Purpose
The purpose of this privacy policy (this "Privacy Policy") is to inform users of our Site of the following:
- The personal data we will collect;
- Use of collected data;
- Who has access to the data collected;
- The rights of Site users; and
- The Site's cookie policy.
This Privacy Policy applies in addition to the terms and conditions of our Site.
GDPR
For users in the European Union, we adhere to the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, known as the General Data Protection Regulation (the "GDPR"). For users in the United Kingdom, we adhere to the GDPR as enshrined in the Data Protection Act 2018.
Consent
By using our Site users agree that they consent to:
- The conditions set out in this Privacy Policy.
When the legal basis for us processing your personal data is that you have provided your consent to that processing, you may withdraw your consent at any time. If you withdraw your consent, it will not make processing which we completed before you withdrew your consent unlawful.
You can withdraw your consent by: Users may withdraw their consent at any time by contacting us directly via email at hello@yeahseen.com. Upon receipt of your request, we will cease the processing of your data for the specified purposes within 30 days and confirm the action in writing.
To protect your privacy and security, we will take reasonable steps to verify your identity before granting access to your personal data or fulfilling a withdrawal request. This may include asking you to confirm information already in our possession (such as your account email or recent transaction details) or, in certain high-risk circumstances, requesting additional documentation. We will only request the minimum information necessary for verification and will dispose of such information once your identity is confirmed.
For website visitors who have not provided an email address or created an account, our analytics data is pseudonymous. To fulfill a data access or deletion request, the user must provide their Google Analytics Client ID (found in their browser's cookie settings) so that we may locate the specific records associated with their device.
Legal Basis for Processing
We collect and process personal data about users in the EU only when we have a legal basis for doing so under Article 6 of the GDPR.
We rely on the following legal bases to collect and process the personal data of users in the EU:
- Users have provided their consent to the processing of their data for one or more specific purposes;
- Processing of user personal data is necessary for us or a third party to pursue a legitimate interest. Our legitimate interest is not overridden by the interests or fundamental rights and freedoms of users. Our legitimate interests) are:
- Ensuring network and information security, including preventing unauthorized access, malware distribution, and stopping cyberattacks (such as DDoS attacks) on our Site.
- Analyzing website usage and interaction data to improve our Site's performance, user experience, and the effectiveness of our services.
- Promoting our services to professional and business contacts who have a relevant and appropriate relationship with Yeah Seen Inc., subject to their right to object to such communications.; and
- Processing of user personal data is necessary for us to take, at the request of a user, steps before entering a contract or for the performance of a contract to which a user is a party. If a user does not provide the personal data necessary to perform a contract the consequences are as follows: If you choose not to provide personal data that is necessary for us to fulfill our contractual obligations or enter into an agreement with you, we will be unable to provide the requested services. In such cases, we may have to cancel or suspend your service or order. We will notify you if this is the case at the time.
Personal Data We Collect
We only collect data that helps us achieve the purpose set out in this Privacy Policy. We will not collect any additional data beyond the data listed below without notifying you first.
Data Collected Automatically
When you visit and use our Site, we may automatically collect and store the following information:
- IP address;
- Location;
- Hardware and software details;
- Clicked links;
- Content viewed; and
- Referrer URL.
Data Collected in a Non-Automatic Way
We may also collect the following data when you perform certain functions on our Site:
- First and last name;
- Email address;
- Phone number; and
- Business/Company name.
This data may be collected using the following methods:
- When users submit inquiries, request quotes, or sign up for newsletters through our contact forms.;
- Through user interactions and chat history with our on-site AI chatbots and automation assistants.;
- When users provide information via email, phone calls, or video consultations for project discovery.; and
- Through the creation of client accounts or the completion of service agreements and onboarding documents..
How We Use Personal Data
Data collected on our Site will only be used for the purposes specified in this Privacy Policy or indicated on the relevant pages of our Site. We will not use your data beyond what we disclose in this Privacy Policy.
The data we collect automatically is used for the following purposes:
- We analyze aggregate statistics about website traffic and interactions via Google Analytics 4 to improve our site's functionality, design, and overall user experience.;
- We monitor site access to protect our IT infrastructure, identifying and blocking malicious traffic, unauthorized access, or potential cyberattacks.;
- We track the sources of our traffic (Referrer URLs) to measure the effectiveness of our outreach efforts and Search Generative Optimization (SGO).;
- We use technical interaction data to ensure our content and AI agents are correctly delivered to both human users and authorized search crawlers.;
- We analyze system performance data to refine the accuracy and reliability of our AI-driven solutions and automation frameworks.; and
- We process interaction data to respond to inquiries and provide tailored information about our AI agency services to prospective business partners.
The data we collect when the user performs certain functions may be used for the following purposes:
- To fulfill our contractual obligations, including the development, implementation, and maintenance of AI and SGO solutions.;
- To respond to inquiries, provide technical assistance, and troubleshoot service issues.;
- To send essential project updates, invoices, and administrative notices related to our business relationship.;
- To send newsletters and information about new AI features or agency services that may be of interest to the user.;
- To analyze anonymized interaction data for the purpose of refining and improving the performance of our AI automation agents,; and
- To maintain accurate business records for tax, audit, and regulatory reporting requirements in Ontario and internationally.
Who We Share Personal Data With
Employees
We may disclose user data to any member of our organization who reasonably needs access to user data to achieve the purposes set out in this Privacy Policy.
Third Parties
We may share user data with the following third parties:
- Analytics Providers (c.g., Google Analytics) to track and report website traffic.;
- Payment Processors (c.g., Stripe) to securely process service fees.;
- Hosting and Infrastructure Providers (e.g., Google Cloud, Vercel) to maintain our website and data storage.; and
- AI and Automation Platforms (e.g., OpenAI, Zapier) to power our automated agency services and AI agents. All third parties are contractually prohibited from using your personal data for any purpose other than providing services to Yeah Seen Inc.
We may share the following user data with third parties:
- Technical Data: We share IP addresses and browsing activity with analytics and hosting providers to optimize site performance and security.;
- Financial Data: Payment details are sent directly to our third-party processors (c.g., Stripe) to complete transactions; we do not store this data.;
- Identity Data: Names and contact info are shared with our communication tools to manage inquiries and provide services.; and
- Interaction Data: Queries entered into our AI tools are processed by third-party AI platforms (e.g., OpenAI) to generate automated responses..
We may share user data with third parties for the following purposes:
- Service Fulfillment: To provide and maintain our AI automation and SO services, including the processing of user queries and the delivery of technical results.;
- Transaction Processing: To securely handle service fees and billing through encrypted payment gateways.;
- Performance Monitoring: To analyze website traffic and usage patterns, helping us improve our site's speed, layout, and content relevance.;
- Security & Risk Management: To detect, prevent, and respond to potential fraud, cyberattacks, or unauthorized access to our infrastructure.; and
- Business Communications: To manage client relationships, respond to support requests, and send administrative or marketing updates..
Third parties will not be able to access user data beyond what is reasonably necessary to achieve the given purpose.
Other Disclosures
We will not sell or share your data with other third parties, except in the following cases:
- If the law requires it;
- If it is required for any legal proceeding:
- To prove or protect our legal rights; and
- To buyers or potential buyers of this company in the event that we seek to sell the company.
If you follow hyperlinks from our Site to another site, please note that we are not responsible for and have no control over their privacy policies and practices.
How Long We Store Personal Data
User data will be stored until the purpose the data was collected for has been achieved.
You will be notified if your data is kept for longer than this period.
How We Protect Your Personal Data
Encryption in Transit: We use industry-standard TLS 1.2 or 1.3 (Transport Layer Security) encryption to protect all data transmitted between your browser and our servers.
Encryption at Rest: Sensitive user data is stored using robust AES-256 encryption on secure cloud infrastructure.
Access Controls: We implement the "Principle of Least Privilege," ensuring only authorized employees with a specific business need can access personal information.
Multi-Factor Authentication (MFA): All internal agency accounts (email, CRM, and AI platforms) require MFA to prevent unauthorized access.
Employee Training: All team members undergo privacy and security training, including safe AT handling practices and phishing
awareness.
Data Minimization: We regularly audit our databases to delete information that is no longer necessary for our stated business purposes.
Incident Response Plan: We maintain a documented plan to quickly identify, contain, and report any potential data breaches.
Secure Infrastructure: Our data is hosted in Tier-1 data centers with 24/7 physical security, biometric access, and environmental monitoring.
While we take all reasonable precautions to ensure that user data is secure and that users are protected, there always remains the risk of harm. The Internet as a whole can be insecure at times and therefore we are unable to guarantee the security of user data beyond what is reasonably practical.
International Data Transfers
We transfer user personal data to the following countries:
- United States;
- European Economic Area (EEA);
- Canada; and
- Global Cloud Infrastructure.
When we transfer user personal data we will protect that data as described in this Privacy Policy and comply with applicable legal requirements for transferring personal data internationally.
If you are located in the United Kingdom or the European Union, we will only transfer your personal data if:
- The country your personal data is being transferred to has been deemed to have adequate data protection by the European Commission or, if you are in the United Kingdom, by the United Kingdom adequacy regulations; or
- We have implemented appropriate safeguards in respect of the transfer. For example, the recipient is a party to binding corporate rules, or we have entered into standard EU or United Kingdom data protection contractual clauses with the recipient.
Your Rights as a User
Under the GDPR, you have the following rights:
- Right to be informed;
- Right of access;
- Right to rectification;
- Right to erasure;
- Right to restrict processing;
- Right to data portability; and
- Right to object.
Children
The minimum age to use our website is 18 years of age. We do not knowingly collect or use personal data from children under 16 years of age. If we learn that we have collected personal data from a child under 16 years of age, the personal data will be deleted as soon as possible. If a child under 16 years of age has provided us with personal data their parent or guardian may contact our data protection officer.
How to Access, Modify, Delete, or Challenge the Data Collected
If you would like to know if we have collected your personal data, how we have used your personal data, if we have disclosed your personal data and to who we disclosed your personal data, if you would like your data to be deleted or modified in any way, or if you would like to exercise any of your other rights under the GDPR, please contact our data protection officer here:
Muhammad Khizar Khan
privacy@ycahseen.com
+1 (416) 826-4001
79 Thorncliffe Park Drive, Unit 1507 East York, ON, Canada, M4H IL5
Do Not Track Notice
Do Not Track ("DNT") is a privacy preference that you can set in certain web browsers. We respond to browser-initiated DNT signals. If we receive a DNT signal that indicates a user does not wish to be tracked, we will not track that user. We are not responsible for and cannot guarantee how any third parties who interact with our Site and your data will respond to DNT signals.
How to Opt-Out of Data Collection, Use or Disclosure
In addition to the method(s) described in the How to Access, Modify, Delete, or Challenge the Data Collected section, we provide the following specific opt-out methods for the forms of collection, use, or disclosure of your personal data:
- Marketing Emails: Users can opt-out of promotional communications by clicking the "unsubscribe" link at the bottom of any email or by contacting us directly.
- Website Analytics: Users can opt-out of performance tracking by declining cookies via our on-site consent banner or by using the Google Analytics Opt-out Browser Add-on.
- Targeted Advertising: Users can limit cross-site tracking by adjusting their ad preferences on platforms like Meta (Instagram) or by enabling "Global Privacy Control" (GPC) in their browser.
- Data Correction and Deletion: Users may opt-out of further data storage by requesting the deletion of their personal information from our active databases. You can opt-out by cookie Preference Center: Users can manage or withdraw consent for nonessential cookies and tracking pixels by clicking the "Cookie Settings" link in our website footer.
- Email Unsubscribe: Every marketing email includes a clear "Unsubscribe" link, which immediately removes the user from our promotional mailing lists.
- Browser-Based Opt-Out: Our website recognizes and honors Global Privacy Control (GPC) signals. Users can enable this in their browser settings to automatically opt-out of cross-site tracking.
- Direct Request: Users may contact our Privacy Officer at privacy@yeahseen.com to request the deletion of their data or to withdraw consent for specific processing activities.
- Mobile Ad Settings: Users interacting with our Instagram or Facebook ads can opt-out through their mobile device's "Limit Ad Tracking" settings or Meta's ad preference dashboard.
Cookie Policy
A cookie is a small file, stored on a user's hard drive by a website. Its purpose is to collect data relating to the user's browsing habits. You can choose to be notified each time a cookie is transmitted. You can also choose to disable cookies entirely in your internet browser, but this may decrease the quality of your user experience.
We use the following types of cookies on our Site:
- Functional cookies
Functional cookies are used to remember the selections you make on our Site so that your selections are saved for your next visits;
- Analytical cookies
Analytical cookies allow us to improve the design and functionality of our Site by collecting data on how you access our Site, for example data on the content you access, how long you stay on our Site, etc;
- Targeting cookies
Targeting cookies collect data on how you use the Site and your preferences. This allows us to personalize the information you see on our Site for you; and
- Third-Party cookies
Third-party cookies are created by a website other than ours. We may use third-party cookies to achieve the following purposes: - We allow the following third-party services to set cookies on our website to facilitate advertising, analytics, and enhanced site functionality.
Modifications
This Privacy Policy may be amended from time to time in order to maintain compliance with the law and to reflect any changes to our data collection process. When we amend this Privacy Policy we will update the "Effective Date" at the top of this Privacy Policy. We recommend that our users periodically review our Privacy Policy to ensure that they are notified of any updates. If necessary, we may notify users by email of changes to this Privacy Policy.
Complaints
If you have any complaints about how we process your personal data, please contact us through the contact methods listed in the Contact Information section so that we can, where possible, resolve the issue. If you feel we have not addressed your concern in a satisfactory manner you may contact a supervisory authority. You also have the right to directly make a complaint to a supervisory authority. Under the GDPR, users have the right to lodge a complaint with a supervisory authority in the EU Member State of their habitual residence, place of work, or the place of the alleged infringement. A full list of European Data Protection Authorities and their contact information can be found on the European Data Protection Board (EDPB) website at: https://edpb.europa.eu/about-edpb/about-edpb/members_en
Contact Information
If you have any questions, concerns or complaints, you can contact our data protection officer, Muhammad Khizar Khan, at:
privacy@yeahseen.com
+1 (416) 826-4001
79 Thorncliffe Park Drive, Unit 1507 East York, ON, Canada, M4H 1L5