Last Updated: May 8, 2026
Effective as of: May 8, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between Stonesystems LLC ("Processor," "we," "us," or "our") and the business entity using our Services ("Controller," "you," or "your") and applies where we process personal information on your behalf in connection with the Services. This DPA supplements your agreement with us and our Privacy Policy.
You are the business or controller of Personal Information you submit to the Services about your customers, leads, or personnel. We act as your service provider or processor and will Process that Personal Information only on your documented instructions and as described in this DPA and our agreement, unless otherwise required by law.
We ensure that persons authorized to Process Personal Information are subject to appropriate confidentiality obligations (contractual or statutory). We provide training on data protection appropriate to their role.
You authorize us to engage the sub-processors listed below to Process Personal Information on your behalf. We remain responsible for each sub-processor's performance of its obligations in accordance with this DPA.
| Sub-processor | Service provided | Location |
|---|---|---|
| HighLevel LLC (GoHighLevel) | CRM, SMS/MMS, marketing automation, client portal, and related platform services | United States |
| Stripe, Inc. | Payment processing and billing | United States |
| Meta Platforms, Inc. | Advertising delivery, measurement, and conversion tracking | United States |
| Google LLC | Google Ads, Google Analytics, and related advertising or analytics services | United States |
| TikTok Technology Ltd / TikTok For Business | Advertising delivery and measurement | United States / Singapore |
| LinkedIn Corporation | Advertising delivery and measurement | United States |
| PostHog, Inc. | Product and website analytics | United States |
| Resend, Inc. | Transactional email delivery (e.g., privacy and account notifications) | United States |
| Vercel Inc. | Website hosting, CDN, and application infrastructure | United States |
We may replace or appoint additional sub-processors in accordance with Section 5.2. An up-to-date list is published at stonesystems.io/subprocessors.
We will provide you at least 30 days' advance notice of a new sub-processor or a material change to a sub-processor arrangement, unless we cannot do so due to legal or security reasons (in which case we will notify you as soon as reasonably practicable). If you object on reasonable data-protection grounds, we will work with you in good faith to resolve the objection.
We implement and maintain appropriate technical and organizational measures designed to protect Personal Information against unauthorized access, loss, or alteration, taking into account the nature of processing and the risks involved. Measures may include access controls, encryption in transit, logging, vendor reviews, and incident response procedures.
Taking into account the nature of the Processing, we will assist you by appropriate technical and organizational measures, insofar as possible, to fulfill your obligation to respond to consumer rights requests under Applicable Privacy Laws. Where a request is submitted directly to us, we will instruct the requester to contact you unless we are legally required to respond directly.
We retain Personal Information only as long as necessary to provide the Services and as described in our Privacy Policy. Upon termination of the Services or upon your written request (subject to legal retention requirements), we will delete or return Personal Information in our possession, unless retention is required by law.
Upon reasonable written request, we will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of our security practices or completed questionnaires. Where an on-site audit is required by Applicable Privacy Laws, such audit will be conducted during business hours, with reasonable advance notice, and subject to confidentiality and security controls.
Personal Information may be processed in the United States. If we transfer Personal Information across borders where required by law, we will implement appropriate safeguards described in our agreement or as otherwise required by Applicable Privacy Laws.
Liability arising from our Processing of Personal Information under this DPA is subject to the limitations and exclusions in your agreement with us, except where prohibited by Applicable Privacy Laws.
For questions about this DPA or our Processing of Personal Information on your behalf, contact [email protected] or (808) 645-4509.
See everything we do to help you grow your business so you can implement it yourself or let us do it for you.
Book A Call
Demo Call
(20 mins)
It's actually a sales call, we just didn't want to scare you. But seriously... we'll answer all your questions, show you any features you have questions about, and show you live client accounts & results.
We build your system
(7-10 days)
Fill out a basic onboarding form with your business details. After we have the correct information, we'll get to work on building your new website & marketing system.
Launch Call
(25 mins)
We'll walk you through your new website & marketing system, answer any questions you have, and show you how "everything" works... And by everything, we’re really just talking about pressing two buttons.