Data Processing Addendum
Effective October 5, 2026. This addendum is part of the Terms of Service between Inversion Systems, LLC and each business customer of Stage 1. It applies when we process personal data on the customer's behalf. Need a signed copy? Email hello@getstage1.com.
1. Roles
The customer is the controller, or a business under the CCPA, of the personal data in its workspace ("Customer Personal Data"). Inversion Systems is the processor, or service provider. Each party will meet its obligations under data protection laws that apply to it, including the GDPR, the UK GDPR and the CCPA as amended by the CPRA.
2. What we process
Subject matter and purpose: providing Stage 1, which finds buying signals, researches accounts and contacts, drafts messages, and sends approved messages through accounts the customer connects. Duration: the term of the agreement and the deletion period in section 9. Types of data: names, job titles, employers, business contact details, professional profile and public activity information, message content and reply history. Data subjects: the customer's users, and the prospects and contacts the customer chooses to research or contact. We don't intend to process special categories of data, and the customer agrees not to put them into Stage 1.
3. Instructions
We process Customer Personal Data only on the customer's documented instructions. The agreement, the customer's settings and its use of the service are those instructions. We'll tell the customer if we believe an instruction breaks data protection law. Under the CCPA, we won't sell or share Customer Personal Data, keep or use it outside our direct business relationship with the customer, or combine it with data from other sources except as the CCPA allows for providing the service.
4. Confidentiality and security
Everyone with access to Customer Personal Data is bound by confidentiality. We maintain technical and organizational measures appropriate to the risk, including encryption in transit, encryption at rest for connection credentials with AES-256-GCM, password hashing with scrypt, hashed session tokens, logical separation of each customer's data, least-privilege access and regular backups. The security page describes them.
5. Subprocessors
The customer authorizes the subprocessors below. We'll give at least 30 days' notice of a new subprocessor by updating this page and emailing customers who ask to be told. The customer may object on reasonable data protection grounds, and if we can't resolve it, may end the affected service and receive a refund of prepaid fees for it. We hold each subprocessor to data protection terms at least as protective as these and remain responsible for its work.
| Subprocessor | What it does | Location |
|---|---|---|
| Render Services, Inc. | Hosting for the application and database | United States |
| Anthropic, PBC | AI models that read sources and draft messages | United States |
| Unipile SAS | Connection to the customer's LinkedIn and email accounts | European Union |
| Resend, Inc. | Account emails such as password resets | United States |
| Stripe, Inc. | Payment processing | United States |
Integrations the customer turns on, such as HubSpot and Slack, are the customer's own vendors and act on its instructions, not as our subprocessors.
6. Data subject requests
Taking into account the nature of the processing, we'll help the customer respond to requests from data subjects to exercise their rights. If we receive a request directly, we'll pass it to the customer and won't respond ourselves unless the customer tells us to or the law requires it. Stage 1's opt-out list lets the customer stop all contact with a person or a whole company domain.
7. Personal data breaches
We'll notify the customer without undue delay, and within 72 hours, after becoming aware of a breach affecting Customer Personal Data. We'll share what we know about its nature, likely consequences and the measures taken, and update the customer as we learn more.
8. Assistance and audits
We'll give the customer reasonable help with data protection impact assessments and consultations with regulators where the processing requires them. We'll make available the information reasonably needed to show compliance with this addendum, and allow audits by the customer or an independent auditor it appoints, no more than once a year, on 30 days' notice, during business hours and under confidentiality, at the customer's cost.
9. Return and deletion
When the agreement ends, the customer may request an export of Customer Personal Data within 30 days. We then delete it within 60 days, except where the law requires us to keep it. Backups are overwritten on their normal schedule and stay protected under this addendum until then.
10. International transfers
Where Customer Personal Data from the European Economic Area, the UK or Switzerland is transferred to a country without an adequacy decision, the parties agree to the European Commission's Standard Contractual Clauses (Module Two, controller to processor, or Module Three, processor to processor, as applicable), with the UK International Data Transfer Addendum for UK data. Those clauses are incorporated by reference, with Ireland's law and courts chosen where the clauses require a choice, and the details in section 2 and the measures in section 4 completing their annexes.
11. Order of precedence
If this addendum conflicts with the Terms of Service on the processing of Customer Personal Data, this addendum controls. If it conflicts with the Standard Contractual Clauses, the clauses control.