> For the complete documentation index, see [llms.txt](https://docs.stacksync.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.stacksync.com/security-and-other-resources/security/stacksync-dora-addendum.md).

# Stacksync DORA Addendum

Digital Operational Resilience Act (DORA) Addendum for subject Customers Using Stacksync ICT Services.

Updated September 7th, 2026.

This Digital Operational Resilience Act Addendum ("DORA Addendum") supplements and forms part of the agreement governing the Customer's use of the Stacksync services, including any applicable order form, service consumption table, terms and conditions, data processing addendum, and service level agreement (collectively, the "Agreement").

This DORA Addendum applies where the Customer is subject to Regulation (EU) 2022/2554 on digital operational resilience for the financial sector ("DORA") and uses Stacksync as an ICT third-party service provider within the meaning of DORA.

This DORA Addendum applies only to customers that have notified Stacksync in writing that they are subject to DORA and that have entered into a contractual commitment with Stacksync for a minimum term of twelve (12) months. These conditions are necessary to enable Stacksync to meet its obligations under this DORA Addendum.

Where there is a conflict between this DORA Addendum and another provision of the Agreement, this DORA Addendum will prevail solely to the extent necessary to address the applicable requirements of DORA.

Nothing in this DORA Addendum represents that Stacksync has been designated as a critical ICT third-party service provider pursuant to Article 31 of DORA.

### 1. Definitions

**"Customer"** means the entity identified in the applicable Agreement.

**"Stacksync"** means the Stacksync contracting entity identified in the applicable Agreement.

**"ICT Services"** means the services provided by Stacksync to Customer that constitute ICT services for purposes of DORA.

**"Critical or Important Function"** has the meaning given to that term under DORA.

**"ICT Incident"** means an ICT-related incident affecting the ICT Services within the meaning of DORA.

Capitalized terms not otherwise defined in this DORA Addendum have the meanings given to them in the Agreement or DORA.

Customer will inform Stacksync if Customer determines that any ICT Services support a Critical or Important Function so that the additional requirements applicable to such services can be implemented.

### 2. Description of ICT Services

The functions and ICT Services provided by Stacksync are described in the applicable Order form, Service Consumption Table, product documentation, and other applicable portions of the Agreement.

Depending on Customer's configuration, the ICT Services may include data synchronization, workflow automation, API integration, data processing, connector services, and associated monitoring and support services.

Customer controls the systems connected to Stacksync and the configuration of the relevant synchronization, workflow, or integration.

### 3. Security and Protection of Data

Stacksync will maintain technical and organizational measures designed to protect the **availability, authenticity, integrity and confidentiality** of data processed in connection with the ICT Services.

Stacksync's security controls, including encryption, access control, infrastructure security, monitoring, data retention, secure connectivity, and data residency measures, are described in the Stacksync Security Overview, Security Whitepaper, and Data Processing Addendum.

Stacksync maintains an information security management and assurance program supported by independent security assessments and certifications, including ISO 27001 and SOC 2 Type II.

Stacksync will maintain security measures appropriate to the nature of the ICT Services and the risks associated with their provision.

The current documentation supports these commitments, including TLS 1.2+, AES encryption, hardened IAM, least-privilege access, monitoring, audit logging, vulnerability management, penetration testing and regional processing.

### 4. Processing Locations and Data Residency

Customer may select the available processing region applicable to its Stacksync environment as described in the Stacksync Security Overview. When a Customer selects a processing region, their data is exclusively processed within that processing region. There is no cross-processing between regions, each region is completely self-contained.

Stacksync will process Customer Data in accordance with the processing region selected by Customer, subject to the Agreement and the documented exceptions applicable to the ICT Services.

The locations of Stacksync subprocessors and subcontractors involved in providing the ICT Services are described in Stacksync's Subprocessors documentation or otherwise made available to Customer.

Stacksync will provide Customer with information reasonably necessary to identify the countries or regions in which contracted or subcontracted ICT Services are provided and Customer Data is processed or stored.

Stacksync will notify Customer in advance of a material change to a location applicable to the ICT Services where required by DORA.

Stacksync's current documentation already provides customer-selected regional processing and states that, for example, data configured for EU processing remains within the EU during processing and storage.

### 5. Data Access, Recovery, Return and Deletion

Stacksync generally processes business data transiently as part of synchronization and workflow operations. Applicable retention exceptions, including temporary processing queues, synchronization errors, hashed record fingerprints, credentials and configuration metadata, are described in the Stacksync Security Overview.

To the extent Customer Data remains in Stacksync's possession or control, Stacksync will, upon termination or expiration of the applicable ICT Services, make such Customer Data available for return in a commonly accessible format or delete it in accordance with the Agreement and the Data Processing Addendum.

These obligations also apply, where relevant, in connection with Stacksync's insolvency, resolution, discontinuation of the applicable ICT Services, or termination of the contractual arrangement.

Stacksync's DPA already requires return or destruction of Personal Data following Customer request or termination, subject to limited legal and backup exceptions.

### 6. Service Levels and Monitoring

The service levels applicable to Customer are set out in the applicable Order form, service level agreement, or other applicable portion of the Agreement.

Stacksync will maintain appropriate monitoring of the ICT Services and will make relevant service status information available to Customer.

Customer can publicly access Stacksync product's status at the following page: <https://status.stacksync.com/> as well as contacting Stacksync via the [contact page](https://www.stacksync.com/contact).

Where ICT Services support a Critical or Important Function, applicable service levels will include quantitative or qualitative performance targets sufficient for Customer to monitor the ICT Services and identify failures to meet agreed service levels.

Stacksync will take appropriate corrective action without undue delay where agreed service levels are not met.

### 7. ICT Incidents and Customer Assistance

Stacksync will maintain processes designed to detect, manage, investigate and respond to ICT Incidents affecting the ICT Services.

Stacksync will notify Customer without undue delay after becoming aware of an ICT Incident or other development that has a material impact on Stacksync's ability to provide the applicable ICT Services in accordance with agreed service levels.

Stacksync will provide Customer with information reasonably available to Stacksync and reasonably necessary for Customer to assess the incident and satisfy applicable regulatory reporting obligations.

Stacksync will provide reasonable assistance in connection with an ICT Incident related to the ICT Services.

Standard incident-response assistance is provided without additional charge. If Customer requests extraordinary professional services beyond Stacksync's standard incident-response obligations, any additional charges must be agreed by Customer in advance.

Stacksync's existing DPA already requires notification without undue delay of qualifying personal-data breaches and ongoing cooperation regarding remediation and reporting. This DORA provision intentionally expands that concept to material **ICT incidents**, not only personal-data breaches.

### 8. Business Continuity and Operational Resilience

Stacksync will maintain appropriate business continuity, disaster recovery and ICT response and recovery measures proportionate to the ICT Services and associated risks.

Stacksync will periodically test relevant contingency and recovery measures and maintain appropriate ICT security measures, tools and policies designed to support the secure and resilient provision of the ICT Services.

For ICT Services supporting Critical or Important Functions, Stacksync will provide reasonable information regarding such measures and testing upon Customer's request, subject to appropriate confidentiality and security restrictions.

### 9. Regulatory Cooperation

Stacksync will cooperate with competent authorities, resolution authorities and persons appointed by such authorities to the extent required under DORA in connection with Customer's use of the ICT Services.

Stacksync will provide reasonable information and assistance necessary to permit Customer to comply with lawful supervisory requirements relating to the ICT Services.

Nothing in the Agreement will be interpreted to prevent the effective supervision of Customer by its competent authorities.

### 10. Audit, Access and Inspection Rights

For ICT Services supporting a Critical or Important Function, Stacksync will grant Customer, an auditor appointed by Customer, and the applicable competent or resolution authorities the rights of access, inspection and audit required under DORA.

Such rights include access to relevant information, systems, premises, policies, procedures and documentation relating to the ICT Services, as applicable, and the right to take copies of relevant documentation where required by DORA.

Stacksync will fully cooperate with inspections and audits conducted pursuant to DORA.

Where independent third-party assurance reports, certifications, SOC reports, ISO certifications, penetration-testing reports or equivalent evidence provide sufficient assurance, the parties may agree to use such evidence as an alternative assurance mechanism. Such alternative assurance mechanisms will not prevent Customer or a competent authority from exercising audit, inspection or access rights where those rights must be exercised under DORA.

Audits and inspections will be coordinated in a manner designed to protect the confidentiality and security of Stacksync's systems and other customers' information, provided that such measures do not prevent or materially impede the effective exercise of rights required under DORA.

### 11. Threat-Led Penetration Testing

Where Customer is required under DORA to conduct threat-led penetration testing ("TLPT") involving ICT Services provided by Stacksync, Stacksync will participate and cooperate as reasonably required under Articles 26, 27 and 30 of DORA.

The parties will coordinate the scope, timing, security safeguards and operational requirements applicable to such testing so that the exercise does not unnecessarily create risks to Stacksync, Customer or other Stacksync customers.

### 12. ICT Security Awareness and Training

Where reasonably appropriate to the ICT Services and Customer's obligations under DORA, Stacksync will make relevant personnel available to participate in Customer's ICT security awareness or digital operational resilience training relating specifically to the ICT Services.

Such participation will be reasonably scoped and scheduled between the parties.

### 13. Subcontractors

Customer authorizes Stacksync to use subprocessors and subcontractors in connection with the ICT Services subject to this Addendum and the Agreement.

Stacksync's current subprocessors are identified in its Subprocessors documentation.

Stacksync remains responsible for performance of its contractual obligations where elements of the ICT Services are provided through subcontractors.

Where a subcontractor provides ICT Services supporting a Critical or Important Function or a material part thereof, Stacksync will, as applicable:

1. monitor the subcontracted services and the subcontractor's performance;
2. conduct appropriate due diligence and risk assessment regarding relevant subcontractors;
3. assess relevant risks associated with the subcontractor's location and the location from which ICT Services are provided;
4. maintain information regarding applicable data processing and storage locations;
5. require appropriate information security, monitoring, reporting and business-continuity obligations;
6. take reasonable measures to preserve continuity of the ICT Services throughout the subcontracting chain;
7. maintain appropriate oversight over material subcontracting arrangements;
8. ensure that applicable regulatory cooperation and audit requirements are addressed throughout the relevant subcontracting chain as required by DORA; and
9. remain accountable to Customer for the contracted ICT Services.

These requirements reflect the additional subcontracting rules now contained in Commission Delegated Regulation (EU) 2025/532.

### 14. Material Changes to Subcontracting

For subcontracting arrangements supporting a Critical or Important Function or a material part thereof, Stacksync will provide Customer with reasonable advance notice of a proposed material change.

Unless otherwise agreed with Customer, Stacksync will provide at least **30 days' prior notice** before implementing such a material change.

Customer may object during the notice period on reasonable grounds related to its obligations or risk tolerance under DORA.

Stacksync will reasonably cooperate with Customer to address such concerns before implementing the material change.

Where Customer objects and the parties cannot reasonably resolve the matter, Customer may exercise any termination rights required under DORA or Commission Delegated Regulation (EU) 2025/532.

### 15. Termination Rights

In addition to termination rights otherwise available under the Agreement, Customer may terminate the affected ICT Services where required under Article 28(7) of DORA, including where:

1. Stacksync materially breaches applicable laws, regulations or contractual obligations relevant to the ICT Services;
2. circumstances arise that materially impair Stacksync's ability to perform the contracted ICT Services;
3. material weaknesses in Stacksync's ICT risk management create an unacceptable risk to the availability, authenticity, integrity or confidentiality of Customer Data; or
4. circumstances relating to the contractual arrangement prevent Customer's competent authority from effectively supervising Customer.

For ICT Services supporting Critical or Important Functions, Customer will also have applicable termination rights arising from material subcontracting changes under Commission Delegated Regulation (EU) 2025/532.

### 16. Exit and Transition Assistance

For ICT Services supporting a Critical or Important Function, Stacksync will reasonably cooperate with Customer's documented exit strategy.

Following termination, Stacksync will provide an adequate transition period appropriate to the nature and complexity of the ICT Services to allow Customer to migrate to another provider or an internal solution while reducing avoidable disruption.

During an agreed transition period, Stacksync will continue to provide the applicable ICT Services subject to Customer's continued compliance with its payment and other applicable contractual obligations.

Stacksync will reasonably assist Customer with the recovery, export, return or deletion of Customer Data and with other information reasonably required to transition the affected ICT Services.

Any transition services materially beyond the normal scope of the ICT Services will be subject to fees agreed by the parties in advance.

### 17. DORA Register of Information

Upon reasonable request, Stacksync will provide information in its possession that Customer reasonably requires to maintain its register of information concerning ICT third-party contractual arrangements under DORA.

Such information may include, as applicable:

* Stacksync contracting entity information;
* description of the ICT Services;
* applicable processing and service locations;
* applicable subcontractors;
* data-processing arrangements;
* service-level information; and
* other information reasonably required under applicable DORA reporting templates.

### 18. Regulatory Changes

The parties will cooperate in good faith to amend this DORA Addendum where reasonably necessary to address material changes in DORA, applicable regulatory technical standards, implementing technical standards, binding supervisory requirements, or other applicable requirements concerning the ICT Services.

### 19. Continued Responsibility of Customer

Customer remains responsible for determining the regulatory classification and criticality of its functions and for satisfying obligations imposed directly upon Customer under DORA.

Stacksync's obligations under this DORA Addendum are intended to support Customer's compliance as an ICT third-party service provider and do not transfer Customer's regulatory responsibilities to Stacksync.
