Data Processing Agreement

Last updated: February 19, 2026

1. Introduction

This Data Processing Agreement ("DPA") is entered into between the customer entity that has agreed to the Yander Terms of Service ("Customer," "Controller," or "you") and Yander Labs, Inc. ("Yander," "Processor," "we," "us," or "our"). This DPA supplements and forms part of the Yander Terms of Service ("Agreement") and the Yander Privacy Policy.

This DPA sets out the terms that apply when Personal Data is processed by Yander on behalf of the Customer in the course of providing the Service. The purpose of this DPA is to ensure that such processing is conducted in accordance with applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK General Data Protection Regulation ("UK GDPR"), and other applicable data protection legislation.

By using the Service, the Customer enters into this DPA on behalf of itself and, to the extent required under applicable data protection laws, on behalf of its authorized users and employees.

2. Definitions

The following terms shall have the meanings set out below. Any capitalized terms not defined in this DPA shall have the meanings given to them in the Agreement.

  • "Personal Data" means any information relating to an identified or identifiable natural person ("Data Subject") that is processed by Yander on behalf of the Customer in connection with the Service.
  • "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.
  • "Controller" means the entity that determines the purposes and means of the Processing of Personal Data. For the purposes of this DPA, the Customer is the Controller.
  • "Processor" means the entity that processes Personal Data on behalf of the Controller. For the purposes of this DPA, Yander is the Processor.
  • "Data Subject" means an identified or identifiable natural person whose Personal Data is processed under this DPA, including the Customer's employees and authorized users of the Service.
  • "Sub-processor" means any third party engaged by Yander to process Personal Data on behalf of the Customer in connection with the Service.
  • "Standard Contractual Clauses" means the standard contractual clauses for the transfer of personal data to processors established in third countries, as approved by the European Commission pursuant to Implementing Decision (EU) 2021/914.

3. Scope and Roles

The Customer acts as the Controller and Yander acts as the Processor with respect to the Personal Data processed in connection with the Service. Yander shall process Personal Data only on the documented instructions of the Customer, unless required to do so by applicable law, in which case Yander shall inform the Customer of that legal requirement before Processing (unless prohibited by law from doing so).

The categories of Personal Data processed under this DPA include workplace communication content and metadata from connected integrations. This includes email content (subject lines, message bodies, sender and recipient addresses, timestamps), messaging content (message text, channel information, timestamps from Slack and similar tools), calendar event details (titles, descriptions, attendees, times, locations), meeting transcripts (speaker-attributed text from recorded meetings), and document content (page text and comments from tools such as Notion). This data is processed by AI models to extract facts, collaboration patterns, and engagement insights. Raw communication content is not displayed to end users; only AI-generated summaries and scores are surfaced in the Service. The Data Subjects include the Customer's employees, contractors, and other authorized users of workplace tools connected to the Service.

The duration of Processing shall be for the term of the Agreement between the Customer and Yander, plus the period from expiry of the Agreement until deletion of all Personal Data by Yander in accordance with this DPA.

4. Customer Obligations

The Customer, as Controller, shall be responsible for the following:

  • Ensuring that it has a lawful basis for the Processing of Personal Data under applicable data protection laws, including but not limited to obtaining any necessary consents or establishing a legitimate interest.
  • Providing adequate notice to its employees, contractors, and other Data Subjects regarding the Processing of their Personal Data through the Service, including the nature of data collected, the purposes of Processing, and their rights under applicable law.
  • Ensuring that the instructions given to Yander regarding the Processing of Personal Data comply with all applicable data protection laws and regulations.
  • Complying with all applicable data protection laws in relation to the Processing of Personal Data and the use of the Service, including any notification or registration requirements.
  • Ensuring that it has the right to transfer, or provide access to, the Personal Data to Yander for Processing in accordance with the terms of this DPA and the Agreement.

5. Yander's Obligations

Yander, as Processor, shall comply with the following obligations:

5.1 Processing Instructions

Yander shall process Personal Data only in accordance with the Customer's documented instructions as set out in this DPA and the Agreement, unless required to do so by applicable law. Yander shall immediately inform the Customer if, in its opinion, an instruction infringes applicable data protection laws.

5.2 Confidentiality

Yander shall ensure that all personnel authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access to Personal Data shall be limited to those personnel who require such access to perform the Service.

5.3 Security Measures

Yander shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk of Processing, as described further in Section 7 of this DPA.

5.4 Data Subject Requests

Yander shall promptly assist the Customer in responding to requests from Data Subjects exercising their rights under applicable data protection laws, as further described in Section 9 of this DPA.

5.5 Breach Notification

Yander shall notify the Customer without undue delay upon becoming aware of a Personal Data breach and shall assist the Customer in meeting its breach notification obligations, as further described in Section 8 of this DPA.

5.6 Data Protection Impact Assessments

Yander shall provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with supervisory authorities, to the extent required by applicable data protection laws and taking into account the nature of the Processing and the information available to Yander.

5.7 Deletion and Return of Data

Upon termination of the Agreement, Yander shall, at the Customer's election, delete or return all Personal Data to the Customer and delete existing copies, unless applicable law requires further storage, as further described in Section 11 of this DPA.

5.8 Audit and Compliance

Yander shall make available to the Customer all information necessary to demonstrate compliance with the obligations set out in this DPA and shall allow for and contribute to audits and inspections, as further described in Section 12 of this DPA.

6. Sub-processors

The Customer provides general authorization for Yander to engage Sub-processors to process Personal Data on the Customer's behalf. Yander shall maintain an up-to-date list of Sub-processors, as set out in Schedule 1 below.

Yander shall notify the Customer of any intended changes concerning the addition or replacement of Sub-processors at least thirty (30) days prior to such change, thereby giving the Customer the opportunity to object to such changes. If the Customer objects to a new Sub-processor on reasonable grounds related to data protection, Yander shall use commercially reasonable efforts to make available an alternative arrangement that avoids the use of the objected-to Sub-processor. If no alternative is reasonably available, either party may terminate the portion of the Service that cannot be provided without the use of the objected-to Sub-processor.

Yander shall impose on each Sub-processor data protection obligations no less protective than those set out in this DPA by way of a written contract. Yander shall remain fully liable to the Customer for the performance of each Sub-processor's obligations.

Schedule 1: Sub-processors

Sub-processorPurposeLocation
Railway (AWS)Application hosting, database infrastructure, and RedisUnited States
ClerkAuthentication and user managementUnited States
NangoOAuth and integration API proxyUnited States / European Union
OpenRouterLLM inference (AI processing)United States
StripePayment processingUnited States
SentryError monitoring (no personally identifiable information transmitted)United States
PostHogProduct analytics (anonymous event data)United States / European Union

7. Data Security

Yander shall implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful Processing, accidental loss, destruction, or damage. These measures include, but are not limited to:

  • Encryption at rest: All Personal Data stored in databases and file systems is encrypted using AES-256 encryption via our infrastructure provider (Railway on AWS).
  • Encryption in transit: All data transmitted between clients and servers is protected using TLS 1.3 via our edge proxy. Internal service-to-service communication occurs within the same isolated network.
  • Tenant-level data isolation: Every database query is filtered by tenant identifier, ensuring strict logical separation of Customer data. No Customer can access another Customer's data.
  • Role-based access control: Access to Customer data within the Service is governed by role-based permissions (owner, admin, staff), ensuring that users can only access data appropriate to their role.
  • No personally identifiable information in logs: Application logs are designed to minimize personally identifiable information. Logs primarily contain anonymized identifiers, tenant identifiers, and operational metadata.
  • Regular security assessments: Yander conducts regular security reviews, vulnerability assessments, and updates to its security measures to address evolving threats.
  • Access controls for personnel: Yander limits access to Personal Data to authorized personnel on a need-to-know basis, and enforces multi-factor authentication for all administrative access.

8. Data Breach Notification

Yander shall notify the Customer without undue delay, and where feasible within seventy-two (72) hours, after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed under this DPA (a "Personal Data Breach").

Such notification shall include, to the extent reasonably available:

  • A description of the nature of the Personal Data Breach, including, where possible, the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned.
  • The name and contact details of Yander's point of contact from whom more information can be obtained.
  • A description of the likely consequences of the Personal Data Breach.
  • A description of the measures taken or proposed to be taken by Yander to address the Personal Data Breach, including measures to mitigate its possible adverse effects.

Yander shall cooperate with the Customer and take such commercially reasonable steps as the Customer may direct to assist in the investigation, mitigation, and remediation of each Personal Data Breach.

9. Data Subject Rights

Yander shall, taking into account the nature of the Processing, assist the Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests from Data Subjects exercising their rights under applicable data protection laws. These rights include:

  • Right of access: The right to obtain confirmation as to whether Personal Data is being processed and, where that is the case, access to the Personal Data.
  • Right to rectification: The right to obtain the rectification of inaccurate Personal Data.
  • Right to erasure: The right to obtain the erasure of Personal Data where certain conditions are met.
  • Right to data portability: The right to receive Personal Data in a structured, commonly used, and machine-readable format.
  • Right to object: The right to object to Processing of Personal Data on grounds relating to the Data Subject's particular situation.

If Yander receives a request directly from a Data Subject, Yander shall promptly notify the Customer and shall not respond to the request without the Customer's prior written authorization, unless required to do so by applicable law.

10. International Transfers

The Customer acknowledges that Yander processes and stores Personal Data primarily in the United States. Where Personal Data originating from the European Economic Area ("EEA"), the United Kingdom, or Switzerland is transferred to the United States or any other country that has not been deemed to provide an adequate level of data protection by the relevant authority, the parties agree to rely on the Standard Contractual Clauses (EU Commission Implementing Decision 2021/914) as the lawful mechanism for such transfer.

For transfers subject to the UK GDPR, the parties shall rely on the International Data Transfer Addendum to the EU Standard Contractual Clauses, as issued by the UK Information Commissioner's Office. For transfers subject to the Swiss Federal Act on Data Protection, the Standard Contractual Clauses shall be interpreted to cover such transfers.

Yander shall ensure that any onward transfer of Personal Data to Sub-processors in third countries is subject to appropriate safeguards as required by applicable data protection laws.

11. Data Retention and Deletion

Yander shall retain Personal Data for the duration of the Agreement and as necessary to provide the Service. Upon termination or expiration of the Agreement, Yander shall, at the Customer's written request, delete all Personal Data processed on behalf of the Customer within thirty (30) days of receiving such request, unless applicable law requires continued retention.

If no deletion request is received within ninety (90) days of termination, Yander shall proceed to delete the Customer's Personal Data in accordance with its standard data retention policies.

Yander may retain anonymized or aggregated data that cannot be used to identify any individual. Such data is not considered Personal Data and is not subject to the deletion obligations of this DPA.

12. Audit Rights

Yander shall make available to the Customer, on request, all information reasonably necessary to demonstrate compliance with the obligations set out in this DPA, and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.

Audits shall be subject to the following conditions:

  • The Customer shall provide at least thirty (30) days' written notice prior to conducting an audit.
  • Audits shall be limited to no more than one (1) per calendar year, unless required by a supervisory authority or following a Personal Data Breach.
  • The Customer shall conduct audits during normal business hours and in a manner that minimizes disruption to Yander's operations.
  • The Customer and its auditors shall be bound by confidentiality obligations with respect to any information obtained during the audit.

Yander may satisfy audit requests by providing relevant certifications, audit reports (such as SOC 2 Type II reports), or other documentation that reasonably demonstrates compliance with the obligations of this DPA. The Customer shall consider such documentation in good faith before requiring an on-site audit.

13. Liability

Each party's liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitations and exclusions of liability set out in the Agreement (Terms of Service). For the avoidance of doubt, Yander's total aggregate liability under this DPA shall be subject to the same caps and limitations as set forth in the Agreement.

Nothing in this DPA shall limit either party's liability for breaches of applicable data protection laws to the extent that such limitation is not permitted by law.

14. Term and Termination

This DPA shall become effective on the date the Customer agrees to the Agreement and shall remain in effect for the duration of the Agreement. This DPA shall automatically terminate upon the termination or expiration of the Agreement, subject to the provisions of this DPA that by their nature are intended to survive termination.

The following provisions shall survive termination of this DPA: Section 5.2 (Confidentiality), Section 5.7 (Deletion and Return of Data), Section 8 (Data Breach Notification) to the extent a breach is discovered after termination, Section 11 (Data Retention and Deletion), Section 12 (Audit Rights) for a period of twelve (12) months following termination, and Section 13 (Liability).

15. Contact

If you have questions about this Data Processing Agreement or wish to exercise any rights under it, please contact us:

Yander Labs, Inc.

2261 Market Street STE 46212

San Francisco, CA 94114

Email: jordan@yanderlabs.com