Privacy Policy

Last updated: 11 August 2026

This Privacy Policy explains what personal data Uboros collects when you use our platform, why we collect it, how we use it, and the choices and rights available to you. It is aligned with the EU General Data Protection Regulation ("GDPR") and the Estonian Personal Data Protection Act (Isikuandmete kaitse seadus).

Uboros (the "Service") is operated by WorkHold Technologies OÜ, an Estonian private limited company (osaühing), registry code 17570836, registered at Ahtri tn 12, Kesklinna linnaosa, Tallinn 15551, Estonia.

1. Who controls your data

Uboros is the data controller for personal data we collect about you as a user of the Service (e.g. your email address, your account preferences, your billing history). For personal data that you process through the Service (e.g. data you ingest from your ad accounts or upload as creative inputs), Uboros acts as a data processor on your behalf — see our Data Processing Agreement.

2. What data we collect

2.1 Data you provide directly

2.2 Data we generate as you use the Service

2.3 Data we receive from third parties

We do not use third-party advertising trackers (Google Analytics, Facebook Pixel, etc.) — no ad networks, no retargeting, no cross-site tracking. Visitor analytics on our marketing site remain first-party only (coarsened IP, coarsened user-agent, hashed session). Inside the signed-in Service, we use PostHog — a product-analytics processor, not an advertising tracker — to understand onboarding completion and feature usage; see the sub-processor table below and our Cookie Policy for what it stores.

3. How we use your data

4. Legal bases for processing

Under GDPR Article 6, we process personal data on the following bases:

Processing Legal basis
Operating the Service for paying customers Contract (Art. 6(1)(b))
Operating the Service for trial users Pre-contractual measures (Art. 6(1)(b))
Billing and tax records Legal obligation (Art. 6(1)(c))
Security, fraud and abuse prevention Legitimate interests (Art. 6(1)(f))
Aggregate product analytics Legitimate interests (Art. 6(1)(f))
Transactional emails Contract (Art. 6(1)(b))

Where we rely on legitimate interests, you have the right to object — see Your rights under GDPR.

5. Who we share data with (sub-processors)

To run the Service we share data with carefully selected sub-processors. Each is bound by data-processing terms equivalent to or stricter than this policy.

Sub-processor Purpose Region
Stripe Subscription billing, payment processing, customer portal Ireland (EU) / USA (SCC)
Cloudflare DNS, CDN, DDoS protection, edge tunnels Global edge / USA (SCC)
Hosting provider Application servers and database (location confirmed at launch) EU
Anthropic Claude AI models — competitor tagging, brief generation, AI iteration USA (SCC)
OpenAI GPT and Whisper models — brief drafting, audio transcription USA (SCC)
Google Gemini and Veo models — brief drafting, video generation EU + USA (SCC)
Apify Public competitor-ad-library data extraction EU (Czech Republic)
fal.ai Image and video generation models USA (SCC)
Resend Transactional email delivery USA (SCC)
PostHog Product analytics inside the signed-in Service (onboarding funnel, feature usage). Identified by account id only — no name or email is sent USA (SCC)

We will update this list when we add or change sub-processors. Material changes will be announced in-product at least thirty (30) days before they take effect.

6. International transfers

Some of our sub-processors are based outside the European Economic Area, primarily in the United States. Where data is transferred to a country without a European Commission adequacy decision, we rely on the EU Standard Contractual Clauses (SCCs) and, where appropriate, supplementary technical measures (encryption in transit and at rest, access controls).

You can request a copy of the SCCs in place with a specific sub-processor by emailing hello@uboros.com.

7. How long we keep data

7.1 Integrator / API data handling

When you connect a third-party platform to Uboros via our API or MCP server, that platform acts on your authorisation. It sends us only what is needed for the feature you invoke — typically creative media URLs and aggregate performance statistics. We process these through the AI sub-processors listed in section 5 (Anthropic, OpenAI, Google, fal.ai) to produce annotations and creative, return the result to you, and do not use the inputs to train shared models. Access is tenant-scoped to your project and bound to a revocable access token you (or the operator) control.

8. Security

We protect your data with industry-standard technical and organisational measures, including:

If you discover a security issue, please email security@uboros.com.

9. Your rights under GDPR

You have the following rights regarding personal data we hold about you. You can exercise them by emailing hello@uboros.com from the address on your account; we will respond within thirty (30) days.

10. Children

Uboros is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified at least thirty (30) days before they take effect, by email to the address on your account and by an in-product notice. Minor clarifications may be made with the updated date noted above.

12. Contact and complaints

Privacy questions, rights requests, or complaints can be sent to hello@uboros.com. If you are unsatisfied with our response, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (AKI) or your local data-protection supervisory authority.