Yetify

Privacy Policy


Yetify — GDPR / UK GDPR / Swiss FADP / CCPA-CPRA

Effective date: 4 September 2026
Hypnotic Digital Agency, Lda


1. Who We Are and Scope of This Policy

This Privacy Policy explains how Hypnotic Digital Agency, Lda ("Yetify", "we", "us", "our"), a company established in Portugal, collects, uses, shares, and protects personal data in connection with the Yetify website (yetify.ai) and the Yetify AI-visibility platform ("Service").

We are the data controller (or, under U.S. state privacy laws, the "business") responsible for the personal data described in this Policy, except where we act as a processor on behalf of a Customer in respect of Customer Content submitted to the Service — in that case, the Customer is the controller and our processing is governed by our Data Processing Addendum ("DPA"), available on request.

Because our customers and their audiences are global, this Policy is designed to address our obligations under: the EU General Data Protection Regulation ("EU GDPR"); the UK General Data Protection Regulation ("UK GDPR"); the Swiss Federal Act on Data Protection ("FADP"); the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"); and other comprehensive U.S. state privacy laws currently in force. This Policy applies to our website, the Service, and our sales and marketing activities; it does not cover third-party websites, AI platforms, or services we link to or interoperate with, whose own privacy practices govern their handling of data.

2. Personal Data We Collect

2.1 Data you provide to us

  • Account data: name, business email address, password (stored hashed), company name, and job title.
  • Billing data: billing address and payment details, which are processed by our third-party payment processor; we do not store full card numbers ourselves.
  • Communications: information you provide when you contact support, request a demo, or otherwise correspond with us.
  • Brand and monitoring inputs: the brand names, domains, competitor names, and keywords you configure the Service to track.

2.2 Data collected automatically

  • Usage data: pages viewed, features used, dashboard interactions, and timestamps.
  • Device and log data: IP address, browser type, device identifiers, and operating system.
  • Cookies and similar technologies: as described in Section 10.

2.3 AI visibility and monitoring data

To provide the Service, Yetify queries third-party AI assistants and search engines — currently OpenAI’s ChatGPT, Google’s Gemini and AI Overview, and Anthropic’s Claude — with prompts related to the brands, competitors, and keywords you configure, and analyzes the resulting outputs together with publicly available web and SEO data. This monitoring is generally directed at brand and market information rather than data about identifiable individuals. Where AI outputs or public sources happen to incidentally include the name or other identifier of an individual (for example, a published author or company representative), we apply data-minimization controls and do not seek to build profiles of such individuals; we handle any such incidental data under the principles set out in this Policy, and you may object to this processing at any time by contacting us using the details in Section 17.

2.4 Website and Competitor Page Data

To generate SEO and AI-visibility audits, we crawl and analyze the pages of your website and, where relevant to benchmarking, publicly available pages of your competitors, together with page-performance and SEO data from our data providers. This data is about web pages, not individuals, though it may incidentally include publicly published names (for example, an author byline).

3. How We Use Personal Data

  • To provide, operate, and maintain the Service, including generating your visibility reports and dashboards;
  • To create and manage your account and process payments;
  • To communicate with you about your account, updates, and support requests;
  • To send product and marketing communications, where you have consented or as otherwise permitted by law (you can opt out at any time);
  • To monitor, secure, and improve the Service, including diagnosing technical issues and preventing fraud or abuse;
  • To comply with legal obligations and enforce our Terms and Conditions.

4. Legal Bases for Processing (EU/UK GDPR)

  • Performance of a contract — to provide the Service you have subscribed to (Art. 6(1)(b) GDPR / UK GDPR).
  • Legitimate interests — to secure and improve the Service, prevent fraud, carry out direct marketing to existing business customers, and process incidental public-data mentions of individuals in a proportionate, minimized way (Art. 6(1)(f) GDPR / UK GDPR).
  • Consent — for optional cookies, and for marketing communications where consent is required by law (Art. 6(1)(a) GDPR / UK GDPR).
  • Legal obligation — where processing is necessary to comply with applicable law, such as tax and accounting records (Art. 6(1)(c) GDPR / UK GDPR).

Under the Swiss FADP, which does not use the same "legal basis" concept as the GDPR, we process personal data in a manner that is lawful, proportionate, and consistent with the purposes described in this Policy, and in compliance with data subjects’ rights under the FADP.

5. AI / Machine-Learning Model Training

We do not use Customer Content to train general-purpose third-party AI or machine-learning models. Where an AI provider we use to deliver the Service would otherwise use submitted data to train its own models, we require, to the extent commercially available, that such providers not use Customer Content for that purpose. If this practice changes for a given feature, we will update this Policy and, where required by law, request your consent or provide an opt-out before doing so.

6. How We Share Personal Data

We do not sell personal data, and we do not share personal data for cross-context behavioral advertising. We share personal data only in the following circumstances:

  • Sub-processors: the hosting, infrastructure, AI, and business-tool providers listed in Section 6.1, each acting under a data-processing agreement and only to the extent needed to provide their service to us.
  • Third-party AI providers as independent platforms: where you interact directly with a third-party AI assistant or search engine outside the Service, that platform acts as an independent controller of its own service, governed by its own privacy policy.
  • Legal and safety reasons: where required to comply with law, respond to lawful requests from public authorities, or protect the rights, property, or safety of Yetify, our users, or others.
  • Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality safeguards and notice to you of any change in controllership.

6.1 Our Sub-processors

We send each sub-processor only the data necessary for the purpose listed below — for example, the AI providers receive the brand, competitor, and keyword prompts needed to run your monitoring, not your account or billing data. This list may change as our infrastructure evolves; a current version is always available on request.


Sub-processor

Purpose

Firebase (Google)

User authentication

Vercel

Application hosting

Neon (Neon.tech))

Primary database hosting

Sanity

Website and content management

Resend

Transactional email delivery (e.g., account and notification emails)

Trigger.dev

Background jobs and scheduled tasks (e.g., running recurring AI-visibility checks)

Sentry

Error monitoring and application logs

Stripe

Payment processing

Firecrawl

Crawling your website and, for benchmarking, publicly available competitor pages

DataForSEO

SEO and AI Overview data used in page audits

Google PageSpeed Insights (Lighthouse)

Page-performance checks

Google Calendar

Scheduling demo calls

Google Looker Studio (Data Studio) API

Connecting and displaying reporting data

OpenAI ( ChatGPT)

Running brand/competitor/keyword prompts for AI-visibility monitoring

Google ( Gemini, AI overview)

Running brand/competitor/keyword prompts for AI-visibility monitoring

Anthropic ( Claude

Running brand/competitor/keyword prompts for AI-visibility monitoring


Most of these providers are headquartered outside the European Economic Area, primarily in the United States; see Section 7 for the safeguards that apply to those transfers.

7. International Data Transfers

We transfer personal data internationally to operate the Service. We rely on the following mechanisms, as applicable to the destination:

  • EU/EEA transfers: the European Commission���s Standard Contractual Clauses ("SCCs"), adequacy decisions, or equivalent safeguards, supplemented by the technical, contractual, and organizational measures described in our DPA.
  • UK transfers: the UK International Data Transfer Addendum to the EU SCCs, issued by the UK Information Commissioner’s Office, or a UK adequacy regulation where applicable.
  • Swiss transfers: the EU SCCs with the Swiss-specific amendments recognized by the Swiss Federal Data Protection and Information Commissioner ("FDPIC"), or a Swiss adequacy finding where applicable.
  • U.S. and other destinations: Standard Contractual Clauses, the EU-U.S. Data Privacy Framework (where a provider is certified), or other legally recognized transfer mechanisms.

Details of the transfer mechanism in place for a given sub-processor are available on request using the contact details in Section 17.

8. Data Retention

We retain personal data only for as long as necessary for the purposes described in this Policy, and to meet our legal, tax, and accounting obligations. Retention periods:

  • Account and contact data: for the duration of your subscription or account, plus 90 days after closure, to allow reactivation and to resolve any outstanding billing or support matters.
  • Billing and financial records: 10 years from the end of the financial year to which they relate, as required by Portuguese commercial and tax law.
  • Platform usage and log data (technical/security logs): 12 months, then deleted or aggregated.
  • AI visibility and monitoring data (Section 2.3) — your reports, scores, and historical trend data: retained for the duration of your active subscription, since historical trends are part of the Service’s core value, then deleted 90 days after your subscription ends unless you export it beforehand.
  • Marketing records: 3 years from your last interaction with us (for example, an email open, click, or reply), or until you unsubscribe, whichever is sooner.
  • Support and correspondence records: 3 years from the date the matter is resolved.
  • Cookies: up to 13 months from the date of consent, in line with EU regulatory guidance; see our Cookie Policy / cookie banner for the duration of each specific cookie.

When personal data is no longer needed, we delete or anonymize it in accordance with these periods. Where you close your account, you may request earlier deletion at any time, subject to any legal obligation we have to retain specific records (for example, billing records).

9. No Sale or Sharing of Personal Information

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, in each case as those terms are defined under the CCPA and analogous U.S. state privacy laws. We have not done so in the preceding twelve (12) months. We honor the Global Privacy Control ("GPC") signal, where technically detected, as a request to opt out of any sale or sharing, even though we do not engage in either.

10. Cookies and Similar Technologies

We use cookies and similar technologies on yetify.ai and within the Service to:

  • Enable core site and product functionality (strictly necessary cookies);
  • Remember preferences and settings (functional cookies);
  • Understand how visitors use our website and Service (analytics cookies);
  • Where applicable, measure the effectiveness of our marketing (marketing cookies).

Where required by law, we ask for your consent to non-essential cookies through a cookie banner or preference center, and you can withdraw consent or manage preferences at any time through your browser settings or our cookie preference tool.

11. Data Security

We implement technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction, including encryption in transit, access controls, and regular security reviews. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal data breach affecting your personal data, we will notify you without undue delay and, where required by law, notify the competent supervisory authority.

12. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal or similarly significant effects on individuals. The Service’s scores, rankings, and recommendations are analytical outputs provided to you, the business customer, for your own review and decision-making — they are not automated decisions made about any individual.

13. Your Rights — EU, UK, and Swiss Residents

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the right to:

  • Access the personal data we hold about you;
  • Request rectification of inaccurate or incomplete data;
  • Request erasure of your personal data, subject to legal exceptions;
  • Request restriction of, or object to, certain processing, including processing based on legitimate interests;
  • Request portability of data you provided to us in a structured, machine-readable format;
  • Withdraw consent at any time, where processing is based on consent, without affecting prior processing;
  • Lodge a complaint with your local data protection supervisory authority.

Our lead supervisory authority, as a company established in Portugal, is the Comissão Nacional de Proteção de Dados ("CNPD"). UK residents may also contact the Information Commissioner’s Office ("ICO"); Swiss residents may also contact the Federal Data Protection and Information Commissioner ("FDPIC"). We would welcome the opportunity to resolve any concern directly — please contact us first using the details in Section 17.

Because we are established in the EU, we are not required to appoint an EU Article 27 representative. We do not currently have customers or users in the United Kingdom or Switzerland, so no processing of UK or Swiss residents’ personal data takes place at this time, and the representative requirements under UK GDPR Article 27 and the equivalent Swiss FADP provisions do not apply to us. This does not affect your rights: should we begin processing UK or Swiss residents’ data, you would still be able to exercise the rights described above and lodge a complaint with the ICO or FDPIC respectively, by contacting us directly using the details in Section 17. We will reassess and, if required at that point, appoint a representative in the relevant territory and update this Policy.

14. Your Rights — California Residents (CCPA/CPRA)

Under the California Consumer Privacy Act, as amended by the CPRA, California residents have the right to:

  • Know the categories and specific pieces of personal information we have collected, the sources, the business or commercial purposes for which we use it, and the categories of third parties with whom we share it;
  • Delete personal information we have collected, subject to limited exceptions;
  • Correct inaccurate personal information;
  • Opt out of the sale or sharing of personal information — we do not sell or share personal information, but you may submit such a request and we will honor it;
  • Limit the use and disclosure of sensitive personal information — we do not collect sensitive personal information as defined by the CCPA (see the table below);
  • Non-discrimination — we will not deny goods or services, charge different prices, or provide a different level or quality of service because you exercised a right under the CCPA.

Categories of personal information we have collected, sold, shared, or disclosed in the preceding twelve (12) months, per the CCPA categories (Cal. Civ. Code Section 1798.140):

CCPA Category

Collected

Sold

Shared (ad)

Disclosed (business purpose)

Identifiers (name, email, IP address)

Yes

No

No

Yes — to sub-processors

Customer records (Cal. Civ. Code § 1798.80(e))

Yes

No

No

Yes — to sub-processors

Commercial information (subscription, transactions)

Yes

No

No

Yes — to sub-processors

Internet/network activity (usage logs)

Yes

No

No

Yes — to sub-processors

Geolocation (general, IP-based)

Yes

No

No

Yes — to sub-processors

Professional/employment information

Yes

No

No

Yes — to sub-processors

Inferences drawn from the above

Limited

No

No

Yes — to sub-processors

Sensitive personal information

No

No

No

No

Retention for each category is described in Section 8. To exercise your CCPA rights, contact us using the details in Section 17 with the subject line "CALIFORNIA PRIVACY REQUEST." You may use an authorized agent to submit a request on your behalf, in which case we will require written proof of authorization. We may need to verify your identity before responding, and we will respond within 45 days (with one 45-day extension where reasonably necessary).

"Shine the Light" (Cal. Civ. Code § 1798.83) entitles California residents to request information about our disclosure of personal information to third parties for their own direct marketing purposes. We do not disclose personal information to third parties for their own direct marketing.

15. Your Rights — Other U.S. State Residents

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Tennessee, Indiana, Florida, Delaware, New Jersey, New Hampshire, Minnesota, Maryland, Kentucky, Rhode Island, and other states with comprehensive privacy laws in force have rights similar to those of California residents. These typically include the right to:

  • Confirm whether we process personal data about you and access that data;
  • Correct inaccurate personal data;
  • Delete personal data;
  • Obtain a portable copy of personal data;
  • Opt out of targeted advertising, the sale of personal data, and certain profiling that produces legal or similarly significant effects — we do not engage in any of these activities;
  • Appeal a denial of any of the above rights.

To exercise your rights, contact us using the details in Section 17. If we deny your request, you may appeal by replying to our response, and if your appeal is denied, you may contact your state attorney general.

16. Children’s Privacy

The Service is intended for business use and is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you are a parent or guardian and believe a child has provided us with personal data, please contact us so we can delete it.

17. Contact Us

For any questions about this Privacy Policy or to exercise your data protection rights, contact:

Hypnotic Digital Agency, Lda

info@yetify.ai

18. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. Material changes will be notified through the Service or by email, and the "Effective date" at the top of this document will be updated accordingly.

Join the Early Bird List

Early access spots are limited. Submit your email for a chance to be selected for our beta and get 3 months free on the Starter plan.