📄 Legal Document — Data Protection Policy

Data Protection Policy

Last updated: July 2026

1. Data Controller

The data controller responsible for your personal data is:

Name: Edgar Apolonio Aguilera

Tax ID (RFC): AOAE781008V98

Email: admin@yayika.com

Website: yayika.com

2. Types of Personal Data Collected

Yayika may collect the following categories of personal data:

CategoryDescription
IdentityFirst name, last name, date of birth, profile photo
ContactEmail address, phone number, postal address
FinancialBilling data, payment history, card information (processed by Stripe)
Health / Menstrual CycleCycle data, symptoms, wellness notes (only with explicit consent)
BehavioralBrowsing history, preferences, platform interactions

3. Purposes of Data Processing

PurposeLegal BasisData Categories
Service provisionContract performanceIdentity, Contact, Health
Account managementContract performanceIdentity, Contact
Payment processingContract performanceFinancial
Service notificationsLegitimate interestContact
Experience personalizationLegitimate interestBehavioral
Service improvementLegitimate interestBehavioral
Aggregated health reportsExplicit consentHealth
Legal complianceLegal obligationIdentity, Financial
Fraud preventionLegitimate interestIdentity, Behavioral

4. Legal Bases for Processing

We process your personal data under the following legal bases:

5. Data Retention Periods

Your personal data will be retained for the following periods:

6. Security Measures

Yayika implements technical, administrative, and physical security measures to protect your data, including:

7. International Data Transfers

Note: Your data may be transferred to and stored on servers located outside your country of residence.

ProviderCountryPurposeSafeguards
SupabaseUnited StatesDatabase storageStandard contractual clauses
StripeUnited StatesPayment processingStandard contractual clauses, PCI DSS

8. Data Processing Table

PurposeLegal BasisCategoriesRetention
Main serviceContractIdentity, Contact, HealthDuration of service
PaymentsContractFinancial5+ years (fiscal)
MarketingConsentContact, BehavioralUntil withdrawal
AnalyticsLegitimate interestBehavioral24 months
Legal complianceLegal obligationIdentity, FinancialPer regulation

🇪🇸 MEXICO — Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP)

8.1 Supervisory Authority

The competent authority is the Secretaría Anticorrupción y Buen Gobierno (SABG), through the Transparency Unit.

8.2 ARCO Rights

Pursuant to Articles 15 to 47 of the LFPDPPP, you have the right to:

RightDescription
AccessKnow what personal data we hold and how we process it
RectificationRequest correction of inaccurate or incomplete data
CancellationRequest deletion of data when no longer necessary
OppositionObject to the processing of your data for specific purposes

8.3 Consent

8.4 Simplified Privacy Notice

In accordance with Article 16 of the LFPDPPP, we provide a simplified privacy notice containing the essential elements of data processing.

8.5 Data Protection Contact

To exercise your ARCO rights, contact: admin@yayika.com


🇪🇺 EUROPEAN UNION — General Data Protection Regulation (GDPR)

8.6 Legal Basis for Processing

Processing is based on:

8.7 Data Subject Rights (GDPR)

RightArticleDescription
AccessArt. 15Obtain confirmation and a copy of your data
RectificationArt. 16Correct inaccurate data
ErasureArt. 17Right to be forgotten — data deletion
RestrictionArt. 18Restrict processing in certain cases
PortabilityArt. 20Receive data in structured format
ObjectArt. 21Object to processing based on legitimate interest

8.8 Data Protection Officer (DPO)

Due to our company size, we are not required to appoint a DPO. However, you may contact us at: admin@yayika.com

8.9 Data Protection Impact Assessment

We will conduct a Data Protection Impact Assessment (DPIA) for the processing of health/menstrual cycle data in accordance with Article 35 of the GDPR.

8.10 Supervisory Authority

Supervisory authorities vary by member state. Examples: CNIL (France), BfDI (Germany), AEPD (Spain). You have the right to lodge a complaint with the authority in your country of residence.

8.11 Data Retention

In accordance with Article 5(1)(e) of the GDPR, data will not be retained longer than necessary for the purposes of processing.

8.12 Cookie Consent

We comply with the ePrivacy Directive regarding cookie usage. We use a cookie banner that allows you to accept or reject non-essential cookies.


🇧🇷 BRAZIL — Lei Geral de Proteção de Dados (LGPD)

8.13 National Authority

The competent authority is the Autoridade Nacional de Proteção de Dados (ANPD).

8.14 Legal Bases (Art. 7 LGPD)

8.15 Data Subject Rights (Art. 18 LGPD)

RightDescription
ConfirmationConfirm the existence of processing
AccessAccess personal data
CorrectionCorrect incomplete or outdated data
AnonymizationAnonymize, block, or delete unnecessary data
PortabilityRequest data portability
DeletionRequest deletion of data processed with consent
InformationKnow entities with whom data is shared

8.16 Data Protection Officer

Our DPO (Encargado) is: admin@yayika.com

8.17 Sensitive Data

Health data (menstrual cycle) is considered sensitive data under Art. 5(II) of the LGPD and requires specific and highlighted consent.


Argentina — Ley de Protección de Datos Personales No. 25.326

If you are in Argentina, your personal data is protected by the Ley de Protección de Datos Personales No. 25.326 and its regulations (Decreto 1558/2001). You have rights of access, rectification, update, and deletion of your data. The regulatory authority is the Agencia de Acceso a la Información Pública (AAIP). You may file complaints before the AAIP or competent courts.

Chile — Ley No. 19.628 sobre Protección de la Vida Privada

If you are in Chile, your personal data is protected by the Ley No. 19.628 sobre Protección de la Vida Privada. You have rights of information, access, rectification, cancellation, and opposition. The regulatory authority is the Servicio Nacional del Consumidor (SERNAC). You may file complaints before SERNAC or competent courts.

Colombia — Ley Estatutaria 1755 de 2015

If you are in Colombia, your personal data is protected by the Ley Estatutaria 1755 de 2015 and the Ley 1581 de 2012. You have rights of access, rectification, update, deletion, and portability. The regulatory authority is the Superintendencia de Industria y Comercio (SIC). You may file complaints before the SIC or competent courts.

Peru — Ley No. 29733, Ley de Protección de Datos Personales

If you are in Peru, your personal data is protected by the Ley No. 29733 and its regulations (Decreto Supremo No. 003-2013-JUS). You have rights of access, rectification, update, deletion, and opposition. The regulatory authority is the Autoridad Nacional de Protección de Datos Personales (ANPDP) under INDECOPI. You may file complaints before INDECOPI or competent courts.

Ecuador — Ley Orgánica de Protección de Datos Personales

If you are in Ecuador, your personal data is protected by the Ley Orgánica de Protección de Datos Personales. You have rights of access, rectification, update, deletion, and portability. The regulatory authority is the Superintendencia de Control del Poder de Mercado. You may file complaints before the Superintendencia or competent courts.


🇺🇸 UNITED STATES — CCPA/CPRA (California) and COPPA

8.18 California Consumer Privacy Act (CCPA/CPRA)

If you are a California resident, you have the following rights:

RightDescription
Right to KnowRequest the categories and sources of data collected
Right to DeleteRequest deletion of personal information
Right to Opt-OutOpt out of the sale of personal information
Right to Non-DiscriminationNot be discriminated against for exercising your rights

8.19 Categories of Personal Information (CCPA)

8.20 No Sale of Data

Yayika does not sell personal information to third parties.

8.21 Children's Online Privacy Protection Act (COPPA)

Platform designed for users 18+. We do not knowingly collect data from children under 13. If we discover that a user under 13 has provided data, we will immediately delete the account.


🇬🇧 UNITED KINGDOM — UK GDPR + Data Protection Act 2018

8.22 Supervisory Authority

The competent authority is the Information Commissioner's Office (ICO).

8.23 Post-Brexit Legal Framework

The UK GDPR is the version of the GDPR incorporated into UK law through the Data Protection Act 2018. Rights and obligations are substantially equivalent to the EU GDPR.

8.24 Adequacy Decisions

The UK has EU adequacy decisions, allowing data transfers from the EU/EEA to the UK without additional safeguards.


🇨🇦 CANADA — PIPEDA

8.25 Supervisory Authority

The competent authority is the Office of the Privacy Commissioner (OPC).

8.26 Meaningful Consent

PIPEDA requires meaningful consent for the collection, use, and disclosure of personal data. Consent must be informed and apply only to the purposes communicated.

8.27 Access and Challenge Rights

You have the right to access your personal data and to challenge its accuracy, completeness, and currency.


🇨🇭 SWITZERLAND — New Federal Act on Data Protection (nFADP)

8.28 Supervisory Authority

The competent authority is the Federal Data Protection and Information Commissioner (FDPIC).

8.29 Entry into Force

The nFADP came into force on September 1, 2023, modernizing the Swiss data protection framework.

8.30 Data Protection Impact Assessment

The nFADP requires a Data Protection Impact Assessment for processing that may result in a high risk to personality and fundamental rights.

8.31 Cross-Border Transfers

International data transfers are only permitted if the destination country appears on the Federal Council's adequacy list or if adequate safeguards are established.


9. Changes to This Policy

We reserve the right to update this policy. Any changes will be published on this page with the date of last update.

10. Contact

To exercise your rights or make inquiries about this policy:

Email: admin@yayika.com

Website: yayika.com