Data Processing Addendum

Last updated 1 March 2026

Version 1.0 · Applies to every customer for whom YICCO processes Customer Content

What this document is. This Data Processing Addendum (“DPA”) applies whenever YICCO B.V. processes personal data on your behalf as a processor — principally personal data contained in the documents you upload to the Services (“Customer Content”). It is incorporated into the YICCO Terms of Service by reference and takes effect on your acceptance of those Terms; no separate signature is required. The same standard DPA applies to every customer, individual or organisation. It does not govern data for which YICCO is itself the controller (account, authentication, billing, usage and analytics data), which is governed by the Privacy Policy.

1. Parties and Structure

The Parties. This DPA is entered into between YICCO B.V., a company registered in the Netherlands at Keizersgracht 241, 1016 EA Amsterdam (Chamber of Commerce no. 99795035; VAT NL869136240B01) (“YICCO”, the “Processor”), and the customer who accepts the Terms of Service — whether an individual using the Services in a professional capacity, or an organisation subscribing on behalf of its members (“Customer”, the “Controller”).

Relationship to the Terms. This DPA forms part of, and is subject to, the YICCO Terms of Service (the “Terms”). Capitalised terms not defined here have the meaning given in the Terms. In case of conflict between this DPA and the Terms regarding the processing of Customer Content, this DPA prevails; in all other respects the Terms govern.

No separate signature. This DPA is effective on the Customer’s acceptance of the Terms, including where an organisation accepts the Terms on behalf of its users. An organisation whose procurement rules require a signed copy may request one under the General clause below; signature affects execution only, not the content, which is standard and non-negotiable.

2. Definitions

In this DPA:

  • “Data Protection Law” means all data protection and privacy laws applicable to the processing of personal data under this DPA, including Regulation (EU) 2016/679 (the “GDPR”); the GDPR as incorporated into the law of the United Kingdom (the “UK GDPR”), where applicable; and any other applicable national implementing or equivalent legislation.
  • “Controller”, “Processor”, “data subject”, “personal data”, “processing”, “personal data breach”, “special categories of personal data” and “supervisory authority” have the meanings given in the GDPR.
  • “Customer Content” means the documents, publications, manuscripts, reports, source materials and other content the Customer (or its authorised users) uploads to or generates within the Services, together with the AI-generated outputs derived from them.
  • “Customer Personal Data” means personal data within Customer Content that YICCO processes on the Customer’s behalf under this DPA — typically personal data incidentally contained in scientific publications and similar materials (for example author names, affiliations, ORCID identifiers and contact details).
  • “Sub-processor” means any processor engaged by YICCO to process Customer Personal Data.
  • “Affiliate” means any entity that controls, is controlled by, or is under common control with a Party.
  • “FADP” means the Swiss Federal Act on Data Protection, and “FDPIC” the Swiss Federal Data Protection and Information Commissioner.
  • “CCPA” means the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020, and its implementing regulations.
  • “EU SCCs” means the Standard Contractual Clauses set out in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, and “UK Addendum” means the International Data Transfer Addendum to those clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018; together with any successor or replacement instrument, the “SCCs”.
  • “Annex” means an annex to this DPA. Annexes I–III may be updated by YICCO in accordance with this DPA without re-executing the DPA itself.

3. Roles of the Parties and Scope

The Parties acknowledge that, with respect to the processing of Customer Personal Data, the Customer is the Controller and YICCO is the Processor. Where Customer Personal Data relates to data subjects for whom a third party is controller, the Customer warrants that it is authorised to instruct YICCO as Processor in respect of that data.

Data outside this DPA. This DPA does not apply to personal data for which YICCO is an independent controller, including: account and profile data; authentication and login data; billing and payment data; and usage, device, log and product-analytics data. YICCO processes that data as a controller under its Privacy Policy and applicable Data Protection Law, and the Customer cannot, by instruction, displace YICCO’s own legal obligations in respect of it (for example, retention of invoice records for tax purposes).

Allocation follows the facts. The Parties agree that the role allocation in this DPA reflects who determines the purposes and means of processing (Articles 4(7) and 4(8) GDPR). Labelling does not create a role that the facts do not support.

Duration. This DPA applies for as long as YICCO processes Customer Personal Data, and survives termination of the Terms to the extent YICCO retains any Customer Personal Data.

4. Processing Instructions and Purpose Limitation

YICCO shall process Customer Personal Data only:

  • on the Customer’s documented instructions, including as set out in this DPA, the Terms and the Customer’s use of the Services (the act of uploading content and selecting an output being a documented instruction); and
  • as required by EU or Member State law to which YICCO is subject, in which case YICCO shall (unless that law prohibits it on important grounds of public interest) inform the Customer of that legal requirement before processing.

Single permitted purpose for Customer Content. YICCO shall process Customer Content solely to provide the Services — that is, to generate the communication outputs the Customer requests — and for no other purpose. In particular, YICCO shall not: (a) use Customer Content to train, fine-tune or improve any AI model (whether YICCO’s or a third party’s); (b) build a corpus from, or perform substantive analytics on the contents of, Customer Content; or (c) disclose, sell or share Customer Content other than as instructed or as permitted by this DPA. This restriction is the basis on which YICCO remains a Processor of Customer Content.

Unlawful instructions. YICCO shall inform the Customer if, in its opinion, an instruction infringes Data Protection Law. YICCO may suspend the relevant processing until the instruction is confirmed or amended, without liability.

Customer responsibility for what is uploaded. The Customer determines, and is responsible for, the content it uploads. The Customer warrants that it holds the rights necessary to upload and have Customer Content processed, that the content is not subject to any confidentiality, NDA, embargo or secrecy obligation that would prohibit processing, and that it contains no personal data of third parties that is not either fully anonymised or covered by a lawful basis and the necessary consent. The Services are intended for published scientific and public-facing communication material and must not be used to upload patient data, health records, research-participant data, interview transcripts, special-category personal data, or confidential research datasets. YICCO does not verify the lawfulness of any individual upload.

5. Confidentiality

YICCO shall treat Customer Personal Data as confidential and shall ensure that persons authorised to process it (a) are bound by an appropriate contractual or statutory duty of confidentiality, and (b) process it only on instruction. This obligation survives termination.

6. No Sensitive or Special-Category Data

The Services are designed and intended for published scientific work and public-facing communication material. YICCO does not wish to receive or store, and the Customer must not upload, any of the following: special categories of personal data within the meaning of Article 9 GDPR (including data revealing health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric data, or data concerning sex life or sexual orientation); personal data relating to criminal convictions and offences; patient data or health records; research-participant data; interview transcripts; or any confidential or non-anonymised dataset.

Allocation of responsibility. The Customer is responsible for ensuring that Customer Content does not contain such data, and shall restrict YICCO’s access to any such data within its possession or control. YICCO does not seek out, request, or require sensitive personal data in order to provide the Services, has not designed the Services to process it, and does not knowingly process it. If such data is nonetheless uploaded in breach of this clause, the Customer remains the controller of it and responsible for it, and YICCO’s technical measures (including no training on Customer Content and minimised retention) are intended to contain rather than legitimise its processing.

7. Security of Processing

Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to data subjects, YICCO shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex II (Technical and Organisational Measures).

YICCO may update the measures in Annex II from time to time provided that the updated measures do not materially reduce the overall level of security. The current Annex II is the version published on this page.

8. Sub-processors

General authorisation. The Customer grants YICCO general authorisation to engage Sub-processors to process Customer Personal Data. YICCO maintains a current list of Sub-processors in Annex III (Sub-processor List).

Obligations flow down. YICCO shall ensure that each Sub-processor is bound by data-protection obligations that are no less protective than those in this DPA, in particular regarding security and the prohibition on using Customer Content to train AI models. These obligations are imposed through a binding instrument under Article 28(4) GDPR — which, for established providers (such as the AI Providers and hosting providers), is typically the provider’s own standard data processing agreement or standard processing terms accepted by YICCO, rather than an individually negotiated contract. YICCO remains liable to the Customer for a Sub-processor’s performance of those obligations.

Changes and objection. YICCO shall give the Customer at least ten (10) days’ prior notice of the addition or replacement of a Sub-processor by updating Annex III and, where the Customer has subscribed to notifications, by email or in-product notice. The Customer may object on reasonable, data-protection grounds within that period. The Parties shall work in good faith to resolve the objection; if they cannot, the Customer may terminate the affected Services by notice, as its sole and exclusive remedy.

AI Providers. YICCO’s AI Provider Sub-processors are engaged under terms that, for content submitted via their APIs, prohibit use of that content to train or improve the provider’s models and apply short, automated deletion windows. YICCO does not permit any Sub-processor (including the AI Providers) to use Customer Content to fine-tune, train or develop their AI functionality or models, and YICCO shall not integrate any AI Provider whose standard configuration permits Customer Content to be used for model training.

9. International Transfers

Default location. YICCO’s primary processing infrastructure for Customer Content is located in the European Union. Where YICCO or a Sub-processor processes Customer Personal Data outside the European Economic Area (EEA) or the United Kingdom (a “restricted transfer”), it shall ensure an appropriate transfer mechanism under Data Protection Law before the transfer takes place.

EU transfers — SCCs. For restricted transfers subject to the GDPR, the Parties incorporate by reference the Standard Contractual Clauses set out in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (the “EU SCCs”), completed as follows: the Customer is the data exporter and YICCO (or the relevant recipient) is the data importer; Module Two (controller-to-processor) applies; the optional docking clause (Clause 7) applies; in Clause 9, Option 2 (general written authorisation for sub-processors) applies, with the notice period set out in the Sub-processors clause of this DPA; in Clause 11, the optional independent-dispute-resolution body is not used; in Clause 17, the EU SCCs are governed by the law of the Netherlands; in Clause 18(b), the courts of the Netherlands are chosen; and Annexes I–III to the EU SCCs are populated by Annexes I, II and III of this DPA respectively. Where there is a conflict between the EU SCCs and this DPA in respect of a restricted transfer, the EU SCCs prevail.

UK transfers — IDTA / Addendum. For restricted transfers subject to the UK GDPR, the Parties apply the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018 (the “UK Addendum”), which incorporates and amends the EU SCCs above for use under the UK GDPR. Part 1 of the UK Addendum is completed using the details in this DPA and its Annexes; the start date is the effective date of this DPA; and either Party may end the UK Addendum as permitted where the Information Commissioner issues a revised version that would, in that Party’s reasonable opinion, materially increase its obligations. Alternatively, the Parties may use the ICO International Data Transfer Agreement (IDTA) for UK-only transfers.

Swiss transfers — FADP. For restricted transfers subject to the FADP, the EU SCCs apply with the following adaptations: references to the GDPR are read as references to the FADP; references to the EU and EU Member States are read to include Switzerland; the competent supervisory authority is the FDPIC insofar as the transfer is governed by the FADP; and the term “Member State” is not read so as to deny data subjects in Switzerland the right to bring proceedings in their place of habitual residence.

Transfer risk assessment and safeguards. Where required by the EU SCCs or the UK Addendum, the Parties will conduct and document a transfer risk assessment, and YICCO will apply supplementary technical and organisational measures (as described in Annex II, including encryption in transit and at rest and EU data residency for Customer Content) appropriate to the risks identified.

Adequacy and successor instruments. Where a restricted transfer is instead covered by an adequacy decision (including any applicable EU–US or UK data-bridge framework) or by another lawful transfer mechanism, that mechanism may be relied upon. If the EU SCCs or the UK Addendum are replaced, amended or supplemented by the competent authority (including any additional set of clauses for importers themselves subject to the GDPR), the Parties will apply the updated or successor instrument from the date it becomes required.

10. Assistance to the Controller

10.1 Data subject rights

Taking into account the nature of the processing, YICCO shall assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests by data subjects to exercise their rights under Chapter III of the GDPR. If YICCO receives such a request directly relating to Customer Personal Data, it shall, without undue delay, direct the data subject to the Customer and notify the Customer, and shall not respond to the request itself except on the Customer’s instruction.

10.2 DPIAs and prior consultation

YICCO shall provide the Customer with reasonable assistance with data-protection impact assessments and prior consultations with a supervisory authority under Articles 35 and 36 GDPR, taking into account the nature of the processing and the information available to YICCO.

10.3 Cost

Except where Data Protection Law requires YICCO to provide assistance free of charge, YICCO may charge a reasonable fee for the assistance described in this clause, reflecting the time and resources involved. YICCO will notify the Customer of any such fee in advance.

11. Personal Data Breach Notification

YICCO shall notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notification shall, to the extent then known and as it becomes available, describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. YICCO shall provide reasonable assistance to enable the Customer to meet its own notification obligations under Articles 33 and 34 GDPR. YICCO’s notification is not, and shall not be construed as, an acknowledgement of fault or liability.

12. Government and Public Authority Access Requests

If YICCO receives a legally binding request from a public authority (including a law-enforcement or judicial authority) for access to Customer Personal Data, YICCO shall, unless legally prohibited, notify the Customer without undue delay, including a summary of the nature of the request. Where prohibited from notifying, YICCO shall use reasonable efforts to obtain a waiver of that prohibition. YICCO shall review the lawfulness of the request and, where it concludes on reasonable grounds that the request is unlawful under Data Protection Law, challenge it, provided that nothing in this clause requires YICCO to take action that would expose it to civil or criminal penalty. YICCO shall disclose only the minimum amount of Customer Personal Data necessary to respond to a valid and binding request.

13. Deletion of Data

During the term. By default, Customer Content and the outputs derived from it are retained only as long as needed to provide the Services and are deleted or irreversibly anonymised on a short, documented schedule, or earlier on Customer instruction (for example by deleting content within the Services).

On termination. On termination or expiry of the Services, YICCO shall delete all Customer Personal Data and delete existing copies, unless EU or Member State law requires storage. Where deletion from active systems has occurred but residual copies remain in routine backups, those copies are isolated from further processing and deleted in the ordinary backup-rotation cycle. Customers are responsible for retaining their own copies of any Output they wish to keep before termination.

14. Audit and Demonstration of Compliance

YICCO shall make available to the Customer the information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA. YICCO satisfies this obligation in the first instance by providing, on request, its security documentation and any third-party certifications or audit reports it holds.

Where that information is not sufficient for the Customer to demonstrate its own compliance, the Customer (or an independent auditor it mandates, who is not a YICCO competitor and is bound by confidentiality) may, on reasonable prior notice of at least thirty (30) days, no more than once in any twelve-month period (save where required by a supervisory authority or following a personal data breach), and during business hours without unreasonably disrupting YICCO’s operations, conduct an audit limited to YICCO’s processing of Customer Personal Data. Each Party bears its own costs unless the audit reveals a material non-compliance by YICCO.

15. Liability

Each Party’s liability arising out of or related to this DPA, whether in contract, tort or any other theory of liability, is subject to the limitations and exclusions of liability set out in the Terms, and any reference in the Terms to the liability of a Party is deemed to include that Party’s liability under this DPA. Nothing in this DPA limits liability that cannot be limited under Data Protection Law, including a data subject’s rights to compensation. As between the Parties, each Party is liable for the portion of any damage caused by its own breach.

16. Authorised Affiliates

Where the Customer is an organisation, it may accept this DPA on behalf of its Affiliates that are permitted to use the Services and for which the Customer is the controller. In that case each such Affiliate is treated as a controller under this DPA, but the contracting Customer remains the single point of contact: it alone exercises any right or remedy under this DPA on behalf of itself and its Affiliates, in a combined manner rather than separately, and combines any audit requests into a single audit wherever reasonably possible. This allows a single DPA to cover a university’s faculties, institutes and affiliated entities without a separate agreement for each.

17. California (CCPA)

To the extent the CCPA applies to Customer Personal Data, YICCO acts as a “service provider”. YICCO receives Customer Content solely to provide the Services and for no other purpose, and shall not: (a) sell or share Customer Content (as “sell” and “share” are defined in the CCPA); (b) retain, use or disclose it for any purpose other than providing the Services or as otherwise permitted by the CCPA; or (c) combine it with personal information from other sources except as the CCPA permits for a service provider. YICCO certifies that it understands and will comply with these restrictions. This clause supplements, and does not narrow, the rest of this DPA.

18. General and Governing Law

Annex updates. YICCO may update Annexes I–III in accordance with this DPA (and, for Annex III, the notice and objection process in the Sub-processors clause) without re-executing the DPA. The version of each Annex published on this page is the operative version.

Order of precedence. In case of conflict: (1) the SCCs (for transfers they govern); (2) this DPA; (3) the Annexes; (4) the remainder of the Terms.

Signature on request. An organisation that requires a counter-signed copy of this standard DPA may request one from hello@yicco.com. The content is non-negotiable; signature affects execution only.

Governing law and jurisdiction. This DPA is governed by the laws of the Netherlands and the Parties submit to the non-exclusive jurisdiction of the courts of Amsterdam, consistent with the Terms, save where Data Protection Law or the SCCs require otherwise.


Annex I — Processing Description

Version 1.0 · Last updated 1 March 2026

Maintenance note. This Annex describes the processing carried out under the DPA. It is organised by YICCO’s role: Part B sets out the processing for which YICCO is a Processor and which is subject to this DPA. Parts A and C set out processing for which YICCO is an independent Controller — governed by the Privacy Policy, not this DPA — and are shown for transparency and to mark the boundary. Only Part B is subject to the DPA.

Part A. Processing where YICCO acts as Controller — Customer account data

Outside the scope of this DPA. Governed by the YICCO Privacy Policy; shown here for transparency and to mark the boundary. Any restricted transfer of this data relies on the mechanism in the Privacy Policy (EU SCCs Module 1, controller-to-controller, where applicable), not the Module 2 clauses that govern Part B.

Subject matterCreation and administration of the user’s account and the contractual relationship for the Services.
DurationFor the life of the account, plus any retention required by law (e.g. billing records for statutory tax-retention periods).
PurposeRegistration, authentication, access management, billing and payment, service communications, security and fraud prevention.
Categories of personal dataName; email address; job title; username; password / authentication data; institutional or organisational affiliation; billing and transaction data; social-login profile data (where the user chooses social login). Billing data and invoices are stored with the payment provider Paddle (acting as Merchant of Record); payment-card data is handled by the payment providers and not stored by YICCO.
Categories of data subjectsRegistered users (researchers, experts, and — for organisational subscriptions — the organisation’s authorised users and administrators).

Part B. Processing where YICCO acts as Processor — Customer Content

Subject to this DPA. This is the processing the DPA governs. The Customer is the Controller; YICCO is the Processor, acting only on the Customer’s instructions. Restricted transfers are governed by the EU SCCs (Module 2) incorporated in the DPA.

Subject matterProcessing of documents and materials uploaded by the Customer, and generation of communication outputs from them, on the Customer’s instruction.
DurationFor the period necessary to generate the requested outputs and to make them available within the Services; deleted or irreversibly anonymised on a short documented schedule, or earlier on Customer instruction, and on termination per the DPA.
Nature and purposeReceiving uploaded content; transmitting the text of the content and the user’s inputs to AI Provider Sub-processors via their APIs under non-training terms; generating lay summaries, press releases, blog posts, social posts, interview material and similar communication outputs; storing the content and outputs to deliver the Services. Customer Content is processed solely to provide the Services and is never used to train AI models or to build a corpus.
Categories of personal dataThe Services are intended for published scientific and public-facing communication material. Personal data is expected to appear only incidentally within such material — for example: author and co-author names; institutional affiliations; ORCID and similar researcher identifiers; professional contact details (e.g. corresponding-author email); and other personal data that the author has chosen to include in a public publication.

Uploading the following is prohibited by the Terms and must not occur: patient data or health records; research-participant data; interview transcripts; special-category personal data (Article 9 GDPR); and confidential or non-anonymised datasets.
Categories of data subjectsAuthors and co-authors of the uploaded material; individuals incidentally named or identifiable within published material the Customer is entitled to process. (Research participants, patients and similar vulnerable data subjects are out of scope and must not be uploaded.)
Special categoriesNot intended and prohibited by the Terms. No special-category data should be present in Customer Content.

Part C. Processing where YICCO acts as Controller — product analytics and service operation

Outside the scope of this DPA. Governed by the YICCO Privacy Policy; shown here for transparency and to mark the boundary. As with Part A, any restricted transfer relies on the mechanism in the Privacy Policy, not the Module 2 clauses that govern Part B.

Subject matterUnderstanding and improving how the Services are used, and operating and securing them.
DurationRetained per the Privacy Policy; analytics data is pseudonymous and IP addresses are not stored by the analytics tool.
PurposeProduct analytics (navigation and feature usage); service operation, security, diagnostics and fraud prevention; and product-improvement research based on usage metadata and interaction signals — such as whether and where outputs are revised, which sections are most edited and how many revisions occur — not on the textual content of edits, corrections or comments, and not on the substance of Customer Content.
Categories of personal dataPseudonymous usage and behavioural identifiers; device, log and diagnostic data; and — for product-improvement research — records of whether and where users revise outputs (which sections are edited, how many revisions occur), not the textual content of those revisions, processed on an aggregated or pseudonymised basis wherever practicable.
Categories of data subjectsRegistered users of the Services.
The boundary that keeps YICCO a processor. Parts A and C concern data YICCO controls about the user and their use of the Services. Part B concerns the substance of what the user uploads. Product-improvement research and analytics operate on Part C data — usage metadata and interaction signals, such as whether and where an output is revised — and never on the textual content of edits or corrections, nor on the substance of Part B.

Annex II — Technical and Organisational Measures

Version 1.0 · Last updated 1 March 2026

Maintenance note. This Annex describes the technical and organisational measures YICCO has implemented to protect Customer Personal Data (Article 32 GDPR). It may be updated provided the overall level of security is not materially reduced. Items marked [planned] are not yet implemented and are shown as roadmap only.

1. Encryption

  • Customer Content and Customer Personal Data are encrypted in transit using TLS (HTTPS) on all connections between the user, the Services and Sub-processors.
  • Customer Content and Customer Personal Data are encrypted at rest in YICCO’s storage and database layers using industry-standard algorithms (e.g. AES-256).
  • Transmission to AI Provider Sub-processors occurs over encrypted API connections under non-training terms.

2. Access controls

  • Access to systems holding Customer Personal Data is restricted to authorised personnel on a least-privilege, need-to-know basis, controlled through individual named accounts.
  • Administrative and production access requires strong authentication and is not shared.
  • Access rights are reviewed periodically and revoked promptly when no longer required (e.g. on role change or departure).
  • Customer-facing access is segregated per account so that one customer cannot access another customer’s content.

3. Authentication

  • Where account passwords are used, they are stored only as securely hashed and salted values; plain-text passwords are not stored. For users who sign in by email code or social login, no password is set.
  • User sign-in uses passwordless authentication: the user enters their email address and receives a single-use code (or link) by email to complete sign-in. Multi-factor authentication is enforced for YICCO administrative access to production systems. Where stronger user authentication is required, additional factors can be enabled.
  • Where social login is offered, authentication is delegated to the chosen identity provider and tokens are handled securely.

4. Logging and monitoring

  • Security-relevant events and administrative and support access to account data are logged for accountability.
  • Logs are retained for a defined period and protected against unauthorised access and tampering.
  • Systems are monitored for availability and for indicators of compromise; alerts are triaged by authorised staff.

5. Backups and resilience

  • Regular backups of production data are taken to support recovery from failure or incident.
  • Backups are encrypted and access-controlled; restoration procedures exist to recover the Services.
  • Where content is deleted from active systems, residual copies in routine backups are isolated from further processing and removed in the ordinary backup-rotation cycle.

6. Incident response

  • YICCO maintains an incident-response process covering detection, triage, containment, remediation and notification.
  • On a personal data breach affecting Customer Personal Data, YICCO notifies affected customers without undue delay, consistent with the DPA, and assists with their Article 33/34 obligations.
  • Incidents are reviewed after closure to identify and apply corrective measures.

7. Employee confidentiality and training

  • Personnel with access to Customer Personal Data are bound by confidentiality obligations in their contracts.
  • Personnel receive guidance appropriate to their role on data protection and information security and on the prohibition against using Customer Content for any purpose other than delivering the Services.

8. Data-protection by design and by default

  • Customer Content is processed only to deliver the requested output; it is not used to train AI models or to build a corpus, and retention is minimised by default (Article 25 GDPR).
  • The product is designed to discourage uploads of personal or confidential data, including an active, logged upload-confirmation step that restates the user’s warranties at the point of each upload.
  • Customer Content (uploaded papers and generated outputs) and account data are stored in the EU (Frankfurt). Operational communication (support and email) may be transferred outside the EU under an appropriate transfer mechanism (Data Privacy Framework or EU SCCs); this does not affect the EU storage of Customer Content.

9. Vendor and sub-processor management

  • Sub-processors are bound by data-protection and security obligations no less protective than the DPA, including the no-training restriction — in practice through the provider’s own standard data processing agreement or standard processing terms (for established providers such as the AI Providers and hosting), rather than individually negotiated contracts.
  • AI Provider Sub-processors are used via API under configurations that prohibit training on submitted content and apply short, automated deletion windows.
  • A current Sub-processor list is maintained in Annex III, with a change-notification mechanism.

10. AI-provider-specific controls

  • Content is sent to AI Providers only via their APIs under terms that prohibit use of the content for model training or improvement.
  • A data-minimisation principle is applied to API transmissions: account identifiers such as the user’s name, email and institutional affiliation are not included in the content sent to AI Providers.
  • YICCO will not integrate any AI Provider whose standard API configuration permits Customer Content to be used for model training without explicit prior consent.
  • Where an AI Provider offers zero-data-retention (ZDR) configurations or EU-region endpoints, YICCO uses them: ZDR is enabled for routed API traffic so that content is discarded immediately after processing. As providers make further ZDR or EU-region options available, YICCO adopts them.

This Annex is illustrative of the measures in place and is not an exhaustive specification. It is maintained independently of the DPA and should be reviewed against YICCO’s actual implemented controls before publication, and periodically thereafter.


Annex III — Sub-processor List

Version 1.0 · Last updated 1 March 2026 · Published at yicco.com/subprocessors

How to read and maintain this list. This Annex lists the Sub-processors YICCO engages to process Customer Personal Data. It may be updated without changing the DPA. Material additions or replacements are notified at least ten (10) days in advance under the Sub-processors clause. Confirm each vendor’s current processing location and transfer mechanism, and that the relevant DPA is on file, at each compliance review.

Providers that process the substance of Customer Content (the AI text providers and the content-hosting/database provider) are Sub-processors under the DPA. Providers that process only account, billing, support or usage data (payment, analytics, support, email) are listed for transparency; YICCO is controller for that data and those vendors act under the Privacy Policy. AI image providers receive only AI-generated prompts, never Customer Content. The Purpose column marks each accordingly.

VendorPurposeProcessing locationTransfer mechanismWebsite
SupabaseDatabase, authentication and file storage — core platform infrastructure (Customer Content: uploaded papers, generated outputs, account data)EU — Frankfurt (AWS eu-central-1)EU storage — no transfer mechanism required for data at restsupabase.com
VercelApplication hosting and delivery of the ServicesEU edge nodes (US company)DPA in place; EU SCCs where applicablevercel.com
AnthropicPrimary AI text generation. Receives paper text + questionnaire answers; no YICCO account data. No training on submitted content; maximum 30-day retention.United StatesEU SCCs (Module 2) in DPA Addendum (accepted via console)anthropic.com
Google CloudAI text and image generation, and EU-hosted compute for the Services. Receives paper content / image prompts in transit; no training on submitted content.EU regions available; EU-hosted compute in Frankfurt (US company)Google Cloud DPA + EU SCCscloud.google.com
OpenRouterAI routing layer. Paper text in transit only — immediately discarded (ZDR active); metadata only retained for billing.United StatesEU SCCs (Module 2, Irish law) in DPA Addendum (in force by use of service); ZDR as additional technical controlopenrouter.ai
OpenAIAI image generation. Receives AI-generated image prompts only — never paper text or account data.United StatesEU SCCs (Module 2) in DPA Addendum (accepted via account)openai.com
MidjourneyOptional AI image generation. Receives AI-generated image descriptions only — never paper text, questionnaire answers or account data.United StatesToS accepted; no formal DPA available. Mitigated by content type (no Customer Content in the GDPR sense).midjourney.com
PostHog (PostHog Cloud EU)Product analytics — pseudonymous usage events; IP discarded on collection; no paper content captured (controller-side usage metadata, not Customer Content).EU — Frankfurt (AWS eu-central-1)EU storage — no transfer outside EEA. DPA executed (counter-signed).posthog.com
IntercomCustomer support and communication (chat widget, email). Name, email, IP, support chat and email threads. (YICCO is evaluating continued use; some support also runs via Google Workspace.)United States (EU hosting not available at current plan tier)EU-US Data Privacy Framework (primary); EU SCCs (Module 2 / Module 1 for account data, Irish law) as fallback. 20-day sub-processor notice.intercom.com
Google WorkspaceCustomer-facing email (hello@, support@) and Drive documents containing customer data.EU for data-at-rest of covered core services (Business Standard Data Regions policy active); transient processing/indexing/spam-filtering may occur outside EUGoogle Workspace DPA; EU SCCs / DPF for any processing outside EUworkspace.google.com
PaddlePayment processing / Merchant of Record; stores billing data and invoices. Paddle is an independent controller for payment data — YICCO never receives card/bank details.UK / USEU SCCs / adequacy in DPA Addendum (accepted via account)paddle.com
TermlyCookie-consent banner; hosting of published legal documents (consent records).United StatesEU SCCs in DPA (executed, counter-signed)termly.io
LinkedIn APIOAuth publishing integration (where the user chooses to publish). LinkedIn name, profile-picture URL, user ID, temporary OAuth token (not stored after session).United StatesLinkedIn API Terms of Service (no DPA available; ToS is the governing instrument)linkedin.com

Where a Sub-processor is itself a controller for certain processing (e.g. a payment Merchant of Record, or an AI Provider for its own service operation), that processing is governed by that vendor’s own terms and is outside the scope of YICCO’s processing under the DPA. Confirm each vendor’s current processing location, the applicable transfer mechanism, and that an appropriate data-processing agreement is on file, before publishing this Annex.


This DPA and its Annexes are maintained by YICCO B.V. and form part of the YICCO Terms of Service. Prepared in accordance with Article 28 GDPR, with the EU SCCs and UK IDTA for transfers. Questions: hello@yicco.com.