How YesIQ handles personal data

1. Controller and scope

ITYES IT FACTORY S.R.L., a company established in Romania and operating YesIQ ("ITYES", "YesIQ", "we", "us" or "our"), is the controller for the processing described in this notice. Trade Registry number: J15/1504/22.11.2018. Registered office: Crevedia, Strada Dârzei 3 A3, Dâmbovița, Romania, 137180. VAT/tax identification number: RO40200849.

This notice applies to the YesIQ website, API, MCP tools, analyses, previews, reports, payments and support. Privacy enquiries and rights requests may be sent to [email protected] or made by telephone at +40 775 311 986.

This notice is provided in English for the current business product. Please contact us before using the Service if you cannot understand it. This does not limit any mandatory privacy-information requirement that applies in a particular jurisdiction.

2. Data we process

3. Where data comes from

We obtain data directly from the business user, indirectly from public pages on the submitted website, from Stripe when a payment is made or managed, from the relevant authentication or AI-platform provider when MCP access is used, and automatically from the device and infrastructure involved in a request.

4. Why we process data and our legal bases

We do not use incidental public personal data to build profiles of individuals or make decisions that produce legal or similarly significant effects.

5. Public website analysis

YesIQ is designed to process a small number of public business pages, not private accounts or personal dossiers. It does not sign in to submitted websites or bypass access controls. The crawler blocks private, local, link-local and internal destinations; limits pages, depth, response size and time; follows redirects only through revalidation; and avoids obvious non-HTML resources.

Because a public website may contain personal data, users must submit sites only for a lawful business purpose and should avoid pages containing unnecessary sensitive information. Incidental personal data may therefore be obtained indirectly from public pages. ITYES does not use that incidental data to profile people or train a general-purpose AI model.

6. AI processing and human decisions

Bounded website evidence may be processed by OpenAI under the configured service arrangement to produce probabilistic business-opportunity observations and recommendations. Temporary output review or quality assurance is not treated by ITYES as training a general-purpose model. YesIQ does not make solely automated decisions about an identified person that produce legal or similarly significant effects. Business users must validate recommendations and retain human responsibility for implementation.

7. Recipients and service providers

Information may be disclosed or made available only as needed for the relevant role:

We do not sell personal data or use it for third-party behavioural advertising.

8. International transfers

Some providers may process data outside Romania or the European Economic Area. The transfer location, provider role and applicable safeguards depend on the provider agreement and configuration in force. You may contact us for information about the safeguard applicable to a particular transfer. We do not claim EU-only processing or a specific transfer mechanism where it has not been verified.

9. Retention

We keep personal data only for as long as needed for the purpose for which it was collected:

Application cleanup periodically deletes or scrubs the stated analysis data and disables expired report access. A deletion request does not require us to erase payment or accounting records that must be retained by law. YesIQ does not currently create a separate application backup of report content; if backups are introduced, expired copies will disappear through the documented backup-rotation cycle rather than immediate record-level deletion.

10. Report links and local storage

YesIQ uses essential browser storage to remember an analysis, preserve checkout context and reopen an authorized report without requiring an account. Paid reports may be delivered through an unguessable capability link. Treat that link as confidential: anyone who receives it may be able to access the report until it expires. YesIQ stores capability tokens only as one-way hashes in application records. Stripe, an authentication provider or an AI platform may use their own necessary cookies or storage under their privacy notices.

We do not use advertising cookies. If non-essential analytics or marketing technologies are introduced, we will update this notice and request consent where required.

11. Security

We use technical and organizational measures intended to protect data, including encrypted transport, access controls, separated secrets, bounded crawling, authorization checks, rate limits and logging designed to avoid unnecessary sensitive content. No internet service can guarantee absolute security. If you believe a report link or personal data has been exposed, contact [email protected] promptly.

12. Your rights

Subject to the GDPR and applicable exceptions, you may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. You may also ask for information about applicable international-transfer safeguards.

Send a request to [email protected]. To locate a record, provide only the relevant email address, analysis, purchase or report identifier, or MCP account reference where available. We may ask for proportionate information to verify identity. We normally respond within one month, subject to lawful extensions. Where incidental public personal data appears in stored evidence or a report, we can use the submitted site and analysis identifier to locate, restrict or delete it where legally required.

You may lodge a complaint with the Romanian supervisory authority, ANSPDCP, or with the competent authority where you live or work.

13. Children and sensitive data

The Service is intended for adults and business users and is not directed to children. Do not intentionally submit a page for the purpose of analyzing children or special-category personal data. If public source content incidentally contains such information, YesIQ’s analysis must not be used to profile or make decisions about those individuals. Contact us if removal is needed.

14. Third-party websites

This notice does not govern the submitted website or information retained independently by Stripe, OpenAI, ChatGPT, Codex, an identity provider, MCP client or another third-party service. YesIQ receives only information exposed to it through the relevant integration and authorization flow and cannot control independent third-party retention. Their own privacy information applies to their processing.

15. Changes and contact

We may update this notice when the Service, providers or law change. The effective date above identifies the current version. Material changes will be communicated through the Service where appropriate. Contact: [email protected].