Yes Chef AI · Legal
Data Processing Agreement
Processor terms that apply when a Customer uses Yes Chef AI to store operational personal data.
1. Parties, definitions and scope
This Data Processing Agreement (DPA) is between the Customer and Yes Chef AI Ltd. It applies to personal data that the Customer or its users enter into the Service for the Customer's own purposes (Customer Personal Data).
Controller, processor, personal data, processing, personal-data breach and data subject have the meanings in UK data-protection law, including the UK GDPR and the Data Protection Act 2018 as amended. This DPA does not apply where we act as controller, which is described in the Privacy Policy.
If this DPA conflicts with another part of the agreement about processing of Customer Personal Data, this DPA takes priority to the extent of the conflict.
2. Customer's instructions
We will process Customer Personal Data only on the Customer's documented instructions, unless UK law requires otherwise. Documented instructions include: the Terms, this DPA, the Customer's configuration and use of the Service, and written instructions the Customer gives us.
We will tell the Customer if, in our opinion, an instruction infringes UK data-protection law, unless the law prohibits that notice. If law requires processing other than as instructed, we will tell the Customer before processing unless the law prohibits that notice.
The Customer instructs us to process Customer Personal Data to provide, secure, back up and support the Service, including using the providers listed in Schedule 2 where the relevant feature is used.
3. Customer's responsibilities
The Customer is responsible for:
- determining the purposes and essential means of its processing;
- ensuring it has a lawful basis, and where relevant an Article 9 condition, for Customer Personal Data it places in the Service;
- providing required privacy information to data subjects, including its own workers;
- configuring user access, including who may view fitness-to-work declarations; and
- not submitting special-category data to AI features unless that is necessary and lawful for the Customer's purpose.
4. Confidentiality of processing staff
We will ensure that people we authorise to process Customer Personal Data are subject to a duty of confidentiality and access it only as needed for their role.
5. Security
Taking account of the nature, scope, context and purposes of the processing and the risk to individuals, we will implement appropriate technical and organisational measures as required by UK GDPR Article 32. Current measures include:
- authentication of users;
- access controls and tenant separation of Customer records;
- HTTPS for production access;
- HttpOnly session cookies for application admission;
- restricted use of service credentials;
- backup and recovery arrangements provided by our infrastructure providers; and
- incident-response processes.
We do not claim a named security certification in this DPA. The Customer remains responsible for configuring authorised users and for the devices they use.
Fitness-to-work declarations, where enabled by the Customer, are stored in the Customer's tenant records with the same tenant isolation as other operational records. Access is limited to users the Customer authorises and to our staff and providers who need access to operate the feature.
6. Subprocessors
The Customer gives general written authorisation for us to use subprocessors needed to provide the Service. Current subprocessors for Customer Personal Data are listed in Schedule 2.
We will impose data-protection obligations on each subprocessor that are no less protective than those in this DPA, in particular as required by UK GDPR Article 28(4). We remain responsible to the Customer for the subprocessor's performance of those obligations.
We will give the Customer reasonable notice of a material addition or replacement of a subprocessor that processes Customer Personal Data, by updating Schedule 2 on this page or by email, so the Customer can raise a reasonable objection on data-protection grounds. If we cannot reasonably accommodate the objection, either party may end the affected Service in accordance with the Terms. This DPA does not set a fixed number of days' notice.
Stripe processes payment data as our payment provider. Card details are not stored by Yes Chef AI. Stripe is not used to host kitchen operational records.
7. International transfers
The Customer instructs us to transfer Customer Personal Data to the subprocessors in Schedule 2, including where those subprocessors process data outside the United Kingdom, as needed to provide the requested feature.
Where a transfer is a restricted transfer under UK GDPR, we will ensure it is made only with a lawful mechanism: UK adequacy regulations; appropriate safeguards such as the UK International Data Transfer Agreement or UK Addendum, with a transfer risk assessment where required; or an applicable Article 49 exception. This DPA does not itself reproduce signed transfer contracts. The Customer may ask us for the current transfer position for a named subprocessor.
8. Assistance with data-subject rights
Taking account of the nature of the processing, we will provide reasonable assistance to the Customer, through the Service's existing functions where possible, so the Customer can respond to requests to exercise data-subject rights. If we receive a request that relates to Customer Personal Data, we will redirect it to the Customer unless law requires us to act directly.
9. Personal-data breaches
We will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data. The notice will include information then reasonably available to us to help the Customer meet its own notification duties, including the nature of the breach, likely consequences, and measures taken or proposed. We will update the Customer as further information becomes available.
This DPA does not set a fixed hour-count for notification.
10. DPIA and regulator consultation
Taking account of the nature of the processing and information available to us, we will provide reasonable assistance with data-protection impact assessments and prior consultation with the ICO where those exercises relate to our processing of Customer Personal Data.
11. Return and deletion
When the Service ends, the Customer may export Customer Content using the export functions then available, or ask us in writing to return a copy of Customer Personal Data where that is technically practicable. After the Service ends, and at the Customer's choice where technically and legally applicable, we will delete Customer Personal Data from live systems, except:
- where UK law requires retention;
- where information remains in routine encrypted backups for a limited period until those backups expire in the ordinary cycle; and
- where a user's personal account is deleted but the Customer still requires organisation operational records, those records remain the Customer's data until the organisation is closed in accordance with the Terms.
We do not promise that every copy is erased immediately from all backups. If a Customer asks us to close an organisation, we record that request and complete deletion of live Customer Personal Data as part of offboarding.
12. Information, audits and inspections
We will make available information reasonably necessary to demonstrate compliance with this DPA. The Customer may exercise audit rights as follows:
- first, by written questions and review of information we already produce (including this DPA, the Privacy Policy, and security descriptions we can share);
- then, if that is not reasonably sufficient, by an independent auditor bound by confidentiality, on reasonable notice, during business hours, no more than once in any 12-month period except after a personal-data breach or ICO request; and
- without accessing other customers' data, our unrelated systems, or information that would compromise security.
13. Special-category data
If the Customer enables daily fitness-to-work declarations, we will process health information (symptom declarations and related fitness status, including any manager override reason) solely to provide that feature. The Customer determines the Article 6 basis and Article 9 condition. We will not use that data for our own purposes, and we will not send it to AI subprocessors unless the Customer includes it in a prompt or other input to an AI feature.
14. Contact
Data-protection enquiries: hello@yeschefai.co.uk.
Schedule 1 — Processing details
| Subject matter | Hosting and processing Customer Personal Data in the Yes Chef AI Service |
|---|---|
| Duration | The term of the Customer's agreement and any residual backup or legal-retention period |
| Nature | Hosting, storage, organisation, retrieval, display, transmission, backup, security logging, and, where the Customer uses the feature, AI-assisted analysis or document extraction |
| Purpose | To provide the Service the Customer has selected |
| Data subjects | The Customer's authorised users; workers and staff whose details the Customer records; supplier or other business contacts the Customer records; and other individuals whose information the Customer chooses to place in the Service |
| Types of personal data | Names, work contact details, roles, account identifiers, activity records, operational and audit records, evidence files, task and sign-off information, recipe and allergen records, and other Customer-selected content |
| Special-category data | Only if the Customer enables fitness-to-work declarations: health/symptom information connected with food-handler fitness, and related manager-override reasons |
Schedule 2 — Subprocessors of Customer Personal Data
Current as of 23 August 2026. A provider appears here only where product evidence shows it can process Customer Personal Data.
| Provider | Processing activity | When used |
|---|---|---|
| Vercel | Application hosting and delivery | All Service use |
| Supabase | Database, authentication infrastructure and file storage | All Service use |
| Anthropic | AI model inference on prompts, images or source material submitted to the feature | When the Customer uses Anthropic-backed features |
| Groq | AI model inference on prompts and conversation context | When the Customer uses Groq-backed chat/agent features |
| Microsoft Azure (Document Intelligence) | Extraction from invoices or receipts the Customer submits | When the Customer uses that feature |
| Upstash | Rate-limiting identifiers for PIN and similar controls | When those controls are used |
| Brevo | Delivery of transactional emails that may include user name and email | When the Service sends account or operational notification emails |
Hosting and processing locations are those operated by the named provider. Some providers process data outside the United Kingdom. See clause 7.
Company details
Yes Chef AI Ltd
Registered in England and Wales
Company no. 17117657
Registered office: 71–75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
hello@yeschefai.co.uk