If your organisation is subject to GDPR, you need a Data Processing Agreement (DPA) with every processor that handles personal data on your behalf — Yaplet is one of them. You can sign Yaplet's DPA in a single click from the dashboard and download the signed PDF immediately. No legal email back-and-forth.
Sign the DPA
- Go to Settings → Organization settings → DPA.
- Click Sign DPA.
- Confirm by clicking the button. Your signature — name, email and timestamp — is recorded immediately under the organisation owner's account.
- Click Download PDF to save a signed copy for your records.
Only the organisation owner can sign the DPA, and the signature is written to the audit log.
If Yaplet updates the DPA, the button changes to Re-sign DPA. Your new signature replaces the previous one and the updated version is recorded.
Where your data lives
Yaplet hosts customer data in Frankfurt, Germany. Your conversation data, visitor profiles, agent accounts and media uploads stay on EU infrastructure during normal operations. International transfers, where they occur, are covered by Standard Contractual Clauses — see our privacy policy and DPA linked below for the full legal terms.
Encryption
- In transit — TLS 1.2 or higher on every connection between your team, your visitors and Yaplet's servers.
- At rest — AES-256 encryption on the database and file storage.
What Yaplet deletes, and when
Old data is removed automatically on a schedule. Nobody is exempt, and every cleanup is written to the audit log:
- Conversations and their attachments — deleted after three years of inactivity on a paid plan, or 120 days on the free plan. The clock runs on the last activity in the conversation, not on when it started.
- Empty chat records — the placeholder the widget opens for a new visitor, which never received a message, is deleted after 60 days of that visitor's inactivity.
- Idle anonymous visitors — a visitor with no conversations left is deleted after 125 days of inactivity. Anyone who identified themselves, carries a security review status or risk signal, owns a session replay, or is banned is kept regardless.
- Website analytics — kept for roughly 120 days, which is why the Reports date picker will not go back further.
Newsletter send history is not on any deletion schedule. For the full picture, see What Yaplet deletes automatically.
Sub-processors
Yaplet uses a small number of sub-processors for specific features. The full, up-to-date list is published at yaplet.com/legal/sub-processors. At the time of writing, the list includes:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, storage | EU (Frankfurt, Germany) |
| Stripe | Payments and subscription billing | EU / US |
| Sentry | Error monitoring and diagnostics | US |
| OpenAI | AI model processing | US |
| Anthropic | AI model processing | US |
| Google AI | AI model processing | EU / US |
| AWS (SES / SNS) | Transactional email and notifications | EU / US |
| Telnyx | Phone numbers and voice call routing | EU / US |
| OneSignal | Push notifications | US |
| DigitalOcean | Infrastructure services | EU / US |
| Cloudflare | CDN, edge security, traffic routing | Global |
| DeepL | Translation services | EU |
Each sub-processor's own DPA is linked from the public sub-processor list. The AI sub-processors only receive conversation content while an AI agent is switched on.
Turning the AI off
An AI agent belongs to a brand, and each brand has at most one. Switch it off at Brand → (your brand) → Vex → Personality. There is no per-widget AI switch. If the word "brand" is new to you, see what a brand is.
Privacy masking
If you would rather the AI never saw personal details in the first place, turn on Privacy masking at Brand → (your brand) → Brand settings → Advanced. It hides email addresses, phone numbers and card numbers in what visitors write, before that text is sent to the AI provider. It also applies to what the AI remembers about a visitor between conversations, and to AI-generated ticket titles. Four things you need to know before you rely on it:
- One switch, two different behaviours. On chat it redacts what we send. On voice it redacts what we store — a phone call is answered in real time, so the caller's words have already reached the AI by the time anything can be masked, and masking cleans up the saved transcript afterwards.
- It is best-effort, not a guarantee. If the masking service is slow or unavailable, the text goes out as written and you are not notified. Do not treat it as a control you can promise an auditor.
- It is not encryption. It removes recognisable patterns from text; it does not protect anything cryptographically.
- Two things it does not cover — the page addresses a visitor came from, which routinely carry email addresses and order numbers in the query string, and the contents of uploaded images.
Conversations recorded before you switched masking on are left exactly as they were. Turning it on changes what happens next, not what already happened.
Access controls
- Role-based permissions on every dashboard and API call, enforced on the server.
- Row-level security at the database layer — every server route is gated.
- Organisation-scoped AI search — the AI finds passages in two ways at once, by keyword and by meaning, and both halves check that the content belongs to your own organisation before returning it.
- Audit logging for critical actions — see Audit log.
Visitor data rights
If a visitor exercises their GDPR rights, you can fulfil the request directly from the dashboard:
- Subject access request — see Export visitor data.
- Right to erasure — see Erase a visitor's data.
Where to read more
- Security page: yaplet.com/security
- DPA full text: yaplet.com/legal/dpa
- Sub-processors list: yaplet.com/legal/sub-processors
- Privacy policy: yaplet.com/legal/privacy-policy