Data Processing Addendum
Last updated: 30 June 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between UDAIX ("Processor", operator of Turelis) and the customer ("Controller") and applies where UDAIX processes personal data on the Controller's behalf in connection with the Service. For a countersigned copy for your records, email [email protected].
1. Roles & scope
The Controller determines the purposes and means of processing; UDAIX acts as Processor and processes personal data only on the Controller's documented instructions, including as set out in the Terms and the Service's functionality.
2. Subject-matter & duration
Processing continues for the duration of the Controller's use of the Service and any retention period described in the Privacy Policy.
3. Nature & purpose
To research, generate, store, schedule, and publish social-media content at the Controller's direction, and to provide related analytics and support.
4. Categories of data & data subjects
- Data subjects: the Controller's authorized users and the audiences of content the Controller publishes.
- Personal data: account identifiers (name, email), brand/content data, connection tokens (encrypted), usage and technical data. The Controller must not submit special-category data unless agreed in writing.
5. Security measures
UDAIX maintains appropriate technical and organizational measures, including encryption in transit (HTTPS) and encryption of social tokens at rest, access controls, least-privilege administration, and logging.
6. Sub-processing
The Controller authorizes UDAIX to engage the subprocessors listed at our Subprocessor page, each under terms protecting personal data. We will give notice before adding a new subprocessor and allow reasonable objection.
7. Assistance & data-subject requests
UDAIX will assist the Controller, taking into account the nature of processing, to respond to data-subject requests (access, deletion, portability, etc.) and to meet security, breach-notification, and impact-assessment obligations.
8. Personal-data breach
UDAIX will notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's data, with information reasonably available to assist the Controller's own notification duties.
9. Return & deletion
On termination, UDAIX will delete or return the Controller's personal data within the periods described in the Privacy Policy (soft-delete grace, then purge), except where retention is required by law.
10. International transfers
Where personal data is transferred across borders, the parties rely on appropriate safeguards such as the Standard Contractual Clauses.
11. Audits
UDAIX will make available information reasonably necessary to demonstrate compliance and allow for audits, subject to confidentiality and reasonable notice.
This DPA is a standard template offered for convenience. Enterprise customers with specific requirements may request a negotiated agreement at [email protected].