Skip to content

Data Processing Addendum

Last updated: August 10, 2026

This Data Processing Addendum, or DPA, forms part of the agreement between the customer identified in an account, order, or other agreement ("Customer") and 1811 Labs (Vatsal Sanghvi), operating UGC Pulse, for the processing of Customer Personal Data. It applies when UGC Pulse processes personal data on Customer's behalf.

1. Definitions and scope

"Applicable Data Protection Law" means privacy and data protection law applicable to the processing. "Controller," "Processor," "Data Subject," "Personal Data," "Processing," and "Personal Data Breach" have the meanings given by applicable law. "Customer Personal Data" means Personal Data processed by UGC Pulse on Customer's behalf under the agreement.

This DPA does not govern data for which UGC Pulse acts as an independent Controller, including account administration, direct billing relationship data we control, service security, or public social data selected for UGC Pulse's own product purposes. Those activities are described in our Privacy Policy.

2. Roles and responsibilities

Where Customer determines the purposes and means of processing, Customer is the Controller and UGC Pulse is the Processor. Where Customer processes data for another Controller, Customer is a Processor and UGC Pulse is a subprocessor. References in this DPA to Controller and Processor include equivalent terms under applicable law.

Customer remains responsible for the lawfulness, fairness, transparency, accuracy, and proportionality of its instructions and Customer Personal Data. Customer will provide required notices, obtain required permissions, respond as Controller, and avoid instructing UGC Pulse to process data in violation of law or the agreement.

3. Documented instructions

UGC Pulse will process Customer Personal Data only on Customer's documented instructions, including instructions in the agreement, product configuration, authorized use of the Service, support requests, and this DPA. Customer instructs UGC Pulse to process data as needed to provide, secure, maintain, and support the Service and to make lawful transfers described in this DPA.

We may process Customer Personal Data where required by law. Unless prohibited, we will inform Customer before that processing. We will notify Customer if an instruction appears to violate Applicable Data Protection Law and may suspend the affected processing until the parties resolve the issue.

4. Confidentiality and personnel

UGC Pulse will authorize only personnel who need access to Customer Personal Data for their assigned duties. Authorized personnel are subject to confidentiality obligations or an appropriate statutory duty of confidentiality and receive privacy or security guidance appropriate to their role.

5. Security

Taking into account the state of the art, implementation cost, nature, scope, context, and purposes of processing, and risks to individuals, UGC Pulse will maintain appropriate technical and organizational measures designed to protect Customer Personal Data. The current categories of measures are described in the Security Schedule in Annex 2.

Customer is responsible for using available security features, protecting credentials, configuring access appropriately, and securely managing exports and data outside the Service.

6. Personal Data Breaches

UGC Pulse will notify Customer without undue delay after confirming a Personal Data Breach involving Customer Personal Data. The notice will include information reasonably available to help Customer meet applicable notification duties, such as the nature of the breach, affected data and people, likely consequences, mitigation, and a contact point. Information may be provided in phases as it becomes available.

We will take reasonable steps to contain, investigate, mitigate, remediate, and document the incident. A notice or cooperation under this section does not admit fault or liability. Customer is responsible for deciding whether and how to notify individuals or authorities unless law assigns that duty directly to UGC Pulse.

7. Assistance to Customer

Taking into account the nature of processing and information available to us, UGC Pulse will provide reasonable assistance with:

  • responding to verified data-subject requests when Customer cannot reasonably fulfil them through the Service;
  • security obligations, breach assessment, and legally required notifications;
  • data-protection impact assessments;
  • prior consultation with a regulator where required; and
  • information reasonably needed to demonstrate compliance with processor obligations.

If a Data Subject contacts us about Customer Personal Data, we will direct the person to Customer unless law permits or requires us to respond. Customer will reimburse reasonable costs for unusual or extensive assistance not caused by our breach, where permitted.

8. Subprocessors

Customer gives UGC Pulse general written authorization to appoint subprocessors needed to provide the Service. We will make the current list through our subprocessor page. Customers may request change notices at hello@ugcpulse.app.

We will provide advance notice of a new subprocessor when required by Applicable Data Protection Law or the agreement. Customer may make a reasonable objection based on documented data-protection grounds within the notice period. The parties will work in good faith on a commercially reasonable solution. If none is available, Customer may stop the affected processing or terminate the affected Service, subject to the agreement and mandatory law.

UGC Pulse will impose the same data-protection obligations required by applicable law on each subprocessor for the relevant processing. UGC Pulse remains responsible for a subprocessor's performance of those obligations to the extent required by applicable law and the agreement.

9. Return and deletion

During the term, Customer may use available product features to access or export Customer Personal Data. After termination or a valid instruction, UGC Pulse will delete or return Customer Personal Data, at Customer's choice where technically available, unless law requires retention.

Data deleted from active systems may remain in backups until normal backup rotation, generally within 90 days, while protected and not restored except for disaster recovery, security, or legal need. If restored, deletion instructions will be reapplied. Limited records may remain where law, fraud prevention, security, or legal claims require them.

10. Information and audits

On reasonable written request, UGC Pulse will provide information reasonably necessary to demonstrate compliance with this DPA. We may satisfy a request through security documentation, questionnaires, summaries, or an independent audit report if one is available.

If that information is insufficient and law requires an audit, Customer may conduct one no more than annually, or after a confirmed material incident, with reasonable advance notice. An audit must occur during normal business hours, minimize disruption, use a qualified independent auditor bound by confidentiality, follow reasonable security rules, and not expose another customer's data, confidential information, or security-sensitive details. Customer bears its audit costs unless the audit identifies our material breach.

11. International transfers

Customer authorizes processing in the United States, India, and other locations used by approved subprocessors, subject to Applicable Data Protection Law. Customer will not instruct a restricted transfer unless an appropriate mechanism and required information are in place.

For a transfer subject to the EU GDPR that lacks another valid mechanism, the EU Standard Contractual Clauses issued under Commission Implementing Decision (EU) 2021/914 are incorporated by reference. Module Two applies to Controller-to-Processor transfers and Module Three applies to Processor-to-Processor transfers, as relevant. The optional docking clause applies. The Annex 1 processing details and Annex 2 security measures below apply unless a signed annex states otherwise.

For a restricted transfer under UK law, the UK International Data Transfer Addendum to the EU Standard Contractual Clauses is incorporated when required. Party addresses, exporter details, competent authority, transfer role, and other mandatory fields may be supplied through an order form, account record, or signed annex. A transfer mechanism is not complete until all legally required fields and signatures or acceptance steps are supplied.

If a transfer clause conflicts with this DPA, the transfer clause controls for the restricted transfer. UGC Pulse will provide reasonable cooperation for a transfer assessment and supplementary measures where required.

12. US state privacy terms

Where US state privacy law applies and UGC Pulse processes Customer Personal Data as a service provider or contractor, UGC Pulse will not sell or share Customer Personal Data, retain, use, or disclose it outside the specified business purposes and direct relationship, or combine it with personal data received from another source, except as the law permits.

UGC Pulse will provide the same level of privacy protection required by applicable law, notify Customer if we determine we can no longer meet those obligations, and permit reasonable steps to stop and remediate unauthorized processing. Customer may monitor compliance through the information and audit process in Section 10.

13. India data-protection cooperation

Where the Digital Personal Data Protection Act, 2023 and its applicable rules govern Customer Personal Data, UGC Pulse will process on valid instructions, maintain reasonable safeguards, assist with breach and Data Principal obligations as described in this DPA, and delete data when the purpose and lawful retention end. Customer remains responsible for the required notice, consent or other lawful use, and instructions as Data Fiduciary.

14. Liability and order of precedence

The liability provisions in the agreement apply to this DPA to the maximum extent permitted by law. Nothing in this DPA limits a right or liability that cannot legally be limited.

If documents conflict, mandatory transfer clauses control for the relevant transfer, then this DPA controls for processing Customer Personal Data, then the agreement. A signed order may add stricter obligations expressly identified as overriding this DPA.

15. Term and contact

This DPA begins when Customer accepts or enters an agreement that incorporates it and continues while UGC Pulse processes Customer Personal Data. Sections intended to protect retained data survive termination.

DPA questions, notices, and requests may be sent to hello@ugcpulse.app.

Annex 1: Processing details

  • Subject matter: providing, securing, maintaining, and supporting UGC Pulse under Customer's instructions.
  • Duration: the agreement term plus the deletion and lawful-retention period described above.
  • Nature and purpose: hosting, storing, organizing, retrieving, transmitting, analyzing, and generating content as needed to provide requested features, support, security, and maintenance.
  • Processing frequency:continuous or as initiated by Customer and its authorized users during the term.
  • Categories of Data Subjects: Customer users, personnel, customers, prospects, creators, contacts, and other individuals whose data Customer submits or directs UGC Pulse to process.
  • Categories of Customer Personal Data: identity and contact data, account and organization data, Customer Content, prompts, selected public social data, usage and diagnostic data, support communications, and other data described in Customer's instructions.
  • Sensitive data: not intended for processing unless the parties expressly agree in writing and adopt required safeguards.
  • Retention: as described in Section 9, Customer's documented instructions, and the agreement, subject to legal retention.

Annex 2: Security Schedule

The measures below are maintained in a manner appropriate to the Service, risk, and available provider capabilities. They may evolve without materially reducing overall protection during the term.

  • access controls intended to limit production and customer-data access to authorized personnel with a legitimate need;
  • authentication and credential practices appropriate to the systems and provider capabilities in use;
  • use of reputable infrastructure providers and transport or storage protections available through their configured services;
  • logging, monitoring, dependency management, and investigation practices proportionate to the Service;
  • backup, recovery, retention, and deletion processes appropriate to system availability and legal requirements;
  • confidentiality commitments and access removal when access is no longer required; and
  • incident response processes for containment, investigation, mitigation, notification, and lessons learned.

No certification or audit standard is promised by this schedule. A certification applies only if UGC Pulse separately identifies it in writing and it remains current.