Data Processing Agreement

Version 1.0 | Last Updated: March 30, 2026

Zero-Retention Architecture

StitchLink operates on a zero-retention data architecture. Calendar event data (titles, descriptions, attendee lists) is fetched, processed in memory, and immediately purged. We never persist sensitive calendar content in our database. Only computed free/busy time slots are used transiently during scheduling.

1. Parties and Scope

This Data Processing Agreement ("DPA") is entered into between the customer ("Controller") and Project Kaz LLC, doing business as StitchLink ("Processor"), and supplements our Terms of Service and Privacy Policy.

This DPA applies to the processing of personal data by StitchLink on behalf of the Controller in connection with the Controller's use of the StitchLink scheduling service.

2. Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person, as defined under GDPR Article 4(1).
  • Processing: Any operation performed on personal data, including collection, storage, use, disclosure, and deletion.
  • Sub-processor: A third-party entity engaged by StitchLink to process personal data on behalf of the Controller.
  • Data Subject: An identified or identifiable natural person whose personal data is processed.

3. Data Processing Details

3.1 Categories of Data Subjects

  • Host users (account holders)
  • Guest participants (invitees — no account required)

3.2 Types of Personal Data Processed

Data TypeRetentionPurpose
Email address (host)Until account deletion + 30-day graceAuthentication, notifications
Display name (host)Until account deletionPersonalization
Calendar free/busy dataPurged after computationScheduling overlap calculation
Calendar event titles/detailsNever storedNot applicable — not processed
Guest email (invitee)Purged daily via cleanup cronInvitation delivery
OAuth tokensEncrypted; revokable by userCalendar API access
Payment informationManaged by Stripe (PCI DSS L1)Subscription billing

4. Sub-processors

StitchLink engages the following sub-processors to deliver the Service. The Controller is notified of sub-processor changes via this page (updated within 30 days of any change).

Sub-processorPurposeLocationDPA Available
Supabase Inc.PostgreSQL database, authenticationUS (us-east-1)Link ↗
Stripe Inc.Subscription billing, payment processingUSLink ↗
Vercel Inc.Application hosting, edge functionsUS (global CDN)Link ↗
Resend Inc.Transactional email deliveryUSLink ↗
PostHog Inc.Consent-gated product analyticsUSLink ↗
Sentry (Functional Software Inc.)Error tracking, performance monitoringUSLink ↗

5. Security Measures

StitchLink implements the following technical and organizational measures to protect personal data:

  • Encryption in transit: All data transmitted via TLS 1.3.
  • Encryption at rest: Database encryption managed by Supabase (AES-256).
  • Access control: Row Level Security (RLS) enforced at the database layer for all user data.
  • Authentication: OAuth 2.0 with secure token storage. No passwords stored.
  • WAF protection: Web Application Firewall with bot detection, rate limiting (60 req/IP/min), and attack pattern blocking.
  • Zero-retention processing: Calendar content is never persisted. Computed only in memory.
  • Content Security Policy: Enforcing mode CSP headers on all routes.
  • Regular monitoring: Sentry error tracking + daily automated health checks.

6. Data Subject Rights

StitchLink supports the Controller in fulfilling data subject rights requests under GDPR Articles 15–22:

  • Right of access: Data export available via Settings → Export Data.
  • Right to erasure: Account deletion with 30-day grace period, followed by permanent purge.
  • Right to restriction: Contact privacy@stitchlink.ai.
  • Right to portability: JSON export of all account data.
  • Right to object: Analytics tracking can be disabled via cookie consent banner.

7. Breach Notification

In the event of a personal data breach, StitchLink will notify the Controller without undue delay and in any event within 72 hours of becoming aware of the breach. The notification will include:

  • Nature of the breach, including categories and approximate number of data subjects affected.
  • Name and contact details of the data protection contact.
  • Description of likely consequences of the breach.
  • Description of measures taken or proposed to address the breach.

8. International Data Transfers

Personal data is processed in the United States. For transfers from the EEA/UK, StitchLink relies on:

  • EU-U.S. Data Privacy Framework (where applicable).
  • Standard Contractual Clauses (SCCs) as adopted by the European Commission.

All sub-processors listed in Section 4 maintain their own GDPR compliance programs and DPAs.

9. Term and Termination

This DPA is effective as long as StitchLink processes personal data on behalf of the Controller. Upon termination of the Service agreement, StitchLink will delete all Controller personal data within 30 days, unless retention is required by applicable law.

10. Contact

Data Protection Contact

For DPA inquiries, data subject requests, or breach notifications:

Project Kaz LLC

4001 S Inglewood Ave, Bldg 101 Ste 248, Redondo Beach, CA 90278

Email: privacy@stitchlink.ai

For our full security practices, visit our Security page. For general privacy information, see our Privacy Policy.