Data Processing Agreement

Version: September 8, 2026

This English version is a translation. The binding version of this agreement is the German one: view the German version

Parties

This data processing agreement is concluded between

the holder of the uplads account through which the uplads.com service is used, as the controller (the „controller“),

and

replient.ai Software GmbH
Derflerstraße 27/1
4040 Lichtenberg, Austria
as the processor (the „processor“, controller and processor together the „parties“).

Preamble

The controller has engaged the processor under the existing contract for the use of uplads.com (the „main contract“) for the services described therein. Performing that contract involves processing personal data. Art. 28 GDPR in particular sets requirements for such processing. To meet those requirements, the parties conclude the following data processing agreement (the „agreement“), the performance of which is not remunerated separately unless expressly agreed.

Section 1 Definitions

(1) The controller, pursuant to Art. 4(7) GDPR, is the body which alone or jointly with others determines the purposes and means of the processing of personal data.

(2) The processor, pursuant to Art. 4(8) GDPR, is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

(3) Personal data, pursuant to Art. 4(1) GDPR, is any information relating to an identified or identifiable natural person (the „data subject“); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

(4) Special categories of personal data are personal data pursuant to Art. 9 GDPR revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, personal data pursuant to Art. 10 GDPR relating to criminal convictions and offences or related security measures, as well as genetic data pursuant to Art. 4(13) GDPR, biometric data pursuant to Art. 4(14) GDPR, health data pursuant to Art. 4(15) GDPR and data concerning a natural person’s sex life or sexual orientation.

(5) Processing, pursuant to Art. 4(2) GDPR, is any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

(6) A supervisory authority, pursuant to Art. 4(21) GDPR, is an independent public authority established by a member state pursuant to Art. 51 GDPR.

Section 2 Subject matter

(1) The processor provides the controller with the services set out in the main contract. In doing so, the processor obtains access to personal data which it processes for the controller exclusively on the controller’s behalf and instructions. The scope and purpose of the processing follow from the main contract and any associated service descriptions. Assessing the lawfulness of the processing is the controller’s responsibility.

(2) The parties conclude this agreement in order to specify their mutual data protection rights and obligations. In case of doubt, the provisions of this agreement take precedence over those of the main contract.

(3) This agreement applies to all activities connected with the main contract in which the processor, its employees or persons commissioned by the processor come into contact with personal data originating from the controller or collected for the controller.

(4) The term of this agreement follows the term of the main contract, unless the following provisions give rise to obligations or termination rights that extend beyond it.

Section 3 Right to issue instructions

(1) The processor may only collect, process or use data within the scope of the main contract and in accordance with the controller’s instructions. If the processor is required to carry out further processing by the law of the European Union or of a member state to which it is subject, it shall inform the controller of those legal requirements before processing.

(2) The controller’s instructions are initially set out in this agreement and may subsequently be amended, supplemented or replaced by the controller in writing or in text form by individual instructions. The controller is entitled to issue such instructions at any time. This includes instructions concerning the rectification, erasure and restriction of data.

(3) The controller shall document all instructions issued. Instructions that go beyond the service agreed in the main contract are treated as a request to change the service.

(4) If the processor considers that an instruction of the controller infringes data protection law, it shall inform the controller without undue delay. The processor is entitled to suspend the execution of the instruction concerned until it is confirmed or amended by the controller. The processor may refuse to carry out a manifestly unlawful instruction.

(5) Operating the application by the controller, its users and the AI assistants it has connected constitutes an instruction within the meaning of this agreement. This applies in particular to uploading creatives, creating and launching campaigns, and using the AI features.

Section 4 Types of data, categories of data subjects, third countries

(1) In performing the main contract, the processor obtains access to the personal data specified in Annex 1.

(2) The categories of data subjects are set out in Annex 2.

(3) Personal data may be transferred to a third country (outside the EEA) subject to the conditions of Art. 44 et seq. GDPR.

Section 5 Protective measures taken by the processor

(1) The processor is obliged to observe the statutory data protection provisions and not to disclose information obtained from the controller’s sphere to third parties or expose it to their access. Documents and data shall be secured against access by unauthorised persons, taking the state of the art into account.

(2) Within its area of responsibility, the processor shall organise its internal operations so that they meet the specific requirements of data protection. It has implemented the technical and organisational measures set out in Annex 3 for the appropriate protection of the controller’s data pursuant to Art. 32 GDPR, which the controller acknowledges as appropriate. The processor reserves the right to change the security measures taken while ensuring that the contractually agreed level of protection is not undercut.

(3) Persons employed by the processor in the processing of data are prohibited from collecting, processing or using personal data without authorisation. The processor shall place all persons entrusted with performing this contract (the „employees“) under a corresponding obligation of confidentiality pursuant to Art. 28(3)(b) GDPR and shall ensure compliance with due care.

(4) The processor has appointed a data protection officer. The processor’s data protection officer is heyData GmbH, Schützenstr. 5, 10117 Berlin, datenschutz@heydata.eu, www.heydata.eu.

Section 6 The processor’s duties to inform

(1) In the event of disruptions, suspected data protection breaches or breaches of the processor’s contractual obligations, suspected security incidents or other irregularities in the processing of personal data by the processor, by persons employed by it under the contract or by third parties, the processor shall inform the controller without undue delay. The same applies to inspections of the processor by the data protection supervisory authority. A notification of a personal data breach shall contain at least the following information:

  1. a description of the nature of the personal data breach including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
  2. a description of the measures taken or proposed by the processor to address the breach and, where appropriate, measures to mitigate its possible adverse effects;
  3. a description of the likely consequences of the personal data breach.

(2) The processor shall without undue delay take the measures necessary to secure the data and to mitigate possible adverse consequences for the data subjects, shall inform the controller accordingly and shall request further instructions.

(3) The processor is further obliged to provide the controller with information at any time in so far as the controller’s data is affected by a breach under paragraph 1.

(4) The processor shall inform the controller of material changes to the security measures under Section 5(2).

Section 7 The controller’s audit rights

(1) The controller may satisfy itself of the processor’s technical and organisational measures before processing begins and annually thereafter. For this purpose it may, for example, obtain information from the processor, request existing expert attestations, certifications or internal audit reports, or inspect the processor’s technical and organisational measures itself during normal business hours after timely coordination, or have them inspected by a qualified third party who is not a competitor of the processor. The controller shall carry out audits only to the extent necessary and shall not disproportionately disrupt the processor’s operations.

(2) The processor undertakes to provide the controller, upon oral or written request and within a reasonable period, with all information and evidence required to carry out an audit of the processor’s technical and organisational measures.

(3) The controller shall document the audit result and communicate it to the processor. In the event of errors or irregularities which the controller identifies, in particular when reviewing the results of the processing, it shall inform the processor without undue delay. If the audit identifies matters whose future avoidance requires changes to the prescribed procedure, the controller shall notify the processor of the necessary changes without undue delay.

Section 8 Use of service providers

(1) The contractually agreed services are performed with the involvement of the service providers listed in Annex 4 (the „subprocessors“). The controller grants the processor its general authorisation within the meaning of Art. 28(2) sentence 1 GDPR to engage further subprocessors or to replace existing ones within the scope of its contractual obligations.

(2) The processor shall inform the controller in advance by email to the address held in the uplads account of any intended change regarding the addition or replacement of a subprocessor. The controller may object to an intended addition or replacement of a subprocessor on important data protection grounds.

(3) An objection must be raised within 2 weeks of the information being sent. If no objection is raised, the addition or replacement is deemed approved. If there is an important data protection ground and no amicable solution can be found between the controller and the processor, the controller has a special right of termination effective at the end of the month following the objection.

(4) When engaging subprocessors, the processor shall place them under obligations corresponding to those of this agreement.

(5) A subprocessing relationship within the meaning of these provisions does not exist where the processor commissions third parties with services that are purely ancillary. These include, for example, postal, transport and shipping services, cleaning services, telecommunications services without a specific connection to the services the processor provides for the controller, and security services. Maintenance and inspection services constitute subprocessing relationships requiring consent in so far as they are provided for IT systems that are also used in connection with providing services for the controller.

(6) The advertising platforms with which the controller connects its own ad account (Annex 4, section 2) are not subprocessors of the processor. The processor transmits data to them exclusively on the controller’s instructions. That processing is governed by the contractual relationship between the controller and the platform concerned.

(7) Personal data may be transferred to a third country (outside the EEA) subject to the conditions of Art. 44 et seq. GDPR.

Section 9 Data subject requests and rights

(1) The processor shall, as far as possible, assist the controller with appropriate technical and organisational measures in fulfilling its obligations under Art. 12 to 22 and 32 to 36 GDPR.

(2) If a data subject asserts rights, such as access, rectification or erasure of their data, directly against the processor, the processor shall not act on its own initiative but shall refer the data subject to the controller and await the controller’s instructions.

Section 10 Liability

(1) As between the parties, the controller alone is responsible towards the data subject for compensating damage suffered by a data subject as a result of processing or use that is unlawful or incorrect under data protection law in the context of the processing on behalf.

(2) The processor is liable without limitation for damage where the cause of the damage rests on an intentional or grossly negligent breach of duty by the processor, its legal representative or vicarious agent.

(3) For negligent conduct, the processor is liable only for the breach of a duty whose fulfilment makes the proper performance of the contract possible in the first place and on whose observance the controller regularly relies and may rely, and then limited to the typical foreseeable damage. Otherwise the processor’s liability, including for its vicarious agents, is excluded.

(4) The limitation of liability under Section 10(3) does not apply to claims for damages arising from injury to life, body or health, or from the assumption of a guarantee.

Section 11 Termination of the main contract

(1) Upon termination of the main contract, the processor shall return to the controller all documents, data and data carriers provided to it or, at the controller’s request and unless Union law or other applicable national law requires the personal data to be stored, delete them. This also covers any backups held by the processor. The processor shall, on request, provide documented evidence of proper deletion.

(2) The controller has the right to verify, in an appropriate manner, the complete and contractually compliant return or deletion of the data by the processor.

(3) The processor is obliged to treat data that has become known to it in connection with the main contract confidentially even after the main contract has ended. This agreement remains valid beyond the end of the main contract for as long as the processor holds personal data that was transmitted to it by the controller or that it collected for the controller.

Section 12 Final provisions

(1) In so far as the processor does not expressly perform support activities under this agreement free of charge, it may invoice the controller a reasonable fee, unless the processor’s own acts or omissions made that support directly necessary.

(2) Amendments and additions to this agreement must be made in text form. This also applies to a waiver of this formal requirement. The precedence of individually agreed terms remains unaffected.

(3) Should individual provisions of this agreement be or become wholly or partly invalid or unenforceable, the validity of the remaining provisions is not affected.

(4) This agreement is governed by Austrian law.

Section 13 Conclusion

(1) This agreement forms part of the main contract and is concluded together with it. On acceptance of the terms of service this agreement is deemed concluded as well. No separate signature is required.

(2) On request the processor provides a signed counterpart carrying the controller’s details. An email to office@replient.ai stating the controller’s company name and full address is sufficient.

(3) The current version is available at uplads.com/dpa, and the subprocessor list additionally at uplads.com/subprocessors. The version in force at the time of use applies. Changes are made in accordance with Section 12(2) and, where they concern subprocessors, Section 8.

Annex 1: Description of the data and data categories

In providing the contractually agreed service (a SaaS solution for creating, managing and analysing advertisements on connected advertising platforms in bulk), the processor obtains access to the following types and categories of personal data:

1. Master and identification data

  • First and last names of the controller’s users
  • Email addresses of users and of the team members they invite
  • Company and billing details of the controller
  • Names and identifiers of the connected ad accounts, pages, profiles and organisations

2. Content data

  • Uploaded creatives (images, videos) including the people depicted in them
  • Ad copy, headlines, descriptions and destination URLs
  • Brand context stored by the controller, and prompts and results of the AI features
  • Transcripts of the audio track of uploaded videos, produced to analyse and tag creatives
  • Support messages and files sent with them

When the AI features are used, creatives, ad copy and brand context are transmitted to the AI provider concerned. This covers images and individual video frames for image analysis, and the audio track extracted from videos for transcription. Where those features are not used, no transmission to AI providers takes place.

Note: creatives and free-text fields are unstructured content. They may contain personal data of third parties, such as testimonials or employees who appear in them. The controller decides which content it uploads.

3. Ad account and performance data

  • Campaign, ad set and ad structures of the connected ad accounts
  • Targeting and placement settings, budgets and bids
  • Aggregated performance metrics (impressions, clicks, cost, conversions). These relate to advertising activity, not to individual end users.
  • Identifiers of connected pixels, datasets and custom audiences (without their contents)

4. Metadata and communication data

  • IP addresses and HTTP metadata
  • Access and refresh tokens for the connected platforms, stored encrypted
  • Credentials the controller stores for its own services, such as API keys for AI providers, Slack webhooks or ClickUp tokens, stored encrypted
  • Session data, job identifiers and logs of background processing

5. Usage data

  • Log data on interaction with the application, including session replay
  • Consumption and billing data for the AI features

Customer lists, hashed lists and other raw audience data of the controller are not subject to the processing. Of custom audiences, only the identifier, name, type and size indication are processed, not their contents; matching takes place exclusively inside the respective advertising platform. Of lead forms, only the identifier, name, status, locale and creation time are processed, not the data subjects’ submissions received through those forms.

Annex 2: Description of the data subjects

  • Users and employees of the controller: people who hold an uplads login or have been invited into a workspace.
  • Clients of the controller: people whose ad accounts the controller manages through uplads, and their contacts.
  • People depicted in creatives: third parties visible or audible in the uploaded images or videos, such as models, testimonials or employees.
  • People named in ad copy: third parties named in texts, brand context or prompts.
  • Support contacts: people who write to the processor via the live chat or by email.

Annex 3: Technical and organisational measures

This annex summarises the measures within the meaning of Art. 32(1) GDPR with which the processor protects personal data.

Confidentiality (Art. 32(1)(b) GDPR)

Physical access control

  • Operation exclusively in the data centres of professional providers with physical access control (Annex 4). No own server hardware is operated.
  • Instruction to employees not to work in publicly accessible spaces
  • Home office work: instruction to employees to work, where possible, in a study separated from living areas

System access control

  • Authentication with username and password; passwords are stored hashed only
  • Two-factor authentication for all administrative access
  • Server access exclusively via SSH keys, no password login
  • Automatic screen lock and instruction to lock the workstation when leaving it

Data access control

  • Tenant separation at database level through row level security: every query is limited to the data of the account concerned
  • Role model within a workspace (full access, editor, view only)
  • Encrypted storage of the access tokens for the advertising platforms (AES-256), with the key held separately from the database
  • Credentials the controller stores for third-party services are held encrypted and are not returned to the browser
  • Logging of access as well as of creation, modification and deletion of data
  • The number of administrators is kept as small as possible

Separation control

  • Separation of production and test systems
  • Separate database and storage areas per account

Integrity (Art. 32(1)(b) GDPR)

Transfer control

  • Transport encryption (TLS) for all connections to the application and to the APIs
  • Encrypted storage of creatives in the object store
  • Access to uploaded creatives only through short-lived, signed links
  • Logging of access and retrieval

Input control

  • Logging of the entry, modification and deletion of data
  • Traceability through individual user accounts, no shared accounts
  • Complete history of every launch and every change to an ad

Availability and resilience (Art. 32(1)(b) GDPR)

  • Daily database backups by the database provider
  • Hosting with professional providers on redundant infrastructure
  • Monitoring of the application and background processes with automatic alerting
  • Separation of operating system and data

Procedures for regular review, assessment and evaluation (Art. 32(1)(d), Art. 25(1) GDPR)

Data protection management

  • Appointment of heyData GmbH as external data protection officer
  • Use of the heyData platform for data protection management
  • Employees bound to data secrecy
  • Regular data protection training for employees
  • Maintaining a record of processing activities (Art. 30 GDPR)

Incident response management

  • Notification process for personal data breaches to the supervisory authorities (Art. 33 GDPR)
  • Notification process for personal data breaches to data subjects (Art. 34 GDPR)
  • Involvement of the data protection officer in security incidents and data breaches
  • Central error capture with evaluation and follow-up

Data protection by design and by default (Art. 25(2) GDPR)

  • Employee training in privacy by design and privacy by default
  • No more personal data is collected than is necessary for the respective purpose.
  • Connections to advertising platforms and cloud storage are created only when the controller establishes them.

Commissioning control

  • Instructions to subprocessors in text form, regularly by data processing agreement
  • Careful selection of contractors, in particular with regard to data security
  • Ongoing review of contractors and their activities
  • Ensuring deletion of data after the end of the engagement

Annex 4: Subprocessors and other recipients

This annex is additionally available, with identical content, at uplads.com/subprocessors.

1. Subprocessors

These service providers process personal data on behalf of the processor.

NameFunctionLocation and transfer
Hetzner Online GmbHServer hosting for the application, background workers and the job queueEU (Germany, Falkenstein)
Supabase, Inc.Database, authentication and file storageEU (Ireland, eu-west-1), parent company in the USA. EU standard contractual clauses under Art. 46(2)(c) GDPR are in place.
Cloudflare, Inc.Object storage (R2) for uploaded creatives, CDN, DNS and attack protectionUSA. EU standard contractual clauses under Art. 46(2)(c) GDPR are in place and a DPF certification exists.
Anthropic PBCAI model/API for ad copy, image analysis and the optimizer, when the AI is billed by upladsUSA. EU standard contractual clauses under Art. 46(2)(c) GDPR are in place. API data is not used to train the models.
OpenAI Ireland Ltd.AI model/API for ad copy, image analysis and transcription of the audio track of uploaded videos, when the AI is billed by upladsIreland / USA. EU standard contractual clauses under Art. 46(2)(c) GDPR are in place. API data is not used to train the models.
Stripe Payments Europe, Ltd.Payment processing and subscription managementIreland / USA. EU standard contractual clauses under Art. 46(2)(c) GDPR are in place and a DPF certification exists.
PostHog, Inc.Product analytics and session replay of the uplads interfaceEU cloud (Germany), parent company in the USA. EU standard contractual clauses under Art. 46(2)(c) GDPR are in place.
Chatwoot Inc.Support live chat in the application and on the websiteUSA. EU standard contractual clauses under Art. 46(2)(c) GDPR are in place.
Plus Five Five, Inc. (Resend)Delivery of system and notification emailsUSA. EU standard contractual clauses under Art. 46(2)(c) GDPR are in place.

OpenAI and Anthropic act as subprocessors only in so far as the use of the AI features is billed through the processor. If the controller stores its own API key for a provider, the processing concerned takes place on the basis of the contractual relationship between the controller and that provider, which is then the controller's own processor for it. Stored keys are held encrypted and are not returned to the controller's browser.

2. Recipients acting on the controller’s instructions

Advertising platforms with which the controller connects its own account. They are not subprocessors (Section 8(6)). Only what the controller triggers itself is transmitted.

NameFunctionLocation and transfer
Meta Platforms Ireland Ltd.The controller's Facebook and Instagram ad accountsIreland / USA
Google Ireland Ltd.The controller's Google Ads and YouTube accountsIreland / USA
TikTok Technology Ltd.The controller's TikTok ad accountsIreland
Snap Group Ltd.The controller's Snapchat ad accountsUnited Kingdom / USA
LinkedIn Ireland Unlimited CompanyThe controller's LinkedIn ad accountsIreland / USA

3. Optional integrations

These services are used only if the controller explicitly connects them.

NameFunctionLocation and transfer
Dropbox International Unlimited CompanyImporting creatives from the controller's Dropbox accountIreland / USA
Google Ireland Ltd. (Drive)Importing creatives from the controller's Google DriveIreland / USA
Slack Technologies Ltd.Notifications into the controller's Slack workspaceIreland / USA
ClickUp (Mango Technologies, Inc.)Tasks in the controller's ClickUp workspaceUSA