Data Processing Agreement
Effective 1 September 2026. Last updated 1 September 2026.
This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Terms of Service or the Master Services Agreement between Yin Yang, Inc., a Delaware corporation trading as Elaichi ("Elaichi", "Processor"), and the customer that accepts them ("Customer", "Controller"). It applies where Elaichi processes Personal Data on Customer's behalf.
No signature is required: this DPA takes effect when Customer accepts the Terms of Service or executes an Order Form. A countersigned copy is available on request from [email protected].
1. Definitions
Terms not defined here take their meaning from the GDPR. "Data Protection Law" means all applicable privacy and data protection law, including the GDPR, UK GDPR, the Swiss FADP, and US state privacy laws including the CCPA. "Customer Personal Data" means Personal Data within Customer Data as defined in the Terms. "SCCs" means the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914.
2. Roles and scope
Customer is the Controller and Elaichi is the Processor in respect of Customer Personal Data. Where Customer is itself a processor for a third-party controller, Elaichi is a sub-processor and this DPA applies accordingly.
Elaichi is a Controller only in respect of account, billing, support, and website data, as described in the Privacy Policy. That processing is outside the scope of this DPA.
Customer is responsible for the lawfulness of the Personal Data it makes reachable through the Service, for having a valid legal basis, and for issuing required notices to data subjects. Elaichi has no visibility into, and exercises no control over, which third-party systems Customer connects or what Personal Data those systems contain.
3. Processing instructions
Elaichi will process Customer Personal Data only on Customer's documented instructions, including for international transfers, unless required otherwise by law — in which case Elaichi will inform Customer before processing unless that law prohibits it on important grounds of public interest.
The Terms, this DPA, Customer's configuration of the Service, and Customer's use of the Service through its interfaces together constitute Customer's complete documented instructions. The subject matter, duration, nature, purpose, categories of data, and categories of data subjects are set out in Annex I.
Elaichi will inform Customer if, in its opinion, an instruction infringes Data Protection Law.
Elaichi does not train, fine-tune, or otherwise improve any model on Customer Personal Data, does not log prompts or completions, and does not sell or share Customer Personal Data.
4. Confidentiality
Elaichi ensures that personnel authorized to process Customer Personal Data are bound by an appropriate obligation of confidentiality, are subject to role-based access limited to what their function requires, and receive security and privacy training.
5. Security
Elaichi implements the technical and organisational measures set out in Annex II, taking into account the state of the art, implementation cost, and the nature, scope, context, and purposes of processing, as well as the risk to data subjects.
Customer is responsible for its own configuration of the Service — including roles, restrictions, toolbox scope, connection ownership, and the choice of which systems to connect — and for assessing whether the measures in Annex II meet its requirements.
6. Sub-processors
Customer grants Elaichi general written authorisation to engage sub-processors. The current list is published at /subprocessors/ and in our Trust Center at trust.elaichi.ai, with the sub-processors as at the effective date listed in Annex III.
Elaichi will give at least 30 days' notice before adding or replacing a sub-processor. Customers may subscribe to notifications in the Trust Center at trust.elaichi.ai. Customer may object on reasonable data protection grounds within that period, in which case the parties will discuss in good faith. If the objection is not resolved, Customer may terminate the affected Service without penalty, with a pro-rata refund of prepaid fees for the unused remainder of the term.
Elaichi imposes on each sub-processor data protection obligations no less protective than those in this DPA, and remains fully liable to Customer for each sub-processor's performance.
7. International transfers
Elaichi is not certified under the EU–US Data Privacy Framework. Where processing involves a transfer of Customer Personal Data out of the EEA, the United Kingdom, or Switzerland to a country without an adequacy decision, the following apply and are incorporated by reference:
- EEA — the SCCs. Module Two (Controller to Processor) applies where Customer is a controller; Module Three (Processor to Processor) applies where Customer is itself a processor, and to onward transfers by Elaichi to its sub-processors.
- United Kingdom — the SCCs as amended by the International Data Transfer Addendum issued by the UK Information Commissioner under s.119A of the Data Protection Act 2018.
- Switzerland — the SCCs, with references to the GDPR read as references to the FADP, the competent authority read as the FDPIC, and "Member State" read so as not to deprive data subjects in Switzerland of the right to sue in their place of habitual residence. The SCCs also protect the data of legal entities until the revised FADP provisions cease to apply.
For the SCCs: the optional docking clause (Clause 7) does not apply; Option 2 of Clause 9(a) applies with the 30-day notice period in section 6 above; the Clause 11 independent dispute resolution option does not apply; Clause 17 is governed by the law of Ireland; and Clause 18(b) designates the courts of Ireland. Annexes I, II, and III below complete the corresponding SCC annexes. Where this DPA conflicts with the SCCs, the SCCs prevail.
8. Assistance with data subject requests
Taking into account the nature of the processing, Elaichi will assist Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling Customer's obligations to respond to data subject requests.
The Service gives Customer direct, self-service access to Customer Personal Data through its interfaces and API, which is ordinarily sufficient for Customer to respond without Elaichi's involvement. Where a data subject contacts Elaichi directly, Elaichi will not respond substantively but will promptly refer the request to Customer, unless legally required to do so.
9. Personal data breach
Elaichi will notify Customer without undue delay and in any event within 72 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point — to the extent known, supplemented as further information becomes available.
Elaichi will assist Customer in meeting its own notification obligations under Articles 33 and 34 GDPR. Notification is not an acknowledgement of fault or liability.
10. Data protection impact assessments
Elaichi will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities under Articles 35 and 36 GDPR, taking into account the nature of processing and the information available to Elaichi. Elaichi maintains a transfer impact assessment available on request.
11. Deletion and return
On termination, Customer may retrieve Customer Personal Data for the duration of the recovery period described in the Terms of Service, by CSV or NDJSON export from any exportable table, through the cursor-paginated API, or by continuous forwarding to a Customer-configured destination.
Deleting an organization revokes all access immediately and begins a 30-day recovery period, after which all Customer Personal Data — including audit history and usage counters — is permanently deleted. Customer may instead elect immediate permanent deletion, which is irreversible.
Elaichi will not retain Customer Personal Data after deletion except where required by law, in which case it will continue to protect it and process it only to the extent and for the period required.
12. Audits and information
Elaichi will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, in the following manner:
- by making available its current certifications, audit reports, and control posture through the Elaichi Trust Center, including documents released under NDA on request; and
- by responding to a reasonable security questionnaire, no more than once per twelve months unless required by a supervisory authority or following a Personal Data Breach.
The parties agree that (1) and (2) ordinarily satisfy Customer's audit rights under Article 28(3)(h) GDPR and Clause 8.9 of the SCCs. On-site audits are not offered. Where Data Protection Law entitles Customer to an on-site audit that cannot be satisfied by the above, the parties will agree its scope, timing, and duration in advance, it will occur no more than once per year during business hours without unreasonably disrupting operations, it will be subject to confidentiality obligations, and Customer will bear its cost.
13. US state privacy law
This section applies where Elaichi processes Personal Information subject to the CCPA or a comparable US state privacy law. Elaichi acts as a service provider (or processor, under the equivalent state term) and not as a third party. Terms in this section take their CCPA meanings.
Elaichi certifies that it understands the restrictions in this section and will comply with them. Specifically, Elaichi will not:
- retain, use, or disclose Personal Information for any purpose other than the specific purpose of performing the Services specified in the Terms, or as otherwise permitted by the CCPA;
- sell or share Personal Information as those terms are defined by the CCPA;
- retain, use, or disclose Personal Information outside the direct business relationship between Elaichi and Customer; or
- combine Personal Information received from or on behalf of Customer with Personal Information received from or on behalf of any other person, or collected from its own interactions with a consumer, except as expressly permitted by the CCPA.
Elaichi will notify Customer if it determines it can no longer meet these obligations. Customer may take reasonable and appropriate steps to stop and remediate unauthorised use. Elaichi will assist Customer in responding to verifiable consumer requests as described in section 8.
Elaichi does not sell or share Personal Information and does not use it for cross-context behavioral advertising. Any aggregated or de-identified data generated under the Terms will be maintained and used in de-identified form, and Elaichi will not attempt to re-identify it.
14. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service or the Master Services Agreement, except where Data Protection Law prohibits such limitation. Nothing in this DPA limits a data subject's rights under Data Protection Law or the SCCs.
15. General
This DPA supersedes any conflicting data protection terms elsewhere. On any question of data protection or the processing of personal data, the order of precedence is: the SCCs, this DPA, the Master Services Agreement, the Order Form, then the Terms of Service. On all other questions, the order in section 2 of the Terms of Service applies.
This DPA takes effect on the effective date above and continues until Elaichi ceases to process Customer Personal Data. Elaichi may update it to reflect changes in law or to its sub-processors or security measures, provided the updated version is no less protective; material changes take effect on 30 days' notice.
Contact: [email protected] · Data protection contact: [email protected]
Annex I — Description of processing
A. List of parties
Data exporter. The Customer identified in the Order Form or account records. Role: Controller (or Processor, where Module Three applies). Contact: the administrator email addresses on the account. Activities: use of the Elaichi MCP control plane as described in the Terms.
Data importer. Yin Yang, Inc. (dba Elaichi), 9450 SW Gemini Dr, PMB 69868, Beaverton, Oregon 97008‑7105, USA. Role: Processor. Contact: [email protected]. Activities: provision of the Elaichi MCP control plane.
EU representative (Art. 27 GDPR). Rickert Rechtsanwaltsgesellschaft mbH – YIN YANG, INC., Colmantstraße 15, 53115 Bonn, Germany — [email protected]
UK representative (Art. 27 UK GDPR). Rickert Services Ltd UK – YIN YANG, INC., PO Box 1487, Peterborough PE1 9XX, United Kingdom — [email protected]
B. Description of transfer
Categories of data subjects. Customer's personnel and authorised users of the Service; and any data subject whose Personal Data is present in the third-party systems Customer elects to connect — which may include Customer's own employees, contractors, customers, prospects, suppliers, and correspondents. Elaichi does not determine or control these categories.
Categories of personal data.
- Account data: name, work email address, organization, role, authentication and identity provider metadata.
- Connection metadata: which connectors and accounts are connected, ownership scope, and operational status.
- Credentials: third-party authentication credentials supplied by Customer, held encrypted in the credential vault and never exposed to end users or to any AI model.
- Tool-call metadata: tool name, connector, connection identifier, status, duration, error code, and the record identifier returned by the third-party system. Request arguments and response payloads are not persisted.
- Audit records: privileged actions with acting user identifier and timestamp.
- Data in transit through connectors: any Personal Data contained in the third-party systems Customer connects, processed transiently to fulfil a tool call and not persisted by Elaichi.
Sensitive data. The Terms prohibit Customer from submitting protected health information, payment card data, biometric identifiers, government identification numbers, financial account credentials, and Article 9 special category data, except where an Order Form expressly permits it. Elaichi does not knowingly process sensitive data outside such an agreement.
Frequency. Continuous, for the duration of the subscription.
Nature and purpose. Hosting, storage, transmission, access control, and execution of tool calls, in order to provide the Elaichi MCP control plane.
Retention. Audit and tool-call metadata: 90 days. Organization data: for the subscription term, then a 30-day recovery period, then permanent deletion — or immediate permanent deletion at Customer's election.
Onward transfers. To the sub-processors in Annex III, for the same duration and purposes.
C. Competent supervisory authority
The supervisory authority of the Member State in which the data exporter is established. Where the data exporter is not established in the EEA but has appointed a representative under Article 27, the supervisory authority of the Member State in which that representative is established. For transfers subject to the UK Addendum, the UK Information Commissioner's Office. For transfers subject to Swiss law, the Federal Data Protection and Information Commissioner.
Annex II — Technical and organisational measures
Encryption. Third-party credentials are held in a dedicated credential vault encrypted at rest with AES‑256‑GCM. Eligible plans may wrap credential encryption with Customer-managed AWS KMS keys held in Customer's own AWS account (BYOK). All data in transit is encrypted with TLS.
Pseudonymisation and minimisation. Tool-call logging is metadata-only: request arguments and response payloads are never written to the log. Prompts and completions are not logged. The control plane stores credential configurations — the shape of what a connector requires — not secrets.
Access control. Role-based access control with system and custom roles; connector and tool restrictions enforced at connect, advertise, and execute time with user-over-role-over-organization precedence; enforced SSO via SAML or OIDC; SCIM provisioning and deprovisioning; group-to-role mapping; and TOTP multi-factor authentication with single-use recovery codes.
Token handling. Session, API, MCP, and invite tokens are stored as keyed hashes and displayed exactly once at creation. Endpoints can be rotated, which revokes the prior token before issuing a replacement. Rate limits apply on both the control and data planes.
Credential isolation. Credentials are resolved server-side at execution time and are never exposed to end users or to any AI model. Delegated connections allow a shared toolbox to execute against the sharer's connection without disclosing the underlying credential.
Logging and monitoring. An append-only audit log records every privileged action, including individual MCP tool calls with tool, connection, status, and duration, and can be forwarded continuously to a Customer-configured destination.
Resilience and recovery. Infrastructure is operated on Cloudflare with point-in-time recovery of 30 days on D1 and Durable Objects.
Data location. Organizations select a region at creation, which cannot be changed afterwards. For US and EU, the organization's Durable Object is pinned to the corresponding Cloudflare jurisdiction. APAC is a placement hint and not a residency guarantee. The global index of organization and user records, the session store, and stored logos are not region-pinned. The audit-log store is a single European Union instance serving all regions.
Offboarding. Removal of a member runs a preflight requiring resolution of personal connections on which shared toolboxes depend, so shared workflows do not silently break and orphaned access does not persist.
Governance. Security and privacy training for personnel; confidentiality obligations; role-scoped internal access; vulnerability intake under a published disclosure policy; and independent assessment as published in the Trust Center at https://trust.elaichi.ai.
Measures for onward transfers. Sub-processors are bound by written terms no less protective than this DPA, and transfers rely on the SCCs as set out in section 7.
Annex III — Sub-processors
As at the effective date. The authoritative current list is published at /subprocessors/ and mirrored at trust.elaichi.ai.
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting, compute, storage, queues, email delivery, rate limiting, and access control | Global, with EU/US jurisdiction pinning for organization data |
| Stripe, Inc. | Subscription billing and payment processing | USA |
| OVH SAS | Hosting of the self-hosted audit-log store | European Union |
| Yin Yang Technologies Private Limited | Engineering, operations, and support personnel; wholly owned affiliate of Yin Yang, Inc. | India |
The following are not sub-processors of Elaichi. They are services Customer elects to connect and configure under its own accounts and agreements: AI model providers accessed with Customer's own API key, log-forwarding destinations, social login providers, Customer's identity provider, AWS KMS for BYOK, and every third-party SaaS product Customer connects through a connector.