This Data Processing Agreement ("DPA") forms part of the Terms of Service. It is between High Mesa Ltd, trading as Yumee, Company No. 13626375, 123 Kings Mill Way, Denham, Uxbridge, UB9 4BT, United Kingdom ("Processor", "we"), and the business that subscribes to YuMeeWave ("Controller", "you").
It applies to all personal data we process on your behalf under the UK GDPR, the Data Protection Act 2018 and, where applicable, the EU GDPR. It is accepted together with the Terms of Service. A signed copy is available on request. Capitalised terms not defined here have the meaning given in the Terms of Service.
1. Subject matter, duration, nature and purpose
We process personal data solely to provide the YuMeeWave service to you. This means:
- hosting your WiFi login pages;
- authorising Guests' devices on your WiFi controller;
- recording Guests' details, visits and consent;
- sending emails and text messages you configure;
- collecting feedback and review requests;
- producing statistics;
- providing the AI features and integrations you choose to use.
Processing continues for the duration of the subscription and the 30-day export window after it ends. The data is then deleted under section 8.
2. Categories of data subjects and personal data
Data subjects: Guests who use your WiFi login pages, and your Users of the admin panel.
Personal data, depending on your settings and the features you use:
- identification and contact data: name, email address, phone number;
- demographic data you choose to request: date of birth, gender;
- answers to questions you add;
- social login profile data: provider user ID, name, email address, profile picture link;
- device and network data: MAC address, access point, network name (SSID), IP address, browser language, the page originally requested;
- visit data: login method, session times, visit counts, tags and notes;
- consent records: acceptance of your terms, marketing consent, withdrawal;
- feedback, ratings and messages;
- email engagement: opens;
- for Users: name, email address, role and activity in the panel.
Special category data: none is intended. You must not use custom questions to collect special category data or data about criminal convictions.
3. Your obligations as Controller
You warrant that:
- you have a lawful basis for the processing;
- you have given Guests the information required by Articles 13 and 14, including through your WiFi terms and the controller details you enter in the admin panel;
- you have obtained any consent required by the Privacy and Electronic Communications Regulations 2003 before sending marketing or enabling email tracking or advertising integrations.
You are responsible for the instructions you give through your settings, including the data fields you require, automations, retention and integrations. You are also responsible for managing User access.
4. Our obligations as Processor (Article 28(3))
We will:
- process personal data only on your documented instructions, which are the Terms of Service, this DPA and your use of the service's features and settings, unless the law requires otherwise. In that case, we will tell you first where the law allows;
- ensure that persons authorised to process the data are bound by confidentiality;
- implement the technical and organisational measures in section 6;
- engage sub-processors only under section 5;
- assist you, taking into account the nature of the processing, in responding to data subject requests. This includes the guest self-service deletion page, the panel's delete and export tools, and manual help for other requests;
- assist you with security, breach notification, data protection impact assessments and prior consultation;
- delete or return all personal data at the end of the service under section 8;
- make available the information necessary to demonstrate compliance, and allow audits under section 9;
- inform you immediately if we believe an instruction infringes data protection law.
5. Sub-processors
You give general authorisation to the sub-processors listed on our GDPR Compliance page. We will notify account administrators by email at least 30 days before adding or replacing a sub-processor. You may object on reasonable grounds; if you do, either party may terminate the affected service, and we will refund fees paid in advance for the period after termination.
We impose on each sub-processor data protection obligations equivalent to those in this DPA, and we remain responsible for their performance.
Some services are enabled or operated by you, and are not our sub-processors: your WiFi controller, your own SMS account, CRM and email-marketing tools, advertising platforms and webhook destinations. We transmit data to them only on your instruction, and you are responsible for your arrangements with them.
6. Security measures (Article 32)
- Data is encrypted in transit (TLS) and at rest.
- WiFi controller passwords are encrypted with AES-256-GCM. The key is held in a managed secret store, separately from the data.
- Admin panel access requires an authenticated session and an explicit role. Authorisation is checked on our servers for every request, and each venue is isolated from the others.
- Database security rules deny access by default. Guest data can be read only by authorised Users of the venue concerned.
- Login sessions are signed, forms are protected against forgery, and logins are rate-limited per device, IP address and phone number.
- Guest data exports are recorded in an audit log.
- Access to production systems is limited to named High Mesa Ltd staff.
7. Personal data breaches
We will notify you without undue delay, and in any event within 48 hours of becoming aware, of a personal data breach affecting your data. We will provide the information you reasonably need to meet your Article 33 and 34 obligations, and will cooperate in the investigation and remediation.
8. Return and deletion
- You may export your guest list from the admin panel at any time.
- Individual Guests can be deleted from the panel. Guests can also request deletion themselves through the "Your data" link on the login page.
- Guest records are deleted automatically 24 months after the Guest's last visit. Records used to let a device online are removed when the session ends.
- On termination, data remains exportable for 30 days. After that, all personal data processed for you is permanently deleted from our systems and those of our sub-processors. The exception is data we must retain by law.
9. Audit
On request, no more than once a year or following a breach, we will provide reasonable information, including summaries of our security practices and sub-processor arrangements. We will also allow an audit by you, or by an independent auditor bound by confidentiality, at your cost, with at least 30 days' notice and during business hours.
10. International transfers
Personal data is stored in the European Union and the United Kingdom. Where a sub-processor processes data in the United States, the transfer is covered by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or by the UK Extension to the EU–US Data Privacy Framework where the sub-processor is certified.
11. Liability and term
Liability under this DPA is subject to the limitations in the Terms of Service. This DPA takes effect when you accept the Terms of Service, and continues until all personal data processed for you has been deleted or returned. For data protection matters, contact support@yumeeservices.com.