Skip to content
Elaichi Elaichi

GDPR

Effective 1 September 2026. Last updated 1 September 2026.

This page explains how Yin Yang, Inc. (dba Elaichi) supports the GDPR, the UK GDPR, and the Swiss FADP. It supplements the Privacy Policy and the Data Processing Agreement.

1. Our role

For almost everything that matters to your organization, we are a processor. You are the controller. You decide which SaaS systems to connect, who may call which tool, and how long records are kept. We act on your documented instructions under the DPA, which incorporates the Standard Contractual Clauses.

We are a controller only for account, billing, support, and website data — the information we need to run our own business. See Privacy Policy §2.

If you are an individual whose data sits in a customer's Elaichi workspace, we cannot act on your request directly. Contact that organization; we will forward your request and assist them.

2. Lawful bases, where we are the controller

Processing Lawful basis
Providing the Service to an account holder Art. 6(1)(b) — performance of a contract
Billing, invoicing, and tax records Art. 6(1)(c) — legal obligation, and 6(1)(b)
Securing the Service, preventing abuse, maintaining audit trails Art. 6(1)(f) — legitimate interests
Service and security notices to administrators Art. 6(1)(b) and 6(1)(f)
Marketing communications Art. 6(1)(a) — consent, withdrawable at any time
Website analytics and advertising measurement Art. 6(1)(a) — consent, collected through an opt-in banner and withdrawable at any time

Where we rely on legitimate interests, we have assessed that our interest in operating and securing a business service does not override the rights and freedoms of the individuals concerned. You may object at any time — see section 5.

3. Data protection governance

We have not appointed a Data Protection Officer under Article 37. Our core activities do not consist of large-scale regular and systematic monitoring of data subjects, nor of large-scale processing of special category data, so the appointment is not required. Privacy is owned internally by our Privacy Officer, reachable at [email protected].

Our representatives

Because we are established outside the EEA and the UK, we have appointed representatives under Article 27:

European Union Rickert Rechtsanwaltsgesellschaft mbH – YIN YANG, INC. Colmantstraße 15, 53115 Bonn, Germany [email protected]

United Kingdom Rickert Services Ltd UK – YIN YANG, INC. PO Box 1487, Peterborough PE1 9XX, United Kingdom [email protected]

You may contact either representative on any matter relating to our processing of personal data.

4. International transfers

We are a US company and we transfer personal data to the United States and to India, where our wholly owned affiliate provides engineering, operations, and support.

We are not certified under the EU–US Data Privacy Framework. Our transfer mechanism is the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), together with the UK International Data Transfer Addendum and the Swiss amendments. Module Two applies where you are a controller; Module Three applies where you are yourself a processor and to our onward transfers to sub-processors. The full terms and completed annexes are in DPA §7.

A transfer impact assessment is available on request from [email protected].

5. Your rights

Under the GDPR and UK GDPR you have the right to access your personal data, to rectification, to erasure, to restrict processing, to data portability, to object to processing based on legitimate interests, to withdraw consent at any time without affecting prior processing, and not to be subject to solely automated decisions producing legal or similarly significant effects.

We do not carry out automated decision-making or profiling that produces legal or similarly significant effects.

How to exercise them

  • If your data is in a customer's workspace — contact that organization. They control it. We will route any request we receive to them and assist.
  • If we are the controller — email [email protected]. We verify by confirming from the email address on file, with an additional check for erasure requests.

We respond within one month, extendable by two further months for complex requests, with notice to you. There is no charge for a reasonable request.

6. What we do with your data

Our commitments, stated plainly:

  • We do not train, fine-tune, or improve any model on your data.
  • We do not log prompts or completions, and tool-call logging is metadata-only — request arguments and response payloads are never written.
  • We do not sell personal data, and we never use Customer Data for advertising or profiling. Website advertising measurement is opt-in only and never touches data reached through a connector.
  • Third-party credentials are never exposed to end users or to any AI model. AI model providers run on your own key, under your own account.

7. Security and breach notification

Our technical and organisational measures are set out in full in Annex II of the DPA and summarised in Privacy Policy §12.

We notify affected customers of a personal data breach without undue delay and within 72 hours of confirming it, and assist with your own obligations under Articles 33 and 34.

8. Sub-processors

The current list is published at /subprocessors/ and in our Trust Center at trust.elaichi.ai, with 30 days' advance notice of any addition and a right to object. We remain fully liable for our sub-processors' performance.

9. Assistance we provide

  • DPIAs and prior consultation — reasonable assistance under Articles 35 and 36 (DPA §10).
  • Data subject requests — the Service gives you direct API access to your data, which is usually sufficient to respond without involving us (DPA §8).
  • Audits — our Trust Center at trust.elaichi.ai, documents released under NDA on request, and a security questionnaire once per twelve months (DPA §12).
  • Records of processing — Annex I of the DPA describes the processing in the detail Article 30 requires.

10. Data location

Organizations select a region at creation, which cannot be changed afterwards. For US and EU, most organization data is pinned to that Cloudflare jurisdiction. Please note two limits, stated plainly: APAC is a placement hint, not a residency guarantee, and the audit-log store is a single European Union instance serving all regions. Full detail in Privacy Policy §8.

11. Complaints

If you believe we have not handled your data properly, please contact [email protected] first — we would like the chance to put it right.

You also have the right to lodge a complaint with a supervisory authority: in the EEA, the authority in your country of residence, work, or where the issue arose; in the UK, the Information Commissioner's Office; in Switzerland, the Federal Data Protection and Information Commissioner.

12. Contact

Purpose Address
Privacy questions and rights requests [email protected]
Privacy Officer, DPA and transfer questions [email protected]
Sub-processor notifications and DPA copies [email protected]
Security [email protected]

Yin Yang, Inc., 9450 SW Gemini Dr, PMB 69868, Beaverton, Oregon 97008‑7105, USA.