StableState
STABLESTATE
← Back to portal

Data Processing Agreement

Last updated: April 12, 2026Version 1.0StableState LLC

1. Parties & Scope

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Data Controller", "Client") and StableState LLC ("Data Processor", "StableState") for the IronFist AI platform at https://www.ironfistai.com.

This DPA applies to all personal data processed by StableState on your behalf through the Platform.

2. Roles

Data Controller: You (the subscriber). You determine the purposes and means of processing personal data through your agent.

Data Processor: StableState. We process personal data solely on your instructions, as implemented through your agent's configuration, tools, and procedures.

3. Processing Details

Categories of data: Any personal data you or your agent processes through the Platform, which may include contact information, business communications, calendar entries, document contents, and any other data your agent interacts with via configured integrations.

Purpose: To operate and maintain your autonomous AI agent as configured by you.

Duration: For the duration of your subscription, plus the 30-day post-cancellation retention period.

Data residency: Azure East US region.

4. Security Measures

StableState implements the following technical and organizational measures: dedicated Azure resource group per tenant (complete infrastructure isolation), Azure Key Vault with FIPS 140-2 Level 2 HSMs for credential storage, managed identity with RBAC scoped to tenant resources only, encryption at rest (AES-256) and in transit (TLS 1.2+), write-protected audit logs with tier-based retention (90/180/365 days), 3-layer infrastructure circuit breaker, daily automated backups under tenant-scoped identity, and financial domain blocklist for browser automation.

5. Sub-Processors

StableState engages the following sub-processors:

Browserbase is not a StableState sub-processor. It is a client-direct relationship where you provide your own Browserbase API key. You are responsible for your own Browserbase terms compliance.

StableState will notify you before engaging any new sub-processor, providing 30 days to object.

6. International Data Transfers

All data is processed and stored in the United States (Azure East US). If you are located outside the US, your use of the Platform constitutes consent to the transfer of data to the US. For EU/EEA clients, the GDPR Addendum (Section 10) provides additional safeguards.

7. Data Subject Rights

StableState will assist you in responding to data subject requests (access, rectification, erasure, portability, restriction, objection) to the extent technically feasible. You may export your agent data at any time via the dashboard. Contact [email protected] for assistance with data subject requests.

8. Data Breach Notification

StableState will notify you of any confirmed data breach affecting your data without undue delay and in any event within 72 hours of becoming aware. Notification will include the nature of the breach, categories and approximate number of records affected, likely consequences, and measures taken or proposed to address the breach.

9. Data Deletion

Upon termination of your subscription: 30-day retention window for data export, followed by permanent deletion of your Azure resource group and all data. Deletion is completed within 30 days of the retention window expiry. Upon request, StableState will provide written confirmation of deletion.

10. GDPR Addendum

This section applies only to subscribers who selected EU/EEA as their jurisdiction during onboarding.

StableState processes personal data in accordance with Article 28 of the GDPR. Processing is conducted solely on documented instructions from the Controller. StableState ensures that persons authorized to process personal data have committed to confidentiality. StableState implements appropriate technical and organizational measures as described in Section 4. StableState assists the Controller with data protection impact assessments where required. StableState makes available all information necessary to demonstrate compliance and allows for audits. Upon termination, StableState deletes all personal data as described in Section 9.

For the purposes of international transfers, StableState relies on Standard Contractual Clauses (SCCs) as approved by the European Commission. Contact [email protected] to request a copy of the executed SCCs.

Questions about this document?

Contact us at contact@stablestateit.com

Visit https://www.stablestateit.com for general inquiries and our contact form.

Powered by StableState  |  stablestateit.com  |  ironfistai.com
Patent pending - US Application 19/638,025