Data Processing Agreement
Our UK GDPR Article 28 terms for processing your customers' data.
Last updated: 18 June 2026
This Data Processing Agreement (the "DPA") sets out the terms on which Precise Impact Ltd, trading as Yappa, processes personal data on behalf of your organisation when you use the Yappa platform. It is designed to satisfy Article 28 of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, and it forms part of, and is governed by, our Terms of Service.
1. Introduction
This DPA is entered into between Precise Impact Ltd (Company No. 15244656), trading as Yappa ("Processor", "Yappa", "we", "our", "us"), and the customer organisation that subscribes to the Service ("Controller", "Customer", "you"). It governs the processing of personal data that you upload, submit, connect or otherwise make available to the Service so that we can generate, verify, publish and distribute content on your behalf.
Precise Impact Ltd is registered with the Information Commissioner's Office (ICO) under registration number ZB829059. Where this DPA conflicts with any other agreement between the parties in relation to the processing of personal data, this DPA prevails.
2. Definitions
Terms used but not defined in this DPA have the meaning given to them in the Terms of Service or in UK GDPR. In this DPA:
- "Personal Data" means any information relating to an identified or identifiable natural person, as defined in UK GDPR, that is processed by us on your behalf under this DPA.
- "Processing" means any operation performed on Personal Data, including collection, recording, organisation, storage, use, disclosure, transfer, embedding, retrieval, restriction, erasure or destruction.
- "Data Subject" means the individual to whom Personal Data relates.
- "Controller" means the entity that determines the purposes and means of Processing Personal Data.
- "Processor" means the entity that processes Personal Data on behalf of the Controller.
- "Sub-processor" means any third party engaged by us to process Personal Data on your behalf.
- "Customer Data" means the content, source documents, contacts, audience records and other data you submit to, connect to, or generate through the Service, including any Personal Data it contains.
- "Business Brain" means the per-tenant knowledge store in which your source material is held and embedded so that the Service can generate and verify content for you.
- "UK GDPR" means the UK General Data Protection Regulation as defined in the Data Protection Act 2018.
3. Scope and Roles
When your organisation uses Yappa, you act as the Controller of any Personal Data contained in the Customer Data, for example, the contacts, subscribers and audience members you load for distribution, the names and details of individuals that appear within your source documents and Business Brain, and the details of your own users and team members. We act as the Processor of that data, Processing it solely on your documented instructions in order to provide the Service to you.
The Service interacts with the websites and channels you connect to it (for example your own WordPress site and your distribution channels). Where you direct us to publish or distribute content to those destinations, you remain the Controller of the Personal Data involved and are responsible for having a lawful basis to use it for that purpose.
Separately, we act as an independent Controller for the data we collect for our own purposes, such as account registration details, billing information, marketing data and website usage data. That Processing is governed by our Privacy Policy, not this DPA.
4. Customer Instructions
This DPA, the Terms of Service, your configuration of the Service, and your use of its features together constitute your documented instructions for the Processing of Customer Data. We will process Personal Data only on those instructions, including with regard to international transfers, unless we are required to process it by law, in which case we will inform you of that legal requirement before Processing, unless the law prohibits us from doing so on important grounds of public interest.
If we believe that an instruction infringes UK GDPR or other applicable data protection law, we will inform you without undue delay. You may give additional reasonable written instructions consistent with this DPA; we may charge for material changes that are not within the scope of the Service.
5. Details of Processing
Subject matter and duration
The subject matter of the Processing is the provision of the Yappa platform: turning your ideas and existing knowledge into verified, published and distributed website content. Processing continues for the duration of your subscription term, plus the deletion window described in Section 12. Full particulars are set out in the Annex to this DPA.
Nature and purpose of Processing
We process Personal Data contained in Customer Data in order to:
- Host and store the Customer Data and your Business Brain;
- Generate embeddings and retrieve relevant context to produce and improve content for you;
- Run the content pipeline, drafting, the Trust Engine / Board of Inquisitors verification and critic passes, and elevation;
- Publish, update and unpublish content to the WordPress site you connect via the Yappa receiver plugin;
- Distribute content and campaigns through the channels you connect, such as email, social and AutomagicalCRM (GoHighLevel);
- Operate the conversational interface (including the Telegram front door) that you use to instruct the Service;
- Display dashboards, reports and usage information to your users; and
- Provide customer support and maintain the security of the Service.
Categories of Data Subjects
- Your organisation's members, users and team members;
- Your contacts, subscribers and audience whose details you load for distribution;
- Your website visitors and the recipients of content you distribute;
- Any individuals whose Personal Data appears within the source documents and other material you place in your Business Brain.
Types of Personal Data
- Names and job titles;
- Email addresses and phone numbers;
- Contact, subscriber and audience records and segmentation data;
- User profile and authentication data;
- Any Personal Data contained within source documents, content drafts, messages and other material you submit to the Service.
You must not submit special category data (UK GDPR Article 9) or criminal offence data to the Service unless you have agreed appropriate additional measures with us in writing. The Service is not designed to process such data.
6. Processor Obligations
As your Processor, we shall:
- Process Personal Data only on your documented instructions, as set out in Section 4, unless required to do otherwise by law;
- Ensure that persons authorised to process Personal Data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality;
- Implement appropriate technical and organisational security measures (see Section 7);
- Respect the conditions in Section 8 for engaging another Sub-processor;
- Taking into account the nature of the Processing, assist you by appropriate technical and organisational measures, insofar as possible, in responding to Data Subject requests (see Section 9);
- Assist you in ensuring compliance with your obligations under UK GDPR Articles 32 to 36 (security, breach notification and communication, and data protection impact assessments and prior consultation), taking into account the nature of Processing and the information available to us;
- At your choice, delete or return all Personal Data on termination of the Service, as set out in Section 12;
- Make available to you all information necessary to demonstrate compliance with this DPA; and
- Allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, as set out in Section 13.
7. Security Measures
Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Tenant isolation at the database layer: every tenant-owned record carries a tenant identifier and is protected by Postgres row-level security, so retrieval and generation can never return another tenant's data. This is enforced in the database, not only in application code.
- Encryption in transit: all connections to the Service are encrypted using TLS.
- Credential and token protection: external OAuth tokens and API keys are encrypted at rest and referenced rather than inlined; user passwords are stored only as salted hashes; and the tokens used by the WordPress receiver plugin are hashed on the customer's site.
- Access controls: role-based access control with least-privilege defaults, so each organisation's data is segregated from other customers'.
- Infrastructure: managed, EU-region PostgreSQL with the pgvector extension for embeddings, with regular automated backups.
- Monitoring: application monitoring and logging to detect and investigate anomalous activity.
- Staff access: least-privilege access for staff, limited to what is needed to operate and support the Service, under confidentiality obligations.
- Vulnerability management: regular dependency updates, automated secret scanning, security review and patching as part of our build and release process.
8. Sub-processors
You provide a general authorisation for us to engage Sub-processors to assist in providing the Service. We impose on each Sub-processor, by contract, data protection obligations that are no less protective than those set out in this DPA, and we remain fully liable to you for the performance of each Sub-processor's obligations.
Current Sub-processors
| Sub-processor | Purpose | Location / safeguard |
|---|---|---|
| Railway | Application hosting, PostgreSQL + pgvector database, and object (file) storage | EU region; UK IDTA / SCCs where applicable |
| Amazon Web Services (S3) / Railway object store | Source documents, images, exports and generated assets | EU/UK region; SCCs where applicable |
| Stripe | Subscription payments and billing | UK/EU entities, global group (SCCs) |
| Resend | Transactional email delivery | United States (SCCs) |
| Cloudflare | DNS, CDN, secure tunnel and security proxy | Global network (SCCs) |
| Anthropic and other model / inference providers | Commercial critic, verification and elevation passes within the content pipeline | United States / contracted regions (SCCs); no training on your data |
| GoHighLevel / AutomagicalCRM (LeadConnector) | CRM and distribution / marketing automation | United States (SCCs) |
| Telegram | Conversational front door, where you choose to use the Telegram interface | Operated outside the UK/EEA (SCCs / safeguards as applicable) |
| Your own WordPress site | Destination for published content via the Yappa receiver plugin (under your control) | As hosted by you |
Most pipeline stages are processed by local models; commercial model providers are used only for critic, verification and elevation passes. Where you connect your own WordPress site or distribution channels, those destinations operate under your control and your own agreements with them.
We will notify you of any intended changes concerning the addition or replacement of Sub-processors, giving you a reasonable opportunity to object before the new Sub-processor begins Processing. If you have a legitimate, data-protection-related objection, we will work with you in good faith to find an alternative; if none can be found within a reasonable period, you may terminate the affected part of the Service.
9. Data Subject Rights
Taking into account the nature of the Processing, we will assist you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to requests by Data Subjects exercising their rights under UK GDPR, including the rights of access, rectification, erasure, restriction, portability, and objection.
If we receive a request directly from a Data Subject relating to Customer Data, we will, unless prohibited by law, promptly notify you and will not respond to the request ourselves without your instructions, other than to confirm that the request has been passed to you as Controller.
10. Data Breach Notification
In the event of a Personal Data breach affecting Customer Data, we will notify you without undue delay, and in any event within 48 hours, after becoming aware of it. Our notification will, to the extent known and as it becomes available, include:
- A description of the nature of the breach;
- The categories and approximate number of Data Subjects affected;
- The categories and approximate number of Personal Data records affected;
- The likely consequences of the breach;
- The measures taken or proposed to address the breach and mitigate its effects; and
- The name and contact details of our point of contact.
We will cooperate with you and take reasonable steps as directed by you to assist in your investigation, mitigation and remediation of the breach. Notification of, or response to, a breach will not be construed as our acknowledgement of any fault or liability.
11. International Transfers
Our primary hosting and database infrastructure is located in the EU region. Some Sub-processors (see Section 8) process Personal Data outside the UK and EEA. We do not transfer Personal Data outside the UK/EEA unless an appropriate safeguard or exception is in place, such as the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses (SCCs), or UK adequacy regulations covering the destination country. Where you instruct us to publish or distribute content to destinations you have connected, you are responsible for the safeguards applicable to those onward transfers.
12. Data Retention and Deletion
We retain Customer Data for the duration of your subscription. On termination of the Service:
- You may export a copy of your Customer Data in a portable format for 30 days after termination;
- At your choice, we will delete or return your Customer Data within 30 days after that export window closes;
- Backup copies will be purged within 90 days in line with our backup rotation; and
- We may retain Personal Data to the extent, and for as long as, required by law, and may retain anonymised or aggregated data, from which no Data Subject can be identified, for analytical and product purposes.
Content that you have already published to your own WordPress site or distributed through connected channels remains under your control on those destinations and is not deleted by the steps above.
13. Audits
We will make available to you all information necessary to demonstrate compliance with the obligations in this DPA and allow for, and contribute to, audits and inspections conducted by you or an auditor you mandate. Audits shall be conducted on reasonable prior notice, during normal business hours, no more than once per year unless required by a supervisory authority or following a Personal Data breach, and shall not unreasonably interfere with our operations or compromise the confidentiality or security of other customers' data.
We may satisfy audit requests by providing relevant certifications, audit reports, security documentation, or written responses to a reasonable security questionnaire.
14. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service. We shall be liable for damage caused by Processing only where we have not complied with obligations of UK GDPR specifically directed to processors, or where we have acted outside or contrary to your lawful instructions.
15. Changes to This Agreement
We may update this DPA to reflect changes in our Processing activities, legal or regulatory requirements, or Sub-processors. We will notify you of material changes and make the updated DPA available before it takes effect. Your continued use of the Service after the effective date constitutes acceptance of the updated DPA.
16. Governing Law
This DPA is governed by the laws of England & Wales, and the courts of England & Wales have exclusive jurisdiction over any dispute arising from or in connection with it, except where applicable data protection law provides otherwise.
17. Contact
For questions about this Data Processing Agreement or to exercise your rights under it, contact:
Precise Impact Ltd
Trading as Yappa
128 City Road, London, EC1V 2NX
United Kingdom
Company Registration: 15244656 (England & Wales)
ICO Registration:
ZB829059
Data protection enquiries:
privacy@getyappa.com
Legal enquiries: legal@getyappa.com
Annex: Details of Processing
This Annex forms part of the DPA and describes the Processing carried out by Yappa as Processor.
| Item | Details |
|---|---|
| Controller | The customer organisation that subscribes to the Service. |
| Processor | Precise Impact Ltd, trading as Yappa (Company No. 15244656). |
| Subject matter | AI-assisted content generation, verification, publishing and distribution through the Yappa platform. |
| Duration | The term of the subscription, plus the deletion window in Section 12. |
| Nature and purpose | Hosting and embedding Customer Data; generating, verifying and elevating content; publishing to the customer's WordPress site; distributing via email, social and GoHighLevel; and providing support. |
| Types of Personal Data | Names, job titles, email addresses, phone numbers, contact and audience records, user profile and authentication data, and any Personal Data within source documents and content. |
| Categories of Data Subjects | The customer's users and team members; the customer's contacts, subscribers and audience; website visitors and content recipients; and individuals named within source material. |
| Special category data | None, unless separately agreed in writing. The Service is not designed to process special category or criminal offence data. |
| Sub-processors | As listed in Section 8, as updated from time to time. |
Related policies
- Terms of Service
The agreement that governs your use of the Yappa platform.
- Privacy Policy
What personal data we collect, why, and your rights under UK GDPR.
- Cookie Policy
The cookies we use and how consent controls analytics.
- Security
How we protect your data, tenant isolation, encryption and more.
- Application Terms
Terms specific to the Yappa apps and connected channels.