Legal

Data Processing Addendum

Last Updated: January 2, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between you ("Customer") and Yeda AI ("Processor") and governs the processing of Personal Data in connection with our Services. This DPA is designed to meet the requirements of GDPR, CCPA, and other applicable data protection laws.

1. Definitions

"Controller" means the entity that determines the purposes and means of processing Personal Data. "Processor" means the entity that processes Personal Data on behalf of the Controller. "Personal Data" means any information relating to an identified or identifiable natural person. "Processing" means any operation performed on Personal Data, including collection, storage, use, and deletion. "Data Subject" means the individual to whom Personal Data relates. "Sub-processor" means any third party engaged by Yeda AI to process Personal Data.

2. Scope and Roles

This Data Processing Addendum ("DPA") applies when Yeda AI processes Personal Data on your behalf in connection with our Services. You are the Controller of Personal Data collected through your chatbot widgets. Yeda AI acts as a Processor, processing Personal Data only according to your documented instructions and this DPA.

3. Data Processing Details

Categories of Data Subjects: Your end users, website visitors, and chatbot users. Types of Personal Data: Names, email addresses, chat messages, IP addresses, device identifiers. Processing Activities: Storing chat conversations, processing AI responses, analytics aggregation. Duration: Data is processed for the duration of your subscription plus the retention period specified in our Privacy Policy.

4. Processor Obligations

Yeda AI shall: (a) process Personal Data only on your documented instructions; (b) ensure personnel are bound by confidentiality obligations; (c) implement appropriate technical and organizational security measures; (d) assist you in responding to Data Subject requests; (e) delete or return Personal Data upon termination; (f) make available information necessary to demonstrate compliance; (g) notify you of any data breaches without undue delay.

5. Security Measures

We implement industry-standard security measures including: encryption in transit (TLS 1.3) and at rest (AES-256), access controls and authentication, regular security assessments, employee security training, incident response procedures, and secure data centers (AWS with SOC 2 Type II certification). Details are available in our Security Documentation.

6. Sub-processors

We use the following sub-processors: Amazon Web Services (AWS) for cloud infrastructure and data storage; Stripe for payment processing; Groq and Google for AI model inference. We maintain contracts with sub-processors imposing data protection obligations. You may object to new sub-processors within 30 days of notification.

7. Data Subject Rights

We will assist you in fulfilling Data Subject requests including: access to Personal Data, rectification of inaccurate data, erasure ("right to be forgotten"), restriction of processing, data portability, and objection to processing. Our GDPR compliance endpoints (/api/auth/export-data and /api/auth/delete-account) facilitate these rights.

8. International Transfers

Personal Data may be transferred to and processed in the United States. For transfers from the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission. We implement supplementary measures as necessary to ensure adequate protection.

9. Data Breach Notification

In the event of a Personal Data breach, we will notify you without undue delay (within 72 hours where feasible) and provide: a description of the breach, categories and approximate number of affected Data Subjects, likely consequences, and measures taken or proposed to address the breach.

10. Audit Rights

Upon reasonable notice, you may audit our compliance with this DPA. We will provide access to relevant documentation, facilities, and personnel. Audits shall be conducted during normal business hours and shall not unreasonably interfere with our operations. You may also rely on third-party audit reports (SOC 2, ISO 27001).

11. Term and Termination

This DPA remains in effect for the duration of your use of our Services. Upon termination, we will delete or return all Personal Data within 30 days, unless retention is required by law. You may request a certificate of deletion upon completion.

12. Contact Information

For questions about this DPA or to exercise your rights, contact our Data Protection Officer at: Email: privacy@yeda-ai.com Address: Yeda AI, Data Protection Officer, [Address] For urgent data protection matters, please include "URGENT: DPA" in your subject line.