Privacy Policy
Last updated: September 2026
1. Data Controller (Art. 13(1)(a) GDPR)
KonzeptWeber LLC
30 N Gould St Ste N
Sheridan, WY 82801, USA
Email: info@yachay.systems
Website: https://yachay.systems
App: Rikuna (rikuna.yachay.systems)
For data protection inquiries, please contact: info@yachay.systems
2. Data Collected and Purposes
2.1 Website Visit and Usage Analytics
When you visit our website, we collect the following data for the purpose of improving our service and understanding how our pages are used:
- IP address (automatically anonymized after 7 days)
- Approximate location (country, city) derived from IP address via ip-api.com
- Browser type and version (User-Agent)
- Referrer URL (the page you came from)
- Pages visited, page type, and associated industry vertical
- Scroll behavior (how far you scrolled on the page)
- Time spent on each page (session duration)
- Clicks on call-to-action buttons
- UTM campaign parameters (if present in the URL)
This data is stored in our own database on European servers. We do not use third-party analytics services (no Google Analytics, no Meta Pixel). A temporary session identifier is stored in your browser's sessionStorage, which is automatically deleted when you close the browser tab. We do not use tracking cookies. To recognise returning visits we derive a pseudonymous value on our server from your IP address and browser identifier, secured with a secret key that never leaves our server. It does not allow your IP address to be reconstructed. The value is deleted after 12 months together with the visit record. If your browser sends a Do-Not-Track (DNT) signal, no analytics data is collected.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure provision and improvement of the website)
2.2 Contact and Onboarding
When you use our contact form, onboarding form, or email address, we process:
- Name, company name
- Email address
- WhatsApp number (optional)
- Information about your business (opening hours, typical inquiries, etc.)
- Content of the message
Legal basis: Art. 6(1)(b) GDPR (contract initiation/fulfillment) or Art. 6(1)(f) (legitimate interest in processing inquiries)
2.3 Payment Processing
For purchases through our website, payment data (name, email, billing address, payment method information) is processed by our payment provider Stripe. We only receive from Stripe the information necessary for order processing (email, amount, package). Complete payment data (e.g., card numbers) is stored exclusively by Stripe.
Legal basis: Art. 6(1)(b) GDPR (contract fulfillment)
2.4 AI Agent Communication
In the course of operating AI communication agents for our customers (businesses), conversation data is processed through the following channels:
- WhatsApp Business API - Messages via the customer's WhatsApp business number
- Instagram Direct Messages - Messages via the customer's Instagram Business account
- Facebook Messenger - Messages via the customer's Facebook Page
- TikTok Content Posting API - Video and photo publishing from the Rikuna dashboard via the customer's TikTok account (OAuth). Post metadata is stored; uploaded media is hosted on European servers.
- Web chat widget - Chat function on the customer's website (no login required)
- Telegram Bot API - optional, at the customer's request
The following data categories may be processed:
- Name and contact details of end users (patients, clients, guests)
- Content of messages and inquiries
- Appointment requests, booking information
- Health-related information (e.g., complaints, prescription information) - only for medical verticals and only when voluntarily provided by the end user
- Prescription data (diagnosis or ICD-10 code, prescribed remedy, number and frequency of treatments, date of issue) and a photo of the prescription - physiotherapy customers only, see 2.4.1
- Treatment documentation dictated by the practice's practitioners - physiotherapy customers only, see 2.4.2
- Conversation metadata (timestamps, channel, conversation ID)
Messages are stored server-side to allow the customer (business) to view conversation histories via their admin dashboard. Data is stored on European servers.
Yachay Systems processes this data as a data processor on behalf of the respective customer (business), who acts as the data controller. Processing is based on a Data Processing Agreement (DPA) pursuant to Art. 28 GDPR.
Legal basis: Art. 6(1)(b) GDPR (contract initiation/appointment coordination) and Art. 6(1)(f) GDPR (legitimate interest in processing customer inquiries).
2.4.1 Prescription Photos (Physiotherapy)
Patients of physiotherapy customers can send a photo of their medical prescription via WhatsApp. The photo is checked by an AI image model at OpenAI to determine whether it shows a prescription and whether it is legible; the model returns only that verdict. The photo is then stored, together with the prescription data recorded by the practice, in the customer's Rikuna dashboard on European servers, where the practice reviews it. Photos that are not recognized as a prescription are rejected and not stored. The temporary copy used for the check is deleted immediately afterwards.
The customer (practice) is the controller for this data and provides the legal basis for processing health data (typically Art. 9(2)(h) GDPR). Patients can present the prescription in person instead.
2.4.2 Voice Documentation (Physiotherapy)
Practitioners of physiotherapy customers can dictate a treatment note in the Rikuna dashboard. The recording is transmitted to OpenAI solely for transcription (speech to text) under API terms that exclude use for model training, and is not stored by us. Only the transcript, its duration in seconds, and a structured draft of the note (complaint, history, findings, goal, measures, next step) generated by an OpenAI language model are stored on European servers. The draft becomes part of the treatment record only after the practitioner has reviewed and confirmed it.
Data subjects are the patient (content of the note) and the practitioner (voice, authorship). The customer (practice) is the controller and is responsible for the statutory retention of treatment records.
2.5 Google Account Integration (Calendar, Business Profile & YouTube)
Where a customer (business) chooses to connect their Google account to the Rikuna dashboard, we access Google user data via Google APIs strictly to provide the connected features. This integration is optional and is only activated through the customer's explicit OAuth consent.
Depending on the permissions granted, we access:
- Google Calendar (reading) - calendar event titles, start/end times, descriptions and status, read so that appointments stay in sync and times the business is already busy are never offered for booking.
- Google Calendar (writing bookings) - for appointments booked through our product, we create, update and delete the corresponding event in the calendar the business connected, including a Google Meet link for online sessions. If the business enters a customer's email address, the customer is added as a guest so Google sends them the invitation. Events our product did not create are never modified or deleted, and we do not create, delete or share calendars.
- Google account email address - to identify the connected account and display the connection status.
- Google Business Profile (where enabled) - business listing information such as opening hours and customer reviews, to display reviews in the dashboard, publish replies, and update opening hours on the business's own listing.
- YouTube channel and videos (read-only) - the title and avatar of the channel the business connects, so the dashboard can show which channel is connected, and the titles and public counts (views, likes, comments) of that channel's own videos for its statistics screen. We do not search, rate, comment on, edit or delete anything on the channel, and we access no other channel.
- YouTube video upload - videos the business composes in the dashboard are uploaded to that same business's own channel, immediately or at a time the business schedules.
- YouTube statistics (read-only) - views, watch time, average view duration, likes, comments, shares and subscribers gained or lost for the connected channel, shown to that business on its own statistics screen. We do not access revenue or monetisation data.
Our use of YouTube API Services is subject to the YouTube Terms of Service and the Google Privacy Policy.
OAuth access and refresh tokens are stored encrypted at rest on European servers and are used solely to call the Google APIs on the customer's behalf. The customer can revoke access at any time by disconnecting in the dashboard or via their Google account permissions; revocation deletes the stored tokens and the data imported from Google. For YouTube in detail: disconnecting in the dashboard also withdraws our access at Google and deletes the tokens immediately; access withdrawn in the Google account deletes them the next time we try to use them; video titles and per-video figures are deleted within 48 hours of the channel being disconnected. A video title we have not refreshed for 30 days is deleted even while the channel stays connected. Aggregated channel statistics collected while the connection existed contain no viewer-level data and are retained.
We do not use Google user data for advertising, we do not sell it, and we do not use it to train generalized AI/ML models. Human access occurs only where necessary for support requested by the customer, for security, or where required by law.
Limited Use: Yachay Systems' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use and transfer of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Legal basis: Art. 6(1)(b) GDPR (provision of the contractually agreed dashboard features) and Art. 6(1)(a) GDPR (the OAuth consent given when connecting the account).
How we use, process and share YouTube data: We use the data received from YouTube API Services only to show the connected business its own channel, to upload the videos the business itself releases, and to show the business its own statistics. The data is processed and stored on our servers at Hetzner Online GmbH in Germany (see section 3). Internally, it is shown only to the business that connected the channel, in its own dashboard; our staff access it only for support the business requests, for security, or where required by law. Externally, we share it with no one: it is not sold, not passed to advertisers, not passed to OpenAI or any other AI provider, and not shown to any other customer. The only external party that receives data from us in this integration is Google itself, when we upload a video or request statistics on the business's behalf.
Revoking access and deleting stored YouTube data: The business can revoke our access at any time, either with "Disconnect" on the YouTube screen of the dashboard or on the Google security settings page at myaccount.google.com/connections. In both cases the stored data is deleted as described above. To have all stored YouTube data deleted, including the aggregated channel statistics, the business can email info@yachay.systems; we delete it within 30 days at the latest and confirm the deletion by email.
Google Data Segregation: Google user data obtained via Google APIs is processed solely by Google and OpenAI, in accordance with the Limited Use requirements of the Google API Services User Data Policy. Data received from YouTube API Services is not passed to OpenAI.
2.6 How We Protect Your Data
We protect personal data, and in particular sensitive data and data received from Google APIs, with the following technical and organisational measures:
- Encryption in transit: Every connection to our website, the Rikuna dashboard and our APIs runs over HTTPS (TLS). HSTS instructs browsers to connect to us only over encrypted connections.
- Encryption at rest: OAuth access and refresh tokens for Google (Calendar, Business Profile, YouTube) and all other connected accounts are stored with AES encryption. The encryption key is kept separately from the database.
- Passwords and sessions: Dashboard passwords are stored only as salted bcrypt hashes, never in plain text. Session cookies are marked HttpOnly and Secure. After five failed password attempts the account is temporarily locked.
- Access control: Every dashboard request is authenticated and limited to the business the login belongs to. A business never sees another business's data. Our staff access customer data only as described in section 2.5.
- Hosting in the EU: Our servers are operated by Hetzner Online GmbH in ISO/IEC 27001-certified data centres in Germany.
- Data minimisation: We request only the Google permissions a feature needs, store only the data that feature uses, and delete stored Google data when the account is disconnected (see section 2.5).
- Data breaches: If a personal data breach occurs, we notify the competent supervisory authority and the affected customers as required by Art. 33 and 34 GDPR.
3. Third-Party Providers and Processors
| Provider | Purpose | Location / Privacy |
|---|---|---|
| Stripe, Inc. | Payment processing | USA/EU · stripe.com/de/privacy |
| Hetzner Online GmbH | Server hosting and infrastructure | Germany · hetzner.com/legal/privacy-policy |
| OpenAI, LLC | AI language processing (agent responses), speech-to-text transcription of dictated notes, image check of prescription photos | USA · openai.com/policies/privacy-policy |
| Anthropic, PBC | AI language processing (agent responses) | USA · anthropic.com/policies/privacy |
| Google LLC | AI language processing (Gemini) | USA · policies.google.com/privacy |
| Meta Platforms Ireland Ltd. | WhatsApp Business API, Instagram Graph API, Facebook Messenger Platform (messaging channels) | Ireland · whatsapp.com/legal/privacy-policy |
| TikTok Technology Ltd. | TikTok Content Posting API (social publishing channel) | Ireland / Singapore · tiktok.com/legal/privacy-policy |
| Telegram Messenger Inc. | Telegram Bot API (messaging channel, optional) | UAE · telegram.org/privacy |
| Resend, Inc. | Transactional emails (confirmations, notifications) | USA · resend.com/legal/privacy-policy |
| BunnyWay d.o.o. | Font delivery (Bunny Fonts, privacy-friendly, no tracking) | EU (Slovenia) · bunny.net/privacy |
| ip-api.com | IP geolocation (country, city lookup for visit statistics) | Data queried in real-time, not stored by provider · ip-api.com/docs/legal |
For the transfer of personal data to third countries (USA, China), we rely on Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR and, where applicable, the EU-US Data Privacy Framework.
4. Retention Period
Personal data is only stored as long as necessary for the respective purpose:
- Usage analytics: 1 year (IP addresses automatically anonymized after 7 days)
- Onboarding data, contract documents: 10 years (statutory retention obligation under HGB/AO)
- Payment records: 10 years (tax law retention obligation)
- Conversation data (AI agents): Per customer (controller) instructions, typically until contract termination
- Treatment records, prescription data and prescription photos (physiotherapy): Per customer (controller) instructions; the customer is subject to a statutory retention period of 10 years (Section 630f German Civil Code) and receives this data in the export upon termination
- Email correspondence: 3 years after conclusion of the inquiry
5. Cookies
Our website does not use cookies. For language and theme preferences, we use localStorage, which is stored locally in your browser and is never transmitted to our servers. For usage analytics, we use sessionStorage (a temporary session identifier that is automatically deleted when the browser tab is closed). No analytics, advertising, or tracking cookies are used. Cookie consent is therefore not required.
Customer websites that we operate for our clients may additionally display a map from Google Maps. This map is only loaded after you give your consent via the cookie banner. When loaded, content is requested from Google and Google may set cookies or use local storage in your browser. You can withdraw your consent at any time via the "Cookie settings" button, which stops the map from loading. Legal basis: Art. 6(1)(a) GDPR (consent).
6. Your Rights (Art. 15–22 GDPR)
You have the right to:
- Access (Art. 15 GDPR) - What data we process about you
- Rectification (Art. 16 GDPR) - Correction of inaccurate data
- Erasure (Art. 17 GDPR) - "Right to be forgotten"
- Restriction (Art. 18 GDPR) - Restriction of processing
- Data portability (Art. 20 GDPR) - Provision of your data in a machine-readable format
- Objection (Art. 21 GDPR) - Against processing based on legitimate interests
- Withdrawal - Of given consents, without affecting the lawfulness of prior processing
Please direct inquiries to: info@yachay.systems
7. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority. In Germany, please contact the state authority responsible for your place of residence. A list of supervisory authorities can be found at the Federal Commissioner for Data Protection:
8. Changes to This Privacy Policy
We reserve the right to update this privacy policy when changes to our services or legal requirements occur. The current version is always available at yachay.systems/legal/privacy.html.
Datenschutzerklärung
Stand: September 2026
1. Verantwortlicher (Art. 13 Abs. 1 lit. a DSGVO)
KonzeptWeber LLC
30 N Gould St Ste N
Sheridan, WY 82801, USA
E-Mail: info@yachay.systems
Website: https://yachay.systems
App: Rikuna (rikuna.yachay.systems)
Für Anfragen zu Datenschutzthemen wenden Sie sich bitte an: info@yachay.systems
2. Erhobene Daten und Zwecke
2.1 Websitebesuch und Nutzungsanalyse
Beim Besuch unserer Website erheben wir folgende Daten zur Verbesserung unseres Angebots und zum Verständnis der Seitennutzung:
- IP-Adresse (automatisch anonymisiert nach 7 Tagen)
- Ungefährer Standort (Land, Stadt), abgeleitet aus der IP-Adresse über ip-api.com
- Browsertyp und -version (User-Agent)
- Referrer-URL (die Seite, von der Sie kamen)
- Besuchte Seiten, Seitentyp und zugehörige Branche
- Scrollverhalten (wie weit Sie auf der Seite gescrollt haben)
- Verweildauer auf jeder Seite (Sitzungsdauer)
- Klicks auf Call-to-Action-Schaltflächen
- UTM-Kampagnenparameter (falls in der URL vorhanden)
Diese Daten werden in unserer eigenen Datenbank auf europäischen Servern gespeichert. Wir verwenden keine Drittanbieter-Analysedienste (kein Google Analytics, kein Meta Pixel). Eine temporäre Sitzungskennung wird im sessionStorage Ihres Browsers gespeichert und automatisch gelöscht, wenn Sie den Browser-Tab schließen. Wir verwenden keine Cookies zur Nachverfolgung. Um wiederkehrende Besuche zu erkennen, bilden wir auf unserem Server einen pseudonymen Wert aus IP-Adresse und Browserkennung, gesichert mit einem geheimen Schlüssel, der unseren Server nicht verlässt. Ein Rückschluss auf Ihre IP-Adresse ist daraus nicht möglich. Der Wert wird nach 12 Monaten zusammen mit dem Besuchsdatensatz gelöscht. Wenn Ihr Browser ein Do-Not-Track-Signal (DNT) sendet, werden keine Analysedaten erhoben.
Rechtsgrundlage: Art. 6 Abs. 1 lit. f DSGVO (berechtigtes Interesse an der sicheren Bereitstellung und Verbesserung der Website)
2.2 Kontaktaufnahme und Onboarding
Wenn Sie unser Kontaktformular, das Onboarding-Formular oder die E-Mail-Adresse nutzen, verarbeiten wir:
- Name, Unternehmensname
- E-Mail-Adresse
- WhatsApp-Nummer (freiwillig)
- Angaben zu Ihrem Unternehmen (Öffnungszeiten, typische Anfragen etc.)
- Inhalt der Mitteilung
Rechtsgrundlage: Art. 6 Abs. 1 lit. b DSGVO (Vertragsanbahnung/-erfüllung) bzw. lit. f (berechtigtes Interesse an der Bearbeitung von Anfragen)
2.3 Zahlungsverarbeitung
Bei Käufen über unsere Website werden Zahlungsdaten (Name, E-Mail, Rechnungsadresse, Zahlungsmittelinformationen) von unserem Zahlungsanbieter Stripe verarbeitet. Wir erhalten von Stripe nur die für die Auftragsabwicklung notwendigen Informationen (E-Mail, Betrag, Paket). Vollständige Zahlungsdaten (z. B. Kartennummern) werden ausschließlich von Stripe gespeichert.
Rechtsgrundlage: Art. 6 Abs. 1 lit. b DSGVO (Vertragserfüllung)
2.4 KI-Agenten-Kommunikation
Im Rahmen des Betriebs von KI-Kommunikationsagenten für unsere Kunden (Unternehmen) werden Gesprächsdaten über folgende Kanäle verarbeitet:
- WhatsApp Business API - Nachrichten über die WhatsApp-Geschäftsnummer des Kunden
- Instagram Direct Messages - Nachrichten über das Instagram-Business-Konto des Kunden
- Facebook Messenger - Nachrichten über die Facebook-Seite des Kunden
- TikTok Content Posting API - Video- und Foto-Veröffentlichung aus dem Rikuna-Dashboard über das TikTok-Konto des Kunden (OAuth). Beitrags-Metadaten werden gespeichert; hochgeladene Medien werden auf europäischen Servern gehostet.
- Web-Chat-Widget - Chat-Funktion auf der Kunden-Website (kein Login erforderlich)
- Telegram Bot API - optional, auf Wunsch des Kunden
Dabei können folgende Datenkategorien verarbeitet werden:
- Name und Kontaktdaten der Endnutzer (Patienten, Kunden, Gäste)
- Inhalt der Nachrichten und Anfragen
- Terminwünsche, Buchungsinformationen
- Gesundheitsbezogene Angaben (z. B. Beschwerden, Rezeptinformationen) - nur bei medizinischen Verticals und nur soweit vom Endnutzer freiwillig mitgeteilt
- Verordnungsdaten (Diagnose bzw. ICD-10-Code, verordnetes Heilmittel, Anzahl und Frequenz der Behandlungen, Ausstellungsdatum) und ein Foto der Verordnung - nur bei Physiotherapie-Kunden, siehe 2.4.1
- Von den Behandlerinnen und Behandlern der Praxis diktierte Behandlungsdokumentation - nur bei Physiotherapie-Kunden, siehe 2.4.2
- Gesprächsmetadaten (Zeitstempel, Kanal, Gesprächs-ID)
Nachrichten werden serverseitig gespeichert, um dem Kunden (Unternehmen) die Einsicht in Gesprächsverläufe über sein Admin-Dashboard zu ermöglichen. Die Speicherung erfolgt auf europäischen Servern.
Yachay Systems verarbeitet diese Daten als Auftragsverarbeiter im Auftrag des jeweiligen Kunden (Unternehmen), der als Verantwortlicher fungiert. Die Verarbeitung erfolgt auf Basis eines Auftragsverarbeitungsvertrags (AVV) gemäß Art. 28 DSGVO.
Rechtsgrundlage: Art. 6 Abs. 1 lit. b DSGVO (Vertragsanbahnung/Terminkoordination) und Art. 6 Abs. 1 lit. f DSGVO (berechtigtes Interesse an der Bearbeitung von Kundenanfragen).
2.4.1 Verordnungsfotos (Physiotherapie)
Patientinnen und Patienten von Physiotherapie-Kunden können ein Foto ihrer Heilmittelverordnung per WhatsApp senden. Das Foto wird von einem KI-Bildmodell bei OpenAI daraufhin geprüft, ob es eine Verordnung zeigt und ob diese lesbar ist; das Modell gibt nur dieses Urteil zurück. Anschließend wird das Foto zusammen mit den von der Praxis erfassten Verordnungsdaten im Rikuna-Dashboard des Kunden auf europäischen Servern gespeichert, wo die Praxis es prüft. Fotos, die nicht als Verordnung erkannt werden, werden abgewiesen und nicht gespeichert. Die für die Prüfung angelegte temporäre Kopie wird unmittelbar danach gelöscht.
Verantwortlicher für diese Daten ist der Kunde (Praxis); er stellt die Rechtsgrundlage für die Verarbeitung von Gesundheitsdaten bereit (in der Regel Art. 9 Abs. 2 lit. h DSGVO). Patientinnen und Patienten können die Verordnung stattdessen persönlich vorlegen.
2.4.2 Sprachdokumentation (Physiotherapie)
Behandlerinnen und Behandler von Physiotherapie-Kunden können im Rikuna-Dashboard eine Behandlungsnotiz diktieren. Die Aufnahme wird ausschließlich zur Transkription (Sprache zu Text) an OpenAI übermittelt, unter API-Bedingungen, die eine Nutzung zum Modelltraining ausschließen, und wird von uns nicht gespeichert. Gespeichert werden auf europäischen Servern nur das Transkript, seine Dauer in Sekunden und ein von einem OpenAI-Sprachmodell erzeugter strukturierter Entwurf der Notiz (Beschwerde, Vorgeschichte, Befund, Ziel, Maßnahmen, nächster Schritt). Der Entwurf wird erst Teil der Behandlungsdokumentation, nachdem die Behandlerin oder der Behandler ihn geprüft und bestätigt hat.
Betroffene sind die Patientin oder der Patient (Inhalt der Notiz) und die Behandlerin oder der Behandler (Stimme, Urheberschaft). Verantwortlicher ist der Kunde (Praxis); er ist für die gesetzliche Aufbewahrung der Behandlungsdokumentation zuständig.
2.5 Google-Konto-Integration (Kalender, Unternehmensprofil & YouTube)
Sofern ein Kunde (Unternehmen) sein Google-Konto mit dem Rikuna-Dashboard verbindet, greifen wir über Google-APIs auf Google-Nutzerdaten zu, ausschließlich um die verbundenen Funktionen bereitzustellen. Diese Integration ist optional und wird nur durch die ausdrückliche OAuth-Einwilligung des Kunden aktiviert.
Abhängig von den erteilten Berechtigungen greifen wir auf folgende Daten zu:
- Google Kalender (Lesen) - Titel, Start-/Endzeiten, Beschreibungen und Status von Kalenderterminen, die gelesen werden, damit Termine synchron bleiben und Zeiten, in denen das Unternehmen bereits belegt ist, nie zur Buchung angeboten werden.
- Google Kalender (Eintragen von Buchungen) - für Termine, die über unser Produkt gebucht werden, legen wir den zugehörigen Eintrag im verbundenen Kalender des Unternehmens an, ändern und löschen ihn, bei Online-Terminen samt Google-Meet-Link. Trägt das Unternehmen die E-Mail-Adresse eines Kunden ein, wird der Kunde als Gast hinzugefügt, damit Google ihm die Einladung schickt. Einträge, die nicht von unserem Produkt stammen, werden nie verändert oder gelöscht; Kalender selbst legen wir weder an, noch löschen oder teilen wir sie.
- E-Mail-Adresse des Google-Kontos - zur Identifikation des verbundenen Kontos und Anzeige des Verbindungsstatus.
- Google Unternehmensprofil (sofern aktiviert) - Eintragsdaten wie Öffnungszeiten und Kundenbewertungen, um Bewertungen im Dashboard anzuzeigen, Antworten zu veröffentlichen und Öffnungszeiten im eigenen Eintrag des Unternehmens zu aktualisieren.
- YouTube-Kanal und -Videos (nur Lesezugriff) - Name und Kanalbild des Kanals, den das Unternehmen verbindet, damit im Dashboard sichtbar ist, welcher Kanal verbunden ist, sowie Titel und öffentliche Zähler (Aufrufe, Likes, Kommentare) der eigenen Videos dieses Kanals für dessen Statistik. Wir durchsuchen, bewerten, kommentieren, ändern und löschen nichts auf dem Kanal und greifen auf keinen anderen Kanal zu.
- YouTube-Video-Upload - Videos, die das Unternehmen im Dashboard zusammenstellt, werden auf den eigenen Kanal desselben Unternehmens hochgeladen, sofort oder zu einem selbst gewählten Zeitpunkt.
- YouTube-Statistiken (nur Lesezugriff) - Aufrufe, Wiedergabezeit, durchschnittliche Wiedergabedauer, Likes, Kommentare, geteilte Beiträge sowie gewonnene und verlorene Abonnenten des verbundenen Kanals, die dem Unternehmen auf seinem eigenen Statistik-Bildschirm angezeigt werden. Auf Umsatz- oder Monetarisierungsdaten greifen wir nicht zu.
Für unsere Nutzung der YouTube-API-Dienste gelten die YouTube-Nutzungsbedingungen und die Google-Datenschutzerklärung.
OAuth-Zugriffs- und Refresh-Token werden verschlüsselt auf europäischen Servern gespeichert und ausschließlich verwendet, um die Google-APIs im Auftrag des Kunden aufzurufen. Der Kunde kann den Zugriff jederzeit widerrufen, indem er die Verbindung im Dashboard trennt oder über seine Google-Kontoberechtigungen; der Widerruf löscht die gespeicherten Token und die aus Google importierten Daten. Für YouTube im Einzelnen: Das Trennen im Dashboard widerruft zusätzlich unseren Zugriff bei Google und löscht die Token sofort; ein im Google-Konto widerrufener Zugriff löscht sie beim nächsten Versuch, sie zu verwenden; Videotitel und Kennzahlen je Video werden innerhalb von 48 Stunden nach dem Trennen des Kanals gelöscht. Ein Videotitel, den wir 30 Tage lang nicht aktualisiert haben, wird auch bei weiter verbundenem Kanal gelöscht. Aggregierte Kanalkennzahlen, die während der Verbindung erhoben wurden, enthalten keine Daten einzelner Zuschauer und bleiben gespeichert.
Wir verwenden Google-Nutzerdaten nicht für Werbung, verkaufen sie nicht und nutzen sie nicht, um verallgemeinerte KI-/ML-Modelle zu trainieren. Ein Zugriff durch Menschen erfolgt nur, soweit für vom Kunden angeforderten Support, aus Sicherheitsgründen oder gesetzlich erforderlich.
Limited Use: Die Verwendung und Weitergabe der über Google-APIs erhaltenen Informationen durch Yachay Systems an andere Anwendungen entspricht der Google API Services User Data Policy, einschließlich der Limited-Use-Anforderungen. Die Verwendung und Weitergabe von rohen oder abgeleiteten Nutzerdaten, die über Google Workspace APIs empfangen werden, entspricht der Google API Services User Data Policy, einschließlich der Limited-Use-Anforderungen.
Rechtsgrundlage: Art. 6 Abs. 1 lit. b DSGVO (Bereitstellung der vertraglich vereinbarten Dashboard-Funktionen) und Art. 6 Abs. 1 lit. a DSGVO (die beim Verbinden des Kontos erteilte OAuth-Einwilligung).
Wie wir YouTube-Daten nutzen, verarbeiten und weitergeben: Wir nutzen die über die YouTube API Services erhaltenen Daten ausschließlich, um dem verbundenen Unternehmen seinen eigenen Kanal anzuzeigen, die Videos hochzuladen, die das Unternehmen selbst freigibt, und ihm seine eigenen Statistiken zu zeigen. Die Daten werden auf unseren Servern bei der Hetzner Online GmbH in Deutschland verarbeitet und gespeichert (siehe Abschnitt 3). Intern sieht sie nur das Unternehmen, das den Kanal verbunden hat, in seinem eigenen Dashboard; unsere Mitarbeitenden greifen nur darauf zu, soweit für vom Unternehmen angeforderten Support, aus Sicherheitsgründen oder gesetzlich erforderlich. Extern geben wir sie an niemanden weiter: Sie werden nicht verkauft, nicht an Werbetreibende, nicht an OpenAI oder einen anderen KI-Anbieter weitergegeben und keinem anderen Kunden angezeigt. Die einzige externe Stelle, die in dieser Integration Daten von uns erhält, ist Google selbst, wenn wir im Auftrag des Unternehmens ein Video hochladen oder Statistiken abrufen.
Zugriff widerrufen und gespeicherte YouTube-Daten löschen: Das Unternehmen kann unseren Zugriff jederzeit widerrufen, entweder über „Trennen“ im YouTube-Bereich des Dashboards oder auf der Google-Sicherheitsseite unter myaccount.google.com/connections. In beiden Fällen werden die gespeicherten Daten wie oben beschrieben gelöscht. Um alle gespeicherten YouTube-Daten einschließlich der aggregierten Kanalkennzahlen löschen zu lassen, genügt eine E-Mail an info@yachay.systems; wir löschen sie spätestens innerhalb von 30 Tagen und bestätigen die Löschung per E-Mail.
Datentrennung (Google-Daten): Über Google-APIs bezogene Google-Nutzerdaten werden ausschließlich von Google und OpenAI verarbeitet, im Einklang mit den Limited-Use-Anforderungen der Google API Services User Data Policy. Über die YouTube API Services erhaltene Daten werden nicht an OpenAI weitergegeben.
2.6 Wie wir Ihre Daten schützen
Wir schützen personenbezogene Daten, insbesondere sensible Daten und über Google-APIs erhaltene Daten, mit folgenden technischen und organisatorischen Maßnahmen:
- Verschlüsselung bei der Übertragung: Jede Verbindung zu unserer Website, zum Rikuna-Dashboard und zu unseren APIs läuft über HTTPS (TLS). Per HSTS weisen wir Browser an, sich nur verschlüsselt mit uns zu verbinden.
- Verschlüsselung bei der Speicherung: OAuth-Zugriffs- und Refresh-Token für Google (Kalender, Unternehmensprofil, YouTube) und alle anderen verbundenen Konten werden AES-verschlüsselt gespeichert. Der Schlüssel wird getrennt von der Datenbank aufbewahrt.
- Passwörter und Sitzungen: Dashboard-Passwörter speichern wir nur als gesalzene bcrypt-Hashes, nie im Klartext. Sitzungs-Cookies sind als HttpOnly und Secure gekennzeichnet. Nach fünf fehlgeschlagenen Anmeldeversuchen wird das Konto vorübergehend gesperrt.
- Zugriffskontrolle: Jede Anfrage an das Dashboard ist authentifiziert und auf das Unternehmen beschränkt, zu dem die Anmeldung gehört. Ein Unternehmen sieht nie die Daten eines anderen. Unsere Mitarbeitenden greifen nur wie in Abschnitt 2.5 beschrieben auf Kundendaten zu.
- Hosting in der EU: Unsere Server betreibt die Hetzner Online GmbH in nach ISO/IEC 27001 zertifizierten Rechenzentren in Deutschland.
- Datenminimierung: Wir fordern nur die Google-Berechtigungen an, die eine Funktion braucht, speichern nur die Daten, die sie nutzt, und löschen gespeicherte Google-Daten, wenn das Konto getrennt wird (siehe Abschnitt 2.5).
- Datenpannen: Kommt es zu einer Verletzung des Schutzes personenbezogener Daten, benachrichtigen wir die zuständige Aufsichtsbehörde und die betroffenen Kunden gemäß Art. 33 und 34 DSGVO.
3. Drittanbieter und Auftragsverarbeiter
| Anbieter | Zweck | Sitz / Datenschutz |
|---|---|---|
| Stripe, Inc. | Zahlungsabwicklung | USA/EU · stripe.com/de/privacy |
| Hetzner Online GmbH | Server-Hosting und Infrastruktur | Deutschland · hetzner.com/legal/privacy-policy |
| OpenAI, LLC | KI-Sprachverarbeitung (Agenten-Antworten), Transkription diktierter Notizen, Prüfung von Verordnungsfotos | USA · openai.com/policies/privacy-policy |
| Anthropic, PBC | KI-Sprachverarbeitung (Agenten-Antworten) | USA · anthropic.com/policies/privacy |
| Google LLC | KI-Sprachverarbeitung (Gemini) | USA · policies.google.com/privacy |
| Meta Platforms Ireland Ltd. | WhatsApp Business API, Instagram Graph API, Facebook Messenger Platform (Nachrichtenkanäle) | Irland · whatsapp.com/legal/privacy-policy |
| TikTok Technology Ltd. | TikTok Content Posting API (Social-Media-Veröffentlichungskanal) | Irland / Singapur · tiktok.com/legal/privacy-policy |
| Telegram Messenger Inc. | Telegram Bot API (Nachrichtenkanal, optional) | UAE · telegram.org/privacy |
| Resend, Inc. | Transaktions-E-Mails (Bestätigungen, Benachrichtigungen) | USA · resend.com/legal/privacy-policy |
| BunnyWay d.o.o. | Schriftarten-Auslieferung (Bunny Fonts, datenschutzfreundlich, kein Tracking) | EU (Slowenien) · bunny.net/privacy |
| ip-api.com | IP-Geolokalisierung (Land/Stadt-Abfrage für Besucherstatistiken) | Daten werden in Echtzeit abgefragt, nicht beim Anbieter gespeichert · ip-api.com/docs/legal |
Bei der Übermittlung personenbezogener Daten in Drittländer (USA, China) stützen wir uns auf Standardvertragsklauseln (SCCs) gemäß Art. 46 Abs. 2 lit. c DSGVO sowie ggf. auf das EU-US Data Privacy Framework.
4. Speicherdauer
Personenbezogene Daten werden nur so lange gespeichert, wie es für den jeweiligen Zweck erforderlich ist:
- Nutzungsanalyse: 1 Jahr (IP-Adressen werden nach 7 Tagen automatisch anonymisiert)
- Onboarding-Daten, Vertragsunterlagen: 10 Jahre (gesetzliche Aufbewahrungspflicht nach HGB/AO)
- Zahlungsbelege: 10 Jahre (steuerrechtliche Aufbewahrungspflicht)
- Gesprächsdaten (KI-Agenten): Gemäß Weisung des Kunden (Verantwortlicher), in der Regel bis zur Kündigung des Vertrags
- Behandlungsdokumentation, Verordnungsdaten und Verordnungsfotos (Physiotherapie): Gemäß Weisung des Kunden (Verantwortlicher); der Kunde unterliegt einer gesetzlichen Aufbewahrungsfrist von 10 Jahren (§ 630f BGB) und erhält diese Daten bei Vertragsende im Export
- E-Mail-Korrespondenz: 3 Jahre nach Abschluss der Anfrage
5. Cookies
Unsere Website verwendet keine Cookies. Für Sprach- und Theme-Einstellungen nutzen wir localStorage, das lokal in Ihrem Browser gespeichert wird und niemals an unsere Server übertragen wird. Für die Nutzungsanalyse verwenden wir sessionStorage (eine temporäre Sitzungskennung, die beim Schließen des Browser-Tabs automatisch gelöscht wird). Es werden keine Analyse-, Werbe- oder Tracking-Cookies eingesetzt. Eine Cookie-Einwilligung ist daher nicht erforderlich.
Kunden-Websites, die wir für unsere Auftraggeber betreiben, können zusätzlich eine Karte von Google Maps anzeigen. Diese Karte wird erst geladen, nachdem Sie über den Cookie-Banner Ihre Einwilligung erteilt haben. Beim Laden wird Inhalt von Google angefragt und Google kann Cookies setzen oder lokalen Speicher in Ihrem Browser nutzen. Sie können Ihre Einwilligung jederzeit über die Schaltfläche „Cookie-Einstellungen“ widerrufen; die Karte wird dann nicht mehr geladen. Rechtsgrundlage: Art. 6 Abs. 1 lit. a DSGVO (Einwilligung).
6. Ihre Rechte (Art. 15–22 DSGVO)
Sie haben das Recht auf:
- Auskunft (Art. 15 DSGVO) - Welche Daten wir über Sie verarbeiten
- Berichtigung (Art. 16 DSGVO) - Korrektur unrichtiger Daten
- Löschung (Art. 17 DSGVO) - „Recht auf Vergessenwerden"
- Einschränkung (Art. 18 DSGVO) - Einschränkung der Verarbeitung
- Datenübertragbarkeit (Art. 20 DSGVO) - Herausgabe Ihrer Daten in maschinenlesbarem Format
- Widerspruch (Art. 21 DSGVO) - Gegen die Verarbeitung auf Basis berechtigter Interessen
- Widerruf - Von erteilten Einwilligungen, ohne Auswirkung auf die bisherige Verarbeitung
Anfragen richten Sie bitte an: info@yachay.systems
7. Beschwerderecht bei der Aufsichtsbehörde
Sie haben das Recht, sich bei einer Datenschutzaufsichtsbehörde zu beschweren. In Deutschland wenden Sie sich an die für Ihren Wohnsitz zuständige Landesbehörde. Eine Liste der Aufsichtsbehörden finden Sie beim Bundesbeauftragten für den Datenschutz:
8. Änderungen dieser Datenschutzerklärung
Wir behalten uns vor, diese Datenschutzerklärung bei Änderungen unserer Dienste oder der rechtlichen Anforderungen anzupassen. Die jeweils aktuelle Version ist unter yachay.systems/legal/privacy.html abrufbar.
Política de Privacidad
Última actualización: septiembre de 2026
1. Responsable del tratamiento (Art. 13.1.a RGPD)
KonzeptWeber LLC
30 N Gould St Ste N
Sheridan, WY 82801, EE. UU.
Correo electrónico: info@yachay.systems
Sitio web: https://yachay.systems
Aplicación: Rikuna (rikuna.yachay.systems)
Para consultas sobre protección de datos, por favor contacte: info@yachay.systems
2. Datos recopilados y finalidades
2.1 Visita al sitio web y análisis de uso
Al visitar nuestro sitio web, recopilamos los siguientes datos para mejorar nuestro servicio y comprender cómo se utilizan nuestras páginas:
- Dirección IP (anonimizada automáticamente después de 7 días)
- Ubicación aproximada (país, ciudad) derivada de la dirección IP a través de ip-api.com
- Tipo y versión del navegador (User-Agent)
- URL de referencia (la página de la que vino)
- Páginas visitadas, tipo de página y vertical de industria asociada
- Comportamiento de desplazamiento (cuánto se desplazó en la página)
- Tiempo en cada página (duración de la sesión)
- Clics en botones de llamada a la acción
- Parámetros de campaña UTM (si están presentes en la URL)
Estos datos se almacenan en nuestra propia base de datos en servidores europeos. No utilizamos servicios de análisis de terceros (sin Google Analytics, sin Meta Pixel). Un identificador de sesión temporal se almacena en el sessionStorage de su navegador, que se elimina automáticamente al cerrar la pestaña del navegador. No utilizamos cookies de seguimiento. Para reconocer visitas recurrentes generamos en nuestro servidor un valor seudónimo a partir de su dirección IP y del identificador del navegador, protegido con una clave secreta que no sale de nuestro servidor. No permite deducir su dirección IP. El valor se elimina a los 12 meses junto con el registro de la visita. Si su navegador envía una señal Do-Not-Track (DNT), no se recopilan datos de análisis.
Base legal: Art. 6.1.f RGPD (interés legítimo en la provisión segura y mejora del sitio web)
2.2 Contacto e incorporación
Cuando utiliza nuestro formulario de contacto, formulario de incorporación o dirección de correo electrónico, procesamos:
- Nombre, nombre de la empresa
- Dirección de correo electrónico
- Número de WhatsApp (opcional)
- Información sobre su negocio (horarios de apertura, consultas típicas, etc.)
- Contenido del mensaje
Base legal: Art. 6.1.b RGPD (inicio/cumplimiento del contrato) o Art. 6.1.f (interés legítimo en el procesamiento de consultas)
2.3 Procesamiento de pagos
Para compras a través de nuestro sitio web, los datos de pago (nombre, correo electrónico, dirección de facturación, información del método de pago) son procesados por nuestro proveedor de pagos Stripe. Solo recibimos de Stripe la información necesaria para el procesamiento de pedidos (correo electrónico, importe, paquete). Los datos de pago completos (por ejemplo, números de tarjeta) son almacenados exclusivamente por Stripe.
Base legal: Art. 6.1.b RGPD (cumplimiento del contrato)
2.4 Comunicación con agentes de IA
En el marco de la operación de agentes de comunicación de IA para nuestros clientes (empresas), los datos de conversación se procesan a través de los siguientes canales:
- WhatsApp Business API - Mensajes a través del número comercial de WhatsApp del cliente
- Instagram Direct Messages - Mensajes a través de la cuenta de Instagram Business del cliente
- Facebook Messenger - Mensajes a través de la página de Facebook del cliente
- TikTok Content Posting API - Publicación de videos y fotos desde el panel de Rikuna a través de la cuenta de TikTok del cliente (OAuth). Los metadatos de las publicaciones se almacenan; los medios subidos se alojan en servidores europeos.
- Widget de chat web - Función de chat en el sitio web del cliente (sin necesidad de inicio de sesión)
- Telegram Bot API - opcional, a solicitud del cliente
Se pueden procesar las siguientes categorías de datos:
- Nombre y datos de contacto de los usuarios finales (pacientes, clientes, huéspedes)
- Contenido de mensajes y consultas
- Solicitudes de citas, información de reservas
- Información relacionada con la salud (por ejemplo, síntomas, información de recetas) - solo para verticales médicos y solo cuando el usuario final la proporciona voluntariamente
- Datos de la prescripción (diagnóstico o código CIE-10, tratamiento prescrito, número y frecuencia de sesiones, fecha de emisión) y una foto de la prescripción - solo clientes de fisioterapia, véase 2.4.1
- Documentación del tratamiento dictada por los profesionales de la consulta - solo clientes de fisioterapia, véase 2.4.2
- Metadatos de conversación (marcas de tiempo, canal, ID de conversación)
Los mensajes se almacenan en el servidor para permitir al cliente (empresa) ver los historiales de conversación a través de su panel de administración. Los datos se almacenan en servidores europeos.
Yachay Systems procesa estos datos como encargado del tratamiento en nombre del respectivo cliente (empresa), quien actúa como responsable del tratamiento. El procesamiento se basa en un Acuerdo de Procesamiento de Datos (APD) conforme al Art. 28 RGPD.
Base legal: Art. 6.1.b RGPD (inicio del contrato/coordinación de citas) y Art. 6.1.f RGPD (interés legítimo en el procesamiento de consultas de clientes).
2.4.1 Fotos de prescripciones (fisioterapia)
Los pacientes de clientes de fisioterapia pueden enviar por WhatsApp una foto de su prescripción médica. Un modelo de imagen de IA de OpenAI comprueba si la foto muestra una prescripción y si es legible; el modelo devuelve únicamente ese veredicto. A continuación, la foto se almacena junto con los datos de la prescripción registrados por la consulta en el panel de Rikuna del cliente, en servidores europeos, donde la consulta la revisa. Las fotos que no se reconocen como prescripción se rechazan y no se almacenan. La copia temporal utilizada para la comprobación se elimina inmediatamente después.
El cliente (consulta) es el responsable del tratamiento de estos datos y aporta la base legal para el tratamiento de datos de salud (normalmente Art. 9.2.h RGPD). Los pacientes pueden presentar la prescripción en persona en su lugar.
2.4.2 Documentación por voz (fisioterapia)
Los profesionales de clientes de fisioterapia pueden dictar una nota de tratamiento en el panel de Rikuna. La grabación se transmite a OpenAI exclusivamente para su transcripción (voz a texto), bajo condiciones de API que excluyen su uso para entrenar modelos, y no la almacenamos. Solo se almacenan en servidores europeos la transcripción, su duración en segundos y un borrador estructurado de la nota (motivo de consulta, antecedentes, hallazgos, objetivo, medidas, siguiente paso) generado por un modelo de lenguaje de OpenAI. El borrador pasa a formar parte del historial de tratamiento solo después de que el profesional lo haya revisado y confirmado.
Los interesados son el paciente (contenido de la nota) y el profesional (voz, autoría). El cliente (consulta) es el responsable del tratamiento y responde de la conservación legal de los historiales de tratamiento.
2.5 Integración con cuenta de Google (Calendario, Perfil de Empresa y YouTube)
Cuando un cliente (empresa) decide conectar su cuenta de Google con el panel de Rikuna, accedemos a los datos de usuario de Google a través de las APIs de Google estrictamente para proporcionar las funciones conectadas. Esta integración es opcional y solo se activa mediante el consentimiento OAuth explícito del cliente.
Según los permisos concedidos, accedemos a:
- Google Calendar (lectura) - títulos, horas de inicio/fin, descripciones y estado de los eventos del calendario, que se leen para mantener las citas sincronizadas y no ofrecer nunca un horario en el que el negocio ya está ocupado.
- Google Calendar (registro de reservas) - para las citas reservadas a través de nuestro producto, creamos, actualizamos y eliminamos el evento correspondiente en el calendario que el negocio conectó, con un enlace de Google Meet en las sesiones en línea. Si el negocio introduce el correo electrónico de un cliente, este se añade como invitado para que Google le envíe la invitación. Los eventos que no creó nuestro producto nunca se modifican ni se eliminan, y no creamos, eliminamos ni compartimos calendarios.
- Dirección de correo de la cuenta de Google - para identificar la cuenta conectada y mostrar el estado de la conexión.
- Perfil de Empresa de Google (cuando está habilitado) - información de la ficha como horarios de apertura y reseñas de clientes, para mostrar las reseñas en el panel, publicar respuestas y actualizar los horarios en la propia ficha de la empresa.
- Canal y vídeos de YouTube (solo lectura) - el nombre y la imagen del canal que la empresa conecta, para que el panel pueda mostrar qué canal está conectado, y los títulos y contadores públicos (visualizaciones, me gusta, comentarios) de los vídeos propios de ese canal para su pantalla de estadísticas. No buscamos, valoramos, comentamos, modificamos ni eliminamos nada en el canal, y no accedemos a ningún otro canal.
- Subida de vídeos a YouTube - los vídeos que la empresa compone en el panel se suben al canal propio de esa misma empresa, de inmediato o en el momento que ella programe.
- Estadísticas de YouTube (solo lectura) - visualizaciones, tiempo de reproducción, duración media de reproducción, me gusta, comentarios, veces compartido y suscriptores ganados o perdidos del canal conectado, mostrados a esa empresa en su propia pantalla de estadísticas. No accedemos a datos de ingresos ni de monetización.
Nuestro uso de los servicios de la API de YouTube está sujeto a los Términos de Servicio de YouTube y a la Política de Privacidad de Google.
Los tokens de acceso y de actualización OAuth se almacenan cifrados en servidores europeos y se utilizan únicamente para llamar a las APIs de Google en nombre del cliente. El cliente puede revocar el acceso en cualquier momento desconectando la integración en el panel o a través de los permisos de su cuenta de Google; la revocación elimina los tokens almacenados y los datos importados de Google. Para YouTube en detalle: desconectar en el panel revoca además nuestro acceso en Google y elimina los tokens de inmediato; un acceso revocado en la cuenta de Google los elimina la próxima vez que intentemos usarlos; los títulos de los vídeos y las cifras por vídeo se eliminan en un plazo de 48 horas tras desconectar el canal. Un título de vídeo que no hayamos actualizado en 30 días se elimina aunque el canal siga conectado. Las cifras agregadas del canal recopiladas mientras existía la conexión no contienen datos de espectadores individuales y se conservan.
No utilizamos los datos de usuario de Google con fines publicitarios, no los vendemos ni los usamos para entrenar modelos de IA/ML generalizados. El acceso humano solo se produce cuando es necesario para el soporte solicitado por el cliente, por motivos de seguridad o cuando lo exige la ley.
Limited Use: El uso y la transferencia por parte de Yachay Systems de la información recibida de las APIs de Google a cualquier otra aplicación se ajustará a la Google API Services User Data Policy, incluidos los requisitos de Limited Use. El uso y la transferencia de datos de usuario sin procesar o derivados recibidos de las APIs de Google Workspace se ajustará a la Google API Services User Data Policy, incluidos los requisitos de Limited Use.
Base legal: Art. 6.1.b RGPD (prestación de las funciones del panel acordadas contractualmente) y Art. 6.1.a RGPD (el consentimiento OAuth otorgado al conectar la cuenta).
Cómo usamos, tratamos y compartimos los datos de YouTube: Utilizamos los datos recibidos a través de los YouTube API Services únicamente para mostrar a la empresa conectada su propio canal, subir los vídeos que la propia empresa publica y mostrarle sus propias estadísticas. Los datos se tratan y almacenan en nuestros servidores de Hetzner Online GmbH en Alemania (véase la sección 3). Internamente, solo los ve la empresa que conectó el canal, en su propio panel; nuestro personal accede a ellos únicamente cuando es necesario para el soporte solicitado por la empresa, por motivos de seguridad o cuando lo exige la ley. Externamente no los compartimos con nadie: no se venden, no se ceden a anunciantes, no se ceden a OpenAI ni a ningún otro proveedor de IA y no se muestran a ningún otro cliente. La única parte externa que recibe datos nuestros en esta integración es la propia Google, cuando subimos un vídeo o solicitamos estadísticas en nombre de la empresa.
Revocar el acceso y eliminar los datos de YouTube almacenados: La empresa puede revocar nuestro acceso en cualquier momento, con «Desconectar» en la sección de YouTube del panel o en la página de seguridad de Google en myaccount.google.com/connections. En ambos casos los datos almacenados se eliminan como se describe arriba. Para que se eliminen todos los datos de YouTube almacenados, incluidas las cifras agregadas del canal, basta con un correo a info@yachay.systems; los eliminamos en un plazo máximo de 30 días y confirmamos la eliminación por correo.
Segregación de datos de Google: Los datos de usuario de Google obtenidos a través de las APIs de Google son procesados únicamente por Google y OpenAI, de conformidad con los requisitos de Uso Limitado de la Política de Datos de Usuario de los Servicios API de Google. Los datos recibidos a través de los YouTube API Services no se ceden a OpenAI.
2.6 Cómo protegemos sus datos
Protegemos los datos personales, en particular los datos sensibles y los datos recibidos a través de las APIs de Google, con las siguientes medidas técnicas y organizativas:
- Cifrado en tránsito: Toda conexión con nuestro sitio web, el panel de Rikuna y nuestras APIs se realiza por HTTPS (TLS). Mediante HSTS indicamos a los navegadores que se conecten con nosotros solo de forma cifrada.
- Cifrado en reposo: Los tokens de acceso y de actualización OAuth de Google (Calendar, Perfil de Empresa, YouTube) y de todas las demás cuentas conectadas se guardan cifrados con AES. La clave de cifrado se guarda separada de la base de datos.
- Contraseñas y sesiones: Las contraseñas del panel se guardan solo como hashes bcrypt con sal, nunca en texto plano. Las cookies de sesión están marcadas como HttpOnly y Secure. Tras cinco intentos fallidos de contraseña, la cuenta se bloquea temporalmente.
- Control de acceso: Cada solicitud al panel está autenticada y limitada a la empresa a la que pertenece el inicio de sesión. Una empresa nunca ve los datos de otra. Nuestro personal accede a los datos de clientes solo como se describe en la sección 2.5.
- Alojamiento en la UE: Nuestros servidores los opera Hetzner Online GmbH en centros de datos con certificación ISO/IEC 27001 en Alemania.
- Minimización de datos: Solicitamos solo los permisos de Google que una función necesita, guardamos solo los datos que esa función usa y eliminamos los datos de Google almacenados cuando se desconecta la cuenta (véase la sección 2.5).
- Violaciones de seguridad: Si se produce una violación de la seguridad de los datos personales, lo notificamos a la autoridad de control competente y a los clientes afectados según los art. 33 y 34 del RGPD.
3. Proveedores terceros y encargados del tratamiento
| Proveedor | Finalidad | Ubicación / Privacidad |
|---|---|---|
| Stripe, Inc. | Procesamiento de pagos | EE. UU./UE · stripe.com/de/privacy |
| Hetzner Online GmbH | Alojamiento de servidores e infraestructura | Alemania · hetzner.com/legal/privacy-policy |
| OpenAI, LLC | Procesamiento lingüístico de IA (respuestas de agentes), transcripción de notas dictadas, comprobación de fotos de prescripciones | EE. UU. · openai.com/policies/privacy-policy |
| Anthropic, PBC | Procesamiento de lenguaje IA (respuestas de agentes) | EE. UU. · anthropic.com/policies/privacy |
| Google LLC | Procesamiento de lenguaje IA (Gemini) | EE. UU. · policies.google.com/privacy |
| Meta Platforms Ireland Ltd. | WhatsApp Business API, Instagram Graph API, Facebook Messenger Platform (canales de mensajería) | Irlanda · whatsapp.com/legal/privacy-policy |
| TikTok Technology Ltd. | TikTok Content Posting API (canal de publicación en redes sociales) | Irlanda / Singapur · tiktok.com/legal/privacy-policy |
| Telegram Messenger Inc. | Telegram Bot API (canal de mensajería, opcional) | EAU · telegram.org/privacy |
| Resend, Inc. | Correos electrónicos transaccionales (confirmaciones, notificaciones) | EE. UU. · resend.com/legal/privacy-policy |
| BunnyWay d.o.o. | Entrega de fuentes (Bunny Fonts, respetuoso con la privacidad, sin rastreo) | UE (Eslovenia) · bunny.net/privacy |
| ip-api.com | Geolocalización IP (consulta de país/ciudad para estadísticas de visitas) | Datos consultados en tiempo real, no almacenados por el proveedor · ip-api.com/docs/legal |
Para la transferencia de datos personales a terceros países (EE. UU., China), nos basamos en las Cláusulas Contractuales Tipo (CCT) conforme al Art. 46.2.c RGPD y, cuando sea aplicable, en el Marco de Privacidad de Datos UE-EE. UU.
4. Período de conservación
Los datos personales solo se conservan durante el tiempo necesario para el respectivo fin:
- Análisis de uso: 1 año (direcciones IP anonimizadas automáticamente después de 7 días)
- Datos de incorporación, documentos contractuales: 10 años (obligación legal de conservación según HGB/AO)
- Comprobantes de pago: 10 años (obligación de conservación fiscal)
- Datos de conversación (agentes de IA): Según las instrucciones del cliente (responsable), generalmente hasta la terminación del contrato
- Historiales de tratamiento, datos y fotos de prescripciones (fisioterapia): Según las instrucciones del cliente (responsable); el cliente está sujeto a un plazo legal de conservación de 10 años (art. 630f del Código Civil alemán) y recibe estos datos en la exportación al finalizar el contrato
- Correspondencia por correo electrónico: 3 años después de la conclusión de la consulta
5. Cookies
Nuestro sitio web no utiliza cookies. Para las preferencias de idioma y tema, utilizamos localStorage, que se almacena localmente en su navegador y nunca se transmite a nuestros servidores. Para el análisis de uso, utilizamos sessionStorage (un identificador de sesión temporal que se elimina automáticamente al cerrar la pestaña del navegador). No se utilizan cookies de análisis, publicidad ni rastreo. Por lo tanto, no se requiere consentimiento de cookies.
Los sitios web que operamos para nuestros clientes pueden mostrar además un mapa de Google Maps. Este mapa solo se carga después de que dé su consentimiento mediante el banner de cookies. Al cargarlo, el contenido se solicita a Google y Google puede establecer cookies o usar almacenamiento local en su navegador. Puede retirar su consentimiento en cualquier momento mediante el botón „Ajustes de cookies“; la carga del mapa se detiene. Base legal: Art. 6.1.a RGPD (consentimiento).
6. Sus derechos (Art. 15–22 RGPD)
Usted tiene derecho a:
- Acceso (Art. 15 RGPD) - Qué datos procesamos sobre usted
- Rectificación (Art. 16 RGPD) - Corrección de datos inexactos
- Supresión (Art. 17 RGPD) - "Derecho al olvido"
- Limitación (Art. 18 RGPD) - Limitación del tratamiento
- Portabilidad de datos (Art. 20 RGPD) - Entrega de sus datos en formato legible por máquina
- Oposición (Art. 21 RGPD) - Contra el tratamiento basado en intereses legítimos
- Revocación - De consentimientos otorgados, sin afectar la licitud del tratamiento previo
Por favor, dirija sus consultas a: info@yachay.systems
7. Derecho a presentar una reclamación ante una autoridad de control
Usted tiene derecho a presentar una reclamación ante una autoridad de supervisión de protección de datos. En Alemania, contacte a la autoridad estatal responsable de su lugar de residencia. Puede encontrar una lista de autoridades de supervisión en el Comisionado Federal para la Protección de Datos:
8. Cambios en esta política de privacidad
Nos reservamos el derecho de actualizar esta política de privacidad cuando se produzcan cambios en nuestros servicios o requisitos legales. La versión actual siempre está disponible en yachay.systems/legal/privacy.html.