Data Processing Addendum

Version date: September 25, 2026

This Data Processing Addendum (DPA) sets the terms for Metalcraft Inc (UFO) to process personal data for a business customer (Customer). It takes effect when UFO and Customer incorporate it into their written service agreement (Agreement). To arrange a DPA, email support@ufo.ai.

1. Scope and roles

Customer controls the personal data submitted to UFO or accessed through accounts that Customer connects (Customer Data). UFO acts as Customer's processor, or as a subprocessor where Customer acts for another controller. Customer must have authority to give the instructions in this DPA. Each party must comply with the data protection laws that apply to its role, including the EU GDPR, UK GDPR, and California privacy law where applicable.

This DPA governs Customer Data processing if it conflicts with the Agreement. It does not govern data UFO processes as an independent controller for billing, account administration, or its own legal duties. The Privacy Policy describes that processing.

2. Processing instructions

UFO will process Customer Data only to provide the service under the Agreement and Customer's documented instructions. These include authorized chat requests, account connections, and scheduled tasks. UFO will inform Customer if an instruction appears to violate applicable data protection law. If law requires other processing, UFO will notify Customer before processing unless the law prohibits that notice.

Customer is responsible for lawful collection, notices, permissions, and its instructions. UFO will not sell or share Customer Data for cross-context behavioral advertising, retain or use it outside the specified service purposes or direct business relationship, or combine it with other personal data except as applicable law permits. UFO will not use Customer Data to train general-purpose AI models.

3. Confidentiality and security

UFO will limit access to authorized persons who need it to provide the service and are bound by confidentiality duties. UFO will maintain technical and organizational measures appropriate to the risk. These include access controls, separation of customer data, encryption in transit and at rest, protection of credentials, service monitoring, incident response, and procedures to restore availability and assess the effectiveness of security measures.

4. Subprocessors

Customer gives general authorization to use the providers on the Subprocessor List for the services Customer uses. UFO will impose data protection duties at least as protective as this DPA and remain responsible for their performance. Customer-selected services receiving data at Customer's direction are governed by Customer's agreement with those services.

UFO will give Customer at least 30 days' written notice before a new or replacement subprocessor starts processing Customer Data. Customer may raise a concern during that period on reasonable data protection grounds. The parties will seek a solution. If none is available, Customer may end the affected service before the change takes effect and receive a refund of prepaid fees for the unused affected service.

5. Assistance and incidents

Taking account of the processing and information available, UFO will help Customer respond to individual rights requests and meet its security, breach notification, impact assessment, and regulator consultation duties. UFO will refer requests about Customer Data to Customer unless law requires a direct response.

UFO will notify Customer without undue delay after it becomes aware of a personal data breach affecting Customer Data. UFO will provide available information about the nature, impact, affected data and people, contact point, and corrective measures. UFO will provide updates as facts become available and cooperate with Customer's response.

6. Return and deletion

At the end of the service, UFO will return or delete Customer Data at Customer's choice and delete remaining copies, unless law requires retention. The parties will agree the export method and completion schedule in the Agreement. Until deletion is complete, retained data remains protected by this DPA and will be processed only for required retention or secure deletion.

7. Information and audits

UFO will provide information needed to demonstrate compliance and allow audits, including inspections, by Customer or an independent auditor that Customer appoints. The parties will agree reasonable notice, confidentiality, and security arrangements that do not prevent an audit required by law or a regulator. Customer may take reasonable steps to stop and remedy unauthorized processing. UFO will notify Customer if it can no longer meet its obligations.

8. International transfers

Before a transfer that requires additional legal safeguards, the parties will complete and sign the applicable transfer terms and annexes. These can include the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum. The schedule must identify the parties, transfer roles, processing locations, security measures, and competent authority. This DPA alone does not put those transfer safeguards in place.

9. Processing details