Data Processing Addendum
Last updated: July 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between you ("Customer") and YRECURRING LLC ("yRecurring") and applies where yRecurring processes personal data on the Customer's behalf in providing the Service. Where data protection law requires a signed agreement, contact [email protected] to request an executable copy.
1. Roles and definitions
For personal data the Customer submits to the Service ("Customer Personal Data"), the Customer is the controller and yRecurring is the processor. "Controller", "processor", "data subject", "personal data", and "processing" have the meanings given in applicable data protection law, including the GDPR and UK GDPR where they apply. yRecurring processes Customer Personal Data only to provide the Service and on the Customer's documented instructions, including those in the Terms and this DPA.
2. yRecurring's obligations
- Instructions. We process Customer Personal Data only on your documented instructions, unless law requires otherwise, in which case we will tell you unless the law forbids it.
- Confidentiality. People we authorize to process the data are bound by confidentiality.
- Security. We maintain the technical and organizational measures described in Annex II, appropriate to the risk.
- Subprocessors. You give general authorization for us to use subprocessors listed on our Subprocessors page. We impose data protection obligations on them no less protective than this DPA, remain responsible for their performance, and will give notice of changes so you can object on reasonable data protection grounds.
- Data subject requests. We will help you respond to requests from data subjects to exercise their rights, taking into account the nature of the processing.
- Assistance. We will help you meet your obligations for security, breach notification, and data protection impact assessments, taking into account the information available to us.
- Breach notification. We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.
- Deletion or return. On termination, we will delete or return Customer Personal Data as described in the Terms, subject to legal retention and routine backups that cycle out over time.
- Audits. We will make available information reasonably necessary to show compliance and will allow audits, including through third-party reports or a questionnaire, on reasonable notice and subject to confidentiality.
3. International transfers
Where we transfer Customer Personal Data across borders in a way that triggers legal safeguards, the Standard Contractual Clauses (and the UK Addendum where relevant) are incorporated into this DPA and apply to that transfer.
4. Liability
Each party's liability under this DPA is subject to the limitations of liability in the Terms.
Annex I: Description of processing
- Subject matter and duration: processing to provide the Service, for the term of the Terms.
- Nature and purpose: hosting, storing, and processing Customer Personal Data to run billing, invoicing, and subscription management.
- Types of personal data: identifiers and contact details of your customers, billing and subscription records, and related metadata. Not full payment card numbers.
- Categories of data subjects: your customers and their representatives.
Annex II: Security measures
Encryption of data in transit and at rest, tenant isolation enforced in the database, access controls with least privilege and multi-factor authentication for administrative access, an append-only audit trail of changes, logging and monitoring, and a responsible disclosure channel. See our Security page for detail.
Annex III: Subprocessors
The current subprocessors are listed on our Subprocessors page, which is part of this DPA.