How StrideHQ processes personal data on behalf of clients under UK GDPR.
Last updated: 30 July 2026For engagement data submitted to the platform (creator details, contracts, invoices, payment instructions), the client is the controller and StrideHQ is the processor. Where StrideHQ determines its own purposes, for example fraud prevention, security logging and its own regulatory compliance, it acts as an independent controller. The payment provider acts as an independent controller for payment execution and its own AML obligations.
StrideHQ processes personal data only to provide the services described in the Client Terms and the client's documented instructions, unless required otherwise by law. Categories of data subjects: creators, client personnel. Categories of data: identity, contact, tax, banking, contract and transaction data.
The client authorises the use of sub-processors for hosting, communications and service delivery. A current list is available on request. StrideHQ gives at least 30 days' notice before adding or replacing a sub-processor, during which the client may object on reasonable data protection grounds. StrideHQ remains responsible for its sub-processors' performance.
Technical and organisational measures include encryption in transit (TLS 1.2+) and at rest (AES-256), UK and EU data residency by default, least-privilege access with MFA enforced, and audit logging across onboarding, contracts and payments.
Personnel with access to personal data are bound by confidentiality obligations and receive data protection training appropriate to their role.
StrideHQ will promptly notify the client of data subject requests it receives relating to client data, and will assist the client with requests, security, breach notification, and data protection impact assessments, taking into account the nature of the processing.
StrideHQ notifies affected clients without undue delay after becoming aware of a personal data breach affecting client data, providing the information reasonably required for the client to meet its own notification obligations.
Transfers outside the UK or EEA are made under adequacy regulations, the UK International Data Transfer Agreement or Addendum, or EU Standard Contractual Clauses, as applicable.
On termination, StrideHQ deletes or returns client data at the client's choice, except where retention is required by law (including AML and tax record-keeping), in which case the data remains protected under these terms until deletion.
StrideHQ makes available information reasonably necessary to demonstrate compliance and allows audits by the client or its appointed auditor, on reasonable notice, no more than once per year unless required by a supervisory authority or following a breach.