Last updated: August 2026 · Version 1.0
Data Processing Agreement (DPA)
This Data Processing Agreement (DPA) is YOWO7’s standard agreement under Art. 28 GDPR. It becomes part of the contract when the customer uses the YOWO7 platform or enters into a paid agreement, and supplements the Terms of Service. Material changes will be announced with reasonable notice (typically by email to workspace owners). Individual enterprise deviations require a separate written agreement. On request we provide a written copy (hello@yowo7.com). You may print this page or save it as PDF from your browser.
§ 1 Parties and roles
The controller is the customer operating a YOWO7 workspace. The processor is Markus Holzner, operating YOWO7, Kinderheimgasse 76, 2732 Willendorf, Austria (hereinafter “YOWO7”).
Where YOWO7 processes personal data on behalf of the customer, YOWO7 acts as processor. For the website, accounts, billing, and YOWO7’s own support, YOWO7 acts as controller; that is covered by the Privacy Policy.
§ 2 Subject matter, duration and nature of processing
The subject matter is the provision of the YOWO7 SaaS platform (including CRM, inbox, forms, support widget, chat, projects, files, calendar, sales, automation, API/MCP), including hosting, storage, transmission, and supporting AI features under the customer’s instructions.
The duration matches the contract term plus the periods required for deletion or return after contract end.
Nature of processing: collection, storage, retrieval, transmission, deletion, and other processing required to operate the service.
§ 3 Categories of personal data and data subjects
Depending on the customer’s use, data types may include contact details, communication content, form and ticket data, files, calendar data, usage and technical metadata, and customer-defined custom properties.
Data subjects typically include the customer’s clients, prospects, employees, suppliers and other contacts, as well as end users of public forms and the support widget.
YOWO7 does not actively collect special categories of personal data (Art. 9 GDPR). If the customer stores such data, the customer remains responsible for lawfulness and instructions.
§ 4 Obligations of YOWO7
- Process data only on documented instructions of the customer, unless required by law
- Ensure persons authorised to process data are bound to confidentiality
- Implement technical and organisational measures under Art. 32 GDPR (see § 6)
- Assist the customer with data-subject rights, security incidents and, where reasonable, data protection impact assessments
- Inform the customer if an instruction appears to infringe data protection law
§ 5 Instructions
Instructions are given through platform features, documented APIs, and written notices to hello@yowo7.com. Oral instructions require written confirmation.
The customer ensures that instructions are lawful and that it has the necessary rights in the data.
§ 6 Technical and organisational measures (TOMs)
YOWO7 implements appropriate TOMs, including encryption in transit and at rest, EU hosting of core systems, access control, malware scanning on uploads, audit logs, and backups. An overview is available at https://www.yowo7.com/security. YOWO7 may evolve TOMs provided the level of protection is not reduced.
§ 7 Subprocessors
The customer grants general authorisation to engage the subprocessors listed in the current subprocessor list (https://www.yowo7.com/subprocessors).
YOWO7 binds subprocessors contractually to at least the data protection level of this DPA. For material list changes YOWO7 provides advance notice; the customer may object on important data-protection grounds.
§ 8 International transfers
Core systems (application, database, files, platform email, AI) are operated exclusively in the EU (AWS Frankfurt). Where auxiliary services transfer data to third countries, in particular the United States, this occurs only with appropriate safeguards (EU-US Data Privacy Framework and/or EU Standard Contractual Clauses). The mapping per provider is in the subprocessor list.
§ 9 Assistance with data-subject rights and DPIAs
YOWO7 assists the customer with appropriate technical and organisational measures to respond to data-subject requests relating to data processed on the customer’s behalf. Requests received directly by YOWO7 that clearly concern the customer will be forwarded without undue delay.
YOWO7 assists the customer with data protection impact assessments and supervisory consultations to the extent necessary and reasonable.
§ 10 Personal data breach notification
YOWO7 notifies the customer of a personal data breach without undue delay after becoming aware of it and provides available information needed for notifications to authorities and data subjects.
§ 11 Deletion and return
After processing ends, YOWO7 deletes customer data or returns it at the customer’s choice, unless retention is required by law. Platform export features remain available during the contract and a reasonable wind-down period. Backup copies are overwritten in the ordinary backup cycle.
§ 12 Evidence and audit
On request YOWO7 provides suitable evidence (e.g. TOM descriptions, subprocessor information). Audits are primarily remote based on documented information. On-site audits are possible for legitimate cause after reasonable notice, during business hours and without disrupting operations; costs are borne by the customer unless a material deficiency is found.
§ 13 Confidentiality
YOWO7 treats customer data as confidential and does not use it for its own purposes outside instructed processing and the contracted platform features.
§ 14 Liability
Liability is governed by the Terms of Service to the extent permitted by law and by mandatory GDPR provisions.
§ 15 Final provisions
Austrian law applies, excluding the UN Convention on Contracts for the International Sale of Goods, unless mandatory data protection law provides otherwise.
If any provision is invalid, the remaining provisions remain in effect.
In case of conflict between this DPA and the Terms of Service, the data-protection provisions of this DPA prevail.