Data Processing Agreement

Under Article 28 of the GDPR, with the Standard Contractual Clauses for transfers

Version 1.0, September 27, 2026.

We sign it on request. Write to legal@wpmaven.ai with your company's legal name, registered address, registration number and a privacy contact, and we send it to you for signature. It applies between YOTAKO S.A. and a customer who signs it.

Related: our subprocessors (Annex III) and our security answers (the detail behind Annex II).

Parties

1. YOTAKO S.A., a public limited company (société anonyme) under Luxembourg law, registered with the Luxembourg Trade and Companies Register under number B 205443, VAT LU 29326106, with its registered office at 4 rue Samuel Beckett, Luxmill building, L-4371 Belvaux, Sanem, Grand-Duchy of Luxembourg, operating the WPMaven service ("WPMaven", the "Processor"); and

2. The customer named on the signature page ("Customer").

This Data Processing Agreement ("DPA") forms part of the WPMaven Terms of Service accepted by Customer, or of another written agreement between the parties for the Service (the "Agreement").

1. Definitions

1.1 "GDPR" means Regulation (EU) 2016/679. "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing" and "Supervisory Authority" have the meanings given in the GDPR.

1.2 "Data Protection Law" means the GDPR, the Luxembourg Law of 1 August 2018 on the organization of the National Data Protection Commission and the general data protection framework, Directive 2002/58/EC as implemented in the relevant Member State, and, where they apply to the Processing, the UK GDPR and UK Data Protection Act 2018 and the Swiss Federal Act on Data Protection.

1.3 "Customer Personal Data" means Personal Data that WPMaven Processes on behalf of Customer in providing the Service, as described in Annex I.

1.4 "Service" means the WPMaven service described in the Agreement: building and hosting WordPress sites, the AI team that prepares work and, after Customer's approval, publishes it to Customer's sites and connected channels, the weekly report, email sending for Customer's sites, and related features.

1.5 "Sub-processor" means any processor engaged by WPMaven to Process Customer Personal Data.

1.6 "SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021. "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018 (version B1.0, in force 21 March 2022).

1.7 "Client" means, where Customer is an agency or a hosting company, a business for which Customer uses the Service.

2. Roles and scope

2.1 Customer as controller. Where Customer uses the Service for its own business, Customer is the Controller and WPMaven is the Processor of Customer Personal Data.

2.2 Customer as processor. Where Customer uses the Service for its Clients (for example on the White label plan), Customer acts as a processor on behalf of each Client, and WPMaven acts as Customer's Sub-processor. Customer warrants that its instructions, including its engagement of WPMaven, are authorized by each Client, and that its contract with each Client allows it. Customer remains WPMaven's only point of contact, and WPMaven will not contact Clients except as Customer instructs.

2.3 Processing for WPMaven's own purposes. WPMaven acts as an independent Controller, not as Processor, for the following, which are governed by the WPMaven Privacy Policy and not by this DPA: (a) the account, billing and tax records of Customer and its users, including records WPMaven must keep under Luxembourg law; (b) security, fraud and abuse prevention (for example the one-per-customer check on the $1 first week, rate limits and bot checks), and compliance with law; (c) service analytics about how Customer's users use the WPMaven dashboard and website; and (d) the business descriptions and prompts that Customer's users type into WPMaven, which WPMaven keeps to improve how the Service understands requests, as described in section 6.1 of the Privacy Policy. Customer may ask WPMaven at any time to erase them.

2.4 Customer's own responsibilities. Customer is responsible for the lawfulness of the Customer Personal Data it provides or has the Service collect, for giving Data Subjects the information required by Articles 13 and 14 GDPR (including on its own sites' privacy notices and cookie banners), for obtaining any consents (for example for marketing emails sent to its contacts), and for the content it approves for publication.

3. Instructions

3.1 WPMaven Processes Customer Personal Data only on Customer's documented instructions, including with regard to transfers to third countries, unless Union or Member State law requires otherwise, in which case WPMaven will inform Customer of that legal requirement before Processing unless that law prohibits it (Article 28(3)(a) GDPR).

3.2 Customer's instructions are this DPA, the Agreement, and the choices Customer makes in the Service, including the approvals Customer gives in the dashboard, by email or on WhatsApp, which after the first build of a site are required before the AI team changes that site or publishes a page or a post, and the channels Customer connects. WPMaven's WordPress plugin and WordPress's own security releases update automatically on the sites WPMaven hosts.

3.3 WPMaven will tell Customer immediately if, in its opinion, an instruction infringes Data Protection Law (Article 28(3), last subparagraph).

3.4 AI models. WPMaven does not use Customer Personal Data to train AI models.

4. Confidentiality of personnel

4.1 WPMaven ensures that persons authorized to Process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Article 28(3)(b)).

4.2 WPMaven staff open a Customer account only from staff accounts. Each staff session in a Customer account lasts at most 60 minutes, and every change made through WPMaven during it is recorded in an audit log under the staff member's own identity. If staff open the WordPress admin of a Customer site, they use their own named WordPress administrator account, which loses its access 12 hours after they last used a sign-in link, unless it is the only administrator the site has; changes made inside WordPress are not recorded in WPMaven's audit log. Some administrative changes staff can make outside such a session are not yet recorded.

5. Security

5.1 WPMaven implements the technical and organizational measures in Annex II, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing, as well as the risks for Data Subjects (Article 28(3)(c) and Article 32 GDPR).

5.2 WPMaven may update Annex II, provided that the overall level of protection is not reduced.

6. Sub-processors

6.1 General authorization. Customer gives WPMaven general written authorization to engage Sub-processors. The Sub-processors engaged at the date of this DPA are listed in Annex III.

6.2 Changes. WPMaven will inform Customer of any intended addition or replacement of a Sub-processor at least 30 days in advance, by email to the privacy contact Customer gives when signing and by updating its subprocessors page, giving Customer the opportunity to object (Article 28(2)).

6.3 Objection. Customer may object on reasonable data protection grounds within 15 days of the notice. The parties will discuss the objection in good faith. If WPMaven cannot offer a reasonable alternative, Customer may terminate the affected part of the Service with effect from the date the new Sub-processor would start, and WPMaven will refund the prepaid fees for the remaining term of the terminated part. Refunds are confirmed and paid by WPMaven's team; they are never automatic.

6.4 Flow-down. WPMaven engages each Sub-processor under a written contract that imposes data protection obligations providing sufficient guarantees of appropriate technical and organizational measures (Article 28(4)). WPMaven remains fully liable to Customer for the performance of each Sub-processor's obligations.

6.5 Emergency replacement. If a Sub-processor must be replaced urgently for security or continuity reasons, WPMaven may do so at once and will notify Customer as soon as possible, with the objection right in 6.3 applying from the notice.

7. International transfers

7.1 WPMaven is established in Luxembourg. Customer Personal Data is stored in the European Union (Belgium) as described in Annex I, except where Annex III states that a Sub-processor Processes it outside the European Economic Area.

7.2 WPMaven transfers Customer Personal Data to a country outside the EEA only (a) to a country covered by an adequacy decision, including to a recipient certified under the EU-U.S. Data Privacy Framework (Commission adequacy decision of 10 July 2023), or (b) under the SCCs as incorporated in the Sub-processor's data processing terms, in the module that fits the parties' roles (normally Module 3, processor to processor), together with the supplementary measures that a transfer impact assessment requires. Annex III gives the safeguard for each Sub-processor.

7.3 Customer outside the EEA. Where Customer is located in a country that has no adequacy decision, the parties agree that Module 4 of the SCCs (processor to controller) applies to the return and disclosure of Customer Personal Data by WPMaven to Customer, and is incorporated by reference, with the following choices: Clause 7 (docking clause) applies; Clause 17: the law of the Grand-Duchy of Luxembourg; Clause 18: the courts of Luxembourg.

7.4 UK and Switzerland. For transfers subject to UK data protection law, the UK Addendum applies, with Table 1 completed from Annex I and Table 4 set to neither party. For transfers subject to the Swiss Federal Act on Data Protection, the SCCs apply with the adaptations required by the Swiss Federal Data Protection and Information Commissioner (references to the GDPR read as references to the Swiss Act, the Commissioner as competent supervisory authority for such transfers, and "Member State" read to include Switzerland for the purposes of Clause 18(c)).

7.5 Transfer impact assessments. At the date of this version, WPMaven has not completed transfer impact assessments for the non-EEA Sub-processors in Annex III. WPMaven will make them available to Customer on request once they are completed.

8. Assistance

8.1 Data Subject requests. Taking into account the nature of the Processing, WPMaven assists Customer by appropriate technical and organizational measures, insofar as possible, in responding to requests from Data Subjects exercising their rights (Article 28(3)(e)). The Service lets Customer export each site from its WordPress admin at any time, edit or delete content, contacts and orders in its WordPress site, and disconnect any social channel (which deletes the stored tokens at once); Customer may also ask WPMaven to delete its account. WPMaven forwards to Customer, without undue delay, any request it receives directly from a Data Subject about Customer Personal Data, and does not answer it except on Customer's instruction.

8.2 Security, breach and impact assessments. WPMaven assists Customer in meeting its obligations under Articles 32 to 36 GDPR, taking into account the nature of Processing and the information available to WPMaven (Article 28(3)(f)), including by providing the information in Annexes I to III and its security questionnaire answers.

8.3 Assistance beyond what the Service provides as standard may be charged at a rate agreed in advance.

9. Personal Data Breach

9.1 WPMaven notifies Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data (Article 33(2)).

9.2 The notice contains, to the extent then known, the information listed in Article 33(3): the nature of the breach including the categories and approximate number of Data Subjects and records concerned; the name and contact details of WPMaven's contact point; the likely consequences; and the measures taken or proposed. Information not available at first is provided in phases without undue further delay.

9.3 WPMaven takes reasonable steps to contain, investigate and mitigate the breach, and cooperates with Customer. Notifying a Supervisory Authority or Data Subjects remains Customer's decision, except where WPMaven must notify on its own account as Controller under 2.3.

10. Return and deletion

10.1 During the term, Customer can export each site at any time in standard WordPress format, from the site's WordPress admin.

10.2 After the end of the Service for a site or for the account, WPMaven keeps Customer Personal Data for 90 days so that Customer can come back or retrieve its data, then deletes it, unless Union or Member State law requires storage (Article 28(3)(g)). Customer may ask in writing for earlier deletion, including deletion of its whole account.

10.3 WPMaven deletes backups containing Customer Personal Data together with the rest of Customer Personal Data under 10.2. Annex II, section 6, describes how backups are kept today.

10.4 WPMaven keeps the billing and tax records it must keep as Controller under 2.3(a) for the period the law requires.

11. Audits and information

11.1 WPMaven makes available to Customer all information necessary to demonstrate compliance with Article 28 GDPR (Article 28(3)(h)), first by answering Customer's written security questionnaire and by providing this DPA with its Annexes.

11.2 Where that information is not sufficient to demonstrate compliance, or where a Supervisory Authority requires it, Customer (or an independent auditor bound by confidentiality and not a competitor of WPMaven) may carry out an audit, no more than once in any 12-month period except after a Personal Data Breach, on at least 30 days' written notice, during business hours, without access to other customers' data, and at Customer's cost. Audits of Sub-processors are satisfied by the reports and certifications those Sub-processors make available.

11.3 WPMaven holds no SOC 2 report, ISO 27001 certificate or PCI certification at the date of this DPA.

12. Records

WPMaven shall keep a record of the Processing activities carried out on behalf of Customer as required by Article 30(2) GDPR.

13. Liability and precedence

13.1 Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement.

13.2 In case of conflict, the SCCs (where they apply) prevail over this DPA, and this DPA prevails over the Agreement as regards the Processing of Customer Personal Data.

14. Term, law and jurisdiction

14.1 This DPA runs for as long as WPMaven Processes Customer Personal Data.

14.2 This DPA is governed by the law of the Grand-Duchy of Luxembourg. The courts of Luxembourg-City have exclusive jurisdiction, without prejudice to Clause 18 of the SCCs where they apply.

Signatures

Signed for YOTAKO S.A.: name, title, date.

Signed for Customer: legal name, registered address, registration number, name and title of the signatory, privacy contact, date.

Annex I: Description of the Processing

A. List of parties

Data exporter: Customer, as set out on the signature page, with the privacy contact given there. Activities: use of the WPMaven Service. Role: Controller (2.1) or processor on behalf of its Clients (2.2).

Data importer: YOTAKO S.A. (WPMaven), address above. Data protection contacts: privacy@wpmaven.ai and dpo@wpmaven.ai. Role: Processor (or Sub-processor).

B. Description

Categories of Data Subjects

  1. Customer's own users: the people who sign in to the WPMaven account.
  2. Visitors to Customer's websites.
  3. Customer's own customers and prospects: buyers, people who book, people who submit forms, subscribers and other contacts on Customer's sites.
  4. People who interact with Customer's connected social accounts: people who comment on Customer's posts or send messages to Customer's Facebook Page or Instagram account.
  5. People who appear in material Customer provides or approves: photos, videos, testimonials, team pages.
  6. Where Customer registers a domain through WPMaven: the registrant.

Categories of Personal Data

  1. Account users: name, email address, phone number linked for WhatsApp, sign-in records, IP address, messages exchanged with the AI team (in the dashboard, by email and on WhatsApp, including voice notes and images sent on WhatsApp), approvals given.
  2. Site visitors: pseudonymous visitor identifiers (hashed with a key that changes every day), pages viewed, referrer, campaign parameters, approximate location worked out on WPMaven's servers from the IP address, device and browser type, performance measurements, order events.
  3. Customer's customers and contacts: what Customer's WordPress site holds, for example names, email addresses, postal addresses, phone numbers, orders, bookings and form submissions, and the content of the emails the site sends to them.
  4. Social interactions: public names or handles and IDs provided by the network, comment text, direct message text, engagement statistics.
  5. Images and video of people provided by Customer.
  6. Domain registrant details: name, organization, postal address, email address, phone number.

Special categories of data (Article 9 GDPR). The Service is not designed to Process special categories of Personal Data. Customer's own content, descriptions or site data may contain them (for example a clinic's bookings). Customer should not use the Service for health records or other special-category data unless agreed in writing. Restrictions applied: approval before publication once a site is first built; encryption at rest; access limited to staff accounts.

Frequency of the transfer: continuous, for the duration of the Service.

Nature of the Processing: hosting and backing up WordPress sites and their databases; generating text, images, voice-over and video from Customer's instructions and materials; publishing approved work to Customer's sites and to the social networks Customer connects; reading statistics, comments and messages from connected channels to report and draft replies for approval; sending email on behalf of Customer's sites; forwarding email sent to Customer's professional addresses to Customer's inbox; measuring site visits; registering domains on Customer's request; support.

Purpose: providing the Service to Customer under the Agreement.

Duration: the term of the Agreement plus the 90 days in section 10, then deletion.

Transfers to Sub-processors: as listed in Annex III, for the same nature, purpose and duration.

Location: WPMaven's application, database, hosted sites and backups run in the European Union (Belgium). AI processing runs in the United States. Other locations are given in Annex III.

C. Competent Supervisory Authority

Commission Nationale pour la Protection des Données (CNPD), Luxembourg.

Annex II: Technical and organizational measures

Every measure below is in place at the date of this version. Where a measure is missing or partial, this Annex says so. Each point is answered in more detail in our security questionnaire answers (109 questions in our own words, covering every domain of the CSA CAIQ v4: 29 Yes, 43 Partial, 37 No).

1. Encryption

2. Access control for Customer users

3. Access control for WPMaven staff and systems

4. Isolation of hosted sites

5. Change management and testing

6. Backups and recovery

7. Deletion

8. Availability

9. Approval before publication

10. Data minimization in analytics

11. Logging and monitoring

12. Organization

Annex III: Sub-processors

The Sub-processors engaged at the date of this version. The current list is kept on our subprocessors page; changes are notified under section 6.2.

CompanyWhat it does for WPMavenPersonal data it processesWhereTransfer safeguard
Google Cloud Platform Runs the WPMaven application and its database, the websites we host, file storage, website backups, secrets, operational logs, and the analytics tool we operate ourselves. Everything stored in WPMaven, including your websites' databases (your customers, orders and form entries), your files and your backups. European Union (Belgium). Operational logs are kept in the provider's logging service, which is not tied to a region. Data stored in the EU. Any access from outside the EU is covered by the Standard Contractual Clauses in Google Cloud's data processing terms.
Google (Gemini) AI models that write text, create images and voice-overs, make premium videos, read the numbers from your connected channels, and search the web for research. What you and your team write, as written; your conversations with your team, including voice notes and photos you send on WhatsApp; the data from your connected channels that your team works with; your website's content and images. United States, and other countries where Google operates. Standard Contractual Clauses, as our Privacy Policy states.
Amazon Web Services (Amazon SES) Delivers the emails WPMaven sends you (sign-in codes, approvals, reports, billing notices) and the emails your hosted website sends (order confirmations, password resets, form notifications, booking and cart emails), and reports bounces back to us. Recipient names and email addresses, including your own customers', and the content of each email. United States (N. Virginia). Standard Contractual Clauses in AWS's data processing terms.
Cloudflare The edge network in front of every website we host: delivers pages, absorbs attacks and routes your domain. Also manages DNS for domains connected through WPMaven, forwards email sent to your professional addresses to your inbox, serves videos and images from our media address, and runs the bot check when you start building a site. Your visitors' IP addresses and requests, email sent to your professional addresses and the inbox it goes to, and the signals the bot check reads. Worldwide network, including outside the EU. Standard Contractual Clauses in Cloudflare's data processing terms.
Stripe Payments: checkout, subscriptions, invoices, tax calculation and the billing portal. Stripe also acts on its own account for purposes such as fraud prevention and financial regulation, under its own privacy policy. Your name, email, billing address, tax ID, payment details and invoices. We never see your full card number. Worldwide. Standard Contractual Clauses in Stripe's data processing terms.
Meta (WhatsApp Business Platform) Carries your conversation with your team on WhatsApp: approvals, weekly reports, replies, voice notes and photos. Your phone number and WhatsApp name, and the messages, voice notes and photos you exchange with your team, which can quote your customers' comments or messages. Worldwide (Meta's data centers). Standard Contractual Clauses in Meta's WhatsApp Business data processing terms.
fal (Features & Labels, Inc.) Turns still images into short video clips for the videos your team makes. The images used in a clip (your products and premises, and people if your photos show them) and the instructions for each clip. Its terms let it use de-identified data to improve its services. United States, and other countries where it operates. Standard Contractual Clauses (Module 2) in fal's data processing addendum.
Spaceship Registers, renews and transfers the domains you buy through WPMaven. The registrant details a domain registration requires: name, organization, postal address, email and phone. United States. Not yet confirmed.
Zoho (Zoho Mail) Hosts our email: the mailboxes at wpmaven.ai (support, privacy, legal and the others), which also receive the messages sent through the contact form on this website, and our staff mailboxes, which receive operational alerts. The emails you send us and anything in them; staff alerts, which can include a customer's email address and the details of a task that failed. European Union (Netherlands and Ireland) for wpmaven.ai addresses; United States for staff mailboxes. EU storage for wpmaven.ai addresses; Standard Contractual Clauses in Zoho's data processing terms for staff mailboxes.
Crisp The live chat with our team. On wpmaven.ai it loads only after you accept cookies. In your dashboard and while you build your business, it loads only when you open the chat, and on your later visits once you have used it, so our replies reach you. The messages you send in the chat and the details you give in them, and your browser information. When you are signed in, also your name, email address, account and plan, so we know who we are talking to. European Union (Netherlands). Data stored in the EU.

The social networks Customer connects receive data at Customer's direction and are not Sub-processors.