Final Stage · Legal

Data Processing Addendum

Last updated 14 August 2026

This addendum forms part of the Terms of Service and applies whenever Final Stage handles personal data belonging to your customers — the people who book, enquire or buy through the site we host for you.

1. Which of us is responsible for what

For your customers' data, you are the controller and we are the processor. You decide what is collected and why; we only act on your instructions. Using the service is the instruction — building a booking form tells us to store bookings.

For your own account and billing data we are the controller, and the Privacy Policy governs it. That distinction is not decoration: the two sets of data are treated differently throughout.

2. What we process, and why

CategoryPurpose
Bookings — name, email, phone, notesRunning the booking feature you enabled
Enquiries and contact messagesDelivering them to you and storing them in your dashboard
Intake and quote submissions, including typed signaturesStoring what was submitted and signed, with the form version
Store orders and customer detailsFulfilling orders placed through your site
Contacts you add or importYour customer list
Uploaded images and filesPublishing them on your site or delivering them to buyers

We process this data for the duration of your account and do not use it for our own purposes. We do not sell it, we do not market to your customers, and we do not use it to train any AI model.

3. Subprocessors

We use the following, and only these. We will tell you before adding another.

SubprocessorRole
CloudflareHosting, database, file storage, and the AI features
StripePayments and subscriptions
ResendSending transactional email
GoogleFonts on our pages; and, if you connect them, sign-in and Drive galleries
GitHubStoring the generated code for your site so it can be deployed and rebuilt
VirusTotalMalware scanning of files uploaded as paid digital deliverables

4. Security

Passwords are stored using PBKDF2 hashing. Sessions use signed, HttpOnly, Secure cookies. Connected third-party credentials are encrypted at rest. Every database query for a site is scoped to that site, so one customer's data cannot be read through another's account. Uploaded files are checked by content rather than by the name or type the browser claims.

5. Your customers' requests

If one of your customers asks you for access to, correction of, or deletion of their data, you can usually do it yourself from your dashboard. Where you cannot, email us and we will help within a reasonable period. If such a request reaches us directly we will point them to you, because it is your relationship, not ours.

6. Breaches

If we become aware of a breach affecting personal data we process for you, we will tell you without undue delay, with what we know and what we are doing about it. We will not decide on your behalf whether you need to notify anyone.

7. Deletion and return

Deleting a project purges its data — bookings, enquiries, form submissions, orders and uploaded files — from our database and file storage. Deleting your account does the same for every project on it. Export anything you want to keep first.

Two honest caveats, the same ones in the Privacy Policy: backups and point-in-time database history exist so we can recover from a failure, and deleted data can persist there for a limited period before ageing out. Billing records are retained where we are required to keep them.

8. Location

Data is stored on Cloudflare's infrastructure, which is distributed. Where a transfer out of your region requires a legal mechanism, the relevant subprocessor's standard contractual clauses apply — each of the companies above publishes its own.

9. Contact

Questions about this addendum, or to request a signed copy: [email protected].