Yee

Data Processing Agreement

The terms for data Yee processes on behalf of site owners.

Last updated October 5, 2026

Agreement and scope

This Data Processing Agreement (“DPA”) forms part of the Yee Terms of Service or another agreement between a customer (“Customer”, “you”) and Yee Site (“Yee”, “we”, “us”) governing use of Yee and its services (the “Services”).

This DPA applies where Yee processes Personal Data on Customer’s behalf in connection with the Services. Under applicable data protection law, including Regulation (EU) 2016/679 (“GDPR”), Customer acts as the Controller and Yee acts as the Processor, except where this DPA or the Privacy Policy says otherwise.

1. Definitions

Applicable Data Protection Law means the GDPR and any other data protection or privacy law that applies to the processing covered by this DPA.

Controller, Processor, Data Subject, Personal Data, Processing, Personal Data Breach and Supervisory Authority have the meanings given to them by the GDPR.

Customer Data means Personal Data processed by Yee on Customer’s behalf through the Services. Subprocessor means a third party engaged by Yee to process Customer Data on Customer’s behalf.

2. Roles of the parties

Customer is the Controller of Customer Data collected or otherwise processed through Customer’s Yee sites. Customer determines the purposes and essential means of that processing, including which features and fields are enabled and how submitted information is used.

Yee is the Processor of Customer Data and will process it only on Customer’s documented instructions, including the instructions expressed through Customer’s use and configuration of the Services, unless applicable law requires otherwise. If law requires processing outside those instructions, Yee will inform Customer before processing unless the law prohibits that notice.

Yee separately acts as an independent Controller for Personal Data needed to operate Yee itself, including account, authentication, subscription, billing, security and platform-administration data. That processing is governed by the Yee Privacy Policy.

3. Customer instructions

Customer instructs Yee to process Customer Data as necessary to:

  • host and display Customer’s sites and content;
  • receive, store and present contact, newsletter and booking submissions;
  • provide dashboards, site analytics and media storage where enabled;
  • maintain security, prevent abuse and provide requested support; and
  • otherwise provide the Services according to Customer’s settings and use.

Customer’s use and configuration of the Services are documented processing instructions. Yee will inform Customer if, in Yee’s reasonable opinion, an instruction infringes Applicable Data Protection Law, unless prohibited by law.

4. Customer responsibilities

Customer is responsible for ensuring that its collection and use of Customer Data complies with Applicable Data Protection Law. In particular, Customer must:

  • have an appropriate legal basis for processing;
  • give visitors a clear privacy notice and obtain valid consent where required;
  • use newsletter and marketing information lawfully—submitting a contact form does not by itself constitute consent to marketing;
  • respond to Data Subject requests and configure forms and fields appropriately;
  • collect only data necessary for Customer’s stated purposes; and
  • comply with rules for cookies, analytics, tracking and third-party embeds enabled by Customer.

Customer must not use Yee to intentionally process special-category data under GDPR Article 9, criminal-conviction data under Article 10, or other highly sensitive information unless Yee expressly supports that processing and appropriate safeguards are agreed.

5. Processing details

The subject matter, nature, purpose, duration, categories of Data Subjects and types of Personal Data are set out in Annex I. Processing continues for the duration of Customer’s use of the relevant Services and for any additional period needed to securely delete or return Customer Data under this DPA and applicable law.

6. Confidentiality

Yee will ensure that people authorised to process Customer Data are subject to appropriate confidentiality obligations. Access will be limited to personnel and contractors who need it to provide, secure, maintain or support the Services.

7. Security

Yee will maintain appropriate technical and organisational measures designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures take into account the state of the art, implementation costs, the nature and scope of processing, and risks to Data Subjects.

Current categories of measures are described in Annex II. Yee may update those measures without materially reducing the overall security of the Services.

8. Personal Data Breaches

Yee will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data. To the extent reasonably available, the notice will describe the nature of the breach, affected data and Data Subjects, likely consequences, and measures taken or proposed to address or mitigate it. Yee will reasonably assist Customer with Customer’s related legal obligations.

9. Subprocessors

Customer gives Yee general written authorisation to appoint Subprocessors needed to provide the Services. Yee will require each Subprocessor that processes Customer Data to accept data-protection obligations appropriate to its services.

Current Subprocessors are listed in Annex III. Yee may update that list and will provide reasonable notice before adding or replacing a Subprocessor where Applicable Data Protection Law requires it. Customer may raise a reasonable objection on legitimate data-protection grounds through yee.site/contact. If no reasonable alternative is available, Customer may stop using the affected Service.

Providers such as Polar and Google may process some information as independent controllers under their own terms, depending on the activity, and are not necessarily Subprocessors for Customer Data.

10. International transfers

Customer acknowledges that Yee and its Subprocessors may process Personal Data in countries other than where Customer or a Data Subject is located. Yee does not promise that all Customer Data remains exclusively in the EU or EEA.

Where Customer Data protected by the GDPR is transferred outside the EEA to a country without an adequacy decision, Yee will ensure that a lawful transfer mechanism is used where required, such as the European Commission’s Standard Contractual Clauses and appropriate supplementary safeguards.

11. Data Subject requests

Taking into account the nature of the processing, Yee will reasonably assist Customer in responding to requests for access, correction, deletion, restriction, portability or objection. If Yee receives a request directly about Customer Data, Yee may direct the person to Customer unless legally required to respond itself. Customer remains responsible for deciding how to respond.

12. Compliance assistance

Taking into account the nature of processing and the information available to Yee, Yee will provide reasonable assistance with Customer’s obligations concerning processing security, breach notifications, data-protection impact assessments and consultations with Supervisory Authorities where required by Applicable Data Protection Law.

13. Deletion and return

Customer may access and delete Customer Data using available Yee account tools. On termination or expiry of the Services, Yee will delete or return Customer Data according to Customer’s instructions and Yee’s applicable retention procedures, unless law requires continued retention.

Residual copies may remain temporarily in backups or disaster-recovery systems and will be removed through normal retention cycles. Yee may retain information needed to comply with law, resolve disputes, prevent fraud or enforce agreements, but will not use retained Customer Data for unrelated purposes.

14. Audits and information

Yee will make available information reasonably necessary to demonstrate compliance with GDPR Article 28. If that information is insufficient, Customer may request an audit subject to reasonable conditions protecting the security, confidentiality and operation of Yee and other customers.

Unless required after a significant security incident or by a Supervisory Authority, audits must be requested with reasonable notice, occur no more than once each year, take place during normal business hours, avoid unreasonable disruption and remain subject to confidentiality. Customer bears reasonable audit costs unless the audit identifies a material breach of this DPA by Yee.

15. Liability, conflicts and term

Each party’s liability under this DPA is subject to the limitations and exclusions in the Yee Terms of Service, to the extent permitted by law. Nothing limits rights or liabilities that Applicable Data Protection Law does not allow to be limited.

If this DPA conflicts with the Terms regarding Customer Data processing, this DPA prevails. Applicable Standard Contractual Clauses prevail over conflicting terms in this DPA.

This DPA becomes effective when Customer accepts the Terms or otherwise enters into an agreement under which Yee processes Personal Data on Customer’s behalf, and remains effective for as long as Yee processes that Customer Data.

16. Contact

Questions, requests or notices about this DPA may be sent to Yee Site through yee.site/contact.

Annex I — Details of processing

Subject matter and duration

Provision of the Yee website-building and creator platform and the features selected by Customer, for the duration of Customer’s use of those Services and applicable deletion or retention periods.

Nature and purpose

  • hosting Customer sites and content;
  • collecting and presenting contact, newsletter and booking submissions;
  • sending notification emails enabled by Customer to Customer and to the people who submitted a form or made a purchase;
  • confirming purchases with Customer’s connected Polar store to show delivery content and order details;
  • storing Customer-uploaded content;
  • providing dashboards and site analytics where enabled;
  • maintaining and securing the Services; and
  • providing related functionality requested by Customer.

Categories of Data Subjects

Visitors to Customer’s sites, subscribers, leads, prospective or current customers, people making bookings, people submitting forms, and people interacting with Customer’s content.

Categories of Personal Data

Depending on Customer’s configuration: name, email address, telephone number, company or organisation, website URL, messages, booking dates and times, booking responses, newsletter subscription information, form responses, purchase details (order ID, product, amount, buyer name and email), Customer-uploaded content, IP-derived or technical information, device and browser information, referral and campaign information, analytics events and identifiers, and other information Customer chooses to request through supported fields.

Sensitive data

Yee is not designed for intentional processing of special-category data under GDPR Article 9 or criminal-conviction data under Article 10 unless expressly agreed otherwise.

Annex II — Technical and organisational measures

  • Access control: authentication, restricted administrative access and least-privilege controls.
  • Encryption: HTTPS/TLS in transit and encryption at rest where provided by the relevant infrastructure.
  • Data isolation: application and database controls designed to separate customer data.
  • Infrastructure: established cloud, storage, network and delivery providers.
  • Monitoring and resilience: logging, monitoring, backups and recovery measures appropriate to the Services.
  • Security maintenance: software updates, dependency management, rate limits, upload restrictions and remediation of identified vulnerabilities.
  • Confidentiality and response: limited authorised access and procedures for investigating and responding to incidents.
  • Data minimisation and deletion: processing limited to supported purposes, with account tools and procedures for deletion subject to retention requirements.

Annex III — Subprocessors

The current infrastructure Subprocessors for Customer Data may include:

  • Supabase — database, authentication and file storage infrastructure.
  • Lovable — application hosting and server runtime for the Services and published sites.
  • Cloudflare — DNS, network, security and routing for yee.site and *.yee.site addresses.
  • Vercel — routing and TLS certificates for custom domains connected by Customer.
  • Resend — delivery of notification emails enabled by Customer (recipient email address, email content and delivery metadata).

When Customer connects its own Cal.com account to a booking section, booking details are sent to Cal.com on Customer’s instruction; Cal.com acts under Customer’s own agreement with Cal.com, not as Yee’s Subprocessor.

When Customer connects its own Polar account to sell products, buyers pay on Polar’s hosted checkout. Polar acts as merchant of record and independent controller of payment, tax and buyer data under Customer’s own agreement with Polar, not as Yee’s Subprocessor. Yee receives no payment data and reads order details from Customer’s Polar store only on Customer’s instruction.

Other providers may be used where reasonably necessary to operate the Services. Processing locations and transfer safeguards depend on the services and configurations in use; international transfers are handled as described in section 10.

Made inYee