Privacy Policy

As of: May 2026 · info@yondo.at

The protection of your personal data is of particular concern to us. We therefore process your data exclusively on the basis of the statutory provisions (GDPR, TKG 2021). In this privacy notice, we inform you about the most important aspects of data processing in connection with our website and our SaaS service.

1. Controller

The controller for data processing on this website is:

Yondo IT Solutions e.U.
Inhaber: Serhii Kravchenko
Hervicusgasse 4/1/6, 1120 Wien, Österreich
E-Mail: info@yondo.at
Telefon: +43 650 690 66 42

2. Data Collection on Our Website & Cookies

Server Log Files (Hosting)

We host our website with Hetzner Online GmbH (Germany). When you visit our website, your IP address, start and end of the session, browser type and operating system are automatically recorded. This is necessary for technical reasons (ensuring error-free operation and defending against hacking attacks) and constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR. These log data are automatically deleted after at most 7 days, unless there is a legal obligation for further storage. A data processing agreement (DPA) has been concluded with the hosting provider.

Cookies

Our website uses so-called cookies. These are small text files stored on your device by the browser. They cause no harm.

  • Technically necessary cookies: We use cookies for technical reasons to offer our information service in a functional manner. For functionally required cookies, we base our legal basis on our legitimate interest (Art. 6(1)(f) GDPR in conjunction with § 165(3) TKG 2021) to design the web presence securely and in a user-friendly manner.
  • Consent-based cookies (analytics & marketing): For cookies that are not functionally required (e.g. for web analysis or personalised advertising by third-party providers), we request your explicit consent via our cookie banner (Art. 6(1)(a) GDPR in conjunction with § 165(3) TKG 2021). Only if this is actively given will your data be processed. You can withdraw your consent at any time via "Privacy Preferences" in the footer of our website.

3. Data Processing in Our SaaS Service ("Yondo")

Our core product is a digital AI assistant for businesses (B2B). Depending on the role, we process data for different purposes and on different legal bases:

A. You as Our Contractual Partner (B2B Customer)

  • Purpose & data categories: When you register for the trial period or conclude a subscription, we process your master data (name, company, address, email, phone number) as well as payment data for contract processing and invoicing. We also use your email address to send technical information (e.g. expiry of the trial period) as well as information about our own similar services and pricing (direct marketing to existing customers).
  • Legal basis: Processing is necessary for the performance of the contract (Art. 6(1)(b) GDPR) and for compliance with legal obligations (Art. 6(1)(c) GDPR). The sending of direct marketing to existing users of our services (including users of the trial period) is carried out on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in conjunction with § 174(4) TKG 2021. You can object to this advertising use at any time free of charge (e.g. via the unsubscribe link in every email).
  • Recipients & bot management (WhatsApp): Payment data is transmitted in encrypted form to Stripe (Stripe Technology Europe, Limited, Ireland). Invoice data is shared with our tax adviser. As our AI assistant also allows management via WhatsApp (e.g. receiving daily summaries, entering commands), when using this feature your phone number and the control content you enter will be transmitted to Meta Platforms Ireland Limited.
  • Retention period: Data is deleted if a purchase process is abandoned. In the event of a contract being concluded, invoice and contract data are stored until expiry of the statutory tax retention period in Austria (7 years). Your email address for direct marketing purposes is stored only until you object to its use (unsubscribe).
  • Telemetry and system optimisation: For error analysis, to ensure system security (protection against hacking and spam attacks) and for continuous improvement of our AI models and general service quality, we process technical log data, metadata and aggregated usage statistics. These data are anonymised as quickly as possible. Processing is carried out on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in providing a secure and error-free SaaS service. A link to individual end customers is excluded through anonymisation.

B. We as Your Data Processor (for Calls from Your End Customers)

  • Purpose & role: When end customers call the phone number assigned to you, we act as a technological service provider and strictly instruction-bound data processor (pursuant to Art. 28 GDPR) for you. You (the business owner) remain the controller for your callers' data.
  • Communications secrecy: The secure handling of communications data and maintaining communications secrecy (pursuant to TKG 2021) is a central concern of our architecture. Connection data (routing) is processed only to the extent technically strictly necessary.
  • Recipients (categories of sub-processors): To technically realise the telephone service, our system uses strictly vetted sub-processors in real time, with whom data processing agreements (DPAs) exist. These include telecommunications providers and cloud services for speech recognition that operate their servers exclusively within the EU. For semantic understanding, we use Microsoft Azure OpenAI (Microsoft Ireland Operations Limited). The data is processed in the protected enterprise environment in Europe and is NOT used by Microsoft for training AI models. For the final entry of appointments, the necessary data (e.g. name, phone number of the caller) is transmitted via an API interface to the calendar system connected by you (typically Google Calendar, Google Ireland Limited).
  • Retention period: Transcriptions and call metadata are stored in our database (hosted at Hetzner) only for as long as necessary for transmission to the customer calendar and are then automatically deleted in accordance with the deadlines defined in the data processing agreement (DPA), at the latest after 30 days.

4. Data Processing, European Hosting and Third Country Transfers

The processing of audio data and transcripts takes place exclusively on servers within the European Union (EU) (e.g. at Hetzner Online GmbH in Germany).

For semantic language understanding, we use Microsoft Azure OpenAI (Microsoft Ireland Operations Limited) in the Sweden (EU) region. Processing takes place exclusively in this EU region; the transmitted data is contractually not used by Microsoft for training public AI models (Azure OpenAI Enterprise terms). Possible jurisdictional accessibility by US authorities under the US CLOUD Act is addressed by the EU-US Data Privacy Framework (DPF), which Microsoft has joined.

Only when using other services such as marketing cookies on the website, payment processes via Stripe, or API interfaces to Google Calendar and WhatsApp/Meta, may corresponding text or metadata be transmitted to these US service providers certified under the EU-US Data Privacy Framework.

5. Your Rights (Data Subject Rights)

With regard to your data processed by us, you generally have the rights to access, rectification, erasure, restriction, data portability, withdrawal and objection. We respond to your requests as a rule immediately, but at the latest within one month (pursuant to Art. 12(3) GDPR).

If you withdraw consent that has been given, the lawfulness of the data processing up to the point of withdrawal is not affected. The provision of data in the context of concluding a contract (B2B) is contractually required; if not provided, we cannot fulfil the SaaS contract. We do not use automated decision-making (profiling) that has a legal effect on you.

If you believe that the processing of your data violates data protection law or your data protection rights have otherwise been violated, you can contact us at info@yondo.at or lodge a complaint with the supervisory authority. In Austria this is the Austrian Data Protection Authority (DSB), Barichgasse 40–42, 1030 Vienna, Email: dsb@dsb.gv.at.