Data Processing Addendum
Version: 1.0
Effective date: 27 July 2026
This Data Processing Addendum (“DPA”) forms part of the agreement (“Agreement”) between Yubano (“Processor”) and the customer identified in the Agreement (“Customer”) for Yubano. It applies when Processor processes Customer Personal Data on Customer’s behalf.
1. Definitions
“Applicable Data Protection Law” means laws applicable to the Processing of Customer Personal Data under the Agreement, including, where applicable, the GDPR, UK GDPR, Swiss FADP, and U.S. state comprehensive privacy laws.
“Customer Personal Data” means Personal Data contained in Inputs, Outputs, account data, or other data that Processor processes on Customer’s behalf under the Agreement.
“GDPR” means Regulation (EU) 2016/679. “UK GDPR” has the meaning under UK data-protection law. “Personal Data,” “Process,” “Processor,” “Controller,” “Data Subject,” “Subprocessor,” and “Supervisory Authority” have the meanings in Applicable Data Protection Law.
“Security Incident” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. It excludes unsuccessful attempts that do not compromise Customer Personal Data.
2. Roles and scope
Customer is Controller and Processor is Processor for Customer Personal Data. Each party will comply with Applicable Data Protection Law. Annex I describes the subject matter, duration, nature, purpose, data categories, and Data Subjects.
Processor may process account, billing, security, abuse, and product-relationship data as an independent Controller where and to the extent described in the Privacy Policy and permitted by law.
3. Customer instructions
Processor will Process Customer Personal Data only on Customer’s documented instructions, including the Agreement, Customer’s configured use of the Service, and written instructions consistent with the Agreement, unless law requires otherwise. If law requires Processing, Processor will inform Customer before Processing unless prohibited.
Processor will promptly inform Customer if it believes an instruction violates Applicable Data Protection Law. Processor is not required to perform an instruction that violates law or the Agreement. Customer is responsible for the lawfulness, accuracy, and quality of Customer Personal Data, its instructions, notices, consents, and legal bases.
4. Confidentiality
Processor will ensure personnel authorized to Process Customer Personal Data are bound by confidentiality obligations and receive appropriate privacy and security training.
5. Security
Processor will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data, taking account of the state of the art, implementation costs, and the nature, scope, context, purposes, and risks of Processing. Current measures are described in Annex II.
Customer is responsible for securely configuring the Service, managing user permissions, protecting credentials, and avoiding submission of data not appropriate for the Service.
6. Security Incidents
Processor will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data and, where feasible, within 48 hours. Notice will include available information about the nature of the incident, affected data and Data Subjects, likely consequences, mitigation, and a contact point. Processor may provide information in phases and will take reasonable steps to contain, investigate, and mitigate the incident.
Notification is not an admission of fault. Customer is responsible for notifications to authorities and Data Subjects unless law assigns that duty to Processor. Processor will reasonably assist Customer, considering the nature of Processing and information available.
7. Subprocessors
Customer gives general written authorization for the subprocessors in the . Processor will impose data-protection obligations materially protective as this DPA requires for the relevant Processing and remains responsible for each Subprocessor’s performance to the extent required by law.
Processor will give at least 30 days’ advance notice of a new Subprocessor, except an urgent replacement needed for security, law, or continuity. Customer may object on reasonable data-protection grounds within 15 days. The parties will seek a commercially reasonable solution. If none is available, Customer may terminate the affected Service and receive a pro-rata refund of prepaid unused fees for that Service. This is Customer’s sole remedy for a Subprocessor objection, except where law requires otherwise.
8. Data Subject requests
Considering the nature of Processing, Processor will provide reasonable technical and organizational assistance for Customer to respond to Data Subject requests. If Processor receives a request relating to Customer Personal Data, it will direct the requester to Customer where legally permitted and will not independently respond except on Customer’s instruction or as required by law.
9. DPIAs and regulatory consultation
Processor will provide information reasonably necessary for Customer’s data-protection impact assessment and prior consultation obligations, considering the nature of Processing and information available. Additional assistance beyond standard documentation may be subject to reasonable fees unless required because of Processor’s breach.
10. Deletion and return
During the term, Customer may export or delete Customer Personal Data using available Service features. At termination or Customer’s written request, Processor will delete or return Customer Personal Data within 30 days, unless law requires retention. Backup copies will be isolated from ordinary use and deleted on the normal cycle within up to 30 days. Processor may retain data necessary to establish or defend legal claims, comply with law, or maintain security records, subject to continued protection.
11. Audits and information
Processor will make available information reasonably necessary to demonstrate compliance, including current security documentation and independent audit reports when available. No more than once annually, Customer may submit a written audit questionnaire. If that is insufficient and Applicable Data Protection Law requires further audit, Customer may conduct an audit through an independent auditor bound by confidentiality, on at least 30 days’ notice, during normal business hours, without accessing other customers’ data or disrupting operations.
Customer bears audit costs unless an audit identifies Processor’s material breach. Processor may charge reasonable fees for disproportionate assistance. Nothing requires disclosure of trade secrets, vulnerability details that would create security risk, or information violating another party’s rights.
12. International transfers
12.1 EEA restricted transfers
If Customer Personal Data protected by the GDPR is transferred to a country without an applicable adequacy decision, the parties incorporate the (“EU SCCs”) as follows:
- Module Two (Controller to Processor) applies where Customer is Controller and Processor is Processor.
- Module Three (Processor to Processor) applies where Customer is Processor for another Controller.
- Clause 7 (docking) applies.
- In Clause 9, Option 2 general written authorization applies with the notice period in Section 7.
- In Clause 11, the optional independent dispute-resolution language applies only if the parties so agree upon DPA execution.
- In Clause 17, Option 1 applies and the governing EU member-state law is completed upon DPA execution.
- In Clause 18, courts are those of the same EU member state.
- Annexes I–III of this DPA complete the corresponding SCC annexes.
If the EU SCCs conflict with this DPA, the EU SCCs control for the restricted transfer.
12.2 UK and Switzerland
For UK restricted transfers, the parties incorporate the UK International Data Transfer Addendum to the EU SCCs, completed using this DPA, with the exporter/importer details and table options completed upon DPA execution. For Swiss transfers, references in the EU SCCs are adapted as required by the Swiss FADP, and the competent authority is the Swiss Federal Data Protection and Information Commissioner where applicable.
12.3 Supplementary measures
The parties will cooperate on transfer impact assessments and reasonable supplementary safeguards. Processor will provide information about transfer locations, government-access request practices, encryption, access controls, and relevant Subprocessors.
13. U.S. state privacy terms
Where U.S. state privacy law treats Processor as a processor, service provider, or contractor, Processor will:
- Process Customer Personal Data only for the limited and specified purposes in the Agreement and this DPA;
- not sell or share Customer Personal Data or use it for cross-context behavioral advertising;
- not retain, use, or disclose it outside the direct business relationship or for a commercial purpose other than providing the Service, except as permitted by law;
- not combine it with personal data received from another person or collected from its own consumer interaction, except as permitted by law;
- provide the same level of privacy protection required of Customer for the delegated Processing;
- notify Customer if Processor determines it can no longer meet applicable obligations; and
- permit Customer to take reasonable and appropriate steps to stop and remediate unauthorized use.
The parties acknowledge Customer discloses Customer Personal Data only for the limited purposes in Annex I and not for monetary or other valuable consideration.
14. Liability and order of precedence
Liability under this DPA is subject to the Agreement’s exclusions and caps unless Applicable Data Protection Law requires otherwise. If this DPA conflicts with the Agreement, this DPA controls for data protection. The EU SCCs or UK transfer terms control over conflicting terms for their restricted transfers.
15. Term
This DPA begins when both parties accept it or the Agreement incorporates it and continues while Processor Processes Customer Personal Data.
16. Signatures
This DPA may be accepted by signature below or incorporated by reference into the Agreement.
Annex I — Processing details
A. Parties
Data exporter: Customer details in the Agreement; role: Controller or Processor as applicable.
Data importer: Yubano, ; role: Processor.
B. Description of Processing
C. Competent supervisory authority
The competent supervisory authority is identified under EU SCC Clause 13 based on the exporter’s establishment or representative, and is completed upon DPA execution.
Annex II — Technical and organizational measures
Annex III — Subprocessors
The current is incorporated into this Annex. Before signature, export or otherwise preserve the version in effect so the parties have an auditable record.