Skip to content
Legal

Data Processing Addendum

Last updated July 2026

This DPA forms part of the agreement between Yaib (processor) and the customer (controller) where Yaib processes personal data on the customer's behalf under GDPR and comparable laws.

Roles

The customer is the controller and Yaib is the processor. Yaib processes personal data only on documented instructions from the customer, as needed to provide the service.

Security measures

  • Encryption in transit and at rest; secrets in an encrypted vault.
  • Per-organization data isolation enforced by database row-level security.
  • Role-based access control and immutable audit logs.
  • SSRF-guarded egress and dependency allowlisting.

Sub-processors

Yaib maintains a current list of sub-processors and will provide notice of changes, giving the customer the opportunity to object.

International transfers

Where personal data is transferred outside its region, transfers rely on Standard Contractual Clauses or an equivalent approved mechanism. Enterprise customers may elect data residency or bring-your-own-cloud.

Data-subject requests & breach

Yaib assists the customer in responding to data-subject requests and notifies the customer without undue delay upon becoming aware of a personal-data breach.

Return & deletion

On termination, Yaib deletes or returns personal data at the customer's choice, subject to legal retention requirements.

This is a template for the Yaib platform. For a binding agreement tailored to your organization, contact our team.

Data Processing Addendum — Yaib