Data Processing Agreement
DATA PROCESSING AGREEMENT (DPA)
Last Updated: July 11, 2026
1. INTRODUCTION AND PARTIES
This Data Processing Agreement (“DPA”) forms part of and is incorporated into the Terms of Service, Privacy Policy, and any other agreement (collectively, the “Main Agreement”) between Uoculi LLC, a company based in Kansas, United States (“Company,” “Controller,” “we,” “our,” or “us”), and any individual, customer, business, service provider, partner, or other entity that accesses, purchases from, or otherwise interacts with the Uoculi e-commerce website and related services (“User,” “Customer,” “you,” or “your”).
This DPA governs the processing of Personal Data in connection with the Uoculi e-commerce website, online store, order fulfillment services, customer accounts, payment processing, shipping, customer support, marketing communications, and related products and services (collectively, the “Services”).
This DPA establishes the rights and obligations of the parties concerning the collection, use, storage, disclosure, transfer, and other processing of Personal Data in accordance with applicable privacy and data protection laws, including, where applicable, the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the UK General Data Protection Regulation (“UK GDPR”), the California Consumer Privacy Act (“CCPA”), as amended by the California Privacy Rights Act (“CPRA”), and other applicable federal, state, and international privacy and data protection laws.
2. DEFINITIONS
For the purposes of this DPA:
Personal Data means any information relating to an identified or identifiable natural person and includes any equivalent term, such as “personal information,” as defined under applicable Data Protection Laws.
Processing means any operation or set of operations performed on Personal Data, including collection, recording, organization, structuring, storage, alteration, retrieval, consultation, use, transmission, disclosure, dissemination, restriction, deletion, or destruction.
Controller means the person or entity that, alone or jointly with others, determines the purposes and means of processing Personal Data.
Processor means a person or entity that processes Personal Data on behalf of a Controller.
Sub-processor means any third party engaged by a Processor to process Personal Data on behalf of a Controller.
Data Subject means the identified or identifiable individual to whom Personal Data relates, including customers, website visitors, account holders, gift recipients, and customer support contacts.
Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
Applicable Data Protection Laws means all privacy, data protection, and data security laws and regulations applicable to the processing of Personal Data under this DPA.
3. SCOPE AND NATURE OF PROCESSING
3.1 Subject Matter
This DPA applies to the processing of Personal Data carried out in connection with the Services, including:
- Browsing and interacting with the website;
- Creating and managing customer accounts;
- Processing and fulfilling orders;
- Processing payments and refunds;
- Shipping and delivering products;
- Managing returns, exchanges, and cancellations;
- Communicating order and shipping updates;
- Providing customer service and support;
- Preventing fraud, unauthorized transactions, and abuse;
- Conducting analytics and performance monitoring;
- Managing marketing communications, where permitted by law;
- Maintaining website functionality, security, and availability; and
- Complying with applicable legal, tax, accounting, regulatory, and contractual obligations.
3.2 Nature and Purpose of Processing
Personal Data may be processed for purposes including:
- Receiving, processing, and fulfilling customer orders;
- Confirming purchases and transactions;
- Processing payments through third-party payment service providers;
- Arranging shipping, delivery, tracking, and customs documentation;
- Communicating with customers regarding orders, deliveries, returns, exchanges, refunds, and customer support inquiries;
- Creating and administering customer accounts;
- Maintaining purchase histories and transaction records;
- Detecting, investigating, and preventing fraudulent or unauthorized activity;
- Protecting the security and integrity of the website and Services;
- Personalizing the shopping experience;
- Conducting website analytics and measuring performance;
- Sending promotional emails, newsletters, offers, or other marketing communications where the customer has consented or where otherwise permitted by applicable law;
- Managing product reviews, feedback, and customer communications;
- Responding to legal requests and enforcing contractual rights; and
- Complying with applicable laws and regulatory requirements.
3.3 Categories of Data Subjects
The categories of Data Subjects may include:
- Customers and purchasers;
- Website visitors;
- Prospective customers;
- Newsletter and marketing subscribers;
- Gift recipients or other designated delivery recipients;
- Individuals contacting customer support;
- Authorized representatives of customers; and
- Business partners, suppliers, or service-provider contacts, where applicable.
3.4 Categories of Personal Data
Depending on how the Services are used, Personal Data processed may include:
- Full name;
- Email address;
- Telephone number;
- Billing address;
- Shipping and delivery address;
- Order details and purchase history;
- Product preferences;
- Payment and transaction information;
- Refund and return information;
- Shipping and tracking information;
- Customs-related information where required for international shipments;
- IP address;
- Device identifiers;
- Browser type and operating system information;
- Cookie identifiers and similar online identifiers;
- Website browsing and interaction data;
- Marketing preferences and consent records;
- Customer reviews and feedback;
- Customer support inquiries and correspondence;
- Fraud prevention and risk assessment information; and
- Diagnostic, analytics, and security data.
The Company does not necessarily receive or store complete payment card information where payments are processed directly by an independent third-party payment processor.
4. ROLES AND RESPONSIBILITIES
4.1 Uoculi LLC as Controller
For Personal Data collected directly from customers, website visitors, and other individuals through the Services, Uoculi LLC generally acts as a Controller and determines the purposes and means of processing such Personal Data.
Uoculi LLC shall process Personal Data in accordance with applicable Data Protection Laws and its published Privacy Policy.
4.2 Uoculi LLC as Processor
Where Uoculi LLC processes Personal Data on behalf of another party acting as a Controller, and applicable law requires a controller-processor agreement, Uoculi LLC shall:
- Process Personal Data only on documented instructions from the Controller, unless otherwise required by law;
- Ensure that persons authorized to process Personal Data are subject to appropriate confidentiality obligations;
- Implement appropriate technical and organizational security measures;
- Provide reasonable assistance to the Controller in fulfilling applicable data protection obligations;
- Not process Personal Data for unauthorized purposes; and
- Notify the Controller if, in Uoculi LLC’s reasonable opinion, an instruction infringes applicable Data Protection Laws, where legally required.
5. DATA PROCESSING PRINCIPLES
Personal Data processed under this DPA shall be handled in accordance with the following principles, where applicable:
Lawfulness, Fairness, and Transparency: Personal Data shall be processed lawfully, fairly, and transparently.
Purpose Limitation: Personal Data shall be collected for specified, explicit, and legitimate purposes and shall not be processed incompatibly with those purposes.
Data Minimization: The Company shall seek to collect only Personal Data that is reasonably necessary and proportionate for the applicable processing purpose.
Accuracy: Reasonable steps shall be taken to maintain accurate and, where necessary, up-to-date Personal Data.
Storage Limitation: Personal Data shall not be retained longer than reasonably necessary for the purposes for which it was collected, subject to legal, tax, accounting, dispute-resolution, fraud-prevention, and other legitimate retention requirements.
Integrity and Confidentiality: Appropriate technical and organizational safeguards shall be maintained to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage.
Accountability: The Company shall take reasonable measures to demonstrate compliance with applicable Data Protection Laws where required.
6. SECURITY MEASURES
Uoculi LLC shall maintain reasonable and appropriate technical and organizational safeguards designed to protect Personal Data against unauthorized access, use, disclosure, alteration, loss, or destruction.
Such safeguards may include, as appropriate:
- Secure website connections and encrypted data transmission;
- Access controls and authentication mechanisms;
- Restricted access to Personal Data based on legitimate business needs;
- Secure cloud infrastructure and hosting services;
- Monitoring and logging of security-relevant activities;
- Security patches, updates, and vulnerability management;
- Backup and disaster recovery procedures;
- Fraud detection and transaction monitoring measures;
- Secure integration with payment processors and other service providers; and
- Measures designed to maintain the confidentiality, integrity, availability, and resilience of systems processing Personal Data.
While Uoculi LLC takes reasonable measures to protect Personal Data, no website, electronic transmission, storage system, or security measure can be guaranteed to be completely secure.
7. E-COMMERCE AND ORDER PROCESSING
Personal Data may be processed as necessary to facilitate e-commerce transactions and fulfill customer orders.
Such processing may include:
- Receiving and confirming orders;
- Verifying customer and delivery information;
- Processing transactions through third-party payment providers;
- Preparing products for shipment;
- Sharing necessary recipient and delivery information with postal services, shipping carriers, fulfillment partners, and customs authorities;
- Providing tracking information and delivery notifications;
- Processing cancellations, returns, exchanges, and refunds;
- Maintaining transaction records;
- Detecting fraudulent transactions or misuse of the Services; and
- Handling customer inquiries concerning purchases and deliveries.
For international orders, certain Personal Data may be disclosed to shipping carriers, customs authorities, postal operators, customs brokers, or other entities where reasonably necessary to facilitate international delivery and comply with customs, import, export, tax, and regulatory requirements.
8. PAYMENT PROCESSING
Payments made through the Services may be processed by independent third-party payment processors.
Uoculi LLC may receive limited transaction-related information, such as:
- Customer name;
- Billing information;
- Transaction amount;
- Payment status;
- Transaction identifier;
- Payment method type or limited payment details; and
- Fraud prevention or risk-related information.
Unless expressly stated otherwise, Uoculi LLC does not directly store complete credit or debit card numbers, card security codes, or other full payment credentials where such information is collected and processed directly by an independent payment processor.
Third-party payment providers may process Personal Data in accordance with their own terms, privacy notices, legal obligations, and security practices.
9. SUB-PROCESSING AND THIRD-PARTY SERVICE PROVIDERS
Uoculi LLC may engage trusted third-party service providers and, where applicable, Sub-processors to assist in operating and providing the Services.
Such providers may offer services including:
- Website hosting and cloud infrastructure;
- E-commerce platform functionality;
- Payment processing;
- Order fulfillment;
- Shipping and delivery;
- Email and transactional communications;
- Customer service and support;
- Website analytics;
- Advertising and marketing;
- Fraud prevention;
- Security monitoring;
- Content delivery networks;
- Data storage and backup; and
- Other technical or operational services reasonably necessary to operate the business.
Where Uoculi LLC acts as a Processor and appoints a Sub-processor, it shall take reasonable measures to ensure that the Sub-processor is subject to appropriate contractual data protection obligations as required by applicable law.
Where a third-party service provider acts as an independent Controller, its processing of Personal Data may be governed by its own privacy policy and legal obligations.
10. INTERNATIONAL DATA TRANSFERS
Personal Data may be processed, stored, accessed, or transferred in countries other than the country in which a Data Subject resides, including the United States and other jurisdictions in which Uoculi LLC or its service providers operate.
Where required by applicable law, Uoculi LLC shall implement or rely upon appropriate safeguards for international transfers of Personal Data, which may include:
- Standard Contractual Clauses (“SCCs”) approved by the European Commission;
- The UK International Data Transfer Agreement or UK Addendum, where applicable;
- Adequacy decisions;
- Approved certification mechanisms;
- Other lawful transfer mechanisms recognized under applicable Data Protection Laws.
11. DATA SUBJECT RIGHTS
Depending on the Data Subject’s jurisdiction and applicable law, individuals may have certain rights concerning their Personal Data, including:
- The right to request access to Personal Data;
- The right to request correction of inaccurate Personal Data;
- The right to request deletion of Personal Data;
- The right to request restriction of processing;
- The right to data portability;
- The right to object to certain processing;
- The right to opt out of certain sales, sharing, targeted advertising, or profiling, where applicable;
- The right to withdraw consent where processing is based on consent;
- The right to opt out of marketing communications; and
- The right not to be unlawfully discriminated against for exercising applicable privacy rights.
These rights are not absolute and may be subject to exceptions, limitations, identity-verification requirements, and other conditions imposed by applicable law.
Where Uoculi LLC acts as a Processor on behalf of a Controller, Uoculi LLC shall provide reasonable assistance to the Controller in responding to valid Data Subject requests, taking into account the nature of the processing and information reasonably available to Uoculi LLC.
12. PERSONAL DATA BREACHES
Uoculi LLC shall maintain reasonable procedures designed to identify, investigate, mitigate, and respond to security incidents involving Personal Data.
Where Uoculi LLC acts as a Processor and becomes aware of a confirmed Personal Data Breach affecting Personal Data processed on behalf of a Controller, Uoculi LLC shall, where required by applicable law:
- Notify the relevant Controller without undue delay;
- Provide available information reasonably necessary to understand the nature and potential consequences of the breach;
- Provide information concerning measures taken or proposed to address and mitigate the breach; and
- Reasonably cooperate with the Controller in fulfilling applicable legal obligations.
Nothing in this Section shall be construed as an acknowledgment of fault or liability by Uoculi LLC concerning any security incident.
13. DATA RETENTION AND DELETION
Personal Data shall be retained only for as long as reasonably necessary for the purposes for which it was collected or as otherwise required or permitted by applicable law.
Personal Data may be retained as necessary to:
- Process and fulfill orders;
- Maintain customer accounts;
- Process returns and refunds;
- Provide customer support;
- Maintain business, transaction, tax, and accounting records;
- Prevent and investigate fraud or abuse;
- Resolve disputes;
- Establish, exercise, or defend legal claims;
- Enforce agreements and policies;
- Protect the security and integrity of the Services; and
- Comply with applicable legal and regulatory obligations.
Upon termination of an applicable controller-processor relationship, Personal Data shall be deleted, anonymized, or returned where required by applicable law, unless continued retention is required or permitted by law.
14. MARKETING, COOKIES, AND ANALYTICS
Where permitted by applicable law, Uoculi LLC may process Personal Data to communicate with customers regarding products, promotions, special offers, abandoned shopping carts, newsletters, and other marketing content.
Customers may opt out of promotional email communications by using the unsubscribe mechanism included in such communications or by contacting the Company.
The website may also use cookies, pixels, analytics technologies, and similar tracking tools to:
- Maintain essential website functionality;
- Remember user preferences;
- Analyze website traffic and usage;
- Measure website and advertising performance;
- Personalize content or advertising, where permitted; and
- Detect fraud and protect website security.
Where legally required, non-essential cookies or tracking technologies shall be used only after obtaining appropriate consent.
15. AUDIT AND COMPLIANCE
Where required by applicable law and where Uoculi LLC acts as a Processor, the Company shall make available information reasonably necessary to demonstrate compliance with applicable obligations under this DPA.
A Controller may request reasonable compliance information or, where legally required, conduct an audit, provided that:
- Reasonable advance written notice is given;
- The audit occurs during normal business hours;
- The audit is limited to information and systems relevant to the processing covered by this DPA;
- The audit does not unreasonably interfere with Uoculi LLC’s business operations;
- Appropriate confidentiality and security obligations are maintained; and
- The Controller bears its own audit-related costs unless otherwise required by applicable law.
Uoculi LLC may provide relevant independent security reports, certifications, questionnaires, or other compliance documentation in satisfaction of an audit request where appropriate.
16. LIABILITY AND INDEMNIFICATION
Each party shall remain responsible for its own acts and omissions in connection with this DPA and the processing of Personal Data.
To the fullest extent permitted by applicable law, liability arising under or in connection with this DPA shall be subject to any exclusions and limitations of liability set forth in the Main Agreement.
Where Uoculi LLC processes Personal Data on behalf of a Customer or other Controller, that party agrees, to the extent permitted by applicable law, to indemnify and hold harmless Uoculi LLC and its officers, directors, employees, and agents from claims, damages, penalties, losses, costs, or liabilities arising from:
- Unlawful or unauthorized processing instructions provided to Uoculi LLC;
- Failure to obtain any consent or authorization legally required for the collection or processing of Personal Data;
- Unlawful collection, use, or disclosure of Personal Data by the Controller;
- Violation of applicable Data Protection Laws by the Controller; or
- Material breach of this DPA by the Controller.
Nothing in this DPA shall exclude or limit liability where such exclusion or limitation is prohibited by applicable law.
17. GOVERNING LAW
This DPA shall be governed by and construed in accordance with the laws of the State of Kansas, United States, without regard to its conflict of law principles, except to the extent that applicable Data Protection Laws require otherwise.
18. CONTACT INFORMATION
If you have any questions, concerns, or requests regarding this Data Processing Agreement or the processing of Personal Data, you may contact:
Uoculi LLC 7111 W 151st St, PMB 192 Overland Park, KS 66223 United States uoculi@protonmail.com
19. FINAL PROVISIONS
This DPA forms an integral part of the Main Agreement. In the event of any inconsistency between this DPA and the Main Agreement concerning the processing and protection of Personal Data, the provisions of this DPA shall prevail solely with respect to data protection matters, unless otherwise required by applicable law.
If any provision of this DPA is held to be invalid, unlawful, or unenforceable, the remaining provisions shall remain in full force and effect.
Failure by either party to exercise or enforce any right or provision under this DPA shall not constitute a waiver of that right or provision.
Uoculi LLC may update this DPA from time to time to reflect changes in its Services, processing activities, business practices, legal requirements, or regulatory developments. Where required by applicable law, appropriate notice of material changes shall be provided.
