Data Processing Addendum

Version: 1.0
Effective date: 27 July 2026

This Data Processing Addendum (“DPA”) forms part of the agreement (“Agreement”) between Yubano (“Processor”) and the customer identified in the Agreement (“Customer”) for Yubano. It applies when Processor processes Customer Personal Data on Customer’s behalf.

1. Definitions

“Applicable Data Protection Law” means laws applicable to the Processing of Customer Personal Data under the Agreement, including, where applicable, the GDPR, UK GDPR, Swiss FADP, and U.S. state comprehensive privacy laws.

“Customer Personal Data” means Personal Data contained in Inputs, Outputs, account data, or other data that Processor processes on Customer’s behalf under the Agreement.

“GDPR” means Regulation (EU) 2016/679. “UK GDPR” has the meaning under UK data-protection law. “Personal Data,” “Process,” “Processor,” “Controller,” “Data Subject,” “Subprocessor,” and “Supervisory Authority” have the meanings in Applicable Data Protection Law.

“Security Incident” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. It excludes unsuccessful attempts that do not compromise Customer Personal Data.

2. Roles and scope

Customer is Controller and Processor is Processor for Customer Personal Data. Each party will comply with Applicable Data Protection Law. Annex I describes the subject matter, duration, nature, purpose, data categories, and Data Subjects.

Processor may process account, billing, security, abuse, and product-relationship data as an independent Controller where and to the extent described in the Privacy Policy and permitted by law.

3. Customer instructions

Processor will Process Customer Personal Data only on Customer’s documented instructions, including the Agreement, Customer’s configured use of the Service, and written instructions consistent with the Agreement, unless law requires otherwise. If law requires Processing, Processor will inform Customer before Processing unless prohibited.

Processor will promptly inform Customer if it believes an instruction violates Applicable Data Protection Law. Processor is not required to perform an instruction that violates law or the Agreement. Customer is responsible for the lawfulness, accuracy, and quality of Customer Personal Data, its instructions, notices, consents, and legal bases.

4. Confidentiality

Processor will ensure personnel authorized to Process Customer Personal Data are bound by confidentiality obligations and receive appropriate privacy and security training.

5. Security

Processor will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data, taking account of the state of the art, implementation costs, and the nature, scope, context, purposes, and risks of Processing. Current measures are described in Annex II.

Customer is responsible for securely configuring the Service, managing user permissions, protecting credentials, and avoiding submission of data not appropriate for the Service.

6. Security Incidents

Processor will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data and, where feasible, within 48 hours. Notice will include available information about the nature of the incident, affected data and Data Subjects, likely consequences, mitigation, and a contact point. Processor may provide information in phases and will take reasonable steps to contain, investigate, and mitigate the incident.

Notification is not an admission of fault. Customer is responsible for notifications to authorities and Data Subjects unless law assigns that duty to Processor. Processor will reasonably assist Customer, considering the nature of Processing and information available.

7. Subprocessors

Customer gives general written authorization for the subprocessors in the . Processor will impose data-protection obligations materially protective as this DPA requires for the relevant Processing and remains responsible for each Subprocessor’s performance to the extent required by law.

Processor will give at least 30 days’ advance notice of a new Subprocessor, except an urgent replacement needed for security, law, or continuity. Customer may object on reasonable data-protection grounds within 15 days. The parties will seek a commercially reasonable solution. If none is available, Customer may terminate the affected Service and receive a pro-rata refund of prepaid unused fees for that Service. This is Customer’s sole remedy for a Subprocessor objection, except where law requires otherwise.

8. Data Subject requests

Considering the nature of Processing, Processor will provide reasonable technical and organizational assistance for Customer to respond to Data Subject requests. If Processor receives a request relating to Customer Personal Data, it will direct the requester to Customer where legally permitted and will not independently respond except on Customer’s instruction or as required by law.

9. DPIAs and regulatory consultation

Processor will provide information reasonably necessary for Customer’s data-protection impact assessment and prior consultation obligations, considering the nature of Processing and information available. Additional assistance beyond standard documentation may be subject to reasonable fees unless required because of Processor’s breach.

10. Deletion and return

During the term, Customer may export or delete Customer Personal Data using available Service features. At termination or Customer’s written request, Processor will delete or return Customer Personal Data within 30 days, unless law requires retention. Backup copies will be isolated from ordinary use and deleted on the normal cycle within up to 30 days. Processor may retain data necessary to establish or defend legal claims, comply with law, or maintain security records, subject to continued protection.

11. Audits and information

Processor will make available information reasonably necessary to demonstrate compliance, including current security documentation and independent audit reports when available. No more than once annually, Customer may submit a written audit questionnaire. If that is insufficient and Applicable Data Protection Law requires further audit, Customer may conduct an audit through an independent auditor bound by confidentiality, on at least 30 days’ notice, during normal business hours, without accessing other customers’ data or disrupting operations.

Customer bears audit costs unless an audit identifies Processor’s material breach. Processor may charge reasonable fees for disproportionate assistance. Nothing requires disclosure of trade secrets, vulnerability details that would create security risk, or information violating another party’s rights.

12. International transfers

12.1 EEA restricted transfers

If Customer Personal Data protected by the GDPR is transferred to a country without an applicable adequacy decision, the parties incorporate the (“EU SCCs”) as follows:

  • Module Two (Controller to Processor) applies where Customer is Controller and Processor is Processor.
  • Module Three (Processor to Processor) applies where Customer is Processor for another Controller.
  • Clause 7 (docking) applies.
  • In Clause 9, Option 2 general written authorization applies with the notice period in Section 7.
  • In Clause 11, the optional independent dispute-resolution language applies only if the parties so agree upon DPA execution.
  • In Clause 17, Option 1 applies and the governing EU member-state law is completed upon DPA execution.
  • In Clause 18, courts are those of the same EU member state.
  • Annexes I–III of this DPA complete the corresponding SCC annexes.

If the EU SCCs conflict with this DPA, the EU SCCs control for the restricted transfer.

12.2 UK and Switzerland

For UK restricted transfers, the parties incorporate the UK International Data Transfer Addendum to the EU SCCs, completed using this DPA, with the exporter/importer details and table options completed upon DPA execution. For Swiss transfers, references in the EU SCCs are adapted as required by the Swiss FADP, and the competent authority is the Swiss Federal Data Protection and Information Commissioner where applicable.

12.3 Supplementary measures

The parties will cooperate on transfer impact assessments and reasonable supplementary safeguards. Processor will provide information about transfer locations, government-access request practices, encryption, access controls, and relevant Subprocessors.

13. U.S. state privacy terms

Where U.S. state privacy law treats Processor as a processor, service provider, or contractor, Processor will:

  • Process Customer Personal Data only for the limited and specified purposes in the Agreement and this DPA;
  • not sell or share Customer Personal Data or use it for cross-context behavioral advertising;
  • not retain, use, or disclose it outside the direct business relationship or for a commercial purpose other than providing the Service, except as permitted by law;
  • not combine it with personal data received from another person or collected from its own consumer interaction, except as permitted by law;
  • provide the same level of privacy protection required of Customer for the delegated Processing;
  • notify Customer if Processor determines it can no longer meet applicable obligations; and
  • permit Customer to take reasonable and appropriate steps to stop and remediate unauthorized use.

The parties acknowledge Customer discloses Customer Personal Data only for the limited purposes in Annex I and not for monetary or other valuable consideration.

14. Liability and order of precedence

Liability under this DPA is subject to the Agreement’s exclusions and caps unless Applicable Data Protection Law requires otherwise. If this DPA conflicts with the Agreement, this DPA controls for data protection. The EU SCCs or UK transfer terms control over conflicting terms for their restricted transfers.

15. Term

This DPA begins when both parties accept it or the Agreement incorporates it and continues while Processor Processes Customer Personal Data.

16. Signatures

This DPA may be accepted by signature below or incorporated by reference into the Agreement.

CustomerYubano
Name:Name:
Title:Title:
Date:Date:
Signature:Signature:

Annex I — Processing details

A. Parties

Data exporter: Customer details in the Agreement; role: Controller or Processor as applicable.
Data importer: Yubano, ; role: Processor.

B. Description of Processing

ItemDescription
Subject matterProviding a generative-AI media studio, including accounts, projects, chat, generation, storage, support, billing, security, and observability
DurationAgreement term plus deletion and backup periods in Section 10
NatureCollection, recording, organization, storage, retrieval, consultation, transmission to authorized Subprocessors, generation/transformation, support, restriction, deletion
PurposesProvide, secure, support, and maintain the Service according to Customer instructions
Data SubjectsCustomer users and personnel; individuals depicted, named, heard, or otherwise identified in Inputs/Outputs; Customer’s prospects, customers, contractors, talent, and other individuals whose data Customer submits
Personal DataIdentity/contact, account, prompts/chat, uploaded and generated image/audio/video/text, product/project data, likeness/voice, usage/device, support, transaction metadata, observability and security logs
Sensitive dataNot intentionally required, and we do not intentionally process special-category data. It may be present if Customer submits it. Potential biometric or sensitive inferences from faces/voices require prior written approval and additional safeguards.
FrequencyContinuous or as initiated by Customer during the term
Return/deletionSection 10

C. Competent supervisory authority

The competent supervisory authority is identified under EU SCC Clause 13 based on the exporter’s establishment or representative, and is completed upon DPA execution.


Annex II — Technical and organizational measures

Control areaMeasures
GovernanceSecurity/privacy owner; policies; risk assessment; staff training; vendor review; incident plan
AccessUnique accounts; least privilege; role-based access; MFA for privileged access; periodic access review; prompt revocation
EncryptionTLS 1.2+ in transit; AES-256 at rest; managed key controls; secret rotation
Application securitySecure development review; dependency and secret scanning; vulnerability remediation targets; environment separation
InfrastructureHardened cloud configuration; network controls; monitored administrative access; backups; change management
Tenant separationLogical access controls and authorization tests preventing cross-customer access
Logging/monitoringAuthentication, administrative, security, and data-access logging; alerting; tamper resistance; defined retention
Customer ContentMinimized observability capture; redaction where feasible; restricted trace access; short retention; deletion workflow
AvailabilityBackups, restore testing, provider redundancy, and recovery objectives are maintained
Incident responseDetection, triage, containment, investigation, notification, lessons learned, evidence preservation
Vendor riskContract and security review; subprocessor inventory; transfer review; periodic reassessment
Data lifecycleRetention schedule; user deletion/export; backup expiry; legal-hold controls; media-object deletion
Physical securityRelied on hosting and infrastructure provider data-center controls; office/device controls as applicable
AssuranceWe are not currently SOC 2 or ISO 27001 certified and do not currently run a public bug-bounty program.

Annex III — Subprocessors

The current is incorporated into this Annex. Before signature, export or otherwise preserve the version in effect so the parties have an auditable record.