Legal information

Data Processing Agreement

This document was last updated on Sep 24, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Mockuuups s.r.o. ("Processor", "we", "us") and you ("Controller", "Customer") for use of our services.

1. Scope

This DPA applies when we process personal data on your behalf in connection with Mockuuups services. For most users of our desktop application, plugins, and website, your content is processed locally on your device and this DPA does not apply to that content.

This DPA primarily applies to account and billing data we process for all customers. It also applies when you use optional features that send content to our servers (such as Share links), and to the Developer API if you use it. If we offer a server-side render fallback in the future, this DPA would apply to that processing when you use it.

2. Processing details

The following details describe the nature of our data processing activities:

3. Our obligations

We will:

4. Security measures

Our security measures include:

5. Sub-processors

We use the sub-processors listed on our List of Subprocessors. The list also shows planned additions and when they take effect. We give at least 30 days' notice by email before we add or replace a sub-processor. Team owners can subscribe to these notices for free in team settings. The owner is always included and can add up to five compliance contacts. You may object on reasonable data-protection grounds by replying before the change takes effect. If we cannot resolve your objection, you may terminate the affected service and receive a pro-rata refund for it. We may give less than 30 days' notice for an emergency replacement. We will explain the reason in the notice.

6. International transfers

Some sub-processors transfer data outside the EEA. These transfers rely on the EU-US Data Privacy Framework (for certified US companies) and Standard Contractual Clauses (2021 SCCs).

7. Data breach notification

We will notify you without undue delay (within 72 hours) upon becoming aware of a personal data breach affecting your data.

8. Termination

Upon termination of services, you may delete your data via your account settings at the account management area, or request deletion by using the contact methods listed below. We will delete your data within 30 days of termination.

9. Liability

Our liability under this DPA is subject to the limitations in our Terms of Service.

10. Governing law

This DPA is governed by the laws of the Czech Republic. Disputes will be resolved by the courts in Prague, Czech Republic.

Contact

For questions about this DPA, please contact us at [email protected] or use the contact form.