Key points
- We process data only on your instructions
- We follow GDPR — the European privacy law
- Protections in place when data moves between countries
- Every company we share data with is named
This is the short version. The full document below is what counts.
1. Parties
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between NoCodePro.AI (the “Processor”) and the customer (the “Controller”). It applies where we process personal data on the Controller’s behalf.
2. Definitions
- “GDPR” means the General Data Protection Regulation and equivalent applicable data-protection laws;
- “Personal Data”, “Processing”, “Data Subject”, and “Sub-processor” have the meanings given in the GDPR.
3. Scope of Processing
We process Personal Data only to provide the Service, in accordance with the Controller’s documented instructions (including these Terms), and as required by law. The subject matter is the provision of the NoCodePro.AI platform; the data subjects and categories are those the Controller submits through the Service. This includes what visitors send through forms on sites the Controller publishes with the Service, when the Controller’s plan saves those entries (typically names, email addresses and messages), which we keep until the Controller deletes them.
4. Controller Obligations
The Controller warrants that it has a lawful basis for the Processing, has provided required notices to Data Subjects, and will comply with applicable data-protection laws.
5. Processor Obligations
We agree to:
- Process Personal Data only on documented instructions;
- Ensure personnel are bound by confidentiality;
- Implement appropriate technical and organisational security measures;
- Assist the Controller with Data-Subject requests and with security, breach-notification, and impact-assessment obligations;
- Delete or return Personal Data on termination, subject to legal retention requirements;
- Remain responsible to the Controller for any sub-processor’s performance of its data-protection obligations.
6. Sub-Processors
The Controller authorises us to engage the following sub-processors, each bound by data-protection obligations. We will give the Controller prior notice of sub-processor changes and a reasonable period to object on data-protection grounds.
| Sub-processor | Purpose | Region |
|---|---|---|
| Anthropic | AI model provider (Claude) for code generation, consultation & chat | USA |
| AI model provider (Gemini) for generation & image creation | USA / EU | |
| Google (Play) | Optional Google Play connection — uploads builds you request to your own Play Console | USA / global |
| OpenAI | AI model provider (GPT) for code generation, consultation & chat | USA |
| Clerk | Authentication & account identity | USA |
| Convex | Application database & backend | USA |
| Stripe | Payment processing, subscriptions & tax | USA / EU |
| Resend | Transactional email delivery | USA / EU |
| Vercel | Application hosting & content delivery | USA / global edge |
| Cloudflare | Asset storage (R2) & managed-site hosting/delivery | USA / global edge |
| Upstash | Rate limiting & caching (Redis) | USA / EU |
| Railway | Background workers & build services (mobile builds, container builds, Google Play connection) | USA (US West) |
| PostHog | Privacy-friendly product analytics | EU |
| Sentry | Error monitoring & performance tracing | USA / EU |
7. International Transfers
Where Personal Data is transferred outside your country or region, the parties rely on appropriate safeguards, including Standard Contractual Clauses, together with any supplementary measures required.
8. Security Measures
We maintain measures including encryption in transit and at rest, access controls and authentication, logging and monitoring, and incident-response procedures.
9. Data Subject Rights
We provide tools (data export and deletion in account settings) and reasonable assistance to help the Controller respond to Data-Subject requests for access, rectification, erasure, and portability.
10. Breach Notification
We will notify the Controller without undue delay after becoming aware of a Personal Data breach, with information reasonably available to help the Controller meet its own notification obligations.
11. Audit
We will make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits, subject to reasonable notice, frequency limits, and confidentiality.
12. Termination
On termination of the Service we will, at the Controller’s choice, delete or return Personal Data and delete existing copies within a reasonable period (typically 30 days) and, on request, confirm deletion in writing, except where retention is required by law.