yebo®
Legal

Data Processing Agreement

The data-protection terms governing Yebo's processing of personal data on the customer's behalf.

Effective date: [to be set]Last updated: [to be set]

This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("Controller") and [Yebo legal entity] ("Processor", "Yebo") for the provision of the Yebo OS services (the "Services"). It governs the Processor's processing of Personal Data on behalf of the Controller and applies to the extent that data-protection laws, including the GDPR and [applicable local data-protection law], apply to that processing. Where this DPA and the main agreement conflict on data protection, this DPA prevails.

1. Definitions

Terms such as "Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Personal Data Breach" have the meanings given in applicable data-protection law. "Sub-processor" means any processor engaged by Yebo to process Personal Data in connection with the Services.

2. Roles and scope

As between the parties, the Controller is the controller and Yebo is the processor of the Personal Data processed under the Services. Yebo processes Personal Data only on the Controller's documented instructions, including those set out in the agreement and this DPA, unless required to do otherwise by law, in which case Yebo will inform the Controller (unless legally prohibited).

3. Details of processing

Subject matter: provision of the Services. Duration: the term of the agreement plus any period required for return or deletion. Nature and purpose: hosting, integration, unification, and governed analysis of the Controller's data to deliver the Services. Types of Personal Data and categories of Data Subjects: as determined and supplied by the Controller and recorded in [Annex I / the Order Form].

4. Controller obligations

The Controller warrants that it has a lawful basis for the processing it instructs, that its instructions are lawful, and that it has provided any notices and obtained any consents required for Yebo to process the Personal Data as contemplated by the agreement.

5. Confidentiality

Yebo ensures that personnel authorised to process Personal Data are bound by appropriate confidentiality obligations and process the data only as instructed.

6. Security measures

Yebo implements and maintains appropriate technical and organisational measures to protect Personal Data, including encryption in transit and at rest, tenant isolation, identity and access management, least-privilege access, and immutable audit logging. A current description is set out in the Security architecture overview and [Annex II].

7. Sub-processors

The Controller grants general authorisation for Yebo to engage Sub-processors to process Personal Data, provided Yebo imposes data-protection obligations no less protective than this DPA and remains responsible for their performance. Yebo maintains a list of Sub-processors and notifies the Controller of intended changes with a reasonable opportunity to object on legitimate data-protection grounds. See the Sub-processors page.

8. Data subject requests

Taking into account the nature of the processing, Yebo assists the Controller by appropriate technical and organisational measures, insofar as possible, to respond to requests to exercise Data Subject rights. If Yebo receives such a request directly, it will, unless legally prohibited, refer the Data Subject to the Controller.

9. Personal data breaches

Yebo notifies the Controller without undue delay after becoming aware of a Personal Data Breach affecting the Controller's Personal Data, and provides information reasonably available to it to assist the Controller in meeting its own notification obligations.

10. International transfers

Where processing involves a transfer of Personal Data to a third country, the parties rely on an appropriate transfer mechanism, including the Standard Contractual Clauses (incorporated by reference where applicable) and the deployment-region controls the Controller selects.

11. Audits

Yebo makes available information necessary to demonstrate compliance with this DPA and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable notice, confidentiality, and safeguards for the security of other customers.

12. Return and deletion

On termination or expiry of the Services, Yebo, at the Controller's choice, returns or deletes the Personal Data and deletes existing copies, unless applicable law requires continued storage.

13. Governing law

This DPA is governed by [governing law] and subject to the jurisdiction set out in the main agreement.

Items shown in [square brackets] — legal entity, governing law, dates, service-level figures, and contact addresses — are to be finalised by Yebo and its counsel before publication.

Questions

Need more detail, or a compliance review with your team?

Talk to us about security, data protection, and contractual terms — including the full pack under NDA.

DISCUSS COMPLIANCE ↗