Launch week — start free, no credit card

Data Processing Agreement

Last updated: August 2026

1. About this DPA

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you (“Customer”) and UGCABC and applies whenever we process personal data on your behalf in the course of providing the Service. It reflects the requirements of the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”) and the UK GDPR.

If your organisation requires a counter-signed copy for your records, email privacy@ugcabc.com with your entity name and address and we'll return one signed.

2. Roles

For personal data submitted to, or generated by, the Service in the context of your account, the Customer acts as the Data Controller and UGCABC acts as the Data Processor. UGCABC processes such data only on the Customer's documented instructions, which are the Terms of Service and any settings the Customer configures in the app.

3. Nature and purpose of processing

We process personal data solely to provide and operate the Service: generating AI video ads from Customer-supplied product inputs, storing renders and assets, managing accounts and billing, providing support, ensuring security, and meeting legal obligations.

4. Categories of data subjects and personal data

  • Data subjects: Customer's account users (typically the Customer's employees or contractors); recipients of ads generated with the Service (indirectly, via any personal data shown in the ad script or composited assets the Customer uploads).
  • Personal data: account identifiers (name, email, workspace name); authentication and session data (via Clerk); billing identifiers (payment reference from Paytree); content the Customer uploads (product images, scripts, brand assets, and — for custom avatars — a photo of the person to be depicted, which is personal data of a heightened kind); usage metadata (pages viewed, features used, render history, IP address, user-agent, error diagnostics).

5. Duration

Processing continues for the term of the underlying Terms of Service. On termination, section 10 below governs deletion.

6. Sub-processors

UGCABC engages the sub-processors listed below to help provide the Service. Each is bound by contractual obligations equivalent to those in this DPA. We remain responsible to the Customer for the performance of each sub-processor.

Sub-processorPurposePrimary region
Clerk, Inc.Authentication, session management, MFAUnited States
Neon (Postgres)Application databaseEuropean Union
Amazon Web Services (S3, Lambda, SQS)Media storage, background rendering, job queueUnited States
VercelApplication hosting, edge network, log processingGlobal CDN
Paytree (payment-crm-eu.com)Payment processing — receives your name, email, IP address and billing country at checkoutEuropean Union
StripeCard processing on the hosted checkout page Paytree routes you toUnited States
TopviewUpstream AI video generation vendorSingapore
AnthropicScript writing and caption translation (product text and scripts only)United States
ElevenLabsVoice synthesis for voiceovers and speech recognition for caption timing (script text, finished audio)United States
Microsoft (Edge TTS)Fallback voice synthesis (script text)United States
ReplicateLegacy avatar rendering for non-catalogue avatars (avatar image, audio)United States
Tawk.toSupport chat widget (chat messages, browser metadata)United States
ResendTransactional email deliveryUnited States
PostHog (EU)Product analytics, aggregated usageEuropean Union
SentryError monitoring and diagnosticsUnited States

We'll notify Customer of intended additions or replacements of sub-processors with reasonable advance notice by updating this page. If the Customer objects on reasonable data-protection grounds, we'll work with them to find a resolution; if none is possible, the Customer may terminate the Service.

7. Security

UGCABC implements appropriate technical and organisational measures to protect personal data — including encryption in transit and at rest, least-privilege access, audit logging, and continuous monitoring. A plain-English summary lives on our Security page; that page is honest about both what we do and what a pre-launch team cannot yet claim (no SOC 2 of our own yet, no formal bug bounty).

8. Data subject rights

We assist the Customer in responding to requests from data subjects (access, rectification, deletion, restriction, portability, objection) to the extent reasonably possible, taking into account the nature of the processing. Where a data subject contacts us directly, we forward the request to the Customer.

9. Personal data breaches

UGCABC will notify the Customer without undue delay — and in any event within 72 hours of becoming aware — of any confirmed personal data breach affecting the Customer's data. Notifications will include the nature of the breach, the categories and approximate number of data subjects and records concerned, likely consequences, and measures taken or proposed.

10. Deletion or return of personal data

On termination of the Service or at the Customer's written request, UGCABC will delete or return all Customer personal data within a reasonable period, and will delete existing copies unless retention is required by applicable law (for example, financial-records requirements). Sub-processor deletion propagates automatically for content stored on our behalf.

11. International transfers

Personal data may be transferred to, and processed in, jurisdictions outside the EEA / UK — primarily the United States — as reflected in the sub-processor table above. Such transfers rely on the European Commission's Standard Contractual Clauses (module 3, processor-to-processor, or module 2, controller-to-processor as applicable) and the UK Addendum, together with any supplementary measures reasonably required.

12. Audits

On reasonable prior written notice, and no more than once per year (or more frequently where required by a regulator or following a personal data breach), the Customer may request information necessary to demonstrate compliance with this DPA. Where the Customer requires an on-site audit, the parties will agree on the scope, timing and cost in advance. Third-party audit reports of our sub-processors (for example, Clerk's SOC 2 report) satisfy audit requests to the extent they cover the relevant processing.

13. Order of precedence

In the event of any conflict between this DPA and the main Terms of Service, this DPA prevails with respect to the processing of personal data.

14. Contact

For anything related to this DPA — a counter-signed copy, a specific data-processing question, a data subject request, or a suspected breach — email privacy@ugcabc.com.