Data Processing Agreement (DPA)
Effective date: 2026-07-20
This Data Processing Agreement ("DPA") forms part of the Terms of Service between YAStuning OÜ ("Processor", "we") and the customer ("Controller", "you") and applies whenever we process personal data on your behalf. It is concluded under Article 28 GDPR. Where it conflicts with the Terms, this DPA prevails for matters of personal data processing.
1. Roles
For personal data contained in the store/catalog data you connect, you are the controller (or a processor acting for your client merchant) and we are the processor. For data about your account and users, we are an independent controller as described in the Privacy Policy; that is outside this DPA.
2. Subject matter and details of processing (Art. 28(3))
- Subject matter: processing of catalog/store data to provide the audit, enrichment, fix, feed, content and - where you enable it - AI-visibility monitoring functionality of the Service.
- Duration: for the term of the Terms of Service and until data is deleted or returned per Section 9.
- Nature and purpose: reading, storing (snapshotting), analysing, enriching (including via AI), and, where enabled and supported by the platform, writing back catalog data on your instructions. Where you enable AI-visibility monitoring, this also includes disclosing catalog text to third-party answer engines outside the EEA in order to measure whether those assistants mention your brand and products. The exact fields sent per feature are listed in the Privacy Policy, Section 3, and per provider in Sub-processors; that listing is the documented instruction for this disclosure.
- Types of personal data: typically only personal data incidentally contained in product content - e.g. names of individuals appearing in free-text product descriptions or reviews, and author, brand-representative or supplier contact names included in product metadata. The Service is not designed to process your end-customers' or shoppers' data.
- Categories of data subjects: individuals mentioned in your product catalog content (e.g. authors, brand representatives, suppliers) - not your end-customers or shoppers, unless you choose to feed such data through the Service (which we recommend against; see the note below).
NOTEThe Service is not intended to process special categories of data (Art. 9) or end-consumer order/customer data. You should not connect such data.
3. Controller's instructions
3.1 We process personal data only on your documented instructions, including the configuration choices you make in the Service (e.g. read-only vs write access, auto-apply settings), unless required by EU or Member State law (in which case we inform you unless legally prohibited).
3.2 We will inform you if, in our opinion, an instruction infringes the GDPR.
4. Confidentiality
We ensure that persons authorized to process personal data are bound by confidentiality and process data only as needed to provide the Service.
5. Security measures (Art. 32)
Taking into account the state of the art, we implement appropriate technical and organisational measures, including: encryption of connected-store credentials at rest and TLS in transit; hashing of passwords (Argon2); multi-tenant logical isolation; short-lived, rotating access tokens with instant revocation; redaction of secrets from logs; access controls, abuse protection, and audit logging; and regular review of measures.
6. Sub-processors (Art. 28(2),(4))
6.1 You provide general authorisation for us to engage sub-processors. The current list is published at Sub-processors and includes our cloud hosting provider (Hetzner Online GmbH, Germany), Stripe, Google (Gemini API / AI Studio), Cloudflare (Turnstile), our email provider, Google Analytics (website analytics, subject to your consent), and - only where you enable the optional AI-visibility monitoring add-on - OpenAI and Perplexity AI. The published list is definitive.
6.2 We impose data-protection obligations on each sub-processor equivalent to those in this DPA.
6.3 We will give you at least 30 days' notice of any intended addition or replacement of a sub-processor. You may object on reasonable data-protection grounds; if we cannot resolve your objection, you may terminate the affected Service. One exception is outside our control: Perplexity AI reserves the right to change the model providers it uses to answer a query without a right of objection. If you are not willing to accept that, do not enable the AI-visibility monitoring add-on.
6.4 We remain fully responsible to you for each sub-processor's performance of its data-protection obligations. If a sub-processor fails to meet them, we stay liable to you for that failure.
7. Data subject rights (Art. 28(3)(e))
Taking into account the nature of the processing, we will assist you with appropriate technical and organisational measures, insofar as possible, to respond to data subject requests under Chapter III GDPR. If a data subject contacts us directly regarding your data, we will refer them to you.
Within our own systems we can act on an erasure request (Art. 17) in full. Where you have enabled AI-visibility monitoring, requests and answers already sent to the answer engines are held by those providers on their own retention schedules and cannot be deleted record by record on request - see Section 9.4 and Sub-processors. Take this into account before you instruct us to send data that identifies an individual.
8. Assistance and breach notification (Art. 28(3)(f), 33)
8.1 We assist you in ensuring compliance with Art. 32-36, taking into account the information available to us.
8.2 We notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you reasonably need to meet your own notification obligations.
9. Return and deletion (Art. 28(3)(g))
9.1 At your choice, on termination we either delete or return the personal data we process on your behalf, and delete existing copies, unless EU or Member State law requires us to keep it.
9.2 If you ask us to delete or return it, we do so within 30 days of your request. If you make no choice, we delete it automatically within 30 days of termination. Catalog snapshots are deleted as soon as you disconnect a store or close your account.
9.3 Copies held in routine backups are deleted on the normal backup rotation and stay protected under this DPA until then. Where law requires us to retain data, we keep only what is required, for only as long as required, and continue to protect it.
9.4 Exception - data already sent to the answer engines. If you enabled AI-visibility monitoring, the requests and answers exchanged with OpenAI, Perplexity AI and Google are stored by those providers under their own terms, which do not offer selective, per-record deletion for API data. Sections 9.1-9.3 therefore cover our systems and our backups, not those copies. Disabling monitoring stops any further data being sent, immediately and for good; what has already been sent expires on the schedule published in Sub-processors.
10. Audits (Art. 28(3)(h))
We make available the information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits, subject to reasonable notice, confidentiality, and frequency limits, and not unreasonably disrupting our operations.
11. International transfers
11.1 Most processing stays within the EEA (our hosting is in Germany). Where a sub-processor processes personal data outside the EEA, the transfer relies on appropriate safeguards under Chapter V GDPR - the European Commission's Standard Contractual Clauses (Decision 2021/914), and, where the recipient is certified, the EU-U.S. Data Privacy Framework. See Sub-processors for each provider's location and safeguard.
11.2 The Standard Contractual Clauses are incorporated into this DPA by reference and are entered into by both parties when you accept the Terms, with no separate signature needed. Module Two (controller to processor) applies where you act as a controller; Module Three (processor to processor) applies where you act as a processor for your own client. The optional docking clause in Clause 7 does not apply. Where the Clauses and this DPA conflict, the Clauses prevail for the transfer they govern.
12. Liability and term
This DPA is effective for as long as we process personal data on your behalf. Liability is subject to the limitations in the Terms of Service. This DPA is governed by the law of Estonia.
13. Acceptance
Acceptance of the Terms of Service constitutes acceptance of this DPA. A countersigned copy can be provided on request to [email protected].