Data Processing Addendum

Last updated: September 2026 · Applies to Youleap's processing of Customer Personal Data under the Agreement between Youleap Ltd and its business customers.

This Data Processing Addendum (“Addendum”) forms an integral part of, and is incorporated by reference to, the purchase order and accompanying agreement ("Agreement") entered between Youleap Ltd, (“Youleap”) and the customer identified in the Agreement ("Customer").

WHEREAS, the service that Youleap provides to the Customer pursuant to the Agreement (“Services”) involves Youleap's processing of certain personal data on behalf of the Customer;

WHEREAS, the parties wish to set forth the terms and conditions for Youleap's processing of such personal data through this Addendum.

THEREFORE, The parties have agreed to this Addendum, consisting of the following parts:

Part 1 – General Provisions

In the event of any conflicting provisions between this Addendum and the Agreement or any other agreement between the parties, the provisions of this Addendum shall prevail solely with respect to data protection and privacy matters, provided that such precedence shall not override any limitations of liability, indemnification provisions, or dispute resolution mechanisms set forth in the Agreement. The limitation of liability provisions under the Agreement shall apply to liability arising from or in connection with a breach of this Addendum.

Specifics of Processing

Restrictions on Processing

Youleap is prohibited from using or disclosing the Customer Personal Data for any purpose other than providing the Service. Youleap certifies that it understands the restrictions specified in this Section and will comply with them.

Data Subject Requests

Youleap will follow Customer's instructions to accommodate data subjects' requests to exercise their rights in relation to the personal data that Youleap processes on Customer's behalf. Youleap shall notify Customer of the receipt of such a request as soon as possible, and no later than five (5) business days from receipt of such request, together with the relevant details.

Disclosure

Unless prohibited by law, Youleap will expeditiously provide Customer with notice of any request it receives from any governmental or judicial authority or agency to produce or disclose personal data Youleap processes on Customer's behalf, so that Customer may contest or seek to limit the scope of such production or disclosure request.

Data Security

Youleap shall implement and maintain reasonable security measures and practices appropriate to the nature of the personal data that Youleap processes on Customer's behalf, to protect such personal data from unauthorized access, destruction, use, modification, or disclosure (including data breaches). Youleap will ensure that its staff authorized to process personal data on Customer's behalf have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

Data Breaches

Youleap shall, without undue delay, notify Customer of any data breach as defined in the applicable data protection and privacy laws, or any actual, accidental, or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data that Youleap processes on Customer's behalf. Youleap shall investigate the breach and take all available measures to mitigate the breach and prevent its recurrence. Upon Customer's request, Youleap will cooperate with Customer in Customer's issuance of statements or notices regarding such breaches to authorities and data subjects, without prejudice to Youleap's own data breach notification obligations.

Subcontracting to Suppliers

Customer acknowledges and specifically authorizes Youleap's use of its sub-processors existing as of the execution of the Agreement, as detailed in Appendix A, attached hereto, to assist Youleap in its processing of personal data on Customer's behalf. Customer hereby gives a general authorization for further sub-processors, provided Youleap follows the following procedure:

Data Return and Deletion

Upon Customer's request, Youleap will delete the personal data Youleap processed on Customer's behalf from its own and its sub-processors' systems, within thirty (30) business days of receiving a request to do so. Youleap will also delete such personal data upon termination or expiration of the Agreement. Upon Customer's request, Youleap will furnish written confirmation that such personal data has been deleted or returned pursuant to this Section.

Audits

Subject to prior coordination with Youleap as to the time, scope, and agenda of the audit, and no more than once per year (unless data protection law or a governmental authority requires otherwise), Youleap shall allow for and contribute to audits, including inspections conducted by Customer or another auditor mandated by Customer, in order to establish Youleap's compliance with this Addendum as regards the personal data Youleap processes on Customer's behalf.

All provisions of this Addendum which by their nature and purpose should persist following termination of the Agreement shall survive and continue to apply after the expiry or termination of the Agreement between the parties, insofar as Youleap continues to hold or process the personal data it processes on Customer's behalf.

Part 2 – GDPR & UK GDPR Addendum

Definitions

Instructions

Controller-Processor Relationship. Youleap shall only Process the Customer Personal Data on behalf of Customer when providing the Service. The parties acknowledge that with regard to the Processing of Customer Personal Data between the parties, Customer acts as the Controller and Youleap acts as the Processor.

Youleap shall Process the Customer Personal Data only on Customer's instructions documented in this Addendum or otherwise provided either in writing or through the options of the Service configurable by Customer ("Instructions"). Any additional or alternate instructions must be agreed upon separately through prior written agreement between Customer and Youleap. The foregoing applies unless Youleap is otherwise required by law to which it is subject (and in such a case, Youleap shall inform Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest).

If Youleap believes that compliance with any of Customer's instructions infringes Data Protection Laws, Youleap shall immediately notify Customer thereof.

Security

Security Controls. Youleap shall implement appropriate technical and organizational measures to protect and safeguard the Customer Personal Data that is processed as part of the Service against Personal Data Breaches (as defined under the Data Protection Laws). The technical and organizational measures are specified in Part 3.

Compliance Demonstration by Youleap

Youleap will make available to Customer all necessary information at its disposal to demonstrate compliance with the obligations under the Data Protection Laws.

Cross-Border Transfers

Without limiting the sub-processor appointment procedure in Part 1, Youleap and its sub-processors will only Process Customer Personal Data in member states of the European Economic Area or in territories or territorial sectors recognized by an adequacy decision of the European Commission as providing an adequate level of protection for personal data pursuant to Article 45 of the GDPR, or using adequate safeguards as required under Data Protection Laws governing cross-border data transfers (e.g., EU SCC or UK Addendum, as applicable). Youleap must inform Customer at least 10 business days in advance of any materially new cross-border data transfer scenario that involves transfers to jurisdictions not already covered by adequate safeguards, in which case Customer shall have the right to object to that new cross-border data transfer on reasonable grounds related to data protection compliance. If Customer objects, Youleap may not engage in that new cross-border data transfer for the purpose of Processing Customer Personal Data in the provision of the Service.

In the event that the foregoing mechanism for cross-border data transfers is invalidated by an Authority, the parties shall discuss in good faith and agree to such variations (such agreement not to be unreasonably withheld or delayed) to this Addendum as are required to enable valid cross-border data transfers.

Data Protection Impact Assessment

Youleap will assist Customer with the preparation of data protection impact assessments and prior consultation, as appropriate and if needed.

Part 3 – Israeli Law

Definitions

In this Part, the following terms shall be interpreted as follows:

General Provisions

This Part applies to Youleap's own Processing activities regarding the Customer Personal Data. It does not apply to Customer's own Processing activities regarding the Customer Personal Data. Customer is independently responsible for applying appropriate security measures and complying with Applicable Law regarding the Processing activities it performs, configures, or initiates concerning the Customer Personal Data.

Youleap declares and undertakes that during the period it provides the Service to Customer, it shall comply with all provisions of Applicable Law. In this regard, Youleap declares and confirms that it is familiar with Applicable Law.

Customer is the sole owner of the Databases containing the Customer Personal Data, and nothing contained in this Part and/or the Agreement shall be deemed to constitute the grant of proprietary rights to Youleap in the Customer Personal Data.

Youleap's Obligations Regarding the Processing of Customer Personal Data

Youleap shall develop, implement, and enforce an information security policy that shall include at least the following issues (the "Information Security Policy"):

Youleap shall map the operational environment of the Database. Youleap shall prepare an inventory list that includes all the data systems, software, interfaces, hardware components, and communication components that Youleap operates in the Database environment for the ongoing operation of the Database (the "Database Systems"). Youleap shall update the inventory list specified in this Section from time to time and shall only disclose the document to those individuals who require access to it for the performance of their job functions. However, Youleap shall update the aforesaid list in any case in which substantial changes to the operating environment are performed in the Database Systems or in the manner in which data is processed.

Transfer of Customer Personal Data

Youleap shall use accepted encryption mechanisms for each transfer of Customer Personal Data to a third party and for any remote access to the Database Systems.

Retention and Return of Customer Personal Data

Audit, Documentation, and Monitoring

Updating the Information Security Policy

Youleap will conduct discussions regarding Security Incidents at least once a year and assess the need to update the Information Security Policy.

Transfer of Customer Personal Data to Foreign Jurisdictions

Youleap shall act in accordance with the law applicable to the transfer of Customer Personal Data to foreign jurisdictions, including but not limited to the Protection of Privacy Regulations (Transfer of Information to Databases Outside of Israel), 5761-2001.

General Cooperation

Youleap shall fully cooperate with Customer by providing all information and assistance reasonably requested by Customer in connection with data security issues, practices, and supplementary documents, to allow Customer to properly address information security, privacy, and regulatory matters relating to the Database.

Part 4 – California

Scope

This Part 4 applies to any Personal Information subject to Applicable State Privacy Laws that Youleap Processes within the scope of the Service it provides to Customer under the Agreement.

Definitions

Youleap's Obligations

The Parties acknowledge and agree that in processing the Customer Personal Information, Youleap is a "service provider" within the meaning of that term in Applicable State Privacy Laws. To that end, and unless otherwise required by law:

Appendix A – List of Sub-Processors

Sub-Processor (Name and Jurisdiction)Purpose of ProcessingLocation of ProcessingDuration of Sub-Processing
Amazon Web Services, Inc. (USA) / Amazon Web Services EMEA SARL (Luxembourg)Cloud infrastructure and hosting for the ServiceIreland (AWS Region eu-west-1)Duration of the Agreement
Hyp Ltd. (Israel)Payment processing for end-customer transactionsIsraelDuration of the Agreement
Twilio Inc. (SendGrid) (USA)Transactional email delivery to end-customersUSA; EUDuration of the Agreement
Google LLC (USA)Bot protection (reCAPTCHA) on login and registration flowsUSADuration of the Agreement

Contact

Questions about this Addendum or Youleap's data processing practices can be directed to:

eli@youleap.com