Legal

Data Processing
Addendum.

For customers who require a formal DPA when Ugrat processes personal data on their behalf.

Last updated: 2026-01-15

1. Roles

When you use Ugrat to send messages on behalf of your end users, you act as data controller and Ugrat acts as data processor for the personal data contained in those messages and recipient phone numbers.

2. Scope of processing

Ugrat processes personal data only to deliver messages, operate the platform, prevent fraud, and meet legal obligations — and only on documented instructions from you.

3. Sub-processors

Current sub-processors: Turkmen mobile operators (SMS routing) and our billing processor. We will give 30 days' notice before adding or replacing a sub-processor.

4. Security measures

Ugrat implements the technical and organisational measures described in our Security page, including encryption, access controls, and incident response procedures.

5. Data subject requests

If we receive a request directly from a data subject, we will redirect it to you. We will assist you in fulfilling such requests within reasonable cooperation.

6. Data breach

We notify you in writing within 72 hours of becoming aware of a personal data breach affecting your data, with all information reasonably required for you to meet your own notification obligations.

7. Audits

We provide on request the latest reports demonstrating compliance with these obligations. Customers on Enterprise plans may request an audit once per year, with 30 days' notice.

8. Termination

On termination, we delete or return personal data within 90 days, except where retention is required by law.

9. How to execute

To countersign this DPA, email legal@ugrat.com with your company name, address, and authorised signatory. We return a signed copy within 5 business days.