yodev Spend
2026-09-06

Data Processing Agreement

Spend acts as a processor for customer-imported data and documents purposes, security controls, retention, and onward subprocessors.

Scope and instructions

For personal data entrusted to a workspace, the client determines purposes and instructions; the publisher processes it to provide provider inventory and spending tracking. Operations include authorized collection, organization, access, export and erasure. Data subjects may include users, employees, client contacts and provider representatives.

Security and confidentiality

Access is restricted by workspace and role. Connection secrets are encrypted, amounts retain their currency, and audit events exclude repository contents and secrets. Authorized personnel must maintain confidentiality. Incident procedures must support notifying the client without undue delay after discovering a breach and documenting remedial action.

Assistance and subprocessors

The publisher assists with individual requests, security evidence, incidents and necessary impact assessments. Providers, roles and locations appear in the subprocessors document. Change notification, objection rights, transfer safeguards and audit procedures must be agreed in the final contract.

Return and erasure

Owners can export data. A deletion request stops connections and opens a thirty-day export period before business data erasure. Identities shared across workspaces and the publisher's own legal obligations are handled separately. Backup retention must be finalized, and restored backups must reapply erasures.

Publisher identity

The publisher’s complete legal identity must be supplied before commercial launch.

Contact

The professional support address must be confirmed before commercial launch.