Our commitment
STU is built to help your organisation meet its obligations under the UK GDPR and the EU GDPR: a single accurate source of truth, granular access control, audit trails, and data that stays in the region you choose.
Controller & processor
For the people data your organisation stores in STU, you are the controller and we are your processor: we act only on your documented instructions. For data you give us directly through this website, we are the controller, as described in our privacy policy.
Data processing agreement
Every customer contract includes our data processing agreement, which covers the subject matter and duration of processing, the types of personal data involved, our confidentiality and security obligations, and our duties to assist you with data subject requests and impact assessments. A signable copy is available from privacy@stu.solutions.
Data subject rights
The platform is designed so you can answer rights requests quickly:
- Access & portability: export a person's complete record in machine-readable form.
- Rectification: every field is editable, with an audit trail of what changed and when.
- Erasure: delete a person's record, with certified deletion from live systems within 30 days.
- Restriction & objection: access controls let you freeze or limit processing per record.
Sub-processors
We use a short list of vetted sub-processors for hosting, email delivery, and support tooling, all bound by GDPR-equivalent contractual terms. Customers receive the current list with their data processing agreement and at least 30 days' notice before any addition, with the right to object.
International transfers
Customer data is hosted in the EU or the UK, at your choice. Where any supporting service involves a transfer outside those regions, it is protected by UK and EU approved safeguards such as adequacy decisions or standard contractual clauses.
If something goes wrong
We maintain a tested incident response process. If a personal data breach affects your data, we will notify you without undue delay and in time for you to meet your own 72-hour obligations, with the facts you need: what happened, what data was involved, and what we are doing about it.
Contact
Our data protection lead can be reached at dpo@stu.solutions for anything GDPR-related: DPA requests, sub-processor questions, or help with a data subject request.