Last Updated: September 9, 2026
This Data Processing Addendum (“DPA”) supplements the SaaS Subscription Agreement and Terms of Service (“Agreement”) between UNTU, Inc. (“Company” or “Processor”) and the entity or individual subscribing to the SaaS Services (“Customer” or “Controller”).
This DPA governs the processing of Personal Data in connection with the Services and reflects the parties' commitment to comply with applicable Data Protection Laws (including the EU/UK GDPR and US State Privacy Laws).
1. Definitions
- “Data Protection Laws” means all applicable worldwide legislation relating to privacy and data protection, including the General Data Protection Regulation (EU 2016/679) (“GDPR”), the UK GDPR, and US state privacy frameworks.
- “Personal Data” means any information uploaded by Customer to the SaaS Services that relates to an identified or identifiable natural person.
- “Data Subject” means the individual to whom the Personal Data relates.
- “Security Incident” means any accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure of, or access to Customer Personal Data.
2. Scope and Role of Parties
2.1 Roles
The parties acknowledge and agree that with regard to the processing of Personal Data within the SaaS platform, Customer acts as the Data Controller and UNTU, Inc. acts as the Data Processor.
2.2 Instructions
Processor shall process Personal Data only on behalf of and in accordance with Controller’s documented instructions, including with respect to transfers of Personal Data to a third country. The Agreement and this DPA constitute the Controller’s complete instructions.
3. Processor Obligations
3.1 Confidentiality
Processor shall ensure that persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
3.2 Security Measures
Processor shall implement and maintain appropriate technical and organizational measures designed to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure.
4. Subprocessors
4.1 Authorization
Controller grants a general written authorization to Processor to engage third-party Subprocessors to fulfill its contractual duties. The current list of authorized Subprocessors is available in the Subprocessor Disclosure List.
4.2 Notification of Changes
Processor shall inform Controller of any intended changes concerning the addition or replacement of Subprocessors at least fifteen (15) days in advance, giving Controller the opportunity to object to such changes on reasonable grounds.
5. Data Subject Rights
Processor shall, to the extent legally permitted, promptly notify Controller if it receives a request from a Data Subject to exercise their rights (such as access, correction, deletion, or portability). Processor will not respond to such requests directly except on documented instructions from the Controller or as required by law.
6. Security Incident Notification
In the event of a confirmed Security Incident involving Customer Personal Data, Processor shall notify Controller without undue delay, and no later than 72 hours after becoming aware of the breach. Processor shall provide reasonable cooperation and information regarding the incident to enable Controller to fulfill its breach notification obligations.
7. Audits and Reports
Processor shall make available to Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, at Controller's sole expense and no more than once per calendar year.
8. International Data Transfers
To the extent that the processing of Personal Data involves transfers from the EEA, Switzerland, or the UK to countries that do not ensure an adequate level of data protection, the parties agree to rely on standard contractual clauses (SCCs) approved by the European Commission or the UK Information Commissioner's Office, which are hereby incorporated by reference.
9. Return or Deletion of Data
Upon termination or expiration of the Agreement, Processor shall, at the choice of the Controller, delete or return all Personal Data to the Controller and delete existing copies unless applicable law requires storage of the Personal Data.
10. Contact Information
For any privacy, security, or data protection inquiries regarding this DPA, please contact our Data Protection Officer:
support@untubiz.com
Attention: Data Protection Officer / DPA