Data Processing Agreement (DPA)
Effective date: 2026-07-20
This Data Processing Agreement ("DPA") forms part of the Terms of Service between YAStuning OÜ ("Processor", "we") and the customer ("Controller", "you") and applies whenever we process personal data on your behalf. It is concluded under Article 28 GDPR. Where it conflicts with the Terms, this DPA prevails for matters of personal data processing.
1. Roles
For personal data contained in the store/catalog data you connect, you are the controller (or a processor acting for your client merchant) and we are the processor. For data about your account and users, we are an independent controller as described in the Privacy Policy; that is outside this DPA.
2. Subject matter and details of processing (Art. 28(3))
- Subject matter: processing of catalog/store data to provide the audit, enrichment, fix and feed functionality of the Service.
- Duration: for the term of the Terms of Service and until data is deleted or returned per Section 9.
- Nature and purpose: reading, storing (snapshotting), analysing, enriching (including via AI), and, where enabled and supported by the platform, writing back catalog data on your instructions.
- Types of personal data: typically only personal data incidentally contained in product content - e.g. names of individuals appearing in free-text product descriptions or reviews, and author, brand-representative or supplier contact names included in product metadata. The Service is not designed to process your end-customers' or shoppers' data.
- Categories of data subjects: individuals mentioned in your product catalog content (e.g. authors, brand representatives, suppliers) - not your end-customers or shoppers, unless you choose to feed such data through the Service (which we recommend against; see the note below).
NOTEThe Service is not intended to process special categories of data (Art. 9) or end-consumer order/customer data. You should not connect such data.
3. Controller's instructions
3.1 We process personal data only on your documented instructions, including the configuration choices you make in the Service (e.g. read-only vs write access, auto-apply settings), unless required by EU or Member State law (in which case we inform you unless legally prohibited).
3.2 We will inform you if, in our opinion, an instruction infringes the GDPR.
4. Confidentiality
We ensure that persons authorized to process personal data are bound by confidentiality and process data only as needed to provide the Service.
5. Security measures (Art. 32)
Taking into account the state of the art, we implement appropriate technical and organisational measures, including: encryption of connected-store credentials at rest and TLS in transit; hashing of passwords (Argon2); multi-tenant logical isolation; short-lived, rotating access tokens with instant revocation; redaction of secrets from logs; access controls, abuse protection, and audit logging; and regular review of measures.
6. Sub-processors (Art. 28(2),(4))
6.1 You provide general authorisation for us to engage sub-processors. The current list is published at Sub-processors and includes our cloud hosting provider (Hetzner Online GmbH, Germany), Stripe, Google (Gemini API / AI Studio), Cloudflare (Turnstile), our email provider, Google Analytics (website analytics, subject to your consent), and - only where you enable the optional AI-visibility monitoring add-on - OpenAI and Perplexity AI. The published list is definitive.
6.2 We impose data-protection obligations on each sub-processor equivalent to those in this DPA.
6.3 We will give you at least 30 days' notice of any intended addition or replacement of a sub-processor. You may object on reasonable data-protection grounds; if we cannot resolve your objection, you may terminate the affected Service.
6.4 We remain fully responsible to you for each sub-processor's performance of its data-protection obligations. If a sub-processor fails to meet them, we stay liable to you for that failure.
7. Data subject rights (Art. 28(3)(e))
Taking into account the nature of the processing, we will assist you with appropriate technical and organisational measures, insofar as possible, to respond to data subject requests under Chapter III GDPR. If a data subject contacts us directly regarding your data, we will refer them to you.
8. Assistance and breach notification (Art. 28(3)(f), 33)
8.1 We assist you in ensuring compliance with Art. 32-36, taking into account the information available to us.
8.2 We notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you reasonably need to meet your own notification obligations.
9. Return and deletion (Art. 28(3)(g))
9.1 At your choice, on termination we either delete or return the personal data we process on your behalf, and delete existing copies, unless EU or Member State law requires us to keep it.
9.2 If you ask us to delete or return it, we do so within 30 days of your request. If you make no choice, we delete it automatically within 30 days of termination. Catalog snapshots are deleted as soon as you disconnect a store or close your account.
9.3 Copies held in routine backups are deleted on the normal backup rotation and stay protected under this DPA until then. Where law requires us to retain data, we keep only what is required, for only as long as required, and continue to protect it.
10. Audits (Art. 28(3)(h))
We make available the information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits, subject to reasonable notice, confidentiality, and frequency limits, and not unreasonably disrupting our operations.
11. International transfers
11.1 Most processing stays within the EEA (our hosting is in Germany). Where a sub-processor processes personal data outside the EEA, the transfer relies on appropriate safeguards under Chapter V GDPR - the European Commission's Standard Contractual Clauses (Decision 2021/914), and, where the recipient is certified, the EU-U.S. Data Privacy Framework. See Sub-processors for each provider's location and safeguard.
11.2 The Standard Contractual Clauses are incorporated into this DPA by reference and are entered into by both parties when you accept the Terms, with no separate signature needed. Module Two (controller to processor) applies where you act as a controller; Module Three (processor to processor) applies where you act as a processor for your own client. The optional docking clause in Clause 7 does not apply. Where the Clauses and this DPA conflict, the Clauses prevail for the transfer they govern.
12. Liability and term
This DPA is effective for as long as we process personal data on your behalf. Liability is subject to the limitations in the Terms of Service. This DPA is governed by the law of Estonia.
13. Acceptance
Acceptance of the Terms of Service constitutes acceptance of this DPA. A countersigned copy can be provided on request to [email protected].