Legal · dpa

Data Processing Addendum

Effective July 11, 2026 · Last updated August 20, 2026

This Data Processing Addendum ("DPA") supplements the Terms of Service between Yapii LLC ("Yapii") and the customer that has accepted those Terms ("Customer"). It applies whenever Yapii processes Personal Data on Customer's behalf as part of providing the Service. Capitalized terms not defined here have the meanings given in the Terms.

1 · Definitions

For purposes of this DPA, the following terms have the meanings below. Where a term is also defined in applicable Data Protection Laws (such as GDPR or CCPA), the meaning under that law applies.

  • "Controller" means the entity that determines the purposes and means of processing Personal Data. For Customer Personal Data, Customer is the Controller.
  • "Processor" means an entity that processes Personal Data on behalf of a Controller. Yapii is the Processor with respect to Customer Personal Data.
  • "Personal Data" means any information relating to an identified or identifiable natural person that Customer uploads to or generates within the Service.
  • "Sub-processor" means any third party engaged by Yapii to process Personal Data on behalf of Customer (e.g. hosting providers, messaging carriers, model providers).
  • "Data Subject" means the identified or identifiable natural person to whom Personal Data relates.
  • "Data Protection Laws" means all applicable laws regulating the processing of Personal Data, including the EU GDPR, UK GDPR, Swiss FADP, CCPA/CPRA, PIPEDA, and other comparable laws.

2 · Roles of the parties

With respect to Customer Personal Data, Customer is the Controller and Yapii is the Processor. Each party will comply with its obligations under applicable Data Protection Laws in those roles.

With respect to Personal Data Yapii collects in its own right (for example, billing contacts, account administrators, and marketing-site visitors), Yapii acts as a Controller and processes that data in accordance with the Privacy Policy.

3 · Duration of processing

Yapii will process Customer Personal Data for the duration of Customer's subscription to the Service, plus any period during which Customer Data is made available for export following termination, plus any period during which Personal Data persists in encrypted backups before being purged in the ordinary backup cycle (currently 90 days). See Return & Deletion.

4 · Nature & purpose of processing

The purpose of processing is to enable Customer to use the Service: to store and organize contacts, generate predictive seller scores, deliver multi-channel messaging, render analytics, support its users, and operate the integrations the Customer enables. Processing operations include collection, storage, structuring, retrieval, modification, transmission, and deletion of Personal Data.

5 · Categories of Data Subjects & Personal Data

The categories of Data Subjects whose Personal Data is processed include Customer's contacts, leads, prospects, past clients, and Customer's own Authorized Users. Categories of Personal Data typically include identifiers (name, email, phone, mailing address), professional information (employer, job title where provided), property attributes (where the Customer is a real estate professional), engagement and consent records, and content of messages exchanged through the Service.

Customer is responsible for not uploading special categories of Personal Data (such as health, biometric, racial, or trade-union data) unless explicitly agreed in writing.

6 · Customer instructions & audit rights

Yapii will process Personal Data only on Customer's documented instructions, including with regard to international transfers, except where required by law. The Service itself, the Documentation, and the configuration choices Customer makes inside the product constitute Customer's documented instructions.

If Yapii is required by law to process Personal Data outside Customer's instructions, Yapii will notify Customer in advance unless legally prohibited from doing so.

Audit rights

On reasonable advance written notice (at least 30 days, except where a regulator requires less), and no more than once in any 12-month period (except in case of a confirmed material incident), Customer may audit Yapii's compliance with this DPA. Audits will be conducted during normal business hours, in a manner that does not disrupt Yapii's operations or compromise other customers' data, and at Customer's expense. Yapii may satisfy this obligation by providing current third-party audit reports (e.g. SOC 2 Type II) and responses to a reasonable security questionnaire.

7 · Security measures

Yapii implements appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing, accidental loss, destruction, or damage. The current measures are described in Annex II - Technical & Organizational Measures. Yapii may update specific measures from time to time, provided the level of protection is not materially decreased.

8 · Sub-processors

Updated 2026-07-12

Customer authorizes Yapii to engage Sub-processors to process Personal Data on its behalf, subject to a written contract that imposes data protection obligations no less protective than those in this DPA. Yapii remains responsible for the acts and omissions of its Sub-processors as if performed by Yapii.

Yapii engages Sub-processors in the following categories; the named provider and processing location for each is maintained on the Sub-processors page:

CategoryPurpose
Cloud hosting & infrastructureProduction hosting, managed storage, and encrypted backups
Payment processingSubscription billing and payment method tokenization
SMS & voice messagingOutbound and inbound SMS, MMS, and voice features
Transactional & broadcast emailSending account, workspace, and campaign email
Property & public-records dataProperty records and parcel data used for enrichment
AI / LLM inferenceLarge-language-model inference powering AI features

The current named Sub-processor for each category, and the specific purpose and location of processing, is maintained on the Sub-processors page so it can be kept current without requiring a DPA amendment. Customer may subscribe to advance notice of changes at trust@yapii.com.

Change-notification process

Yapii will provide at least 14 days' advance notice of any new or replacement Sub-processor by updating the in-product Sub-processor list and emailing the change-notification list. Customer may subscribe to that list at trust@yapii.com. Customer may object in good faith to a new Sub-processor on data-protection grounds within 14 days of the notice; Yapii will work in good faith to resolve the objection, and if it cannot, Customer's exclusive remedy is to terminate the affected portion of the Service and receive a pro-rated refund of prepaid, unused fees.

9 · Data subject request assistance

Taking into account the nature of the processing, Yapii will provide reasonable assistance, by appropriate technical and organizational measures, to enable Customer to respond to requests from Data Subjects to exercise their rights under Data Protection Laws (access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making).

Customer can fulfill most data subject requests directly inside the product (delete, export, anonymize). For requests that require Yapii's intervention, Customer can contact privacy@yapii.com; Yapii will respond as soon as reasonably practicable and in any event within timelines that allow Customer to meet its statutory deadlines.

10 · International transfers

Updated 2026-08-20

Where Customer Personal Data of EEA, UK, or Swiss Data Subjects is transferred to Yapii or its Sub-processors in countries that have not received an adequacy decision, the transfer is governed by the European Commission's Standard Contractual Clauses, Module Two (Controller-to-Processor) or Module Three (Processor-to-Processor) as applicable, with the UK International Data Transfer Addendum or the Swiss FDPIC adaptations where relevant. The Standard Contractual Clauses are incorporated into this DPA by reference and take precedence in case of conflict on transfer matters.

11 · Personal data breach notification

Yapii will notify Customer without undue delay, and in any event within 72 hours of confirmation, of any Personal Data Breach affecting Customer Personal Data. The notification will include, to the extent then known: the nature of the breach, the categories and approximate number of Data Subjects and records affected, likely consequences, and the measures taken or proposed to address it.

Yapii's notification or response is not an acknowledgement of fault or liability. Yapii will provide updates as additional information becomes available, and will reasonably cooperate with Customer's obligations to notify regulators and Data Subjects.

12 · Return & deletion of Personal Data

On termination of the Service or on Customer's written request, Yapii will make Customer Personal Data available to Customer for export for 30 days. After that window, Yapii will delete Customer Personal Data from production systems within 30 days and from encrypted backups within 90 days, except where retention is required by law or for the establishment, exercise, or defense of legal claims.

On request, Yapii will provide written confirmation of deletion. Hashed suppression records may be retained indefinitely so that Yapii does not re-message contacts who have opted out, as described in the AUP.

13 · US State Privacy Laws

13.1 Roles

To the extent Yapii processes Customer Personal Data subject to the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020, Cal. Civ. Code 1798.100 et seq., and its regulations (the "CCPA"), Customer is the "Business" and Yapii is Customer's "Service Provider" (each as defined in Cal. Civ. Code 1798.140). To the extent Yapii processes Customer Personal Data subject to another US state comprehensive consumer privacy law (including those of Virginia, Colorado, Connecticut, Texas, Utah, and Oregon) (collectively with the CCPA, "US State Privacy Laws"), Customer is the "Controller" and Yapii is the "Processor" as defined in the applicable law. The parties acknowledge that Customer discloses Customer Personal Data to Yapii only for the Business Purposes below and that no monetary or other valuable consideration is exchanged for it.

13.2 Business Purposes

Customer discloses Customer Personal Data to Yapii solely for the following business purposes and services (the "Business Purposes"): (i) providing, operating, maintaining, and supporting the Service for Customer, including generating home-value estimates, reports, communications, and analytics on Customer's behalf; (ii) helping to ensure security and integrity, and detecting and protecting against fraud, malicious, deceptive, or illegal activity; (iii) debugging to identify and repair errors; (iv) short-term, transient use; (v) internal research and quality and safety verification and improvement of the Service; and (vi) as otherwise documented in the Agreement or Customer's written instructions. Customer instructs Yapii, as part of the Service, to match and combine Customer Personal Data with publicly available government records and licensed third-party property data sources in order to produce valuations, reports, and related outputs for Customer.

13.3 Restrictions

Yapii shall not: (a) sell or share Customer Personal Data (as "sell" and "share" are defined in the applicable US State Privacy Law), including for cross-context behavioral or targeted advertising; (b) retain, use, or disclose Customer Personal Data for any purpose other than the Business Purposes, including for any commercial purpose other than the Business Purposes, or outside the direct business relationship between Yapii and Customer, except as expressly permitted by the applicable US State Privacy Law and its regulations; or (c) combine Customer Personal Data with personal information that Yapii receives from or on behalf of another person, or collects from its own interaction with a consumer, except as expressly permitted by the applicable US State Privacy Law and its regulations for the Business Purposes, and except as instructed in Section 13.2.

13.4 Compliance; Monitoring; Remediation

Yapii shall comply with all obligations applicable to it under US State Privacy Laws, and shall provide the same level of privacy protection for Customer Personal Data as US State Privacy Laws require of Customer. Yapii shall notify Customer without undue delay, and no later than five business days after making the determination, if it determines it can no longer meet its obligations under this Section. Customer may take reasonable and appropriate steps, upon notice to Yapii, (i) to help ensure that Yapii uses Customer Personal Data in a manner consistent with Customer's obligations under US State Privacy Laws, including through the audit and information rights in Section 6, and (ii) to stop and remediate unauthorized use of Customer Personal Data.

13.5 Personnel; Sub-processors

Yapii ensures that persons authorized to process Customer Personal Data are subject to a duty of confidentiality. Yapii shall engage sub-processors only pursuant to Section 8 and pursuant to written contracts that impose obligations on the sub-processor at least as protective as those in this Section, including the restrictions in Section 13.3.

13.6 Consumer Requests; Assistance; Deletion

Yapii shall assist Customer in responding to verifiable consumer requests and in meeting Customer's obligations regarding consumer rights, assessments, and security, as described in Sections 9, 7, and 6. Upon termination, Yapii shall delete or return Customer Personal Data as described in Section 12, except where retention is required by law. Yapii shall make available to Customer information reasonably necessary to demonstrate compliance with this Section and shall allow and cooperate with reasonable assessments as provided in Section 6, or, at Yapii's election where permitted by law, provide a report of an independent assessment against a recognized framework.

13.7 Deidentified and Aggregated Data

Yapii may create and use deidentified or aggregated data derived from Customer Personal Data to develop and improve its products and services, provided that, with respect to deidentified data, Yapii (i) takes reasonable measures to ensure the data cannot be associated with a consumer or household, (ii) publicly commits to maintain and use the data only in deidentified form and not attempt to reidentify it, except as permitted by law to test deidentification, and (iii) contractually obligates any recipients to comply with the foregoing, in each case in accordance with Cal. Civ. Code 1798.140(m) and analogous provisions of other US State Privacy Laws.

13.8 Certification

Yapii certifies that it understands the restrictions in this Section and will comply with them.

14 · Liability

Each party's liability under this DPA is subject to the limitations of liability set out in the Terms of Service. For the avoidance of doubt, the cap on aggregate liability in the Terms applies to all claims arising under this DPA in the aggregate, and is not duplicative.

Annex I - Processing details

A. List of parties

  • Data exporter: Customer (the entity that has accepted the Terms of Service).
  • Data importer: Yapii LLC, 1883 W Royal Hunte Dr, Ste 200A, Cedar City, UT 84720, United States. Contact: dpo@yapii.com.

B. Description of transfer

  • Categories of Data Subjects: Customer's contacts, leads, prospects, past clients, and Authorized Users.
  • Categories of Personal Data: identifiers, contact details, professional information, property attributes, engagement and consent records, and message content.
  • Sensitive data: not contemplated; Customer is not to upload special categories without prior written agreement.
  • Frequency of transfer: continuous, for the duration of the subscription.
  • Nature of processing: hosting, storage, retrieval, modification, transmission, analytics, AI inference, and deletion.
  • Purpose: provision of the Service to Customer.
  • Retention: as described in Return & Deletion and the Privacy Policy.

C. Competent supervisory authority

For EEA Data Subjects, the supervisory authority of the EU representative's establishment, or otherwise the supervisory authority designated under the SCCs. For UK Data Subjects, the Information Commissioner's Office. For Swiss Data Subjects, the Swiss FDPIC.

Annex II - Technical & organizational measures

The following measures are implemented and maintained by Yapii to protect Personal Data. Specific controls may be updated from time to time provided the overall level of protection is not materially decreased.

Encryption

  • AES-256 encryption at rest for production data stores and backups.
  • TLS 1.3 (or higher) in transit for all customer-facing endpoints; TLS for service-to-service traffic.
  • Customer-managed key options on Enterprise plans where available.

Access control

  • Role-based access control inside the product, with least-privilege defaults.
  • SSO (SAML/OIDC) and 2FA available; required for Yapii personnel access to production systems.
  • Periodic access reviews; immediate revocation on personnel changes.

Network security

  • Production environment isolated from corporate environment; segmented VPCs.
  • WAF and DDoS protection at the edge.
  • Default deny security groups; bastion-only administrative access with short-lived credentials.

Vulnerability management

  • Continuous dependency scanning and base-image patching.
  • Annual external penetration test by a reputable third party; remediation tracked in a CISO-owned register.
  • Bug-bounty program scoped to production endpoints.

Incident response

  • Documented incident response plan with severity levels, on-call rotation, and post-mortem process.
  • Tabletop exercises at least annually.
  • Customer notification within 72 hours of a confirmed Personal Data Breach.

Business continuity

  • Encrypted, geo-separated backups; regularly tested restores.
  • Defined Recovery Time Objective (RTO) and Recovery Point Objective (RPO); communicated to Enterprise customers under SLA.

Personnel security

  • Background checks for personnel with access to production systems, where lawful.
  • Mandatory security and privacy training on hire and annually thereafter.
  • Confidentiality obligations in employment and contractor agreements.

Vendor management

  • Sub-processors are assessed for security, privacy, and operational maturity before onboarding.
  • Contracts impose data protection obligations no less protective than this DPA.
  • Annual review of material Sub-processors.

Change history

Meaningful updates to this document, most recent first. Minor copy edits and typo fixes aren't tracked here.

  1. 10 · International transfers

    Added explicit references to the UK International Data Transfer Addendum and Swiss FDPIC adaptations alongside the EU SCCs.

  2. 8 · Sub-processors

    Replaced the named Sub-processor table with categories of processing; the current named list now lives exclusively on the standalone Sub-processors page so it can be updated independently of this DPA.

This document is provided as a plain-English template to help you understand how Yapii operates. It is not legal advice, and it is not a substitute for review by your own counsel. Please have your attorney review before relying on it for a binding obligation or compliance decision.

Questions? Email legal@yapii.com.