Last updated: July 4, 2026
Data Processing Agreement
This is the data-processing agreement (DPA) that applies when a customer (the “Controller”) uses yeil services to process personal data on behalf of their end users, within the meaning of the EU General Data Protection Regulation (GDPR) Article 28 or analogous laws. By accepting yeil's Terms of Service while using the service to process personal data of your customers / employees / users, you accept this DPA.
1. Definitions
“Controller” means you, the yeil customer. “Processor” means yeil. “Personal data”, “processing”, “data subject”, and “sub-processor” have the meanings given them in GDPR Article 4. “Services” means the yeil products you use (mail, dns, analytics, team, etc.).
2. Scope and purpose
yeil processes personal data only on documented instructions from the Controller, as set out in this DPA and the underlying Terms of Service. The duration of processing is the duration of your subscription. The categories of data subjects are the users, customers, employees, and contacts whose data you choose to put into yeil. The categories of personal data are those you choose to put into yeil; typically email metadata and message content, DNS records, account profile data, and anything else covered by the Privacy Policy. Where the Controller uses analytics, the data subjects also include visitors to the Controller's own websites, and section 9 describes that processing in place of this paragraph.
3. Processor obligations
yeil will:
- process personal data only on the Controller's documented instructions, including the instruction inherent in the Controller's use of the service;
- ensure that personnel with access to personal data are bound by confidentiality obligations;
- implement appropriate technical and organizational measures to protect personal data, including those listed in Schedule A below;
- assist the Controller in fulfilling its obligations to respond to data-subject requests (access, rectification, erasure, portability);
- notify the Controller without undue delay (within 72 hours of becoming aware) of any personal-data breach affecting the Controller's data;
- upon termination, delete or return all personal data to the Controller, except where retention is required by law.
4. Sub-processors
The Controller authorizes yeil to engage sub-processors listed in /subprocessors. yeil will give at least 30 days' notice of any new sub-processor; the Controller may object on reasonable grounds related to data protection, in which case the parties will work in good faith to resolve, including by the Controller terminating the affected service with a pro-rated refund.
5. International transfers
Personal data is processed in jurisdictions listed in /subprocessors. Where personal data is transferred outside the EEA, UK, or Switzerland, the transfer is governed by the European Commission's Standard Contractual Clauses (Module Two, controller-to-processor), incorporated into this DPA by reference, with yeil as the data importer.
6. Security measures
yeil's current technical and organizational measures include: zero-access encryption of message bodies, previews, and attachments at rest (per-message data keys sealed to mailbox public keys; master keys wrapped under password-derived KEKs; decryption on end-user devices only, with the server holding only ciphertext; message headers such as sender, recipient, and subject are retained in plaintext for routing, threading, and search); TLS-only transport for the web and SMTP surfaces; argon2id for password verification; passkeys and TOTP two-factor for accounts, with step-up passkey verification required for staff and admin actions; access logging on privileged actions; backup retention via hypervisor snapshots; documented incident-response procedures.
7. Audit and information
yeil will make available to the Controller, on request, the information necessary to demonstrate compliance with this DPA. Once per year per Controller (or more often if required by applicable law), yeil will respond to a reasonable audit request, which may be satisfied by a written security questionnaire response, a current SOC 2 report (when available), or a remote interview, depending on the size and risk profile of the Controller.
8. Liability and term
This DPA forms part of the Terms of Service. Conflicts between this DPA and the Terms are resolved in favor of this DPA insofar as the conflict concerns personal-data processing. The DPA remains in force as long as yeil processes personal data on the Controller's behalf, plus any retention period required by law.
9. Analytics annex
This section applies where the Controller uses yeil analytics. Analytics differs from every other yeil product in one way that matters here: the personal data concerns third parties who never signed up for yeil, so this annex sets out precisely what is processed and what is kept.
Data subjects. Visitors to the websites on which the Controller installs the yeil analytics script, and people on whose behalf the Controller sends events through the analytics API.
Processed in transit and not stored.A visitor's IP address and User-Agent are used, at the moment the request arrives, to derive a visitor identifier and a coarse geographic location. The identifier is a keyed hash taken over a salt that exists only in memory, is never written to disk or to a log, and changes every UTC day, so it cannot be reversed to an address and does not link a visitor across days. The address and the User-Agent are not stored, unless the Controller turns on the optional setting to retain visitor IP addresses, in which case they are stored encrypted under the Controller's own keys.
Stored.The contents of each recorded event, which the Controller determines: the page path, the referring address, campaign parameters, the names and properties of custom events, and any user identifier the Controller chooses to send. Those contents are encrypted in the visitor's browser before they are transmitted, under keys held by the Controller and not available to yeil. yeil stores the resulting ciphertext, the derived visitor identifier, and the time of the event.
Retention. Individual event records are deleted after the retention period configured for the site, and in no case later than 90 days. The encrypted aggregate counts derived from them are kept for as long as the site exists. Counters recording how many requests each site accepted or rejected per day are kept for as long as the site exists and contain no visitor data. Deleting a site, or closing the account that owns it, deletes all of the above.
Sub-processors.Analytics adds none. Geographic lookup runs against database files held on yeil's own servers, so no visitor data is sent to a third party for that or for any other analytics purpose.
The Controller's responsibilities.The Controller decides what is collected and must have a lawful basis for collecting it, must describe the collection in its own privacy notice, and is responsible for whatever it chooses to send as a user identifier or as a custom event property. yeil cannot read those values and therefore cannot review them on the Controller's behalf.
10. How to sign
By accepting yeil's Terms of Service through the signup or admin flow, the Controller accepts this DPA. If your internal procurement requires a counter-signed copy, write to legal@yeil.org and we will provide a signed version with the same content.