Data Processing Addendum
Last updated July 2026
This DPA forms part of the agreement between Yaib (processor) and the customer (controller) where Yaib processes personal data on the customer's behalf under GDPR and comparable laws.
Roles
The customer is the controller and Yaib is the processor. Yaib processes personal data only on documented instructions from the customer, as needed to provide the service.
Security measures
- Encryption in transit and at rest; secrets in an encrypted vault.
- Per-organization data isolation enforced by database row-level security.
- Role-based access control and immutable audit logs.
- SSRF-guarded egress and dependency allowlisting.
Sub-processors
Yaib maintains a current list of sub-processors and will provide notice of changes, giving the customer the opportunity to object.
International transfers
Where personal data is transferred outside its region, transfers rely on Standard Contractual Clauses or an equivalent approved mechanism. Enterprise customers may elect data residency or bring-your-own-cloud.
Data-subject requests & breach
Yaib assists the customer in responding to data-subject requests and notifies the customer without undue delay upon becoming aware of a personal-data breach.
Return & deletion
On termination, Yaib deletes or returns personal data at the customer's choice, subject to legal retention requirements.
This is a template for the Yaib platform. For a binding agreement tailored to your organization, contact our team.