1. Scope and responsible entity
This Policy is intended to cover ulpi websites, account creation, the hosted platform, support, billing, and related operational communications. The binding version must name the legal entity responsible for account and service-administration data, its address, applicable representatives, and privacy contact. It does not replace a customer's own privacy notice for personal data the customer controls through its companies, agents, WorkProducts, or connectors.
2. Our privacy roles
ulpi generally determines why and how account identity, authentication, billing, security, product-administration, and support data is processed and therefore acts as the relevant controller or business for that data. For personal data contained in customer instructions, files, connector payloads, and generated work, ulpi generally acts as the customer's processor or service provider under the DPA. A provider or connector may have its own independent role under its terms.
3. Data we collect
Data may include account email and profile details; password hashes, verification/reset records, sessions, roles, and company relationships; subscription and payment identifiers; goals, prompts, files, comments, approvals, WorkProducts, and other customer content; model and connector configuration and scoped credential references; run, usage, budget, cost, audit, security, device, and request metadata; support communications; and deletion or export evidence. ulpi is not intended to store plaintext passwords or expose stored provider credentials in ordinary product views.
4. Sources of data
We receive data from account holders and their organisations, authorised users and agents, customer-connected model/API providers and MCP connectors, payment and email providers, platform and security logs, support interactions, and records generated when the service performs customer instructions. Customers decide which third-party accounts to connect and must provide required notices to the people whose data they supply.
5. Purposes of processing
We process data to create and secure accounts; provide, orchestrate, verify, and troubleshoot agent work; enforce tenant isolation, roles, approvals, budgets, and acceptable-use rules; connect customer-selected providers and tools; meter usage and administer billing; communicate about service and incidents; provide support and exports; investigate abuse and protect rights; comply with law; and improve reliability and product design using data permitted by the binding agreement.
6. Legal bases
Where a law requires a legal basis, the final policy will map each purpose to performance of a contract, legitimate interests such as security and service improvement, compliance with legal obligations, or consent where required. The final mapping depends on the contracting entity, markets, product analytics, and communications actually used. Customer content is processed on the customer's documented instructions under the DPA, subject to limited legal exceptions.
7. Model and API providers
When a customer selects a model or API provider, ulpi may transmit the prompt, relevant context, tool results, output, identifiers, and usage metadata needed to perform that request. Provider identity, location, retention, training controls, and terms vary by configuration. The binding subprocessor and provider disclosures must identify the production defaults and available customer choices. Customers should not send sensitive data unless the selected provider and contract permit it.
8. MCP connectors and customer-directed services
A connected service can receive requests and customer content and return records that ulpi processes for the customer. Connector scopes and actions are controlled by catalog, authorisation, and approval settings, but the external service applies its own terms and privacy practices. Catalog availability does not prove the service is an ulpi subprocessor; the final notice will distinguish ulpi-engaged subprocessors from third parties a customer independently directs ulpi to contact.
9. When data is disclosed
Data may be disclosed to authorised customer users; infrastructure and service providers under appropriate terms; customer-selected model providers and connectors; professional advisers and auditors under confidentiality; a successor in a corporate transaction subject to safeguards; and authorities or other parties when lawfully required or necessary to protect rights and safety. The product is not designed to sell personal data or use it for cross-context behavioural advertising; that statement must be reverified against final production analytics and commercial practices.
10. Hosting, residency, and international transfers
The platform is designed for a k3s deployment with database, workflow, object-store, and gateway components in controlled infrastructure, but the binding policy must state the actual host, primary region, backup and disaster-recovery regions, and locations of every production provider. If data moves across borders, ulpi will use the transfer mechanism required for the relevant parties and destination, which may include adequacy decisions, contractual safeguards, and supplementary measures. No specific residency promise is made by this draft.
11. Retention and deletion
We intend to keep personal data only for the period needed for the stated purpose, account lifecycle, security, dispute, tax, and legal obligations. Customer data may also remain temporarily in encrypted backups and immutable deletion evidence until scheduled expiry. Company deletion removes tenant data and encryption keys; global account erasure additionally addresses identity and account-wide records after all companies are resolved. Exact periods, backup windows, legal-hold rules, and treatment of legal-acceptance records must be approved before this Policy becomes binding.
12. Security
Designed safeguards include tenant-scoped database access, role and scope checks, encrypted secret storage, per-company key destruction, content-addressed objects, append-only audit evidence, isolated gVisor workloads, scoped model/MCP authority, signed workflow inputs, backups, and deletion manifests. No system is completely secure. Customers must protect account access and connected services and report suspected compromise to security@ulpi.io.
13. Automated processing
The platform uses software and AI models to carry out customer goals, propose or execute actions, verify work, manage budgets, and flag conditions for approval. Customers configure those workflows and are responsible for required human oversight and notices. ulpi does not intend to make legal or similarly significant decisions about individuals for its own purposes through customer agents; any production profiling or advertising use would require separate review and disclosure.
14. Privacy rights and requests
Depending on location and role, a person may request access, correction, deletion, portability, restriction, objection, withdrawal of consent, or review of certain automated decisions, and may complain to a regulator. Requests concerning customer-controlled content should normally be directed to that customer; ulpi will assist under the DPA. Account holders may use available export/deletion controls or contact support@ulpi.io. We may verify identity, apply lawful exceptions, and explain a refusal or appeal route where required.
15. Children and restricted data
The service is intended for business users and not directed to children. The binding terms must set the minimum age for launch markets. Customers must not use ulpi to collect children's data or highly regulated or sensitive data unless an order form, provider configuration, lawful basis, safeguards, and required notices expressly permit it.
16. Cookies and local storage
The web application uses storage needed for secure sessions, locale, and requested functionality. Before binding publication, ulpi must complete a production cookie and analytics inventory, identify any optional measurement or marketing technologies, state their duration and providers, and deploy consent and opt-out controls where required. This draft does not authorise undisclosed tracking.
17. Changes and contact
We will publish material policy changes under a new immutable version and seek renewed acceptance when required. The final policy must identify the controller, mailing address, privacy contact, representative or DPO if required, and the relevant regulator complaint route. Until then, draft questions may be sent to support@ulpi.io and security issues to security@ulpi.io.