Log in Start Free Trial

Data Processing Agreement

DRAFT — pending legal review. This document has not yet been reviewed by a licensed attorney and should not be relied on as a binding legal commitment until it has. If you are an enterprise customer requesting an executed DPA, contact hello@theyesfunnel.com.

This Data Processing Agreement ("DPA") supplements the YES Funnel Terms and Conditions ("Agreement") between you ("Customer," "Controller," "you") and YES Funnel ("Processor," "we," "us") whenever we process Visitor Data on your behalf, as described in our Privacy Policy. If there is a conflict between this DPA and the Agreement regarding the processing of personal data, this DPA controls.

1. Definitions

2. Roles of the parties

For Visitor Data, you are the Controller and we are the Processor. We process Visitor Data solely to provide the Services to you — storing form/quiz submissions, routing them to the destinations you configure (your dashboard, your connected Google Sheet, your connected CRM or webhook, your connected SendFox list, SMS/email notifications you set up), and generating analytics about your own funnels. We do not use Visitor Data for our own marketing, do not sell it, and do not combine it with other customers' Visitor Data.

For Account Data (your own name, email, and billing details as a YES Funnel customer), we are the Controller, and that processing is governed by our Privacy Policy directly, not this DPA.

3. Processing on your instructions

We will process Visitor Data only on your documented instructions, which consist of: (a) this DPA and the Agreement, and (b) your own configuration of the Services (which integrations you connect, which questions/blocks you publish, which automations you set up). If we believe an instruction violates Data Protection Law, we will tell you before carrying it out.

4. Security measures

We maintain technical and organizational measures appropriate to the risk, including: encryption in transit (TLS/HSTS on all connections), password hashing (bcrypt, never stored in plain text), signed and verified webhook payloads for payment events, session cookies scoped `httpOnly`/`sameSite`, rate limiting and adaptive lockout on authentication endpoints to resist credential-stuffing, and role-based access restricting Visitor Data to your own account and any teammates you've explicitly invited. No method of transmission or storage is 100% secure, and these measures are described further at theyesfunnel.com/features and will be detailed on a dedicated security page.

5. Sub-processors

You authorize us to engage the following Sub-processors to process Visitor Data as necessary to provide the Services. We remain responsible for each Sub-processor's compliance with obligations equivalent to this DPA.

Any third-party destination you configure yourself (a custom webhook URL, Zapier, Activepieces, your own CRM) is your own integration, not our Sub-processor — you are responsible for your relationship with, and any agreement required with, that destination.

We will give you reasonable notice before adding or replacing a Sub-processor materially involved in processing Visitor Data, and you may object on reasonable data-protection grounds by contacting hello@theyesfunnel.com.

6. International transfers

Where Visitor Data is transferred outside the country in which it was collected, we will rely on an appropriate transfer mechanism recognized under applicable Data Protection Law (such as the EU Standard Contractual Clauses) to the extent required. [Placeholder — confirm actual hosting region and, if serving EU/UK customers, attach or reference the applicable SCC module before this DPA is executed.]

7. Assistance with Data Subject requests

If we receive a request from one of your visitors to exercise their rights under Data Protection Law (access, correction, deletion, etc.) directly against us, we will forward it to you without undue delay and will not respond to the visitor ourselves, since you are the Controller. We will provide reasonable assistance to help you respond, including through account-level tools for reviewing and deleting lead records.

8. Personal data breach notification

We will notify you without undue delay, and in any case within 72 hours of becoming aware, after confirming a personal data breach affecting Visitor Data, with the information reasonably available to us at that time about its nature and likely consequences.

9. Audits

On reasonable written request, no more than once per 12-month period absent a suspected breach, we will provide you with information reasonably necessary to demonstrate compliance with this DPA, which may take the form of a summary of our security practices or an available third-party audit/pen-test summary rather than an on-site audit.

10. Return and deletion of data

On termination of the Agreement, and subject to any legal retention obligation, we will delete or anonymize Visitor Data associated with your account within a commercially reasonable period, consistent with the retention terms in our Privacy Policy. You can export your leads at any time before termination via your dashboard.

11. Liability

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement.

12. Contact

Questions about this DPA, or requests for a countersigned copy, can be sent to hello@theyesfunnel.com.