Data Processing Addendum
Last updated: August 24, 2026
1. Overview
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Universal Life Source ("ULS", "we", "us") and any organization ("Customer", "you") that uses the ULS platform. It describes how ULS processes Customer personal data as a data processor on behalf of the Customer (the data controller).
This DPA is designed to comply with Article 28 of the GDPR and similar data protection requirements under CCPA and other applicable laws.
2. Roles and Responsibilities
| Role | Party |
|---|---|
| Data Controller | Customer (the organization using ULS) |
| Data Processor | Universal Life Source |
The Customer determines the purposes and means of processing personal data. ULS processes data only on documented instructions from the Customer, as described in the Terms of Service and this DPA.
3. Categories of Personal Data Processed
- Account data: Email address, display name, organization membership
- Research data: Search queries, journal entries, research notes, saved passages
- Technical data: IP address, browser type, authentication timestamps, audit log entries
- BYOK credentials: User-provided AI provider API keys (encrypted at rest)
4. Sub-Processors
ULS uses the following sub-processors to provide the service. The current sub-processor list is maintained at /sub-processors and is updated with 30 days' notice before engaging any new sub-processor.
- Logto — Authentication (OIDC)
- Cloudflare — CDN, TLS, DDoS protection
- Railway — Application hosting and database
- OpenAI — AI answer generation
- NVIDIA — Query embeddings
- SendGrid — Transactional email
5. Data Security Measures
ULS implements the following technical and organizational security measures:
- TLS 1.3 encryption for all data in transit
- Encrypted database connections (SSL/TLS)
- Symmetric encryption (Fernet/AES) for BYOK API keys at rest
- HttpOnly, Secure, SameSite session cookies
- OIDC authentication via dedicated identity provider
- Multi-factor authentication support
- CSRF protection on all forms
- Rate limiting on authentication and AI endpoints
- Content Security Policy and security headers
- Audit logging of all security-relevant actions
- Point-in-time database recovery backups
- Secret management via environment variables (never in source code)
- Origin protection — backend accessible only through Cloudflare proxy
6. Data Breach Notification
In the event of a personal data breach, ULS will:
- Notify the Customer without undue delay, and in any case within 72 hours of becoming aware of the breach
- Provide a description of the breach, the likely consequences, and the measures taken or proposed
- Cooperate with the Customer in meeting any regulatory notification obligations
7. Data Return and Deletion
Upon termination of the Customer's account or upon written request:
- ULS will export the Customer's data in a machine-readable format within 30 days
- ULS will delete all Customer personal data from production systems within 30 days
- Backups containing Customer data will be purged within 90 days (in accordance with the backup retention schedule)
- ULS will provide written confirmation of deletion upon request
8. Audit Rights
The Customer may audit ULS's compliance with this DPA, subject to:
- Providing at least 30 days' written notice
- Conducting the audit during normal business hours
- Not disrupting ULS's business operations
- Maintaining confidentiality of any ULS confidential information observed during the audit
Alternatively, ULS may provide a third-party audit report (such as a SOC 2 report) upon request when available.
9. International Data Transfers
All data is stored and processed within the United States. ULS does not transfer personal data outside the United States. Sub-processors are also US-based. If the Customer is located outside the United States, the Customer is responsible for ensuring that transferring data to ULS complies with applicable data protection laws.
10. Requesting a Signed DPA
To request a signed copy of this DPA for your organization, or to discuss custom data processing terms, contact [email protected].