1. Parties, formation, and scope
This Data Processing Agreement (“DPA”) is between the business or organisation that accepts the Unograph Terms of Service or an order (“Customer”) and Grigorii Feoktistov, an individual entrepreneur registered in Georgia with identification number 306408795, who operates Unograph (“Unograph”). It forms part of the agreement governing Customer’s use of the Service (the “Agreement”).
This DPA applies when Unograph processes Customer Personal Data as a processor on Customer’s behalf through the Service. It does not apply to personal data for which Unograph determines the purposes and means as an independent controller, such as account administration, security, billing, and our own consent-based analytics. Our Privacy Policy covers that processing.
The DPA becomes binding when Customer accepts the Agreement or continues to use the Service after being notified that this DPA applies. Customer’s account or order identifies the Customer and its contact details. Unograph’s legal and contact details are identified in the Agreement. Unograph’s registered address is Georgia, Tbilisi, Krtsanisi District, Ponichala 3 Settlement, Building 5, Entrance 2, Floor 4, auxiliary storage. A customer that needs a countersigned copy may contact [email protected].
Customer should not submit regulated special-category data, highly sensitive credentials, health data, payment-card data, or government identifiers unless a separate written agreement expressly authorises that processing.
2. Definitions and roles
“Applicable Data Protection Law” means privacy and data-protection law applicable to the processing under this DPA, including, where applicable, the Law of Georgia on Personal Data Protection, the EU General Data Protection Regulation (“GDPR”), the UK GDPR, and national laws implementing or supplementing them.
“Customer Personal Data” means personal data contained in Customer Content that Unograph processes on Customer’s behalf. “Controller,” “processor,” “data subject,” “personal data,” “processing,” “personal data breach,” and “subprocessor” have the meanings given by Applicable Data Protection Law. “SCCs” means the European Commission standard contractual clauses adopted by Implementing Decision (EU) 2021/914.
Customer is the controller of Customer Personal Data, or a processor acting for another controller. Unograph is Customer’s processor, or subprocessor where Customer is itself a processor. Each party will comply with the obligations that apply to its role.
Customer is responsible for the lawfulness, fairness, accuracy, and transparency of its processing; providing required notices; obtaining required permissions; responding to data subjects; configuring access and public links; and ensuring its instructions comply with law.
3. Documented instructions and purpose limitation
Unograph will process Customer Personal Data only:
- to provide, maintain, secure, and support the Service described in the Agreement and Annex I;
- through Customer’s and authorised users’ use, settings, support requests, and other documented instructions;
- as needed to prevent or address security incidents, abuse, or technical problems; and
- where required by applicable law, in which case we will inform Customer before processing unless law prohibits notice.
We will not sell Customer Personal Data or use it for cross-context behavioural advertising.
If we reasonably believe an instruction violates Applicable Data Protection Law, we will inform Customer and may pause the affected processing until the parties resolve the issue. Additional instructions outside the Service’s normal functionality may require a written agreement and reasonable fees.
4. Confidentiality and personnel
We will ensure that personnel authorised to process Customer Personal Data are bound by confidentiality obligations, receive access only as necessary for their responsibilities, and process the data only under our instructions. Confidentiality obligations continue after access ends.
We maintain responsibility for our personnel’s compliance with this DPA. We will disclose Customer Personal Data to public authorities only where required by law and, unless prohibited, will notify Customer and reasonably challenge requests that appear unlawful or disproportionate.
5. Security measures
Taking into account the state of the art, implementation cost, and the nature, scope, context, and purposes of processing, we will maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Current measures are described in Annex II.
We may update security measures as technology and risk evolve, provided we do not materially reduce the overall protection of Customer Personal Data during the Service term.
Customer is responsible for using available security features, managing users and roles, securing credentials, reviewing public links, and not placing data in the Service that is incompatible with the agreed risk level.
6. Personal data breaches
After becoming aware of a confirmed personal data breach affecting Customer Personal Data, we will notify Customer without undue delay. As information becomes available, the notice will describe:
- the nature and known scope of the incident;
- the categories of affected data and data subjects;
- known or likely consequences;
- measures taken or proposed to contain and remediate it; and
- a contact for follow-up.
We will take reasonable steps to contain, investigate, and mitigate the incident and will provide information reasonably needed for Customer’s legally required notifications. Our notice is not an admission of fault or liability. Customer is responsible for determining whether and how to notify data subjects or authorities, except for notifications law requires us to make directly.
7. Assistance and compliance information
Taking into account the nature of processing and information available to us, we will reasonably assist Customer with:
- requests to access, correct, delete, restrict, object to, or port Customer Personal Data;
- security, breach notifications, data-protection impact assessments, and prior consultation with regulators;
- demonstrating compliance with processor obligations under Applicable Data Protection Law; and
- responding to a regulator with authority over the processing.
If a data subject contacts us directly about Customer Personal Data, we will ordinarily refer the request to Customer and will not respond substantively without Customer’s instruction unless law requires it. Customer may use Service functionality to fulfil a request where available. Substantial assistance beyond standard functionality may be subject to reasonable fees unless needed because of our breach.
8. Subprocessors
Customer gives Unograph general written authorisation to use the subprocessors in Annex III to provide the Service. We will:
- conduct appropriate diligence before a subprocessor handles Customer Personal Data;
- enter a written agreement imposing data-protection obligations no less protective in substance than the relevant obligations in this DPA;
- remain responsible for the subprocessor’s performance of those obligations to the extent required by law; and
- maintain a current public list in Annex III.
We will give Customer at least 30 days’ advance notice by email, in-product notice, or an update notice linked from this page before a new subprocessor begins processing Customer Personal Data. Customer may object during that period on reasonable, documented data-protection grounds.
The parties will work in good faith on a reasonable alternative. If none is available, Customer may stop using the affected feature or terminate the affected Service before the new subprocessor begins processing. This is Customer’s sole remedy for a subprocessor objection, without limiting rights that cannot be excluded by law.
9. International transfers
Unograph operates from Georgia (country), and approved subprocessors may process data in the locations described in Annex III. Unograph will use a transfer mechanism and supplementary measures required by Applicable Data Protection Law.
For a restricted transfer of EEA Customer Personal Data to Unograph where the SCCs are a valid mechanism, the relevant SCC module is incorporated as described in Annex IV. For restricted UK transfers, the UK Addendum applies as described there.
Georgian law may require authorisation from the State Audit Office of Georgia for a transfer to a country without recognised adequate protection when contractual safeguards are used. Where that requirement applies, the affected transfer is conditional on the required authorisation or another lawful basis. The SCCs do not replace a Georgian authorisation requirement.
Customer will provide information and cooperation reasonably needed for a transfer assessment or regulatory application. Customer may request available information about the transfer mechanism for its data at [email protected]. Customer should not submit data requiring a specific transfer approval until the parties confirm the required mechanism is in place.
10. Return and deletion
During the Service term, Customer may access or export Customer Content using available functionality. Customer should retrieve needed data before closing its account.
On termination or a valid deletion instruction, we will delete or, where technically available and requested before deletion, return Customer Personal Data, unless applicable law requires retention. Data is normally removed from active systems within 30 days. Protected backup copies may remain for up to 90 days and will be isolated from ordinary use until overwritten or deleted, except where needed for recovery, security, or legal obligations.
We may retain de-identified data that no longer identifies a person. Customer acknowledges that disabling a public link cannot recall copies made outside Unograph.
11. Information and audits
On reasonable written request, no more than once per year unless a regulator, confirmed incident, or material compliance concern requires more, we will provide information reasonably necessary to demonstrate compliance with this DPA. We may satisfy this obligation through current policies, questionnaires, third-party reports, certifications, or summaries, subject to confidentiality and security restrictions.
If that information is insufficient, Customer may request a proportionate remote audit by an independent qualified auditor bound by confidentiality. An on-site audit is available only where required by law or a regulator, or where credible evidence of material non-compliance cannot reasonably be addressed remotely. Audits must avoid disruption and access to another customer’s data. Customer bears its audit costs unless the audit identifies our material breach.
12. Priority, liability, and general terms
If this DPA conflicts with the Agreement on processing Customer Personal Data, this DPA controls. If the SCCs or UK Addendum conflict with this DPA, the applicable transfer clauses control. Nothing in this DPA reduces data-subject rights or obligations that cannot be limited by law.
The liability provisions in the Agreement apply to this DPA in the aggregate with other claims under the Agreement, except to the extent Applicable Data Protection Law or the SCCs prohibit that limitation.
This DPA ends when Unograph no longer processes Customer Personal Data, but confidentiality, deletion, audit, transfer, and liability provisions survive as needed to protect retained data. Governing law and dispute terms are those in the Agreement, without displacing the law and forum mandated by applicable transfer clauses.
Annex I — Details of processing
| Item | Description |
|---|---|
| Subject matter | Providing a hosted collaborative software-architecture modeling, documentation, versioning, and read-only sharing service |
| Duration | The Agreement term plus the deletion and protected-backup periods described in this DPA |
| Nature of processing | Collection, transmission, organisation, storage, retrieval, display, collaboration, versioning, backup, support access when requested, restriction, export, and deletion |
| Purpose | To provide, secure, maintain, and support the Service according to Customer’s instructions |
| Frequency | Continuous or as initiated by Customer and authorised users during the Service term |
| Data subjects | Customer users, workspace members, invitees, personnel, contractors, customers, suppliers, end users, and other individuals whose data Customer chooses to include in Customer Content |
| Data categories | Names, business contact details, role and membership data, user identifiers, authorship and activity metadata, collaboration data, and any personal data Customer places in diagrams, models, flows, descriptions, comments, or documentation |
| Sensitive data | Not intended. Customer must not submit special-category or highly sensitive data unless separately agreed in writing with additional safeguards |
| Customer instructions | The Agreement, Customer’s configuration and use of the Service, authorised-user actions, and documented support requests consistent with the Agreement |
Annex II — Technical and organisational measures
Measures are applied according to risk and the relevant Service component. They currently include:
- Access control: role-based workspace access, least-privilege production access, access revocation, and confidentiality commitments.
- Authentication: one-way password hashing, secure session cookies in production, email verification, password-reset controls, rate limiting, and optional stronger authentication where available.
- Transmission: HTTPS/TLS for browser and service traffic and secure provider connections where supported.
- Tenant and sharing controls: workspace roles, explicit sharing permissions, public-link state, and the ability to disable links.
- Service protection: network and application controls, request limiting, security logging, vulnerability and patch management proportionate to risk, and restricted administrative access.
- Availability: protected backups and recovery processes appropriate to the current early-access Service, without a guaranteed recovery objective unless separately agreed.
- Analytics minimisation: optional consent, allowlisted events, input masking, route sanitisation, disabled console capture, and exclusion of network bodies and headers from Session Replay on the website. Customer Content and authentication credentials are not intended for analytics.
- Deletion: removal from active systems and expiry of isolated backup copies under documented retention periods.
- Incident handling: procedures to investigate, contain, remediate, document, and communicate confirmed personal data breaches.
Annex III — Approved subprocessors
The following providers may process Customer Personal Data only to the extent needed for the listed Service function. Product, account, and region configuration can affect the exact data and location.
| Provider | Function and data | Processing location |
|---|---|---|
| Cloudflare, Inc. | DNS, network delivery, security, proxying, and related request metadata; cached content only where the enabled product requires it | Global edge network and provider/subprocessor locations; data localisation depends on enabled configuration |
| Vultr / The Constant Company group | Compute, network, application hosting, and infrastructure used for PostgreSQL storage and protected backups | Configured data-centre region; provider support and subprocessors may operate from other disclosed locations |
| PostHog, Inc. | Optional analytics and Session Replay for pseudonymous, allowlisted product interactions; no intentional Customer Content, password, token, or private credential collection | EU Cloud for collection and storage; limited provider operations and subprocessors in disclosed locations |
Google processes a user’s direct choice to use Google OAuth under Google’s own identity-service terms; Stripe or another provider may process a future paid checkout as processor and independent controller depending on the activity. Neither is used to host Customer Content as part of the current free early-access Service.
Annex IV — EEA and UK transfer terms
European Economic Area
Where a restricted transfer to Unograph requires the SCCs and their use is legally valid:
- Module Two (controller to processor) applies when Customer is a controller, and Module Three (processor to processor) applies when Customer is a processor.
- Customer and any relevant affiliate are the data exporter; Unograph is the data importer. The parties’ details are those in the Agreement, order, account, and this DPA.
- Clause 7 (docking) applies. For Clause 9(a), Option 2 (general written authorisation) applies with 30 days’ notice. The optional language in Clause 11 does not apply.
- For Clause 17, Option 1 applies and the SCCs are governed by the law of Ireland. Under Clause 18(b), disputes are resolved by the courts of Ireland.
- The competent supervisory authority under Clause 13 is determined by that clause based on the data exporter and data subjects.
- Annex I of this DPA supplies the transfer description and frequency; Annex II supplies security measures; Annex III lists subprocessors. The transfer is continuous for the Agreement term, with retention as described in this DPA.
The parties are deemed to have signed the SCCs through their legally binding acceptance of the Agreement and this DPA. They will provide additional information and complete a transfer impact assessment as reasonably required.
United Kingdom
For a restricted transfer subject to the UK GDPR, the then-current mandatory clauses of the UK International Data Transfer Addendum to the EU SCCs issued by the Information Commissioner form part of this DPA. The parties and selected modules are as stated above, and Annexes I–III provide the Appendix Information. Neither party may end the Addendum solely because the approved form changes unless the mandatory clauses permit it.
Other jurisdictions
Where another jurisdiction recognises the SCCs with local adaptations, references will be read to include the applicable local law and regulator, and disputes will be heard in the forum required by that law. If those adaptations are insufficient, the parties will cooperate on a valid alternative.