almondaccount

Effective August 21, 2026 · Provider: Yeira Inc.

Data Processing Addendum

Default data-processing terms for customer content handled by the standard Almond service.

The service boundary. Almond is an agent-agnostic, lightweight publishing and persistence process. It does not select, train, supervise, or control the AI model, agent, agentic harness, prompts, tools, or external systems that a customer connects. Those components remain separate services under the customer's direction.

This addendum is a baseline contract template, not a claim that every deployment or use case is automatically compliant. It applies only when incorporated into an Agreement between the customer and Yeira Inc., a United States company.

1. Parties and roles

For Customer Personal Data, Customer is the controller or processor as applicable, and Yeira Inc. is the processor or subprocessor. Each party will comply with data protection law applicable to its role. Customer determines the purposes of processing, the data sent to Almond, permitted users and agents, collection fields, public visibility, retention, and the lawfulness of its instructions.

2. Instructions and details

Almond will process Customer Personal Data only to provide, secure, maintain, and support the service; follow documented instructions in the Agreement and product configuration, including transmission of explicitly projected action fields to a Customer-approved fixed endpoint; or comply with law. Processing lasts for the Agreement term and any limited deletion or backup period.

Subject matterLightweight publication, persistence, forms, files, records, revisions, domains, protected fixed-endpoint actions, authorization, export, and diagnostics.
Data subjectsCustomer personnel, collaborators, site visitors, form respondents, and other people whose data Customer submits.
Data typesAccount data, online identifiers, customer-defined form and record fields, content and files, protected endpoint credentials, authorization metadata, and diagnostics. Sensitive or regulated data is not intended unless expressly agreed.
OperationsCollection, transmission, organization, storage, retrieval, display, modification, export, restriction, security monitoring, and deletion.

3. Customer instructions and harness controls

Customer instructs Almond through its users, API and MCP calls, product configuration, and connected agentic harness. Customer is responsible for confirming that people and machines issuing instructions are authorized, limiting scopes, protecting credentials, validating generated schemas and collection fields, and preventing a harness from sending prohibited or unnecessary data. Almond is not required to inspect prompts or infer whether an instruction is legally appropriate.

4. Confidentiality and security

Almond will ensure personnel authorized to process Customer Personal Data are subject to confidentiality duties and will maintain technical and organizational measures appropriate to the service risk. Standard measures include logical tenant separation, scoped and revocable capabilities, digest storage for high-entropy capabilities, password hashing, authenticated application-layer encryption for protected action values, fixed-hostname and public-network enforcement for outbound actions, transport encryption through service providers, request bounds, abuse controls, and restricted infrastructure identities.

5. Subprocessors and external resources

Customer generally authorizes Almond to use subprocessors to provide the service. Almond remains responsible for imposing data-protection obligations appropriate to their services. The standard categories and currently identified providers are application hosting, compute, database, storage, and protected-action key environment (Convex); account identity interface and token validation (Google); and managed domain and certificate infrastructure (Amazon Web Services). The account page loads Google Identity Services to offer optional Google sign-in. Customer-selected URLs, including protected action endpoints, remote avatars, or resources embedded in Customer content, transmit data to the selected external provider. Those direct recipients are not made Almond subprocessors merely because Customer configured their URL. Almond will provide notice of material new subprocessors through an agreed channel where required by the Agreement.

6. Assistance

Considering the nature of processing and information available to it, Almond will provide reasonable assistance with data-subject requests, security obligations, impact assessments, regulator consultations, and evidence of compliance. Customer is responsible for receiving and validating requests and for costs beyond standard product functionality unless law or a signed agreement provides otherwise.

7. Security incidents

Almond will notify Customer without undue delay after confirming a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data under Almond's control. Notice will include available information reasonably needed for Customer's obligations. Unsuccessful attacks, customer or harness credential exposure outside Almond, and events not involving Customer Personal Data are not Personal Data Breaches under this addendum.

8. Return, deletion, and audits

On termination or valid instruction, Almond will delete or return Customer Personal Data as required by the Agreement, except where law requires retention and subject to backup aging. Exports may not include credentials, sessions, active domain-provider resources, or security data. Almond will make available information reasonably necessary to demonstrate compliance and may satisfy audits through current reports, questionnaires, or a scoped independent review under confidentiality and reasonable limits.

9. Restricted data and transfers

Customer must not submit protected health information, payment-card data, government identification numbers, biometric templates, precise location, children's data, or other sensitive or specially regulated data unless a signed agreement expressly permits it. For restricted transfers from the EEA, the parties will incorporate the applicable module of the European Commission Standard Contractual Clauses adopted by Decision (EU) 2021/914 and complete the required annexes, transfer-impact assessment, and supplementary-measures analysis. UK transfers will use the applicable UK addendum or other lawful mechanism. No transfer terms are effective until validly incorporated into the Agreement.

10. Conflict

This addendum controls over conflicting Agreement terms only for processing of Customer Personal Data. Undefined capitalized terms have the meanings in applicable data protection law or the Agreement.