Skip to content
New: simulate any flow against real records before it goes live. See what's new

Data Processing Addendum

Last updated 10 July 2026

1. Scope and roles

This Data Processing Addendum ("DPA") forms part of the Terms of Service and applies where Solstral processes personal information within Customer Data on your behalf. You are the controller (or a processor acting for another controller); Solstral is the processor. Solstral processes Customer Data only on your documented instructions, as expressed through your use and configuration of the Service, unless required by law (in which case we inform you unless legally prohibited).

2. Details of processing

Subject matter: provision of the CRM and marketing platform. Duration: the subscription term plus the 30-day export window. Nature and purpose: hosting, storage, transmission, display, sending of communications you compose, and automated processing you configure. Data subjects: your contacts, leads, customers and users. Categories: names, contact details, employment information, communication history, behavioural data (opens/clicks), and any custom fields you define. You agree not to store special-category health, biometric or criminal-record data without a separate written agreement.

3. Confidentiality and personnel

Solstral personnel with access to Customer Data are bound by confidentiality obligations and access data strictly on a need-to-know basis, with access logged.

4. Security

We maintain technical and organisational measures including: encryption at rest (AES-256 via AWS RDS) and in transit (TLS 1.2+), role-based access control enforced in a single audited access layer, MFA, audit logging with field-level diffs, network controls via Cloudflare, signature verification on all inbound webhooks, and environment separation. We will not materially degrade these measures during your term.

5. Sub-processors

You authorise the sub-processors listed below. The current list is always published at solstral.com/legal/subprocessors, which is generated from the same source as this section.

  • Amazon Web Services (Amazon Web Services, Inc. / AWS Australia) — Application hosting, the PostgreSQL database, file storage, and outbound email delivery (Amazon SES). Processes Platform Data received from Meta. Location: Sydney, Australia (ap-southeast-2).
  • Cloudflare (Cloudflare, Inc.) — DNS, TLS termination, network security and DDoS protection, and inbound email routing. Processes Platform Data received from Meta. Location: Global edge network (United States entity).
  • OpenAI (OpenAI, L.L.C.) — Powers the AI assistant, the AI chatbot, AI automation steps, AI-assisted drafting, and voice input (speech-to-text) in the assistant. Content is sent to the model only when one of those features is used. OpenAI does not use API data to train its models. Processes Platform Data received from Meta. Location: United States. Optional — can be disabled.
  • Stripe (Stripe, Inc. / Stripe Payments Australia Pty Ltd) — Subscription billing and payment processing. Card details are entered directly into Stripe's hosted fields and never reach Solstral's servers. Location: United States and Australia.
  • Hostinger (Hostinger International Ltd) — Hosting for the public marketing website (solstral.com). Location: European Union.
  • GitHub (GitHub, Inc. (Microsoft)) — Source code hosting and the automated build/deployment pipeline. Location: United States.

AI model provider. OpenAI receives Customer Data only when you use an AI feature, and only the content that feature needs. It does not train on that content, and deletes it within 30 days. If your policy does not permit disclosure to a third-party model provider, an owner or admin can disable AI for your workspace in Settings → AI, after which no Customer Data is sent to it at all.

Cross-border disclosure. Amazon Web Services processes and stores Customer Data in Sydney. The remaining sub-processors operate outside Australia (principally the United States), so using the Service involves cross-border disclosure for the purposes of Australian Privacy Principle 8 and Chapter V of the GDPR. We rely on standard contractual clauses and the providers' own transfer frameworks.

We will give workspace owners at least 14 days' notice before adding or replacing a sub-processor, during which you may object on reasonable grounds; if we cannot resolve the objection, you may terminate the affected service with a pro-rata refund.

6. Data subject requests

Taking into account the nature of processing, we provide the tools (search, export, deletion, suppression) to answer data subject requests yourself, and will provide reasonable further assistance on request.

7. Breach notification

We will notify affected customers without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer Data, including known scope, likely consequences, and mitigation taken or proposed.

8. International transfers

Customer Data is stored in Australia. Where a transfer outside Australia or the EEA/UK becomes necessary, we implement recognised safeguards (including standard contractual clauses) before transferring.

9. Deletion and return

On termination, Customer Data remains exportable for 30 days, then is deleted from production within a further 7 days and from backups within 35 days, except where retention is required by law.

10. Audit

We will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party assessments, no more than once per year and under confidentiality.