Data Processing Addendum
Last updated: September 2026 · Applies to Youleap's processing of Customer Personal Data under the Agreement between Youleap Ltd and its business customers.
This Data Processing Addendum (“Addendum”) forms an integral part of, and is incorporated by reference to, the purchase order and accompanying agreement ("Agreement") entered between Youleap Ltd, (“Youleap”) and the customer identified in the Agreement ("Customer").
WHEREAS, the service that Youleap provides to the Customer pursuant to the Agreement (“Services”) involves Youleap's processing of certain personal data on behalf of the Customer;
WHEREAS, the parties wish to set forth the terms and conditions for Youleap's processing of such personal data through this Addendum.
THEREFORE, The parties have agreed to this Addendum, consisting of the following parts:
- Part One – General Provisions
- Part Two – EU GDPR & UK GDPR
- Part Three – Israeli Privacy Protection Regulations (Information Security)
- Part Four – United States
Part 1 – General Provisions
In the event of any conflicting provisions between this Addendum and the Agreement or any other agreement between the parties, the provisions of this Addendum shall prevail solely with respect to data protection and privacy matters, provided that such precedence shall not override any limitations of liability, indemnification provisions, or dispute resolution mechanisms set forth in the Agreement. The limitation of liability provisions under the Agreement shall apply to liability arising from or in connection with a breach of this Addendum.
Specifics of Processing
- Duration of the Processing. The duration of the Processing shall be the duration of the Agreement.
- Subject-Matter, Nature, and Purpose of the Processing. The purpose and object of Youleap's processing of Personal Data are to perform and provide the Service pursuant to the Instructions, as specified in the Agreement and this Addendum, on behalf of and for the benefit of Customer.
- Types of Personal Data ("Customer Personal Data"). The types of personal data are determined and selected by the Customer according to Customer's choices in its use of the Services.
- Categories of Data Subjects. The categories of data subjects are the Customer's end-users or consumers.
Restrictions on Processing
Youleap is prohibited from using or disclosing the Customer Personal Data for any purpose other than providing the Service. Youleap certifies that it understands the restrictions specified in this Section and will comply with them.
Data Subject Requests
Youleap will follow Customer's instructions to accommodate data subjects' requests to exercise their rights in relation to the personal data that Youleap processes on Customer's behalf. Youleap shall notify Customer of the receipt of such a request as soon as possible, and no later than five (5) business days from receipt of such request, together with the relevant details.
Disclosure
Unless prohibited by law, Youleap will expeditiously provide Customer with notice of any request it receives from any governmental or judicial authority or agency to produce or disclose personal data Youleap processes on Customer's behalf, so that Customer may contest or seek to limit the scope of such production or disclosure request.
Data Security
Youleap shall implement and maintain reasonable security measures and practices appropriate to the nature of the personal data that Youleap processes on Customer's behalf, to protect such personal data from unauthorized access, destruction, use, modification, or disclosure (including data breaches). Youleap will ensure that its staff authorized to process personal data on Customer's behalf have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
Data Breaches
Youleap shall, without undue delay, notify Customer of any data breach as defined in the applicable data protection and privacy laws, or any actual, accidental, or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data that Youleap processes on Customer's behalf. Youleap shall investigate the breach and take all available measures to mitigate the breach and prevent its recurrence. Upon Customer's request, Youleap will cooperate with Customer in Customer's issuance of statements or notices regarding such breaches to authorities and data subjects, without prejudice to Youleap's own data breach notification obligations.
Subcontracting to Suppliers
Customer acknowledges and specifically authorizes Youleap's use of its sub-processors existing as of the execution of the Agreement, as detailed in Appendix A, attached hereto, to assist Youleap in its processing of personal data on Customer's behalf. Customer hereby gives a general authorization for further sub-processors, provided Youleap follows the following procedure:
- Youleap shall inform Customer at least ten (10) business days in advance of any new or substitute sub-processor, in which case Customer shall have the right to object to such new or substitute sub-processor. If Customer objects, Youleap may not engage that new or substitute sub-processor for the purpose of processing personal data on Customer's behalf.
- Youleap will ensure that substantially equivalent data protection obligations as set out in this Addendum are imposed on such other sub-processor by way of a contract. Should such other sub-processor fail to fulfill its data protection obligations, Youleap shall remain fully liable to Customer for the performance of such other sub-processor's obligations.
Data Return and Deletion
Upon Customer's request, Youleap will delete the personal data Youleap processed on Customer's behalf from its own and its sub-processors' systems, within thirty (30) business days of receiving a request to do so. Youleap will also delete such personal data upon termination or expiration of the Agreement. Upon Customer's request, Youleap will furnish written confirmation that such personal data has been deleted or returned pursuant to this Section.
Audits
Subject to prior coordination with Youleap as to the time, scope, and agenda of the audit, and no more than once per year (unless data protection law or a governmental authority requires otherwise), Youleap shall allow for and contribute to audits, including inspections conducted by Customer or another auditor mandated by Customer, in order to establish Youleap's compliance with this Addendum as regards the personal data Youleap processes on Customer's behalf.
All provisions of this Addendum which by their nature and purpose should persist following termination of the Agreement shall survive and continue to apply after the expiry or termination of the Agreement between the parties, insofar as Youleap continues to hold or process the personal data it processes on Customer's behalf.
Part 2 – GDPR & UK GDPR Addendum
Definitions
- “Authority” means any supervisory authority with authority under Data Protection Laws over all or any part of the provision or receipt of the Service or the Processing of Customer Personal Data.
- “Customer Personal Data” means data relating to any identified or identifiable individual that Youleap processes on behalf of Customer.
- “Controller” means the entity that determines the purposes and means of the Processing of Customer Personal Data.
- “Processor” means the entity that processes Customer Personal Data on behalf of the Controller.
- “Data Protection Laws” means all applicable laws and regulations, including laws and regulations of the European Union, the European Economic Area, and their member states, applicable to the Processing of Customer Personal Data under the Agreement, and including the General Data Protection Regulation (Regulation (EU) 2016/679) (the “GDPR”) as of its effective date and the United Kingdom's Data Protection Act 2018 and the GDPR as saved into United Kingdom law by virtue of Section 3 of the United Kingdom's European Union (Withdrawal) Act 2018 (“UK GDPR”).
- “Process,” “Processes,” or “Processing” means any operation or set of operations performed upon Customer Personal Data, whether or not by automatic means, including the collection, recording, organization, storage, updating, modification, retrieval, consultation, use, transfer, dissemination by means of transmission, distribution, or otherwise making available, merging, linking, blocking, erasure, or destruction.
- “Standard Contractual Clauses” means (i) where the GDPR applies, the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (the “EU SCCs”); and (ii) where the UK GDPR applies, the “International Data Transfer Addendum to the EU Commission Standard Contractual Clauses” issued by the Information Commissioner under s.119A(1) of the Data Protection Act 2018 (“UK Addendum”).
Instructions
Controller-Processor Relationship. Youleap shall only Process the Customer Personal Data on behalf of Customer when providing the Service. The parties acknowledge that with regard to the Processing of Customer Personal Data between the parties, Customer acts as the Controller and Youleap acts as the Processor.
Youleap shall Process the Customer Personal Data only on Customer's instructions documented in this Addendum or otherwise provided either in writing or through the options of the Service configurable by Customer ("Instructions"). Any additional or alternate instructions must be agreed upon separately through prior written agreement between Customer and Youleap. The foregoing applies unless Youleap is otherwise required by law to which it is subject (and in such a case, Youleap shall inform Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest).
If Youleap believes that compliance with any of Customer's instructions infringes Data Protection Laws, Youleap shall immediately notify Customer thereof.
Security
Security Controls. Youleap shall implement appropriate technical and organizational measures to protect and safeguard the Customer Personal Data that is processed as part of the Service against Personal Data Breaches (as defined under the Data Protection Laws). The technical and organizational measures are specified in Part 3.
Compliance Demonstration by Youleap
Youleap will make available to Customer all necessary information at its disposal to demonstrate compliance with the obligations under the Data Protection Laws.
Cross-Border Transfers
Without limiting the sub-processor appointment procedure in Part 1, Youleap and its sub-processors will only Process Customer Personal Data in member states of the European Economic Area or in territories or territorial sectors recognized by an adequacy decision of the European Commission as providing an adequate level of protection for personal data pursuant to Article 45 of the GDPR, or using adequate safeguards as required under Data Protection Laws governing cross-border data transfers (e.g., EU SCC or UK Addendum, as applicable). Youleap must inform Customer at least 10 business days in advance of any materially new cross-border data transfer scenario that involves transfers to jurisdictions not already covered by adequate safeguards, in which case Customer shall have the right to object to that new cross-border data transfer on reasonable grounds related to data protection compliance. If Customer objects, Youleap may not engage in that new cross-border data transfer for the purpose of Processing Customer Personal Data in the provision of the Service.
In the event that the foregoing mechanism for cross-border data transfers is invalidated by an Authority, the parties shall discuss in good faith and agree to such variations (such agreement not to be unreasonably withheld or delayed) to this Addendum as are required to enable valid cross-border data transfers.
Data Protection Impact Assessment
Youleap will assist Customer with the preparation of data protection impact assessments and prior consultation, as appropriate and if needed.
Part 3 – Israeli Law
Definitions
In this Part, the following terms shall be interpreted as follows:
- “Applicable Law” means the Israeli Protection of Privacy Law, 5741-1981 (hereinafter – the “Privacy Law”) and the regulations promulgated thereunder and in particular the Protection of Privacy Regulations (Information Security), 5777-2017.
- “Customer Personal Data” means data relating to any identified or identifiable individual that Youleap processes on behalf of the Customer.
- "Database" means a collection of Customer Personal Data held by physical, magnetic, or optical means.
- "Processing" (and its derivatives, including, but not limited to "Process") means the collection, access, retention, modification, use, disclosure, and transfer of Customer Personal Data.
- "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data transmitted, stored, or otherwise processed.
General Provisions
This Part applies to Youleap's own Processing activities regarding the Customer Personal Data. It does not apply to Customer's own Processing activities regarding the Customer Personal Data. Customer is independently responsible for applying appropriate security measures and complying with Applicable Law regarding the Processing activities it performs, configures, or initiates concerning the Customer Personal Data.
Youleap declares and undertakes that during the period it provides the Service to Customer, it shall comply with all provisions of Applicable Law. In this regard, Youleap declares and confirms that it is familiar with Applicable Law.
Customer is the sole owner of the Databases containing the Customer Personal Data, and nothing contained in this Part and/or the Agreement shall be deemed to constitute the grant of proprietary rights to Youleap in the Customer Personal Data.
Youleap's Obligations Regarding the Processing of Customer Personal Data
- Youleap undertakes to manage access rights to Customer Personal Data, including providing its users with ‘Least Privileges’ based on their ‘Need to Know’ for the purpose of carrying out their tasks, and shall take measures to prevent access by unauthorized individuals to the Customer Personal Data.
- Youleap will maintain an up-to-date list of all authorized individuals for the Database, and prevent access by any individual who does not have a legitimate need to be exposed to the Customer Personal Data.
- Youleap shall not grant access to the Customer Personal Data to its employees, consultants, or anyone acting on its behalf before: (a) reviewing and confirming that their background, personal integrity, and reliability are suitable for a position granting them access to the Customer Personal Data; and (b) binding them to a letter of undertaking to maintain the confidentiality, information security, and privacy of the data subjects whose details are included in the Database. Youleap shall be liable to Customer for any act or omission by itself or any of its employees, advisors, sub-contractors, sub-processors, or anyone else acting on its behalf in connection with a breach of the provisions of this Part 3.
- Youleap shall grant its employees access to the Database, subject to conducting training regarding privacy protection and information security obligations applicable to Youleap by virtue of Applicable Law or this Part 3. Such training shall take place at least once every two years and as soon as possible after their recruitment.
- Youleap shall implement security and monitoring measures through which it shall record each access to the Database Systems (as defined below).
Youleap shall develop, implement, and enforce an information security policy that shall include at least the following issues (the "Information Security Policy"):
- Mapping the security measures taken by Youleap regarding the Database Systems;
- Instructions regarding the manner in which access to the Database is managed, the means of controlling access to the Customer Personal Data, and the actions taken within it;
- Guidelines for individuals authorized to access Customer Personal Data and Database Systems;
- A review of the risks to which the Customer Personal Data is exposed as part of Youleap's ongoing activities;
- Instructions regarding the means of recording, monitoring, and identifying threats to which the Database Systems are exposed, and events in which there is a risk of a Breach of Information Security;
- Instructions regarding periodic audit reports;
- Instructions regarding the manner in which Youleap shall handle Security Incidents;
- Instructions and procedures regarding periodic backup and restoration of the audit data;
- Instructions regarding the manner in which development activities in the Database are performed and documented.
Youleap shall map the operational environment of the Database. Youleap shall prepare an inventory list that includes all the data systems, software, interfaces, hardware components, and communication components that Youleap operates in the Database environment for the ongoing operation of the Database (the "Database Systems"). Youleap shall update the inventory list specified in this Section from time to time and shall only disclose the document to those individuals who require access to it for the performance of their job functions. However, Youleap shall update the aforesaid list in any case in which substantial changes to the operating environment are performed in the Database Systems or in the manner in which data is processed.
Transfer of Customer Personal Data
Youleap shall use accepted encryption mechanisms for each transfer of Customer Personal Data to a third party and for any remote access to the Database Systems.
Retention and Return of Customer Personal Data
- Youleap declares and undertakes to take appropriate information security measures to ensure the integrity, availability, confidentiality, and reliability of the Customer Personal Data.
- Youleap shall maintain logical separation between the Database Systems and the computer systems used by Youleap that are not directly related to the provision of the Service to Customer. In the event of connection of the Database Systems to the Internet or to another public network, Youleap shall implement appropriate safeguards against a Breach of Information Security.
- Youleap undertakes to enable authentication of authorized users to the Database Systems by physical means subject to their exclusive control, in addition to a password-based identification measure.
- Youleap shall restrict and specify rules regarding the connection of portable devices to the Database Systems.
- Youleap shall keep Customer Personal Data solely as long as necessary to fulfill the purposes for which it was transferred to Youleap, or as required by Applicable Law.
- Youleap shall regularly update the Database Systems, including the software installed in the Database Systems, with information security updates. In operating the Database Systems, Youleap shall not use any software or hardware components whose manufacturer does not support their security aspects.
- Pursuant to the Agreement and without limiting its generality, Youleap shall return, delete, or destroy all Customer Personal Data to which this Part applies, including, but not limited to, all original and other copies of such Customer Personal Data, in any medium, including but not limited to hard drives, backups, and any other magnetic or optical media and all materials arising from or incorporating the Customer Personal Data upon Customer's written request for return, deletion, or removal for any reason whatsoever.
Audit, Documentation, and Monitoring
- Youleap undertakes to monitor and document the activity carried out in physical sites where the Database Systems are located, including (but not limited to) documentation of attempts to access the sites, as well as the installation and removal of equipment in and from the sites.
- Youleap undertakes to document the activity carried out in the Database Systems by an automated mechanism, including (but not limited to) documentation of attempts to access the Database Systems, deletion and/or change of Customer Personal Data, and change of access rights to the Database Systems ("Audit Mechanism"). The Audit Mechanism shall collect at least the following data: the user identity, the date and time of the activity, the source of the activity (Internet address or computer name), the component of the system in which the activity was performed, the type of activity, and whether or not the activity was successful.
- The audit data to be generated by the Audit Mechanism shall be maintained for 24 months.
- Youleap undertakes to back up all data generated by the Audit Mechanism.
- Youleap shall provide Customer, at least every 12 months, or upon Customer's request, a written confirmation that it performs and fulfills its obligations pursuant to this Part and the provisions of the Applicable Law.
- Youleap undertakes to conduct, at least once every 24 months, an internal audit by an entity or a person with appropriate certification for auditing information security, and who is not Youleap's CISO, in order to ascertain Youleap's compliance with these provisions and the provisions of the Applicable Law.
- Youleap acknowledges that it may be subject to audits by privacy regulators.
- Youleap shall perform penetration tests to examine the resilience of the Database Systems against external and internal risks ("Penetration Tests"), shall examine the need to update the Information Security Policy following the Penetration Tests, and shall act to rectify any deficiencies discovered during the tests, to the extent any are discovered. Penetration Tests shall be performed at least once every eighteen (18) months.
Updating the Information Security Policy
Youleap will conduct discussions regarding Security Incidents at least once a year and assess the need to update the Information Security Policy.
Transfer of Customer Personal Data to Foreign Jurisdictions
Youleap shall act in accordance with the law applicable to the transfer of Customer Personal Data to foreign jurisdictions, including but not limited to the Protection of Privacy Regulations (Transfer of Information to Databases Outside of Israel), 5761-2001.
General Cooperation
Youleap shall fully cooperate with Customer by providing all information and assistance reasonably requested by Customer in connection with data security issues, practices, and supplementary documents, to allow Customer to properly address information security, privacy, and regulatory matters relating to the Database.
Part 4 – California
Scope
This Part 4 applies to any Personal Information subject to Applicable State Privacy Laws that Youleap Processes within the scope of the Service it provides to Customer under the Agreement.
Definitions
- “Applicable State Privacy Laws” means the CPRA and other applicable state privacy laws in the United States, such as (but not limited to): the Virginia Consumer Data Protection Act, the Connecticut Act Concerning Personal Data Privacy and Online Monitoring, the Utah Consumer Privacy Act, and the Colorado Privacy Act.
- “CPRA” means Cal. Civ. Code §1798.100 et seq. and the regulations at 11 C.C.R. §7000 et seq.
- “Collect” (and its cognate terms) means buying, renting, gathering, obtaining, receiving, or accessing any Customer Personal Data pertaining to an individual by any means. This includes obtaining information from the individual, either actively or passively, or by observing the individual's behavior or interaction.
- “Customer Personal Data” means data relating to any identified or identifiable individual that Youleap processes on behalf of the Customer.
- “Process” (and its cognate terms) means any operation or set of operations performed on Customer Personal Data, whether by automated means.
- “Sell” (and its cognate terms) means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, Customer Personal Data for monetary or other valuable consideration.
- "Share" (and its cognate terms) means sharing, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, Customer Personal Data for cross-context behavioral advertising, whether or not for monetary or other valuable consideration, including transactions for cross-context behavioral advertising in which no money is exchanged.
Youleap's Obligations
The Parties acknowledge and agree that in processing the Customer Personal Information, Youleap is a "service provider" within the meaning of that term in Applicable State Privacy Laws. To that end, and unless otherwise required by law:
- Youleap will not Sell or Share any Customer Personal Data it Processes.
- The Parties agree that Customer is disclosing the Customer Personal Data to Youleap solely for the limited and specified business purpose of providing the Service under the Agreement.
- Youleap is prohibited from retaining, using, or disclosing the Customer Personal Data that it Processes for any commercial purpose other than the foregoing business purposes, unless Youleap is otherwise required under applicable law. Additionally, Youleap is prohibited from retaining, using, or disclosing the Customer Personal Data that it Collects pursuant to this Agreement outside the direct business relationship between Youleap and Customer, unless Youleap is otherwise required under applicable law.
- Youleap shall comply with all relevant sections of Applicable State Privacy Laws and shall provide, with respect to the Customer Personal Data it Collects, the same level of privacy protection as required by Applicable State Privacy Laws.
- Youleap grants Customer the right to take reasonable and appropriate steps to ensure that Youleap uses the Customer Personal Data it Collects in a manner consistent with the obligations under this Addendum and the CPRA.
- Youleap must promptly notify Customer when it determines that it can no longer meet its obligations under this Addendum or Applicable State Privacy Laws.
- Youleap grants Customer the right, upon notice, to take reasonable and appropriate steps to stop and remediate Youleap's unauthorized use of the Customer Personal Data.
Appendix A – List of Sub-Processors
| Sub-Processor (Name and Jurisdiction) | Purpose of Processing | Location of Processing | Duration of Sub-Processing |
|---|
| Amazon Web Services, Inc. (USA) / Amazon Web Services EMEA SARL (Luxembourg) | Cloud infrastructure and hosting for the Service | Ireland (AWS Region eu-west-1) | Duration of the Agreement |
| Hyp Ltd. (Israel) | Payment processing for end-customer transactions | Israel | Duration of the Agreement |
| Twilio Inc. (SendGrid) (USA) | Transactional email delivery to end-customers | USA; EU | Duration of the Agreement |
| Google LLC (USA) | Bot protection (reCAPTCHA) on login and registration flows | USA | Duration of the Agreement |
Contact