Privacy Notice · Version 2026-08-01-b2b-v1 · Effective 1 August 2026
How YesIQ handles personal data
1. Controller and scope
ITYES IT FACTORY S.R.L., a company established in Romania and operating YesIQ ("ITYES", "YesIQ", "we", "us" or "our"), is the controller for the processing described in this notice. Trade Registry number: J15/1504/22.11.2018. Registered office: Crevedia, Strada Dârzei 3 A3, Dâmbovița, Romania, 137180. VAT/tax identification number: RO40200849.
This notice applies to the YesIQ website, API, MCP tools, analyses, previews, reports, payments and support. Privacy enquiries and rights requests may be sent to [email protected] or made by telephone at +40 775 311 986.
This notice is provided in English for the current business product. Please contact us before using the Service if you cannot understand it. This does not limit any mandatory privacy-information requirement that applies in a particular jurisdiction.
2. Data we process
- Analysis data: the submitted and canonical URLs, public page content and metadata collected during the bounded crawl, detected website features, analysis results, analysis and report identifiers, and the authorization status of capability-based access.
- Incidental public personal data: names, professional contact details or other information that a website operator has made publicly accessible and that appears on an analyzed page.
- Payment and customer data: the email returned by Stripe, Stripe Checkout reference, payment status, purchase and analysis identifiers, accepted Terms version and time, business-use confirmation, and information needed for invoices, refunds or disputes. YesIQ does not receive or store full payment-card or bank-account details.
- Security and technical data: IP address used transiently for rate limiting, minimized rate-limit identifiers, timestamps, request outcome, error category and security or fraud information made available by relevant infrastructure. Browser or user-agent information may appear in limited infrastructure access logs but is not stored in YesIQ analysis records.
- MCP authentication data: the authorization scope is validated during a request. When OAuth is enabled, YesIQ stores a one-way hash derived from the verified issuer and subject so records can be separated by account. Raw issuer/subject values, bearer access tokens and authentication-event histories are not stored in ordinary YesIQ application records.
- Communications: the content of support, privacy, complaint and refund correspondence.
3. Where data comes from
We obtain data directly from the business user, indirectly from public pages on the submitted website, from Stripe when a payment is made or managed, from the relevant authentication or AI-platform provider when MCP access is used, and automatically from the device and infrastructure involved in a request.
4. Why we process data and our legal bases
- Provide the requested analysis, preview, checkout, report and support: to take requested pre-contract steps or perform our contract.
- Process payments, invoices, tax records and refunds: contract and compliance with legal obligations.
- Secure the Service, prevent abuse, enforce limits, investigate faults and defend legal claims: our legitimate interests in operating a safe and reliable service.
- Analyze bounded public website evidence and improve output quality: our legitimate interests in providing and improving the requested service, balanced against the rights of affected people.
- Use non-essential analytics, marketing storage or optional communications if introduced: consent where required; consent may be withdrawn at any time.
We do not use incidental public personal data to build profiles of individuals or make decisions that produce legal or similarly significant effects.
5. Public website analysis
YesIQ is designed to process a small number of public business pages, not private accounts or personal dossiers. It does not sign in to submitted websites or bypass access controls. The crawler blocks private, local, link-local and internal destinations; limits pages, depth, response size and time; follows redirects only through revalidation; and avoids obvious non-HTML resources.
Because a public website may contain personal data, users must submit sites only for a lawful business purpose and should avoid pages containing unnecessary sensitive information. Incidental personal data may therefore be obtained indirectly from public pages. ITYES does not use that incidental data to profile people or train a general-purpose AI model.
6. AI processing and human decisions
Bounded website evidence may be processed by OpenAI under the configured service arrangement to produce probabilistic business-opportunity observations and recommendations. Temporary output review or quality assurance is not treated by ITYES as training a general-purpose model. YesIQ does not make solely automated decisions about an identified person that produce legal or similarly significant effects. Business users must validate recommendations and retain human responsibility for implementation.
7. Recipients and service providers
Information may be disclosed or made available only as needed for the relevant role:
- OpenAI may process bounded website evidence for AI-assisted analysis under the configured service arrangement;
- Stripe processes checkout, payment, invoicing, fraud prevention and refunds and may act under its own legal responsibilities;
- hosting, database, network and security providers may process information on ITYES’s behalf;
- the configured MCP identity provider validates access, while ChatGPT, Codex, MCP clients and other AI platforms may separately process prompts, account data and interactions under their own privacy notices;
- ITYES personnel and professional advisers subject to appropriate duties; and
- public authorities or other recipients when disclosure is legally required.
We do not sell personal data or use it for third-party behavioural advertising.
8. International transfers
Some providers may process data outside Romania or the European Economic Area. The transfer location, provider role and applicable safeguards depend on the provider agreement and configuration in force. You may contact us for information about the safeguard applicable to a particular transfer. We do not claim EU-only processing or a specific transfer mechanism where it has not been verified.
9. Retention
We keep personal data only for as long as needed for the purpose for which it was collected:
- raw public-page crawl evidence used for a paid report is deleted within two hours after the complete report is generated;
- an unpaid analysis and its stored evidence are deleted after 24 hours;
- a paid report, its PDF and its access link are deleted or irreversibly disabled seven days after payment confirmation;
- ordinary runtime logs are not stored in the YesIQ application database and are kept only for operationally necessary infrastructure rotation periods; records isolated for investigating a security incident may be retained for up to 90 days where necessary;
- payment, invoice and accounting records are retained for the retention periods required by applicable Romanian and EU accounting, tax and payment laws; and
- support and rights-request records are retained while the request is handled and for any applicable limitation period.
Application cleanup periodically deletes or scrubs the stated analysis data and disables expired report access. A deletion request does not require us to erase payment or accounting records that must be retained by law. YesIQ does not currently create a separate application backup of report content; if backups are introduced, expired copies will disappear through the documented backup-rotation cycle rather than immediate record-level deletion.
10. Report links and local storage
YesIQ uses essential browser storage to remember an analysis, preserve checkout context and reopen an authorized report without requiring an account. Paid reports may be delivered through an unguessable capability link. Treat that link as confidential: anyone who receives it may be able to access the report until it expires. YesIQ stores capability tokens only as one-way hashes in application records. Stripe, an authentication provider or an AI platform may use their own necessary cookies or storage under their privacy notices.
We do not use advertising cookies. If non-essential analytics or marketing technologies are introduced, we will update this notice and request consent where required.
11. Security
We use technical and organizational measures intended to protect data, including encrypted transport, access controls, separated secrets, bounded crawling, authorization checks, rate limits and logging designed to avoid unnecessary sensitive content. No internet service can guarantee absolute security. If you believe a report link or personal data has been exposed, contact [email protected] promptly.
12. Your rights
Subject to the GDPR and applicable exceptions, you may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. You may also ask for information about applicable international-transfer safeguards.
Send a request to [email protected]. To locate a record, provide only the relevant email address, analysis, purchase or report identifier, or MCP account reference where available. We may ask for proportionate information to verify identity. We normally respond within one month, subject to lawful extensions. Where incidental public personal data appears in stored evidence or a report, we can use the submitted site and analysis identifier to locate, restrict or delete it where legally required.
You may lodge a complaint with the Romanian supervisory authority, ANSPDCP, or with the competent authority where you live or work.
13. Children and sensitive data
The Service is intended for adults and business users and is not directed to children. Do not intentionally submit a page for the purpose of analyzing children or special-category personal data. If public source content incidentally contains such information, YesIQ’s analysis must not be used to profile or make decisions about those individuals. Contact us if removal is needed.
14. Third-party websites
This notice does not govern the submitted website or information retained independently by Stripe, OpenAI, ChatGPT, Codex, an identity provider, MCP client or another third-party service. YesIQ receives only information exposed to it through the relevant integration and authorization flow and cannot control independent third-party retention. Their own privacy information applies to their processing.
15. Changes and contact
We may update this notice when the Service, providers or law change. The effective date above identifies the current version. Material changes will be communicated through the Service where appropriate. Contact: [email protected].