Privacy
1. Controller, version, and contact
The controller is Yair Vega García, self-employed, operating under the YATH.AI brand. This notice is version 2026-09-17, effective from 2026-09-17. For privacy matters write to hi@yath.ai. Address: Calle el Hoyo, 136, 35330 Teror, Las Palmas, Spain. The wording remains subject to final legal-adviser review.
2. Data processed
We may process: name, company, email, optional telephone, inquiry type and content, language, source URL, referrer, UTM parameters, date and time, technical submission identifier, privacy acceptance, marketing consent or rejection, and policy version. Source URL, referrer, UTM parameters, and date and time currently travel only in the email; their CRM persistence is pending schema approval. Rate limiting uses an HMAC; we do not retain the IP address in clear text. Telephone and WhatsApp are used only to answer the inquiry; this consent does not authorize campaigns by calls, SMS, or WhatsApp.
3. Purposes and legal bases
A) handle inquiries, prepare proposals, and take requested steps before a possible contract: pre-contractual measures; B) manage a contractual relationship if one arises: performance of the contract and legal obligations; C) protect security, prevent abuse, and maintain technical integrity: legitimate interest and service security; D) send commercial communications by email: optional, separate, revocable consent, with no automatic subscription when submitting an inquiry; E) conduct analytics and advertising: consent for the corresponding cookie category.
4. Retention
Inquiries with no subsequent relationship are kept for a maximum of 12 months from the last interaction. Proposals or contractual relationships are kept during the relationship and afterwards for the applicable legal periods. Marketing data are kept until consent is withdrawn or for a maximum of 24 months without significant interaction, whichever occurs first. YATH currently retains the available evidence of consent received. Commercial campaigns will not be sent until a direct unsubscribe mechanism is available. Before campaigns begin, withdrawals must be recorded and only the minimum evidence needed to demonstrate compliance and prevent further mailings may be retained. Rate-limit data are kept only for the configured technical window.
5. Recipients and providers
Hosting infrastructure, the authenticated email provider, essential technical providers, and private EspoCRM when enabled may be involved. Google and Meta may receive data only if their technologies are enabled and the user grants the corresponding category. Search Console verification by DNS, file, or meta tag is not a cookie and does not require consent. We do not sell personal data or claim unverified contracts or activations.
6. International transfers
YATH does not enable optional analytics or advertising tools without the corresponding consent. If Google or Meta services are enabled, those providers may process data outside the European Economic Area under their own terms and legal transfer mechanisms. Before enabling any provider involving an international transfer, YATH must verify and apply the required safeguards, such as an adequacy decision or Standard Contractual Clauses, and disclose them in this policy and the cookie preferences panel. When users voluntarily open external links such as WhatsApp, the external service processes data under its own privacy policy.
7. Rights and marketing withdrawal
You may exercise access, rectification, erasure, objection, restriction, and portability by writing to hi@yath.ai and verifying your identity where necessary. To withdraw from commercial communications, write to hi@yath.ai. Every future commercial email must include a direct, valid unsubscribe mechanism; until it exists, campaigns and commercial communications will not be sent and consent will only be stored correctly. Withdrawal does not affect your inquiry or cookies. You may also complain to the Spanish Data Protection Agency.