Data processing terms
Last updated: 2 October 2026
These terms apply between STRATIVA (the processor) and each customer company (the controller) for personal data processed in the STRATIVA service.
1. Roles and instructions
The customer decides which personal data is entered into STRATIVA and for which purposes. STRATIVA processes it only to provide the service and on the customer's documented instructions (the use of the service and its settings are such instructions).
2. Confidentiality
Everyone at STRATIVA with access to customer data is bound by confidentiality. Access is limited to what is needed for support and operations, and is logged.
3. Security measures
Separation of every customer's data in the database, enforced by the database itself and tested automatically.
Two-factor sign-in (required for owners and admins by default), sign-out after inactivity, sign-in history and alerts about new devices.
Encryption in transit (HTTPS with HSTS) and encrypted storage of connection secrets; strict browser security headers.
An audit trail of changes; backups by the database provider.
4. Sub-processors
Supabase Inc. — database and authentication (Singapore region).
Vercel Inc. — application hosting.
Google LLC — Gemini AI, only when the customer switches Ask STRATIVA on.
Faktura.uz — e-invoicing in Uzbekistan, only when the customer switches it on.
Resend — sending emails.
STRATIVA informs customers before adding or replacing a sub-processor, so they can object.
5. Personal data breaches
STRATIVA informs the customer without undue delay after becoming aware of a breach affecting its data, with the information it has, and helps the customer meet its own notification duties.
6. Helping the customer
STRATIVA helps the customer answer requests from people about their data (access, correction, export, deletion), for example with the data export and the person's data export in the service.
7. End of the service
The customer can export all its data at any time. On a deletion request, all customer data is deleted 30 days later (the customer can cancel within that time); a short record that the deletion took place is kept, without customer data.
8. International transfers and local rules
Data is stored in Singapore. Transfers follow the safeguards required by the applicable law.
[For the lawyer: check the data localization requirements of Uzbekistan (Law No. ZRU-547, article 27¹), Russia and other target markets, and the Saudi and UAE personal data laws, Morocco Law 09-08, Egypt Law 151/2020 and the GDPR for EU customers.]
9. Audits
On request, STRATIVA provides the information needed to show that these terms are followed. [Audit terms to be completed by the lawyer.]