Privacy Policy
Last updated: 2026-09-21 · Effective immediately
1. Data Controller & Data Processor Roles
Yield Force is operated by Gaia Holdings Limited, an entity incorporated and registered under the laws of England and Wales ("we", "us", "our").
In delivering the Yield Force AI sales automation platform, the legal roles under the UK General Data Protection Regulation (UK GDPR) and EU GDPR (Regulation (EU) 2016/679) are designated as follows:
- Merchant Clients as Data Controllers: The Shopify merchant deploying Yield Force is the Data Controller responsible for customer inquiries, customer orders, and conversational data collected via connected channels.
- Yield Force as Data Processor: Gaia Holdings Limited acts as the Data Processor, processing store and customer data strictly under the merchant's instructions and the Data Processing Agreement (DPA).
- Gaia Holdings Limited as Data Controller: For direct business relationships with merchants (such as merchant account management, subscription billing, and merchant direct inquiries), Gaia Holdings Limited acts as the Data Controller.
2. Categories of Data Collected and Processed
We strictly collect and process only the minimal data necessary to provide AI-powered commerce automation:
- WhatsApp & Messaging Channels: Inbound and outbound message text, timestamps, message delivery status, customer display names, and phone numbers / sender identifiers required for conversational routing.
- Shopify Store & Order Data: Store product catalog (titles, descriptions, pricing, inventory availability) and order fulfillment status (order numbers, fulfillment status, shipping tracking numbers, and delivery addresses required for customer order lookups).
- Ad Platform Metrics: Aggregated campaign metrics, click-to-WhatsApp/messaging ad identifiers, and lead form submissions from Meta (Instagram & Facebook), TikTok, and LinkedIn.
- Website Analytics: None. Yield Force does not deploy tracking cookies, advertising pixels, session recording scripts, or third-party behavioral trackers on our static marketing website or merchant dashboards.
3. Purpose of Processing & Legal Basis
We process data for the primary purpose of AI-powered commerce automation on behalf of merchant clients, including resolving inbound customer inquiries, looking up order statuses, checking catalog availability, and routing escalation requests to merchant staff.
Our lawful grounds for processing under GDPR Article 6 include:
- Contractual Necessity (Art. 6(1)(b)): Fulfilling our service agreements with merchants to operate automated customer messaging and API integrations.
- Legitimate Interest (Art. 6(1)(f)): B2B customer support, service security, fraud prevention, and platform reliability.
- Legal Obligation (Art. 6(1)(c)): Retaining statutory financial, tax, and billing records.
4. Data Retention Policy
We adhere to strict data minimization and storage limitation principles:
- Conversation History: Retained for 90 days by default (configurable down to immediate erasure upon session close by the merchant in their configuration panel). Once the retention window lapses, records are permanently deleted via automated background sweeps.
- Merchant Uninstall: If a merchant uninstalls the Yield Force app, a GDPR cascade delete initiates, permanently purging all associated customer and shop records within 48 hours.
- Billing & Tax Records: Retained for 7 years in accordance with UK statutory accounting and tax obligations.
5. Authorized Subprocessors
We partner with vetted infrastructure providers under rigorous Data Processing Agreements (DPAs) with standard contractual clauses:
| Subprocessor | Purpose | Region / Location | Safeguard |
|---|---|---|---|
| Supabase Inc. | PostgreSQL Database, tenant authentication & encrypted storage | EU Region (Frankfurt / Ireland) | DPA, GDPR Adequacy |
| Google Cloud Vertex AI | AI inference & embeddings generation (zero customer training) | europe-west1 (Belgium) | EU Model Processing Addendum |
| Resend Inc. | Transactional merchant notification emails | US / Global Edge | Standard Contractual Clauses (SCCs) |
| Cloudflare Inc. | CDN, edge proxy, DNS routing, and DDoS mitigation | Global Edge / UK & EU routing | DPA, ISO 27001 |
6. International Data Transfers
Primary data storage and LLM inference occur strictly within the European Union (EU/EEA) and the United Kingdom. Where limited edge routing or vendor delivery requires transfer outside the UK or EEA, transfers occur under UK Adequacy Regulations or the UK Information Commissioner's Office (ICO) International Data Transfer Addendum / standard contractual clauses.
7. Data Subject Rights
Under UK and EU GDPR, individuals possess statutory rights regarding their personal data:
- Right of Access: Request a full copy of personal data processed by Yield Force.
- Right to Rectification: Rectify inaccurate or incomplete records.
- Right to Erasure ("Right to be Forgotten"): Request immediate permanent erasure of conversational logs.
- Right to Restrict Processing: Request restrictions on specific processing activities.
- Right to Data Portability: Obtain structured, machine-readable JSON exports.
- Right to Object: Object to processing based upon legitimate interests.
End customers of Shopify merchants should first contact the merchant directly as the Data Controller. Merchants or direct contacts may exercise rights or contact our designated Privacy Office by emailing dev@yieldforce.dev. We respond to all verified requests within 30 days without charge.
8. Contact Information
For privacy inquiries, data subject access requests (DSAR), or data protection officer inquiries:
UK residents also hold the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.
