Privacy Policy

Last modified: October 12, 2023
1. Introduction

Please carefully review this Privacy Policy ("Privacy Policy") before utilizing our Service, which encompasses the Website, Widget, and API (as defined below) and is collectively referred to as the "Service." This Privacy Policy establishes the parameters regarding the types of information and data we collect, as well as how we utilize and share such information. Your access to and use of the Service is contingent upon your acceptance of the Terms of Service, which can be found at the following address: https://yochats.com/terms/ ("Terms of Service"). These Terms of Service encompass and incorporate the terms outlined in this Privacy Policy.The Service is operated by YoChats ("Company"), and we utilize your data to deliver and enhance the Service. Your utilization of the Service implies your consent to the collection and utilization of information in accordance with the terms set forth in this policy. Unless otherwise defined within this Privacy Policy, the terms used herein shall have the same meanings as those outlined in our Terms of Service.

2. Definitions

2.1. API stands for YoChats Application Programming Interface, which can be integrated with a user's software.
2.2. Cookies are small files stored on your device.
2.3. Device refers to a computer or a mobile device.
2.4. Data Controller refers to a natural or legal person who, either alone or in conjunction with others, determines the purposes and methods by which any personal data is or will be processed. In the context of this Privacy Policy, we serve as the Data Controller for your data.
2.5. Data Processors, also known as Service Providers, are natural or legal entities that process data on behalf of the Data Controller. We may engage various Service Providers to help process your data more effectively.
2.6. Data Subject is any living individual who is the subject of personal data.
2.7. Personal Data pertains to data about a living individual that can be used to identify that individual, whether from the data itself or in conjunction with other information in our possession or likely to come into our possession.
2.8. Service encompasses the Website, Widget, and/or the API, depending on the specific usage by a given user.
2.9. Usage Data comprises data collected automatically, generated by the use of the Service or the Service infrastructure itself. This may include information such as the duration of a page visit.
2.10. User is the individual using our Service, and this term corresponds to the Data Subject, who is the subject of Personal Data.
2.11. Website means web pages located at https://yochats.com/.
2.12. Widget means a YoChats widget that may be implemented to the User’s website.

3. The Data Controller

The controller of your Personal Data is: YoChats.

4. Information Collection and Use

We gather various categories of information for diverse purposes aimed at delivering and enhancing our Service to you.

5. Types of Data Collected

5.1. Personal Data
During the utilization of our service, we may request that you furnish us with specific personally identifiable information, referred to as "Personal Data," which can be employed for the purpose of contacting or distinguishing you. This Personal Data may include but is not limited to:Email addressFirst name and last nameCookies and Usage Data
5.2. Usage Data
We may collect Usage Data, which is information that your browser sends when you visit our Service or access it through a Device. This Usage Data may encompass details like your computer's Internet Protocol address (e.g., IP address), browser type, browser version, the pages you visit on our Service, the date and time of your visit, the duration of your visit to those pages, unique Device identifiers, and other diagnostic data. When you access our Service via a Device, this Usage Data may also include information such as the type of Device you are using, your Device's unique ID, your Device's IP address, your operating system, the type of Internet browser you use, unique Device identifiers, and other diagnostic data.
5.3. Tracking Cookies
DataWe employ cookies and similar tracking technologies to monitor activity on our Service and retain certain information. Cookies are small data files that may contain an anonymous unique identifier. They are sent to your browser from a website and stored on your Device. Additionally, we utilize other tracking technologies like beacons, tags, and scripts to collect and monitor information, contributing to the improvement and analysis of our Service. You can configure your browser to reject all cookies or alert you when a cookie is being sent. However, declining cookies may limit your ability to use certain parts of our Service.

Examples of Cookies we employ:
- Session Cookies: These are used to operate our Service.
- Preference Cookies: We utilize Preference Cookies to remember your preferences and various settings.
- Security Cookies: Security Cookies are employed for security purposes.
- Advertising Cookies: These are used to provide you with advertisements that are relevant to your interests.

6. Use of Data

YoChats utilizes the collected Personal Data for the following purposes:
1. To provide and maintain our Service, including but not limited to the processing of email addresses, first names, last names, cookies, and usage data. This processing is necessary for the performance of a contract to which you are a party.
2. To notify you about changes to our Service, involving the processing of email addresses, first names, last names, cookies, and usage data. This processing is necessary for the performance of a contract to which you are a party.
3. To enable your participation in interactive features of our Service when you choose to do so, requiring the processing of email addresses, first names, last names, cookies, and usage data. This processing is necessary for the performance of a contract to which you are a party.
4. To provide customer support, involving the processing of email addresses, first names, last names, cookies, and usage data. This processing is necessary for the performance of a contract to which you are a party.
5. To gather analysis or valuable information for the improvement of our Service, including the processing of email addresses, first names, last names, cookies, and usage data. This is carried out based on the legitimate interests of the Data Controller.
6. To monitor the usage of our Service, requiring the processing of email addresses, first names, last names, cookies, and usage data. This is carried out based on the legitimate interests of the Data Controller.
7. To detect, prevent, and address technical issues, involving the processing of email addresses, first names, last names, cookies, and usage data. This is carried out based on the legitimate interests of the Data Controller.
8. To fulfill any other purpose for which you provide your Personal Data, including email addresses, first names, last names, cookies, and usage data. This processing is necessary for the performance of a contract to which you are a party.
9. To carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including billing and collection, entailing the processing of email addresses, first names, last names, cookies, and usage data. This processing is necessary for the performance of a contract to which you are a party.
10. To provide you with notices about your account and/or subscription, such as expiration and renewal notices, email instructions, and similar communications, involving the processing of email addresses, first names, last names, cookies, and usage data. This processing is necessary for the performance of a contract to which you are a party.
11. To provide you with news, special offers, and general information about other goods, services, and events similar to those you have already purchased or inquired about, subject to your consent. This processing includes email addresses, first names, last names, cookies, and usage data.
12. In any other way described at the time of data collection, with the processing of email addresses, first names, last names, cookies, and usage data, as necessary for the performance of a contract to which you are a party.

7. Retention of Data

We will retain your Personal Data only for the duration necessary to fulfill the purposes outlined in this Privacy Policy. We will maintain and utilize your Personal Data as required to meet our legal obligations (e.g., for compliance with applicable laws), resolve disputes, and enforce our legal agreements and policies. Personal Data processed with your consent will be kept as long as the consent remains in effect and until any potential claims arising from the Service expire. Additionally, we will retain Usage Data for internal analytical purposes. Typically, Usage Data is stored for a limited duration, unless it is utilized to enhance security, improve the functionality of our Service, or is mandated by legal obligations necessitating a longer retention period.

8. Transfer of Data

Your information, including Personal Data, may be transferred to and stored on computers located outside of the jurisdiction of Cyprus, where data protection laws may differ from those in Cyprus. If you are located outside of Cyprus and choose to provide us with your information, please be aware that we will transfer the data, including Personal Data, to Cyprus for processing. Our company will take all reasonable steps to ensure the secure and compliant treatment of your data in accordance with this Privacy Policy. We will not transfer your Personal Data to any organization or country without adequate safeguards, including the security of your data and other personal information, in place. When we transfer your Personal Data to other countries, we will protect it as described in this Privacy Policy and in accordance with applicable law. We employ contractual safeguards for the international transfer of Personal Data, including the use of the European Commission's standard contractual clauses as referred to in Article 46.2(c) of the General Data Protection Regulation (GDPR).

9. Disclosure of Data

We may disclose the Personal Data you provide under various circumstances, as follows:
1. When compelled by law or in response to legitimate requests from public authorities.
2. In the event of our company or its subsidiaries being involved in a merger, acquisition, or asset sale.
3. To our subsidiaries, affiliates, and employees.
4. To contractors, service providers, and other third parties that assist in supporting our business operations.
5. To fulfill the specific purposes for which you have provided the data.For the purpose of displaying your company's logo on our website, with your explicit consent.
6. It is important to note that we do not engage in the sale or any other form of unauthorized sharing of your Personal Data, except as explicitly outlined in this Privacy Policy.

10. Security of Data

We place significant importance on the security of your data. However, it is crucial to recognize that no method of data transmission over the Internet or electronic storage can guarantee absolute security. Our company implements suitable administrative, technical, and physical measures to safeguard the Personal Data you entrust to us, aiming to mitigate the risk of accidental, unlawful, or unauthorized destruction, loss, alteration, access, disclosure, or use. These measures include the maintenance of backup copies and the restriction of access to Personal Data to authorized personnel only.

11. Your Data Protection Rights Under General Data Protection Regulation (GDPR)

If you are a resident of the European Union (EU) and the European Economic Area (EEA), you are entitled to certain data protection rights in accordance with the General Data Protection Regulation (GDPR). Our company, incorporated in Cyprus, is committed to facilitating the exercise of these rights. You have the following data protection rights:

11.1. Right to Access:
You can request access to your Personal Data, including receiving a copy of all your Personal Data that we process.
11.2. Right to Rectification:
You have the right to request the correction of any inaccuracies in your Personal Data by specifying the data that requires correction.
11.3. Right to Erasure:
You can request the deletion of your Personal Data. Please note that there are legal circumstances where we may be entitled to refuse erasure.
11.4. Right to Restriction of Processing:
You have the right to request the restriction of processing of your Personal Data by specifying the data that should be subject to restrictions.
11.5. Right to Object:
You can object to the processing of your Personal Data, particularly if it is based on specific grounds related to your situation.
11.6. Right to Withdraw Consent:
You have the right to withdraw your consent for the processing of your Personal Data at any time. Please be aware that this withdrawal applies only to data processing based on your consent, and we may continue processing your Personal Data if there is a legal basis for doing so.
11.7. Right to Lodge a Complaint:
If you believe that the processing of your Personal Data infringes the GDPR, you have the right to file a complaint with a supervisory authority, especially in the EU member state where you reside, work, or where the alleged infringement occurred.If you wish to exercise any of these rights, please contact us at app@yochats.com. We may request verification of your identity before responding to your requests. It's important to note that, in some cases, we may not be able to provide our services without certain necessary data.

12. Your Data Protection Rights under the California Privacy Protection Act (CalOPPA)

CalOPPA, the California Online Privacy Protection Act, represents the first state law in the United States mandating that commercial websites and online services must display a privacy policy. This law has a broad scope, extending its applicability not only to entities within California but also to individuals or companies operating websites worldwide, which collect personally identifiable information from California consumers. Such entities are obliged to conspicuously present a privacy policy on their website, explicitly detailing the information collected and the parties with whom it is shared. Furthermore, these entities must adhere to the policies outlined in their privacy policy.

For more information, you can refer to: https://consumercal.org/about-cfc/cfc-education-foundation/california-online-privacy-protection-act-caloppa-3/

In compliance with CalOPPA, we commit to the following principles:
1. Users can navigate our site anonymously.
2. Our Privacy Policy link prominently features the term "Privacy" and is readily accessible on the specified page of our website's homepage.
3. Users will be duly informed of any revisions to our privacy policy through our Privacy Policy Page.
4. Users possess the ability to modify their personal information by contacting us via email at app@yochats.com.

Our Approach to "Do Not Track" Signals:We respect "Do Not Track" signals and refrain from tracking, deploying cookies, or employing advertising when a user's web browser is configured with a "Do Not Track" mechanism. "Do Not Track" serves as a user preference that can be enabled or disabled via the Preferences or Settings page of their web browser.

13. Service Providers

We may engage third-party companies and individuals to assist in the facilitation of our Service ("Service Providers"), provide services on our behalf, perform services related to our Service, or aid us in the analysis of how our Service is utilized. These third parties shall be granted access to your Personal Data solely for the purpose of executing these tasks on our behalf and are legally bound not to disclose or utilize such data for any other purposes. As our company is incorporated in Cyprus, all data processing shall be in accordance with the applicable data protection laws and regulations of Cyprus.

14. Analytics

We may engage the services of third-party Service Providers to oversee and analyze the usage of our Service.

14.1. Google Analytics
Google Analytics is a web analytics service provided by Google, designed to track and report website traffic. Google employs the data collected to observe and assess the utilization of our Service. This information may be shared with other Google services. Google might utilize this gathered data to tailor and customize advertisements within its advertising network. For comprehensive details regarding Google's privacy practices, please refer to the Google Privacy.

Terms webpage at: https://policies.google.com/privacy?hl=en
We also recommend that you review Google's policies pertaining to data security at: https://support.google.com/analytics/answer/6004245

15. Payments

Our company may offer paid products and/or services through our Service. In such instances, we engage third-party services for payment processing, such as payment processors. It is important to note that we do not retain or gather your payment card information. This sensitive data is directly transmitted to our third-party payment processors, whose management of your personal information is subject to their respective Privacy Policies. These payment processors strictly adhere to the standards established by the Payment Card Industry Data Security Standard (PCI-DSS), as administered by the PCI Security Standards Council, a collaborative effort involving major brands like Visa, Mastercard, American Express, and Discover. PCI-DSS requirements are designed to ensure the secure handling of payment information.
The payment processors with whom we collaborate include:

15.1. Stripe
For further details regarding Stripe Inc.'s Privacy Policy, please visit: https://stripe.com/us/privacy

16. Links to Other Sites

Our Service may include hyperlinks to websites not under our control. Clicking on such third-party links will redirect you to the respective third-party website. We strongly recommend that you diligently review the Privacy Policy of every website you access. We hereby disclaim any authority over and disavow any responsibility for the content, privacy policies, or practices of any third-party websites or services.

17. Children's Privacy

Our Service is not intended for use by individuals under the age of 16 ("Children"). We do not intentionally gather personally identifiable information from individuals under the age of 16. If you are a parent or legal guardian and you have knowledge that your Child has furnished us with Personal Data, kindly reach out to us. In the event that we become aware that we have obtained Personal Data from children without duly verified parental consent, we will take measures to expeditiously delete such information from our servers.

18. Changes to This Privacy Policy

We reserve the right to periodically update our Privacy Policy. Notice of such changes will be provided by publishing the revised Privacy Policy on this webpage and updating the "effective date" at the top of this page, unless a different form of notification is mandated by the applicable laws. We recommend that you regularly review this Privacy Policy for any modifications. These changes become effective as soon as they are posted on this page. Should you continue to use our services or furnish us with Personal Data after we have published an updated Privacy Policy, or provided notification if required, you thereby express your consent to the revised Privacy Policy and the practices outlined within it.

19. Contact Us

If you have any questions about this Privacy Policy, please contact us at app@yochats.com.

20. Privacy Policy Addendum

20.1. Addendum to Privacy Policy for Canada
Personal information that is stored and processed by our affiliated entities and third-party service providers in the United States and other international jurisdictions may be disclosed in compliance with lawful access requests made by U.S. or foreign courts or government authorities. Your information will not be shared with third parties for marketing purposes without obtaining your explicit consent. For additional details regarding our privacy policies, or if you wish to access, update, or rectify any inaccuracies in your personal data, or if you have any inquiries or complaints concerning how we or our service providers handle your personal information, please do not hesitate to contact us using the information provided in the "Contact us" section above.
20.2. Addendum to Privacy Policy for Mexico
To the extent that Mexican privacy laws or regulations are applicable, the following Mexico-specific provisions shall take precedence over any conflicting provisions outlined in the Privacy Policy.
20.2.1. How We Use the Information We Obtain: Additionally, we may employ your Personal Data for purposes outlined in the "Use of Data" section of the Privacy Policy, which may be deemed as secondary purposes under Mexican law. We refrain from utilizing or sharing personal payment or financial information except in cases related to payment processing or when another legal basis exists. You retain the right to withdraw your consent for us to process your Personal Data by contacting us, as specified in the "How to contact us" section of the Privacy Policy. Should you choose to withdraw your consent for the processing of your Personal Data for any of the primary purposes mentioned above, it may affect our ability to provide certain services, although we may still engage in processing authorized by law. The Company may also employ data and associated data analysis in other Company products and services.
20.2.2. Information We Share: We may share your Personal Data in accordance with the Privacy Policy, and to the extent permitted by law, you have the option to withdraw your consent for such sharing by contacting us, as indicated in the "How to contact us" section of the Privacy Policy. Additionally, we share the information we collect with our customers, partners, affiliates, and joint marketing partners. Collectively, these entities are referred to as "Business Partners" herein and may utilize the information for the purposes outlined in this Privacy Policy. We may also share information with our Business Partners and other third parties for purposes such as warranty fulfillment, troubleshooting, maintenance, or enhancements to the design and performance of their products and services.
20.2.3. Requests for Access, Correction, Cancellation, Objection, or Consent Withdrawal: In addition to the rights provided in the Privacy Policy, you may request the cancellation of your Personal Data to the extent permitted by law by contacting us, as specified in the "How to Contact us" section of the Privacy Policy. Following a valid cancellation request, we may retain the Personal Data for the duration and purposes allowed by law before permanent deletion. We commit to responding to your requests for access, correction, cancellation, objection, or withdrawal of consent to our processing of your Personal Data within 20 business days from the date of receiving your comprehensive request, or in accordance with applicable legal requirements. A complete request must include your full name, contact address, and a clear, detailed description of your request.
20.3. Addendum to Privacy Policy for Japan
The Company operates in accordance with Japanese laws and regulations, notably the Act on the Protection of Personal Information. The Company assumes primary responsibility for overseeing the management of Personal Data that is jointly utilized with our affiliates or third parties. Your information will not be disclosed to third parties for marketing purposes without obtaining your explicit prior consent.
20.4. Addendum to Privacy Policy for Republic of Korea
Unless otherwise mandated by law, consumer Personal Data will be promptly and securely disposed of in the following circumstances: (i) upon the consumer's revocation of consent for our utilization of the information, (ii) once the intended purpose of collecting and using the Personal Data has been achieved, or (iii) when the legally required retention period has expired. If the applicable law necessitates the preservation of Personal Data that would otherwise be disposed of, such data will be transferred to a distinct database and subsequently disposed of in accordance with the timeframe stipulated by the relevant law.The disposal of Personal Data will be executed in a manner reasonably designed to prevent its retrieval or reutilization. We commit not to disclose your Personal Data to third parties in contravention of the law, such as without obtaining your consent when consent is mandated.In the context of the services outlined in this Privacy Policy, Company and its affiliates assume responsibility for the management of Personal Data concerning services provided within the Republic of Korea.