Last updated: [insert publish date] • Draft prepared August 3, 2026
Data Processing Agreement
YesOpens — yesopens.com (Annex to the Terms of Service)
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Localesto Sp. z o.o., with its registered office in Warsaw (ul. Szczęsna 26, 02-454 Warszawa, Poland), KRS 0001200212, NIP 5223350892, REGON 543003699 (“Processor,” “YesOpens,” “we”), and the customer entity that has agreed to the Terms of Service (“Controller,” “Customer,” “you”). It applies whenever YesOpens processes personal data on the Customer's behalf in connection with the Service.
1. Definitions
- “GDPR” means Regulation (EU) 2016/679.
- “Personal Data,” “Processing,” “Controller,” “Processor,” “Data Subject,” and “Personal Data Breach” have the meanings given in the GDPR.
- “Customer Personal Data” means personal data submitted to, or connected through, the Service by or on behalf of the Customer, including data of the Customer's own customers or reviewers accessed via a connected Google Business Profile or other third-party account.
- “Sub-processor” means any processor engaged by YesOpens to process Customer Personal Data.
2. Roles of the Parties
The Customer is the Controller of Customer Personal Data. YesOpens is the Processor and will process Customer Personal Data only on behalf of, and in accordance with, the Customer's documented instructions as set out in the Terms of Service and this DPA, unless required to do otherwise by EU or Member State law.
3. Subject Matter, Duration, Nature and Purpose
- Subject matter: provision of the local-SEO Service (rank tracking, audits, review and post management, citation management, reporting) described in the Terms of Service.
- Duration: for as long as YesOpens provides the Service to the Customer, plus any period required under Section 9 (Return or Deletion of Data) or applicable law.
- Nature and purpose: automated collection, storage, analysis, and display of Customer Personal Data to deliver the Service's features.
- Categories of data subjects: the Customer's staff/account users; the Customer's business contacts; and customers or reviewers of the Customer's business appearing in reviews, Q&A, or similar content accessed via connected accounts.
- Categories of personal data: names, contact details, business listing data, review and rating content, and related metadata, as further described in the Privacy Policy.
4. Processor Obligations
YesOpens shall:
- process Customer Personal Data only on the Customer's documented instructions, including regarding international transfers, unless required otherwise by law — in which case YesOpens will inform the Customer before processing, unless prohibited by law;
- ensure persons authorized to process Customer Personal Data are bound by confidentiality;
- implement appropriate technical and organizational security measures as described in Annex 2;
- taking into account the nature of the processing, assist the Customer with appropriate technical and organizational measures in fulfilling requests from data subjects exercising their GDPR rights;
- assist the Customer in complying with its obligations under Articles 32–36 GDPR (security, breach notification, data protection impact assessments), taking into account the information available to YesOpens;
- at the Customer's choice, delete or return all Customer Personal Data after the Service ends, and delete existing copies, unless EU or Member State law requires continued storage;
- make available to the Customer all information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable notice and confidentiality.
5. Sub-processors
The Customer authorizes YesOpens to engage the sub-processors listed in Annex 1, and any additional sub-processors YesOpens engages in the future, provided YesOpens gives the Customer at least 14 days' prior notice of any new sub-processor (e.g., by e-mail or notice within the Service), during which the Customer may object on reasonable data-protection grounds. YesOpens remains liable for its sub-processors' performance of their data-protection obligations, and will impose data-protection terms on sub-processors no less protective than this DPA.
6. International Transfers
Where Customer Personal Data is transferred outside the European Economic Area, YesOpens will ensure the transfer is subject to appropriate safeguards under Chapter V GDPR, such as an adequacy decision or Standard Contractual Clauses.
7. Personal Data Breach
YesOpens will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide reasonably requested information to help the Customer meet its own breach-notification obligations under Articles 33–34 GDPR.
8. Liability
Each party's liability under this DPA is subject to the limitations of liability set out in the Terms of Service, except where such a limitation is not permitted under applicable data protection law.
9. Return or Deletion of Data
Upon termination of the Service, YesOpens will, at the Customer's election, delete or return all Customer Personal Data within 30 days, except to the extent retention is required by applicable law.
10. Term
This DPA takes effect on the date the Customer accepts the Terms of Service and remains in force for as long as YesOpens processes Customer Personal Data on the Customer's behalf.
11. Governing Law
This DPA is governed by the laws of the Republic of Poland, consistent with the governing-law provision of the Terms of Service.
Annex 1 – Sub-processors (as of [date])
- [Hosting provider name] — hosting/infrastructure — [country]
- [Payment processor, e.g., Stripe/Paddle] — billing and payment processing — [country]
- [E-mail delivery provider] — transactional e-mail — [country]
- [Support/chat tool provider] — customer support — [country]
(Update this list to reflect your actual vendors before publishing.)
Annex 2 – Technical and Organizational Security Measures
- Encryption of data in transit (TLS) and at rest where applicable.
- Access controls and role-based permissions; unique credentials per employee.
- Regular security updates and vulnerability management.
- Logging and monitoring of access to production systems.
- Staff confidentiality undertakings and data-protection training.
- Backup and disaster-recovery procedures.
- Documented incident-response procedure.
(Confirm and expand this list to match your actual infrastructure before publishing.)