UiChemy Legal & Compliance
Data Processing Addendum (DPA)
Effective Date: April 1st 2026
Last Updated: April 1st 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between POSIMYTH INC (“Processor”) and the Customer (“Controller”). This DPA applies when UiChemy processes personal data on behalf of the Customer.
1. Definitions
- “Controller” means the entity that determines the purposes and means of processing personal data.
- “Processor” means POSIMYTH INC, which processes personal data on behalf of the Controller.
- “Personal Data” means any information relating to an identified or identifiable individual.
- “Applicable Data Protection Law” includes GDPR, UK GDPR, California privacy laws, and other applicable privacy regulations.
2. Scope of Processing
Processor processes personal data solely:
- To provide the Service
- As instructed by the Controller
- As necessary to fulfill contractual obligations
Processor does not determine the purposes of processing Customer data.
3. Nature & Purpose of Processing
Processing may include:
- Storage
- Hosting
- Transmission
- AI-assisted processing
- Backup
- Technical support
Categories of data may include:
- Names
- Email addresses
- Uploaded files
- Project content
- AI prompts and outputs
Data subjects may include:
- Customer employees
- Agency clients
- End users
4. Processor Obligations
Processor shall:
- Process data only on documented instructions
- Implement commercially reasonable security measures
- Ensure personnel are subject to confidentiality obligations
- Assist Controller in responding to data subject requests where reasonably feasible
Processor is not responsible for compliance obligations that fall to the Controller.
5. Security Measures
Processor implements commercially reasonable administrative, technical, and organizational safeguards.
Processor does not warrant:
- Absolute security
- Specific certifications
- Guaranteed uptime
6. Subprocessors
Controller authorizes Processor to use subprocessors.
Current subprocessors may include:
- Paddle (billing)
- OpenAI
- Anthropic
- Plausible
- Mixpanel
- Hetzner
- DigitalOcean
Processor may update subprocessors from time to time.
7. International Transfers
Personal data may be processed in:
- United States
- European Union
- India
Controller acknowledges and consents to such transfers.
Processor shall implement appropriate safeguards where required by applicable law.
8. Data Subject Rights
To the extent legally required, Processor will:
- Assist Controller in responding to data subject requests
- Provide reasonable cooperation
Controller remains responsible for responding to such requests.
9. Data Breach Notification
In the event of a confirmed personal data breach affecting Customer data, Processor will:
- Notify Controller without undue delay
- Provide available information necessary for compliance
Processor is not liable for breaches caused by Controller or third parties beyond its reasonable control.
10. Data Retention & Deletion
Upon termination:
- Customer has 30-day data export window
- After that, data may be deleted
- Backup copies may persist temporarily
Processor is not required to retain data beyond operational or legal necessity.
11. Liability
Liability under this DPA is subject to the limitations set forth in the Terms of Service. Nothing in this DPA expands Processor’s liability beyond those limits.
12. Governing Law
This DPA is governed by the governing law specified in the Terms of Service (Delaware, USA).
13. Conflict
In case of conflict between this DPA and the Terms of Service, this DPA controls solely with respect to data protection obligations.