Stem legal
Data Processing Addendum
This DPA applies automatically where a Stem customer controls personal data about customers, staff, suppliers or other people and asks Stem to process that data to provide the Services.
- Effective
- 4 September 2026
- Version
- 2026-09-04
1. Roles and instructions
The Customer is the controller and Stem is the processor for Customer Personal Data. Stem will process it only to provide, secure and support the Services, follow the Customer’s documented lawful instructions and comply with law. The User Agreement, configured features, support requests and this DPA form those instructions.
2. Customer duties
- Have a lawful basis, provide required notices and give only lawful instructions.
- Configure access and retention appropriately and keep account contacts current.
- Respond to people’s rights requests and tell Stem when assistance is needed.
- Do not submit prohibited or unusually sensitive data without written approval and safeguards.
3. Confidentiality and security
Stem ensures people authorised to process Customer Personal Data are bound by confidentiality and access it only as needed. Stem maintains proportionate technical and organisational measures including access controls, secure credential handling, encrypted transport, tenant separation, logging, rate limiting, backup controls and incident procedures.
4. Subprocessors and transfers
The Customer gives general authorisation for vetted subprocessors needed for hosting, synchronisation, storage, communications, security, support, document rendering and payment confirmation. Stem remains responsible for imposing appropriate data-protection obligations on them.
Stem will give reasonable notice of a material new subprocessor where required, consider a documented reasonable objection and use a lawful safeguard for restricted international processing.
5. Assistance
Taking account of the nature of processing, Stem will reasonably assist with access, correction, deletion, restriction, portability and objection requests; security and breach duties; impact assessments; regulator consultations; and information reasonably needed to demonstrate compliance. Extra work outside ordinary product controls may be chargeable if agreed first.
6. Personal-data incidents
Stem will notify the Customer without undue delay after confirming a personal-data breach affecting Customer Personal Data and will provide available information about the nature, likely consequences, affected data and mitigation. The Customer remains responsible for notifications it must make as controller.
7. Return and deletion
During the service, the Customer may use available export features. On verified termination or deletion instruction, Stem will delete or return Customer Personal Data within a reasonable period, subject to protected backup rotation and records that law requires Stem to retain. Retained data remains protected and is used only for the required purpose.
8. Processing details
Subject: providing the contracted business software and support. Duration: the account term plus deletion, backup and lawful-retention periods. People: the Customer’s staff, customers, suppliers, contacts and any other people lawfully recorded.
Data: identity/contact, roles, activity/audit, sales/returns, products, credit/loyalty, invoices, delivery details, payment method/reference/status and supplier/staff business data. Sensitive data is not authorised by default.
9. Priority and law
This DPA takes priority over inconsistent User Agreement terms only for processing Customer Personal Data. It is governed by the governing-law clause in the User Agreement, while preserving mandatory data-protection rights and regulator powers.
Operator and contact
Stem Business OS, including Stem POS and Stem Invoicing, is operated by Stem Technologies Uganda. Our address for service is Kampala, Uganda.
Call +256 706 370617, message us on WhatsApp, or use our contact form.