Data-subject requests
9.1 If Stillhaven receives a request from a Data Subject relating to Customer Personal Data, it will, unless legally required to respond, refer the Data Subject to the Customer and/or promptly inform the Customer, and will assist the Customer as described in Section 5.6.
10. International data transfers
10.1 To the extent Stillhaven Processes Customer Personal Data originating from the EU/EEA, UK, or Switzerland in a country without an adequacy decision, the parties agree that the following apply as appropriate safeguards:
(a) EU/EEA: the Standard Contractual Clauses (Decision (EU) 2021/914) are incorporated by reference and completed as follows — Module Two (Controller-to-Processor) where the Customer is a Controller, and Module Three (Processor-to-Processor) where the Customer is itself a processor; the optional docking clause applies; the audit/sub-processor options are as set out in this DPA; the governing law and supervisory authority are set out in Annex 1; and Annexes I–III of the SCCs are populated by Annex 1–3 of this DPA.
(b) UK: the UK International Data Transfer Addendum to the EU SCCs is incorporated by reference and completed using Annex 1–3.
(c) Switzerland: the EU SCCs apply with the adaptations required by Swiss law.
10.2 The Standard Contractual Clauses (and, for the UK, the UK International Data Transfer Addendum) are the operative safeguard for the transfers described in Section 10.1. Stillhaven does not currently self-certify under the EU-U.S. Data Privacy Framework; if it does so in the future, it will update this DPA and its sub-processor information accordingly.
11. Audits
11.1 Stillhaven will make available information reasonably necessary to demonstrate compliance with this DPA. On reasonable prior written notice, no more than once per year (unless required by a supervisory authority or following a Personal Data Breach), the Customer (or an independent auditor it appoints, bound by confidentiality) may audit Stillhaven's compliance, during business hours, without unreasonably disrupting Stillhaven's operations, subject to reasonable confidentiality and security conditions. Stillhaven may satisfy audit requests by providing existing third-party reports or certifications where available.
12. Term, deletion, and return
12.1 This DPA takes effect when the Customer accepts the Terms and continues while Stillhaven Processes Customer Personal Data.
12.2 On termination or expiry, Stillhaven will, at the Customer's choice, delete or return Customer Personal Data and delete existing copies, except to the extent retention is required by law (including preservation of reported child-exploitation material). Deletion timing aligns with the export window in the Terms and Stillhaven's routine backup cycles.
13. US state privacy terms (service provider)
13.1 With respect to Personal Data subject to the CCPA and similar US state laws, Stillhaven acts as the Customer's "service provider" (or "processor"/"contractor" as applicable) and will:
(a) Process the Personal Data only to provide the Services / for the "business purposes" specified, and not for any other purpose; (b) not "sell" or "share" the Personal Data, and not retain, use, or disclose it outside the direct business relationship or as otherwise prohibited by law; (c) not combine the Personal Data with data from other sources except as permitted by law; (d) comply with applicable obligations and provide the same level of privacy protection as required of a service provider; and (e) notify the Customer if it determines it can no longer meet these obligations, and allow the Customer to take reasonable steps to stop and remediate unauthorized use.
14. Liability
14.1 Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability in the Terms. Nothing in this DPA limits liability that cannot be limited under Data Protection Laws (including, as between the parties and Data Subjects, under the SCCs).
15. Relationship to the Terms
15.1 Except as amended by this DPA, the Terms remain in full force. This DPA does not grant either party rights beyond those in the Terms except as required by Data Protection Laws.
ANNEX 1 — DETAILS OF PROCESSING (and SCC Annex I)
-
Data exporter: the Customer (Controller or processor). Contact/role: as identified in the Customer's account.
-
Data importer: B Side Solutions, LLC (Processor), 517 E. Exchange St., Spring Lake, MI 49456, USA. Contact: privacy@stillhaven.io.
-
Categories of Data Subjects: individuals appearing in Customer Content; the Customer's viewers/end-users; the Customer's personnel who administer the account.
-
Categories of Personal Data: identifiers and contact data of account users; images/audio/likeness of individuals in Customer Content; viewer/delivery data (IP address, approximate location, device/browser data, viewing analytics).
-
Special-category data: None..
-
Nature and purpose of Processing: hosting, storage, transcoding, streaming, embedding, delivery, access control, and analytics of Customer Content, and related security and support, to provide the Services.
-
Duration: for the term of the Services plus the retention/deletion periods in Section 12.
-
Frequency of transfer: continuous, as the Customer uses the Services.
ANNEX 2 — TECHNICAL AND ORGANIZATIONAL MEASURES (and SCC Annex II)
Stillhaven maintains measures appropriate to the risk, including:
-
Encryption of Customer Personal Data in transit (TLS) and at rest where supported.
-
Access controls — least-privilege access, unique credentials, and multi-factor authentication for administrative access.
-
Network and infrastructure security — hosting on Amazon Web Services with security controls, segmentation, and signed/authorized content delivery.
-
Logging and monitoring of access and security events.
-
Secure development and change-management practices.
-
Backup and resilience measures.
-
Vendor management — data-protection terms with Sub-processors.
-
Incident response — a process to detect, investigate, and notify Personal Data Breaches.
-
Personnel — confidentiality obligations and security awareness.
ANNEX 3 — SUB-PROCESSORS
Current Sub-processors (maintained at the sub-processor list):
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Hosting, storage, transcoding, content delivery | United States (us-east-1) |
| Stripe | Payment processing | United States |
| Amazon SES | Transactional/system email | United States |
| ActiveCampaign | Marketing/lifecycle email | United States |
| Google (Google Analytics / Tag Manager) | Website and product analytics | United States |