Last Updated: September 2026

1. Parties and Roles

This Data Processing Agreement (“DPA”) forms part of the Terms of Service. The client is the controller of the personal data inside its own systems, such as mailboxes, contact lists, marketing platforms, websites and DNS zones. The Provider named in the client’s order, quote or invoice is the processor:

  • For clients based in the United States: Yeevu LLC, a limited liability company formed in Wyoming, USA (Wyoming Secretary of State filing ID 2025-001686358), 30 N Gould St Ste R, Sheridan, WY 82801, USA.
  • For clients in the United Kingdom and every other country: TK WebHosts Ltd, a private limited company registered in England and Wales (Companies House company number 10252550), 20-22 Wenlock Road, London N1 7GU, United Kingdom.

2. Subject Matter, Nature and Duration

The Provider processes personal data only to deliver the services the client has ordered, such as email, domain, DNS, website, AI automation and support work. The personal data concerned is typically names, email addresses, message content and metadata, and contact records relating to the client’s staff, customers and contacts. Processing lasts for the engagement and ends when working data is deleted under section 8.

3. Processing on Documented Instructions

The Provider processes personal data only on the client’s documented instructions, which are the order, quote or written scope and any later instruction confirmed in writing, and does not use it for any other purpose. If an instruction appears to breach data protection law, the Provider tells the client before acting on it.

4. Confidentiality of People

Everyone who works on the engagement is bound by confidentiality obligations.

5. Security Measures

The Provider applies appropriate technical and organisational measures, including access limited to what the work needs, multi-factor authentication, encrypted credential storage and transport encryption, and captures the existing configuration before making changes so that they can be reversed.

6. Sub-processors

The Provider uses a limited set of service providers in these categories: hosting and cloud infrastructure, domain registrars and DNS providers, email infrastructure and deliverability tooling, payment processing, and business tools such as password management and ticketing. The current named list is provided on request before an engagement starts. Each sub-processor is bound by data protection terms no less protective than this DPA, and the Provider remains responsible for it. The client is told before a new sub-processor handles its personal data and may object on reasonable grounds.

7. Personal Data Breaches

The Provider notifies the client without undue delay after becoming aware of a personal data breach affecting the client’s data, with what is known, what has been done and what is recommended, and cooperates with any notification the client must make.

8. Deletion and Return

When an engagement ends, the Provider deletes the client’s personal data it holds, or returns it first if the client asks, unless the law requires it to be kept. Credentials provided for the work are not kept once the engagement ends.

9. Assistance, Records and Audits

The Provider helps the client respond to requests from individuals exercising their data protection rights, and with security, breach and impact assessment obligations, as far as the engagement’s processing is concerned. It makes available the information needed to show compliance with this DPA and answers reasonable audit questions in writing.

10. International Transfers

Where personal data from the United Kingdom or the European Economic Area is processed outside it, the transfer is made under a recognised safeguard: the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, as applicable.

11. Signed Copies

Organisations that need this DPA in signed form can request it at admin@yeevu.com.

© Yeevu LLC. All Rights Reserved.