Legal · GDPR · Data Pro
Data Processing Agreement
Introduction
This Data Processing Agreement (Data Pro Statement), together with the Standard Processing Clauses (Chapter 2 of the NLdigital Terms 2020), forms the complete data processing agreement for the services delivered by Yuvo.
1. General information
- Address: Loosduinseweg 65H, 2571 AA The Hague, Netherlands
- Data Protection Officer: dpo@alias.yuvo.eu
- Phone: +31 6 48667790
- Website: yuvo.eu
- Effective from: 29 January 2026
We regularly update our security measures. Changes to this agreement are communicated via email or our website.
2. Which services are covered?
This agreement applies to:
- WordPress Maintenance, updates, security monitoring, backups, and optimisation of existing websites
- Yuvo Hosting, if you choose it as part of your Maintenance plan, including server infrastructure and email
- One-time Services and Webdesign projects, for the duration of that engagement, whenever personal data is processed as part of the work (for example a hosting migration or setting up a contact form)
3. What exactly do we do?
Technical management of WordPress websites, on our own hosting or on your current hosting environment, that’s your choice. This includes: WordPress core, plugin, and theme updates; security monitoring; performance optimisation; and creating encrypted backups via WP Umbrella on their own servers in France.
For One-time Services and Webdesign projects, we process personal data only for the duration and purpose of that specific engagement. Think of transferring a full database during a hosting migration, setting up a contact form for a new website, or scanning and categorising cookies and tracking scripts for a GDPR package. Once the engagement is complete, the same retention periods described in section 8 apply.
4. Where is your data stored?
All data processing takes place within the EU/EEA, with the following exceptions:
| Processing | Location | Basis |
|---|---|---|
| 🇨🇭 Switzerland (ProtonMail) | End-to-end encrypted, adequately protected | |
| Form spam prevention | 🇺🇸 United States (Cloudflare Turnstile) | EU-U.S. Data Privacy Framework (DPF); SCCs (Art. 46 GDPR) as fallback |
5. Who do we work with? (subprocessors)
We use the following parties for our service delivery:
| Service provider | Service | Location |
|---|---|---|
| WP Umbrella | Management, monitoring & backups of WordPress websites | 🇫🇷 France (EU) |
| Brevo | Newsletter and email marketing platform | 🇫🇷 France (EU) |
| ProtonMail | Secure email services | 🇨🇭 Switzerland |
| Jortt | Financial administration | 🇳🇱 Netherlands |
| Knab | Banking services | 🇳🇱 Netherlands |
| Mollie | Payment processing | 🇳🇱 Netherlands |
| Crisp | Live chat support | 🇫🇷 France (EU) |
| Cloudflare Turnstile | Form spam prevention (CAPTCHA) | 🇺🇸 United States |
| mijn.host | Server infrastructure, firewall, malware protection & local backups | 🇳🇱 Netherlands |
All these parties have agreed with us to process data only within the EU/EEA or in adequately protected countries. For Cloudflare Turnstile (US), the EU-U.S. Data Privacy Framework (DPF) certification applies, with Standard Contractual Clauses (SCCs, Art. 46 GDPR) as a fallback. Turnstile is used solely for form CAPTCHA verification.
mijn.host is our recommended hosting subprocessor for clients who use our hosting service. If you choose to host your website with a different provider, that provider becomes the applicable subprocessor for your site’s data instead of mijn.host.
6. How do we protect your data?
We have no routine access to your data. We only look at your data when you explicitly ask us to for support purposes.
7. Rights of your website visitors (data subjects)
Support with data subject requests (access, rectification, erasure) is handled as described in our Privacy Policy.
8. How long do we retain data?
When our engagement ends:
| Timing | Action |
|---|---|
| Immediately | Login credentials are deleted |
| Within 6 months | All personal data is irreversibly deleted |
| Transfer | You may transfer your data to your own systems within 6 months |
You indemnify Yuvo against consequences of deletion, unless we have agreed otherwise in writing.
9. What do we do in the event of a data breach?
| Aspect | Description |
|---|---|
| Notification | If a breach affects your website (for example, during our maintenance work), we will notify your contact person within 24 hours. |
| Your responsibility | As controller, you determine whether notification to the Dutch Data Protection Authority is required. |
| Our actions | We document the incident, resolve it immediately (for example by restoring a backup or installing a security patch), and inform you of the extent of the breach and the measures taken. |
10. Legal context
This Data Processing Agreement must be read in conjunction with the Standard Processing Clauses (Chapter 2, NLdigital Terms 2020), deposited with the District Court Midden-Nederland in Utrecht.
Together these documents form your complete data processing agreement under Article 28 GDPR.
Questions? Contact us at dpo@alias.yuvo.eu.