# Data Processing Agreement

_Effective 1 September 2026. Last updated 1 September 2026._

This Data Processing Agreement ("DPA") forms part of, and is incorporated by
reference into, the [Terms of Service](/terms/) or the Master Services
Agreement between **Yin Yang, Inc.**, a Delaware corporation trading as Elaichi
("Elaichi", "Processor"), and the customer that accepts them ("Customer",
"Controller"). It applies where Elaichi processes Personal Data on Customer's
behalf.

No signature is required: this DPA takes effect when Customer accepts the Terms
of Service or executes an Order Form. A countersigned copy is available on
request from **dpa@elaichi.ai**.

## 1. Definitions

Terms not defined here take their meaning from the GDPR. **"Data Protection
Law"** means all applicable privacy and data protection law, including the
GDPR, UK GDPR, the Swiss FADP, and US state privacy laws including the CCPA.
**"Customer Personal Data"** means Personal Data within Customer Data as
defined in the Terms. **"SCCs"** means the Standard Contractual Clauses annexed
to European Commission Implementing Decision (EU) 2021/914.

## 2. Roles and scope

Customer is the Controller and Elaichi is the Processor in respect of Customer
Personal Data. Where Customer is itself a processor for a third-party
controller, Elaichi is a sub-processor and this DPA applies accordingly.

Elaichi is a Controller only in respect of account, billing, support, and
website data, as described in the [Privacy Policy](/privacy/). That processing
is outside the scope of this DPA.

Customer is responsible for the lawfulness of the Personal Data it makes
reachable through the Service, for having a valid legal basis, and for issuing
required notices to data subjects. **Elaichi has no visibility into, and
exercises no control over, which third-party systems Customer connects or what
Personal Data those systems contain.**

## 3. Processing instructions

Elaichi will process Customer Personal Data only on Customer's documented
instructions, including for international transfers, unless required otherwise
by law — in which case Elaichi will inform Customer before processing unless
that law prohibits it on important grounds of public interest.

The Terms, this DPA, Customer's configuration of the Service, and Customer's
use of the Service through its interfaces together constitute Customer's
complete documented instructions. The subject matter, duration, nature,
purpose, categories of data, and categories of data subjects are set out in
**Annex I**.

Elaichi will inform Customer if, in its opinion, an instruction infringes Data
Protection Law.

**Elaichi does not train, fine-tune, or otherwise improve any model on Customer
Personal Data, does not log prompts or completions, and does not sell or share
Customer Personal Data.**

## 4. Confidentiality

Elaichi ensures that personnel authorized to process Customer Personal Data are
bound by an appropriate obligation of confidentiality, are subject to
role-based access limited to what their function requires, and receive security
and privacy training.

## 5. Security

Elaichi implements the technical and organisational measures set out in
**Annex II**, taking into account the state of the art, implementation cost,
and the nature, scope, context, and purposes of processing, as well as the risk
to data subjects.

Customer is responsible for its own configuration of the Service — including
roles, restrictions, toolbox scope, connection ownership, and the choice of
which systems to connect — and for assessing whether the measures in Annex II
meet its requirements.

## 6. Sub-processors

Customer grants Elaichi **general written authorisation** to engage
sub-processors. The current list is published at
**[/subprocessors/](/subprocessors/)** and in our Trust Center at
**[trust.elaichi.ai](https://trust.elaichi.ai)**, with the sub-processors as at the effective date
listed in **Annex III**.

Elaichi will give **at least 30 days' notice** before adding or replacing a
sub-processor. Customers may subscribe to notifications in the Trust Center at
**[trust.elaichi.ai](https://trust.elaichi.ai)**.
Customer may object on reasonable data protection grounds within that period,
in which case the parties will discuss in good faith. If the objection is not
resolved, **Customer may terminate the affected Service without penalty**, with
a pro-rata refund of prepaid fees for the unused remainder of the term.

Elaichi imposes on each sub-processor data protection obligations no less
protective than those in this DPA, and **remains fully liable to Customer for
each sub-processor's performance**.

## 7. International transfers

Elaichi is not certified under the EU–US Data Privacy Framework. Where
processing involves a transfer of Customer Personal Data out of the EEA, the
United Kingdom, or Switzerland to a country without an adequacy decision, the
following apply and are incorporated by reference:

- **EEA** — the SCCs. **Module Two (Controller to Processor)** applies where
  Customer is a controller; **Module Three (Processor to Processor)** applies
  where Customer is itself a processor, and to onward transfers by Elaichi to
  its sub-processors.
- **United Kingdom** — the SCCs as amended by the **International Data Transfer
  Addendum** issued by the UK Information Commissioner under s.119A of the Data
  Protection Act 2018.
- **Switzerland** — the SCCs, with references to the GDPR read as references to
  the FADP, the competent authority read as the FDPIC, and "Member State" read
  so as not to deprive data subjects in Switzerland of the right to sue in
  their place of habitual residence. The SCCs also protect the data of legal
  entities until the revised FADP provisions cease to apply.

For the SCCs: the optional docking clause (Clause 7) does not apply; **Option 2
of Clause 9(a)** applies with the 30-day notice period in section 6 above; the
Clause 11 independent dispute resolution option does not apply; Clause 17 is
governed by the law of Ireland; and Clause 18(b) designates the courts of
Ireland. Annexes I, II, and III below complete the corresponding SCC annexes.
Where this DPA conflicts with the SCCs, **the SCCs prevail**.

## 8. Assistance with data subject requests

Taking into account the nature of the processing, Elaichi will assist Customer
by appropriate technical and organisational measures, insofar as possible, in
fulfilling Customer's obligations to respond to data subject requests.

The Service gives Customer direct, self-service access to Customer Personal
Data through its interfaces and API, which is ordinarily sufficient for
Customer to respond without Elaichi's involvement. **Where a data subject
contacts Elaichi directly, Elaichi will not respond substantively but will
promptly refer the request to Customer**, unless legally required to do so.

## 9. Personal data breach

Elaichi will notify Customer **without undue delay and in any event within 72
hours** of becoming aware of a Personal Data Breach affecting Customer Personal
Data. The notification will describe the nature of the breach, the categories
and approximate number of data subjects and records concerned, the likely
consequences, the measures taken or proposed, and a contact point — to the
extent known, supplemented as further information becomes available.

Elaichi will assist Customer in meeting its own notification obligations under
Articles 33 and 34 GDPR. **Notification is not an acknowledgement of fault or
liability.**

## 10. Data protection impact assessments

Elaichi will provide reasonable assistance with data protection impact
assessments and prior consultations with supervisory authorities under Articles
35 and 36 GDPR, taking into account the nature of processing and the
information available to Elaichi. Elaichi maintains a transfer impact
assessment available on request.

## 11. Deletion and return

On termination, Customer may retrieve Customer Personal Data for the duration of
the recovery period described in the [Terms of Service](/terms/), by **CSV or
NDJSON export** from any exportable table, through the cursor-paginated API, or
by continuous forwarding to a Customer-configured destination.

Deleting an organization revokes all access immediately and begins a **30-day
recovery period**, after which all Customer Personal Data — including audit
history and usage counters — is permanently deleted. **Customer may instead
elect immediate permanent deletion, which is irreversible.**

Elaichi will not retain Customer Personal Data after deletion except where
required by law, in which case it will continue to protect it and process it
only to the extent and for the period required.

## 12. Audits and information

Elaichi will make available to Customer the information reasonably necessary to
demonstrate compliance with this DPA, and will allow for and contribute to
audits, in the following manner:

1. by making available its current certifications, audit reports, and control
   posture through the **[Elaichi Trust Center](https://trust.elaichi.ai)**,
   including documents released under NDA on request; and
2. by responding to a reasonable security questionnaire, no more than **once
   per twelve months** unless required by a supervisory authority or following
   a Personal Data Breach.

The parties agree that (1) and (2) ordinarily satisfy Customer's audit rights
under Article 28(3)(h) GDPR and Clause 8.9 of the SCCs. **On-site audits are
not offered.** Where Data Protection Law entitles Customer to an on-site audit
that cannot be satisfied by the above, the parties will agree its scope,
timing, and duration in advance, it will occur no more than once per year
during business hours without unreasonably disrupting operations, it will be
subject to confidentiality obligations, and **Customer will bear its cost**.

## 13. US state privacy law

This section applies where Elaichi processes Personal Information subject to
the CCPA or a comparable US state privacy law. Elaichi acts as a **service
provider** (or **processor**, under the equivalent state term) and not as a
third party. Terms in this section take their CCPA meanings.

Elaichi **certifies that it understands the restrictions in this section and
will comply with them**. Specifically, Elaichi will not:

1. **retain, use, or disclose** Personal Information for any purpose other than
   the specific purpose of performing the Services specified in the Terms, or
   as otherwise permitted by the CCPA;
2. **sell or share** Personal Information as those terms are defined by the
   CCPA;
3. retain, use, or disclose Personal Information **outside the direct business
   relationship** between Elaichi and Customer; or
4. **combine** Personal Information received from or on behalf of Customer with
   Personal Information received from or on behalf of any other person, or
   collected from its own interactions with a consumer, except as expressly
   permitted by the CCPA.

Elaichi will notify Customer if it determines it can no longer meet these
obligations. Customer may take reasonable and appropriate steps to stop and
remediate unauthorised use. Elaichi will assist Customer in responding to
verifiable consumer requests as described in section 8.

**Elaichi does not sell or share Personal Information and does not use it for
cross-context behavioral advertising.** Any aggregated or de-identified data
generated under the Terms will be maintained and used in de-identified form,
and Elaichi will not attempt to re-identify it.

## 14. Liability

Each party's liability under this DPA is subject to the limitations and
exclusions in the Terms of Service or the Master Services Agreement, except
where Data Protection Law prohibits such limitation. Nothing in this DPA limits
a data subject's rights under Data Protection Law or the SCCs.

## 15. General

This DPA supersedes any conflicting data protection terms elsewhere. **On any
question of data protection or the processing of personal data**, the order of
precedence is: the SCCs, this DPA, the Master Services Agreement, the Order
Form, then the Terms of Service. On all other questions, the order in section 2
of the [Terms of Service](/terms/) applies.

This DPA takes effect on the effective date above and continues until Elaichi
ceases to process Customer Personal Data. Elaichi may update it to reflect
changes in law or to its sub-processors or security measures, provided the
updated version is no less protective; material changes take effect on **30
days' notice**.

Contact: **dpa@elaichi.ai** · Data protection contact: **dpo@elaichi.ai**

---

# Annex I — Description of processing

## A. List of parties

**Data exporter.** The Customer identified in the Order Form or account
records. Role: Controller (or Processor, where Module Three applies). Contact:
the administrator email addresses on the account. Activities: use of the
Elaichi MCP control plane as described in the Terms.

**Data importer.** Yin Yang, Inc. (dba Elaichi), 9450 SW Gemini Dr, PMB 69868,
Beaverton, Oregon 97008‑7105, USA. Role: Processor. Contact:
dpo@elaichi.ai. Activities: provision of the Elaichi MCP control plane.

**EU representative (Art. 27 GDPR).** Rickert Rechtsanwaltsgesellschaft mbH –
YIN YANG, INC., Colmantstraße 15, 53115 Bonn, Germany —
art-27-rep-yinyang@rickert.law

**UK representative (Art. 27 UK GDPR).** Rickert Services Ltd UK – YIN YANG,
INC., PO Box 1487, Peterborough PE1 9XX, United Kingdom —
art-27-rep-yinyang@rickert-services.uk

## B. Description of transfer

**Categories of data subjects.** Customer's personnel and authorised users of
the Service; and any data subject whose Personal Data is present in the
third-party systems Customer elects to connect — which may include Customer's
own employees, contractors, customers, prospects, suppliers, and
correspondents. **Elaichi does not determine or control these categories.**

**Categories of personal data.**

- *Account data*: name, work email address, organization, role, authentication
  and identity provider metadata.
- *Connection metadata*: which connectors and accounts are connected, ownership
  scope, and operational status.
- *Credentials*: third-party authentication credentials supplied by Customer,
  held encrypted in the credential vault and never exposed to end users or to
  any AI model.
- *Tool-call metadata*: tool name, connector, connection identifier, status,
  duration, error code, and the record identifier returned by the third-party
  system. **Request arguments and response payloads are not persisted.**
- *Audit records*: privileged actions with acting user identifier and
  timestamp.
- *Data in transit through connectors*: any Personal Data contained in the
  third-party systems Customer connects, processed transiently to fulfil a tool
  call and not persisted by Elaichi.

**Sensitive data.** The Terms prohibit Customer from submitting protected
health information, payment card data, biometric identifiers, government
identification numbers, financial account credentials, and Article 9 special
category data, except where an Order Form expressly permits it. Elaichi does
not knowingly process sensitive data outside such an agreement.

**Frequency.** Continuous, for the duration of the subscription.

**Nature and purpose.** Hosting, storage, transmission, access control, and
execution of tool calls, in order to provide the Elaichi MCP control plane.

**Retention.** Audit and tool-call metadata: 90 days. Organization data: for
the subscription term, then a 30-day recovery period, then permanent deletion —
or immediate permanent deletion at Customer's election.

**Onward transfers.** To the sub-processors in Annex III, for the same duration
and purposes.

## C. Competent supervisory authority

The supervisory authority of the Member State in which the data exporter is
established. Where the data exporter is not established in the EEA but has
appointed a representative under Article 27, the supervisory authority of the
Member State in which that representative is established. For transfers subject
to the UK Addendum, the UK Information Commissioner's Office. For transfers
subject to Swiss law, the Federal Data Protection and Information Commissioner.

---

# Annex II — Technical and organisational measures

**Encryption.** Third-party credentials are held in a dedicated credential
vault encrypted at rest with **AES‑256‑GCM**. Eligible plans may wrap
credential encryption with Customer-managed AWS KMS keys held in Customer's own
AWS account (BYOK). All data in transit is encrypted with TLS.

**Pseudonymisation and minimisation.** Tool-call logging is metadata-only:
request arguments and response payloads are never written to the log. Prompts
and completions are not logged. The control plane stores credential
*configurations* — the shape of what a connector requires — not secrets.

**Access control.** Role-based access control with system and custom roles;
connector and tool restrictions enforced at connect, advertise, and execute
time with user-over-role-over-organization precedence; enforced SSO via SAML or
OIDC; SCIM provisioning and deprovisioning; group-to-role mapping; and TOTP
multi-factor authentication with single-use recovery codes.

**Token handling.** Session, API, MCP, and invite tokens are stored as keyed
hashes and displayed exactly once at creation. Endpoints can be rotated, which
revokes the prior token before issuing a replacement. Rate limits apply on both
the control and data planes.

**Credential isolation.** Credentials are resolved server-side at execution
time and are never exposed to end users or to any AI model. Delegated
connections allow a shared toolbox to execute against the sharer's connection
without disclosing the underlying credential.

**Logging and monitoring.** An append-only audit log records every privileged
action, including individual MCP tool calls with tool, connection, status, and
duration, and can be forwarded continuously to a Customer-configured
destination.

**Resilience and recovery.** Infrastructure is operated on Cloudflare with
point-in-time recovery of 30 days on D1 and Durable Objects.

**Data location.** Organizations select a region at creation, which cannot be
changed afterwards. For US and EU, the organization's Durable Object is pinned
to the corresponding Cloudflare jurisdiction. **APAC is a placement hint and
not a residency guarantee.** The global index of organization and user records,
the session store, and stored logos are not region-pinned. **The audit-log
store is a single European Union instance serving all regions.**

**Offboarding.** Removal of a member runs a preflight requiring resolution of
personal connections on which shared toolboxes depend, so shared workflows do
not silently break and orphaned access does not persist.

**Governance.** Security and privacy training for personnel; confidentiality
obligations; role-scoped internal access; vulnerability intake under a
published disclosure policy; and independent assessment as published in the
Trust Center at https://trust.elaichi.ai.

**Measures for onward transfers.** Sub-processors are bound by written terms no
less protective than this DPA, and transfers rely on the SCCs as set out in
section 7.

---

# Annex III — Sub-processors

As at the effective date. The authoritative current list is published at
**[/subprocessors/](/subprocessors/)** and mirrored at
**[trust.elaichi.ai](https://trust.elaichi.ai)**.

| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting, compute, storage, queues, email delivery, rate limiting, and access control | Global, with EU/US jurisdiction pinning for organization data |
| Stripe, Inc. | Subscription billing and payment processing | USA |
| OVH SAS | Hosting of the self-hosted audit-log store | European Union |
| Yin Yang Technologies Private Limited | Engineering, operations, and support personnel; wholly owned affiliate of Yin Yang, Inc. | India |

The following are **not** sub-processors of Elaichi. They are services Customer
elects to connect and configure under its own accounts and agreements: AI model
providers accessed with Customer's own API key, log-forwarding destinations,
social login providers, Customer's identity provider, AWS KMS for BYOK, and
every third-party SaaS product Customer connects through a connector.
