Data Processing Agreement

Version 2026-07-10 In force 19 July 2026

This Data Processing Agreement (“DPA”) forms part of the Yuimaru Terms of Service and is entered into between:

Progression Workshops, a trade name of the sole proprietorship (eenmanszaak) of Kevin Buoren Shiue, registered with the Dutch Chamber of Commerce under KvK number 93142854, VAT number NL005001145B96, at Munnikenstraat 1 A 4, 2315 KT Leiden, the Netherlands — the Processor; and the Organization identified in the Yuimaru account — the Controller.

1. Roles

You decide what personal data to collect from your Attendees, why you collect it, and what you do with it. You are the Controller. We process that data only to provide the Service to you. We are the Processor.

We are an independent Controller for the data we hold about your Organizer accounts — names, email addresses, billing details, and support correspondence. That processing is covered by our Privacy Policy, not by this DPA.

Where the GDPR applies to you, this DPA is the agreement required by Article 28(3).

2. Subject matter, duration, nature, and purpose

Subject matter. Processing of personal data relating to Attendees and other individuals whose data you enter into or collect through the Service.

Duration. For as long as you hold a Yuimaru account, plus the retention period in clause 11.

Nature and purpose. Hosting, storing, organizing, structuring, retrieving, transmitting, and deleting personal data so that you can operate event registration, attendee management, workshop scheduling, eligibility and approval decisions, price calculation, and communication with your Attendees.

3. Categories of data subject

4. Categories of personal data

The Service allows you to define your own registration forms, so the precise data is your choice. Typically it includes:

Special category data. Some of what is commonly collected for movement, sports, and workshop events — health information, injury history, dietary requirements that reveal religious belief or health status — is special category data under Article 9 GDPR. The Service does not require you to collect it. If you do, you are responsible for identifying an Article 9 condition permitting it, and for the additional safeguards that follow. We will process it on your instructions but we do not advise on, verify, or approve your basis for collecting it.

5. Our obligations

We will:

a. Process only on your instructions. We process personal data only as needed to provide the Service, as set out in the Terms of Service and this DPA, and on any further documented instruction you give. If we believe an instruction breaches the GDPR or other data protection law, we will tell you and may suspend that instruction.

b. Not process for our own purposes. We do not sell personal data, use it for advertising, or use it to train machine learning models.

c. Ensure confidentiality. Anyone we authorize to process personal data is bound by confidentiality obligations. Given our size, access is currently limited to Kevin Buoren Shiue alone; this clause governs any future personnel or contractor.

d. Implement appropriate security. See clause 6.

e. Assist you with data subject rights. See clause 8.

f. Assist you with Articles 32 to 36, including security, breach notification, and data protection impact assessments, taking into account the nature of processing and the information available to us.

g. Delete or return data on termination. See clause 11.

h. Make available the information needed to demonstrate compliance, and allow for audits as set out in clause 12.

6. Security measures

Taking into account the state of the art, the costs of implementation, and the risks involved, we maintain the following technical and organizational measures:

We may update these measures provided the level of protection is not reduced. The current version is published at static.getyuimaru.com/docs/security.

7. Sub-processors

You give general authorization for us to engage sub-processors. Our current sub-processors are listed at static.getyuimaru.com/docs/subprocessors, which forms part of this DPA. At the date of this version they are:

Sub-processorPurposeLocation
Hetzner Online GmbHHosting and infrastructureGermany
Hanko GmbHAttendee authentication and sign-inEuropean Union
Scaleway SASTransactional email deliveryFrance
Google Cloud EMEA LimitedServing static files and storing uploaded imagesEuropean Union

We use no error monitoring or application performance monitoring provider. No application error data leaves our infrastructure. All Google Cloud Storage buckets used by the Service are configured to European Union regions.

Attendees interact with Google Cloud Storage whenever they load a page or view an uploaded image, which means their IP addresses are processed by Google on every request regardless of where the bucket sits. This is disclosed rather than hidden.

We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance. We will give at least thirty days’ notice before adding or replacing a sub-processor, by email and by updating the published list. If you object on reasonable data protection grounds within that period, we will work with you to find a solution; if none is available, you may terminate the affected Service and receive a pro-rata refund.

Your payment provider is not our sub-processor. You contract with it directly. Where the Service records payment status or transaction references, we process that information as your Processor, but the provider’s own processing is a matter between you and it.

8. Data subject rights

The Service gives you direct access to Attendee data, including search, export, correction, and deletion. In most cases you can respond to a data subject request yourself without involving us.

Where you cannot, we will assist you by appropriate technical and organizational measures, taking into account the nature of the processing. Assistance beyond routine effort is subject to the support terms in the Terms of Service.

If we receive a request directly from one of your Attendees, we will not respond to it substantively. We will tell them to contact you and, where we can identify you, notify you without undue delay.

9. Personal data breaches

We will notify you without undue delay, and in any event within seventy-two hours, after becoming aware of a personal data breach affecting your data.

Our notification will describe, so far as we know it: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information. Where we cannot provide all of this at once, we will provide it in stages without undue delay.

Notifying supervisory authorities and data subjects is your responsibility as Controller. We will provide the information you reasonably need in order to do it.

10. International transfers

Personal data is stored within the European Economic Area. Our infrastructure, email delivery, and file storage all use European regions.

Google Cloud EMEA Limited, listed in clause 7, is part of a group that carries out some support and operational processing outside the EEA. That processing is covered by Standard Contractual Clauses and by Google’s certification under the EU-US Data Privacy Framework, together with the supplementary measures described in Google’s Cloud Data Processing Addendum.

If any other sub-processor requires a transfer outside the EEA, we will only make it where an adequacy decision applies, or under Standard Contractual Clauses together with any supplementary measures required, and we will identify the transfer and its safeguards on the sub-processor list before it begins.

11. Return and deletion

You may export your data in a machine-readable format at any time, including during any read-only period following termination or refund.

On termination of your account we retain personal data for ninety days, so that you can export it or reinstate the account, and then delete it. Where a refund shortens that period to thirty days under the Terms of Service, the shorter period applies.

You may request deletion earlier at any time, and we will comply within thirty days.

Backups are deleted on their normal rotation cycle, currently 30 days. Data may persist in backups after deletion from the live Service for up to that period, during which it is not accessible for any purpose other than restoration.

We may retain data where EU or Member State law requires it, and will tell you if that applies.

12. Audit

We will make available the information reasonably necessary to demonstrate compliance with Article 28, including our security measures documentation and sub-processor list.

Given the scale of the Service, we do not host on-site audits as a matter of course. We will respond to reasonable written questions and to a security questionnaire not more than once per year, at no charge. If you require an on-site or third-party audit, we will cooperate, at your cost and on reasonable notice, subject to confidentiality and to not compromising other customers’ security.

13. Liability

Liability under this DPA is subject to the limitations in the Terms of Service, except where those limitations are not permitted under Article 82 GDPR or other applicable law.

Nothing in this DPA limits a data subject’s rights against either party.

14. Precedence and duration

This DPA forms part of the Terms of Service. Where they conflict on the processing of personal data, this DPA prevails.

It takes effect when you create an account and continues until all personal data has been deleted or returned under clause 11.

15. Governing law

Dutch law governs this DPA, subject to the GDPR and to any mandatory law of the data subject’s jurisdiction. Disputes are subject to the jurisdiction of the Rechtbank Den Haag.