---
title: 'Privacy Policy'
description: 'This policy describes what personal data the service operator processes, why it is needed, how it is protected, and what rights users have. It applies to all information that the operator receives about visitors and users of the website https://yoseno.com.'
type: legal
locale: en
canonical: 'https://yoseno.com/privacy'
---

# Privacy Policy

This policy describes what personal data the service operator processes, why it is needed, how it is protected, and what rights users have. It applies to all information that the operator receives about visitors and users of the website https://yoseno.com.

**Version :version:** 1.1

**Published :publishedAt:** 22 August 2026

## Who processes the data

The personal data operator is Yoseno (hereinafter, the operator). The operator provides a platform for organizational diagnostics: launching surveys, collecting responses, analyzing open-ended text, working with identified growth points, and re-checking changes.

Respect for user rights in data processing, including the protection of privacy, is a mandatory condition for the service's operation. For any questions about data processing, users can contact the operator via the contacts listed on the website. The operator's full details are provided at the end of this policy.

If an organization uses the service for its employees or respondents, it is solely responsible for the lawfulness of launching the survey, the composition of invited participants, and having the necessary grounds for processing their data.

## What data is processed

The composition of data depends on the scenario: registration, launching a survey, participating in a survey, analyzing results, payment, support, or requesting a demo. The operator may process the following categories of data:

- account data — last name, first name, patronymic, email address, phone number;
- organization data — name, roles, teams, invitations, access settings;
- survey content — answers to questions, open-ended comments, identified growth points, and recommendations;
- payment details — data about the plan, invoices, and payment status; payment instrument details are processed by payment providers and are not stored by the operator;
- technical data — IP address, browser and device information, cookies, action logs;
- requests — correspondence with support and data submitted through the demo request form.

The operator does not request more data than is necessary for diagnostics and the operation of the service and does not allow processed data to be excessive relative to the stated purposes.

## Why the data is used

The data is used to create an account and provide access to the service, grant access to an organization, run a survey, collect responses, show results by role, produce anonymized summaries, identify growth points, prepare recommendations, and respond to user requests.

Certain technical data is used to ensure service stability, protect against abuse, diagnose errors, keep action logs, perform the contract with the organization, and fulfill obligations under applicable personal data legislation.

## Legal grounds for processing

The operator processes data on one or more of the following grounds: the user's consent; performance of a contract to which the user is a party or beneficiary, or the conclusion of such a contract at the user's initiative; the legitimate interests of the operator or third parties, provided that this does not violate user rights; and compliance with obligations imposed on the operator by applicable law.

The user may withdraw consent to data processing or demand that processing cease at any time — the procedure is described in the rights section. After consent is withdrawn, the operator may continue processing only if another legal ground exists.

## Processing principles

Processing is carried out on a lawful and fair basis and is limited to achieving specific, predetermined purposes. Only data that serves these purposes is processed; combining databases processed for incompatible purposes is not allowed.

The operator keeps data accurate and up to date: incomplete or inaccurate data is clarified or deleted. Data is stored in a form that allows the user to be identified for no longer than the purposes of processing require, after which it is destroyed or anonymized.

## Responses, anonymity, and summaries

A core strength of the service is controlled anonymization. The manager works with processed summaries and identified growth points, not with raw response text as ordinary management material.

The anonymity mode is selected when a survey is launched. Sensitive breakdowns are disclosed only when there are enough responses; if the sample is too small, the service limits visibility to avoid creating a false sense of security.

The operator does not publicly disclose the user's diagnostic results, or the results of the organization or brand the user represents, without their consent.

Absolute anonymity is impossible when the context of the response itself reveals the respondent. The service therefore reduces the risk of deanonymization through technical and product rules, and organizations must run surveys with clear context and an appropriate audience.

## AI analysis and service providers

AI helps parse open-ended responses, group topics, and prepare summaries and recommendation options. It does not make management decisions and does not replace the responsibility of a manager or organization.

External service providers may be engaged to operate infrastructure, deliver emails, process payments, and process text. They receive only the data necessary to provide the specific service, on the basis of contracts or agreements concluded with them.

Information collected by third-party services — including payment systems and communication tools — is stored and processed by them in accordance with their own user agreements and privacy policies.

## Data transfer to third parties

Personal data is not transferred to third parties, except in three cases: when transfer is required by applicable law; when the user has consented to the transfer; or when transfer is necessary for a service provider to fulfill its obligations under a contract, as described above.

If operating the service requires transferring data to the territory of another country, the operator performs the procedures required by applicable law for such a transfer, including necessary notifications and verification of data protection conditions on the receiving side.

The operator and any other persons who have obtained access to personal data must not disclose them to third parties or distribute them without the user's consent, unless otherwise provided by applicable law.

## Storage and security

Data security is ensured through legal, organizational, and technical measures: role-based access, visibility minimization, technical logs, anonymity settings, and restrictions on displaying sensitive breakdowns.

These measures protect data from unauthorized or accidental access, destruction, modification, blocking, copying, provision, and dissemination. The approach to the visibility matrix, storage, and service providers is described in more detail in the Trust Center.

## Retention periods, export, and deletion

After 24 months without human use of an organization and without an active subscription, the owner and all administrators receive a warning. After a further 30 days, the organization's data is permanently deleted. Deletion is canceled if someone uses the organization again or a subscription becomes active.

Technical logs are kept for 90 days. A minimal payment trace and demo requests are kept for 24 months. Account data and consents are retained until the account is deleted; shorter retention periods continue to apply to temporary authentication and queue data.

## User rights and request procedure

The user has the right to receive information about the processing of their personal data; to request rectification, blocking, or destruction of the data if it is incomplete, outdated, inaccurate, obtained unlawfully, or no longer necessary for the stated purpose; to withdraw consent to processing; to demand that processing be stopped; and to appeal the operator's actions or inaction to the competent authority for the protection of personal data subjects' rights or to a court.

Users can export a copy of their personal data and delete their account independently at any time on the /account page. All other requests are sent to the operator via the contacts listed on the website: for data rectification — with the note “Updating Personal Data”; for consent withdrawal — with the note “Withdrawal of Consent to the Processing of Personal Data”. Responses are provided within the timeframes established by applicable law.

If a request concerns data within an organization, the service may forward it to that organization's administrator or process it together with the administrator. Users, in turn, must provide accurate data about themselves and report any changes; the person who provides inaccurate information or another person's data without that person's consent bears responsibility for the transfer.

## Cookies

The website uses cookies and similar technologies: they are needed for session management, request forgery protection, saving preferences, and, if enabled in a particular instance, for analytics. The terms and processing procedures are described in a separate cookie policy — a link is provided in the related sections below.

## Policy changes

All changes to the policy are reflected in this document. The policy is effective indefinitely until replaced by a new version; the current version is always available at https://yoseno.com/privacy.

## Related sections

- [Terms of Use](https://yoseno.com/terms.md) — rules for using the service
- [Refund Policy](https://yoseno.com/refund.md) — who the seller is, how refunds work, and what happens to credits
- [Trust Center](https://yoseno.com/security.md) — how anonymity, roles, and data visibility work
