Design Studio

StoneSwap Studio — Privacy Policy (Business Customers) and Schedule A (Data Processing Terms)

Version 2026-09-25 · Effective 2026-09-25Print or save as PDFTerms of Service (Brands, Dealers & Contractors)

Version 2026-09-25 · Effective: 2026-09-25

This Privacy Policy explains how StoneSwap Inc. collects, uses, discloses and protects Personal Information about the people who work for our business customers, prospects and partners, and how we act as a service provider for the End Users of our customers' Studios. Schedule A (Data Processing Terms), at the end of this document, sets out our obligations as a processor and forms part of the StoneSwap Studio Terms of Service. Capitalised words that are not defined here have the meanings given in the Terms of Service.

1. Who we are

StoneSwap Inc. (formerly 17524218 Canada Inc.) is a corporation incorporated under the laws of Canada, with its office at 21 King St W, Suite 6, Hamilton, Ontario L8P 4W7, Canada (GST/HST 71855 1765 RT0001). We operate StoneSwap Studio, a white-label AI landscape-design visualizer for hardscape manufacturers, dealers, suppliers and contractors, and StoneSwap.ai, our own visualizer for consumers and contractors.

Our Privacy Officer, who is responsible for our compliance with privacy law and is the person to contact with any privacy question or request, is:

Matthew Stubbs, Privacy Officer
StoneSwap Inc., 21 King St W, Suite 6, Hamilton, ON L8P 4W7, Canada
[email protected]

2. Scope of this Policy

2.1 Who this Policy covers

This Policy covers Personal Information we collect and hold for our own purposes about:

2.2 End Users are covered by the Studio's own privacy page

Homeowners, contractors and other End Users of a Customer's Studio, Showroom Devices or integrations are the Customer's users. Their Personal Information is Tenant Data: the Customer decides why and how it is collected, and we process it only on the Customer's instructions as its service provider (Schedule A). Each Studio has its own privacy page, which we host on the Customer's behalf and on which we are named as the Customer's service provider and privacy contact where the law requires. End Users should read that page. If an End User contacts us directly, we will forward the request to the Customer as Schedule A describes.

2.3 StoneSwap.ai and consumer purchases

Personal Information collected on StoneSwap.ai, and the payment and receipt records of consumer credit packs that we sell to End Users as merchant of record, are governed by the privacy policy published on StoneSwap.ai, not by this Policy.

3. Personal Information we collect

3.1 Portal account and legal acceptance data

Name, business e-mail address, job title, telephone number, company name and address, role and permissions in the Portal, password (stored only as a bcrypt hash), sign-in tokens (stored only as SHA-256 hashes), Google sign-in identity if the user chooses it, language and notification preferences, and, for each acceptance of our legal documents, the accepting person's name, title, e-mail address, IP address, date and time, and the version accepted.

3.2 Billing data

Billing contact name and e-mail, billing address, tax registration numbers, Plan and purchase history, invoices, statements, payment status, bank-transfer references, and the payment-method details that Stripe returns to us (card brand, last four digits, expiry month and year, and a Stripe token). We never receive or store full card numbers or security codes; they are entered on Stripe-hosted fields and held by Stripe.

3.3 Audit logs

Every action in the Portal (settings changes, product changes, user changes, exports, legal acceptances) and every action our staff take on a Customer's account is logged with the acting person's identity, IP address, date and time, and a description of the action. Sign-in attempts, API key use and webhook deliveries are also logged with IP addresses and timestamps.

3.4 Support and other communications

The contents of support tickets, e-mails, chat messages, meeting notes, proposals, feedback and any attachments you send us, together with the metadata of those communications.

3.5 Usage and technical data

Pages and features used in the Portal, timestamps, browser type and version, operating system, device identifiers, screen size, referring pages, IP address and approximate location derived from it, error reports and performance data. Our aggregate render statistics (counts, timings, blocked-attempt counts) are computed from anonymous daily counters and are not Personal Information.

3.6 Prospect data

Name, company, role, business contact details, the information entered in the sign-up wizard or a contact form, the products and plans of interest, notes of our conversations, and publicly available business information about the prospect's company and products that we use to prepare proposals and demonstrations.

3.7 Information we do not collect

We do not ask for government identifiers, health information, financial account numbers (other than the bank references you give us for a transfer) or biometric data, and we do not knowingly collect Personal Information from children.

4. Why we use Personal Information, and our legal basis

We collect, use and disclose Personal Information only for purposes that a reasonable person would consider appropriate in the circumstances, and with your consent (express or implied, as the law permits) or where the law otherwise allows or requires it. Our purposes are:

  1. Providing the Service and performing the Agreement: creating and administering accounts, authenticating users, providing the Portal, Studio, Showroom Device software, API and Network, delivering leads and notifications, and providing support. Basis: performance of the contract with the Customer and implied consent.
  2. Billing and collection: charging Fees, issuing invoices and receipts, recording payments, collecting overdue amounts and handling disputes. Basis: performance of the contract; legal obligations (tax and accounting records).
  3. Security, fraud prevention and auditability: keeping audit logs, detecting and investigating unauthorised access, abuse and fraud, verifying legal acceptances, and enforcing our Terms. Basis: our legitimate business purposes, our contractual commitments to Customers, and legal obligations.
  4. Legal compliance: complying with tax, accounting, anti-spam, privacy and other laws, responding to lawful requests from authorities, and establishing, exercising or defending legal claims.
  5. Communicating with you about the Service: transactional and operational messages, changes to our legal documents, security notices, and responses to your requests. These messages are part of the Service and cannot be opted out of while you have an account.
  6. Marketing to businesses: sending prospects and Customers information about StoneSwap Studio, new features, pricing and events, in accordance with CASL (express consent, or the implied consent that arises from an existing business relationship or a conspicuously published business address, and always with a working unsubscribe). You may withdraw consent at any time (section 9).
  7. Improving the Service: analysing how the Portal is used, diagnosing problems and planning improvements, using aggregated or de-identified data wherever possible.
  8. Business transactions: evaluating and completing a merger, acquisition, financing or sale of all or part of our business, under confidentiality.

We do not use Personal Information covered by this Policy for automated decisions that produce legal or similarly significant effects about you, and we do not use it to train AI models.

5. Sharing and Sub-processors

5.1 We do not sell Personal Information

We do not sell, rent or trade Personal Information, and we do not "share" it for cross-context behavioural advertising within the meaning of the CCPA.

5.2 Service providers (Sub-processors)

We disclose Personal Information to service providers that process it for us under contracts that restrict them to our purposes and require appropriate safeguards. As at the version date, they are:

Where we register a .studio domain for a Customer, the registrar (as at this version, Porkbun LLC, United States) holds StoneSwap's own registrant details, not the Customer's or its End Users' Personal Information; we list it here for transparency only.

5.3 Vendors the Customer enables

A Customer may connect its own vendors in the Portal, such as a CRM webhook (for example HubSpot), Microsoft Clarity, Google Analytics 4, Google Ads, Meta and TikTok pixels. Those vendors are appointed by the Customer, receive data on the Customer's instruction, and are governed by the Customer's own agreements and privacy notices; they are not our Sub-processors.

5.4 Other disclosures

We may disclose Personal Information: to our professional advisers, auditors, insurers and financing sources under confidentiality; to comply with law, a court order or a lawful request by a public authority (where legally permitted, we will notify the Customer before disclosing Tenant Data and disclose only what is required); to protect the rights, property or safety of StoneSwap, our Customers, End Users or the public; to enforce our agreements; and to a successor in a merger, acquisition, financing or sale of all or part of our business, under confidentiality and on the condition that the successor honours this Policy.

6. International transfers

We are located in Ontario, Canada. Our hosting, storage, AI processing, e-mail and payment providers are located in, or operate infrastructure in, the United States, and Cloudflare operates a global edge network through which traffic passes in transit. Personal Information covered by this Policy and Tenant Data are therefore stored and processed in Canada and the United States and may be subject to the laws of those countries, including lawful access by courts and public authorities there. We protect transferred information through the contractual, technical and organisational measures described in Schedule A, including encryption at rest and in transit and contractual restrictions on our Sub-processors.

For Customers subject to Quebec's Law 25, the communication of Personal Information outside Quebec (including to Ontario and the United States) must be assessed under section 17 of the Act. We maintain a section 17 transfer assessment support file describing the information transferred, the purposes, the protection measures and the legal framework of each destination, which we provide to Customers on request to support their own assessment, and Schedule A is the written agreement that section 17 contemplates.

7. Retention

We keep Personal Information only as long as needed for the purposes above and to meet our legal and contractual obligations, then delete or de-identify it. Our standard periods are:

Tenant Data is retained according to the Customer's own retention settings and Schedule A, not according to this section.

8. Security

We protect Personal Information with safeguards appropriate to its sensitivity, including: a dedicated database with its own credentials for each Customer, never commingled with another Customer's data; a control plane that holds only registry data and anonymous aggregates; AES-256 encryption at rest for End User Personal Information under a per-Customer key held outside the web root; bcrypt password hashing and SHA-256 hashing of all session, sign-in and API tokens; TLS on every connection; a cookieless bot-check at sign-up; velocity limits; least-privilege access for our staff, with every staff action logged; audit logging of every Portal change; encrypted backups; and a written incident-response plan reviewed every January and after every incident. No system is perfectly secure, and you are responsible for keeping your own credentials confidential and for telling us promptly if you suspect they have been compromised.

9. Your rights

9.1 Access and correction

You may ask what Personal Information we hold about you, how we use it, and to whom we have disclosed it, and ask us to correct information that is inaccurate or incomplete. Much of this can be done directly in the Portal (profile, users and billing pages). We will respond within 30 days of a written request, or tell you if we need more time and why, and may ask you to verify your identity first.

9.2 Deletion

You may ask us to delete your Personal Information. We will do so unless we must keep it to complete a transaction, to comply with a legal obligation (for example financial records), to evidence a legal acceptance, to establish or defend a claim, or for security and fraud prevention, in which case we will tell you what we are keeping and why.

9.3 Withdrawal of consent

You may withdraw consent at any time, subject to legal and contractual restrictions and reasonable notice. Every marketing e-mail we send contains a one-click unsubscribe that takes effect immediately. Withdrawing consent to processing that is necessary for the Service may mean we can no longer provide the Service to your organisation.

9.4 Portability (Quebec)

Where Law 25 applies, you may ask for computerised Personal Information we collected from you in a structured, commonly used technological format.

9.5 End Users

If you are an End User of a Customer's Studio, your requests are handled by that Customer using the Studio's self-service tools (download my data, account deletion, one-click unsubscribe) and its own processes; if you write to us, we will forward your request to the Customer without undue delay as Schedule A requires.

9.6 Complaints

If you are not satisfied with our response, you may complain to our Privacy Officer (section 11) and, if the matter is not resolved, to the Office of the Privacy Commissioner of Canada (priv.gc.ca; 1-800-282-1376), to the Commission d'accès à l'information du Québec (cai.gouv.qc.ca) if you are in Quebec, or to the privacy regulator in your province or state. We will not penalise you for exercising any right.

10. Cookies on the Portal and our websites

The Portal uses only the cookies and similar technologies strictly necessary to sign you in, keep your session secure and remember your preferences. Our business websites (such as stoneswap.studio) may use analytics and advertising technologies; where the law requires consent for them (including in the European Economic Area, the United Kingdom, Switzerland and Quebec), we ask for it through a consent banner before they are set, and you can change your choice at any time from the banner or your browser settings. No tracking cookies are set on a Customer's Studio before an End User signs up, and analytics or advertising tags on a Studio are set only if the Customer enables them (section 5.3).

11. Privacy Officer and how to contact us

Questions, requests and complaints about this Policy or our handling of Personal Information should be sent to our Privacy Officer, Matthew Stubbs, at [email protected], or by mail to StoneSwap Inc., Attention: Privacy Officer, 21 King St W, Suite 6, Hamilton, Ontario L8P 4W7, Canada. Security and incident notifications should also go to [email protected].

12. Changes to this Policy

We may update this Policy from time to time. We will post the updated version in the Portal and on our legal pages with a new version date and, for changes that materially affect how we handle Personal Information, notify Customers by e-mail at least 30 days before the change takes effect. Changes to Schedule A are governed by section 27 of the Terms of Service. Prior versions are available on request.

Schedule A — Data Processing Terms

These Data Processing Terms ("Schedule A") form part of the StoneSwap Studio Terms of Service (the "Terms") between StoneSwap Inc. ("StoneSwap") and the Customer, and apply whenever StoneSwap Processes Personal Information on the Customer's behalf. On a question of the handling of Personal Information, Schedule A prevails over the Terms. A Data Processing Agreement signed by both parties prevails over Schedule A.

A.1 Definitions

Capitalised words have the meanings given in the Terms. In addition: "Customer Personal Information" means Personal Information contained in Tenant Data, including Personal Information of End Users, leads, Showroom Device operators and the Customer's Portal users; "Confidential Incident" means a confidentiality incident within the meaning of Law 25, a breach of security safeguards within the meaning of PIPEDA, or a security breach within the meaning of the CCPA or another Applicable Privacy Law, affecting Customer Personal Information in StoneSwap's or a Sub-processor's custody; and "Sub-processor" means a third party StoneSwap engages to Process Customer Personal Information.

A.2 Roles

The Customer is the organisation that collects, holds and uses Customer Personal Information for its own purposes (the controller; the person who communicates Personal Information to a service provider under Law 25; the "business" under the CCPA). StoneSwap is the Customer's service provider and processor (a mandatary or person carrying out a contract under Law 25 section 18.3; a "service provider" under the CCPA) and Processes Customer Personal Information only on the Customer's behalf and under its documented instructions. Where StoneSwap sells consumer credit packs to End Users as merchant of record, StoneSwap acts for its own account for the payment transaction only; card data is processed by Stripe and StoneSwap's payment and receipt records for those purchases are StoneSwap's own records.

A.3 Instructions

The Customer's documented instructions are: the Terms and this Schedule; the Customer's configuration choices in the Portal (including retention windows, safeguards, access mode, free-Design allowances, lead-delivery and webhook settings, connected vendors, Network settings and the Studio's legal pages); and the Customer's written requests to StoneSwap. StoneSwap will Process Customer Personal Information only on those instructions, unless required to do otherwise by law, in which case StoneSwap will inform the Customer of the legal requirement before Processing unless the law prohibits it. StoneSwap will inform the Customer if, in its opinion, an instruction breaches Applicable Privacy Law, and may suspend the instruction until the matter is resolved. The Customer instructs StoneSwap to operate the anti-abuse and safety pipeline described in A.6(e) as part of the Service.

A.4 Purpose limitation

StoneSwap Processes Customer Personal Information only to provide, secure, support, improve the operation of, and bill for the Service under the Terms and the Customer's instructions, and for no other purpose. In particular, StoneSwap will not:

  1. sell or share Customer Personal Information within the meaning of the CCPA, or disclose it to any third party except Sub-processors, vendors the Customer has enabled, and as the law requires;
  2. retain, use or disclose Customer Personal Information for any purpose other than the Service, or outside the direct business relationship with the Customer;
  3. combine Customer Personal Information with Personal Information held for any other Tenant or from any other source, except as needed to perform the Service (for example the Network, where the Customer's settings permit) or as Applicable Privacy Law permits; each Customer's data lives in a dedicated database with its own credentials and is not commingled with any other Tenant's data;
  4. use Customer Personal Information, End User photographs or Designs to train machine-learning or AI models, whether for StoneSwap's own products or for other customers, and StoneSwap contracts with its AI providers on terms under which they do not train on that data;
  5. view, analyse, benchmark or profile the Customer's leads, End User records or product-level insights, or build any cross-Tenant product from them; StoneSwap's administrative tooling does not present them, and direct database access is limited to support the Customer requests, incident response, maintenance and legal compliance, and is logged; or
  6. provide another Tenant with product-level analytics about the Customer's products.

StoneSwap certifies that it understands these restrictions and will comply with them, and will notify the Customer without undue delay if it determines that it can no longer meet its obligations under this Schedule, in which case the Customer may take reasonable steps to stop and remediate unauthorised Processing.

A.5 Confidentiality of personnel

StoneSwap ensures that every person it authorises to Process Customer Personal Information (employees and contractors) is bound by written confidentiality obligations at least as protective as this Schedule, has received appropriate training, and accesses Customer Personal Information only as needed to provide the Service. Every staff action on a Customer's account is logged with the acting person and IP address.

A.6 Security measures

StoneSwap maintains, and will not materially reduce during the Term, technical and organisational measures appropriate to the risk, including the following (measures in production as at the version date; StoneSwap may improve or replace individual measures provided the overall level of protection is not weakened):

  1. Isolation. A dedicated MySQL database with its own credentials for each Customer; a control plane that holds only registry data and anonymous aggregates (no End User rows, Designs or leads; billing computed from anonymous daily counters); media stored in a Cloudflare R2 bucket under a Customer-specific key prefix so that deleting media removes it from storage.
  2. Encryption. Lead contact details and End User profile fields (names, e-mail, phone, business, full postal code, free text) encrypted at rest with AES-256 (authenticated mode for profile fields) under a per-Customer key held outside the web root, with per-row initialisation vectors; e-mail addresses additionally stored as SHA-256 hashes for de-duplication; only a coarse postal prefix kept queryable for maps and insights; passwords bcrypt-hashed; all session, magic-link and API tokens stored as SHA-256 hashes; webhook payloads carrying Personal Information encrypted at rest; TLS on all connections.
  3. Access control. Least-privilege access for StoneSwap personnel; named administrator accounts; logging of every staff action and every Portal settings change with actor and IP; rate-limited and audit-logged export endpoints.
  4. Availability and backups. Encrypted routine backups kept for disaster recovery only, expiring within their normal rotation (as at this version, up to 30 days); hosting on infrastructure with redundant power and network; Cloudflare edge protection.
  5. Anti-abuse and content safety. Cloudflare Turnstile (cookieless) at sign-up; a per-request geographic allowlist checked from edge headers with nothing stored for the check; a three-signal location-trust check (typed postal code, browser geolocation only with the End User's explicit permission, edge GeoIP); re-encoding of uploaded photographs on intake so that camera metadata including GPS coordinates does not survive into the stored file; a free rule-based pre-check for junk and malicious input; automated AI safety checks before and after rendering that refuse unsafe or off-purpose content; velocity caps per IP, device and account; blacklisting of banned users (e-mail and device fingerprints blocked permanently, IP addresses temporarily, default seven days); server-side watermarking of every finished Design.
  6. Data minimisation. No tracking cookies before sign-up; product insights contain no names, e-mail addresses or phone numbers (coarse location only); the geographic check stores nothing.
  7. Auditability. An append-only ledger of every billable Design and Blocked Attempt batch; invoices that freeze a full calculation snapshot at issue; automated reconciliation that reports discrepancies exactly.
  8. Organisational measures. A named Privacy Officer with a named second responder; a written Incident Register and Notification Playbook reviewed every January and after every incident; an incident register retained for at least five years with an offline copy; external counsel engaged as needed.

A.7 Sub-processors

Authorisation. The Customer authorises StoneSwap to engage the Sub-processors listed in section 5.2 of the Privacy Policy above (as at the version date: DigitalOcean, Cloudflare, fal.ai, Google, OpenRouter, Resend and Stripe), for the functions and in the locations described there. Vendors the Customer enables itself in the Portal (section 5.3 of the Privacy Policy) are appointed by the Customer and are not StoneSwap's Sub-processors.

Flow-down. StoneSwap will bind each Sub-processor by written contract to data-protection obligations materially equivalent to this Schedule to the extent applicable to the service the Sub-processor provides, including the CCPA service-provider restrictions, and remains responsible to the Customer for each Sub-processor's performance.

Changes. StoneSwap will give the Customer at least 30 days' notice, by e-mail to the Customer's Portal contact and by notice in the Portal, before adding or replacing a Sub-processor that will Process Customer Personal Information (shorter notice may be given where a change is needed urgently to maintain the security or availability of the Service, in which case StoneSwap will explain why). The Customer may object in writing within the notice period on reasonable data-protection grounds. The parties will work in good faith to resolve the objection; if they cannot within 30 days, the Customer may cancel the affected part of the Service, or the Agreement, on written notice, and section 24.3 of the Terms applies to refunds as if StoneSwap had terminated for convenience. A change of AI model that changes which Sub-processor Processes Customer Personal Information is a Sub-processor change for this purpose.

A.8 Confidential Incidents

Notice. If StoneSwap becomes aware of a Confidential Incident, StoneSwap will notify the Customer's designated privacy contact (or, if none is designated, the Customer's Portal owner) without undue delay and in any event within 72 hours after StoneSwap has confirmed that a Confidential Incident affecting Customer Personal Information has occurred, and will supplement the notice as information becomes available.

Content. The notice will describe, to the extent then known, the nature of the incident, the categories and approximate number of individuals and records affected, the likely consequences, the measures taken or proposed to contain and remedy it, and a StoneSwap contact.

Assistance. StoneSwap will give the Customer reasonable assistance with the Customer's obligations to assess the incident (including the "risk of serious injury" test under Law 25 and the "real risk of significant harm" test under PIPEDA), to keep its incident register, and to notify the Commission d'accès à l'information du Québec, the Office of the Privacy Commissioner of Canada, other regulators and affected individuals. The assessment and the decision to notify are the Customer's; StoneSwap will provide the facts. StoneSwap will not notify regulators or individuals on the Customer's behalf unless the Customer instructs it in writing or the law requires StoneSwap to do so directly.

Records. StoneSwap keeps a register of Confidential Incidents for at least five years and will make the entries relevant to the Customer available on request. A notice under this section is not an admission of fault or liability.

A.9 Assistance with individual rights

Requests routed to the Customer. End Users and leads are the Customer's users. If StoneSwap receives an access, correction, deletion, portability, objection or withdrawal request concerning Customer Personal Information, it will forward the request to the Customer without undue delay and will not respond substantively except as the Customer instructs or the law requires.

Self-service tools. The Service includes tools that discharge much of this in practice, and StoneSwap will keep them functioning: End User account deletion with full erasure of the account and its media (the e-mail address is retained only as a SHA-256 hash to prevent free-Design abuse); a self-service "Download my data" export that delivers an End User's data as one structured JSON file, rate-limited and audit-logged; one-click marketing unsubscribe effective immediately, working for prospects without an account, with RFC 8058 List-Unsubscribe headers on every non-essential e-mail; Portal tools for the Customer to look up, export, delete and blacklist End Users and leads; and the Portal retention controls in A.10.

Further assistance. Taking into account the nature of the Processing, StoneSwap will provide reasonable further assistance with individual requests, privacy impact assessments (including a Law 25 section 17 assessment) and consultations with regulators, and may charge its then-current rates for assistance that goes beyond the self-service tools and reasonable written responses.

A.10 Retention

StoneSwap retains Customer Personal Information according to the retention windows the Customer sets in the Portal, which are the Customer's instructions and apply to existing and new data: a media window for photographs and Designs (5 to 365 days) and a data window for leads, End User accounts, insights, activity records and associated data (up to 10 years, or as the Portal permits), the media window being automatically capped at the data window. Data that exceeds its window is purged by a scheduled process within 24 hours of becoming eligible; shortening a window applies retroactively, and lengthening one does not restore data already purged. Purging does not extend to routine backups (A.6(d)), to the billing, usage and security records StoneSwap must keep to invoice, audit and protect the Service (which identify Designs and Blocked Attempts but contain no photographs or Designs), to consent records for active accounts, or to the anti-abuse minimums for banned or deleted accounts. Records in another Tenant's account are governed by that Tenant's settings (Terms, section 13.6).

A.11 Return and deletion at termination

On termination or expiry of the Agreement, StoneSwap will make Tenant Data available for export through the Portal in a structured, commonly used format for 30 days (the Export Window in section 25.2 of the Terms), and will delete or de-identify Customer Personal Information in its custody within 90 days after the termination date, and instruct its Sub-processors to do the same to the extent their terms provide, except for the records described in section 25.3 of the Terms (billing and audit records, legal acceptance and consent records, incident records, anti-abuse minimums, de-identified insights, backups within their rotation, and records in other Tenants' accounts or held by End Users on StoneSwap.ai). No separate deletion step is required at fal.ai, which deletes everything it stores for a request within 24 hours. StoneSwap will confirm deletion in writing on request, including confirmation from Sub-processors to the extent their terms provide it.

A.12 Audits and verification

The Service maintains the records described in A.6(g), and the Customer's Portal exposes the Customer's own records. On the Customer's written request, no more than once in any twelve-month period (and additionally after a Confidential Incident affecting the Customer), StoneSwap will: (a) answer reasonable written security and compliance questionnaires; (b) provide summaries of its security measures, Sub-processor arrangements and, where available, third-party audit reports or certifications; and (c) where a specific concern remains unresolved after the written process and is supported by evidence, permit an audit by the Customer or an independent auditor bound by confidentiality, on at least 30 days' notice, during business hours, limited to what is relevant to Customer Personal Information and conducted so as not to expose other Tenants' data or StoneSwap's trade secrets. Audits under (c) are at the Customer's cost, including StoneSwap's reasonable time at its then-current rates, unless the audit reveals a material breach of this Schedule by StoneSwap. The Customer's audit and remediation rights under the CCPA are satisfied through this section and A.4.

A.13 Cross-border Processing

Customer Personal Information is Processed in Canada and the United States as described in sections 5 and 6 of the Privacy Policy. StoneSwap applies the measures in A.6 and contracts with each Sub-processor so that Customer Personal Information Processed outside Quebec and outside Canada receives protection consistent with this Schedule regardless of location. For a Customer subject to Law 25, this Schedule together with the Terms is the written agreement that section 17 of the Act requires; the Customer remains responsible for conducting its own privacy impact assessment, and StoneSwap will provide the factual information the Customer reasonably needs for it. If legally permitted, StoneSwap will notify the Customer before disclosing Customer Personal Information in response to a court order or government demand and will disclose only what is legally required.

A.14 Liability

Each party's liability arising out of or relating to this Schedule is governed by, and counts toward the limitations and exclusions in, section 21 of the Terms. Nothing in this Schedule creates a right for any person other than the parties, except that the Customer may enforce this Schedule on behalf of the individuals whose Personal Information is affected to the extent Applicable Privacy Law requires.

A.15 Term and survival

This Schedule applies for as long as StoneSwap Processes Customer Personal Information, including during the export and deletion periods in A.11. Sections A.4, A.5, A.8 (records), A.11, A.13 and A.14 survive termination. This Schedule may be changed only under section 27 of the Terms, and a change that materially reduces the Customer's protections is a Material Change requiring re-acceptance.

A.16 Details of Processing

StoneSwap Studio Privacy Policy (Business Customers) and Schedule A (Data Processing Terms) · Version 2026-09-25 · StoneSwap Inc., 21 King St W, Suite 6, Hamilton, ON L8P 4W7, Canada · Privacy Officer: Matthew Stubbs, [email protected]