YouSpot Data Processing Addendum (UK GDPR and EU GDPR)
Last updated: October 7, 2026
This Data Processing Addendum applies automatically to every customer whose use of YouSpotinvolves personal data subject to the UK GDPR or the EU GDPR. It forms part of the YouSpotTerms of Use and needs no signature. If you need a countersigned copy, write toprivacy@youspot.com.
Plain-English summary
- Who does what. You (the customer) decide what goes into YouSpot and why. For that content, including everything about other people that you bring in from Gmail, Outlook, LinkedIn, X, HubSpot, Slack, Granola and your files, you are the controller and YouSpot is your processor. For your own account (sign-in, billing, support, product analytics) YouSpot is the controller under its Privacy Policy.
- What we do with it. We store it, index it (including vector embeddings), and send the parts a request needs to AI and research providers so YouSpot can answer you, draft for you, run your agents and keep your relationship graph current. Nothing else.
- No model training. YouSpot does not train or fine-tune any AI model on your data, and does not let anyone else do so. Every AI provider is used through a paid commercial API plan whose terms do not permit training on your data, and our model gateway runs with zero data retention.
- Where it lives. In the United States: database and files on Supabase (AWS us-east-1), servers on DigitalOcean (New York), web app on Vercel. UK and EU transfers are covered by the EU Standard Contractual Clauses and the UK Addendum.
- Deleting. You can export your Brain and delete your account yourself from Settings. Deletion removes your data from our database and file storage at once, revokes the grants we hold at Google, LinkedIn, X, HubSpot, Slack and MCP servers, deletes your memories at Mem0 and your cloud-agent sessions at Anthropic, cancels billing and deletes your sign-in. Database backups are deleted within 30 days. We keep only a minimal record that the deletion happened (section 12.3).
- Breaches. We tell you without undue delay, and within 72 hours of becoming aware.
This Data Processing Addendum ("Addendum") forms part of the agreement for the YouSpotservices (the "Agreement") between:
- YouSpot, Inc., Two Canal Park, Cambridge, MA 02141, USA ("YouSpot"); privacy contact: privacy@youspot.com; and
- the customer that has accepted the Terms of Use ("Customer").
1. Definitions
Terms such as "controller", "processor", "data subject", "personal data", "personal databreach", "processing" and "supervisory authority" have the meanings given in the DataProtection Laws. In this Addendum:
- "Data Protection Laws" means the UK GDPR and the Data Protection Act 2018, the EU GDPR (Regulation (EU) 2016/679), and any other data protection law that applies to the processing of Customer Personal Data under the Agreement.
- "Customer Personal Data" means personal data that Customer or its Users submit to the Services, or that the Services collect from a Connected Service at Customer's direction, and that YouSpot processes on Customer's behalf. It excludes Account Data.
- "Account Data" means personal data about Users that YouSpot processes as a controller to provide and administer their accounts: sign-in identity, billing records, support correspondence, security logs and product usage analytics.
- "Connected Service" means a third-party service a User connects to YouSpot (for example Gmail, Google Calendar, Microsoft Outlook, LinkedIn, X, HubSpot, Slack, Granola, Substack, Obsidian, Telegram or an MCP server).
- "Subprocessor" means a third party YouSpot engages to process Customer Personal Data.
- "SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914. "UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018 (version B1.0, in force 21 March 2022).
- "Users" means the individuals Customer permits to use the Services under its account.
2. Roles and scope
2.1 Customer as controller, YouSpot as processor. For Customer Personal Data, Customer isthe controller (or a processor acting for its own controller) and YouSpot is a processor.
2.2 YouSpot as controller. YouSpot processes Account Data as an independent controller forthe purposes set out in its Privacy Policy at youspot.com/privacy. This Addendum does not applyto Account Data except where it says so.
2.3 Customer's responsibilities. Customer is responsible for having a lawful basis for theCustomer Personal Data it brings into the Services, including personal data about thirdparties found in mailboxes, calendars, CRM records, social networks and files it connects, andfor giving any notices those data subjects are owed.
3. Processing on instructions
3.1 YouSpot will process Customer Personal Data only on Customer's documented instructions,unless required to do otherwise by UK, EU or Member State law, in which case YouSpot will tellCustomer before processing unless that law prohibits it.
3.2 Customer's instructions are the Agreement, this Addendum, and the actions Users take in theServices (connecting or disconnecting a Connected Service, asking the assistant to act,creating agents and monitors, importing, exporting and deleting).
3.3 YouSpot will tell Customer if, in its opinion, an instruction infringes Data ProtectionLaws.
4. Details of the processing
The subject matter, duration, nature and purpose of the processing and the types of personaldata and categories of data subjects are set out in Annex 1.
5. Confidentiality
YouSpot will ensure that personnel authorised to process Customer Personal Data are bound byconfidentiality obligations, and that production access is limited to the operators who needit, each signing in with multi-factor authentication to the hosting, database and secretsconsoles.
6. Security
6.1 YouSpot will implement and maintain the technical and organisational measures inAnnex 2, which are appropriate to the risk under Article 32.
6.2 YouSpot may update the measures provided it does not materially reduce the overall level ofprotection.
7. Subprocessors
7.1 General authorisation. Customer authorises YouSpot to engage the Subprocessors listedin Annex 3, published at youspot.com/terms#subprocessors.
7.2 Changes. YouSpot will give Customer at least 30 days' notice of a new Subprocessor byupdating the published list, and by email to any Customer that asks for notices atprivacy@youspot.com. Customer may object on reasonable data protection grounds within that period; if theparties cannot resolve the objection, Customer may terminate the affected Services and receivea refund of prepaid fees for the unused term.
7.3 Flow-down. YouSpot will impose data protection obligations on each Subprocessor that areno less protective than this Addendum to the extent applicable to the service it provides, andremains liable to Customer for each Subprocessor's performance.
7.4 Connected Services are not Subprocessors. A Connected Service is engaged by Customer,not by YouSpot. YouSpot reads from and writes to it only at Customer's direction, andCustomer's own agreement with that service governs the data held there.
8. International transfers
8.1 Location. YouSpot is operated from the United States and processes Customer PersonalData there. Its primary database and file storage are hosted by Supabase on AWS in us-east-1;its application servers by DigitalOcean in New York; its web front end by Vercel; and itsSubprocessors are listed with their locations in Annex 3.
8.2 EU transfers. To the extent YouSpot processes Customer Personal Data subject to the EUGDPR in a country without an adequacy decision, the SCCs are incorporated by reference, withModule Two (controller to processor) where Customer is a controller and Module Three (processorto processor) where Customer is a processor, completed as in Annex 4.
8.3 UK transfers. To the extent YouSpot processes Customer Personal Data subject to the UKGDPR, the UK Addendum is incorporated by reference and completed as in Annex 4.
8.4 Onward transfers. Where a Subprocessor receives Customer Personal Data in a thirdcountry, YouSpot will put in place SCCs (Module Three) or another valid mechanism with thatSubprocessor.
8.5 Transfer risk assessment. YouSpot will provide reasonable information Customer needsfor its transfer risk assessment, including the encryption measures in Annex 2. YouSpot hasnot received a government request for access to Customer Personal Data.
9. Assisting with data subject requests
9.1 Self-service. The Services let Users act on most requests themselves:
- Access and portability: a Brain export in Settings (Brain, Exports) packages the User's Second Brain as a downloadable archive. Export files are held in a private storage bucket, served through signed links valid for 60 seconds, and expire after 7 days.
- Rectification: objects, fields and profile data can be edited in the app.
- Erasure: individual objects can be deleted; a Connected Service can be disconnected; and the whole account can be deleted in Settings, which runs the process in section 12.
- Restriction and objection: a Connected Service can be disconnected at any time, and automated emails and agent runs can be switched off.
9.2 Requests YouSpot receives. If YouSpot receives a request from a data subject aboutCustomer Personal Data, it will not respond except to direct the data subject to Customer,unless Customer authorises it, and will tell Customer within 5 business days.
9.3 Assistance. Taking into account the nature of the processing, YouSpot will providereasonable assistance, by email to privacy@youspot.com, for requests the self-service tools donot cover, within 10 business days of Customer's request.
9.4 Third parties in Customer's data. Personal data about a contact who appears in severalcustomers' accounts is held separately in each account. A request from that contact is handledby each customer as controller of its own account; YouSpot will assist each customer under 9.3.
10. Personal data breaches
10.1 YouSpot will notify Customer without undue delay, and in any event within 72 hours,after becoming aware of a personal data breach affecting Customer Personal Data.
10.2 The notice will describe, as far as then known, the nature of the breach, the categoriesand approximate number of data subjects and records concerned, the likely consequences, and themeasures taken or proposed. YouSpot will supplement the notice as more becomes known.
10.3 YouSpot will take reasonable steps to contain and remediate the breach and will cooperatewith Customer's own notification obligations. YouSpot's internal incident response policystarts the response to a critical incident within one hour and targets containment within 24hours, and keeps a written post-incident review.
10.4 Notice is not an admission of fault or liability.
11. Impact assessments and consultation
YouSpot will provide reasonable information and assistance Customer needs for a data protectionimpact assessment or prior consultation with a supervisory authority that relates to theServices, to the extent Customer does not otherwise have access to the information.
12. Return and deletion
12.1 During the term. Customer can export Customer Personal Data with the self-service toolsin 9.1 at any time.
12.2 Account deletion. When a User deletes their account in Settings (POST/api/user/account/delete, which requires the User to type their email address) or YouSpotcloses it on request, YouSpot does all of the following in one run:
- Cancels the account's web page and topic monitors at Parallel, and archives its scheduled cloud agents at Anthropic, then deletes their sessions and the credential vault.
- Cancels Stripe subscriptions.
- Revokes the OAuth grants YouSpot holds for the account at Google (each connected mailbox and Google sign-in), LinkedIn, X, HubSpot portals, Slack and MCP servers; deletes the account's memories at Mem0 and its contacts at Resend. A failure at any one service is reported to YouSpot's operators for follow-up and does not stop the rest.
- Removes from YouSpot's database, in one transaction, every row keyed to the account: the Second Brain (objects, relationships, field values, embeddings), synced mail, calendar, contacts, LinkedIn, X, HubSpot and Slack data, chat history, agents and their runs, files metadata, imports and exports, usage and credit records, logs keyed to the account (activity log, LLM prompt logs, task queue and task metrics), caches keyed by the account, and rows tied to the person by email address or a related id (support tickets and their messages, feedback, ideas, space invitations, LinkedIn sign-in records, HubSpot personal access keys, email delivery events). Accounts previously merged into this one are deleted with it.
- Deletes the account's files from storage: uploads, imports, generated images, signup attachments and Brain exports.
- Deletes the User at Clerk, YouSpot's sign-in provider.
- Writes the deletion record described in 12.3.
A failure at an outside service in steps 1 to 3 or 6 is reported to YouSpot's operators, whocomplete that step by hand; it never leaves the account's data in place.
12.3 What is kept, and why. After deletion:
- A deletion record. YouSpot keeps a minimal record that the deletion happened: the date, who carried it out, the request reference, how many records were removed from which stores, and a one-way keyed hash of each email address on the account. It holds no name, address or content. It lets YouSpot demonstrate that the request was honoured (Article 5(2)) and recognise a later request from the same person, as Article 17(3)(e) permits.
- Billing records. Stripe keeps invoices and payments, and YouSpot keeps a mirror of subscription billing facts with the link to the account removed, to meet accounting and tax obligations.
- Exit survey answers, if the User gave any, with the link to the account removed.
- Backups. Copies in automated database backups are deleted within 30 days. YouSpot will not restore a deleted account from backup, and if a backup is ever restored for disaster recovery it will re-apply completed deletions before returning the system to service.
- Provider-side copies. Requests already sent to AI providers are not retained by our model gateway, which runs with zero data retention, and expire on the providers' own schedules (Anthropic and OpenAI: within 30 days).
- Data that is not the account's. Public-profile caches shared across the service (for example public LinkedIn and X profile data used for enrichment) are not keyed to any account. Data about the same person held in another customer's account belongs to that customer.
12.4 End of the Agreement. On termination Customer may export Customer Personal Data for30 days, after which YouSpot will delete it as in 12.2 and 12.3, unless UK, EU or MemberState law requires storage. On request YouSpot will confirm deletion in writing.
13. Audits
13.1 YouSpot will make available the information reasonably necessary to demonstrate compliancewith Article 28, including its information security policy, incident response policy, dataretention inventory and this Addendum's annexes, and, when complete, the results of its GoogleCloud Application Security Assessment (CASA).
13.2 If that information is not sufficient, Customer (or an independent auditor bound byconfidentiality) may audit YouSpot's compliance, no more than once a year, on at least 30 days'written notice, during business hours, at Customer's cost, without access to other customers'data. A supervisory authority may audit at any time.
14. Artificial intelligence and model training
14.1 No training by YouSpot. YouSpot will not use Customer Personal Data to train, fine-tuneor otherwise improve any machine learning model, YouSpot's or a third party's. YouSpot'scodebase contains no training or fine-tuning pipeline; Customer Personal Data reaches modelsonly as the input to a request made for Customer.
14.2 Providers. YouSpot uses every AI Subprocessor through a paid commercial API plan whoseterms do not permit the provider to train models on Customer Personal Data:
- Anthropic (Claude API and Managed Agents): no training on API inputs or outputs; API inputs and outputs are deleted within 30 days unless flagged for a Usage Policy violation; Managed Agents sessions and vaults are deleted by YouSpot on account deletion.
- OpenAI (direct API, including embeddings): no training on API data; YouSpot sends Responses API calls with
storeoff unless a conversation needs it. - OpenRouter (gateway to OpenAI, Anthropic, Google, xAI and TypeSafe models): the account runs with zero data retention, and every request also carries
provider.data_collection: "deny", so it is only routed to endpoints that neither store nor train on prompts. - Google Gemini API: used on the paid tier, under which Google does not use prompts or responses to improve its products.
- xAI, Perplexity, Mem0, TypeSafe and Recraft: used on paid API plans for the specific features listed in Annex 3.
14.3 Derived data. YouSpot creates vector embeddings, extracted memories and relationshipscores from Customer Personal Data solely to provide the Services to Customer. They areCustomer Personal Data and are deleted with the account.
15. General
15.1 Order of precedence. If this Addendum conflicts with the Agreement, this Addendumprevails for the processing of Customer Personal Data. If it conflicts with the SCCs or the UKAddendum, those prevail.
15.2 Liability. Each party's liability under this Addendum is subject to the limitations inthe Agreement, except where Data Protection Laws or the SCCs do not permit limitation.
15.3 Governing law. This Addendum is governed by the law that governs the Agreement (thelaws of the Commonwealth of Massachusetts), except that the SCCs are governed as stated inAnnex 4 and the UK Addendum by the laws of England and Wales.
Annex 1: Details of the processing
Subject matter. Provision of the YouSpot services: a personal relationship and knowledgegraph ("Second Brain") with an AI assistant, agents and integrations.
Duration. The term of the Agreement, plus the deletion periods in section 12.
Nature of the processing. Collection from Connected Services and uploads; storage;indexing, including vector embeddings; de-duplication and merging of contact records;enrichment from public sources; classification and scoring; retrieval and transmission ofrelevant excerpts to AI providers to answer requests; drafting and, when a User asks, sendingemails and messages; scheduled agents and monitors; export; deletion.
Purpose. To provide the Services to Customer and its Users as described in the Agreement,including keeping the Second Brain current, answering questions about it, draftingcommunications, surfacing what needs attention, and running agents the User configures.
Categories of data subjects.
- Users.
- Customer's contacts and correspondents: people who send or receive email to or from a connected mailbox (Gmail, Outlook), attendees and organisers of calendar events.
- People in Customer's professional networks: LinkedIn connections, people who message, invite, comment on or react to the User on LinkedIn; accounts the User follows, mentions or bookmarks on X.
- People in Customer's CRM: contacts and the people associated with companies and deals in a connected HubSpot portal.
- Members of a connected Slack workspace and participants in Granola meetings.
- People named in notes, files, Obsidian vaults, imports (CSV, LinkedIn export) and chat messages.
- People the User researches, monitors or asks the assistant about.
Categories of personal data.
- Identity and contact details: names, email addresses, phone numbers, social profile URLs and handles, photos.
- Professional information: employer, title, work history, company details, public posts.
- Communications content: email metadata and bodies, calendar event details, LinkedIn and Slack messages, X posts and bookmarks, meeting notes and transcripts, iMessage, SMS and Telegram messages with the assistant.
- CRM records: contact, company and deal properties and history.
- Files and notes the User uploads or syncs.
- AI interactions: prompts, assistant outputs, agent instructions and run results.
- Derived data: embeddings, extracted memories, relationship strength and interaction counts, classification labels.
- Technical data: IP address, browser and device data in request logs.
Special categories. The Services are not designed to process special category data orcriminal offence data. Such data may appear incidentally in communications or files Customerconnects; Customer is responsible for having a lawful basis for it.
Frequency. Continuous for the term of the Agreement.
Retention. For as long as the account exists, except: inbound mail-arrival events (30days); a deleted Gmail-derived Brain item (removed for good 24 hours after deletion); processedSlack event envelopes (7 days); Telegram messages not linked to an account (7 days); Brain export files(7 days); calendar caches (10 minutes). Account deletion as in section 12.
Annex 2: Technical and organisational measures
These are the measures in place on the date above.
Encryption in transit. All traffic to the web app and API uses TLS, with HSTS(max-age=63072000; includeSubDomains; preload). Application connections to the databaserequire TLS (sslmode=require).
Encryption at rest. The database and file storage are encrypted at rest by the hostingprovider (Supabase on AWS). In addition, YouSpot encrypts the credentials of Connected Servicesat the application layer (Fernet, keyed from a secret held in YouSpot's secrets manager): OAuthaccess and refresh tokens for Google, Microsoft, LinkedIn, X, HubSpot and Slack, API keys forGranola and Substack, MCP server credentials and the Google sign-in token. Bearer credentialsYouSpot issues (session and MCP tokens) are stored only as SHA-256 digests.
Access control. Every API request is authenticated and scoped to the account that owns thedata; administrator rights are checked against the database on every request. Productiondatabase, hosting and secrets consoles require multi-factor authentication. Ad hoc productionreads use a separate read-only database role with a statement timeout. Secrets are held in asecrets manager (Doppler) and injected at runtime, never in source control; a CI check fails oncommitted secrets.
Logging and monitoring. Account and administrative actions (including administrator accountclosures) are recorded in an activity log; backend errors are reported to Sentry with personaldata collection off and credentials scrubbed before sending.
Application security. Repeated failed authentication attempts are rate limited (20 perminute per address); session cookies are SameSite=Lax and cross-site writes are refused;responses carry X-Content-Type-Options, X-Frame-Options: DENY, Referrer-Policy andPermissions-Policy headers. Dependencies are scanned daily (pip-audit, bun audit) and updatedmonthly through Dependabot.
Data minimisation and retention. Tool activity logs for Gmail and Calendar store counts andidentifiers, not content; the retention windows in Annex 1 are enforced by a daily job inproduction.
Resilience. Automated daily database backups by the hosting provider, kept for 30 days.
Deletion. Self-service account deletion as described in section 12, with an automated testthat fails when a new table holding personal data is not covered by deletion or explicitlyexcluded with a reason.
Organisational. A written information security policy and incident response policy; a namedsecurity officer; access reviewed at least annually; personnel bound by confidentiality.
Annex 3: Subprocessors
The current list, with what each Subprocessor does and the data it touches, is published atyouspot.com/terms#subprocessors.
Annex 4: Transfer mechanism details
SCCs (EU).
- Modules: Module Two (Customer controller to YouSpot processor); Module Three (Customer processor to YouSpot subprocessor).
- Clause 7 (docking clause): not included.
- Clause 9(a): Option 2 (general written authorisation), with the notice period in section 7.2.
- Clause 11(a): the optional language is not used.
- Clause 13: the supervisory authority determined under Clause 13(a) for Customer, or, where that cannot be determined, the Irish Data Protection Commission.
- Clause 17: the law of Ireland.
- Clause 18(b): the courts of Ireland.
- Annex I.A: data exporter is Customer (details in the Agreement); data importer is YouSpot, Inc., Two Canal Park, Cambridge, MA 02141, USA, privacy@youspot.com, role processor.
- Annex I.B: as in Annex 1 of this Addendum.
- Annex I.C: as in Clause 13 above.
- Annex II: as in Annex 2 of this Addendum.
- Annex III: as in Annex 3 of this Addendum.
UK Addendum.
- Table 1: the parties as in the Agreement; start date the effective date of this Addendum.
- Table 2: the Approved EU SCCs, Modules Two and Three, with the options above.
- Table 3: Annexes 1A, 1B, II and III as above.
- Table 4: neither party may end the UK Addendum under its Section 19.