Last updated · 2026-09-23

Data processing terms

You are the controller of the personal data of your leads and customers. Stelafy processes that data only on your instructions and only for measurement. This page shows in advance what the data processing addendum contains.

Roles

  • You: controller of the lead, outcome and payment data you bring in. Collection, notices and lawful basis are your responsibility.
  • Stelafy: processor of that data, within your instructions and your configuration.
  • For the data of your own account users — name, email address, sign-in records — Stelafy is the controller.

Laws this addendum covers

This addendum applies to processing under the EU GDPR, the UK GDPR, Swiss data protection law and US state privacy laws, including the California Consumer Privacy Act as amended by the CPRA.

Under US state privacy laws we act as your service provider. We do not sell or share the personal information, we do not keep, use or disclose it for any purpose other than providing the service to you, and we do not combine it with personal information from other sources except as those laws permit.

Subject matter and duration

Processing exists to connect ad spend to applications and to money actually collected, and continues for the term of the service agreement. When the agreement ends, processing stops.

Categories of data

  • Lead and application data: name, phone number, email address, the platform's lead id and form id, and the submission time.
  • Form answers: for Meta Instant Form leads, the answers to the questions you added to the form. Contact fields and Meta's standard personal fields (date of birth, gender, marital status, identity numbers, work contact details, street address) are not stored; answers to questions that point to special categories of data are dropped before storage.
  • Outcome data: qualification decisions, opportunity stages, amounts, currency and the dates those things happened.
  • Web visit context, where your site uses the lead-touch script and the visitor consented: an anonymous visit key, utm_* parameters, the Meta click id in fbc form, your own pixel's _fbp value, the browser user agent, the visitor's IP address as your server reports it, and the page address without its query string.
  • Ad data: campaign, ad set and ad names, spend and dates. Contains no personal data.
  • Data subjects: the people who respond to your ads or forms, and the customers who pay you.

What is never processed

Treatment names, diagnoses, health status, insurance details and similar special categories of personal data are not processed. Matching runs on phone number and email address only.

You must not collect such data through the forms you connect. The service's check that drops such answers is a safety net, not a guarantee; data you collect in breach of this remains your responsibility.

A treatment column in your file is not mapped, not read and not stored; the row is still accepted.

Biometric data, national identity numbers, and card or bank details are also out of scope.

Transfers to ad platforms

For a clinic workspace there is no transfer at all. The Meta connection is read-only and the sending path is refused on the server, including through a direct API call, a CSV import, a scheduled job or a retry.

For a general lead-generation workspace, an owner or admin may turn on sending selected outcome events to the business's own Meta dataset, using the business's own token. Email addresses and phone numbers are hashed with SHA-256 before they leave the server; the country the phone number belongs to and the product's internal id for the person are hashed the same way; the Meta lead id and, for website leads, the browser identifiers are sent as the platform requires them; where an event represents money, its amount and currency are sent. Names, files, form answers and free text are never sent.

No custom or lookalike audience is built, no customer list is uploaded, and no ad, ad set, campaign or budget is created or changed. The product contains no code that can do those things.

Security measures

  • Each workspace's rows are isolated in the database itself; one business cannot query another's data even through a direct API call.
  • Ad platform access tokens are encrypted before storage and are never returned by any endpoint.
  • Access is limited to the users you invite, roles are enforced in the database, and changes are recorded in an audit log.
  • Data is encrypted in transit.
  • Everyone who can access the data on our side is bound by a duty of confidentiality.

Subprocessors

Each subprocessor is bound by a written agreement that protects personal data at least as well as this addendum, and we remain responsible to you for its work.

You are told at least 30 days before a new subprocessor is added. You may object; if the objection cannot be resolved, you may end the agreement.

Where a subprocessor processes personal data outside the EEA or the UK, the transfer relies on the Standard Contractual Clauses and, for the UK, the UK Addendum.

  • Supabase — Database, authentication and file storage (EU (Frankfurt)).
  • Vercel — Application hosting; the server code runs here (EU (Frankfurt)).
  • GitHub — Nightly database backup: taken on GitHub's servers, encrypted there before it is stored, and kept for 30 days (US).
  • Meta Platforms — Reading your ad data; and, only if your workspace turns it on, sending outcome events to your own Meta dataset (US / EU).

Data subject requests

Access, correction and deletion requests from the people in your data go to you first, because you are the controller. We provide the technical support needed to answer them, and if a request reaches us directly we route it to you.

Breach notification

If a personal data breach is identified you are informed without undue delay and, where feasible, within 72 hours of us becoming aware of it. The notification states the nature of the breach, the categories and approximate number of people and records affected, its likely consequences, and the measures taken or proposed.

Information and audits

On request we provide the information needed to show that this addendum is being followed. An independent audit can be agreed in writing, at reasonable notice and scope.

End of the agreement

When the agreement ends your data is deleted; a deletion request is completed within 30 days, and copies inside encrypted backups leave the rotation within the same period. Queued outcome events are discarded rather than sent. If you need a copy of your data handed over first, agree it in writing before termination — the product has no self-service export. Where the law requires us to keep a copy, it is not processed for anything else and is deleted when the requirement ends.

Precedence and changes

Where this addendum and the terms of service conflict about personal data, this addendum prevails. If we change this addendum materially, we tell you by email at least 30 days before the change takes effect.

Contact

Please contact the business that gave you access to this service for a signed copy of the data processing addendum.