Yesper
  • Services
  • Platform
  • Customers
  • Pricing
  • Resources
    • Help centerTips and guides
    • InsightsArticles and reports
  • Company
    • About usWho we are
    • ContactChat with us
  • English
  • Svenska
Log in Book demo

Data Processing Agreement

Omiwato Ventures AB (operating as Yesper) · Last updated 3 September 2026

This Data Processing Agreement ("DPA") forms an integral part of the Terms of Service (the "Terms") and applies where Omiwato Ventures AB, registration number 559518-7674, operating as Yesper ("Yesper", "we"), processes Personal Data on behalf of a customer ("Customer", "you") in providing the Services. Capitalised terms not defined here have the meaning given in the Terms.

Where you have entered into a Customer Agreement with us, this DPA forms part of that agreement, unless it includes a separately signed data processing agreement, in which case that agreement applies instead. On matters of data protection, this DPA prevails over the Terms.

1. Roles

You are the controller of the Personal Data that you and your Users submit to the Platform as Customer Content and of the Personal Data about your Users that we process to provide the Platform to you. Yesper processes that data as your processor. The processing is described in the Annex.

Personal Data that we process in our own right, such as account registration data and website data, is covered by our Privacy Policy.

2. Instructions

We process Personal Data only on your documented instructions. Your instructions are this DPA, the Terms and any Customer Agreement, and your and your Users' use of the Platform's features. Instructions beyond the Platform's features require our written agreement and may be charged at our then-current rates. If EU or Member State law requires us to process Personal Data in another way, we inform you before doing so, unless the law prevents us. If we consider that an instruction infringes the GDPR, we tell you.

3. Confidentiality

Everyone at Yesper who processes Personal Data is bound by confidentiality through their employment contract or a written agreement.

4. Security

We implement appropriate technical and organisational measures under Article 32 GDPR, as described in the Annex. We may update them as technology and threats change.

5. Sub-processors

You authorise us to engage sub-processors. The current list is published at yesper.ai/subprocessors. We inform you of intended changes by updating the list before they take effect. You may object within 14 days of the update, on reasonable, documented data protection grounds. If we cannot resolve your objection, your sole and exclusive remedy is to terminate the affected Subscription.

We bind each sub-processor to the same data protection obligations as in this DPA and remain responsible to you for their performance.

6. Assistance

Taking into account the nature of the processing and the information available to us, we assist you with data subject requests and with your obligations under Articles 32 to 36 GDPR. If a data subject contacts us about your data, we refer them to you. Assistance beyond the Platform's functions and our standard documentation may be charged at our then-current rates.

7. Personal data breaches

If we become aware of a personal data breach affecting your Personal Data, we notify the administrative contact registered for your account without undue delay, with the information available to us.

8. International transfers

We process Personal Data within the EU/EEA. Where Personal Data is transferred outside the EU/EEA, we use safeguards under Chapter V GDPR, such as the European Commission's Standard Contractual Clauses, and you authorise such transfers.

9. Deletion and return

You can export your Customer Content during your Subscription. When the Subscription ends, you choose whether to export your Customer Content during the export period set out in the Terms or the Customer Agreement, or to have us delete it. After the export period we delete the Personal Data we process for you, except where EU or Member State law requires us to keep it. Backup copies are deleted as backups are rotated.

10. Audits

We make available the information needed to demonstrate compliance with this DPA, such as our security documentation and answers to a reasonable security questionnaire, and allow audits, including inspections, by you or an auditor you mandate who is not a competitor of ours. Audits take place at most once per 12 months, on 30 days' written notice, during business hours, under confidentiality, within a scope agreed in advance, and at your cost. They cover our processing of your Personal Data and exclude other customers' data and our source code.

11. Your responsibilities

You are responsible for the lawfulness of the Personal Data you process through the Platform: a legal basis under the GDPR, the notices and consents data subjects are entitled to, and the accuracy and content of your Customer Content. You handle data subject requests in the first instance.

The Platform is built for construction and infrastructure project material. Processing of special categories of Personal Data (Article 9 GDPR) or data relating to criminal convictions (Article 10 GDPR) through the Platform requires our prior written agreement.

Where the EU AI Act applies to your use of the Platform, the obligations of a deployer rest with you.

12. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms or the Customer Agreement, and counts towards the same aggregate cap.

13. Term and changes

This DPA applies for as long as we process Personal Data on your behalf. Changes to this DPA follow Section 24 of the Terms.

14. Governing law and disputes

This DPA is governed by Swedish law. Disputes are resolved as set out in the Terms.

Annex: Details of processing

Subject matter and purpose. Provision of the Services under the Terms: hosting and processing Customer Content, AI-assisted analysis and generation of documents, indexing and search, authentication and access management, support, and the operation and security of the Platform.

Duration. The term of your Subscription, until deletion under Section 9.

Categories of data subjects. Your Users, and individuals who appear in your Customer Content, such as employees, clients, contractors, consultants, and contacts at authorities.

Categories of Personal Data. Personal Data that you and your Users include in Customer Content, typically names, contact details, roles, and other information in project documents, drawings, and correspondence; and your Users' identifiers, roles, and activity in the Platform.

Technical and organisational measures. Hosting in Microsoft Azure, Sweden Central (EU), with AI models run in EU regions of Microsoft Azure and Google Cloud. Encryption in transit and at rest. Role-based access control and least privilege, with single sign-on through your identity provider. Separation of each customer's data. Logging and monitoring of production systems. Backups. Confidentiality obligations for personnel. Incident response procedures.

Sub-processors. Listed at yesper.ai/subprocessors.

Yesper was founded in 2025 by a team combining construction industry experience with AI engineering. Based in Sweden, backed by Microsoft for Startups and partner to leading Nordic construction and infrastructure companies.

Services · Platform · Customers · Pricing · Help center · Insights · Updates · About us · Contact
Log in Book demo
Yesper

Your AI workforce for construction and infrastructure.

© 2026 Yesper · Terms · Privacy Policy