Legal

Data Processing Addendum

How we process personal data on your behalf. This addendum is part of the Terms of Service and applies to every workspace automatically; nothing needs signing. If your procurement process needs a countersigned copy, ask and we will send one.

Last updated 24 September 2026

1. Parties and scope

This Data Processing Addendum (DPA) is between the customer who owns a workspace on the Service (Customer, you) and Jia Yang Inc., trading as Jiayang Cloud (Jiayang, we):

Jia Yang Inc. 2810 N Church St STE 90394 Wilmington, DE 19802 US Contact: privacy@jiayang.cloud

It applies whenever we process personal data on your behalf in providing the Service under the Terms of Service. It is intended to meet the requirements of Article 28 of the GDPR and the UK GDPR, and the equivalent provisions of other laws that require a written contract between a controller and its processor.

2. Definitions

Data protection law means every law that applies to the processing of personal data under this DPA, including the GDPR, the UK GDPR and Data Protection Act 2018, the Swiss FADP, and Singapore's Personal Data Protection Act 2012. Personal data, processing, controller, processor, data subject, personal data breach and supervisory authority have the meanings given in the GDPR. Customer data means the personal data you or your users put into the Service or that the Service produces for you, as described in Annex 1. Subprocessor means a third party we engage to process customer data. SCCs means the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914.

3. Roles

For customer data, you are the controller (or a processor acting for your own controller) and we are your processor. That covers the people you share apps with, the data your apps store, the audit log of who used them, and the members of your workspace in their capacity as your users.

For the data we need to run our relationship with you (your account, sign-in security, billing, support), we are an independent controller, as described in the Privacy Policy. This DPA does not apply to that.

You are responsible for the lawfulness of the data you process on the Service: for having a basis to collect it, for telling data subjects what you do with it, and for the instructions you give us.

4. Instructions

We process customer data only on your documented instructions. Your instructions are: this DPA, the Terms of Service, and what you do in the Service (deploying an app, sharing it, setting a public path, exporting or deleting data). Using the Service's features is an instruction to do what those features do.

We will tell you if we believe an instruction breaks data protection law, and we may pause the affected processing until it is resolved. We will not process customer data for any purpose of our own, and we will not sell it.

If a law we are subject to requires us to process customer data otherwise, we tell you before we do, unless that law forbids it on important grounds of public interest.

5. Confidentiality

Everyone we authorise to process customer data is bound by a written duty of confidentiality, is given access only as far as operating the Service needs, and has that access logged. We don't read the content of your apps or the data they store, except where you ask us to for support or where a legal obligation requires it.

6. Security

We implement and maintain the technical and organisational measures in Annex 2, which are designed to protect customer data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. We may improve them over time; we will not reduce the overall level of protection during the term.

The Service is built so that you can meet your own obligations: a signed identity on every request, a complete audit log, revocation within a minute, an export of the workspace and of each app's database on every plan, and a delete that is immediate and complete.

7. Subprocessors

You give us general authorisation to engage the subprocessors in Annex 3 and on the Subprocessors page. Each of them is bound by a written contract with data protection obligations at least as protective as this DPA, and we remain fully responsible to you for their performance.

Notice. We tell workspace owners by email at least 30 days before adding or replacing a subprocessor, with what it will do and where.

Objection. If you object on reasonable data protection grounds within those 30 days, we will talk to you about a way around it. If there is none, you may end the affected workspace's plan and delete the workspace before the change takes effect, and we refund any prepaid fees for the period after that.

8. Data subject requests

If a data subject contacts us about data in your workspace, we point them to you and tell you, unless the law requires us to answer directly. We don't respond on your behalf.

The Service gives you the means to answer most requests yourself: the audit log shows what was processed about whom; the export gives it to you in a portable form; removing a share or deleting a record is immediate, though a record deleted from an app's database stays in that database's point-in-time history for up to 30 days (Annex 2). Where a request needs something the Service can't do, we assist within a reasonable time, at no charge unless the effort is disproportionate, in which case we agree a cost with you first.

9. Personal data breaches

If we become aware of a personal data breach affecting customer data, we notify the affected workspace owners without undue delay, and in any case within 72 hours of confirming it, by email to the owner's address. The notice says what happened, which data and roughly how many people are affected, what we have done and are doing, and who to contact. We update it as we learn more.

We cooperate with you and give you the information you reasonably need to meet your own notification obligations. We don't notify supervisory authorities or data subjects on your behalf unless you ask us to in writing or the law requires it.

10. Assistance

Taking into account the nature of the processing and the information available to us, we assist you with data protection impact assessments and prior consultations with a supervisory authority, where they concern the Service. The Security page, Annex 2 and the Subprocessors page are written to be the starting material for one.

11. Deletion and return

You can export customer data at any time while the workspace exists, on every plan: the workspace as one JSON document (configuration, members, grants, the names of tokens, secrets and environment variables, and the retained audit log) and each app's database as SQL. A static site is the files you uploaded. When you delete an app or a workspace, or when the agreement ends, deletion is immediate and permanent: the apps are taken offline at once and their scripts, databases, containers and files are removed from Cloudflare right away. A deleted app's configuration, versions, sharing grants, tokens, secrets and environment variables go with it. Its entries in the workspace's audit log, the one recording the deletion among them, stay for the audit log's retention (Annex 1) like any other entry, and go with the workspace. Only the control plane's own records of a deleted workspace linger, for 30 days, for accounting; they are never restored. The control-plane database's restore history (Neon's point-in-time restore, up to 7 days on the plan we run: Launch, neon.com/pricing, checked 22 September 2026) ages out within a further 7 days and is not used to restore deleted data. While an app exists, what it deletes or overwrites in its database stays in Cloudflare D1's point-in-time history for up to 30 days (Annex 2). We confirm deletion in writing if you ask.

We keep only what the law requires us to keep (billing records, for example), for as long as it requires, and protect it as confidential.

12. Audit

We make available the information you need to show that we meet the obligations in this DPA. In order:

  1. The documentation we publish: this DPA, the Security page, the Subprocessors page, and our providers' own certifications and reports.
  2. Written answers to a reasonable security questionnaire, once a year, or after a breach or a material change.
  3. An audit, by you or an independent auditor you appoint who is bound by confidentiality and is not a competitor of ours, no more than once a year unless required by a supervisory authority or following a breach, on at least 30 days' written notice, during business hours, in a way that does not disrupt the Service or expose other customers' data, and at your cost. You give us a copy of the findings.

13. International transfers

Customer data may be processed in the countries listed in Annex 3. Where that involves a transfer of personal data protected by the GDPR, the UK GDPR or the Swiss FADP to a country without an adequacy decision:

If a transfer mechanism we rely on stops being valid, we will work with you in good faith to put an alternative in place.

14. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, taken together with liability under the Terms as a single cap, except where data protection law does not allow a limitation.

15. Term and precedence

This DPA lasts as long as we process customer data for you, and sections 5, 11 and 14 survive it. If it conflicts with the Terms of Service, this DPA wins for personal data. If it conflicts with the SCCs, the SCCs win. We may update this DPA to reflect changes in law or in the Service, with the notice described in the Terms; a change that reduces your protection needs your agreement.

Annex 1: Details of the processing

Subject matterHosting, serving, access control and audit logging of the applications the Customer deploys on the Service.
DurationThe life of the Customer's workspace; the control plane's records of it for a further 30 days.
Nature and purposeStoring and running the Customer's code and data; authenticating the people the Customer shares apps with and passing their identity to the app; recording every request and every change in an audit log; sending invitation emails on the Customer's instruction; holding third-party credentials the Customer gives us and attaching them to the app's outgoing requests; checking the signature of each delivery to a verified public path with the signing secret the Customer gives us, before the delivery reaches the app.
Categories of data subjectsThe Customer's staff and contractors who are workspace members; the people the Customer shares apps with (typically colleagues, contractors, clients); the end users of the Customer's apps, whose data the apps store; anyone whose data appears in the Customer's content.
Categories of personal dataEmail addresses and roles; sign-in and request metadata (IP address, user agent, country, timestamps, paths, response codes); the audit log; the contents of deliveries to a verified public path, which the control plane reads to check their signature and does not keep, apart from the identifier the provider gives a delivery, which is recorded in the audit log, and, where the provider signs the time it sent a delivery, a hash of the delivery's signature, kept so that a replayed copy can be refused and deleted within an hour; and whatever the Customer's apps store, which is determined by the Customer. The Service is not designed for special categories of data or for data about children, and the Customer must not use it for those without a written agreement with us covering the additional measures required.
FrequencyContinuous, for as long as the workspace exists.
RetentionAs set out in section 11 and in the Privacy Policy; the audit log for 3 months (Free, Team) or 12 months (Business), and after a downgrade, events older than the new plan's retention are deleted 30 days after the plan changed.

Annex 2: Technical and organisational measures

Access to apps

Isolation between customers

Encryption

Audit and monitoring

People and process

Annex 3: Subprocessors

The current list, kept up to date, is the Subprocessors page. At the date of this DPA it is:

SubprocessorWhat it doesLocation
Cloudflare, Inc.Hosting, edge network, application runtime and storage, audit queueRequests on the global edge; account data in the United States
Neon, Inc.The control-plane database (Postgres)AWS us-east-2 (Ohio), United States
Resend, Inc.Transactional email: sign-in codes, invitations, notices to workspace owners, and alerts to our own staffeu-west-1 (Ireland)
Stripe, Inc.Payments, invoicing and tax; receives the workspace owner's email address and the workspace name as the customer's email and name, and the hourly request countsUnited States
Proton AGOur support, privacy and security mailboxes: the email you send us and our answersSwitzerland, Germany or Norway