

Last updated: July 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service (the "Agreement") between UOVA, Inc. ("Processor" or "UOVA") and the entity agreeing to these terms ("Controller" or "Customer") and applies to the processing of Personal Data by UOVA on behalf of the Customer in connection with the provision of the UOVA Services.
This DPA is entered into to ensure compliance with Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, the Swiss Federal Act on Data Protection ("FADP"), and any other applicable data protection legislation (collectively, "Data Protection Laws").
In the event of any conflict between this DPA and the Agreement, this DPA shall prevail with respect to the processing of Personal Data.
In this DPA, the following terms shall have the meanings set out below:
"Controller" — means the entity that determines the purposes and means of the processing of Personal Data, i.e., the Customer.
"Processor" — means the entity that processes Personal Data on behalf of the Controller, i.e., UOVA.
"Sub-processor" — means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
"Personal Data" — means any information relating to an identified or identifiable natural person as defined in applicable Data Protection Laws.
"Data Subject" — means the identified or identifiable natural person to whom Personal Data relates.
"Processing" — means any operation or set of operations performed on Personal Data, including collection, recording, organization, storage, adaptation, alteration, retrieval, consultation, use, disclosure, erasure, or destruction.
"Personal Data Breach" — means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed.
"Standard Contractual Clauses" or "SCCs" — means the standard contractual clauses approved by the European Commission for international transfers of Personal Data.
UOVA will process Personal Data on behalf of the Customer only as necessary to provide the Services described in the Agreement. The details of the processing are as follows:
Subject Matter — Provision of website building, AI content generation, hosting, and collaboration services.
Duration — For the duration of the Agreement, plus any retention period required by applicable law.
Nature and Purpose — Storage, retrieval, display, and transmission of Customer's content and end-user data as necessary to operate the Service; processing of AI prompts for content generation; hosting and serving published websites.
Categories of Data Subjects — Customer's employees, team members, contractors, end-users, and website visitors.
Types of Personal Data — Names, email addresses, IP addresses, browser/device information, user-generated content, AI prompts and outputs, website analytics data, and any other Personal Data uploaded or collected through the Customer's use of the Services.
UOVA, as the Processor, shall:
The Controller provides general authorization for UOVA to engage Sub-processors for the processing of Personal Data, subject to the following conditions:
Current list of Sub-processors:
| Sub-processor | Service | Location | Data Processed |
|---|---|---|---|
| Supabase, Inc. | Authentication, database, storage | United States (AWS) | Account data, user content, project data |
| Stripe, Inc. | Payment processing and merchant payouts (Connect) | United States | Payment information, transaction records, merchant onboarding data |
| Vercel, Inc. (incl. Vercel AI Gateway) | Hosting, CDN, edge functions, AI model routing | Global (edge network) | Published website content, request logs, AI prompts |
| Anthropic, PBC | AI text/site generation and image analysis | United States | AI prompts, uploaded images, generation metadata |
| OpenAI, Inc. | AI text generation (fallback) | United States | AI prompts, generation metadata |
| Google LLC | AI image generation (Imagen) and analytics | United States | AI prompts, usage data, device info |
| fal.ai (Features and Labels, Inc.) and its model providers | AI image and video generation | United States / Global | AI prompts, uploaded images, generation metadata |
| Replicate, Inc. | AI image and video generation (fallback) | United States | AI prompts, generation metadata |
| Higgsfield, Inc. | AI image and video generation | United States | AI prompts, uploaded images, generation metadata |
| Meta Platforms, Inc. | Advertising measurement (Meta Pixel), with consent | United States | Advertising event data and identifiers |
| Cloudflare, Inc. | CDN, DNS, DDoS protection, bot/abuse prevention (Turnstile) | Global (edge network) | IP addresses, request metadata |
| Upstash, Inc. | Rate limiting and abuse prevention | United States / Global | IP-derived identifiers (transient) |
| Resend (Plus Five Five, Inc.) | Transactional and marketing email delivery | United States | Email addresses, email content, engagement events |
| Tucows / OpenSRS | Domain registration and transfer | Canada / United States | Domain registrant contact data (name, address, email, phone) |
| Crisp IM SARL | Customer support chat | France (EU) | Chat messages, email addresses |
| Functional Software (Sentry) | Error tracking | United States | Technical error data (PII scrubbed) |
To subscribe to Sub-processor update notifications, please email dpo@uova.io with the subject line "Sub-processor Notifications."
UOVA shall assist the Controller in responding to requests from Data Subjects exercising their rights under applicable Data Protection Laws, including but not limited to:
If UOVA receives a request directly from a Data Subject, UOVA shall promptly redirect the Data Subject to the Controller and shall not respond to the request directly without the Controller's authorization, unless required by applicable law.
UOVA implements and maintains appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing, and against accidental loss, destruction, damage, theft, or disclosure. Taking into account the state of the art and the nature of the processing, these measures include, as applicable, measures such as:
Encryption — Data in transit is encrypted using TLS, and data at rest is encrypted by our infrastructure providers using strong encryption (such as AES-256).
Access Controls — Role-based access control and the principle of least privilege for internal systems, and support for multi-factor authentication for access to production systems.
Network Security — DDoS protection and web-application-firewall capabilities via Cloudflare, and network controls provided by our infrastructure.
Application Security — Code review, dependency monitoring, automated vulnerability scanning, and secure-development practices.
Physical Security — All infrastructure is hosted in reputable third-party data centers that maintain recognized security certifications (such as SOC 2). UOVA does not maintain its own physical data centers.
Personnel Security — Confidentiality obligations for personnel and contractors, access limited on a need-to-know basis, and security awareness practices.
Monitoring — Logging, monitoring, and alerting for production systems to help detect anomalous activity.
Business Continuity — Automated backups and disaster-recovery capabilities provided by our infrastructure providers. We aim to restore critical systems promptly following an incident.
In the event of a Personal Data Breach, UOVA shall:
The notification shall include, to the extent reasonably available:
Where Personal Data is transferred outside the European Economic Area (EEA), the United Kingdom, or Switzerland to a country that has not been deemed to provide an adequate level of data protection, UOVA shall ensure that appropriate safeguards are in place:
Upon request, UOVA shall provide the Controller with copies of the relevant transfer mechanism documentation.
UOVA shall make available to the Controller, upon reasonable request and at the Controller's expense, all information necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, conducted by the Controller or an independent auditor mandated by the Controller.
Audits are subject to the following conditions:
This DPA shall remain in effect for the duration of the Agreement. Upon termination of the Agreement, UOVA shall, at the Controller's choice:
Notwithstanding the above, UOVA may retain Personal Data to the extent required by applicable law, provided that UOVA shall ensure the confidentiality of such Personal Data and shall not process it for any purpose other than compliance with such legal requirements.
The obligations of UOVA under this DPA shall continue for as long as UOVA processes Personal Data on behalf of the Controller.
Each party's liability under this DPA shall be subject to the exclusions and limitations of liability set out in the Agreement. Nothing in this DPA shall limit either party's liability with respect to any rights that Data Subjects may have under applicable Data Protection Laws.
Where UOVA is held liable for damage caused by processing that infringes applicable Data Protection Laws, UOVA shall be liable only to the extent that the processing does not comply with the obligations of this DPA or where UOVA has acted outside of or contrary to the Controller's lawful instructions.
For questions about this DPA or to exercise rights under this agreement, please contact: