YAKKL Data Processing Addendum
Data-processing terms for business customers using YAKKL services.
This Data Processing Addendum ("DPA") forms part of the YAKKL Business Services Agreement or other agreement ("Agreement") between the customer identified in the Agreement ("Customer") and YAKKL, Inc. ("YAKKL"). It applies when YAKKL Processes Customer Personal Data on Customer's behalf in providing the Services. Capitalized terms not defined here have the meanings in the Agreement or applicable Data Protection Laws.
1. Definitions
- Customer Personal Data means Personal Data contained in Customer Data that YAKKL Processes on behalf of Customer under the Agreement.
- Data Protection Laws means privacy and data-protection laws applicable to a Party's Processing under the Agreement, including, where applicable, the GDPR, UK GDPR, Swiss Federal Act on Data Protection, California Consumer Privacy Act as amended by the CPRA, and other applicable U.S. state privacy laws.
- Data Subject, Personal Data, Personal Data Breach, Process/Processing, Controller, Processor, and Supervisory Authority have the meanings in applicable Data Protection Laws.
- Subprocessor means a third party engaged by YAKKL to Process Customer Personal Data for the Services.
- SCCs means the European Commission Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914, as amended or replaced.
- UK Addendum means the then-current UK International Data Transfer Addendum to the EU SCCs or other lawful UK transfer mechanism selected in Schedule 3.
2. Scope and roles
Customer is the Controller or Processor of Customer Personal Data, and YAKKL is the Processor or Subprocessor, as applicable. Each Party will comply with its obligations under Data Protection Laws.
The Agreement, this DPA, Orders, Service settings, administrator configurations, and documented support instructions are Customer's documented instructions. YAKKL will Process Customer Personal Data only on those instructions to provide, secure, maintain, support, and administer the Services; prevent abuse; and comply with law. If law requires other Processing, YAKKL will notify Customer before Processing unless legally prohibited.
YAKKL will promptly inform Customer if, in YAKKL's reasonable opinion, an instruction violates Data Protection Laws. YAKKL may suspend the affected Processing until the Parties resolve the issue.
YAKKL does not use Customer Personal Data or Output to train AI models and will not authorize a Subprocessor to do so on YAKKL's behalf.
3. Customer obligations
Customer will:
- provide lawful instructions and have a lawful basis for Processing;
- provide required notices and obtain required consents;
- determine whether the Services, settings, retention, providers, and security are appropriate for Customer Personal Data;
- avoid submitting prohibited or specially regulated data unless expressly supported by the Order and controls;
- respond to Data Subjects and regulators as Controller; and
- configure Users, administrators, permissions, BYOK routes, custom endpoints, retention, and integrations appropriately.
Customer acknowledges that direct BYOK providers and custom endpoints selected and contacted directly by Customer may be independent recipients controlled by Customer rather than YAKKL Subprocessors.
4. Confidentiality and personnel
YAKKL will ensure that personnel authorized to Process Customer Personal Data are bound by confidentiality obligations, receive appropriate privacy and security training, and access data only as necessary for their duties. YAKKL will apply role-based or equivalent access controls appropriate to the Services.
5. Security
YAKKL will maintain reasonable technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The baseline measures are described in Schedule 2 and may evolve without materially reducing overall protection during an Order Term.
Customer is responsible for security outside YAKKL's control, including devices, local storage, identity providers, Users, administrator permissions, repositories, credentials, BYOK keys, custom endpoints, customer-controlled encryption, deployment targets, and backups.
6. Personal Data Breaches
YAKKL will notify Customer without undue delay after confirming a Personal Data Breach affecting Customer Personal Data. Notification will include information reasonably available to YAKKL about the nature of the incident, affected data and Data Subjects, likely consequences, mitigation, and a contact for follow-up. Information may be provided in phases.
YAKKL's notice is not an admission of fault or liability. Customer is responsible for determining whether to notify authorities or Data Subjects, and YAKKL will provide reasonable assistance considering the nature of Processing and information available.
7. Data Subject requests
Taking into account the nature of Processing, YAKKL will provide reasonable technical and organizational assistance for Customer to respond to Data Subject requests. If YAKKL receives a request concerning Customer Personal Data, YAKKL will direct the requester to Customer and notify Customer where permitted, unless law requires YAKKL to respond directly.
Customer is responsible for confirming the requester, interpreting the request, and instructing YAKKL. Additional work beyond standard controls may be subject to reasonable fees where legally permitted.
8. Impact assessments and consultations
YAKKL will provide information reasonably necessary for Customer's data-protection impact assessment or prior consultation, considering the nature of Processing and information available to YAKKL. Customer remains responsible for the assessment, consultation, and its use of the Services.
9. Subprocessors
Customer gives YAKKL general written authorization to engage Subprocessors listed in YAKKL's current subprocessor register. YAKKL will impose data-protection obligations materially consistent with this DPA to the extent applicable to the Subprocessor's services and remains responsible for its Subprocessors' performance to the extent required by Data Protection Laws.
YAKKL will update the register before a new Subprocessor begins Processing Customer Personal Data and provide notice to subscribed business contacts at least 15 days in advance where reasonably practicable. Urgent replacements for security, availability, legal, or provider-discontinuation reasons may receive shorter notice with an explanation.
Customer may object during the notice period on reasonable data-protection grounds. The Parties will work in good faith on a commercially reasonable alternative. If none is available, Customer may stop using the affected feature; any further termination remedy must be stated in the Order or required by law. An objection does not permit Customer to continue using an affected Subprocessor while withholding authorization.
Customer-selected direct BYOK providers, custom endpoints, and integrations are not YAKKL Subprocessors for data transmitted without YAKKL Processing. If the same provider also processes data for YAKKL-managed routing, it is a Subprocessor for that managed path.
10. Audits and compliance information
YAKKL will make available information reasonably necessary to demonstrate compliance, such as current security documentation, third-party reports, certifications, summaries, and questionnaire responses appropriate to the Services.
If that information is insufficient, Customer may request one audit per year, and additional audits following a confirmed Personal Data Breach or regulator requirement. Audits must be conducted by an independent qualified auditor under confidentiality, on reasonable notice, during business hours, without accessing another customer's data or disrupting operations. Customer bears its costs and YAKKL's reasonable costs unless an audit identifies a material breach by YAKKL.
11. Return and deletion
During the Term, Customer may access, export, or delete Customer Personal Data through available controls. After termination or expiration, YAKKL will delete or return Customer Personal Data according to the applicable Order, plan, settings, and retention schedule, unless law requires retention.
Deletion may not immediately remove data from encrypted backups, incident records, security logs, legal holds, or billing records. Retained data remains protected and is not used for another purpose. De-identified data that no longer constitutes Personal Data is outside this deletion obligation.
12. Government requests
Unless legally prohibited, YAKKL will notify Customer of a legally binding request for Customer Personal Data. YAKKL will review requests for validity, seek to narrow overbroad requests, disclose only what is legally required, and document responses as appropriate.
13. International transfers
YAKKL may Process Customer Personal Data in the United States and other countries listed in the subprocessor register. Where a restricted transfer requires safeguards:
- an applicable adequacy decision will be used where available;
- otherwise, the SCCs apply as completed in Schedule 3;
- UK transfers use the UK Addendum or other lawful mechanism in Schedule 3;
- Swiss transfers use the SCCs with adaptations required by Swiss law; and
- YAKKL will implement supplementary measures reasonably appropriate to the transfer risk.
If the transfer mechanism is invalidated, the Parties will cooperate to implement a lawful replacement. The unmodified operative text of the SCCs is incorporated by reference as completed by the elections in Schedule 3 and is deemed executed by the Parties upon execution of this DPA. YAKKL is not certified under the EU–U.S. Data Privacy Framework; restricted transfers rely on the mechanisms stated in this Section and Schedule 3.
14. U.S. state privacy terms
To the extent U.S. state privacy laws apply, YAKKL acts as Customer's service provider/processor for Customer Personal Data. YAKKL will not:
- sell or share Customer Personal Data;
- retain, use, or disclose it outside the business purposes specified in the Agreement and Customer's instructions, except as legally permitted;
- combine it with personal data received from another person or from YAKKL's own consumer interactions except as permitted by applicable law to provide the Services; or
- use it for targeted advertising or AI model training.
YAKKL certifies that it understands and will comply with these restrictions. Customer may take reasonable steps to ensure compliant use and require remediation of unauthorized use.
15. Liability and conflicts
The Agreement's liability limits apply to this DPA unless an Order expressly states otherwise or law prohibits limitation. If this DPA conflicts with the Agreement on data protection, this DPA controls. The operative SCCs control over conflicting terms for covered transfers.
Schedule 1 — Details of Processing
Subject matter and purpose
Providing YAKKL Services selected by Customer, including AI-assisted generation and orchestration, agentic execution, collaboration, cloud storage and logging, retrieval and indexing, model routing, managed execution, API services, deployment, hosting, support, security, and billing reconciliation.
Duration
The applicable Order Term plus the period required for return, deletion, backups, legal obligations, security, and dispute handling.
Nature of Processing
Collection, receipt, access, recording, organization, storage, retrieval, indexing, embedding, caching, consultation, transmission, model inference, tool execution, alteration at Customer's instruction, hosting, security monitoring, support, deletion, and other operations required for the Services.
Categories of Data Subjects
Customer Users, employees, contractors, applicants, clients, suppliers, partners, end users, website visitors, support contacts, and other people whose data Customer includes in Customer Data.
Categories of Customer Personal Data
Identifiers and contact data; professional data; account and workspace data; communications; prompts and responses; source code, repositories, files, plans, artifacts, and hosted content containing Personal Data; action and tool records; usage and audit records; device and network data; and other unstructured data submitted by Customer.
Sensitive data
No sensitive, special-category, regulated, or criminal-conviction data is intended unless the applicable Order and documentation expressly support it. Customer controls the data submitted and must apply appropriate restrictions and safeguards.
Frequency
Continuous or intermittent, depending on Customer's use and configuration.
Retention
As specified by the Order, plan, workspace settings, product disclosures, and Section 11. Customer may delete eligible cloud Customer Data through available controls.
Schedule 2 — Baseline Technical and Organizational Measures
YAKKL will maintain measures appropriate to the Services and risk, including:
- documented security and privacy responsibilities;
- access control, least privilege, account lifecycle management, and authentication protections;
- encryption in transit and at rest for applicable YAKKL-controlled cloud systems;
- secure software-development, code-review, dependency, vulnerability, and change-management practices;
- logging, monitoring, incident detection, response, escalation, and post-incident review;
- backups, restoration, availability, and business-continuity measures appropriate to paid cloud Services;
- vendor and Subprocessor diligence and contractual controls;
- personnel confidentiality, training, and access termination;
- data minimization, retention, deletion, and environment separation;
- physical and environmental controls inherited from audited infrastructure providers; and
- periodic risk assessment and testing.
This schedule states baseline categories of measures and does not promise any certification, recovery objective, testing cadence, or notification timeframe not expressly stated in the Agreement or an Order.
Schedule 3 — International Transfer Elections
A. EU SCC elections
- Modules. Module Two (Controller to Processor) applies where Customer is a Controller of Customer Personal Data; Module Three (Processor to Processor) applies where Customer is a Processor acting for another controller. YAKKL is the data importer; Customer is the data exporter.
- Clause 7 (docking). Included.
- Clause 9 (subprocessors). Option 2 (general written authorization); the notice period is the subprocessor-notice period stated in Section 9 of this DPA.
- Clause 11 (redress). The optional independent-dispute-resolution language is not included.
- Clause 13 (supervision). The competent supervisory authority is determined in accordance with Clause 13; where the data exporter is not established in an EU Member State, the Irish Data Protection Commission is the competent supervisory authority.
- Clauses 17 and 18 (law and forum). Option 1: the SCCs are governed by the law of Ireland, and disputes are resolved before the courts of Ireland.
- Annex I. The parties are Customer (exporter; details per the Agreement and applicable Order) and YAKKL, Inc. (importer; contact: privacy@yakkl.com). The description of the transfer is Schedule 1 of this DPA.
- Annex II. Schedule 2 of this DPA.
- Annex III. YAKKL's current subprocessor register, as published, versioned, and dated at YAKKL's legal site and incorporated dynamically per Section 9; the register version in effect at DPA execution is the initial list.
B. UK transfers
The UK International Data Transfer Addendum (ICO approved addendum) is incorporated. Table 1 is completed with the party details in Annex I; Table 2 refers to the SCCs as completed in Part A; Table 3 refers to the Annexes identified in Part A; for Table 4, neither party may end the UK Addendum as set out in its Section 19.
C. Swiss transfers
For transfers subject to the Swiss Federal Act on Data Protection, the SCCs as completed above apply with these adaptations: references to the GDPR are understood as references to the FADP to the extent applicable; the Federal Data Protection and Information Commissioner (FDPIC) is the competent supervisory authority for Swiss transfers; references to EU Member States include Switzerland where required so that Swiss data subjects may enforce their rights in Switzerland.