This Data Processing Agreement ("DPA") forms part of the agreement for the Yellow Duck service (the "Agreement") between the Customer and Yellow Duck. It sets out how Yellow Duck processes personal data on the Customer's behalf under Article 28 of the GDPR.
1. Parties
- Controller: [Customer legal name], [registration number], [address] (the "Customer").
- Processor: [Company legal name], CVR [number], [address], Denmark ("Yellow Duck").
2. Subject matter and duration
Yellow Duck processes personal data as needed to provide the service: hosting, checking and cataloguing the Customer's internal applications, and letting the Customer's people sign in to them. Processing lasts as long as the Agreement, plus the deletion period in section 10.
3. Nature and purpose
- Running the Customer's apps in the EU and serving them to the Customer's users.
- Checking each version of an app for leaked keys, vulnerable dependencies and code that sends data elsewhere.
- Authenticating users through the Customer's own identity provider (Microsoft Entra ID or Google Workspace).
- Keeping an audit log of who built, deployed, changed, switched off and opened which app.
- Counting which apps are opened, by whom, per day.
- Sending service emails (invitations, notices).
4. Data subjects and categories of data
Data subjects: the Customer's employees and contractors who build or open apps; and any person whose data is held inside an app the Customer hosts, as determined by the Customer.
Categories of data:
- Account data: name, email address, identity-provider identifier, role in the organisation.
- Audit events: actor, action, app, timestamp.
- Usage counters: app, user, day, number of opens. No request logs.
- App source code and any data the Customer's apps store, as uploaded or generated by the Customer.
No special categories of data are required by the service. If the Customer's apps process such data, the Customer is responsible for that decision.
5. Yellow Duck's obligations
Yellow Duck will:
- Process personal data only on the Customer's documented instructions: the Agreement, this DPA, the settings the Customer chooses in the product, and written instructions from the Customer's administrators. Yellow Duck will tell the Customer if an instruction appears to infringe the GDPR.
- Make sure everyone with access to personal data is bound by confidentiality.
- Apply the technical and organisational measures in Annex II.
- Help the Customer respond to data subject requests, and help with the Customer's obligations under Articles 32 to 36 of the GDPR, given the nature of the processing and the information available.
- Notify the Customer's administrators without undue delay, and no later than 48 hours after becoming aware of a personal data breach affecting the Customer's data, with what is known at the time and updates as the picture becomes clearer.
- Delete or return personal data at the end of the Agreement as set out in section 10.
- Make the information needed to demonstrate compliance available, and allow audits as set out in section 9.
6. Sub-processors
The Customer gives general authorisation for Yellow Duck to use the sub-processors listed in Annex III. The current list is always published at yellowduck.[tld]/sub-processors.
Yellow Duck gives the Customer's administrators 30 days' notice by email before adding or replacing a sub-processor. The Customer may object in writing within that period on reasonable data-protection grounds. If the parties cannot resolve the objection, the Customer may terminate the affected part of the service without penalty.
Yellow Duck imposes the same data-protection obligations on each sub-processor as in this DPA, and remains responsible to the Customer for their performance.
7. International transfers
The Customer's apps, their data, the database, backups and audit log stay in the EU.
One exception: the plain-language summary of a check is written by Claude, an AI model operated by Anthropic in the United States. Anthropic receives structured findings only (tool, rule, severity, file path), never source code and never personal data by design. This transfer is covered by Anthropic's Data Processing Addendum with the EU Standard Contractual Clauses. The Customer can disable AI summaries for its organisation at any time in the product settings.
No other transfers outside the EU/EEA take place without the Customer's prior written instruction.
8. Security
Yellow Duck applies the measures in Annex II. A current, plain-language description of the controls is kept at yellowduck.[tld]/trust and is updated when the controls change.
9. Audits
The Customer may audit Yellow Duck's compliance with this DPA once per year, or after a personal data breach, with 30 days' written notice. Yellow Duck may first answer in writing and provide its hosting provider's certifications; if that does not satisfy the Customer, an on-site or remote audit is arranged at a time that does not disrupt the service. The Customer bears its own costs. Both parties keep audit results confidential.
10. Deletion and return
When the Agreement ends, the Customer can export the source code and data of its apps from the product for 30 days. After that, Yellow Duck deletes the Customer's personal data within 30 days, unless EU or Danish law requires it to be kept. Backups expire 30 days after deletion. On request, Yellow Duck confirms deletion in writing.
11. Liability
Liability under this DPA follows the liability terms of the Agreement.
12. Governing law
This DPA is governed by Danish law. Disputes are brought before the courts of Copenhagen, Denmark, unless mandatory law says otherwise.
Annex I — Details of the processing
| Subject matter | Hosting, checking and cataloguing the Customer's internal apps |
| Duration | The term of the Agreement plus the deletion period in section 10 |
| Nature | Hosting, authentication, automated checks, audit logging, usage counting, service email |
| Purpose | Giving the Customer's AI-built apps a place to run behind the Customer's company login |
| Data subjects | The Customer's employees and contractors; persons whose data is inside the Customer's apps |
| Categories of data | Account data, audit events, usage counters, app source code and app data |
| Location | EU (Germany, Finland), except AI summaries as described in section 7 |
Annex II — Technical and organisational measures
- Access control: users sign in through the Customer's identity provider (OpenID Connect). Every request to an app is checked at the edge; sessions that have been logged out are refused within 30 seconds. Yellow Duck staff access production only through named accounts with hardware-key two-factor authentication.
- Isolation: each app runs in its own container with its own network, a read-only filesystem, all Linux capabilities dropped, no privilege escalation and CPU, memory and process limits.
- Checks: every version of an app is scanned for leaked secrets, vulnerable dependencies and outbound data flows before it goes live. Findings are kept per version.
- Encryption: TLS on every hostname; data at rest on encrypted volumes at the hosting provider.
- Logging: an audit log of actions on apps, per organisation, with actor and timestamp. Usage is stored as daily counters, not request logs.
- Availability: daily encrypted database backups kept for 30 days in the EU; restore tested quarterly.
- Off switch: the Customer's administrators can switch off any app; it stops answering within 30 seconds.
- Deletion: deleting an app removes its container, image and database rows.
- Vulnerability handling: dependencies of the service are checked with the same tools; a public security contact is kept at yellowduck.[tld]/trust.
Annex III — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting of the service, app containers, database, object storage and backups | Germany, Finland |
| Scaleway SAS | Transactional email | France |
| Anthropic, PBC | Plain-language summaries of check results (structured findings only) | United States, under Standard Contractual Clauses |
The current list, with the data each sub-processor receives and the safeguards in place, is published at yellowduck.[tld]/sub-processors.