Legal

Data Processing Addendum

Your workspace holds personal data about your staff and your suppliers' contacts. This sets out what we do with it on your behalf, who else can see it, and what happens when you leave.

Updated 26 July 202612 sections5 min read
01

Who is who

In this addendum, "Customer" is the business with a Yumpit workspace and "Yumpit" is Yumpit LLC, a limited liability company formed in the State of Wyoming, United States, at 5830 E 2nd St, Ste 7000 #37603, Casper, WY 82609, United States.

For the personal data inside your workspace — your staff, your suppliers' contacts, your own team — you are the controller and Yumpit is the processor. You decide what goes in and why; we act on your instructions.

For a small set of data we decide ourselves — account records, billing information, and the security logs we keep to run the service — Yumpit is the controller, and our Privacy Policy governs it rather than this addendum.

02

What we process, and why

Subject matter: providing the Yumpit platform. Duration: for as long as your workspace exists, plus the retention window described below.

Categories of data subject: your employees and team members, and the individual contacts you record for suppliers.

Categories of personal data: names, email addresses, phone numbers, job titles and roles; attendance and scheduling records where you use those features; and the audit trail of actions taken in the workspace.

We do not ask for and do not want special categories of personal data. Yumpit is not designed to hold health, biometric or similar data, and you should not put it in.

03

Our instructions

We process personal data only to provide and support the service, and only on your documented instructions — which include your use of the product's features.

If we are ever required by law to process data beyond your instructions, we will tell you before doing so unless that same law forbids it.

We will tell you if, in our view, an instruction you give would breach applicable data protection law.

04

Confidentiality and access

Access to customer data inside Yumpit is limited to people who need it to run or support the service, and everyone with such access is bound by confidentiality obligations.

Within your own workspace, who sees what is your decision: roles and permissions are yours to set, and we do not override them.

05

Security

Data is encrypted in transit and at rest. Access to the platform requires authentication, and two-factor authentication is available and enforced at the account level when you enable it.

Workspaces are isolated: every request is scoped to the organisation of the authenticated user, and that scoping is enforced on the server rather than in the interface.

Card details are handled entirely by our payment processor and never reach our systems. Our error monitoring is deliberately configured not to transmit request bodies, so commercial data such as invoice lines, supplier pricing and payroll figures stays out of it.

We keep an append-only audit trail of significant account actions, including sign-ins, permission changes and account deletion.

06

Subprocessors

You give general authorisation for us to engage subprocessors. The current list, including what each can access and where it holds data, is published at /legal/subprocessors and is kept current.

We impose data protection obligations on each subprocessor no less protective than those in this addendum, and we remain responsible to you for their performance.

We update that page before a new subprocessor begins processing customer data. Email us to be notified of changes, and if you reasonably object to a new subprocessor on data protection grounds, tell us and we will work with you or you may terminate the affected service.

07

International transfers

Yumpit is a United States entity serving customers worldwide, and our subprocessors sit across the United States and the European Union. Personal data will therefore cross borders, including out of the country where your business operates.

Where data leaves the European Economic Area or Switzerland we rely on the European Commission's Standard Contractual Clauses. For the United Kingdom we rely on the UK International Data Transfer Addendum to those clauses. For transfers from elsewhere we use the safeguard that country's law provides for.

The subprocessor page states where each provider holds data, so you can see exactly which transfers apply to you. If your regulator requires a specific mechanism or a transfer impact assessment, contact us and we will provide what is needed.

08

Helping you meet your own obligations

If a data subject contacts us directly about data in your workspace, we will not respond on your behalf — we will refer them to you and tell you promptly.

The product gives you the tools to answer most requests yourself: you can export your data, correct records, remove team members, and delete an account from within the app. Where a request needs more than the product provides, we will assist you.

We will provide reasonable assistance with data protection impact assessments and with prior consultation of a supervisory authority, where these relate to our processing.

09

Personal data breaches

If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any event within 72 hours of becoming aware of it.

That notice will describe what happened, the categories and approximate volume of data affected, the likely consequences, and what we are doing about it — including anything you need to do. Where we do not yet have full information, we will send what we have rather than wait.

10

Deletion and return

You can export your data at any time while your workspace is active.

When an account is deleted, access ends immediately and any subscription is cancelled. Where the person deleting is the only member, the workspace is marked for deletion and permanently erased 30 days later — a deliberate window so an accidental deletion can be reversed.

A deleted person's profile is anonymised rather than dropped, because purchase orders, approvals and attendance records reference it and removing the row would erase who did what from records that remain live. All personal data in that profile is scrubbed and it becomes an unattributable placeholder.

We may retain data for longer only where law requires it, and in that case we keep it solely for that purpose.

11

Audits

On reasonable written request, and no more than once a year unless a regulator requires otherwise, we will make available the information necessary to demonstrate compliance with this addendum and contribute to audits conducted by you or an auditor you appoint.

In practice, most security reviews are answered by the information published here and on the subprocessor page. Start there and tell us what is missing.

12

Contact

Data protection enquiries, breach notifications, and requests for a countersigned copy of this addendum: privacy@yumpit.com.