Data Processing
Addendum.
For customers who require a formal DPA when Ugrat processes personal data on their behalf.
1. Roles
When you use Ugrat to send messages on behalf of your end users, you act as data controller and Ugrat acts as data processor for the personal data contained in those messages and recipient phone numbers.
2. Scope of processing
Ugrat processes personal data only to deliver messages, operate the platform, prevent fraud, and meet legal obligations — and only on documented instructions from you.
3. Sub-processors
Current sub-processors: Turkmen mobile operators (SMS routing) and our billing processor. We will give 30 days' notice before adding or replacing a sub-processor.
4. Security measures
Ugrat implements the technical and organisational measures described in our Security page, including encryption, access controls, and incident response procedures.
5. Data subject requests
If we receive a request directly from a data subject, we will redirect it to you. We will assist you in fulfilling such requests within reasonable cooperation.
6. Data breach
We notify you in writing within 72 hours of becoming aware of a personal data breach affecting your data, with all information reasonably required for you to meet your own notification obligations.
7. Audits
We provide on request the latest reports demonstrating compliance with these obligations. Customers on Enterprise plans may request an audit once per year, with 30 days' notice.
8. Termination
On termination, we delete or return personal data within 90 days, except where retention is required by law.
9. How to execute
To countersign this DPA, email legal@ugrat.com with your company name, address, and authorised signatory. We return a signed copy within 5 business days.