Draft GDPR Data Processing Addendum.
Illustrative Article 28 negotiation text for a customer that instructs Yabby to proxy public web traffic and produce aggregate analytics. Replace bracketed terms, attach the service description and subprocessor list, and obtain legal review before signature.
DRAFT — NOT A SIGNED AGREEMENT. This template does not establish that Yabby is a GDPR-compliant processor, that a transfer is lawful, or that the customer has selected an appropriate lawful basis or transfer mechanism.
1. Parties and precedence
This addendum is between [Customer legal name] (Controller) and [Yabby legal entity] (Processor), effective [date], under the master agreement at [agreement]. If terms conflict, the negotiated data-protection terms control only to the extent required by applicable law.
2. Documented instructions and purpose
Yabby may process personal data only to provide the configured reverse-proxy, aggregate analytics, platform-signal, experiment-delivery, security, support, and deletion services described in the order form. Yabby must not sell, share, advertise against, profile, or combine customer data across sites. The Controller determines the purposes, lawful basis, notices, retention instructions, and in-scope hostnames.
3. Scope and data
Data subjects are visitors and users of the Controller’s configured sites. Personal data may be visible transiently in requests and origin responses, including IP address, URL, headers, cookies, and content required to proxy traffic. Persisted analytics are bounded aggregates: canonical path, status/latency bucket, allowlisted platform/content label, optional coarse device class, and experiment counters. Special-category data, children’s data, payment data, credentials, and health data are out of scope unless separately agreed in writing.
4. Confidentiality and security
Yabby will restrict personnel access, maintain confidentiality obligations, use access control and secret management, apply least privilege, protect administrative routes with the configured access controls, and maintain the technical and organisational measures in the security schedule. The parties will document the origin-authentication, rollback, incident, and deployment controls applicable to the customer’s site.
5. Assistance
Taking into account the processing, Yabby will provide reasonable assistance with data-subject requests, security assessments, breach response, DPIAs, and regulator cooperation. The Controller remains responsible for verifying identity, responding to individuals, and determining whether a request or incident is legally reportable.
6. Personal-data breaches
Yabby will notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller’s data and provide available information needed for the Controller’s assessment. The parties will insert a specific notice channel and target: [contact / hours / target].
7. Subprocessors and transfers
Yabby may use the subprocessors listed at [URL or schedule] subject to the agreed authorisation and notice process. For restricted transfers, the parties must select and complete the applicable transfer mechanism, conduct any required transfer-impact assessment, and document supplementary measures. No adequacy or transfer conclusion is made by this draft.
8. Return, deletion, and audit
At termination or on written instruction, Yabby will delete or return personal data where technically applicable, subject to legal retention and backup deletion cycles. Aggregate rows expire under the service retention setting. The Controller may request reasonable evidence of the measures and a proportionate audit, subject to confidentiality and security restrictions.
9. Term, liability, and governing law
The addendum runs with the master agreement. Liability, indemnity, governing law, and dispute terms must be completed by counsel; this draft deliberately leaves them open.
Schedule: processing details
Subject matter: edge proxy and privacy-first aggregate analytics. Duration: contract term plus documented deletion windows. Frequency: each configured request and background aggregate write. Nature: collection by proxy, routing, transformation only under a published experiment, aggregation, retention, deletion, and support. Categories and data subjects: as in section 3. Sensitive data: prohibited unless separately agreed.