Data Processing Agreement
Last updated: August 2026
1. About this DPA
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you (“Customer”) and UGCABC and applies whenever we process personal data on your behalf in the course of providing the Service. It reflects the requirements of the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”) and the UK GDPR.
If your organisation requires a counter-signed copy for your records, email privacy@ugcabc.com with your entity name and address and we'll return one signed.
2. Roles
For personal data submitted to, or generated by, the Service in the context of your account, the Customer acts as the Data Controller and UGCABC acts as the Data Processor. UGCABC processes such data only on the Customer's documented instructions, which are the Terms of Service and any settings the Customer configures in the app.
3. Nature and purpose of processing
We process personal data solely to provide and operate the Service: generating AI video ads from Customer-supplied product inputs, storing renders and assets, managing accounts and billing, providing support, ensuring security, and meeting legal obligations.
4. Categories of data subjects and personal data
- Data subjects: Customer's account users (typically the Customer's employees or contractors); recipients of ads generated with the Service (indirectly, via any personal data shown in the ad script or composited assets the Customer uploads).
- Personal data: account identifiers (name, email, workspace name); authentication and session data (via Clerk); billing identifiers (payment reference from Paytree); content the Customer uploads (product images, scripts, brand assets, and — for custom avatars — a photo of the person to be depicted, which is personal data of a heightened kind); usage metadata (pages viewed, features used, render history, IP address, user-agent, error diagnostics).
5. Duration
Processing continues for the term of the underlying Terms of Service. On termination, section 10 below governs deletion.
6. Sub-processors
UGCABC engages the sub-processors listed below to help provide the Service. Each is bound by contractual obligations equivalent to those in this DPA. We remain responsible to the Customer for the performance of each sub-processor.
| Sub-processor | Purpose | Primary region |
|---|---|---|
| Clerk, Inc. | Authentication, session management, MFA | United States |
| Neon (Postgres) | Application database | European Union |
| Amazon Web Services (S3, Lambda, SQS) | Media storage, background rendering, job queue | United States |
| Vercel | Application hosting, edge network, log processing | Global CDN |
| Paytree (payment-crm-eu.com) | Payment processing — receives your name, email, IP address and billing country at checkout | European Union |
| Stripe | Card processing on the hosted checkout page Paytree routes you to | United States |
| Topview | Upstream AI video generation vendor | Singapore |
| Anthropic | Script writing and caption translation (product text and scripts only) | United States |
| ElevenLabs | Voice synthesis for voiceovers and speech recognition for caption timing (script text, finished audio) | United States |
| Microsoft (Edge TTS) | Fallback voice synthesis (script text) | United States |
| Replicate | Legacy avatar rendering for non-catalogue avatars (avatar image, audio) | United States |
| Tawk.to | Support chat widget (chat messages, browser metadata) | United States |
| Resend | Transactional email delivery | United States |
| PostHog (EU) | Product analytics, aggregated usage | European Union |
| Sentry | Error monitoring and diagnostics | United States |
We'll notify Customer of intended additions or replacements of sub-processors with reasonable advance notice by updating this page. If the Customer objects on reasonable data-protection grounds, we'll work with them to find a resolution; if none is possible, the Customer may terminate the Service.
7. Security
UGCABC implements appropriate technical and organisational measures to protect personal data — including encryption in transit and at rest, least-privilege access, audit logging, and continuous monitoring. A plain-English summary lives on our Security page; that page is honest about both what we do and what a pre-launch team cannot yet claim (no SOC 2 of our own yet, no formal bug bounty).
8. Data subject rights
We assist the Customer in responding to requests from data subjects (access, rectification, deletion, restriction, portability, objection) to the extent reasonably possible, taking into account the nature of the processing. Where a data subject contacts us directly, we forward the request to the Customer.
9. Personal data breaches
UGCABC will notify the Customer without undue delay — and in any event within 72 hours of becoming aware — of any confirmed personal data breach affecting the Customer's data. Notifications will include the nature of the breach, the categories and approximate number of data subjects and records concerned, likely consequences, and measures taken or proposed.
10. Deletion or return of personal data
On termination of the Service or at the Customer's written request, UGCABC will delete or return all Customer personal data within a reasonable period, and will delete existing copies unless retention is required by applicable law (for example, financial-records requirements). Sub-processor deletion propagates automatically for content stored on our behalf.
11. International transfers
Personal data may be transferred to, and processed in, jurisdictions outside the EEA / UK — primarily the United States — as reflected in the sub-processor table above. Such transfers rely on the European Commission's Standard Contractual Clauses (module 3, processor-to-processor, or module 2, controller-to-processor as applicable) and the UK Addendum, together with any supplementary measures reasonably required.
12. Audits
On reasonable prior written notice, and no more than once per year (or more frequently where required by a regulator or following a personal data breach), the Customer may request information necessary to demonstrate compliance with this DPA. Where the Customer requires an on-site audit, the parties will agree on the scope, timing and cost in advance. Third-party audit reports of our sub-processors (for example, Clerk's SOC 2 report) satisfy audit requests to the extent they cover the relevant processing.
13. Order of precedence
In the event of any conflict between this DPA and the main Terms of Service, this DPA prevails with respect to the processing of personal data.
14. Contact
For anything related to this DPA — a counter-signed copy, a specific data-processing question, a data subject request, or a suspected breach — email privacy@ugcabc.com.