Data Processing Agreement
Last updated August 14, 2026
DRAFT — pending legal review. This document has not yet been reviewed by a licensed attorney and should not be relied on as a binding legal commitment until it has. If you are an enterprise customer requesting an executed DPA, contact hello@theyesfunnel.com.
This Data Processing Agreement ("DPA") supplements the YES Funnel Terms and Conditions ("Agreement") between you ("Customer," "Controller," "you") and YES Funnel ("Processor," "we," "us") whenever we process Visitor Data on your behalf, as described in our Privacy Policy. If there is a conflict between this DPA and the Agreement regarding the processing of personal data, this DPA controls.
1. Definitions
- "Visitor Data" means personal data submitted by a person who visits, interacts with, or completes a funnel, quiz, or landing page you build or publish using the Services — including name, email address, phone number, quiz/form answers, uploaded files, recorded video/audio responses (if you enable that feature), IP address, and UTM/referral data.
- "Data Protection Laws" means all laws and regulations applicable to the processing of personal data under this DPA, including, where applicable, the EU General Data Protection Regulation (GDPR), UK GDPR, and US state privacy laws.
- "Controller," "Processor," "Data Subject," "Personal Data," "Processing," and "Sub-processor" have the meanings given in the GDPR, applied by analogy where another Data Protection Law uses different terms for equivalent roles.
2. Roles of the parties
For Visitor Data, you are the Controller and we are the Processor. We process Visitor Data solely to provide the Services to you — storing form/quiz submissions, routing them to the destinations you configure (your dashboard, your connected Google Sheet, your connected CRM or webhook, your connected SendFox list, SMS/email notifications you set up), and generating analytics about your own funnels. We do not use Visitor Data for our own marketing, do not sell it, and do not combine it with other customers' Visitor Data.
For Account Data (your own name, email, and billing details as a YES Funnel customer), we are the Controller, and that processing is governed by our Privacy Policy directly, not this DPA.
3. Processing on your instructions
We will process Visitor Data only on your documented instructions, which consist of: (a) this DPA and the Agreement, and (b) your own configuration of the Services (which integrations you connect, which questions/blocks you publish, which automations you set up). If we believe an instruction violates Data Protection Law, we will tell you before carrying it out.
4. Security measures
We maintain technical and organizational measures appropriate to the risk, including: encryption in transit (TLS/HSTS on all connections), password hashing (bcrypt, never stored in plain text), signed and verified webhook payloads for payment events, session cookies scoped `httpOnly`/`sameSite`, rate limiting and adaptive lockout on authentication endpoints to resist credential-stuffing, and role-based access restricting Visitor Data to your own account and any teammates you've explicitly invited. No method of transmission or storage is 100% secure, and these measures are described further at theyesfunnel.com/features and will be detailed on a dedicated security page.
5. Sub-processors
You authorize us to engage the following Sub-processors to process Visitor Data as necessary to provide the Services. We remain responsible for each Sub-processor's compliance with obligations equivalent to this DPA.
| Sub-processor | Purpose | When it applies |
|---|---|---|
| Bunny.net | File and video/audio recording storage | When a visitor uploads a file or records a video/audio answer |
| Resend / your configured SMTP provider | Delivering lead-notification and automation emails | When email notifications or automations are enabled |
| Twilio | Sending SMS | Only if you configure a "Send SMS" automation |
| Google (Sheets/Drive API) | Syncing Visitor Data to a spreadsheet you own | Only if you connect Google Sheets |
| SendFox | Syncing new leads to a list you own | Only if you connect your own SendFox account |
| OpenRouter, Inc. (routing to an underlying model provider, currently Anthropic) | Powering AI features (chat block responses, AI analytics answers) that may reference Visitor Data you've asked the AI to consider | Only if you use an AI-powered feature on a published funnel |
| Our infrastructure/hosting provider | Application hosting, database, and caching | Always — this is where Visitor Data is stored at rest |
Any third-party destination you configure yourself (a custom webhook URL, Zapier, Activepieces, your own CRM) is your own integration, not our Sub-processor — you are responsible for your relationship with, and any agreement required with, that destination.
We will give you reasonable notice before adding or replacing a Sub-processor materially involved in processing Visitor Data, and you may object on reasonable data-protection grounds by contacting hello@theyesfunnel.com.
6. International transfers
Where Visitor Data is transferred outside the country in which it was collected, we will rely on an appropriate transfer mechanism recognized under applicable Data Protection Law (such as the EU Standard Contractual Clauses) to the extent required. [Placeholder — confirm actual hosting region and, if serving EU/UK customers, attach or reference the applicable SCC module before this DPA is executed.]
7. Assistance with Data Subject requests
If we receive a request from one of your visitors to exercise their rights under Data Protection Law (access, correction, deletion, etc.) directly against us, we will forward it to you without undue delay and will not respond to the visitor ourselves, since you are the Controller. We will provide reasonable assistance to help you respond, including through account-level tools for reviewing and deleting lead records.
8. Personal data breach notification
We will notify you without undue delay, and in any case within 72 hours of becoming aware, after confirming a personal data breach affecting Visitor Data, with the information reasonably available to us at that time about its nature and likely consequences.
9. Audits
On reasonable written request, no more than once per 12-month period absent a suspected breach, we will provide you with information reasonably necessary to demonstrate compliance with this DPA, which may take the form of a summary of our security practices or an available third-party audit/pen-test summary rather than an on-site audit.
10. Return and deletion of data
On termination of the Agreement, and subject to any legal retention obligation, we will delete or anonymize Visitor Data associated with your account within a commercially reasonable period, consistent with the retention terms in our Privacy Policy. You can export your leads at any time before termination via your dashboard.
11. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
12. Contact
Questions about this DPA, or requests for a countersigned copy, can be sent to hello@theyesfunnel.com.