Data Processing Addendum
Last updated 26 June 2026
Written to be readable. This isn’t a substitute for legal advice — questions? Contact us.
This Data Processing Addendum applies when you use Yadi as a business and we process personal data on your behalf. You are the controller; Yadi is your processor. It sets out how we handle that data under Uganda’s Data Protection and Privacy Act, 2019, and lists our subprocessors and security measures.
How this DPA works
This DPA forms part of the agreement between you (the customer) and Embiro Technologies (U) Limited for the Yadi service. It applies where we process personal data on your behalf and the Data Protection and Privacy Act, 2019 (the “Act”) applies. If it conflicts with the rest of the agreement on data protection, this DPA prevails.
Words we use
“Controller”, “processor”, “personal data”, “data subject”, and “processing” have the meanings given in the Act. “Customer data” means the personal data we process on your behalf to provide Yadi.
Roles
For customer data, you are the controller and we are the processor. You are responsible for the lawfulness of the data you put into Yadi and the instructions you give. We process customer data only to provide the service.
Our instructions
We process customer data only on your documented instructions — including the tasks, automations, and integrations you configure — unless the law requires otherwise, in which case we will tell you unless the law forbids it.
Our commitments as processor
- Process customer data only on your instructions, for the purposes in Annex 1.
- Keep customer data confidential and bind our staff to confidentiality.
- Apply the security measures in Annex 3.
- Help you respond to data-subject requests and meet your own duties under the Act, including security, breach notification, and any impact assessments.
- Make available the information you reasonably need to show compliance.
- Delete or return customer data at the end of the service, as set out below.
Subprocessors
You authorize us to use the subprocessors listed in Annex 2 to provide the service. We bind each to data-protection terms no less protective than this DPA and remain responsible for their performance. We will give you notice before adding or replacing a subprocessor so you can object on reasonable data-protection grounds.
Sending data outside Uganda
Providing the service involves transferring customer data outside Uganda, mainly to the United States, to the subprocessors in Annex 2. We rely on section 19 of the Act: your authorization and contracts requiring each subprocessor to protect the data to a comparable standard.
Personal data breach
If we become aware of a breach affecting customer data, we will notify you without undue delay, share what we know, and help you meet your notification duties to the Personal Data Protection Office and to affected people under the Act.
Data-subject requests
If a data subject contacts us about customer data, we will refer them to you and will not respond directly unless you tell us to. We will help you respond within the time the Act allows.
Audits
On reasonable request and notice, no more than once a year unless the Act or a regulator requires otherwise, we will give you the information needed to confirm our compliance with this DPA, subject to confidentiality.
Deleting or returning data
When the service ends, we will delete or, at your choice, return customer data within 30 days, except where the law requires us to keep specific records.
Liability and term
This DPA lasts as long as we process customer data. Liability under it is subject to the limits in the main agreement.
Annex 1 — Details of processing
- Subject matter — providing the Yadi service.
- Duration — the term of the agreement, plus the deletion window above.
- Nature and purpose — hosting, processing, and acting on customer data to run the AI teammates and the tasks you configure.
- Types of personal data — identity and contact details; the content of emails, messages, calendar events, files, and meeting transcripts you connect or upload; usage and log data; and billing data. This may include special personal data where it appears in that content.
- Categories of data subjects — your team members, and the people they communicate with or refer to, including customers, contacts, and meeting participants.
Annex 2 — Subprocessors
| Subprocessor | What it does | Location |
|---|---|---|
| Vercel | Application hosting and AI Gateway | United States |
| Neon | Database hosting (Postgres) | United States |
| Cloudflare | File storage (R2) | United States / global |
| Anthropic | AI model provider | United States |
| AI model provider | United States | |
| OpenAI | AI model provider and embeddings | United States |
| Voyage AI | Embeddings and reranking | United States |
| Composio | OAuth credential broker and tool integrations | United States |
| Mem0 | Long-term agent memory | United States |
| Meta Platforms | WhatsApp messaging channel | United States / Ireland |
| Stripe | Payment processing | United States |
| Inngest | Durable job processing | United States |
| Axiom | Logging and traces | United States |
| PostHog | Product analytics and error tracking | United States / EU |
| Firecrawl | Website crawling for the knowledge base | United States |
| Exa | Web search | United States |
| Fathom | Meeting transcription (where you connect it) | United States |
| Fireflies | Meeting transcription (where you connect it) | United States |
Annex 3 — Security measures
- Encryption of customer data in transit and at rest.
- Brokered credentials — OAuth tokens are held by our broker, never by us, and the AI never sees raw tokens.
- Scoped access — a teammate reaches only the tools you grant, and you can revoke any connection in one click.
- Workspace isolation — each workspace’s data is segregated; one workspace’s data never appears in another’s results.
- Human-in-the-loop — external messages and money movements require explicit approval.
- An append-only audit log of every tool run, approval, and automated action.
- Role-based, least-privilege access for our own staff.
- Daily spend controls that cap AI usage.
- Secrets management, environment isolation, and regular review of access and subprocessors.