Legal

Data Processing Addendum

Effective Date: July 28, 2026 Last Updated: July 28, 2026

This Data Processing Addendum applies where Peko processes personal data on your behalf to run the hosted platform. It supplements the Terms of Service. If you host an application that processes personal data and need an executed copy, contact [email protected].

This Data Processing Addendum ("DPA") forms part of the agreement between Peko UI Technologies LLC ("Peko", "Processor") and the customer identified in the account ("Customer", "Controller") for Customer's use of the Peko hosted platform (the "Agreement"). It applies where Peko processes Customer Personal Data on Customer's behalf in providing the hosting Services. Where there is a conflict, this DPA controls over the Agreement as to the subject matter here.

1. Definitions

Capitalized terms not defined here have the meaning in the Agreement. "Data Protection Laws" means all laws applicable to the processing of Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the Swiss Federal Act on Data Protection, and U.S. state privacy laws including the California Consumer Privacy Act as amended ("CCPA"). "Controller", "Processor", "Personal Data", "Processing", "Data Subject", "Personal Data Breach", and "Supervisory Authority" have the meanings in the GDPR (and the corresponding CCPA terms "Business", "Service Provider", "Consumer", and "sell" apply where the CCPA governs). "Customer Personal Data" means Personal Data that Peko Processes on Customer's behalf as described in Annex A. "Sub-processor" means a third party engaged by Peko to Process Customer Personal Data. "SCCs" means the European Commission Standard Contractual Clauses (Decision 2021/914).

2. Roles and Scope

2.1 As between the parties, Customer is the Controller (or Business) and Peko is the Processor (or Service Provider) of Customer Personal Data. Peko Processes Customer Personal Data only to provide the Services and only on Customer's documented instructions, including as set out in the Agreement, this DPA, and Customer's configuration and use of the Services.

2.2 Customer is responsible for the lawfulness of Customer Personal Data and of Customer's instructions, including having a lawful basis, providing any required notices to, and obtaining any required consents from, Data Subjects (the end-users of Customer's hosted applications).

2.3 Peko will inform Customer if, in its opinion, an instruction infringes Data Protection Laws (without obligation to provide legal advice).

3. Processor Obligations

In accordance with GDPR Article 28(3), Peko will:

  • Instructions. Process Customer Personal Data only on Customer's documented instructions, including regarding transfers, unless required by law (in which case Peko will inform Customer unless legally prohibited).
  • Confidentiality. Ensure that personnel authorized to Process Customer Personal Data are bound by confidentiality obligations.
  • Security. Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk (GDPR Article 32), as described in Annex B.
  • Sub-processors. Engage Sub-processors only under Section 4.
  • Data-subject requests. Taking into account the nature of the Processing, assist Customer by appropriate measures, insofar as possible, to respond to Data Subject requests. If Peko receives such a request directly, it will, unless prohibited, direct the Data Subject to Customer and will not respond except on Customer's instructions.
  • Assistance. Assist Customer in ensuring compliance with its obligations under GDPR Articles 32 to 36 (security, breach notification, data-protection impact assessments, and prior consultation), taking into account the nature of Processing and the information available to Peko.
  • Deletion or return. At the end of the Services, delete or return all Customer Personal Data at Customer's choice and delete existing copies unless retention is required by law (see Section 8).
  • Audits. Make available to Customer information necessary to demonstrate compliance with this Section and allow for and contribute to audits, subject to reasonable confidentiality, security, frequency, and notice conditions. Peko may satisfy this by providing third-party audit reports or certifications where available.

4. Sub-processors

4.1 Customer provides general authorization for Peko to engage Sub-processors to Process Customer Personal Data. Peko's current Sub-processors are listed at pekoui.com/legal/subprocessors and in Annex C.

4.2 Peko will impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA, and remains liable for its Sub-processors' performance.

4.3 Peko will give Customer notice of the addition or replacement of a Sub-processor (by updating the list and, where Customer subscribes to notifications, by email) at least 10 days before the Sub-processor begins Processing, during which Customer may object on reasonable data-protection grounds. If the parties cannot resolve the objection, Customer may terminate the affected Services.

5. Personal Data Breach

Peko will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to it to help Customer meet its breach-notification obligations. Peko's notification is not an acknowledgment of fault.

6. International Transfers

6.1 Peko will not transfer Customer Personal Data out of the EEA or Switzerland except in compliance with Data Protection Laws.

6.2 Where Customer Personal Data originating in the EEA or Switzerland is transferred to Peko or a Sub-processor in a country without an adequacy decision, the parties agree the SCCs are incorporated by reference and completed as follows: Module Two (Controller-to-Processor) applies between Customer and Peko; Module Three (Processor-to-Processor) applies between Peko and its Sub-processors; the docking clause, the option under Clause 9 for general Sub-processor authorization with 10-day notice, and Clause 17 governing law of Ireland apply; the annexes are populated by Annex A to C of this DPA. Peko is a U.S. importer.

7. CCPA and U.S. State Privacy Laws

7.1 Where the CCPA applies, Peko acts as a Service Provider (or Contractor) and Processes Customer Personal Data only to perform the Services (the "business purpose") specified in the Agreement.

7.2 Peko will not: (a) sell or share Customer Personal Data; (b) retain, use, or disclose it for any purpose other than the business purpose, or outside the direct business relationship, except as permitted by the CCPA; or (c) combine it with personal information from other sources except as permitted by the CCPA. Peko certifies that it understands and will comply with these restrictions.

7.3 Peko will assist Customer in responding to Consumer rights requests as described in Section 3, and will notify Customer if it determines it can no longer meet its obligations under the CCPA.

8. Term, Termination, Deletion

This DPA is effective while Peko Processes Customer Personal Data under the Agreement. On termination or expiry, and at Customer's choice, Peko will delete or return Customer Personal Data and delete existing copies within a reasonable period, except where retention is required by law or for routine backups that are overwritten on a rolling basis and remain protected until deleted.

9. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, and any reference to a party's liability means aggregate liability under the Agreement and this DPA together.

10. General

This DPA supplements the Agreement. Except as amended here, the Agreement remains in effect. This DPA is governed by the governing law of the Agreement (State of California) except where Data Protection Laws require otherwise (for example, the SCCs' governing law for transfer matters).

Annex A: Details of Processing

  • Subject matter: Peko's provision of the hosted platform (managed hosting of Customer's server application) under the Agreement.
  • Duration: for the term of the Agreement, plus the deletion period in Section 8.
  • Nature and purpose: hosting, running, storing, transmitting, and delivering Customer's application and its data in order to provide the Services, and related logging and metering.
  • Categories of Data Subjects: the end-users and visitors of Customer's hosted application, and any individuals whose Personal Data Customer chooses to process through the application.
  • Categories of Personal Data: as determined and controlled by Customer through its use of the Services, and may include identifiers, contact details, account data, content submitted by end-users, IP addresses, and usage or technical data. Customer must not send special-category data except as agreed.
  • Special categories: none, unless expressly agreed in writing.

Annex B: Technical and Organizational Measures

Peko maintains measures appropriate to the risk, including: encryption of data in transit (HTTPS/TLS); access controls and least-privilege service identities; tenant isolation; secrets held in a managed secret store; network controls restricting internal backends; logging and monitoring; and personnel confidentiality obligations. Signing material supplied for remote builds is encrypted to the build runner's key and is not decryptable by Peko. Build and screenshot machines are ephemeral and are wiped or destroyed after each run.

Annex C: Sub-processors

The current list is maintained at pekoui.com/legal/subprocessors. As of the effective date:

Sub-processorPurposeLocation
Amazon Web Services, Inc.Application hosting, container builds, and content deliveryUSA / global
Google LLC (Firebase & Google Cloud)Authentication, database, storage, compute, and secretsUSA / global
Cloudflare, Inc.Object storage and media deliveryUSA / global
Stripe, Inc.Payment and subscription processingUSA
Twilio Inc. (SendGrid)Transactional emailUSA
Google LLC (Gemini API)AI drafting, when the customer uses itUSA
HostMyMacApple builds and macOS/iOS screenshot captureUSA

Contact

To request an executed copy of this DPA, or with any question about it, contact [email protected].