Privacy Policy
Last updated: 2026-07-10
1. Who We Are
The controller responsible for the processing of personal data described in this policy within the meaning of Art. 4(7) GDPR is:
Youzu OÜ
Ahtri tn 12, Kesklinna linnaosa
15551 Tallinn, Harju maakond
Estonia
Registry code: 17222905
For any privacy-related questions or requests, contact [email protected]. We have not appointed a data protection officer, as we are not required to do so.
2. Scope of This Policy
This policy covers the youzu.ai website and the Youzu platform (the customer dashboard, APIs, and SDKs) where Youzu OÜ decides how and why personal data is processed — that is, where we act as controller.
Where our customers use the platform to process their own data — for example product catalogues, product images, or images submitted by their end users — we process that data on the customer's behalf and on their documented instructions as a processor (Art. 28 GDPR). That processing is governed by our data processing agreement with the customer, available on request at [email protected]. If you are an end user of one of our customers, please direct privacy requests to that customer, who is the controller of your data.
3. Personal Data We Process
3.1 Visiting the website
When you visit youzu.ai, our servers and our content delivery network automatically process technical data: your IP address, browser type and version, operating system, the pages you request, referrer URL, and the date and time of access. We process this data to deliver the website securely and reliably, to prevent abuse, and to diagnose technical problems. The legal basis is our legitimate interest in operating a secure website (Art. 6(1)(f) GDPR). Server logs are automatically deleted after a short period, typically within 30 days, unless a specific incident requires longer retention.
3.2 Contact and demo requests
When you submit our contact form, we process the data you provide:
- First and last name
- Work email address
- Company name and industry
- Products and features you are interested in
- Your message and any additional information you include
We use this data to respond to your enquiry, prepare a demo or proposal, and follow up with relevant product information. The legal bases are steps taken at your request prior to entering into a contract (Art. 6(1)(b) GDPR), your consent given when submitting the form (Art. 6(1)(a) GDPR), and our legitimate interest in managing business enquiries (Art. 6(1)(f) GDPR). You can withdraw consent or object to follow-up communication at any time by emailing [email protected]. We retain enquiry data for as long as needed to handle the enquiry and up to 24 months after our last contact, unless a business relationship results.
3.3 Platform accounts
When you create an account on the Youzu dashboard, we process your name, email address, organization membership, role, and feature permissions, together with authentication data such as session tokens. To keep accounts secure and to provide an audit trail to your organization's administrators, we also record account and administrative actions (for example sign-ins, invitations, and permission changes) with timestamps. The legal basis is performance of the contract with you or your organization (Art. 6(1)(b) GDPR) and our legitimate interest in securing the platform (Art. 6(1)(f) GDPR). Account data is retained for the duration of the contract and deleted or anonymised after termination, except where retention is legally required.
3.4 Billing
Subscription payments are handled by our payment service providers. We receive and store billing contact details, plan and invoice data, and payment status — not full card numbers. The legal bases are performance of the contract (Art. 6(1)(b) GDPR) and our legal obligations to keep accounting records (Art. 6(1)(c) GDPR). Accounting records are retained for seven years as required by Estonian accounting law.
3.5 Analytics and visitor identification
With your consent (Art. 6(1)(a) GDPR), we use Google Analytics 4 to understand how visitors use our website. Also with your consent, we use the Leadsy visitor tag (Instantly.ai) together with the RB2B identification service to recognise the companies — and, for visitors in some regions, the business contacts — behind visits to our website, so that our sales team can follow up with relevant companies. These services process connection data such as your IP address and pages visited, and store identifiers in your browser. They are only loaded after you choose "Accept all" in our consent banner — see the Cookie Policy for details, including how to withdraw consent.
3.6 Email
If you email us directly, we process your email address and the content of your message to handle the correspondence (Art. 6(1)(b) or (f) GDPR).
4. Recipients and Processors
We share personal data only with service providers that support the operation of our website and platform, under data processing agreements pursuant to Art. 28 GDPR:
- Brevo SAS (France) — enquiry management (CRM) and email delivery, including transactional email such as account invitations. Contact form data from section 3.2 is stored in Brevo.
- Cloudflare, Inc. (USA) — content delivery network, TLS termination, and protection against attacks. Cloudflare processes technical connection data such as IP addresses.
- Google Ireland Ltd. — Google Analytics 4, only after consent (see section 3.5).
- Instantly.ai and RB2B (USA) — visitor identification for B2B sales, only after consent (see section 3.5).
- Stripe Payments Europe, Ltd. (Ireland) and Revolut Bank UAB (Lithuania) — payment processing for platform subscriptions.
- Amazon Web Services EMEA SARL — AI/ML compute in the eu-central-1 region (Frankfurt, Germany).
- Google Cloud — AI/ML compute in the europe-west1 region (Belgium).
Our application servers are operated in data centers in the EU and other locations under appropriate safeguards. We may also disclose personal data where required by law or to establish, exercise, or defend legal claims.
We do not use Google Fonts or other third-party font services. All fonts are self-hosted, so no font data is transferred to third parties when you visit this site.
5. International Transfers
We process personal data primarily within the European Economic Area. Where data is transferred to countries without an EU adequacy decision, we rely on appropriate safeguards under Art. 46 GDPR, in particular the European Commission's Standard Contractual Clauses. Transfers to US providers such as Cloudflare, Google, Stripe, Instantly.ai, and RB2B additionally rely on their certification under the EU-US Data Privacy Framework where applicable.
6. Data Retention
We keep personal data only as long as needed for the purposes described above: server logs typically no more than 30 days (section 3.1), enquiry data up to 24 months after last contact (section 3.2), account data for the duration of the contract (section 3.3), and accounting records for seven years (section 3.4). Records of your consent choices are kept as long as needed to demonstrate compliance. After the applicable period, data is deleted or anonymised.
7. Your Rights
Subject to the conditions of the GDPR, you have the right to:
- Access your personal data (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing based on legitimate interests, including direct marketing (Art. 21 GDPR)
- Withdraw consent at any time with effect for the future, without affecting the lawfulness of processing before withdrawal (Art. 7(3) GDPR)
To exercise any of these rights, email [email protected]. You also have the right to lodge a complaint with a supervisory authority, in particular the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) or the authority of your habitual residence or place of work.
8. No Automated Decision-Making
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects on you (Art. 22 GDPR).
9. Children
Our website and services are directed at business users and are not intended for children under 16. We do not knowingly collect personal data from children.
10. Cookies, Local Storage, and Security
Details on consent, local storage, and analytics cookies are in our Cookie Policy. An overview of our technical and organisational security measures is on our Security page.
11. Changes to This Policy
We update this policy when our processing activities or legal requirements change. The current version is always available at youzu.ai/privacy; the date of the last revision is shown at the top of this page.
Ready to transform how your customers shop?
Start with a representative catalogue, workflow, and measurable acceptance criteria. Book a walkthrough on your own catalogue.
No credit card. We'll reply within one business day.
