Data Processing Agreement

Last updated: August 15, 2026

Privacy PolicyTerms of Service

1. Who this agreement is between, and who does what

This Data Processing Agreement forms part of the Terms of Service between you (the “Customer”) and Prediction Labs Inc., which operates Yanmoo. It applies whenever we process personal data on your behalf. It takes effect when you accept the Terms, and no signature is required.

You are the controller. We are the processor. You decide what personal data enters Yanmoo, which third-party tools to connect, and what you instruct your agents to do. We process that data to run the service for you.

Where we process data about your own team’s use of Yanmoo — account creation, billing, support, and keeping the service secure and working — we act as a controller in our own right, and the Privacy Policy describes that. This agreement covers the processor role.

If a term is defined in the GDPR — controller, processor, personal data, processing, data subject, supervisory authority — it carries that meaning here.

2. What we process, for whom, and for how long

Subject matter. Providing Yanmoo: diagnosing a product, producing growth playbooks, running AI agents that carry out marketing work, and measuring the result.

Duration. For as long as your account is active, plus the deletion windows in section 10.

Nature and purpose. Storage, organisation, retrieval, analysis and transmission of personal data, in order to operate the features you ask for. This includes sending data to AI model providers so that agents can do the work, and reading from and writing to third-party tools you have connected.

Categories of data subject.

  • Your personnel who use Yanmoo.
  • Your customers, prospective customers and website visitors, whose data reaches us through the tools you connect.
  • People your agents contact on your behalf, where you have instructed outreach.

Types of personal data.

  • Account data — name, email address, and the sign-in method chosen.
  • Identity and attribution records — an internal customer identifier we mint, together with the keys that resolve to it. Depending on the tools you connect those keys may include an email address, a click identifier, a coupon or referral code, or an anonymous identifier. These are what make lifetime value, cohorts and channel attribution possible.
  • Commerce and marketing records — orders, revenue events, campaign and audience data read from the tools you connect.
  • Agent activity — the runs your agents perform, the tools they call, and the transcripts of that work, which may contain personal data if your instructions or the connected data contain it.
  • Credentials for the tools you connect, held encrypted.

We do not ask for, and Yanmoo is not designed to hold, special categories of personal data under Article 9, or personal data relating to criminal convictions. Do not put such data into the service.

3. We act only on your instructions

We process personal data only on your documented instructions, including for transfers to another country. Your instructions are: this agreement, the Terms of Service, the configuration you set in the product, the tools you choose to connect, and the work you direct your agents to do.

If we are required by law to process personal data beyond your instructions, we will tell you before we do, unless that law forbids us from telling you.

If we believe an instruction would breach data protection law, we will tell you. We may suspend the affected processing until it is resolved.

An agent acting autonomously is still acting on your instruction. Yanmoo runs AI agents that take actions without a person watching each one. Those actions follow the goals, budgets, approvals and connected tools you configured. You remain the controller for them, and the activity log in the product is there so you can see what was done with your data.

4. Confidentiality

Everyone we allow to access personal data is bound by a duty of confidentiality, by contract or by professional obligation, and that duty survives the end of their engagement with us. Access to production data is limited to the people who operate the service, and only for as long as their role requires it.

5. Security

We maintain technical and organisational measures appropriate to the risk, as required by Article 32. These currently include:

  • Encryption in transit using TLS, and encryption at rest.
  • Credentials and API keys for connected tools encrypted with AES-256-GCM before storage, held in an encrypted secret store rather than in application configuration.
  • Per-company isolation: each company gets its own model credentials and its own execution environment, so one customer’s agents cannot reach another customer’s credentials or work.
  • Agent work runs inside isolated sandboxes, separated from the control plane and from each other.
  • Access control and authentication for our own personnel, with production access limited by role.
  • Logging of agent activity, exposed to you in the product.
  • Backups of the primary database, restorable in the event of loss.

Security is not static. We may change these measures, but not in a way that materially reduces the protection of your personal data.

6. Sub-processors

You give us general authorisation to engage sub-processors. Each is bound by written terms imposing data protection obligations no less protective than these, and we remain fully liable to you for their performance.

Our sub-processors are:

  • Fly.io — application hosting and the managed database.
  • Tigris — object storage for files and run logs.
  • PostHog — product analytics, error tracking, session recording, and the AI request records described in the Privacy Policy. United States region.
  • Daytona — the isolated sandboxes your agents run inside.
  • Anthropic, OpenAI, Google, xAI and Cursor — AI model providers, depending on the model you connect.
  • Resend — transactional email such as address confirmation and password reset.
  • Jina — reading public web pages during a diagnosis.

If you bring your own model subscription or API key, your agent work runs against the provider you chose, under your agreement with them. That provider is your sub-processor for that work, not ours.

The connection layer for third-party tools runs on our own infrastructure rather than as a hosted service, so the vendor of that software does not receive your personal data.

We will give you at least 30 days’ notice before adding or replacing a sub-processor, by email to your account contact. If you reasonably object on data protection grounds, tell us within those 30 days and we will work with you to find an alternative. If we cannot, you may terminate the affected part of the service and we will refund any prepaid fees for the unused period.

7. Where data is processed

Prediction Labs Inc. is established in Canada. Our sub-processors process personal data in Canada and the United States.

Where personal data is transferred out of the European Economic Area, the United Kingdom or Switzerland, we rely on a lawful transfer mechanism for that transfer — an adequacy decision where one applies, and otherwise the European Commission’s Standard Contractual Clauses, together with any additional measures the transfer requires. On request we will provide the mechanism relied on for a given sub-processor.

7a. United States and Canada

The obligations above are written in the language of the GDPR because that is the common standard, but they apply to your personal data regardless of which law governs it. Where a North American privacy law applies, the following also holds.

California. With respect to personal information governed by the California Consumer Privacy Act as amended, we are a service provider and you are the business. We do not sell or share personal information, and we do not retain, use or disclose it for any purpose other than performing the services described in the Terms, or as otherwise permitted by the CCPA. We do not combine personal information received from you with personal information from another source, except as the CCPA permits. We will notify you if we determine we can no longer meet these obligations, and you may take reasonable steps to stop and remediate unauthorised use. We will help you respond to consumer requests to know, delete, correct, and to opt out of sale or sharing.

Other US state privacy laws. Where Virginia, Colorado, Connecticut, Utah, Texas or a comparable state law applies, we act as a processor and you as the controller, and the obligations in this agreement satisfy the terms those laws require between us.

Canada. Prediction Labs Inc. is a Canadian corporation and is subject to PIPEDA. Where Quebec’s Law 25 applies to personal information you entrust to us, we process it only for the purposes you specify, apply the security measures in section 5, and will notify you of a confidentiality incident without delay so you can meet your own reporting duties.

8. AI models, and what we will not do with your data

Operating Yanmoo requires sending text to AI model providers. That text can include content from the tools you connect, the growth information you provide, and the instructions your agents follow.

We do not use, transfer or retain your personal data to develop, improve or train generalised or non-personalised artificial intelligence or machine learning models. This applies to the raw data and to any aggregated, anonymised or derived form of it. Where we use a third-party model provider, we do so under terms that prohibit training on your data and require zero retention.

We retain the AI request and response records described in the Privacy Policy in order to measure quality and cost and to diagnose poor results. That is a processing activity in service of the product you asked for, and it is subject to the retention period in section 10. If you would prefer we did not retain them for your company, email privacy@yanmoo.ai.

Yanmoo does not use personal data to make automated decisions producing legal or similarly significant effects on individuals within the meaning of Article 22.

9. Helping you meet your own obligations

Data subject requests. If a data subject contacts us directly about data we process for you, we will not respond substantively; we will tell them to contact you, and tell you promptly. Taking into account the nature of the processing, we will help you respond to requests for access, rectification, erasure, restriction, portability and objection, through the export and deletion functions in the product and, where those are not enough, by acting on your written request.

Wider assistance. Taking into account the nature of the processing and the information available to us, we will help you comply with Articles 32 to 36 — security, breach notification to authorities and to data subjects, data protection impact assessments, and prior consultation.

10. Breaches, deletion and return

Personal data breaches. We will notify you without undue delay after becoming aware of a personal data breach affecting personal data we process for you. The notice will describe what happened, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where we cannot provide all of it at once, we will provide it in phases without undue delay.

Deletion and return. At any time during the term you can export your company data from the product. When your account closes, we delete company data within 30 days. Disconnecting a tool deletes its credentials immediately and the records derived from it within 30 days. Where you ask for a copy instead of deletion, tell us before the account closes.

Retention periods for each category of data are set out in the Privacy Policy and form part of this agreement. We keep personal data beyond those periods only where law requires it, and only for as long as that law requires.

Backups follow their own rolling schedule, configured for the instance your company runs on. Deleting data removes it from the live service immediately; a copy may persist in a backup until that backup expires. Data in a backup is never restored into active use after a deletion request. On request we will tell you the backup schedule in force for your instance.

11. Audits and information

We will make available to you the information necessary to demonstrate compliance with Article 28, and will allow and contribute to audits, including inspections, conducted by you or an auditor you appoint.

In practice, we ask that you first accept the documentation we can provide — this agreement, the Privacy Policy, our security measures, and answers to a reasonable security questionnaire. Where that genuinely does not answer your question, an on-site or remote audit may be conducted once in any twelve-month period, on 30 days’ written notice, during business hours, without unreasonably disrupting the service, and subject to confidentiality. A supervisory authority exercising its own powers is not subject to those limits.

12. General

Order of precedence. If this agreement conflicts with the Terms of Service on the processing of personal data, this agreement prevails on that point. Everything else in the Terms continues to apply, including the governing law and the liability position.

Changes. We may update this agreement to reflect a change in the service, in our sub-processors, or in the law. Where a change materially affects your rights we will give notice by email to your account contact before it takes effect. Sub-processor changes follow the notice period in section 6.

Contact. For anything in this agreement, including data subject requests, audit requests and sub-processor objections, email privacy@yanmoo.ai.