Yaplet's DPA and data residency

Updated May 22, 2026

If your organisation is subject to GDPR, you need a Data Processing Agreement (DPA) with every processor that handles personal data on your behalf — Yaplet is one of them. You can sign Yaplet's DPA in a single click from the dashboard and download the signed PDF immediately. No legal email back-and-forth.

Sign the DPA

  1. Go to Settings → Organization settings → DPA.
  2. Click Sign DPA.
  3. Confirm by clicking the button. Your signature — name, email and timestamp — is recorded immediately under the organisation owner's account.
  4. Click Download PDF to save a signed copy for your records.

Only the organisation owner can sign the DPA, and the signature is written to the audit log.

If Yaplet updates the DPA, the button changes to Re-sign DPA. Your new signature replaces the previous one and the updated version is recorded.

Where your data lives

Yaplet hosts customer data in Frankfurt, Germany. Your conversation data, visitor profiles, agent accounts and media uploads stay on EU infrastructure during normal operations. International transfers, where they occur, are covered by Standard Contractual Clauses — see our privacy policy and DPA linked below for the full legal terms.

Encryption

  • In transit — TLS 1.2 or higher on every connection between your team, your visitors and Yaplet's servers.
  • At rest — AES-256 encryption on the database and file storage.

What Yaplet deletes, and when

Old data is removed automatically on a schedule. Nobody is exempt, and every cleanup is written to the audit log:

  • Conversations and their attachments — deleted after three years of inactivity on a paid plan, or 120 days on the free plan. The clock runs on the last activity in the conversation, not on when it started.
  • Empty chat records — the placeholder the widget opens for a new visitor, which never received a message, is deleted after 60 days of that visitor's inactivity.
  • Idle anonymous visitors — a visitor with no conversations left is deleted after 125 days of inactivity. Anyone who identified themselves, carries a security review status or risk signal, owns a session replay, or is banned is kept regardless.
  • Website analytics — kept for roughly 120 days, which is why the Reports date picker will not go back further.

Newsletter send history is not on any deletion schedule. For the full picture, see What Yaplet deletes automatically.

Sub-processors

Yaplet uses a small number of sub-processors for specific features. The full, up-to-date list is published at yaplet.com/legal/sub-processors. At the time of writing, the list includes:

Sub-processor Purpose Location
Supabase Database, authentication, storage EU (Frankfurt, Germany)
Stripe Payments and subscription billing EU / US
Sentry Error monitoring and diagnostics US
OpenAI AI model processing US
Anthropic AI model processing US
Google AI AI model processing EU / US
AWS (SES / SNS) Transactional email and notifications EU / US
Telnyx Phone numbers and voice call routing EU / US
OneSignal Push notifications US
DigitalOcean Infrastructure services EU / US
Cloudflare CDN, edge security, traffic routing Global
DeepL Translation services EU

Each sub-processor's own DPA is linked from the public sub-processor list. The AI sub-processors only receive conversation content while an AI agent is switched on.

Turning the AI off

An AI agent belongs to a brand, and each brand has at most one. Switch it off at Brand → (your brand) → Vex → Personality. There is no per-widget AI switch. If the word "brand" is new to you, see what a brand is.

Privacy masking

If you would rather the AI never saw personal details in the first place, turn on Privacy masking at Brand → (your brand) → Brand settings → Advanced. It hides email addresses, phone numbers and card numbers in what visitors write, before that text is sent to the AI provider. It also applies to what the AI remembers about a visitor between conversations, and to AI-generated ticket titles. Four things you need to know before you rely on it:

  • One switch, two different behaviours. On chat it redacts what we send. On voice it redacts what we store — a phone call is answered in real time, so the caller's words have already reached the AI by the time anything can be masked, and masking cleans up the saved transcript afterwards.
  • It is best-effort, not a guarantee. If the masking service is slow or unavailable, the text goes out as written and you are not notified. Do not treat it as a control you can promise an auditor.
  • It is not encryption. It removes recognisable patterns from text; it does not protect anything cryptographically.
  • Two things it does not cover — the page addresses a visitor came from, which routinely carry email addresses and order numbers in the query string, and the contents of uploaded images.

Conversations recorded before you switched masking on are left exactly as they were. Turning it on changes what happens next, not what already happened.

Access controls

  • Role-based permissions on every dashboard and API call, enforced on the server.
  • Row-level security at the database layer — every server route is gated.
  • Organisation-scoped AI search — the AI finds passages in two ways at once, by keyword and by meaning, and both halves check that the content belongs to your own organisation before returning it.
  • Audit logging for critical actions — see Audit log.

Visitor data rights

If a visitor exercises their GDPR rights, you can fulfil the request directly from the dashboard:

Where to read more

  • Security page: yaplet.com/security
  • DPA full text: yaplet.com/legal/dpa
  • Sub-processors list: yaplet.com/legal/sub-processors
  • Privacy policy: yaplet.com/legal/privacy-policy

Did this article answer your question?