Legal

Data Processing Agreement

Last updated: October 6, 2026

This agreement applies when a business or organization (the "customer") uses ListSpace.app to process personal data, such as data about its staff or clients, under the General Data Protection Regulation (GDPR). It meets the requirements of Article 28 GDPR.

The customer is the controller. Sjenkie B.V., trading as Yellow House Digital, registered in the Netherlands (Chamber of Commerce NL: 60310030), which runs ListSpace.app, is the processor ("we", "us"). It adds to the Terms of Service.

1. Subject and duration

We process personal data for the customer only to provide ListSpace.app as described in the Terms of Service. This agreement runs for as long as the customer has a ListSpace account, and the obligations about deletion and confidentiality continue after that.

2. Nature and purpose of the processing

Storing, showing, changing, sharing on instruction, backing up and deleting the content the customer puts in ListSpace, and sending the emails the customer turns on. We do not use the customer's data for any purpose of our own, do not sell it and do not use it for advertising.

3. Types of personal data and data subjects

Data subjects: the customer's users, and any person the customer writes about or uploads files about, such as staff, clients, suppliers or other contacts.

Personal data: account details (email address, name, profile picture, timezone), the content of boards, lists, items, comments, checklists and files, email sent to a board address, and technical data such as IP addresses. The customer decides what content to store. ListSpace is not designed for special categories of personal data (Article 9 GDPR); the customer is responsible if it stores them.

4. The customer's instructions

We process the data only on the customer's documented instructions. Using the service and its settings, and this agreement, are those instructions. If we believe an instruction breaks the GDPR or other data protection law, we tell the customer. If the law requires us to process data in another way, we tell the customer first, unless the law forbids that.

5. Confidentiality

Everyone who can reach the customer's data on our side is bound to confidentiality. We look at content only when the customer asks us to, when it is reported to us, or when the law requires it.

6. Security

We take appropriate technical and organizational measures under Article 32 GDPR. They are described on the Trust page and include encrypted connections, hashed passwords, row-level security in the database, private files behind short-lived signed links, and regular backups. We may improve these measures, but not lower the level of protection.

7. Sub-processors

The customer gives general permission for the sub-processors on the sub-processors page. At least 30 days before we add or replace one, we update that page and email the customers who signed this agreement. A customer that does not agree with the change can object by ending its use of the service before the change takes effect. Each sub-processor is bound by data protection terms that give at least the same protection as this agreement, and we remain responsible for its work.

8. Transfers outside the EU

The database and sign-in run on our server in Germany, and files are stored in the European Union. Emails are sent through MXroute from a server in the United States, and some Cloudflare services may process data outside the European Economic Area. Where a sub-processor processes data outside the European Economic Area, the transfer is covered by the European Commission's standard contractual clauses or another safeguard under Chapter V GDPR.

9. Personal data breaches

If we become aware of a personal data breach that affects the customer's data, we tell the customer without undue delay and at most 48 hours after we became aware of it. We give the information the customer needs to meet its own duties under Articles 33 and 34 GDPR, as far as we have it: what happened, which data and how many people are affected, the likely consequences, and the measures taken. We then keep the customer informed.

10. Help with the customer's obligations

We help the customer, as far as reasonable, to answer requests from data subjects (access, correction, deletion, restriction, portability and objection), and with security, breach notification, data protection impact assessments and prior consultation (Articles 32 to 36 GDPR). Much of this the customer can do in the app: export boards as CSV or JSON, edit or delete content, and delete accounts. If a data subject contacts us directly about the customer's data, we pass the request on to the customer.

11. Deletion or return at the end

The customer can export its boards at any time. When the customer deletes its account, or asks us to at the end of the service, we delete its personal data: the account, boards, lists, items and uploaded files. Copies in backups disappear in the normal backup cycle. We keep data longer only where the law requires it.

12. Showing compliance

On request, we give the customer the information it needs to show that this agreement is met: this page, the Trust page, the sub-processor list, and answers to a reasonable security or privacy questionnaire once a year.

13. Liability and order of documents

Liability under this agreement follows the Terms of Service, unless the law does not allow that. If this agreement and the Terms of Service disagree about personal data, this agreement applies. This agreement is governed by the laws of the Netherlands.

14. How to sign

Email hello@listspace.app with your organization's name, registered address, the email address of your ListSpace account and the name of the person signing. We send back a copy of the agreement as published on this page, for both parties to sign.