UiChemy Legal & Compliance

Data Processing Addendum (DPA)

Effective Date: April 1st 2026

Last Updated: April 1st 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between POSIMYTH INC (“Processor”) and the Customer (“Controller”). This DPA applies when UiChemy processes personal data on behalf of the Customer.

1. Definitions

  • “Controller” means the entity that determines the purposes and means of processing personal data.
  • “Processor” means POSIMYTH INC, which processes personal data on behalf of the Controller.
  • “Personal Data” means any information relating to an identified or identifiable individual.
  • “Applicable Data Protection Law” includes GDPR, UK GDPR, California privacy laws, and other applicable privacy regulations.

2. Scope of Processing

Processor processes personal data solely:

  • To provide the Service
  • As instructed by the Controller
  • As necessary to fulfill contractual obligations

Processor does not determine the purposes of processing Customer data.

3. Nature & Purpose of Processing

Processing may include:

  • Storage
  • Hosting
  • Transmission
  • AI-assisted processing
  • Backup
  • Technical support

Categories of data may include:

  • Names
  • Email addresses
  • Uploaded files
  • Project content
  • AI prompts and outputs

Data subjects may include:

  • Customer employees
  • Agency clients
  • End users

4. Processor Obligations

Processor shall:

  • Process data only on documented instructions
  • Implement commercially reasonable security measures
  • Ensure personnel are subject to confidentiality obligations
  • Assist Controller in responding to data subject requests where reasonably feasible

Processor is not responsible for compliance obligations that fall to the Controller.

5. Security Measures

Processor implements commercially reasonable administrative, technical, and organizational safeguards.

Processor does not warrant:

  • Absolute security
  • Specific certifications
  • Guaranteed uptime

6. Subprocessors

Controller authorizes Processor to use subprocessors.

Current subprocessors may include:

  • Paddle (billing)
  • OpenAI
  • Google
  • Anthropic
  • Plausible
  • Mixpanel
  • Hetzner
  • DigitalOcean

Processor may update subprocessors from time to time.

7. International Transfers

Personal data may be processed in:

  • United States
  • European Union
  • India

Controller acknowledges and consents to such transfers.

Processor shall implement appropriate safeguards where required by applicable law.

8. Data Subject Rights

To the extent legally required, Processor will:

  • Assist Controller in responding to data subject requests
  • Provide reasonable cooperation

Controller remains responsible for responding to such requests.

9. Data Breach Notification

In the event of a confirmed personal data breach affecting Customer data, Processor will:

  • Notify Controller without undue delay
  • Provide available information necessary for compliance

Processor is not liable for breaches caused by Controller or third parties beyond its reasonable control.

10. Data Retention & Deletion

Upon termination:

  • Customer has 30-day data export window
  • After that, data may be deleted
  • Backup copies may persist temporarily

Processor is not required to retain data beyond operational or legal necessity.

11. Liability

Liability under this DPA is subject to the limitations set forth in the Terms of Service. Nothing in this DPA expands Processor’s liability beyond those limits.

12. Governing Law

This DPA is governed by the governing law specified in the Terms of Service (Delaware, USA).

13. Conflict

In case of conflict between this DPA and the Terms of Service, this DPA controls solely with respect to data protection obligations.