yaxbe

Data Processing Agreement

Last updated: 27 August 2026

This agreement forms part of the Terms of Service. It applies whenever a customer puts personal data into Yaxbe. Where the customer has signed a separate negotiated DPA, that one controls.

1. Roles

The customer is the controller. They decide what personal data enters Yaxbe, whose data it is, and why.

Yaxbe is the processor.We process that data only to provide the service, and only on the customer’s documented instructions.

The Terms of Service, this agreement, and the customer’s use of the product are the customer’s documented instructions. We will tell the customer if we believe an instruction breaches applicable data protection law.

2. What we process

Categories of data subject

  • the customer’s own personnel who use Yaxbe
  • the customer’s clients and their personnel, including document recipients
  • any individual named in material the customer sends us to build a scope

Categories of personal data

  • identity and contact details: name, work email, job title, organization
  • authentication identifiers
  • document activity: when a statement of work was opened, by whom, what was selected, what was commented on
  • acceptance evidence: name, title, timestamp, IP address, browser identifier
  • anything present in material the customer sends us to build a scope, which the customer controls

Special category data. Yaxbe is not designed for it and the customer should not send it to us. If it appears inside material the customer sends us to build a scope, the customer remains responsible for having a lawful basis.

Duration.For as long as the customer’s account is open, plus the retention periods in the Privacy Policy.

3. Confidentiality

Everyone we allow to process customer personal data is bound by confidentiality obligations and is granted access only where their role requires it.

4. Security

We maintain technical and organizational measures appropriate to the risk, including:

  • encryption in transit and at rest
  • tenant isolation enforced at the database level, not only in application code, so a mistake in application code cannot expose one customer’s data to another
  • the application connecting with credentials that hold no direct table privileges of their own, so access requires an explicit, verified role assumption on every transaction
  • access to production limited by role, with authentication required
  • logging of administrative access to production systems

We will not materially weaken these measures during the term.

5. Sub-processors

The customer authorizes the sub-processors listed in the Privacy Policy.

We will give at least 30 days’ notice before adding or replacing a sub-processor. If the customer reasonably objects on data protection grounds within that period, we will work in good faith to find an alternative. If we cannot, the customer may terminate the affected part of the service without penalty for the remainder of the paid period.

Each sub-processor is bound by obligations no less protective than those in this agreement, and we remain liable for their performance.

6. Assisting the customer

We will assist the customer, taking into account the nature of the processing and the information available to us, with:

  • responding to requests from data subjects to access, correct, delete, restrict, object to, or port their data
  • data protection impact assessments and prior consultations
  • demonstrating compliance with their own obligations

Where a data subject contacts us directly about data we hold as a processor, we will not respond substantively. We will direct them to the customer and tell the customer promptly.

7. Personal data breach

We will notify the customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting their data. The notification will describe what is known: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed.

We will not delay notification because our investigation is incomplete. We will tell the customer what we know and update them as we learn more.

8. Deletion and return

On termination, the customer may export their data. We will keep it available for export for at least 30 days.

After that, we delete it, except where retention is required by law and except for acceptance records, which are retained for seven years because they evidence an agreement between the customer and their own client. Both parties also received a copy at the time of acceptance.

On request, we will confirm deletion in writing.

9. Audit

We will make available the information reasonably necessary to demonstrate compliance with this agreement, and will contribute to audits conducted by the customer or an auditor they appoint.

Audits will be at the customer’s expense, on at least 30 days’ notice, no more than once in any 12 months unless a breach or a regulator requires otherwise, during business hours, and conducted so as not to disrupt the service or affect other customers.

10. International transfers

Our infrastructure is in the United States.

Where the customer transfers personal data from the European Economic Area, the United Kingdom, or Switzerland, the Standard Contractual Clauses apply and are incorporated into this agreement, with Yaxbe as data importer and the customer as data exporter, together with the UK International Data Transfer Addendum where the transfer originates in the United Kingdom.

11. Liability

Liability under this agreement is subject to the limits in the Terms of Service.

12. Order of precedence

If this agreement conflicts with the Terms of Service on the processing of personal data, this agreement controls.

Annex A: processing summary

Subject matterProvision of the Yaxbe statement of work platform
DurationThe term of the customer’s subscription, plus the retention periods in the Privacy Policy
Nature and purposeHosting, structuring, rendering, transmitting, and recording agreement to commercial statements of work; AI-assisted extraction of structure from customer-supplied material
Data typesAs listed in section 2
Data subjectsAs listed in section 2

Annex B: sub-processors

As listed in the Privacy Policy, which is maintained as the current list.

Annex C: contact

Data protection enquiries: privacy@yaxbe.com
Legal notices: legal@yaxbe.com
Yaxbe LLC, 7533 S Center View Ct Ste N, West Jordan, Utah 84084