Privacy Policy for Ywork

Last Updated: 29 April 2025

1. Introduction

Welcome to Ywork, a platform operated by 90 North Ltd., a company incorporated in the United Kingdom. We are committed to protecting your personal data and ensuring transparency about how it is collected, used, and protected in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This Privacy Policy explains how we handle personal data when you use our platform and outlines your rights and choices. It applies to all users, including business clients, professional service providers, and third parties interacting with Ywork. It is intended to provide a general overview and does not constitute an exhaustive list of all data processing activities or applicable rights.

By accessing or using the platform, you confirm that you have read and understood this Privacy Policy. If you do not agree with its terms, you should not use our services.

2. Scope and Applicability

This Privacy Policy applies to the processing of personal data by 90 North Ltd., in connection with the operation of the Ywork Platform.

It applies to:

  • Any User, including Clients, businesses, or professionals who register an account, access the Platform, or use any of its features.
  • Third Parties, including suppliers and service providers, who interact with Users through the Platform.
  • Individuals whose personal data is provided or generated as part of Platform use, including project submissions, communications, or requests.

This Privacy Policy covers personal data collected through the Platform's digital services, including websites, interfaces, AI-powered tools, and related functionalities, regardless of access method (e.g., desktop, mobile, API).

It does not apply to third-party websites, applications, or services that may be linked or integrated within the Platform. We do not control and are not responsible for the content, policies, or practices of these external services. We encourage you to review their privacy policies before engaging with them.

3. Types of Personal Data We Collect

We collect and process only the personal data required for functionality of the Platform. The types of personal data we may process include:

3.1 Personal Data You Provide

  • Identity and Contact Information: Such as your name, business email address, and organisational affiliation, when you register, update your account, or contact us.
  • Service-Related Inputs: Content you submit while using platform features, including uploaded materials or interaction content related to service functionality.
  • Communications: Information you provide when contacting support or exchanging messages through the Platform.

3.2 Data Collected Automatically

  • Technical and Access Data: Includes IP address, browser and device information, timestamps, and usage logs—collected for security, functionality, and diagnostic purposes.
  • Platform Usage Metrics: Information on how you interact with the Platform's features, including navigation and usage trends, used to improve service delivery.

3.3 Transactional and Payment Information:

Necessary data for subscription management or service purchases, processed securely by authorised third-party payment providers.

3.4 Marketing and Communication Preferences

We may process your contact details and communication preferences to send service-related updates or promotional messages, in accordance with applicable marketing laws. You can opt out of marketing communications at any time.

4. How We Collect Personal Data

We collect personal data through a combination of direct user input, automated technologies, and interactions facilitated through the Platform. The methods of collection include:

4.1 Data Provided by You

You provide data when you:

  • Register or update a user account.
  • Interact with platform features, including content submissions and service requests.
  • Upload documents or files.
  • Communications via the Platform or with our team.
  • Enter payment details or complete a transaction.
  • Subscribe to updates or respond to surveys.

4.2 Data Collected Automatically

We automatically collect data when you interact with the Platform, including:

  • Technical access data (e.g., IP address, device ID, OS, browser type).
  • Usage data including timestamps, feature use, and session logs.
  • Diagnostic data, including performance logs and error reports.
  • Error logs, performance metrics, and interaction histories; Cookies and similar tracking technologies (see our Cookie Policy).

4.3 Data Received from Third Parties

We may receive data about you from external sources, including:

  • Payment processors, for transaction and billing validation.
  • Analytics providers, supplying aggregated platform usage insights.
  • Authentication services or integrated business tools you choose to use.
  • Partners or referring businesses (where applicable).
  • Integrated service providers authorised by you for specific business functions.

6. Use of AI and Automated Processing

The Ywork Platform uses AI-powered tools to assist Users with communication drafting, project interactions, and data structuring. When you use these features, your inputs (including messages, uploaded documents, or prompts) and any associated outputs may be processed using automated systems.

We process this data to:

  • Generate suggested content based on your queries.
  • Structure information for project workflows.
  • Improve the responsiveness and utility of the Platform's features.

Each AI-generated output is linked to your account and project. However:

  • These tools do not make automated decisions that produce legal or similarly significant effects for the purposes of Article 22 UK GDPR.
  • The AI does not profile individual Users, but processes project-level data submitted by Users acting on behalf of a business.
  • In limited circumstances, human reviewers may access AI interactions to improve accuracy, performance, and compliance. See Section 11 for details.

You remain responsible for reviewing any AI-generated output and ensuring its suitability for your business or contractual use. For further disclaimers on the use and limitations of AI content, please refer to our Terms and Conditions.

7. Sharing of Personal Data and Sub processors

We engage trusted third-party service providers (sub processors) to support the operation and delivery of the Platform. These providers assist with essential services such as infrastructure hosting, analytics, identity verification, communication, and payment processing.

Each sub processor is contractually bound to act only on our documented instructions, implement appropriate security measures, and comply with the requirements of Article 28 UK GDPR.

The table below provides an overview of the categories of sub processors and the types of data involved:

Service ProviderPurpose of ProcessingData Categories Involved
Amazon Web Services (AWS)Hosting, database, storage, serverless functionsPlatform application and data, User data, NLP and AI-generated data
Google services – APIs, AnalyticsGoogle integration, Vision API, website user and usage trackingUser data, image processing data
LLMs / NLPs like OpenAI, Deepseek, Mistral ai, Gemini, Llama, etc.AI-powered processing (LLM, NLP)Text data, structured document data
StripePayment collection serviceUser data, payment, fees and subscription related data
HubSpotCRMUser's full name, email address, phone number, company name, company profile, address, website, services or supplies they provide.
Apollo.ioSales engagement and intelligenceFull name, email address, phone number, company name, company profile, address, website, services or supplies they provide.

For more information regarding specific sub processors, please refer to Section 15 ("How to Contact Us").

8. International Data Transfers

Some of the service providers we engage may process personal data outside of the United Kingdom (UK) or the European Economic Area (EEA), including jurisdictions not subject to an adequacy decision under UK data protection law.

These include:

  • Our affiliated entities, such as our Indian subsidiary, with whom we have implemented Standard Contractual Clauses (SCCs) to provide an adequate level of protection; and
  • Third-party service providers, who are contractually bound via Data Processing Agreements (DPAs) and are assessed for their data protection practices, including their international data transfer mechanisms.

Where required, we are actively working to implement appropriate safeguards, such as SCCs or equivalent instruments, in accordance with Article 46 UK GDPR, and adopt technical and organisational measures to ensure a level of protection essentially equivalent to UK standards.

You may request further information about our international transfer safeguards by contacting us at support@ywork.ai.

9. Data Retention and Deletion

We retain personal data for as long as necessary to fulfil the purposes for which it was collected, including to provide the Ywork Platform, comply with legal obligations, resolve disputes (with Platform), and enforce our contractual terms.

9.1 Retention Periods

The duration for which personal data is retained depends on the type of data and the context of its use:

  • Account and Business Profile Data (e.g. name, email, company affiliation, plan details) are retained for the lifetime of the account and up to six (6) years after closure, in line with applicable limitation periods for legal claims and regulatory compliance.
  • Project Data, AI Interactions, and Communication Records are retained throughout the project lifecycle. After closure, relevant information may be retained in anonymised or aggregated form for service development, analytics, or AI training.
  • Payment and Financial Data are retained in accordance with applicable tax and accounting obligations, typically for six (6) years from the transaction date.
  • Technical and Usage Data (e.g. logs, analytics) are retained for up to 24 months unless needed for security or diagnostic purposes.
  • Marketing Data is retained until you withdraw your consent or unsubscribe, after which it is securely deleted or added to a suppression list to prevent future contact.

We do not delete personal data immediately upon account closure but ensure that data no longer required for identifiable processing is either anonymised or securely isolated. Once anonymised, data is no longer considered personal data and may be retained indefinitely for statistical, research, and platform development purposes under Article 89(1) UK GDPR.

9.2 Backup and Archive Data

Personal data stored in system backups may be retained for up to 24 months after deletion from live systems. Such data is stored securely, inaccessible for routine processing, and only restored if required for disaster recovery or legal compliance.

You may request deletion of your personal data at any time, subject to legal and regulatory obligations. To do so, please contact us at support@ywork.ai.

10. Your Rights Under Data Protection Law

You have certain rights under the UK General Data Protection Regulation (UK GDPR) regarding how your personal data is handled. These rights give you control over your information and how we use it.

You can contact us at any time to exercise these rights. We explain them below:

  • Right of Access – To request access to the personal data we hold about you.
  • Right to Rectification – To correct inaccurate or incomplete personal data.
  • Right to Erasure – To request deletion of your data, subject to applicable retention requirements.
  • Right to Restrict Processing – To request we limit the use of your personal data in certain circumstances.
  • Right to Data Portability – To receive your data in a structured, commonly used format and transmit it to another controller.
  • Right to Object – To object to our processing of your data based on legitimate interests or for direct marketing.
  • Right to Withdraw Consent – Where we rely on your consent to process data, you may withdraw it at any time.
  • Right to Lodge a Complaint – You have the right to complain to the UK Information Commissioner's Office (ICO) if you believe we have not handled your data in accordance with the law, please see Section 15 for details.

11. Human Review of Data

To ensure the accuracy, security, and quality of the Ywork Platform, we may conduct limited human review of certain processes and data including user data. This process is designed solely to improve platform functionality, detect misuse, resolve technical issues, and maintain compliance with legal standards.

Any such reviews:

  • Are strictly limited to what is necessary
  • Are conducted by authorised personnel under confidentiality obligations
  • Occur within secure and access-controlled environments

All reviews are subject to role-based access controls and internal audit procedures.

We advise users to avoid submitting unnecessary confidential or sensitive information unless clearly relevant to the service being requested. If you have concerns or wish to understand how your data is handled, please contact us at support@ywork.ai.

If you want to opt out or have any questions or concerns about this process, please contact us at support@ywork.ai.

12. Security Measures

We are committed to safeguarding personal data and implement appropriate technical and organisational measures to protect it against unauthorised access, loss, alteration, or disclosure, in line with Article 32 of the UK General Data Protection Regulation (UK GDPR).

12.1 Technical and Organisational Safeguards

We follow generally accepted industry standards to protect personal data during transmission and once received. These measures include:

  • Encryption in transit and at rest: All data transmitted via the Ywork Platform is protected using HTTPS (TLS encryption) and stored using secure encryption technologies.
  • Access and authentication controls: Role-based access restrictions, password protections, and authentication procedures ensure that only authorised personnel can access personal data.
  • Firewall and infrastructure controls: Our systems are hosted by Amazon Web Services (AWS), which maintains a secure infrastructure certified under ISO 27001 and other recognised standards.
  • Administrative and procedural safeguards: Internal policies are in place to ensure personal data is only accessed and processed as necessary for service provision.

While we take all reasonable steps to ensure data security, no method of transmission over the Internet or method of electronic storage is entirely secure. Therefore, we cannot guarantee absolute security. If you believe your personal data has been compromised, please contact us immediately at support@ywork.ai.

12.2 Breach Notification

If we become aware of a personal data breach that may result in a risk to your rights and freedoms, we will notify affected individuals and the relevant supervisory authority in accordance with legal requirements. Where appropriate, we may also publish a notice on the Platform.

13. Cookies and Similar Technologies

We use cookies and similar tracking technologies to support secure platform access, improve functionality, and understand how our services are used. Some cookies are essential to the operation of the Platform, while others are used for analytics or personalised experiences.

You can manage your cookie preferences or withdraw consent at any time through the cookie settings on the Platform or via your browser settings.

For detailed information about the types of cookies we use, their purposes, and how long they are retained, please refer to our Cookie Policy.

14. Use of Google Workspace API Data

Ywork does not use any data obtained through Google Workspace APIs (such as Gmail, Drive, or Calendar) to develop, improve, or train generalized artificial intelligence (AI) or machine learning (ML) models.

All data retrieved via Google Workspace APIs is handled in full compliance with Google’s API Services User Data Policy, including its Limited Use requirements.

15. Changes to this Privacy Policy

We may update this Privacy Policy from time to time in response to changes in legal, regulatory, operational, or technical developments. When we make material changes, we will notify you by:

  • Posting the updated version on this page, and
  • Providing a notice through the Platform, by email, or by other appropriate means where required by law.

We encourage you to review this Privacy Policy periodically to stay informed about how we process your personal data.

The "Effective Date" at the top of this Privacy Policy indicates when it was last revised. Your continued use of the Platform after any update constitutes your acceptance of the updated Privacy Policy.

16. How to Contact Us

If you have questions, concerns, or would like to exercise any of your rights under this Privacy Policy, you may contact us at:

Email: support@ywork.ai

If you are not satisfied with our response, or believe that we are not processing your personal data in accordance with the law, you have the right to lodge a complaint with the UK's supervisory authority:

Information Commissioner's Office (ICO)
Website: www.ico.org.uk
Helpline: 0303 123 1113