Data Processing Addendum
Last updated October 2026 · Effective 2026-10-02 · Version 2
What changed: Yaap now runs on Railway, with uploaded files stored by Tigris underneath it, in place of Replit; the subprocessor list in the Privacy Policy and the Data Processing Addendum names them. Nothing else changes.
Parties and roles
This Data Processing Addendum ("addendum") is between BlackHoodie LLC, of 7 Adeline Drive, North Haven, CT 06473, which operates Yaap at yaapai.com ("Yaap", "we", "us"), and the business that uses Yaap ("you"). It is part of the Terms of Use and applies to every workspace. You do not have to sign anything separate.
It says how we handle the personal data you put into Yaap about other people — your customers, your leads, the people who fill in your forms, the people you text and email, and the people who sign your estimates and documents.
For that data you are the controller and we are your processor. You decide what data goes into Yaap, why it is there, and what happens to it. We process it only to run the service for you.
For our own data — the account, sign-in, billing, support, and product-usage records we keep about you and your workspace members — we are the controller. That data is covered by our Privacy Policy, not by this addendum.
In short, each side is responsible for this:
- You: have a lawful basis and any consent needed for the data you load and the messages you send; keep it accurate; answer the privacy requests your own customers make; give us instructions that comply with the law; manage who in your workspace can see what, using the OWNER, ADMIN, and MEMBER roles.
- We: process the data only on your instructions and only to provide Yaap; keep it confidential; secure it; use only the subprocessors listed below; help you meet your own obligations; and delete or return the data when the service ends.
Words like "personal data", "consumer", "controller", "processor", and "sale" have the meanings given in the Connecticut Data Privacy Act. Where another state's privacy law uses a different word for the same idea — "personal information", "business", "service provider", "third party" — read this addendum as using that state's word too.
Subject matter, duration, nature, and purpose of the processing
Subject matter. The personal data you and your workspace members store in, send through, or receive into Yaap.
Nature of the processing. We collect, store, organise, display, transmit, back up, and delete that data so the product works. Concretely, that means: keeping customer, lead, deal, note, task, inventory, and file records; sending and receiving text messages through Telnyx on the number registered to your business under 10DLC; sending and receiving email through Resend; creating estimates, invoices, subscriptions, and documents, and recording electronic signatures on estimates and documents with a typed or drawn signature, a timestamp, and the signer's IP address; publishing hosted forms and storing what people submit; running the automations you build; answering API and webhook calls made with your keys; and sending the content you point it at to Anthropic so the AI assistant can act on an instruction you typed or texted.
Purpose. One purpose only: providing, securing, and supporting Yaap for you, and doing what you instruct us to do inside it. We do not use the data for our own purposes. We do not sell it. We do not use it for advertising of any kind, ours or anyone else's. We do not combine it with data from other customers or from outside sources to build profiles. We do not use your personal data to train large language models, and our AI provider does not train its models on the content we send it.
Duration. For as long as your workspace exists, and then for the period described in "Deletion or return at the end of the service" below. Some records survive that period only where the law requires us to keep them; those are listed in the retention section of the Privacy Policy.
Categories of data subjects and personal data
Whose data. Depending on how you use Yaap:
- your customers and the people who work for them;
- your leads, including people who submit one of your hosted forms;
- people who receive text messages or email you send through Yaap, and people who text or email your number or address;
- people who view, accept, sign, or decline your estimates and documents;
- your own employees and contractors, where you store records about them as customers, contacts, or assignees.
What data. Again depending on your use:
- identifiers and contact details — name, business name, email address, mobile and other phone numbers, postal address;
- message content — the full text of the SMS and email you send and receive through Yaap, with delivery status and timestamps;
- commercial records — deals, pipeline stage, estimates, invoices, line items, inventory, subscriptions, payment status, and the Stripe identifiers that link an invoice to a payment;
- documents and e-signature records — the document content, the typed or drawn signature, the signer's name and email, the time of signing, the signer's IP address, and the rest of the signing audit trail;
- form submissions and uploaded files, including the submitter's IP address, which we record with every submission to one of your hosted forms;
- free-text you or your team write — notes, tasks, custom fields, and anything typed into the AI assistant.
Data we ask you not to put in. Yaap is built for ordinary business contact and transaction records. Do not store Social Security numbers, driver's licence or passport numbers, financial account or card numbers, log-in credentials, health or medical information, precise geolocation, or data about children in Yaap — including in notes, custom fields, uploaded files, or the AI assistant. If you do, you do it on your own instruction and at your own risk, and we may ask you to remove it.
Your instructions and our duty to follow them
We process personal data only on your documented instructions. Your instructions are:
- the Terms of Use and this addendum;
- the settings you choose in your workspace — pipelines, templates, automations, forms, roles, and integrations;
- every action you or a member of your workspace takes in the app, through the REST API with one of your API keys, through an automation you built, or by texting the AI assistant, which acts on instructions typed or texted by your owner, admins, and members;
- any further written instruction you send us and we agree to.
We will not process the data for any other reason. If we believe an instruction would break a privacy law that applies to either of us, we will tell you, and we may refuse to carry it out until the point is settled.
We may also process personal data where the law requires it — for example to answer a valid legal demand or to meet a record-keeping duty. If that happens we will tell you first, unless the law forbids us to.
You are responsible for the instructions you give. That includes having the consent needed for the texts and email you send, honouring opt-outs, and making sure the data you load into Yaap was lawfully collected.
Confidentiality
Everyone who can reach personal data we process for you is bound to keep it confidential, by contract or by a duty of employment. That duty carries on after the person stops working with us.
Access to live customer data is limited to the small number of people who need it to operate the platform or to support you, and to the systems that run the product itself. We do not use your data to build a mailing list, and we do not disclose it to anyone except the subprocessors listed below, someone you tell us to send it to, or a lawful demand we must answer.
Security measures
We follow industry-standard security practices that are appropriate to the size of our business and the sensitivity of ordinary business contact records. The measures in place today include:
- Encryption. Traffic to Yaap is encrypted in transit. Each workspace's secrets — the credentials and keys it stores — are encrypted at rest under a key derived for that workspace alone.
- Tenant separation. Every record we store carries the workspace it belongs to, and the application scopes every query we run on your behalf to your own workspace, so one workspace's records are not returned to another.
- Access control. Sign-in is by a one-time code emailed to you; we never store account passwords. Inside a workspace, the OWNER, ADMIN, and MEMBER roles decide what each person can do, and permissions are checked on the server for every action, whether it comes from the app, the API, an automation, or the AI assistant.
- Keys and integrations. API keys are stored hashed, shown once, and can be revoked at any time. Outbound webhooks are signed so you can verify they came from us.
- Logging. Every action taken through the platform's tool layer is written to an audit log with the actor, the workspace, and the result, including failures. In the product, the activity timeline on a customer record shows you the recent entries for that customer. Ask through the privacy request form for the entries for your workspace and we will send them to you.
- Abuse controls. Rate limits apply to sign-in, public forms, the AI assistant, and the API.
We may change these measures as the product changes, but we will not reduce the overall level of security while this addendum is in force.
Subprocessors
You authorise us to use the subprocessors below to provide Yaap. Each is engaged under a written contract that requires it to meet the same obligations we owe you for your data, and each may use the data only to provide its service to us.
| Subprocessor | What it does | Where it processes | Its privacy policy |
|---|---|---|---|
| Railway Corporation | Application hosting and file storage | United States | Railway Corporation privacy policy |
| Tigris Data, Inc. | Object storage underneath Railway Buckets (uploaded files) | United States | Tigris Data, Inc. privacy policy |
| Neon (Databricks, Inc.) | PostgreSQL database hosting | United States (AWS us-east-1) | Neon (Databricks, Inc.) privacy policy |
| Stripe, Inc. | Subscription billing and payments you collect | United States | Stripe, Inc. privacy policy |
| Telnyx LLC | Text messaging and phone numbers | United States | Telnyx LLC privacy policy |
| Resend, Inc. | Transactional email delivery and receiving | United States | Resend, Inc. privacy policy |
| Anthropic, PBC | AI assistant (Claude API) | United States | Anthropic, PBC privacy policy |
This version of our documents took effect on 2026-10-02; the list above is the list in force on that date.
Notice before we add one. Before we add or replace a subprocessor, we send a material-change notice by email to the owners of every workspace. The notice says what is changing and gives an effective date at least 30 days after we send it.
How to object. If you do not accept a new subprocessor, tell us at support@support.yaapai.com and stop using the service before the effective date in that notice: cancel your subscription and delete your workspace, as described in Cancellation and refunds. Ending the agreement before the effective date in that notice is your remedy for an objection. There is no refund for a period already paid. If you are still using Yaap on the effective date in that notice, the new subprocessor applies.
We stay responsible to you for what our subprocessors do with your data, on the same terms as if we had done it ourselves.
Assistance with rights requests, security, breaches, and assessments
We help you meet your own obligations as a controller, insofar as is possible, taking into account how we process the data and what information we have.
Rights requests from your customers. A request about records in your workspace is yours to answer — you are the controller. Yaap gives you the tools: search and open any record, edit it, archive it, void an estimate, invoice, or document, and export customers, invoices, and estimates as CSV whenever you can sign in to the workspace. Archiving hides a record from your workspace but keeps the row, so where a consumer asks you to erase a specific record, ask us through the privacy request form and we will erase it for you. If someone sends us a request about your records instead of sending it to you, we tell them it is your decision, forward the request to you, and give you what we hold that you need to answer it. Ask us for anything else you need through the same form.
Requests that come to us. The privacy request form is our online request mechanism; a request that reaches us another way is logged there too, and no request is refused for arriving by another route. Where we are the controller — the account, sign-in, billing, support, and product-usage records described in Parties and roles — we answer within the statutory windows: 45 days for access, correction, deletion, and portability, extendable once by a further 45 days if we give the reason inside the first 45; 15 days to act on an opt-out of sale or targeted advertising, and 15 days to stop processing after consent is revoked; and 60 days to answer an appeal in writing with our reasons. If we deny an appeal we tell the person how to complain to the Connecticut Attorney General online. Requests are free once in any 12 months. Where the request is about records in your workspace, those clocks are yours, not ours, because you are the controller; our job is to forward it to you and help you answer it.
Security of processing. We help you meet your own security obligations by giving you the description of our measures above, the audit-log entries for your workspace on request through the privacy request form, and answers to reasonable security questions about how we handle your data.
Breach notice. If we discover a breach of security affecting personal data we process for you, we notify you immediately — you are the owner of that data — with what we know at the time: what happened, what data was involved, what we are doing about it, and what we recommend you do. Immediate notice on discovery is the standard that applies to that data, and the Terms of Use adopt it by pointing to this addendum for it. We keep you updated as we learn more, and we help you make any notice you have to give. We do not notify your customers on your behalf unless you ask us to and we agree in writing. Separately, where we are the controller of the data involved, we notify affected Connecticut residents no later than 60 days after we discover the breach and notify the Connecticut Attorney General no later than we notify residents.
Data protection assessments. If you have to carry out and document a data protection assessment, we give you the information in our possession that you need for it, insofar as is possible.
Deletion or return at the end of the service
At the end of the service, at your direction, we delete or return the personal data we process for you, unless the law requires us to keep it.
Return. You can export your customers, invoices, and estimates as CSV from inside Yaap whenever you can sign in to the workspace. Download your signed estimates and documents from the record they belong to. If you need data we do not have an export button for, ask through the privacy request form and we will get it to you in a usable format.
Deletion. What you can remove yourself depends on the record. Notes, forms, and webhooks can be deleted outright in the app, and that deletion is permanent. An API key can be revoked, which stops it working straight away, but its record stays in the database. Customers, deals, and inventory items are archived instead: archiving takes the record out of your lists and out of use, but the row and the personal data in it stay in the database. Leads cannot be archived or deleted in the app at all. Estimates, invoices, and documents are voided rather than erased, because they are financial and signed records. Messages, form submissions, and audit entries have no delete control at all today.
So there are two ways to erase personal data rather than archive it: delete the whole workspace, which removes everything in it, or ask us to erase a specific record through the privacy request form, which we do for you.
What survives. Deleting your workspace removes what is in it. Where the law requires us to keep a record anyway — tax and payment records, and anything we are told to preserve for a legal claim or an investigation — we keep only that. The retention section of the Privacy Policy lists what is kept and for how long.
What deletion means today
Deleting your workspace deletes its data immediately and permanently, and it cannot be undone. There is no grace period and no copy for us to restore from. Export everything you need, including signed estimates and documents, before you delete a workspace.
Records of what you agreed to
A small set of records survives the deletion of your workspace, because the law requires us to keep proof of what you agreed to and when: the record of your acceptance of these documents and of any consent to recurring charges. Those records identify you and your workspace; they do not contain your customers' records. The retention section of the Privacy Policy lists what is kept and for how long.
Audit and information rights
On your reasonable request, we make available the information in our possession that you need to show you are meeting your own obligations: this addendum, the subprocessor table above, the description of our security measures, written answers to reasonable questions about how we process your data, and the audit log of everything done in your workspace — the actor, the action, and the result — which we send you on request through the privacy request form. In the product itself, the activity timeline on a customer record shows you the recent entries for that customer.
Assessments of our processing. This is different from the help with data protection assessments described in Assistance with rights requests, security, breaches, and assessments, which is not limited to once a year and is not at your cost. We allow and cooperate with a reasonable assessment of our processing, on these terms: once in any 12 months, unless a law or an actual security breach affecting your data requires another; on at least 30 days' written notice to support@support.yaapai.com; during normal business hours; without disrupting the service; at your cost; and limited to information about your own data, never another customer's data and never systems we do not run.
Instead of that, we may arrange for a qualified, independent assessor to assess our policies and technical and organisational measures against an appropriate and accepted control framework, and give you the report on request. We do not hold a third-party audit report or a security certification today. If we obtain one, providing it will satisfy this section.
Liability
Everything in the Terms of Use about disclaimers, limitation of liability, and indemnification applies to this addendum. The cap in the Terms is a single, shared cap: claims under the Terms and claims under this addendum count against the same limit, and this addendum does not create a second one.
You are responsible for the personal data you put into Yaap, for the lawfulness of the instructions you give us, and for the messages you send. We are responsible for processing that data as this addendum says we will.
Governing law and venue
This addendum is governed by the laws of the State of Connecticut, without regard to its conflict-of-laws rules, and the exclusive venue for any dispute about it is the state or federal courts sitting in Connecticut. There is no arbitration clause. This matches the governing law and venue section of the Terms of Use, and if the two ever differ, the Terms govern.
How this fits with our other documents
This addendum is part of the Terms of Use and is incorporated into them by reference. It adds to the Terms; it does not replace them. Where both describe the same thing, read them together.
The order of precedence is set out in the General section of the Terms: the Terms come first, then this addendum, then the SMS program terms. The Privacy Policy describes what we do; it is not a contract term and does not change this addendum.
This addendum carries the same version number and effective date as our other legal documents, shown at the top of this page. We change it the same way we change the Terms: notice to workspace owners by email at least 30 days before the new version takes effect. Questions about this addendum go to support@support.yaapai.com; formal legal notices go to BlackHoodie LLC, 7 Adeline Drive, North Haven, CT 06473.