YOKITUP – PERSONAL DATA PROCESSING TERMS AND PRIVACY POLICY

Version 2.0 – Date: 13/08/2026

Subscription by the Client to a contract with YOKITUP implies acceptance without reservation of YOKITUP’s General Terms of Service (“GTS”) and these Personal Data Processing Terms and Privacy Policy (the “Data Processing Terms”).
These Data Processing Terms also describe, in a transparent manner, how personal data may be processed when using the YOKITUP Solution, including through its APIs, applications, connectors and integrations with third-party services.

# PREAMBLE

Capitalised terms used in these Data Processing Terms shall have the same meaning as in the GTS.
Terms such as “processing”, “personal data”, “controller”, “processor”, “sub-processor” and “personal data breach” shall have the meaning given to them by:
* Regulation (EU) 2016/679 of 27 April 2016 (the “GDPR”);* French Law No. 78-17 of 6 January 1978 relating to information technology, files and civil liberties, as amended (the “French Data Protection Act”); and* any applicable implementing legislation,
together referred to as the “Data Protection Legislation”.
YOKITUP provides a software solution for stock management, supplier purchasing, inventory management and other operational management services for restaurants, caterers and other food-service businesses (the “Solution”).
In this context, YOKITUP (the “Processor”) may process Personal Data on behalf of the CLIENT (the “Controller”), which determines the purposes and means of such processing.
The Solution may be accessed directly or through applications, APIs, connectors or integrations with third-party services. Where a Client or an authorised user chooses to use such an integration, certain information may be exchanged between YOKITUP and the relevant third-party service solely to provide the functionality requested by the Client or user, as further described in these Data Processing Terms.
These Data Processing Terms supersede any previous agreement or provision between the Parties relating to the processing of Personal Data, including provisions contained in YOKITUP’s GTS.
In the event of a conflict between the GTS and these Data Processing Terms regarding Personal Data, these Data Processing Terms shall prevail.
This Preamble forms an integral part of these Data Processing Terms.
# ARTICLE 1 – PURPOSE
## 1.1
The purpose of these Data Processing Terms is to define the conditions under which the Processor undertakes to process Personal Data on behalf of the Controller, including the processing operations described in Annex 1.
## 1.2
If the Client itself acts as a processor rather than as a controller, the Client represents that its instructions and actions, including the appointment of YOKITUP as a sub-processor, have been authorised by the relevant controller.
For the purpose of these Data Processing Terms, whether the Client acts as a controller or processor, it shall be referred to as the “Controller”.
## 1.3
These Data Processing Terms also provide information regarding Personal Data processed through the Solution’s applications, APIs, connectors and integrations.
The exact information processed depends on the functionality requested by the Client or authorised user and on the configuration of the Client’s YOKITUP account.
# ARTICLE 2 – DURATION
The commitments made by the Parties under these Data Processing Terms shall take effect, where applicable retroactively, from the effective date of the Contract in accordance with the GTS.
They shall continue to apply throughout the contractual relationship between the Parties and thereafter where expressly provided for in these Data Processing Terms or the Contract.
# ARTICLE 3 – OBLIGATIONS OF THE PROCESSOR
## 3.1 General data protection principles
### 3.1.1 Confidentiality
The Processor undertakes to maintain the confidentiality of Personal Data processed in connection with the performance of the Contract.
The Processor shall ensure that persons authorised internally to process Personal Data are subject to appropriate confidentiality obligations.
### 3.1.2 Privacy by design and by default
The Processor undertakes to take into account, for all tools, products, applications, APIs, integrations and services implemented in connection with the Services, the principles of data protection by design and by default as provided for in Article 25 of the GDPR.
Personal Data processed and exchanged shall be limited to information reasonably necessary for the requested functionality.
## 3.2 Compliance with the Controller’s instructions
### 3.2.1
In connection with the performance of the Services, the Processor processes Personal Data on behalf of the Controller.
The Processor shall not process Personal Data transmitted by the Controller and/or collected directly through its tools, products, applications, APIs, integrations or services for purposes other than the provision, operation, security and support of the Services, in accordance with the Contract and the Controller’s documented instructions.
The Processor shall process Personal Data in accordance with these Data Processing Terms and the documented instructions of the Controller, including Annex 1.
An instruction may result from an action expressly initiated by an authorised user of the Controller through the Solution or through an authorised integration.
### 3.2.2
If the Processor considers that an instruction infringes applicable Data Protection Legislation, it shall inform the Controller without undue delay.
### 3.2.3
If the Processor is required by European Union or Member State law to transfer Personal Data to a third country or international organisation, the Processor shall inform the Controller of that legal requirement before processing unless the applicable law prohibits such information on important grounds of public interest.
## 3.3 Data security
The Processor undertakes, in accordance with Article 32 of the GDPR, to implement appropriate technical and organisational measures to ensure a level of confidentiality, security and integrity appropriate to the risks associated with the processing, taking into account the state of the art, implementation costs, scope, context, purposes and risks of the processing.
The Solution is not intended to collect or process special categories of Personal Data within the meaning of Article 9 of the GDPR unless such processing has been specifically agreed and is lawful.
Integrations provided through the Solution are not designed to request passwords, authentication secrets, API keys, MFA or one-time authentication codes, payment card data, government identification numbers or health information.
Users must not submit such information through free-text fields, integration requests or other inputs unless expressly required and supported by a YOKITUP feature designed for that purpose.
The technical and organisational security measures implemented by YOKITUP are further described in Annex 2.
## 3.4 Personal Data breaches
In order to enable the Controller to comply with its notification and communication obligations under Articles 33 and 34 of the GDPR, the Processor shall notify the Controller of any security incident identified as a Personal Data breach within the meaning of the applicable Data Protection Legislation without undue delay after becoming aware of it.
The Controller remains responsible for determining whether an incident constitutes a Personal Data breach requiring notification to a competent supervisory authority and, where applicable, communication to affected data subjects.
## 3.5 Sub-processing
The Controller expressly grants the Processor general authorisation to use sub-processors for the processing of Personal Data on behalf of the Controller.
The Processor shall ensure that its sub-processors provide sufficient guarantees to ensure that the processing entrusted to them complies with applicable Data Protection Legislation.
The Processor shall inform the Controller of any intended addition or replacement of a sub-processor.
The Controller may object to such changes. Where an objection prevents YOKITUP from continuing to provide all or part of the Services, the Parties shall seek a commercially reasonable solution in accordance with Article 7.
The addition or replacement of a sub-processor in accordance with this Article shall not in itself constitute a breach of the Contract or these Data Processing Terms.
## 3.6 Transfers outside the European Union
The Controller expressly grants the Processor general authorisation to transfer Personal Data outside the European Union where necessary for the provision of the Services.
Where such a transfer occurs, the Processor undertakes to comply with Articles 44 to 49 of the GDPR and to implement an appropriate transfer mechanism so that the level of protection guaranteed by applicable Data Protection Legislation is not undermined.
The Controller may object to a transfer. Where such objection prevents the provision of all or part of the Services, the Parties shall seek a commercially reasonable solution in accordance with Article 7.
A transfer carried out in accordance with applicable Data Protection Legislation shall not in itself constitute a breach of the Contract or these Data Processing Terms.
## 3.7 Data subject rights
The Processor shall provide reasonable assistance to the Controller in enabling the Controller to respond to requests from data subjects exercising their applicable rights, including, as applicable:
* right of access;* right to rectification;* right to erasure;* right to restriction of processing;* right to data portability;* right to object; and* any other right provided by applicable Data Protection Legislation.
Where a YOKITUP user exercises rights relating to Personal Data controlled by the Client, the request should ordinarily be addressed to the Client or the relevant administrator of the Client’s YOKITUP account.
YOKITUP shall reasonably assist the Client in handling such requests.
## 3.8 Assistance by the Processor
Where applicable, the Processor shall provide reasonable assistance to the Controller, at the Controller’s expense and, where appropriate, subject to a prior quotation, in connection with:
1. a data protection impact assessment under Article 35 of the GDPR; and/or2. prior consultation with the competent supervisory authority.
## 3.9 Records of processing activities
The Processor maintains a written record, in accordance with Article 30(2) of the GDPR, of the categories of processing activities carried out on behalf of Controllers.
## 3.10 Personal Data following termination of the Contract
For a period of thirty-six (36) months following termination of the Contract, regardless of the reason for termination, the Controller may request a copy of the Personal Data processed on its behalf in an interoperable `.csv` format where technically applicable.
At the end of this period, the Processor shall delete or anonymise such Personal Data, subject to information that must be retained for a longer period pursuant to applicable law.
Backup copies and technical logs may remain for the limited retention periods described in Annexes 1 and 2 before being automatically deleted or overwritten.
## 3.11 APIs, connectors, AI assistants and third-party integrations
The Solution may enable Clients and authorised users to connect YOKITUP to third-party applications and services, including point-of-sale systems, accounting systems, business intelligence tools, automation platforms and artificial intelligence assistants such as ChatGPT.
The use of such integrations is optional and is initiated or authorised by the Client or an authorised user.
When an integration is used, YOKITUP may receive information from the third-party service and may return information from the Client’s YOKITUP account to that third-party service where necessary to perform the requested action.
### Data that may be received
Depending on the integration and the user’s request, YOKITUP may receive:
* information required to identify and authorise the YOKITUP account, organisation or location concerned;* identifiers and parameters relating to the requested operation;* search terms, filters, dates, quantities or other parameters entered or selected by the user;* business information submitted by the user in connection with the requested functionality;* limited user or account information required for authentication, authorisation, access control and security; and* where the integration supports natural-language interactions, the specific instructions or portions of content necessary to understand and execute the user’s request.
YOKITUP does not require an integration to provide the user’s entire conversation history where this is not necessary to perform the requested functionality.
### Data that may be returned
Depending on the user’s request and access rights, YOKITUP may return:
* the records or business information requested by the user;* results of searches or calculations;* summaries derived from information held in the Client’s YOKITUP account;* status information necessary to confirm whether an operation has been completed;* confirmations of actions created, modified or deleted at the user’s request; and* limited Personal Data contained in the Client’s account where such information is relevant and necessary for the requested operation.
Responses are intended to contain only information relevant to the user’s request and the functionality being performed.
YOKITUP does not intentionally include internal diagnostic information, authentication secrets, API keys or unrelated technical identifiers in integration responses.
### Purpose of such processing
Information exchanged through integrations is processed for the purposes of:
* authenticating and authorising the requesting user;* identifying the appropriate Client account, organisation or location;* retrieving information expressly requested by the user;* executing actions expressly requested by the user;* returning the requested result;* protecting the security and integrity of the Solution;* preventing unauthorised access;* troubleshooting and debugging technical issues; and* maintaining service reliability.
YOKITUP does not use information received solely through an integration for purposes unrelated to providing, securing or supporting the YOKITUP Services unless another lawful basis and appropriate notice apply.
### Third-party recipients
Where a Client or authorised user intentionally uses a third-party integration, information necessary to fulfil the requested operation may be disclosed to the provider of that third-party service.
For example, when an authorised user accesses YOKITUP through ChatGPT, information requested from YOKITUP and returned in response to the user’s instruction may be transmitted to and processed by OpenAI as the provider of ChatGPT.
Such transmission occurs as part of the functionality selected by the Client or authorised user.
Third-party services may process information under their own terms and privacy policies. Their independent processing is outside YOKITUP’s control.
Clients and users should review the privacy and data-processing terms of third-party services before enabling or using an integration.
### User controls
Subject to the technical functionality available for the relevant integration, Clients and authorised users may control integration access by:
* choosing whether or not to use a third-party integration;* limiting the actions they request through an integration;* managing user access and permissions within their YOKITUP organisation;* disconnecting or revoking access to an integration where such functionality is available;* requesting that their organisation administrator modify or revoke their access; and* exercising applicable data protection rights through the Controller.
Revoking an integration prevents future access through that integration but does not automatically delete information previously transmitted to and independently retained by the third-party provider. Such information is subject to that provider’s own retention and deletion rules.
# ARTICLE 4 – RIGHTS AND RESPONSIBILITIES OF THE CONTROLLER
The Controller is primarily responsible for:
1. providing required information to data subjects regarding processing activities carried out on its behalf;2. determining the purposes and means of the processing;3. ensuring that users are appropriately authorised to access the Solution;4. determining which integrations may be enabled for its organisation;5. ensuring that the use of integrations complies with its own internal policies and applicable law; and6. responding to requests relating to the exercise of data subject rights.
The Processor may assist the Controller in accordance with Article 3.7.
# ARTICLE 5 – DATA PROTECTION CONTACT
Where applicable, each Party shall provide the other Party with the name and contact details of its Data Protection Officer, if appointed, or of the person responsible for Personal Data protection matters.
Questions relating to YOKITUP’s processing of Personal Data may also be submitted through YOKITUP’s usual support or contact channels.
# ARTICLE 6 – DOCUMENTARY AUDIT RIGHTS
The Processor shall make available to the Controller the information reasonably necessary to demonstrate compliance with applicable Data Protection Legislation in relation to the Personal Data processing activities covered by these Data Processing Terms and described in Annex 1.
# ARTICLE 7 – TERMINATION
## 7.1
The Contract may be terminated in accordance with the applicable provisions of YOKITUP’s GTS if:
* a Party breaches its obligations under these Data Processing Terms and fails to remedy such breach within one (1) month after receiving formal notice requiring it to do so; or* a Party fails to comply with a binding decision of a competent court or supervisory authority regarding its obligations under these Data Processing Terms and/or applicable Data Protection Legislation.
## 7.2
The Contract may also be terminated in accordance with the applicable provisions of YOKITUP’s GTS if:
* after the Processor has informed the Controller that an instruction infringes these Data Processing Terms and/or applicable Data Protection Legislation, no commercially acceptable solution is found by the Parties within one (1) month;* the Controller objects to the appointment or replacement of a sub-processor pursuant to Article 3.5 and no commercially acceptable solution is found within one (1) month; or* the Controller objects to a transfer pursuant to Article 3.6 and no commercially acceptable solution is found within one (1) month.
## 7.3
Termination of the Contract, for any reason, shall automatically terminate these Data Processing Terms, subject to provisions that by their nature survive termination.
## 7.4
The Parties shall remain bound by these Data Processing Terms until their termination and shall thereafter comply with any surviving obligations, including the rules relating to return, retention, deletion and anonymisation of Personal Data set out in Article 3.10.
## 7.5
The liability of each Party in respect of Personal Data shall be determined in accordance with Article 82 of the GDPR and the other applicable provisions of the Contract.
---
# ANNEX 1 – DESCRIPTION OF PERSONAL DATA PROCESSING OPERATIONS
## 1. Categories of data subjects
Personal Data may relate to:
* users of the Solution;* employees, contractors and authorised representatives of the Controller;* administrators of the Controller’s YOKITUP organisation;* supplier or customer contacts where their information is entered into the Solution by the Controller; and* other individuals whose information the Controller lawfully chooses to process through the Solution.
## 2. Categories of Personal Data processed
Depending on the information provided by the Controller, its authorised users and connected services, the following categories may be processed:
### Identification data
* first name;* last name;* internal user identifier.
### Contact data
* email address;* other business contact information entered by the Controller where applicable.
### Connection and security data
* IP address;* authentication and authorisation information;* access records;* information required to determine the user’s rights and permissions.
Authentication secrets such as passwords, API keys and MFA/OTP codes are not intended to be transmitted through third-party integration requests or returned through integration responses.
### Preference and configuration data
* language;* time zone;* user settings;* organisation and location assignments.
### Integration and request data
Where a user accesses YOKITUP through an API, connector or integration, the following information may also be processed:
* identifiers of the relevant organisation, location, record or resource;* parameters, filters, search terms and instructions required to perform the requested operation;* information submitted by the user for the purpose of creating or modifying a record;* the specific content necessary to understand an instruction issued through a third-party service; and* results returned by YOKITUP to the connected service.
### Business data that may contain Personal Data
The Solution primarily processes business and operational information.
Certain business records may nevertheless contain Personal Data where such information has been entered into the Solution by the Controller, for example contact information associated with a supplier, customer or user.
The precise content depends on the Client’s use and configuration of the Solution.
## 3. Purposes of processing
Personal Data may be processed for the following purposes:
* creation, administration and security of user accounts;* authentication and access control;* provision of the functionality of the Solution;* execution of actions requested by authorised users;* retrieval and presentation of information requested by authorised users;* operation of APIs, connectors and third-party integrations;* communication of information relating to the Solution;* customer support;* monitoring, maintenance and debugging;* prevention and investigation of security incidents and unauthorised access;* service continuity;* compliance with legal and regulatory obligations; and* deletion, anonymisation, export or restoration of data in accordance with contractual obligations.
## 4. Categories of recipients
Personal Data may be accessible to the following categories of recipients, only where necessary for their respective purposes:
* authorised personnel of the Controller;* authorised YOKITUP personnel;* YOKITUP sub-processors listed below;* infrastructure, email, monitoring and technical service providers used to operate the Solution;* third-party services, applications or integration providers expressly enabled or used by the Controller or an authorised user;* competent authorities where disclosure is required by law.
Where an authorised user intentionally accesses YOKITUP through an external service, such as an artificial intelligence assistant, information necessary to answer or execute the user’s request may be returned to that external service.
## 5. Data retention
### Data held in the active Solution
Personal Data required to provide the Solution is generally retained for the duration of the contractual relationship, subject to deletion or deactivation controls made available to the Controller.
### Following termination
For up to thirty-six (36) months following termination of the Contract, the Controller may recover a copy of Personal Data processed on its behalf in `.csv` format where applicable.
At the end of this period, such data shall be deleted or anonymised unless a longer retention period is required by law.
### Access and technical logs
Access logs are retained for **14 days**, unless longer retention is required for the investigation of a specific security incident or by applicable law.
### Backups
Daily backups are retained for **7 days** and are then deleted or overwritten according to YOKITUP’s backup lifecycle.
### Third-party integrations
YOKITUP does not create a separate long-term copy of integration requests or responses solely because they passed through an integration, except where the relevant information forms part of the Client’s YOKITUP records or is included in technical logs required for security, reliability or debugging.
Information transmitted to a third-party service at the Client’s or user’s request may be retained by that third party in accordance with its own retention policy.
## 6. User and Controller controls
Depending on the user’s role and permissions, Personal Data can be managed through:
* user and organisation administration features;* account activation and deactivation;* deletion features made available to the Controller;* access and permission management;* export functionality;* integration connection and revocation controls where available; and* requests to exercise applicable data protection rights.
## 7. Main storage location
Personal Data stored as part of the core YOKITUP Solution is hosted in the **European Union**, subject to the international transfers described in these Data Processing Terms for certain service providers.
## 8. Sub-processors
| Legal entity              | Service   | Processing activity      | Data location            | Transfer safeguard                              || ------------------------- | --------- | ------------------------ | ------------------------ | ----------------------------------------------- || Amazon Web Services, Inc. | AWS       | Hosting                  | European Union (Ireland) | EU-U.S. Data Privacy Framework where applicable || Sinch Email               | Mailjet   | Emailing                 | European Union (Germany) | DPA                                             || New Relic, Inc.           | New Relic | Monitoring and debugging | United States            | EU-U.S. Data Privacy Framework where applicable || Functional Software, Inc. | Sentry    | Monitoring and debugging | United States            | EU-U.S. Data Privacy Framework where applicable |
Third-party applications or services intentionally connected by a Client or authorised user are not necessarily YOKITUP sub-processors. Depending on the circumstances, they may act as independent controllers, processors or recipients acting under the Client’s instructions.
---
# ANNEX 2 – TECHNICAL AND ORGANISATIONAL SECURITY MEASURES
## 1. Hosting
Personal Data processed by YOKITUP is hosted using AWS infrastructure.
YOKITUP selects hosting and infrastructure services taking into account recognised security and data-protection standards and certifications.
## 2. Employee awareness and confidentiality
YOKITUP employees are subject to specific confidentiality obligations regarding Personal Data.
Access to Personal Data is limited to personnel who require such access for their professional responsibilities.
## 3. User authentication
YOKITUP uses individual user accounts with access restrictions according to users’ roles within the organisation.
YOKITUP’s internal password policy requires passwords of at least 12 characters.
## 4. Access management
Employees are provided with individual accounts and access rights restricted according to their role.
Employee accounts are deleted within 10 days following departure from YOKITUP.
## 5. Access logging and incident management
Access logs are retained for 14 days.
Logging is used for security, incident investigation, reliability and debugging purposes.
## 6. Workstation security
Measures include:
* macOS workstations with built-in anti-malware protection;* regular workstation updates;* mobile device management for relevant employee devices; and* as a general rule, no permanent storage of Personal Data on employee workstations.
## 7. Server security
Server security measures include:
* access limited to authorised personnel;* authenticated access restricted through controlled network access mechanisms;* encrypted administrative access using SSH or TLS;* prompt installation of critical security updates;* automatic updates for services where supported by infrastructure providers;* monitored manual updating processes where automatic updates are not available; and* data replication across multiple physical availability zones.
## 8. Web application security
YOKITUP applies measures including:
* TLS encryption, with TLS 1.2 or higher;* no passwords or authentication credentials in URLs;* validation of externally supplied user input before use or storage; and* security controls intended to prevent unauthorised access and common application-level attacks.
## 9. Business continuity and backups
YOKITUP applies business continuity measures including:
* replication of data across at least two separate physical availability zones;* daily backups;* backup storage across multiple availability zones; and* procedures intended to restore availability following an infrastructure incident.
## 10. Secure deletion and archiving
Deleted information may temporarily remain in restricted technical storage before final deletion.
Such data is not intended for normal consultation or statistical use.
In particular:
* daily backups are retained for 7 days;* access and technical logs are retained for 14 days; and* other Personal Data is deleted or anonymised according to the applicable contractual retention period.
## 11. Sub-processor management
YOKITUP limits and records the sub-processors that may have access to Personal Data.
Agreements with sub-processors include appropriate Personal Data protection obligations.
## 12. Exchanges with other organisations and connected services
YOKITUP does not disclose Personal Data to external organisations other than its identified service providers except:
* where required by law;* where necessary for the provision of a service requested by the Client;* where expressly authorised or instructed by the Client; or* where an authorised user intentionally uses an integration or connected third-party service.
Where data is exchanged with a connected third-party service, YOKITUP limits the information transmitted to information reasonably necessary to perform the requested operation.
## 13. Physical security
Personal Data processed by YOKITUP is not hosted in YOKITUP’s office premises and is not ordinarily printed.
Physical access to YOKITUP premises is restricted.
## 14. Cryptographic controls
Where encryption is used, YOKITUP uses recognised and regularly maintained cryptographic libraries and technologies.
Encryption keys are stored using appropriate security controls.
---
# ANNEX 3 – INFORMATION SPECIFIC TO THIRD-PARTY INTEGRATIONS
This Annex applies whenever a Client or authorised user chooses to access YOKITUP through an API, connector or third-party application.
## 1. General principle
An integration may only access information that the relevant YOKITUP user is authorised to access and that is necessary to perform the requested functionality.
The fact that a third-party interface is used does not grant the user additional rights to information within YOKITUP.
## 2. Artificial intelligence assistants
Where YOKITUP is accessed through an artificial intelligence assistant or conversational interface, including ChatGPT:
* the user’s request may cause the third-party service to send a structured request to YOKITUP;* YOKITUP processes the information required to authenticate the request, determine the user’s permissions and perform the requested operation;* YOKITUP may return relevant information from the Client’s account to the third-party service;* the third-party service may then process and present that information to the user; and* any action that creates, changes or deletes information within YOKITUP is performed only where supported by the relevant integration and requested or confirmed by the authorised user.
YOKITUP does not require unrestricted access to a user’s conversation history in order to provide these integration functions. Only information made available to YOKITUP as part of the specific request is processed.
## 3. Data minimisation
Integration inputs should contain only information reasonably necessary to perform the requested operation.
Integration responses are designed to return only information relevant to that request.
Internal authentication secrets, API keys, passwords and unrelated diagnostic information are not intended to be included in responses.
## 4. Disconnection
Clients and users may stop using an integration at any time.
Where the integration supports connection management or revocation, the Client or authorised user may revoke future access.
Organisation administrators may also modify a user’s YOKITUP permissions or disable the relevant account.
Disconnection does not automatically delete information previously transmitted to another independent service. Requests relating to information retained by that service must be addressed in accordance with that service provider’s privacy policy and user controls.
## 5. Changes
YOKITUP may update this Privacy Policy and these Data Processing Terms where its services, integrations, processing activities, sub-processors or legal obligations change.
The version and publication date displayed at the beginning of this document identify the currently applicable version.