Data Protection
Your Data, Your Rights
At yno.ai, we are committed to protecting your personal data and respecting your privacy rights. This page outlines our comprehensive approach to data protection, including GDPR compliance, security measures, and your rights as a data subject.
Quick Actions
Exercise your data protection rights immediately:
1. Data Protection Principles
We adhere to the fundamental principles of data protection as outlined in the General Data Protection Regulation (GDPR) and other applicable privacy laws:
Lawfulness & Fairness
We process data lawfully, fairly, and transparently with clear legal bases for all processing activities.
Purpose Limitation
Data is collected for specific, explicit, and legitimate purposes and not processed incompatibly.
Data Minimization
We collect only data that is adequate, relevant, and limited to what is necessary for our purposes.
Accuracy
Personal data is kept accurate and up to date, with inaccurate data erased or rectified promptly.
Storage Limitation
Data is retained only for as long as necessary for the purposes for which it was collected.
Security
Appropriate technical and organizational measures ensure data security and protection.
2. Legal Bases for Processing
We process your personal data based on the following legal grounds under GDPR:
- Contract Performance: Processing necessary to perform our contract with you (account management, service delivery)
- Legitimate Interests: Processing for our legitimate business interests (service improvement, security, analytics)
- Consent: Processing based on your explicit consent (marketing communications, optional features)
- Legal Obligation: Processing required to comply with legal obligations (tax records, regulatory compliance)
- Vital Interests: Processing necessary to protect vital interests (emergency situations, safety concerns)
3. Your Data Protection Rights
Under GDPR and other applicable privacy laws, you have the following rights regarding your personal data:
Right of Access
You have the right to obtain confirmation of whether we process your personal data and access to that data.
How to exercise: Contact us at [email protected] with your request
Right to Rectification
You can request correction of inaccurate or incomplete personal data we hold about you.
How to exercise: Update your profile or contact our support team
Right to Erasure ("Right to be Forgotten")
You can request deletion of your personal data in certain circumstances, such as when data is no longer necessary.
How to exercise: Submit a deletion request through your account settings or contact us
Right to Restrict Processing
You can request restriction of processing in specific circumstances, such as when contesting data accuracy.
How to exercise: Contact [email protected] with your specific request
Right to Data Portability
You can receive your personal data in a structured, commonly used format and transmit it to another controller.
How to exercise: Request data export through your account settings
4. Data Security Measures
We implement comprehensive technical and organizational measures to protect your personal data:
4.1 Technical Safeguards
- Encryption: AES-256 encryption for data at rest and TLS 1.3 for data in transit
- Access Controls: Multi-factor authentication and role-based access controls
- Network Security: Firewalls, intrusion detection, and DDoS protection
- Monitoring: 24/7 security monitoring and automated threat detection
- Backup & Recovery: Encrypted backups with tested disaster recovery procedures
4.2 Organizational Measures
- Staff Training: Regular privacy and security training for all employees
- Access Management: Principle of least privilege and regular access reviews
- Incident Response: Established procedures for security incident management
- Vendor Management: Due diligence and data protection agreements with third parties
- Regular Audits: Internal and external security assessments and penetration testing
5. International Data Transfers
When we transfer your personal data outside the European Economic Area (EEA), we ensure appropriate safeguards:
- Adequacy Decisions: Transfers to countries with adequate data protection levels
- Standard Contractual Clauses: EU-approved contractual protections for data transfers
- Binding Corporate Rules: Internal data protection rules for multinational organizations
- Certification Schemes: Transfers under approved certification mechanisms
We regularly review and update our transfer mechanisms to ensure continued compliance with evolving regulations.
6. Data Breach Notification
In the unlikely event of a personal data breach that poses a risk to your rights and freedoms:
- Authority Notification: We will notify relevant supervisory authorities within 72 hours
- Individual Notification: We will inform affected individuals without undue delay if high risk exists
- Breach Response: We will take immediate steps to contain and remediate the breach
- Documentation: All breaches are documented and reported as required by law
Our incident response team is trained to handle data breaches efficiently and in compliance with legal requirements.
7. Privacy by Design and Default
We implement privacy by design and default principles in all our systems and processes:
- Proactive Measures: Privacy considerations integrated from the design phase
- Default Settings: Privacy-friendly default settings for all users
- Data Minimization: Systems designed to collect only necessary data
- Transparency: Clear and accessible privacy information
- User Control: Easy-to-use privacy controls and settings
8. Data Protection Impact Assessments
We conduct Data Protection Impact Assessments (DPIAs) for processing activities that may result in high risks to individuals' rights and freedoms. Our DPIA process includes:
- Systematic description of processing operations and purposes
- Assessment of necessity and proportionality of processing
- Identification and assessment of risks to individuals
- Implementation of measures to address identified risks
- Regular review and updating of assessments
9. Supervisory Authority
You have the right to lodge a complaint with a supervisory authority if you believe we have not complied with data protection laws. You can contact:
- Your local data protection authority in your country of residence
- The supervisory authority in the country where the alleged infringement occurred
- Our lead supervisory authority (if applicable based on our main establishment)
10. Contact Our Data Protection Team
For any questions about data protection, to exercise your rights, or to report concerns:
Note: When contacting us about your personal data, please provide sufficient information to help us verify your identity and locate your data. This helps us protect your privacy and respond to your request efficiently.
Related Documentation
Explore these related topics to learn more