What a DPA is#
A binding agreement that sets out how we process personal data on your behalf, and only on your behalf.
- Required by GDPR whenever a processor handles personal data for a controller
- You decide what data to collect and why; we process it on your instructions
- Covers security, sub-processors, assistance, breach notice and deletion
- Forms part of your contract with Uplint
The roles
- You are the controller: you decide what data your product collects from your users and why.
- Uplint is the processor: we act on your documented instructions and nothing else.
Why it matters
Your users' files are yours to protect. When they pass through Uplint — even though the bytes land in your own bucket — the file record, its metadata and the events around it are personal data in our care. The DPA is the legally binding commitment that we handle that data with the care GDPR requires of you.
What the agreement covers
- The personal data we process and for what purpose
- How we secure it: technical and organisational measures
- Which third parties we rely on, and your rights around them
- How we help you answer data-subject requests and regulators
- What happens if there is a breach
- Return and deletion when the relationship ends
What makes the Uplint DPA smaller than most
Uplint does not store file contents. Upload bodies stream through to your storage and are not retained; reads never pass through us. Our processing footprint is the record — IDs, names, sizes, locations, events — which keeps the scope of this agreement, and the risk it governs, deliberately narrow.