Yapily’s Data Handling Agreement (DHA) FAQs
Last updated: 01 October 2026
These FAQs are designed to help you understand our data protection documentation and how personal data is handled across the different Yapily services. They should be read together with the Data Handling Agreement and the Privacy Policy (as applicable), which remain the governing documents. Any term used but not defined in these FAQs has the meaning given to it in the Data Handling Agreement. These FAQs are provided for general guidance only and do not form part of, or vary, your agreement with Yapily.
What is the GDPR?
The GDPR is the main law on how organisations handle personal data, meaning any information about an identifiable person. The UK has the UK GDPR alongside the Data Protection Act 2018. The EU and wider EEA have the EU GDPR. They work in much the same way: data must be handled lawfully, fairly and securely, and people have rights over their data, such as asking to see it or delete it. In these FAQs, “GDPR” covers both, and with other data protection law we call it the “Data Protection Laws”.
What is an independent data controller?
An independent controller decides the why and how of its own processing on its own, not jointly with another organisation. Where a Yapily entity is an independent controller, it does so for the processing it needs to run its own services, and it is responsible for that in its own right. You may also be an independent controller of the same data for your own purposes, for example serving your own customers. Each side relies on its own lawful basis and is responsible for its own processing.
What is a data processor?
A data processor handles personal data for a controller, and only on that controller's written instructions. It does not decide why the data is processed. A processor still has direct duties under the GDPR: keeping data secure, using only approved sub-processors, helping the controller respond to data subject requests, and returning or deleting the data at the end of the service. It cannot use the data for its own purposes.
How do the Yapily services map to controller or processor status?
It depends on which Yapily entity provides your services.
Yapily Connect Ltd or Yapily Connect UAB providing the regulated Yapily Connect Services: they and you are each independent controllers. See Annex A of the DHA.
Yapily Ltd providing Technology, Support or Implementation Services, or the Data or Payments Product Suite: Yapily Ltd is your processor. See Annex B of the DHA.
If you take services from more than one entity, both annexes can apply.
What are the Yapily Connect Services?
These are Yapily's regulated open banking services. Account Information Services (AIS) retrieve a PSU’s account and transaction data with their consent. Payment Initiation Services (PIS) start payments on their behalf. Both run through Yapily's API, and the Yapily Connect entities act as controllers for them.
Who is who: Customer, PSU and sub-client?
Customer: the business that has an agreement with Yapily. “You” means the Customer.
PSU (Payment Service User): the person whose account data is accessed or whose payment is initiated. They are the data subject.
Sub-client: your own customer, where you use Yapily's services to serve them and act as their processor. Here, Yapily Ltd is your sub-processor, and you handle the contract and privacy information with your sub-client.
Which version of the DHA applies to you?
It depends on when you entered into your agreement with Yapily.
Not sure? Contact dpo@yapily.com.
Why has Yapily chosen to change its determination of controller v processor status under the new DHA published on 1 October 2026?
The new roles match what the Yapily Connect entities actually do. As regulated providers of AIS and PIS, they must decide how and why the data is processed to meet their own legal duties, so they act as controllers, not processors. Yapily Connect Ltd is regulated by the FCA and Yapily Connect UAB by the Bank of Lithuania. This describes Yapily's position and does not change yours, whether you are an independent controller or a processor of the same data.
When will Yapily act as a data controller?
A Yapily entity is a controller where it decides the why and how of the processing a service needs. Right now, that is the Yapily Connect entities providing the regulated Yapily Connect Services. When you take those services, Yapily Ltd also provides the underlying technology as a processor or sub-processor on the Connect entity's instructions.
When will Yapily act as a data processor?
A Yapily entity is a processor where it processes data only according to your written instructions and does not decide the why or how. Right now, that is Yapily Ltd providing Technology, Support and Implementation Services, or the Data and Payments Product Suites. It uses the data only to provide those services to you.
Where can I find the Privacy Policy?
The updated Yapily Privacy Policy is published at https://www.yapily.com/legal/privacy-policy.
It sets out in full how the relevant Yapily entities use personal data, the lawful bases they rely on, and how individuals can exercise their rights.
Where can I find the up-to-date sub-processors list, and how will I be notified of any changes?
It is in Schedule 3 of Annex B to the DHA, with each sub-processor's service, location and transfer safeguards. If Yapily Ltd wants to add or replace a sub-processor while acting as your processor, we tell you in advance and you have fifteen (15) business days to raise a reasonable objection. This does not apply where a Yapily entity acts as a controller.
What is the difference between the Privacy Policy and the Data Handling Agreement?
DHA: a contract between you and Yapily. It sets out each side's roles and duties for data, such as security, breaches, transfers, sub-processors and retention. It forms part of your Services Agreement.
Privacy Policy: a transparency document for individuals, including PSUs. It explains how a Yapily entity uses personal data when acting as a controller.
When do we or Yapily need to seek the consent of the PSU?
Before AIS or PIS can run, the PSU must give explicit consent and authenticate with their bank. As the regulated provider, the Yapily Connect entity gets and records that consent and handles any withdrawal. Your job is to support that journey, for example by showing the consent screens, and to tell us promptly if a PSU withdraws through you. This regulatory consent is separate from consent as a lawful basis under the Data Protection Laws. Each side decides its own lawful basis for the relevant data processing. See Annex A of the DHA.
Is Yapily registered with the data protection regulator?
Yes. Each Yapily entity keeps up the registrations and fees the ICO or its national regulator requires. This is a warranty in the DHA.
Will customer personal data be processed or transferred outside the UK or EEA?
Some processing may happen abroad, for example, where a sub-processor is based. When it does, Yapily first puts safeguards in place, such as an adequacy decision, the Standard Contractual Clauses with the UK Addendum, or the UK IDTA. The sub-processor list shows each location and safeguard.
How long will customer personal data be kept, and what happens when the contract ends?
Yapily keeps personal data only as long as it is needed, plus any additional period required by law. When your Services Agreement ends, Yapily will return, delete, anonymise or restrict the data, unless it has to keep some for a legal reason such as defending a claim.
Who do I contact if I have questions?
Please contact success@yapily.com with any questions about the new Data Handling Agreement or the Privacy Policy, and we will be happy to help.