DATA PROCESSING AGREEMENT (DPA)
Annex to the Oxta Terms of Service · Version 1.0 · Effective 18 September 2026
Convenience translation; the Ukrainian text prevails, except for the SCCs, whose authentic text is the English text of Decision 2021/914.
Preamble
This Agreement is between ТОВ «Окста» (Processor, Oxta) and the Customer who accepted the Terms of Service (Controller). It forms part of the Agreement, is accepted together with the Terms and requires no separate signature; on request Oxta provides a signed PDF copy with a qualified electronic signature.
It is entered into pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR) and Article 4 of the Law of Ukraine "On Personal Data Protection" (Ukrainian Law). Terms have the meaning of Article 4 GDPR; for the Ukrainian Law the Controller is the "володілець" and the Processor the "розпорядник".
1. Subject and scope
1.1. This Agreement governs the Processor's processing of Customer Data — personal data passing through the Controller's flows, contained in its files, datasets, sites and connections, and generated in run history during flow execution.
1.2. It does not govern the Controller's own data as a platform user (e-mail, name, payments), for which Oxta is a controller under the Privacy Policy.
1.3. The description of processing is in Annex 1.
2. Roles and instructions
2.1. The Controller determines the purposes and means of processing Customer Data and is responsible for the legal basis and for informing data subjects (Articles 5, 6, 13, 14 GDPR; Articles 6, 11, 12 Ukrainian Law).
2.2. The Processor processes Customer Data only on documented instructions of the Controller (Article 28(3)(a)). Documented instructions are: this Agreement; the configuration of flows, agents, datasets, sites and connections the Controller creates on the platform; triggering runs; account settings; confirmation of the AI Features Terms; written instructions to privacy@oxta.io.
2.3. The platform executes the Controller's configuration literally. Every flow step that sends data outward — to an HTTP endpoint, Telegram, Slack, Google, an SMTP server, a database, a vector store or the Controller's AI provider — is the Controller's instruction to transmit data to a recipient it chose. Such recipients are not Oxta's sub-processors; the Controller establishes its own relationship with them (as its processors or third-party recipients) (Section 6.5).
2.4. If the Processor considers an instruction infringes the GDPR, the Ukrainian Law or other applicable data-protection law, it immediately informs the Controller and may suspend execution (Article 28(3), last subparagraph).
2.5. The Processor processes outside instructions only where required by EU, Member State or Ukrainian law, informing the Controller beforehand unless prohibited on important grounds of public interest.
3. Processor obligations
3.1. Confidentiality. Persons authorised to process are bound by contractual or statutory confidentiality (Article 28(3)(b)).
3.2. Security. The Processor implements the measures in Annex 3 per Article 32 and does not lower their level during this Agreement (Article 28(3)(c)).
3.3. Sub-processors. Section 6 (Article 28(2), (3)(d), (4)).
3.4. Data-subject assistance. Section 7 (Article 28(3)(e)).
3.5. Assistance under Articles 32–36. The Processor assists the Controller with security, breach notification, data-protection impact assessments (DPIA) and prior consultation, providing information in its possession (Article 28(3)(f)). For a DPIA the Processor provides a description of processing architecture, data flows and security measures within 15 business days of request.
3.6. Deletion and return. Section 9 (Article 28(3)(g)).
3.7. Information and audit. Section 10 (Article 28(3)(h)).
3.8. Records. The Processor maintains records of categories of processing carried out on behalf of the Controller (Article 30(2)) and provides an extract on request.
3.9. Purpose limitation. The Processor does not use Customer Data for its own purposes, sell it, train models on it or combine it with other controllers' data. Anonymised metrics (identifiers, statuses, durations, counts) containing no Customer Data are used to operate and develop the platform.
4. Controller obligations
4.1. Hold a legal basis for processing Customer Data and transmitting it to the Processor and to every recipient selected in flow configuration; inform data subjects.
4.2. Not pass special categories of data (Article 9), criminal-conviction data (Article 10) or children's data collected without guardian consent through the platform, nor data whose collection is prohibited. The platform is not designed or certified for such data. On breach the Processor may suspend the relevant flows and delete the data, notifying the Controller.
4.3. Configure flows mindful that the full content of every run is stored in run history (Annex 1). Apply data minimisation at configuration level.
4.4. Ensure external credentials stored on the platform have least privilege and revoke them when use ends.
4.5. Respond promptly to the Processor's queries about instructions, incidents and data-subject complaints.
4.6. Where the Controller is in the EU/EEA or processes EU/EEA data subjects' data — perform the data-exporter obligations in Section 8.
5. AI features
5.1. Customer Data is sent to language models only where the Controller has added an AI node or agent, uses dataset vector search or the assistant. Without such steps no Customer Data reaches models.
5.2. "Oxta key" mode (default): requests run on Cloudflare Workers AI — a sub-processor in Annex 2 — and do not leave Cloudflare's infrastructure. Models are listed in Annex 2 and may be updated to functionally equivalent ones with notice on the sub-processor page.
5.3. "Own key" mode: requests go directly to the provider chosen by the Controller at the address it specifies. This is a transfer on the Controller's instruction (Section 2.3); the provider is not Oxta's sub-processor, and the Processor does not control or answer for its retention or processing. The Processor warrants only that it does not alter request content (other than redacting secrets) and sends it to no other recipient.
5.4. Sent to the model: the Controller's prompt with substituted values from prior steps; the node's system instruction; for search — the query text and dataset fragments. Not sent: the Controller's account data, credentials and keys (redacted automatically), data of other flows and other controllers. If the Controller places personal data in a prompt it will be sent to the model — that is its instruction.
5.5. Model request and response are stored in run history on the same terms as other steps. No separate history switch exists for AI steps.
5.6. Before first use the Controller confirms the AI Features Terms. That confirmation is a documented instruction under Section 2.2 and prior authorisation of the relevant sub-processor under Section 6.1. Withdrawal is governed by the AI Features Terms.
6. Sub-processors
6.1. The Controller gives general written authorisation for the sub-processors listed in Annex 2 (Article 28(2)).
6.2. The Processor imposes on each sub-processor, by contract, data-protection obligations no less protective than this Agreement, including sufficient guarantees on security measures, and remains fully liable to the Controller for the sub-processor's performance (Article 28(4)).
6.3. Changes. The Processor notifies intended additions or replacements at least 30 calendar days in advance by e-mail to the account and updates Annex 2 to this Agreement. The Controller may object within that period on reasonable data-protection grounds. If no solution is found within 15 days of the objection, the Controller may terminate the Agreement without penalty with a refund of prepayment for the unused period. Model updates within the same sub-processor (Section 5.2) are not a sub-processor change.
6.4. The current list is set out in Annex 2 to this Agreement.
6.5. Not sub-processors: recipients the Controller connects itself — arbitrary HTTP endpoints, Telegram, Slack, Google Sheets, the Controller's SMTP server, the Controller's database (Supabase, SQL), its own vector store (Qdrant), its own AI provider. The Controller concludes processing agreements with them where required and answers for the lawfulness of the transfer. The Processor is merely a technical conduit and is neither controller nor processor for their onward processing.
7. Data-subject rights
7.1. The Controller answers data-subject requests itself. A request received by the Processor is forwarded to the Controller within 5 business days (if identifiable) without substantive response.
7.2. The platform provides self-service tools: viewing and searching run history, deleting a flow's entire run history, managing files, datasets, sites, connections; full account deletion.
7.3. Where self-service is insufficient, the Processor, on written request, within 10 business days: provides an export of data relating to the subject in a machine-readable format; deletes or corrects specific records in run history and datasets; restricts processing. This may be done manually.
7.4. Limitations the Controller accepts: (a) data already sent by a flow to external recipients (Section 6.5) is outside the Processor's control; (b) deleted data may persist in infrastructure backups for up to 30 days and is not restored from them, except in a full-system restore after failure, in which case the Processor re-applies executed deletions; (c) vectors in Vectorize are deleted with the dataset, not per fragment.
8. International transfers
8.1. Location. The Processor is in Ukraine, for which there is no Commission adequacy decision. Infrastructure is Cloudflare, Inc. (USA), a global network; processing may occur outside the EEA and Ukraine. The Processor has not configured any regional restriction on processing.
8.2. EEA → Oxta (Ukraine). Where the Controller is subject to the GDPR, the parties hereby enter into the Standard Contractual Clauses of Commission Decision (EU) 2021/914 (SCCs), Module 2 (controller to processor), incorporated by reference, with these options:
- Clause 7 (docking): applies.
- Clause 9(a): Option 2 — general written authorisation, 30 days' notice (Section 6.3).
- Clause 11(a): the independent dispute-resolution body option does not apply.
- Clause 13: supervisory authority determined by the location of the Controller-exporter (or its representative).
- Clause 17: governing law — Ireland.
- Clause 18(b): courts of Ireland.
- SCC Annex I = Annex 1 and the parties' details in this Agreement; SCC Annex II = Annex 3; SCC Annex III = Annex 2.
- For UK Controllers the UK International Data Transfer Addendum to the SCCs additionally applies.
In case of conflict between the SCCs and this Agreement, the SCCs prevail.
8.3. Oxta → Cloudflare (USA). Under the Cloudflare Data Processing Addendum, which contains the SCCs (Module 3, processor to processor) and refers to Cloudflare's EU-U.S. Data Privacy Framework certification. For Article 29 of the Ukrainian Law these constitute contractual data-protection guarantees.
8.4. Transfer impact assessment (TIA). On request the Processor provides information in its possession on Ukrainian and US law regarding public-authority access to data, for the Controller's TIA. The Processor undertakes to challenge disproportionate authority requests for Customer Data by lawful means and to inform the Controller of such requests unless prohibited by law.
8.5. Transfers on the Controller's instruction (Section 6.5) to recipients in third countries are the Controller's transfers; the Processor is not their exporter.
9. Termination and deletion
9.1. Processing ends on account deletion by the Controller or termination of the Agreement.
9.2. Return. Before deletion the Controller exports Customer Data via platform tools (flow export, file download). On written request made before deletion, the Processor provides a machine-readable export within 10 business days.
9.3. Deletion. On account deletion the Processor synchronously deletes flows, agents, datasets and vectors, files, sites, connections and stored credentials, run history, counters, closes the subscription and deletes the account; the service produces a report of anything it could not delete, and the Processor completes deletion manually within 5 business days. Final destruction, including infrastructure backups — within 30 days.
9.4. Exceptions, retained on the basis of the Processor's legal obligations and legitimate interest as a controller: payment records (3 years), records of accepted documents (3 years), anonymised metrics. None contain Customer Data.
9.5. Written confirmation of deletion is provided on request.
10. Audit
10.1. On request, no more than once per 12 months and after any incident, the Processor provides: the current Annex 3; architecture and data-flow description; the records under Section 3.8; sub-processor information with links to their data-protection terms and compliance reports (Cloudflare: via Cloudflare Trust Hub); responses to a written questionnaire within 20 business days.
10.2. Where documentary evidence is insufficient or a supervisory authority requires an audit, the Controller or an independent auditor at its cost (bound by confidentiality, not a competitor) may conduct an audit by interviews and review of documentation, configuration and code relating to the processing, no more than once a year, with 30 days' notice, during business hours, without access to other controllers' data. Access to Cloudflare infrastructure is limited to what Cloudflare provides its customers.
10.3. Disclosure. The Processor holds no ISO 27001 or SOC 2 certification, has no DPO, keeps no separate log of staff access to production data and does not offer two-factor authentication to users. These facts are disclosed for the Controller's own risk assessment.
11. Personal-data breaches
11.1. The Processor notifies the Controller of a breach affecting Customer Data without undue delay and no later than 48 hours after becoming aware, to the account e-mail, with the Article 33(3) information available: nature of the breach, categories and approximate numbers of subjects and records, likely consequences, measures taken and planned, contact person; the rest in phases.
11.2. The Processor assists the Controller with notifying the supervisory authority (72 hours, Article 33) and data subjects (Article 34) and does not notify the Controller's data subjects itself without instruction unless required by law.
11.3. The Processor documents breaches, their effects and remedial action.
12. Liability
12.1. Each party is liable for damage caused by its infringement of the GDPR/Ukrainian Law or this Agreement per Article 82 GDPR. The Processor is liable only where it has not complied with obligations specifically directed to processors or has acted outside the Controller's instructions.
12.2. The Processor's liability to the Controller is limited per Section 14 of the Terms, except for intent and where limitation is prohibited by law. The limitation does not affect data subjects' rights or third-party-beneficiary rights under the SCCs.
12.3. The Controller indemnifies the Processor for losses caused by the Controller's lack of legal basis, breach of Section 4.2 or transfers under Section 6.5.
13. General
13.1. This Agreement runs for the term of the Agreement and until completion of deletion under Section 9.
13.2. Amendments follow Section 17 of the Terms; Annex 2 follows Section 6; Annex 3 changes that do not lower protection take effect on publication.
13.3. Made in Ukrainian; the Ukrainian text prevails except for the SCCs.
ANNEX 1. DESCRIPTION OF PROCESSING (SCC Annex I.B)
Categories of data subjects: the Controller's customers, shoppers, prospects, subscribers, counterparties, employees and other persons whose data the Controller processes in its business and passes through flows; visitors to sites the Controller publishes on the platform.
Categories of personal data: determined by the Controller's flow configuration. Typically: identity and contact data (name, phone, e-mail, messenger accounts), order and transaction data, message and correspondence content, behavioural events (abandoned cart, e-mail open), any data in the Controller's files and datasets. Special categories — prohibited (Section 4.2).
Nature of processing: receipt of data from the Controller's sources on event, schedule or demand; execution of flow steps (transformation, conditions, external-service calls, AI model calls); storage of configuration, files, datasets and vectors, site content; storage of the full content of every run (input, each step's result, variable values, output) in run history with automatic secret redaction; transmission to recipients on the Controller's instruction.
Purpose: automation of the Controller's business processes per its flows. The Processor has no purpose of its own.
Duration: the term of the Agreement until deletion is complete.
Frequency: continuous, per the Controller's configuration.
Retention (SCC Annex I.B, item 9):
| Data | Period | Mechanism |
|---|---|---|
| Run history | Up to the 10,000 most recent runs per flow; older deleted automatically. No time-based cap — rarely-run flows retain history for long periods | Automatic |
| Files, datasets, vectors, sites, configuration | While present in the account / until deleted by the Controller | Controller |
| Daily statistics (counts, durations — no Customer Data) | 730 days | Automatic |
| Response-structure snapshots of external services (structure only, no values) | 30 days | Automatic |
| Infrastructure backups | Up to 30 days | Cloudflare |
Processing location: Ukraine (administration); Cloudflare infrastructure (global).
Competent supervisory authority (SCC Annex I.C): per the Controller's location.
ANNEX 2. SUB-PROCESSORS (SCC Annex III)
Effective 18 September 2026
| # | Sub-processor | Address, country | Function | Data | Transfer safeguards |
|---|---|---|---|---|---|
| 1 | Cloudflare, Inc. | 101 Townsend St, San Francisco, CA 94107, USA; global network | Hosting and compute (Workers, Durable Objects); database (D1); object storage (R2); vector store (Vectorize); anonymised metrics (Analytics Engine); delivery network and security; AI models (Workers AI) — text model @cf/zai-org/glm-5.3-flash, embeddings @cf/google/embeddinggemma-300m | All Customer Data stored or executed on the platform; model request content in "Oxta key" mode | Cloudflare DPA with SCCs (Module 3); EU-U.S. DPF. The Processor grants Cloudflare no permission to use request content for training |
| 2 | Universal Bank JSC (Monobank) | Ukraine | Subscription payment acceptance | Not a sub-processor of Customer Data — processes only the Controller's payment data as a user. Listed for completeness | — |
Recipients connected by the Controller (HTTP endpoints, Telegram, Slack, Google, SMTP, Supabase, Qdrant, own AI provider) are not sub-processors — Section 6.5.
ANNEX 3. TECHNICAL AND ORGANISATIONAL MEASURES (SCC Annex II)
Measures implemented in the platform code as of this version, described at outcome level; they may be improved without lowering protection.
Pseudonymisation and encryption (Art. 32(1)(a))
- User passwords stored solely as scrypt hashes with a random 16-byte salt and 64-byte key; the original password cannot be recovered.
- External-service credentials (API keys, SMTP passwords, database connection strings) encrypted with AES-GCM under a dedicated platform key with a random IV per record; never stored in plaintext.
- Secrets automatically redacted from run content before writing to history (
redactSecrets). - Data in transit — TLS (HTTPS) only.
- Data at rest protected by Cloudflare infrastructure encryption (D1, R2, Vectorize). No separate encryption of run content under the Processor's key.
Confidentiality and isolation (Art. 32(1)(b))
- Every data request verifies the record belongs to the user's account (
findByIdUserIdpattern); cross-account access is impossible at query level. - Single-owner accounts; no shared access.
- IP-based rate limiting of sign-in and registration.
- One-click revocation of all account sessions (
session_version); 24-hour session lifetime. - Usage metrics contain no data content — identifiers, statuses and numbers only.
- Response-structure snapshots store structure without values.
Integrity (Art. 32(1)(b))
- Run history and consent records are append-only.
- Flow versioning.
Availability and resilience (Art. 32(1)(b), (c))
- Geographically distributed Cloudflare infrastructure; provider-level redundancy with restore window up to 30 days.
- Automatic purging per retention periods (Annex 1).
Testing and evaluation (Art. 32(1)(d))
- Code changes are covered by automated tests run before deployment. There is no separate second-person code review process at present.
- Annual review of this Annex and after every incident.
Organisational measures
- Confidentiality undertakings by persons with data access.
- Incident-response procedure with 48-hour Controller notification.
- Minimisation by design: secrets redacted, metrics anonymised, payment data kept off-platform.
Assistance measures — self-service tools (Section 7), export (Section 9), sub-processor page (Section 6).
Sub-processor measures — Cloudflare: ISO 27001, ISO 27701, SOC 2 Type II, PCI DSS and others, per Cloudflare Trust Hub.
Not in place as of this version: two-factor authentication; encryption of run content under the Processor's key; log of staff access to production data; ISO 27001 / SOC 2 certification of the Processor; appointed DPO.