Data Processing Agreement
Last updated: 28 July 2026 - CloudOps S.L.
This Data Processing Agreement ("DPA") forms part of the UxxU Terms of Service (the "Agreement") between CloudOps S.L. ("UxxU", "we", "us") and the customer entity that has accepted the Agreement ("Customer", "you").
This DPA applies where UxxU processes Personal Data on your behalf while providing the UxxU platform and that processing is subject to the EU GDPR, UK GDPR, or Swiss Federal Act on Data Protection. You accept this DPA when you accept the Agreement. No separate signature is required.
1. Roles of the Parties
You are the controller of Personal Data you submit to the Platform. You decide what data is entered, who may access it, and for what purpose.
UxxU acts as processor for that data and processes it only on your documented instructions as set out in this DPA and the Agreement. Where UxxU determines its own purposes, including billing, account administration, security, and website analytics, CloudOps S.L. acts as controller and the Privacy Policy applies.
2. Scope of Processing
The subject matter, duration, nature, purpose, categories of data, and categories of data subjects are described in Annex 1. In summary, UxxU processes account identity data for your users and content you choose to place in architecture models to provide, secure, and support the Platform.
3. Customer Instructions
We process Customer Personal Data only on documented instructions. The Agreement, this DPA, and your ordinary use and configuration of the Platform constitute your instructions.
We will inform you if, in our opinion, an instruction infringes applicable data protection law. We may decline to follow an unlawful instruction.
4. Confidentiality
Every person authorised by UxxU to process Customer Personal Data is bound by a contractual or statutory duty of confidentiality. Access to production data is limited to the founder and is used only where necessary for support, incident response, or maintenance.
5. Security Measures
We maintain appropriate technical and organisational measures under Article 32 GDPR. The measures are summarised in Annex 3 and described on our Security page. We may update these measures, but will not materially reduce the overall security of the Platform.
6. Subprocessors
You give general authorisation for UxxU to use subprocessors to provide the Platform. Our current providers and their roles are listed on the Subprocessors page.
We will give at least 30 days' notice before a new subprocessor begins processing Customer Personal Data by updating the Subprocessors page and notifying subscribers to that page's change notifications. You may object on reasonable data protection grounds within that period by contacting us. If we cannot provide a reasonable alternative, you may terminate the affected service and receive a pro-rata refund of applicable prepaid fees.
We impose data protection obligations on subprocessors that provide protection appropriate to their processing, and remain responsible for their processing as required by applicable law.
7. International Transfers
The primary UxxU application and data region is AWS US East (N. Virginia), us-east-1. This means Customer Personal Data may be processed in the United States.
Amazon Web Services, Inc. is a covered entity under the Amazon.com, Inc. certification to the EU-US Data Privacy Framework. Transfers of Customer Personal Data to AWS in the United States rely on the European Commission's adequacy decision under Article 45 GDPR while that certification and decision remain valid.
Where a restricted transfer requires an Article 46 safeguard, the applicable European Commission Standard Contractual Clauses, including Module Three for processor-to-processor transfers, are incorporated by reference. The UK International Data Transfer Addendum and required Swiss adaptations apply where relevant. Transfer information is maintained on the Subprocessors page.
8. Assistance With Data Subject Requests
The Platform provides export and erasure-request tools to help you respond to data subject requests. Where those tools are insufficient, we will provide reasonable assistance taking into account the nature of processing and information available to us.
If we receive a request directly from one of your data subjects concerning Customer Personal Data, we will redirect the person to you and inform you without responding substantively, unless legally required to do otherwise.
9. Assistance With Articles 32-36
Taking into account the nature of processing and information available to us, we will provide reasonable assistance with security, breach notification, data protection impact assessments, and prior consultation obligations.
10. Personal Data Breaches
We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and in any event within 72 hours. To the extent known, the notice will describe the nature of the breach, affected categories and approximate numbers, likely consequences, and measures taken or proposed. Information may be provided in phases as it becomes available.
Notice will be sent to the administrative contact associated with your account. You are responsible for keeping that address current.
11. Deletion and Return
On termination or expiry of the Agreement, we will delete Customer Personal Data within 30 days, except where retention is required by law or content remains under the control of another authorised member of a shared organisation. You may export organisation content using the Platform's project export tools before deletion.
Residual database copies expire through the ordinary automated Amazon RDS backup cycle, which currently has a 14-day retention period. Those copies remain protected by this DPA until they expire.
12. Audit and Information
We will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR, including this DPA, its annexes, the Security page, and responses to reasonable written security questionnaires.
Where further assurance is reasonably required, we will cooperate in good faith. Any inspection requires reasonable prior written notice, appropriate confidentiality commitments, an agreed scope, and must avoid unreasonable disruption. Unless required following an incident or by a supervisory authority, an inspection may occur no more than once in any 12-month period and is at the Customer's cost.
13. Certification
UxxU does not currently hold ISO 27001, SOC 2, or an equivalent independent certification and does not represent otherwise. The measures described in Annex 3 and on our Security page reflect current implemented controls.
14. Liability, Term, and Precedence
This DPA is subject to the limitations and exclusions of liability in the Agreement. It begins when you accept the Agreement and continues while we process Customer Personal Data on your behalf.
If documents conflict, the order of precedence is the applicable Standard Contractual Clauses, this DPA, and then the Agreement.
15. Contact
Questions and data protection notices may be sent to info@uxxu.io.
CloudOps S.L.
Registered in Spain
CIF: B10716553
Annex 1 - Details of Processing
Subject matter
Provision of the UxxU software architecture Platform.
Duration
The term of the Agreement plus the deletion period described in Section 11.
Nature and purpose
Hosting, storage, transmission, display, backup, and processing of Customer content and account data as necessary to operate, secure, support, and maintain the Platform.
Categories of data subjects
- Customer personnel who hold UxxU user accounts.
- Individuals the Customer names or describes in architecture content, such as system owners, stakeholders, or contacts.
Categories of Personal Data
- Account data: name, email, password hash, organisation membership, role, authentication, and session metadata.
- Usage and technical data: IP address, timestamps, application logs, and API key identifiers.
- Customer content: Personal Data the Customer chooses to include in models, diagrams, documentation, links, or uploaded files.
Special-category data
None is requested or required. The Platform is not designed for special-category data under Article 9 GDPR, and Customers must not submit it unless separately agreed in writing.
Annex 2 - Subprocessors and AI Providers
The current provider list and transfer information are maintained at uxxu.io/subprocessors.
The hosted UxxU application does not currently send Customer architecture content to OpenAI, Anthropic, or another LLM provider. UxxU MCP integrations run in the Customer's chosen AI environment and use the Customer's provider relationship and configuration.
Annex 3 - Technical and Organisational Measures
Encryption
HTTPS/TLS and HSTS protect data in transit. Amazon RDS and the UxxU S3 buckets use managed encryption at rest. Passwords are stored as one-way bcrypt hashes.
Access control
Protected API requests pass through backend authorisation using authenticated user and organisation context. Browser sessions use Secure, HttpOnly, SameSite cookies; access tokens are short-lived and refresh credentials are rotated and checked against server-side hashed records.
Minimisation and retention
Application logging is designed to exclude credentials, cookies, message contents, and sensitive fields. Production application logs are retained for 90 days. Automated routines minimise or remove selected feedback, waitlist, history, reset, session, and privacy-request records.
Availability and backup
UxxU uses managed AWS application, database, and storage services. Automated Amazon RDS backups run daily and are retained for 14 days. Backup data is encrypted at rest in the same AWS region as the production database.
Internal access
Access to production data is limited to the founder on a need-to-access basis for support, incident response, and maintenance.
Vulnerability reporting
Security concerns may be reported to info@uxxu.io. Further information is available on the Security page.