StrideHQ
  • How It Works
  • For Agencies
  • For Brands
  • Book a Demo
All legal documents

Data Processing Agreement

How StrideHQ processes personal data on behalf of clients under UK GDPR.

Last updated: 30 July 2026

1. Roles

For engagement data submitted to the platform (creator details, contracts, invoices, payment instructions), the client is the controller and StrideHQ is the processor. Where StrideHQ determines its own purposes, for example fraud prevention, security logging and its own regulatory compliance, it acts as an independent controller. The payment provider acts as an independent controller for payment execution and its own AML obligations.

2. Subject matter and instructions

StrideHQ processes personal data only to provide the services described in the Client Terms and the client's documented instructions, unless required otherwise by law. Categories of data subjects: creators, client personnel. Categories of data: identity, contact, tax, banking, contract and transaction data.

3. Sub-processors

The client authorises the use of sub-processors for hosting, communications and service delivery. A current list is available on request. StrideHQ gives at least 30 days' notice before adding or replacing a sub-processor, during which the client may object on reasonable data protection grounds. StrideHQ remains responsible for its sub-processors' performance.

4. Security

Technical and organisational measures include encryption in transit (TLS 1.2+) and at rest (AES-256), UK and EU data residency by default, least-privilege access with MFA enforced, and audit logging across onboarding, contracts and payments.

5. Personnel and confidentiality

Personnel with access to personal data are bound by confidentiality obligations and receive data protection training appropriate to their role.

6. Data subject requests and assistance

StrideHQ will promptly notify the client of data subject requests it receives relating to client data, and will assist the client with requests, security, breach notification, and data protection impact assessments, taking into account the nature of the processing.

7. Breach notification

StrideHQ notifies affected clients without undue delay after becoming aware of a personal data breach affecting client data, providing the information reasonably required for the client to meet its own notification obligations.

8. International transfers

Transfers outside the UK or EEA are made under adequacy regulations, the UK International Data Transfer Agreement or Addendum, or EU Standard Contractual Clauses, as applicable.

9. Deletion and return

On termination, StrideHQ deletes or returns client data at the client's choice, except where retention is required by law (including AML and tax record-keeping), in which case the data remains protected under these terms until deletion.

10. Audit

StrideHQ makes available information reasonably necessary to demonstrate compliance and allows audits by the client or its appointed auditor, on reasonable notice, no more than once per year unless required by a supervisory authority or following a breach.

StrideHQ
  • Blog
  • Privacy
  • Terms
  • Cookies
  • DPA
  • Contact

© 2026 StrideHQ. All rights reserved.