# GDPR

_Effective 1 September 2026. Last updated 1 September 2026._

This page explains how **Yin Yang, Inc.** (dba Elaichi) supports the GDPR, the
UK GDPR, and the Swiss FADP. It supplements the [Privacy Policy](/privacy/) and
the [Data Processing Agreement](/dpa/).

## 1. Our role

For almost everything that matters to your organization, **we are a
processor.** You are the controller. You decide which SaaS systems to connect,
who may call which tool, and how long records are kept. We act on your
documented instructions under the [DPA](/dpa/), which incorporates the Standard
Contractual Clauses.

We are a **controller** only for account, billing, support, and website data —
the information we need to run our own business. See
[Privacy Policy §2](/privacy/).

If you are an individual whose data sits in a customer's Elaichi workspace, we
cannot act on your request directly. Contact that organization; we will forward
your request and assist them.

## 2. Lawful bases, where we are the controller

| Processing | Lawful basis |
|---|---|
| Providing the Service to an account holder | Art. 6(1)(b) — performance of a contract |
| Billing, invoicing, and tax records | Art. 6(1)(c) — legal obligation, and 6(1)(b) |
| Securing the Service, preventing abuse, maintaining audit trails | Art. 6(1)(f) — legitimate interests |
| Service and security notices to administrators | Art. 6(1)(b) and 6(1)(f) |
| Marketing communications | Art. 6(1)(a) — consent, withdrawable at any time |
| Website analytics and advertising measurement | Art. 6(1)(a) — consent, collected through an opt-in banner and withdrawable at any time |

Where we rely on legitimate interests, we have assessed that our interest in
operating and securing a business service does not override the rights and
freedoms of the individuals concerned. You may object at any time — see
section 5.

## 3. Data protection governance

We have **not appointed a Data Protection Officer** under Article 37. Our core
activities do not consist of large-scale regular and systematic monitoring of
data subjects, nor of large-scale processing of special category data, so the
appointment is not required. Privacy is owned internally by our **Privacy
Officer**, reachable at **[dpo@elaichi.ai](mailto:dpo@elaichi.ai)**.

### Our representatives

Because we are established outside the EEA and the UK, we have appointed
representatives under Article 27:

**European Union**
Rickert Rechtsanwaltsgesellschaft mbH – YIN YANG, INC.
Colmantstraße 15, 53115 Bonn, Germany
[art-27-rep-yinyang@rickert.law](mailto:art-27-rep-yinyang@rickert.law)

**United Kingdom**
Rickert Services Ltd UK – YIN YANG, INC.
PO Box 1487, Peterborough PE1 9XX, United Kingdom
[art-27-rep-yinyang@rickert-services.uk](mailto:art-27-rep-yinyang@rickert-services.uk)

You may contact either representative on any matter relating to our processing
of personal data.

## 4. International transfers

We are a US company and we transfer personal data to the **United States** and
to **India**, where our wholly owned affiliate provides engineering,
operations, and support.

**We are not certified under the EU–US Data Privacy Framework.** Our transfer
mechanism is the Standard Contractual Clauses (Commission Implementing Decision
(EU) 2021/914), together with the **UK International Data Transfer Addendum**
and the **Swiss amendments**. Module Two applies where you are a controller;
Module Three applies where you are yourself a processor and to our onward
transfers to sub-processors. The full terms and completed annexes are in
[DPA §7](/dpa/).

A **transfer impact assessment** is available on request from
[dpa@elaichi.ai](mailto:dpa@elaichi.ai).

## 5. Your rights

Under the GDPR and UK GDPR you have the right to **access** your personal data,
to **rectification**, to **erasure**, to **restrict** processing, to **data
portability**, to **object** to processing based on legitimate interests, to
**withdraw consent** at any time without affecting prior processing, and not to
be subject to solely automated decisions producing legal or similarly
significant effects.

**We do not carry out automated decision-making or profiling that produces
legal or similarly significant effects.**

### How to exercise them

- **If your data is in a customer's workspace** — contact that organization.
  They control it. We will route any request we receive to them and assist.
- **If we are the controller** — email
  **[privacy@elaichi.ai](mailto:privacy@elaichi.ai)**. We verify by confirming
  from the email address on file, with an additional check for erasure
  requests.

We respond within **one month**, extendable by two further months for complex
requests, with notice to you. There is no charge for a reasonable request.

## 6. What we do with your data

Our commitments, stated plainly:

- **We do not train, fine-tune, or improve any model on your data.**
- **We do not log prompts or completions**, and tool-call logging is
  metadata-only — request arguments and response payloads are never written.
- **We do not sell personal data**, and we never use Customer Data for
  advertising or profiling. Website advertising measurement is **opt-in only**
  and never touches data reached through a connector.
- **Third-party credentials are never exposed** to end users or to any AI
  model. AI model providers run on **your own key, under your own account**.

## 7. Security and breach notification

Our technical and organisational measures are set out in full in
[Annex II of the DPA](/dpa/) and summarised in
[Privacy Policy §12](/privacy/).

We notify affected customers of a personal data breach **without undue delay
and within 72 hours** of confirming it, and assist with your own obligations
under Articles 33 and 34.

## 8. Sub-processors

The current list is published at **[/subprocessors/](/subprocessors/)** and in
our Trust Center at **[trust.elaichi.ai](https://trust.elaichi.ai)**, with **30 days' advance
notice** of any addition and a right to object. We remain
fully liable for our sub-processors' performance.

## 9. Assistance we provide

- **DPIAs and prior consultation** — reasonable assistance under Articles 35
  and 36 ([DPA §10](/dpa/)).
- **Data subject requests** — the Service gives you direct API access to your
  data, which is usually sufficient to respond without involving us
  ([DPA §8](/dpa/)).
- **Audits** — our Trust Center at **[trust.elaichi.ai](https://trust.elaichi.ai)**, documents
  released under NDA on request, and a security questionnaire once per twelve
  months ([DPA §12](/dpa/)).
- **Records of processing** — Annex I of the DPA describes the processing in
  the detail Article 30 requires.

## 10. Data location

Organizations select a region at creation, which **cannot be changed
afterwards**. For US and EU, most organization data is pinned to that
Cloudflare jurisdiction. Please note two limits, stated plainly:
**APAC is a placement hint, not a residency guarantee**, and the **audit-log
store is a single European Union instance serving all regions**. Full detail in
[Privacy Policy §8](/privacy/).

## 11. Complaints

If you believe we have not handled your data properly, please contact
**[privacy@elaichi.ai](mailto:privacy@elaichi.ai)** first — we would like the
chance to put it right.

You also have the right to lodge a complaint with a supervisory authority: in
the EEA, the authority in your country of residence, work, or where the issue
arose; in the UK, the [Information Commissioner's Office](https://ico.org.uk/);
in Switzerland, the Federal Data Protection and Information Commissioner.

## 12. Contact

| Purpose | Address |
|---|---|
| Privacy questions and rights requests | privacy@elaichi.ai |
| Privacy Officer, DPA and transfer questions | dpo@elaichi.ai |
| Sub-processor notifications and DPA copies | dpa@elaichi.ai |
| Security | security@elaichi.ai |

Yin Yang, Inc., 9450 SW Gemini Dr, PMB 69868, Beaverton, Oregon 97008‑7105, USA.
