DPA The DPA, explained clearly.

Data Processing Agreement

When your users’ files pass through Uplint, you are the controller and we are the processor. This page explains what that means, what we commit to, who our sub-processors are, and how to get a signed copy.

Effective
10 September 2026
Last updated
10 September 2026
Version
4.0
Reading time
9 min
CURRENT SUB-PROCESSORS

The authoritative list. Changes are announced 30 days ahead. The storage providers you connect are your contracts and do not appear here.

ProviderPurposeLocationData involved
Amazon Web ServicesControl plane hosting, record store, logsUnited States (us-east-1, backups us-west-2)Account data, file records, event history
CloudflareDNS, CDN, DDoS protection, WAFGlobal edge networkRequest metadata (IP, headers)
StripePayments and invoicingUnited StatesBilling information
PostmarkTransactional emailUnited StatesEmail address, notification content
Plausible AnalyticsOpt-in website analyticsEuropean Union (Germany)Anonymous, aggregated usage
01

What a DPA is#

In short

A binding agreement that sets out how we process personal data on your behalf, and only on your behalf.

  • Required by GDPR whenever a processor handles personal data for a controller
  • You decide what data to collect and why; we process it on your instructions
  • Covers security, sub-processors, assistance, breach notice and deletion
  • Forms part of your contract with Uplint

The roles

  • You are the controller: you decide what data your product collects from your users and why.
  • Uplint is the processor: we act on your documented instructions and nothing else.

Why it matters

Your users' files are yours to protect. When they pass through Uplint — even though the bytes land in your own bucket — the file record, its metadata and the events around it are personal data in our care. The DPA is the legally binding commitment that we handle that data with the care GDPR requires of you.

What the agreement covers

  • The personal data we process and for what purpose
  • How we secure it: technical and organisational measures
  • Which third parties we rely on, and your rights around them
  • How we help you answer data-subject requests and regulators
  • What happens if there is a breach
  • Return and deletion when the relationship ends

What makes the Uplint DPA smaller than most

Uplint does not store file contents. Upload bodies stream through to your storage and are not retained; reads never pass through us. Our processing footprint is the record — IDs, names, sizes, locations, events — which keeps the scope of this agreement, and the risk it governs, deliberately narrow.

02

When you need one#

In short

If you have users in the EU or UK, serve regulated industries, or sell to enterprises, you need this.

  • Required for users in the EU/EEA under GDPR
  • Required for UK users under UK GDPR
  • Routinely required by enterprise procurement and security reviews
  • Healthcare customers need a Business Associate Agreement as well

You need a DPA if

  • You have users in the EU or EEA, or offer services to them
  • You have users in the United Kingdom
  • Your own customers require it in vendor assessments
  • You are pursuing SOC 2 or ISO 27001 and must document processors
  • You handle data for a regulated industry

Healthcare

If you process protected health information under HIPAA you also need a Business Associate Agreement. We provide one for Business and Enterprise plans — email compliance@uplint.dev.

You might not need one if

  • All your users are in the United States and no other framework applies
  • You process no personal data at all
  • You are only testing with synthetic data

When in doubt

Sign it. It costs nothing, takes minutes, and your customers will ask for it eventually.

03

Our commitments#

In short

We process only on your instructions, protect what we hold, help you comply, and delete on request.

  • Process personal data only on your documented instructions
  • Maintain the technical and organisational measures in section 7
  • Assist with data-subject requests, impact assessments and audits
  • Return and delete data when the agreement ends

1. Lawful processing

We process personal data only on your documented instructions — the API calls you make and the policies you set. We never use it for our own purposes and never sell or share it beyond the sub-processors listed here.

2. Security

We implement and maintain the measures described in section 7, review them regularly, and publish our controls on the security page.

3. Confidentiality

Everyone with access to personal data is bound by confidentiality obligations, and access is limited to those who need it to do their job.

4. Sub-processors

We use only the sub-processors listed in this agreement, flow down equivalent obligations to each of them, and give you 30 days notice of any change.

5. Assistance

We help you respond to data-subject requests, support breach notifications, provide information for data protection impact assessments, and cooperate with regulators and audits.

6. Return and deletion

At the end of the agreement we export your records in a standard format on request, delete everything we hold within 30 days, and certify deletion in writing. Objects in your storage are yours throughout and are never touched.

04

Your rights as controller#

In short

You can instruct us, audit us, take your data, and end the relationship.

  • Instruct how and where personal data is processed
  • Audit our practices — questionnaires, reports and assessments
  • Export file records and event history at any time
  • Terminate and receive certification of deletion

Instruct

Set the purposes and limits of processing, define retention, pin storage regions through policy, and instruct deletion. Your policies are the instructions; the audit log is the proof they were followed.

Audit

  • Request our security documentation and completed questionnaires
  • Review independent penetration-test summaries under NDA
  • Conduct a remote security assessment
  • Enterprise customers may arrange an on-site audit on reasonable notice

Access

Export records and events as JSON or CSV from the dashboard or API, and pull the full audit trail for any file. The objects themselves are already in your storage and need no export.

Terminate

End the agreement at any time, request deletion of everything we hold, and receive written confirmation. We provide a transition window for you to export records first.

05

Sub-processors#

In short

Five vetted providers, listed above. Your storage providers are not on the list — they are your contracts.

  • Five sub-processors today, all holding SOC 2 or an equivalent attestation
  • Each bound by data-processing terms at least as protective as these
  • 30 days notice before any addition, with a right to object
  • The storage providers you connect are not Uplint sub-processors

The current list

The table at the top of this page is the authoritative list, kept current as part of this agreement.

The storage providers you connect

Amazon S3, Azure Blob Storage, Google Cloud Storage, Cloudflare R2 or any S3-compatible store you route files to is contracted by you. Uplint writes and reads there only with the credential you supply and only on your instruction. They are your processors under your own DPA with them, not sub-processors of Uplint — which is also why Uplint cannot be compelled to hand over your file contents: we do not hold them.

Changes

  • We notify the account owner by email at least 30 days before adding or replacing a sub-processor
  • You may object within the notice period on reasonable data-protection grounds
  • If we cannot resolve the objection, you may terminate the affected services without penalty
06

Data locations and transfers#

In short

The record is hosted in the United States with Standard Contractual Clauses. File bytes go wherever your policy sends them, and stay there.

  • Control plane: AWS us-east-1, backups us-west-2
  • File bytes: the buckets and regions your policy selects
  • EU SCCs (2021, Module 2) included for transfers of record data
  • Residency is a routing rule available on every plan

Where the record lives

Data Primary Backup
File records and events AWS us-east-1 AWS us-west-2
Account data AWS us-east-1 AWS us-west-2
Request logs AWS us-east-1 30 days retention

Where the bytes live

Wherever your policy routes them, and only there. A residency rule pins a tenant, a file type or a whole product to a bucket in the region you choose — Frankfurt, Mumbai, a customer's own account. Uplint enforces the rule and records the placement; the object never transits our systems. See regulated software for how teams use this.

International transfers

For personal data in the record transferred from the EU or UK to the United States we rely on:

  • The EU Standard Contractual Clauses (2021), Module 2, controller to processor — incorporated into this agreement
  • The UK International Data Transfer Addendum
  • Supplementary measures: encryption in transit and at rest, access controls and audit logging, and a minimal data footprint by design

EU hosting of the record

Enterprise customers with a requirement for the record itself to be hosted in the EU should contact sales@uplint.dev.

07

Technical and organisational measures#

In short

Encryption, least privilege, monitoring, and a design that keeps the sensitive bytes out of our hands entirely.

  • AES-256 at rest for the record and credentials; TLS 1.3 in transit
  • Scoped API keys, MFA, role-based access, time-boxed support access
  • Continuous vulnerability scanning and independent penetration testing
  • Infrastructure providers holding SOC 2 Type II and ISO 27001

Technical measures

Encryption — record store and event log encrypted at rest with AES-256; storage credentials encrypted under a separate key in a managed KMS with rotation; TLS 1.3 for every connection.

Access control — role-based access in the dashboard, scoped API keys, multi-factor authentication for staff, and just-in-time support access that is visible in your audit log.

Network — private networks for internal services, a web application firewall and DDoS protection in front of every endpoint.

Monitoring — centralised logging, anomaly detection on API and credential use, automated alerting.

Organisational measures

  • Confidentiality agreements and security training for everyone with access
  • Least-privilege access, reviewed quarterly
  • Documented information-security, acceptable-use, incident-response and business-continuity policies
  • Independent penetration testing and continuous vulnerability scanning

Inherited controls

Uplint runs on cloud providers that hold SOC 2 Type II and ISO 27001; physical, environmental and network-layer controls are inherited from them. We publish our own controls on the security page rather than claiming certifications we do not hold.

Full detail

A complete description of our measures is available on request from security@uplint.dev.

08

Breach notification#

In short

You hear from us within 48 hours of a confirmed breach affecting your data, with what you need to meet your own obligations.

  • Notification within 48 hours — faster than GDPR’s 72
  • What happened, what was affected, and what we have done
  • Support for your notices to users and regulators
  • Regular updates until the matter is closed

Timeline

  • Detection: continuous monitoring for anomalies
  • Assessment: confirmation and scope within 24 hours of detection
  • Notification: the account owner notified within 48 hours of confirmation
  • Updates: at regular intervals until resolved

What the notice contains

  1. The nature of the breach
  2. The categories and approximate volume of data affected
  3. The likely consequences
  4. The measures taken and proposed
  5. A named contact for follow-up

What is, and is not, exposed

Because file contents are never stored on Uplint, a breach of our systems concerns the record — file names, sizes, locations and events — and not the files themselves. We say so plainly on the security page, and we will say so plainly in any notice.

Our support

We draft technical detail for your regulator, help you word notices to your users, document the timeline, and cooperate with any investigation.

09

How to get your DPA#

In short

Generate a countersigned copy from the dashboard. Enterprise customers can negotiate custom terms.

  • Available on every paid plan
  • Pre-signed by Uplint; executed instantly when you accept
  • Includes SCCs and the annexes on measures, sub-processors and processing details
  • Custom terms and a BAA available for Enterprise

Pro and Business plans

  1. Sign in to the dashboard
  2. Open Settings → Legal
  3. Choose Generate DPA and enter your company details
  4. Download the countersigned copy

Enterprise plans

Custom processing terms, jurisdiction-specific clauses, on-site audit provisions and EU hosting of the record can be agreed in your contract. Email sales@uplint.dev.

What is included

  • GDPR-compliant processing terms
  • EU Standard Contractual Clauses (2021) and the UK Addendum
  • Annex I: details of processing
  • Annex II: technical and organisational measures
  • Annex III: sub-processors

Need a BAA?

For HIPAA, a Business Associate Agreement is available on Business and Enterprise plans — compliance@uplint.dev.

QUESTIONS

Prefer a form? Every inbox is on the contact page. Postal address: Uplint, 548 Market Street, Suite 35000, San Francisco, CA 94104, United States.