Overblast Back to home

Data Processing Agreement

Last updated: September 23, 2026

1. Introduction

This Data Processing Agreement ("DPA") forms part of the agreement between Yumankind OÜ ("Processor", "we", "us") and you ("Controller", "you") for the use of Overblast: the Overblast app, the 0-0 app's Overblast features, the Overblast console and the Overblast API ("the Service"). Yumankind OÜ is registered in Estonia (registry code 16232402, VAT number EE102378229), at Sepapaja 6, 15551 Tallinn, Estonia. It sets out how we process personal data on your behalf in line with applicable data protection law, including the General Data Protection Regulation (EU) 2016/679 ("GDPR").

2. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person that we process on your behalf through the Service.
  • "Processing" means any operation performed on Personal Data, including collection, storage, use, transmission and deletion.
  • "Sub-processor" means any third party we engage to process Personal Data on your behalf.
  • "Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.

3. Scope and purpose of processing

We process Personal Data only to provide the Service to you, including:

  • connecting your social accounts and other channels, and receiving and sending messages, comments, reviews, emails, website chats and phone calls through them;
  • storing and publishing the content you create or schedule;
  • answering on your behalf when you turn on Overblast's auto-reply or an AI phone agent, and producing call recordings, transcripts and summaries;
  • keeping your contacts and tasks, and sharing them with the members of your workspaces;
  • giving the agents and integrations you authorise access through the API.

The data subjects are the people your workspaces talk to (your customers, leads and contacts) and the members of your workspaces.

4. Categories of data

Category Examples
Account and member data Name, email address, role in a workspace
Contact data Names, social handles, phone numbers and email addresses of the people you talk to, and the notes you keep about them
Communications DMs, comments, reviews, emails, website chats, posts and media files
Call data Caller and called numbers, times, durations, recordings and transcripts
Work data Tasks, statuses, approvals and business information you give your agent
Usage data IP addresses, device information, access logs

5. Obligations of the Processor

We shall:

  • process Personal Data only on your documented instructions, which include the settings you choose in the Service, unless the law requires otherwise;
  • make sure the people authorised to process Personal Data are bound by confidentiality;
  • implement appropriate technical and organisational measures to protect Personal Data (section 6);
  • engage Sub-processors only as described in section 7;
  • help you respond to data subjects exercising their rights;
  • delete Personal Data when the Service ends (section 12), unless the law requires us to keep it;
  • make available the information needed to show compliance with this DPA.

6. Security measures

We implement the following technical and organisational measures:

  • Encryption in transit: data is encrypted in transit (TLS). Messages between the 0-0 app and your Mac are signed end to end by both devices, and end-to-end encrypted when both apps are up to date; if one side runs an older version, they are signed but not end-to-end encrypted.
  • Encryption at rest: Cloudflare D1 and R2, which hold our main database and files, encrypt all stored data with AES-256 by default (D1 uses AES-256-GCM). Google Cloud and Firebase encrypt stored data at rest by default. Credentials you give us directly, such as your own SMTP password, are also encrypted by the application.
  • Access control: access follows least privilege. Each workspace is isolated, and its data is reachable only by its members and the API keys it issues, according to their role. Administrative functions are restricted to authorised administrators. Administrative access to production systems and source code requires multi-factor authentication.
  • Separation: the social-account access tokens are held by our connector (Zernio), not in our own databases.
  • Backups: our main database (Cloudflare D1) has point-in-time recovery to any minute within the last 30 days (D1 Time Travel, always on).

7. Sub-processors

You give us general authorisation to engage the Sub-processors below. This is the same list, with the same locations, as in our Privacy Policy. Transfers outside the European Economic Area are covered in section 9.

Sub-processor Purpose Location
Cloudflare Hosting, edge compute, databases, file storage, email sending and receiving, real-time audio and video, the 0-0 relay Global network; our main database (Cloudflare D1) is in Western Europe (region WEUR); files (Cloudflare R2) are in the region the workspace owner chose (the European Union under Cloudflare's EU jurisdiction, or a preferred location in North America or Asia-Pacific), or in Western Europe (region WEUR) for workspaces created without that choice
Google (Firebase and Google Cloud) Sign-in, the Overblast app's database, push notifications, app configuration, analytics, crash reports, maps and place search United States; the legacy Firestore database is in the US multi-region nam5
Google (Gemini API and Vertex AI) AI for search and maps grounding (Gemini API); reading business details, websites, branding, supplier profiles and files, the knowledge agent, and transcription (Vertex AI) United States (Vertex AI region us-central1); the European Union (Vertex AI region europe-west4) for workspaces that choose the EU region for auto-replies
Stripe Web payments, subscriptions, invoices and VAT; card-present payments (Stripe Terminal) United States and Ireland (Stripe Payments Europe for EU customers)
Apple (App Store) In-app purchases and subscriptions on iPhone and iPad United States / Ireland
Google Play In-app purchases and subscriptions on Android United States / Ireland
Zernio Connector to social networks: connecting accounts, publishing, messages, comments and reviews Spain, EU (ZERNIO SOFTWARE SL, Girona)
OpenRouter and the AI model providers it routes to (such as Anthropic, OpenAI, Google and xAI) AI for auto-reply, agents, summaries and drafting United States, with in-region EU or US routing when the agent's model region is set
xAI Realtime voice model on AI phone calls United States
OpenAI Realtime voice model on AI phone calls, for workspaces whose owner chooses it United States
Twilio Phone line, call routing and phone numbers United States
LiveKit Audio connection between a phone call and the AI voice agent United States
fal.ai AI image, video, voice (including ElevenLabs models) and music generation, when used United States
Replicate AI media generation, when used United States

We give at least 30 days' notice of a new Sub-processor by email to the account owner and by updating the list on this page. You may object on reasonable data-protection grounds within that period; if we cannot reasonably accommodate the objection, you may terminate the affected service and receive a pro-rata refund of prepaid fees.

8. Data breach notification

If a Data Breach affects your Personal Data, we will:

  • notify you without undue delay after becoming aware of it;
  • give you the information you need to meet any duty to report the breach to a supervisory authority or to the people affected;
  • take reasonable steps to limit its effects.

9. International data transfers

Where Personal Data is transferred outside the European Economic Area, the transfer relies on the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework. Each Sub-processor's location is listed in section 7.

Where a workspace's files are stored depends on a choice the workspace owner makes when creating the workspace, where we offer it: the European Union, where Cloudflare's EU jurisdiction guarantees the files are stored and processed only in the EU; or North America or Asia-Pacific, which is a preferred location, not a guarantee. The choice cannot be changed later. It covers the workspace's files only: our main database (Cloudflare D1) is in Western Europe for every workspace. Workspaces created without the choice keep their files in Western Europe (region WEUR), which is also a preferred location rather than a guarantee. A file we pass to another Sub-processor to do what you ask is then held where that Sub-processor is.

10. Data subject rights

We will help you respond to requests from data subjects for access, rectification, erasure, restriction, portability and objection. Much of this you can do yourself in the Service, for example by deleting a contact or a whole workspace.

11. Audits

We make available the information necessary to demonstrate compliance with this DPA, including our security documentation and the certifications and reports of our Sub-processors, on request. Where that is not sufficient, or a supervisory authority requires it, you may conduct an audit no more than once a year, with at least 30 days' notice, during business hours, under confidentiality, and at your own cost. Audits must not unreasonably disrupt our operations.

12. Retention, term and termination

While the Service is provided, Personal Data is kept as follows:

  • AI prompts: not kept. Requests to AI models are processed to produce the answer and are not stored by us.
  • Messaging data (the conversations and messages in a workspace's inbox, from social DMs, email, calls and web chat): kept while the workspace exists. Archiving a conversation hides it but does not delete it, and a message deleted on a social network stays in the workspace's history, marked as deleted. When the workspace or the account is deleted, its messages are removed from our live systems straight away and from our backups within 30 days.
  • Payment records (invoices, receipts and refunds): kept for as long as tax and accounting law requires, up to 7 years.

This DPA applies for as long as we provide the Service to you. When you delete a workspace or your account, its Personal Data is deleted straight away, except payment records we must keep by law (up to 7 years). Deleted data can remain for a short time in our systems' recovery history and logs: up to 30 days in the point-in-time recovery of our main database (Cloudflare D1) and in our weekly offline copy of it, up to one hour in the legacy Firestore database, and up to 7 days in our server logs (Cloudflare Workers Logs). After that it is gone. The Service has no one-click export yet: before deleting, you can read your data through the Overblast API, or ask us at support@yumankind.com to return a copy.

13. Governing law

This DPA forms part of our Terms of Service and is governed by the same law and courts: the laws of the Republic of Estonia, and Harju County Court (Harju Maakohus) in Tallinn, without prejudice to mandatory data-protection and consumer-protection rules.

14. Contact

For any question about this DPA, email support@yumankind.com.

Privacy Policy Terms of Service Acceptable Use DPA Support Delete account

© 2026 Yumankind OÜ. All rights reserved.