Data Processing Agreement
Effective: July 21, 2026 · Last updated: July 30, 2026
This Data Processing Agreement, including its schedules (the “DPA”), is between YEETUM LLC, doing business as Y2 (“Y2”), and the customer that has agreed to Y2’s Terms of Service or another agreement for the Services (“Customer”). It forms part of that agreement (the“Agreement”) and applies when Y2 processes Customer Personal Data on Customer’s behalf.
By using the Services to process Customer Personal Data, Customer enters into this DPA for itself and, where applicable, its authorized affiliates. A separately signed copy is available by contacting [email protected].
1. Definitions
“Applicable Data Protection Law” means laws applicable to the processing of Customer Personal Data, including the EU General Data Protection Regulation 2016/679 (“EU GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and applicable United States state privacy laws. Terms such as controller, processor, business, service provider, contractor, personal data, processing, sale, and supervisory authority have the meanings given by applicable law.
“Customer Personal Data” means personal data contained in Customer Content that Y2 processes on Customer’s behalf to provide the Services. It excludes information Y2 processes as an independent controller, such as its own account administration, billing, security, and direct business relationship records. “Subprocessor” means a third party appointed by Y2 to process Customer Personal Data on Customer’s behalf.
2. Scope, roles, and instructions
Customer is the controller or business and Y2 is the processor, service provider, or contractor for Customer Personal Data. If Customer is itself a processor, Y2 is its subprocessor. Each party will comply with Applicable Data Protection Law. Customer is responsible for the lawfulness of Customer Personal Data, Customer’s instructions, and all required notices, rights, and consents.
Y2 will process Customer Personal Data only on Customer’s documented instructions, including those in the Agreement, product configuration, authorized API calls, support requests, and this DPA, unless law requires otherwise. If legally permitted, Y2 will notify Customer before such required processing. Y2 will promptly inform Customer if an instruction, in Y2’s reasonable opinion, infringes Applicable Data Protection Law.
3. United States service-provider terms
For Customer Personal Data subject to United States state privacy law, Y2 will process it only for the specific business purposes in Schedule 1: providing, securing, maintaining, supporting, and improving the Services under the Agreement. Y2 will not:
- sell or share Customer Personal Data;
- retain, use, or disclose it outside those purposes or the direct business relationship;
- combine it with personal information from another person or from Y2’s own interactions, except as legally permitted to provide the business purposes; or
- use it for targeted advertising or to build profiles unrelated to Customer.
Y2 will provide the same level of privacy protection required of Customer, notify Customer if it can no longer comply, and allow Customer to take reasonable and appropriate steps to verify, stop, and remediate unauthorized use. Y2 certifies that it understands and will comply with these restrictions.
4. Confidentiality and personnel
Y2 will ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations, receive appropriate privacy and security guidance, and access the data only as needed for their duties.
5. Security
Taking into account the state of the art, implementation costs, and the nature, scope, context, purposes, and risks of processing, Y2 will maintain appropriate technical and organizational measures designed to protect Customer Personal Data. Current measures are in Schedule 3. Y2 may update them without materially reducing the overall level of protection.
6. Subprocessors
Customer gives Y2 general written authorization to use the Subprocessors listed in Schedule 2. Y2 will require each Subprocessor to protect Customer Personal Data through written terms that are no less protective in substance than this DPA for the processing it performs. Y2 remains responsible for its Subprocessors’ performance to the extent required by law.
Y2 will provide at least 30 days’ notice by email to the account owner or another reasonable electronic method before a new Subprocessor begins materially processing Customer Personal Data. Customer may object during that period on reasonable data-protection grounds. The parties will work in good faith on a commercially reasonable alternative. If none is available, either party may terminate only the affected Service, and Y2 will refund prepaid unused fees for that Service.
7. Assistance and data-subject requests
Taking into account the nature of processing and information available to Y2, Y2 will provide reasonable assistance for Customer to respond to verified data-subject or consumer requests, conduct data-protection impact assessments and prior consultations, and satisfy security, breach-notification, and recordkeeping obligations. If Y2 receives a request concerning Customer Personal Data, it will direct the requester to Customer unless law requires Y2 to respond. Customer is responsible for reasonable costs of unusually burdensome assistance.
8. Personal Data Breaches
Y2 will notify Customer without undue delay after confirming a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data (a “Personal Data Breach”). As information becomes available, the notice will describe the nature and likely consequences, affected data and people, mitigation taken or proposed, and a contact for follow-up. Notification is not an admission of fault. Unsuccessful attacks that do not compromise Customer Personal Data are not Personal Data Breaches under this DPA.
9. Return and deletion
During the term, Customer may use available product and API features to access or export Customer Personal Data. Following termination or a valid deletion request, Y2 will delete or return Customer Personal Data within a reasonable period unless law requires retention. Residual copies in protected backups will remain isolated from ordinary use and be deleted under the applicable backup lifecycle. Customer instructs Y2 to delete data that no longer needs to be retained to provide the Services.
10. Information and audits
On reasonable request, Y2 will provide information necessary to demonstrate compliance with this DPA. Customer will first use current security documentation, provider reports, and written responses. If those are insufficient, Customer may conduct one audit per year, and additional audits following a Personal Data Breach or where required by a supervisory authority. Audits require reasonable advance notice, must occur during business hours, avoid disruption and exposure of other customers’ data, and be subject to confidentiality. Customer bears its audit costs unless the audit identifies a material breach by Y2.
11. International transfers
11.1 European Economic Area
If Customer Personal Data protected by the EU GDPR is transferred to Y2 in a country without an adequacy decision, the parties incorporate the European Commission standard contractual clauses in Decision (EU) 2021/914 (the “EU SCCs”). Module Two applies when Customer is a controller and Module Three applies when Customer is a processor. For the EU SCCs: Clause 7 applies; Clause 9 uses Option 2 with the 30-day period in Section 6; the optional language in Clause 11 does not apply; in Clause 17, Option 1 applies and Irish law governs; and under Clause 18(b), the courts of Dublin, Ireland have jurisdiction. Schedules 1–3 complete the applicable SCC annexes.
11.2 United Kingdom
For restricted transfers under UK law, the EU SCCs are modified by the UK International Data Transfer Addendum issued by the Information Commissioner under section 119A of the Data Protection Act 2018 (the “UK Addendum”). The parties are the exporter and importer identified in Schedule 1, the selected EU SCC modules and tables are completed with this DPA, and either party may end the UK Addendum as permitted by its mandatory clauses.
11.3 Switzerland
For transfers governed by Swiss law, the EU SCCs apply with references to the EU GDPR understood to include the Swiss Federal Act on Data Protection, “Member State” interpreted to include Switzerland, and the competent authority and courts determined under Swiss law.
If a lawful transfer mechanism ceases to be available, the parties will cooperate in good faith to implement an alternative. Nothing in this DPA reduces protections required by the EU SCCs or UK Addendum.
12. Liability, order of precedence, and changes
The Agreement’s liability limits apply to this DPA to the extent permitted by Applicable Data Protection Law. If documents conflict about processing Customer Personal Data, the order is: the EU SCCs or UK Addendum, this DPA, the Agreement, then other documentation. Y2 may update this DPA to reflect legal requirements or processing changes, but will not materially reduce Customer’s protections during a subscription term without notice.
Schedule 1 — Details of processing
A. Parties
| Data exporter / Customer | The Customer identified in its Y2 account or order. Contact details are those in the account or Agreement. Activities are described below. Signature and date are the Customer’s acceptance of the Agreement and this DPA. |
|---|---|
| Data importer / Y2 | YEETUM LLC, 600 Bryan Ave Ste 220, Fort Worth, TX 76104, United States; [email protected]. Activities are providing the Services. Signature and date are Y2’s publication of this DPA and the effective date above. |
For the EU SCCs, the competent supervisory authority is determined under Clause 13. The parties’ roles are controller-to-processor or processor-to-processor as stated in Section 2.
B. Processing description
| Subject matter and purpose | Hosting and securing Customer workspaces; processing prompts, research, files, graphs, reports, API requests, and integrations; generating AI-assisted outputs; and delivering configured email, SMS, audio, or webhook results. |
|---|---|
| Duration | For the Agreement term and the limited deletion, backup, and legal-retention period described in Section 9. |
| Nature and frequency | Collection, storage, organization, retrieval, analysis, generation, transmission, disclosure to authorized recipients, support, security monitoring, and deletion; continuous or as initiated and scheduled by Customer. |
| Data subjects | Customer personnel, workspace members, end users, contacts, delivery recipients, and people described in Customer-submitted research or public intelligence data. |
| Personal data | Names, contact details, online identifiers, account and workspace data, IP and usage data, prompts, messages, files, topics, profile criteria, reports, source material, integration data, and any personal data Customer elects to submit. |
| Sensitive data | Not required or intended. Customer must not submit special-category data, criminal-offense data, protected health information, payment-card data, government identifiers, credentials, or similarly sensitive data unless Y2 expressly agrees in writing and appropriate safeguards are configured. |
| Return and deletion | As described in Section 9 and controlled by Customer’s product configuration. |
Schedule 2 — Subprocessors
The locations below describe the provider’s principal processing location or service scope; remote support and documented downstream processing may occur elsewhere under appropriate safeguards.
| Provider | Purpose and data | Location / scope |
|---|---|---|
| Convex | Backend hosting, database, authentication, workflows, and file storage. | United States |
| Netlify | Frontend hosting, CDN, network delivery, and request logs. | Global / United States |
| OpenRouter | AI model routing for prompts, limited context, outputs, and request metadata. Downstream model providers depend on the selected model and documented routing; current workflows may use Z.ai, Google, MiniMax, or DeepSeek. | United States / provider location |
| Tavily | Web research queries, search results, and request metadata. | United States |
| Cartesia | Text-to-speech generation from report text and audio configuration. | United States |
| Resend | Email delivery, recipient details, message content, and delivery events. | Global / United States |
| Surge | SMS delivery, phone numbers, message content, consent, and delivery events. | United States |
| Stripe | Subscription billing, payment metadata, fraud prevention, tax, and invoicing. | Global / United States |
| PostHog | Consented product analytics, masked session interaction data, surveys, in-app Support conversations, online identifiers, account and workspace attributes, usage events, and identified account contact details. | United States |
| FirstPromoter | Referral attribution, promoter records, and related account identifiers. | European Union / United States |
GitHub may process sign-in data when a user selects GitHub OAuth. Google Analytics, X Ads, and RB2B may process website identifiers and activity only after the relevant privacy choice. These providers and Customer-configured destinations may act as independent controllers for their own purposes; they are included here for transparency and are Subprocessors only to the extent they process Customer Personal Data on Y2’s behalf.
Schedule 3 — Technical and organizational measures
- Access control: authenticated access, role and workspace authorization, least-privilege administration, scoped API keys, and one-way hashing of API credentials.
- Encryption: TLS for data in transit and provider-managed encryption at rest for primary hosted data and files.
- Tenant protection: authorization checks and workspace boundaries designed to prevent access across customers.
- Application security: validated inputs, rate limits, idempotency controls, secret management, dependency review, and separated public and internal operations.
- AI data minimization: limited prompt context, provider data-collection restrictions and zero-data-retention routing where supported, and customer control over model and workflow selection.
- Availability and recovery: managed infrastructure, durable workflows, monitoring, error handling, and provider backup and recovery capabilities.
- Logging and response: security and operational telemetry, restricted log access, incident investigation, containment, remediation, and notification procedures.
- Data lifecycle: account deletion workflows, storage deletion, external contact cleanup where supported, and legal-retention exceptions.
- Governance: confidentiality obligations, provider diligence, access review, and periodic reassessment of risks and safeguards.