Data protection
Data Processing Addendum
Last updated: 1 August 2026 · v2026-08-01
Who this is for
This addendum is for organisations, such as employers, leadership teams, and advisory firms, that use Yurify on behalf of their own people and need GDPR Article 28 terms in place. If you use Yurify as an individual, our privacy policy is the governing document.
1. Parties and roles
The customer acts as data controller. Yurify Pte. Ltd. (UEN 202619993N, 168 Robinson Road, #20-01, Capital Tower, Singapore 068912) acts as data processor and processes personal data only on the customer's documented instructions.
2. Subject matter and duration
Subject matter: providing the Yurify Communication Intelligence service. Duration: the term of the customer's subscription, plus the deletion window described in section 10.
3. Nature and purpose of processing
Secure storage, AI-assisted analysis of message text and conversation metadata, and return of structured insight to the customer's authorised users.
4. Categories of data and data subjects
- Data subjects: the customer's authorised users, and individuals named or quoted in the material those users submit.
- Categories: account identifiers, message and conversation content submitted for analysis, AI-generated insight, and usage metadata.
- Customers must not submit special category data, such as health or biometric information, unless they have a lawful basis to do so.
5. Sub-processors
The customer authorises the sub-processors listed on our sub-processors page. We give at least 15 days' notice before adding a new one, and the customer may object on reasonable data protection grounds.
6. International transfers
Where personal data relating to EU, UK, or Swiss data subjects moves outside their jurisdiction, the transfer relies on the EU Standard Contractual Clauses (2021) Module Two, the UK International Data Transfer Addendum, and equivalent Swiss measures, each incorporated into this addendum by reference.
7. Security measures
We maintain encryption in transit (TLS 1.2 or higher), encryption at rest, least-privilege access, row-level security on every application table, audit logging of sensitive actions, managed secret storage for provider keys, and a documented incident response process. Further detail is on our trust and security page.
8. Personal data breaches
We notify the customer without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting their data, with the information required by GDPR Article 33(3).
9. Data subject rights
We assist the customer in responding to access, rectification, erasure, portability, and objection requests within reasonable cost and timeframes. Individual users can also exercise these rights directly from the your data and rights page, or by writing to info@yurify.co.
10. Return and deletion of data
On termination we delete the customer's personal data within 30 days, except where retention is required by law or to establish, exercise, or defend legal claims.
11. Audits
Once per year, the customer may request a written attestation of compliance with this addendum together with our most recent security assessment summary. On-site audits are available with reasonable notice and a confidentiality undertaking.
12. Acceptance
If you need a counter-signed copy, write to info@yurify.co with your entity name and registered address and we will return a signed PDF.
