Legal

Privacy Policy

How Yourdiai collects, uses and protects personal data under the EU General Data Protection Regulation (GDPR).

Last updated

1. Who is responsible

The controller of the personal data described here is CODEPRENEUR DOOEL, KIRIL PEJCHINOVIKJ 50, North Macedonia. For any privacy question or request, write to [email protected].

This policy covers visitors to our websites and the people who use Yourdiai accounts. The contacts our customers email are the customers’ data: for them each customer is the controller and we act as its processor under the Data Processing Addendum. Those contacts should contact the business that emailed them.

2. What we collect

  • Account data: name, email address and a hashed password of each user, and team roles.
  • Workspace data: company name, address, website and the sender details you configure.
  • Billing data: your plan, subscription status and the payment provider’s customer and transaction references. Card details are handled by the payment provider and never reach us.
  • Technical and security data: IP address and browser details in session and audit records, and logs of sign-ins and important account actions.
  • Support data: the messages you send us.
  • Website data: anonymous “Was this helpful?” answers in the help center and, only with your consent, Google Analytics statistics.
  • Referral data: if you arrived through an affiliate link, which affiliate referred your workspace. Affiliate clicks are counted with an anonymous identifier, not your IP address.
Purpose Legal basis (GDPR)
Providing the Service, your account and support Contract, Art. 6(1)(b)
Service and billing emails about your account Contract, Art. 6(1)(b)
Security, fraud and abuse prevention, deliverability monitoring Legitimate interests, Art. 6(1)(f)
Crediting referrals to our affiliates Legitimate interests, Art. 6(1)(f)
Accounting and tax records Legal obligation, Art. 6(1)(c)
Website analytics (Google Analytics) Consent, Art. 6(1)(a)

We do not sell personal data and we do not use it for automated decisions that have legal or similarly significant effects on you.

4. Who we share it with

We use carefully selected service providers that process data on our behalf under data processing agreements:

  • Our hosting provider: hosting of the application and its database.
  • Amazon Web Services (Amazon SES, region eu-north-1): sending and tracking the emails sent through the Service.
  • Bunny.net: delivery of web fonts (your IP address is processed to deliver them; no cookies).
  • Google (Google Analytics): website statistics, only if you accept analytics cookies.

AgentaOS processes payments as Merchant of Record and is an independent controller for the payment data it collects. Authorities may receive data where the law requires it.

5. International transfers

Where a provider processes personal data outside the European Economic Area, we rely on an adequacy decision of the European Commission (such as the EU-U.S. Data Privacy Framework) or on the Commission’s Standard Contractual Clauses, together with additional safeguards where needed.

6. How long we keep it

  • Account and workspace data: for as long as your account exists. After it is closed we delete it within a reasonable period, except data we must keep by law.
  • Billing and tax records: for the period required by accounting and tax law.
  • Raw payment provider notifications (which can contain buyer names and emails): cleared after 180 days.
  • Sessions: end after 120 minutes of inactivity or when you sign out.
  • Referral cookie: 30 days. Analytics cookies: as described in the Cookie Policy.

7. How we protect it

Data is encrypted in transit (HTTPS). Passwords are hashed, sensitive payout details are encrypted at rest, access is limited to staff who need it and important actions are recorded in an audit log. Each customer’s data is isolated in its own workspace.

8. Your rights

Under the GDPR you have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, to data portability and to withdraw consent at any time (without affecting processing before the withdrawal). To exercise them, write to [email protected]. We reply within one month.

You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state where you live, work or where an alleged infringement took place.

9. Children

The Service is for businesses and is not directed at children under 16. We do not knowingly collect their data.

10. Changes to this policy

We update this policy when our processing changes. The date at the top shows the latest version; for material changes we notify account owners by email.

11. Contact

CODEPRENEUR DOOEL · KIRIL PEJCHINOVIKJ 50 · North Macedonia · Company registration number: 4029025532735 · VAT ID: 7865465 · Email: [email protected]