← Back to Yayika

Privacy Notice

Last updated: July 30, 2026

Data Controller:

Name: Edgar Apolonio Aguilera

RFC: AOAE781008V98 (operating under the registered trademark YAYIKA)

Email: admin@yayika.com

Website: yayika.com

This Privacy Notice is issued in compliance with the UK General Data Protection Regulation (UK GDPR), the California Consumer Privacy Act (CCPA/CPRA), the Children's Online Privacy Protection Act (COPPA), and for awareness purposes, the Lei Geral de Proteção de Dados (LGPD).

Scope

This notice applies to all personal data processed by Yayika through its website (yayika.com) and associated services. It covers data collected from users, customers, and visitors regardless of their location. Where local law imposes additional requirements, those requirements are addressed in the regional sections below.

Data Protection Officer

Yayika is not required to appoint a Data Protection Officer under current regulations. However, all data protection inquiries should be directed to admin@yayika.com, which serves as the primary point of contact for all privacy-related matters.

1. Data We Collect

  • Identity data: full name, email address, phone number (optional)
  • Contact data: email address, phone number
  • Financial data: credit/debit card information processed by Stripe. We do not store card data on our servers
  • Health and cycle data: menstrual cycle patterns, symptoms, energy and mood (provided voluntarily by the user)
  • Behavioural data: preferences, purchase history, platform interactions, browsing data, pages visited and time spent
  • Location data: country and time zone (derived from IP address, general only, no precise geolocation)

This data is obtained directly from you when you register, make a purchase or use the platform services, as well as automatically through your interaction with the site. We do not collect data from third-party sources or data brokers.

1.1 Categories of personal data under CCPA

Under the CCPA, the categories of personal information we collect include: identifiers (name, email), commercial information (purchase history), internet activity (browsing history, interactions), and inferences drawn from the above (preferences, characteristics). We do not collect geolocation data, biometric data, or data from consumer reports.

2. Purposes of Processing

Primary purposes (necessary for the service):

  • Processing purchases and delivering digital products
  • Managing memberships and platform access
  • Sending purchase confirmations, receipts and service updates
  • Providing customer support and technical assistance
  • Processing refunds and returns
  • Complying with legal and tax obligations
  • Preventing fraud and ensuring platform security

Secondary purposes (optional):

  • Sending communications about new products, features and promotions
  • Personalising your experience on the platform
  • Conducting statistical and behavioural analysis to improve the service
  • Sending newsletters and educational content on wellbeing, productivity and finance
  • Generating personalised recommendations using artificial intelligence tools

You may opt out of secondary-purpose communications at any time by emailing admin@yayika.com.

3. Consent

Your consent is obtained when you:

  • Accept this Privacy Notice upon registration or purchase
  • Voluntarily provide your data through platform forms
  • Continue using Yayika services after being notified of this notice
  • Actively tick a consent checkbox on specific forms

You may withdraw your consent at any time by contacting admin@yayika.com. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.

3.1 How to exercise your rights

To exercise any of your rights under this notice, please:

  • Email us at admin@yayika.com with a clear description of your request
  • Include your full name and registered email address
  • Provide a copy of a valid form of identification (where required)
  • Specify which right you wish to exercise

We will acknowledge your request within 3 business days and provide a substantive response within the applicable legal timeframe. We may need to verify your identity before processing your request.

4. International Data Transfers

Your data may be shared with the following third parties, including international transfers:

  • Stripe, Inc. (US): Payment processing. Data transferred under Standard Contractual Clauses (SCCs) and the EU-U.S. Data Privacy Framework. See: stripe.com/privacy
  • Supabase, Inc. (US): Database infrastructure. Data stored under SCCs. Supabase offers EU data residency options. See: supabase.com/privacy
  • Resend, Inc. (US): Transactional email services under SCCs. See: resend.com/privacy
  • Plausible Insights OÜ (EU): Privacy-friendly analytics based in Estonia. No cookies or personally identifiable data. No international transfer. See: plausible.io/privacy
  • Competent authorities: When required by law, court order or governmental authority

4.1 Safeguards for international transfers

Where we transfer personal data outside the UK or EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the relevant authority, the UK International Data Transfer Agreement (IDTA), or reliance on an adequacy decision. You may request a copy of the relevant transfer mechanism by contacting admin@yayika.com.

5. Your Rights

5.1 UK GDPR Rights

If you are a UK resident, you have the following rights under the UK GDPR:

  • Right of access (Art. 15): Request a copy of all personal data we hold about you
  • Right to rectification (Art. 16): Request correction of inaccurate or incomplete data
  • Right to erasure — “right to be forgotten” (Art. 17): Request deletion of your data when it is no longer necessary, you withdraw consent, or you object to processing
  • Right to restriction (Art. 18): Request restriction of processing in certain cases
  • Right to data portability (Art. 20): Receive your data in a structured, commonly used format and transfer it to another controller
  • Right to object (Art. 21): Object to processing based on legitimate interest, including profiling
  • Right not to be subject to automated decisions (Art. 22): Not be subject to decisions based solely on automated processing, including profiling
  • Rights related to automated decision-making (Art. 13-14): Be informed about the existence of automated decision-making, including profiling, and meaningful information about the logic involved

Supervisory authority: Information Commissioner's Office (ICO). Response time: maximum 30 calendar days.

5.2 CCPA / CPRA Rights (California Residents)

  • Right to know: Request the categories of personal data collected, sources, purposes and third parties it is shared with
  • Right to delete: Request deletion of your personal data
  • Right to opt out of sale: Yayika does not sell personal data. If this changes, we will notify you and provide an opt-out mechanism
  • Right to non-discrimination: Not be discriminated against for exercising your privacy rights
  • Right to correct: Request correction of inaccurate data (CPRA)
  • Right to limit use of sensitive data: Limit the use and disclosure of sensitive personal data (CPRA)

To exercise these rights, contact admin@yayika.com. Response time: maximum 45 days.

6. Data Retention

  • Account data: While your account is active. After deletion, retained for up to 30 days for backup purposes
  • Purchase data: 10 years from the transaction (tax obligation)
  • Marketing data: Until you withdraw consent
  • Support data: 2 years from last interaction
  • Cycle data: Until you withdraw consent or request deletion
  • AI interaction data: Up to 12 months after last interaction

When data is no longer required, it is securely deleted or anonymised so that it can no longer be associated with you.

7. Security Measures

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure or destruction. These measures include:

  • SSL/TLS encryption on all communications
  • Secure authentication with JWT tokens
  • Row Level Security (RLS) policies on the database
  • Restricted access to personal data based on the principle of least privilege
  • System access and activity monitoring
  • Encrypted backups and periodic recovery testing
  • Regular security assessments and vulnerability scanning

8. Cookies

Yayika uses only essential cookies for platform functionality (user sessions, preferences). We do not use advertising tracking cookies. For details, see our Cookie Policy.

You can reject analytics cookies through the cookie banner displayed when visiting the platform, or by configuring your browser to block Plausible Analytics cookies.

Third-party services that may set cookies include: Stripe (payment processing session), Supabase (authentication session). These cookies are strictly necessary for the provision of the service and do not require consent.

9. Children's Data (COPPA Awareness)

Yayika's service is intended for users aged 18 and over. We do not knowingly collect personal data from children under 13. In accordance with COPPA, if a parent or guardian becomes aware that their child under 13 has provided us with personal data without their consent, they should contact us at admin@yayika.com for immediate deletion.

For users between 13 and 17, we require parental or guardian consent before processing any personal data. Yayika reserves the right to suspend or delete accounts of users under 18 without prior notice.

If you are a parent or guardian and believe your child has provided personal data to Yayika, please contact us immediately. We will take steps to delete such information from our systems.

We may collect limited data from minors (13-17) with verifiable parental consent as required by COPPA and applicable state laws. Such data is processed under the same conditions as adult data.

10. Third-Party Service Providers

Our third-party service providers process data under written agreements that ensure adequate protection. We conduct due diligence on all processors and sub-processors:

  • Stripe, Inc.: PCI DSS Level 1 certified payment processor. Processes card data using tokenisation. Yayika never has access to raw card numbers
  • Supabase, Inc.: SOC 2 Type II compliant database provider. Offers encryption at rest and in transit with AES-256
  • Resend, Inc.: Email delivery service. Processes only email addresses and message content necessary for transactional emails
  • Plausible Insights OÜ: Privacy-first analytics. Collects aggregate data only, no individual user tracking, no cross-site tracking

10. Automated Decisions and AI Processing

  • Wellbeing and cycle tracking assistants: Pattern analysis for personalised recommendations
  • Automated financial advice: Savings and productivity recommendations
  • Content generation: Personalised affirmations, plans and motivational content
  • Smart notifications: Reminders and content based on your activity and preferences

You have the right to request human intervention, an explanation of the logic involved, and to contest any automated decision that affects you. Under the EU AI Act (Regulation 2024/1689, Art. 50), AI-generated content is clearly identified on the platform.

11. LGPD Awareness (Brazil)

For users in Brazil, processing is governed by the Lei Geral de Proteção de Dados (LGPD — Lei 13.709/2018). You have rights including access, rectification, anonymisation, blocking, deletion, portability, and information about data sharing. Automated decisions (Art. 20) are subject to review upon request. The supervisory authority is the ANPD.

Argentina — Ley de Protección de Datos Personales No. 25.326

If you are in Argentina, your personal data is protected by the Ley de Protección de Datos Personales No. 25.326 and its regulations (Decreto 1558/2001). You have rights of access, rectification, update, and deletion of your data. The regulatory authority is the Agencia de Acceso a la Información Pública (AAIP). You may file complaints before the AAIP or competent courts.

Chile — Ley No. 19.628 sobre Protección de la Vida Privada

If you are in Chile, your personal data is protected by the Ley No. 19.628 sobre Protección de la Vida Privada. You have rights of information, access, rectification, cancellation, and opposition. The regulatory authority is the Servicio Nacional del Consumidor (SERNAC). You may file complaints before SERNAC or competent courts.

Colombia — Ley Estatutaria 1755 de 2015

If you are in Colombia, your personal data is protected by the Ley Estatutaria 1755 de 2015 and the Ley 1581 de 2012. You have rights of access, rectification, update, deletion, and portability. The regulatory authority is the Superintendencia de Industria y Comercio (SIC). You may file complaints before the SIC or competent courts.

Peru — Ley No. 29733, Ley de Protección de Datos Personales

If you are in Peru, your personal data is protected by the Ley No. 29733 and its regulations (Decreto Supremo No. 003-2013-JUS). You have rights of access, rectification, update, deletion, and opposition. The regulatory authority is the Autoridad Nacional de Protección de Datos Personales (ANPDP) under INDECOPI. You may file complaints before INDECOPI or competent courts.

Ecuador — Ley Orgánica de Protección de Datos Personales

If you are in Ecuador, your personal data is protected by the Ley Orgánica de Protección de Datos Personales. You have rights of access, rectification, update, deletion, and portability. The regulatory authority is the Superintendencia de Control del Poder de Mercado. You may file complaints before the Superintendencia or competent courts.

12. Sensitive Data

Yayika may process sensitive personal data (e.g., health and cycle data) only when voluntarily provided by the user. This data is used exclusively for wellness and cycle tracking services and will never be used for discriminatory purposes. Processing of sensitive data requires explicit consent under applicable law.

13. California "Shine the Light" and "Do Not Track"

Under California Civil Code Section 1798.83, California residents may request information regarding the disclosure of personal information to third parties for direct marketing purposes. Yayika does not share personal information with third parties for their direct marketing purposes. We do not currently respond to "Do Not Track" (DNT) browser signals, but you may exercise your CCPA/CPRA rights as described in Section 5.2.

Yayika does not sell, trade, or rent personal information to third parties for monetary or other valuable consideration. We do not have actual knowledge that we sell or share personal information of consumers under 16 years of age.

14. Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours (UK GDPR Art. 33). Where the breach poses a high risk, we will communicate the breach to you without undue delay. Notification will include the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.

14. Complaints

If you believe your data protection rights have been infringed, you have the right to lodge a complaint with the relevant supervisory authority. UK residents should contact the ICO. California residents may contact the California Attorney General's Office.

15. Changes to this Notice

We reserve the right to modify this Privacy Notice at any time. Changes will be published on this page and take effect upon publication. We recommend reviewing this page periodically. Where material changes are made, we will make reasonable efforts to notify registered users via email.

16. Definitions

For the purposes of this notice:

  • Personal data: any information relating to an identified or identifiable natural person
  • Processing: any operation performed on personal data, including collection, recording, storage, adaptation, retrieval, consultation, use, disclosure, erasure or destruction
  • Data controller: the natural or legal person who determines the purposes and means of processing personal data (Yayika / Edgar Apolonio Aguilera)
  • Data processor: a natural or legal person who processes personal data on behalf of the controller (e.g., Stripe, Supabase, Resend)
  • Consent: any freely given, specific, informed and unambiguous indication of the data subject's wishes
  • Data breach: a security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data
  • Data retention period: the period of time for which personal data is stored, after which it is securely deleted or anonymised
  • Supervisory authority: an independent public authority established by an EU/EEA member state or UK (e.g., ICO for the UK, CNIL for France, BfDI for Germany)
  • Third country: a country outside the UK/EEA that does not provide an adequate level of data protection as determined by the European Commission or UK Secretary of State
  • Profiling: any form of automated processing of personal data to evaluate personal aspects relating to a natural person

17. Contact

  • Email: admin@yayika.com
  • Website: yayika.com

18. Last Review

This Privacy Notice was last reviewed and updated on July 30, 2026. It will be reviewed at least annually or whenever there are material changes to our data processing activities, applicable laws, or regulatory guidance. Version 1.0 of this notice was first published on July 30, 2026.

Any previous versions of this notice can be obtained by contacting admin@yayika.com. We maintain records of all changes to this notice for compliance purposes.

This document was last updated on July 30, 2026. Version 1.0.