# Data Processing Agreement

Version 1.0.0-draft.1

> **Draft — pending counsel review** This document is a DRAFT published for transparency. The text below has NOT yet been approved by legal counsel and is not legally binding in its current form. The accepted version is recorded against your account; when counsel approves a new version, you will be asked to re-accept before continuing.

This proposed DPA supplies a controller-processor framework for personal data in customer content. It covers instructions, confidentiality, security, subprocessors, transfers, assistance, incidents, deletion, and audit, but its party details, annexes, regions, vendor list, notice periods, and legal mechanisms require completion before signature.

## 1. Scope and precedence

The binding DPA will form part of the agreement when ulpi processes Customer Personal Data on behalf of a customer. It will prevail over conflicting privacy-processing terms in the main agreement, while an executed transfer mechanism will prevail for the covered transfer. This review draft is not executed, does not identify the parties, and cannot serve as a transfer mechanism.

## 2. Definitions

Customer Personal Data means personal data in customer content that ulpi processes as processor or service provider. Data Protection Law means the privacy law applicable to that processing. Controller, processor, service provider, contractor, business, consumer, personal data, personal information, processing, subprocessor, and supervisory authority have the meanings given by applicable law. Terms not defined here have the meaning in the main agreement.

## 3. Roles and customer responsibility

The customer is controller or processor, as applicable, and ulpi is its processor or subprocessor for Customer Personal Data. Each party is responsible for its own compliance. The customer determines the lawful purposes and means, provides required notices, obtains authorisations, limits data to what is permitted, answers data-subject requests, and ensures its instructions—including selection of models and connectors—comply with law.

## 4. Documented instructions

ulpi will process Customer Personal Data only to provide, secure, support, and delete the service under the agreement, the customer's configuration and authorised use, and other documented instructions, unless law requires different processing. If legally permitted, ulpi will notify the customer of that requirement. ulpi will inform the customer if it believes an instruction infringes applicable Data Protection Law and may pause the affected processing while the parties resolve it.

## 5. Processing details

Subject matter: operation of agent-powered companies and related support. Nature: collection, storage, organisation, retrieval, transmission to authorised providers/connectors, generation, verification, export, restriction, and deletion. Duration: the service term plus approved return, backup, and legal-retention periods. Purposes: performing customer goals and configured workflows. The final Annex I must identify data-subject categories, data categories, sensitive-data restrictions, frequency, and any additional instructions for the actual customer use case.

## 6. Personnel and confidentiality

ulpi will limit access to authorised personnel and contractors who need it to operate or secure the service and who are bound by confidentiality obligations that survive their access. ulpi will provide appropriate privacy and security training and apply least-privilege access, authentication, access review, and offboarding processes appropriate to each role.

## 7. Security measures

ulpi will implement and maintain measures appropriate to the risk, including tenant isolation, least privilege, authentication and authorisation, encryption and key management, secret segregation, isolated execution, egress controls, immutable or append-only evidence, vulnerability and dependency management, logging and monitoring, backup and recovery, incident response, secure deletion, and regular testing. Final Annex II must describe deployed measures, ownership, cadence, and exceptions rather than relying on product design alone.

## 8. Subprocessors

The final DPA must choose prior specific authorisation or general written authorisation. Under a general-authorisation model, ulpi will publish the approved subprocessor list and give the agreed advance notice of additions or replacements so the customer can raise a reasonable data-protection objection. ulpi will impose materially equivalent data-protection obligations and remain responsible for each subprocessor's performance to the extent required by law. Customer-directed connectors must be classified separately.

## 9. International transfers

ulpi will not transfer Customer Personal Data across a restricted border without a valid legal mechanism and required safeguards. Where the parties execute EU Standard Contractual Clauses or another approved mechanism, they must select the correct modules and options, complete and sign the annexes, identify competent authorities and courts, assess the destination, and apply supplementary measures where necessary. The final transfer terms depend on the parties, deployment regions, and subprocessor locations.

## 10. Data-subject requests

Taking account of the processing, ulpi will provide reasonable technical and organisational assistance for the customer to respond to requests to access, correct, delete, restrict, object, or port Customer Personal Data. If a request is sent directly to ulpi about customer-controlled data, ulpi will refer it to the customer where legally permitted and will not independently respond except on documented instruction or as required by law.

## 11. Compliance assistance

Considering the nature of processing and information available, ulpi will reasonably assist with security obligations, breach notifications, risk and data-protection impact assessments, prior consultation, records, and regulator inquiries relating to the service. The agreement may allocate reasonable costs for exceptional assistance caused by customer-specific instructions, but cost terms may not prevent legally required cooperation.

## 12. Personal data incidents

ulpi will notify the customer's designated contact without undue delay after confirming a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data. Notice will include available information needed for the customer's assessment and will be supplemented as facts develop. Notification is not an admission of fault. The final DPA and incident plan must approve the contact, timing objective, investigation, remediation, and regulator coordination.

## 13. Return and deletion

At the customer's choice and subject to the agreement, ulpi will make available an export and then delete or render inaccessible Customer Personal Data after termination or a validated deletion request, unless law requires retention. Deletion includes tenant rows, object versions, workflow histories, credentials, and relevant encryption keys under the approved lifecycle, with backups expiring on the documented schedule. Global account identity and legal-acceptance evidence follow a separately approved policy.

## 14. Information and audits

ulpi will provide information reasonably necessary to demonstrate compliance, ordinarily through current independent reports, certifications, control descriptions, and written responses. If that evidence is insufficient and law requires more, the final DPA should allow a proportionate audit by an independent qualified auditor under confidentiality, scope, timing, safety, tenant-protection, and cost conditions, without exposing another customer's data or platform secrets.

## 15. Government requests

Unless prohibited, ulpi will notify the customer of a legally binding demand for Customer Personal Data, review its validity, disclose only what is required, and pursue available objections or protective measures when there are reasonable grounds. Transfer clauses may impose additional notice, challenge, transparency, and documentation duties that will control for covered data.

## 16. Liability, term, and changes

The DPA will remain effective while ulpi processes Customer Personal Data. Liability is governed by the binding agreement except where applicable law or executed transfer clauses require otherwise. Material changes to processing, security measures, subprocessors, or transfer terms must follow the approved notice and versioning process. No liability allocation, notice period, or governing law is approved by this draft.

## Annex I — Processing description to complete

Before signature, identify the customer and ulpi entities and contacts; their roles; service term; categories of people and personal data; any sensitive data and safeguards; processing operations and purposes; frequency; retention; approved regions; authorised models and connectors; and the competent supervisory authority. A generic product description is not a substitute for customer-specific restrictions where those are required.

## Annex II — Technical and organisational measures to verify

The final annex should map deployed controls for governance, personnel, physical and infrastructure security, tenant isolation, access, authentication, encryption, secret and key management, software development, vulnerability handling, logging, detection, incident response, business continuity, backup/restore, deletion, subprocessor diligence, and control testing. Each claim must be supported by operating evidence and identify material customer responsibilities.

## Annex III — Approved subprocessors to publish

For every ulpi-engaged subprocessor, list the legal entity, service and processing purpose, categories of data, processing locations, transfer mechanism, and effective date. Separately list infrastructure, payment, email, support, observability, and model providers. Customer-selected MCP connectors and bring-your-own providers should be disclosed under their correct legal role rather than automatically labelled as subprocessors.