1. Controller and scope
The personal-data controller is ООО «Виксора». This policy covers the public site, inquiries, accounts, and Yasnora AI capabilities to the extent that each capability is actually enabled.
Use privacy@yasnora.ai for access, correction, deletion, objection, or consent-withdrawal requests.
2. Data categories
- account/profile details such as email, name, and settings;
- technical data such as IP address, device, browser, security logs, and session identifiers;
- prompts, chat history, outputs, projects, and workspace information;
- files, knowledge materials, metadata, and embeddings;
- voice, audio, and transcripts only when the feature is enabled;
- support records: name, email, product, category, impact, subject, messages, statuses, and handling history;
- sales, security, legal, and billing communications;
- payment metadata; full card details remain with the payment provider when payments are enabled;
- analytics data only after applicable consent and when a provider is configured.
3. Purposes
- create and protect accounts;
- provide features and retain user-selected context;
- process files, knowledge, and prompts;
- administer workspaces and access;
- provide support, security, abuse prevention, and incident investigation;
- perform contracts, payments, and mandatory recordkeeping;
- improve the public site using permitted anonymized or consented analytics.
4. Legal bases
The basis is determined per purpose: entering into or performing a contract, complying with law, a legitimate interest within applicable limits, or separate consent. Marketing consent and personal-data consent, when required, are separate and revocable.
The legal basis for a new or materially changed process is reviewed before processing starts.
5. AI and automated processing
Yasnora AI processes prompts and permitted context to generate an output. Model output may be inaccurate and must not be the sole basis for high-impact legal, medical, financial, or similar decisions.
Automated processing does not remove applicable rights to information, review, or challenge.
6. Providers and transfers
Infrastructure, email, payment, monitoring, or AI providers may be used only as actually configured. External AI receives content only when server-side and workspace policy permits that route.
Cross-border transfer is not assumed. Its status depends on provider, region, and deployment, and is published only after the processing register is verified.
7. Retention and deletion
Retention depends on data category, purpose, contract, user settings, and mandatory records. Deleted data is removed from active systems and later expires from backups according to their lifecycle.
Specific periods are not represented as guaranteed before the retention matrix is approved.
8. Individual rights
- request information and access;
- request correction, restriction, or deletion where applicable;
- withdraw consent;
- object to applicable processing;
- obtain an available export without exposing other workspace members’ data;
- complain to an authority or court.
9. Safeguards
Organizational and technical measures are applied proportionately, including access control, secret/session protection, encryption in transit, security logging, and deployment-specific backup controls where verified.
This high-level description is not a certification or independent attestation.
Document control
- Version
- 1.1
- Effective date
- 2026-08-26
- Internally approved by
- Уполномоченный представитель ООО «Виксора»
- Approval date
- 2026-08-23
- Next review
- 2027-08-23
- Contact
- privacy@yasnora.ai