CubieTec
Products Hire Me Ecosystem Company Roadmap Blog Careers Contact Legal
Hire Me →
Home› Legal› Data Processing Agreement

Data Processing Agreement

Last updated: Mar 30, 2026

Details about how we process data on behalf of our users and partners.

This Data Processing Agreement (“DPA”) applies where Cubie Technologies processes personal data on behalf of a business customer (“Controller”) in the course of providing the Services. It supplements our Terms of Service.

Where you use our Services as an individual for your own purposes, our Privacy Policy applies instead.

1. Roles

The Controller determines the purposes and means of processing personal data. Cubie Technologies acts as Processor and processes personal data only on documented instructions from the Controller, except where required to do otherwise by law.

2. Subject matter and duration

Processing lasts for the term of the Controller's subscription, plus the deletion period described in section 8.

Categories of data subject

  • The Controller's employees, contractors and authorised users
  • The Controller's own customers or contacts, where the Controller submits their data

Types of personal data

  • Identity and contact data — name, email address, profile details
  • Account and authentication data
  • Content submitted through the Services
  • Usage and technical data — log entries, device and connection information

The Services are not designed for special-category data as defined by GDPR Article 9, and the Controller should not submit such data without a separate written agreement.

3. Our obligations

  • Process personal data only on the Controller's documented instructions
  • Ensure personnel with access are bound by confidentiality
  • Implement appropriate technical and organisational security measures (section 5)
  • Assist the Controller in responding to data subject requests
  • Assist with data protection impact assessments and prior consultations where required
  • Delete or return personal data at the end of the engagement
  • Make available the information needed to demonstrate compliance

4. Sub-processors

The Controller gives general authorisation for us to engage sub-processors. We currently use providers for hosting and compute, object storage, transactional email, push notification delivery, and error monitoring.

Each sub-processor is bound by data protection obligations no less protective than this DPA. We will give at least 30 days' notice before adding or replacing a sub-processor, and the Controller may object on reasonable data protection grounds.

5. Security measures

  • Encryption of data in transit using TLS
  • Password hashing using bcrypt at a high work factor
  • Parameterised queries throughout, preventing SQL injection
  • Per-user and per-tenant data isolation enforced at the query layer
  • Role-based access control and least-privilege access for personnel
  • Regular backups with defined retention and restoration testing
  • Logging and monitoring of access to production systems

6. Personal data breach

We will notify the Controller without undue delay and in any case within 48 hours of becoming aware of a personal data breach affecting the Controller's data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed.

7. International transfers

Where personal data is transferred outside the EEA, UK or other regions with transfer restrictions, we rely on appropriate safeguards, including the European Commission's standard contractual clauses and, where applicable, the UK International Data Transfer Addendum.

8. Deletion and return

On termination, we will delete or return personal data at the Controller's choice. Deletion from active systems happens within 30 days; backup copies expire on their normal rotation within 90 days. We may retain data where required by law, and it remains subject to this DPA while retained.

9. Audits

We will make available information necessary to demonstrate compliance with this DPA and allow for audits, including inspections, conducted by the Controller or an auditor it mandates. Audits take place no more than once in any twelve-month period unless required by a supervisory authority, on reasonable notice and during business hours.

10. Contact

To enter into this DPA, request our sub-processor list, or raise a data protection question, contact legal@cubietec.com.

← PreviousRefund Policy Next →Intellectual Property Policy

All Documents

Terms of Service Privacy Policy Cookie Policy Acceptable Use Policy Refund Policy Data Processing Agreement Intellectual Property Policy Disclaimer

Questions?

Our legal team is happy to explain anything in this document.

Contact Legal Team →
CubieTec

Building digital products that power the future.

Products
ChatCubie Cubie FX CubieAI CubieMart CubieFlow CubieEdge CubieAlpha CubieX CubieLabs CubieNexus
Company
About Us Our Mission Mr Mehedi — Founder Ecosystem Roadmap Careers Blog
Resources
Hire Me Contact Help Center Status Brand Assets
Legal
Privacy Policy Terms of Service Cookie Policy Refund Policy All policies
Subscribe to our newsletter

Get the latest updates and news.

© 2026 Cubie Technologies. All rights reserved.Powered by Mr Mehedi

Sitemap|Legal|Security