Legal · GDPR · Data Pro

Data Processing Agreement

Version: 10 July 2026

Introduction

This Data Processing Agreement (Data Pro Statement), together with the Standard Processing Clauses (Chapter 2 of the NLdigital Terms 2020), forms the complete data processing agreement for the services delivered by Yuvo.

1. General information

  • Address: Loosduinseweg 65H, 2571 AA The Hague, Netherlands
  • Data Protection Officer: dpo@alias.yuvo.eu
  • Phone: +31 6 48667790
  • Website: yuvo.eu
  • Effective from: 29 January 2026

We regularly update our security measures. Changes to this agreement are communicated via email or our website.

2. Which services are covered?

This agreement applies to:

  • WordPress Maintenance, updates, security monitoring, backups, and optimisation of existing websites
  • Yuvo Hosting, if you choose it as part of your Maintenance plan, including server infrastructure and email
  • One-time Services and Webdesign projects, for the duration of that engagement, whenever personal data is processed as part of the work (for example a hosting migration or setting up a contact form)

3. What exactly do we do?

Technical management of WordPress websites, on our own hosting or on your current hosting environment, that’s your choice. This includes: WordPress core, plugin, and theme updates; security monitoring; performance optimisation; and creating encrypted backups via WP Umbrella on their own servers in France.

Using our hosting? Then the server infrastructure is also covered by this agreement, see section 5 (mijn.host). Staying on your current host? Then we work on your existing installation.

For One-time Services and Webdesign projects, we process personal data only for the duration and purpose of that specific engagement. Think of transferring a full database during a hosting migration, setting up a contact form for a new website, or scanning and categorising cookies and tracking scripts for a GDPR package. Once the engagement is complete, the same retention periods described in section 8 apply.

4. Where is your data stored?

All data processing takes place within the EU/EEA, with the following exceptions:

Processing Location Basis
Email 🇨🇭 Switzerland (ProtonMail) End-to-end encrypted, adequately protected
Form spam prevention 🇺🇸 United States (Cloudflare Turnstile) EU-U.S. Data Privacy Framework (DPF); SCCs (Art. 46 GDPR) as fallback

5. Who do we work with? (subprocessors)

We use the following parties for our service delivery:

Service provider Service Location
WP Umbrella Management, monitoring & backups of WordPress websites 🇫🇷 France (EU)
Brevo Newsletter and email marketing platform 🇫🇷 France (EU)
ProtonMail Secure email services 🇨🇭 Switzerland
Jortt Financial administration 🇳🇱 Netherlands
Knab Banking services 🇳🇱 Netherlands
Mollie Payment processing 🇳🇱 Netherlands
Crisp Live chat support 🇫🇷 France (EU)
Cloudflare Turnstile Form spam prevention (CAPTCHA) 🇺🇸 United States
mijn.host Server infrastructure, firewall, malware protection & local backups 🇳🇱 Netherlands

All these parties have agreed with us to process data only within the EU/EEA or in adequately protected countries. For Cloudflare Turnstile (US), the EU-U.S. Data Privacy Framework (DPF) certification applies, with Standard Contractual Clauses (SCCs, Art. 46 GDPR) as a fallback. Turnstile is used solely for form CAPTCHA verification.

mijn.host is our recommended hosting subprocessor for clients who use our hosting service. If you choose to host your website with a different provider, that provider becomes the applicable subprocessor for your site’s data instead of mijn.host.

6. How do we protect your data?

TransmissionTLS/SSL encryption for all data traffic
CommunicationEnd-to-end encryption via ProtonMail
BackupsEncrypted storage on WP Umbrella’s own servers in France (EU)
Server securityFirewall and DDoS protection (mijn.host)
Email securityDKIM, SPF, and DMARC
DNSDNSSEC protection against redirection
AccessTwo-factor authentication where possible, strong passwords, strict access controls
MonitoringSecurity scans of WordPress sites
UpdatesRegular patches for WordPress and plugins

We have no routine access to your data. We only look at your data when you explicitly ask us to for support purposes.

7. Rights of your website visitors (data subjects)

Support with data subject requests (access, rectification, erasure) is handled as described in our Privacy Policy.

8. How long do we retain data?

When our engagement ends:

Timing Action
Immediately Login credentials are deleted
Within 6 months All personal data is irreversibly deleted
Transfer You may transfer your data to your own systems within 6 months

You indemnify Yuvo against consequences of deletion, unless we have agreed otherwise in writing.

9. What do we do in the event of a data breach?

What is a data breach? A security incident in which personal data is accidentally or unlawfully destroyed, lost, altered, or accessed or shared without authorisation.
Aspect Description
Notification If a breach affects your website (for example, during our maintenance work), we will notify your contact person within 24 hours.
Your responsibility As controller, you determine whether notification to the Dutch Data Protection Authority is required.
Our actions We document the incident, resolve it immediately (for example by restoring a backup or installing a security patch), and inform you of the extent of the breach and the measures taken.