Last update:
19 August 2026
Privacy Policy
1. Introduction
This Privacy Policy explains how myBrick SA, operating under the names Yassi or Yassi.ai (“Yassi”, “we”, “us” or “our”), collects, uses, stores, discloses and otherwise processes personal data when you use our website, software, platform, portals, AI assistants, applications, integrations, communication channels and related services (collectively, the “Services”).
Yassi provides an AI-powered administrative assistance and document management platform primarily intended for businesses and professionals.
Definitions
For the purposes of this Privacy Policy:
“User” or “you” means any natural person using the Yassi Services, whether for their own professional purposes or as a representative, employee, member or authorized user of an Organization.
“Organization” means the company, corporation, association, sole trader, professional practice or other entity for which a User creates, administers or uses a Yassi workspace.
“Contact” or “Recipient” means any natural or legal person with whom a User or Organization interacts through the Services. A Contact may include an End Client, prospect, partner, supplier, employee, counterparty or any other third party receiving a request for documents or information, files or another communication through Yassi.
“End Client” means, where applicable, a Contact to whom the User or their Organization provides its own products or services. An End Client is not necessarily a contractual customer of Yassi.
“User Content” means documents, files, data, messages, instructions, prompts, voice recordings and other content submitted, communicated or processed within the User’s or Organization’s workspace, including content provided by Contacts.
This Privacy Policy applies to personal data processed through the Services, including when you:
visit our website;
create an account or workspace;
use Yassi as a professional User or member of an Organization;
create or manage a request for documents or information;
invite a Contact to provide documents, information or files;
upload, download, receive, analyze, organize or route files through Yassi;
share files with one or more Contacts;
ask a Contact to complete a form, spreadsheet, document or presentation;
use the AI administrative assistant to create, complete, modify, organize or process a form, spreadsheet, document, presentation or other file;
submit or send a voice message to the AI assistant;
use AI, OCR, transcription, extraction, classification, transformation or automation features;
connect third-party storage, email, messaging, communication, CRM, ERP, accounting, identity or collaboration systems;
communicate with us, with Yassi or with other persons through the Services.
Yassi is operated by myBrick SA, a Swiss company.
When a workspace is created or configured, Yassi determines the applicable reference jurisdiction based on the User and their Organization. The Yassi environment directly controlled by Yassi is then configured so that the relevant processing takes place within that jurisdiction, in accordance with the principles described in this Privacy Policy.
2. Scope of the Privacy Policy
This Privacy Policy describes how we process personal data:
collected directly from Users;
received from Contacts or End Clients;
received from services and integrations connected at the instruction of a User or Organization;
contained in documents, files, prompts, messages, voice recordings and metadata processed through the Services;
generated through the use of our website and Services.
This Privacy Policy does not govern the privacy practices of third-party services that you choose to connect to Yassi or use independently, including:
Microsoft: OneDrive, SharePoint, Outlook, Microsoft 365, Teams and other Microsoft services;
Google: Google Drive, Gmail, Google Workspace and other Google services;
Meta: WhatsApp and other Meta services;
Apple: iMessage and other supported Apple services;
Telegram;
Salesforce: CRM, Slack;
CRM systems and ERP systems;
accounting and financial management systems;
storage, messaging, telephony, transcription or other professional service providers connected at the User’s request.
These services have their own infrastructures, terms, configurations and privacy policies.
Information and terms presented to Contacts and End Clients
Depending on the enabled features, Yassi also allows Users and Organizations to present their own terms and conditions, privacy policies, consent notices, legal notices or other contractual documents to their Contacts or End Clients and to request acceptance of such documents as part of a request or portal interaction.
These documents are determined and provided by the User or Organization. Their content, validity, relevance and compliance remain the responsibility of the relevant User or Organization.
A Contact’s or End Client’s acceptance of such documents may be recorded by Yassi in order to provide the Services and maintain the corresponding audit trail.
Such Organization-specific terms or policies may supplement information provided by Yassi but do not replace this Privacy Policy where Yassi itself acts as controller for certain data.
3. Roles and responsibilities
Yassi’s role under applicable data protection laws depends on the nature of the relevant processing activity.
3.1 Responsibilities as data processor
For processing activities related to its own business operations and the operation of the Services, the data controller is:
myBrick SA
Chemin des Côtes-de-Montmoiret 5
1012 Lausanne
Switzerland
Email: hello@yassi.ai
Yassi acts in particular as a data controller for data necessary for:
creating and administering User accounts;
managing contractual and commercial relationships with Users and Organizations;
providing support;
security, abuse prevention and administration of the platform;
administrative communications relating to the Services;
billing, where applicable;
technical operation of the Services;
analyzing use of our public website.
For these processing activities, Yassi determines the essential purposes and means of processing.
3.2 Responsibilities of Yassi.ai as processor or sub-processor
Where Yassi processes User Content through the Services on behalf of a User or Organization, Yassi generally acts as a processor or, where the User or Organization itself acts as a processor on behalf of another party, as a sub-processor.
This may include data relating to:
End Clients;
prospects;
partners;
suppliers;
employees;
Contacts;
counterparties;
or other third parties.
In this context, Yassi processes such data:
to provide the requested functionality;
in accordance with the instructions of the User or Organization;
in accordance with the configuration of the relevant workspace;
to the extent necessary to provide the Services;
subject to any legal obligations directly applicable to Yassi.
Yassi does not acquire ownership of User Content.
The obligations applicable to processing carried out on behalf of an Organization may also be specified in a Data Processing Agreement (“DPA”).
3.3 Role of the User and the Organization
The role of the User or Organization depends on its own relationship with the individuals whose personal data is being processed.
The User or their Organization may, for example:
act as a data controller where it determines the essential purposes and means of processing personal data relating to its Contacts; or
itself act as a processor where it provides a service involving the processing of data on behalf of an End Client or another organization.
It is the responsibility of the User and/or the Organization they represent to determine its own role in relation to a particular processing activity and to comply with the obligations arising from that role.
Where the User or Organization acts as controller, it is responsible in particular for:
having an appropriate lawful basis for the processing;
informing data subjects where required;
obtaining any required consents or authorizations;
determining the relevant purposes and retention periods;
determining whether specific regulatory, contractual or professional requirements apply.
Where the User or Organization acts as a processor on behalf of an End Client, it is responsible for ensuring that it is permitted to appoint Yassi as a sub-processor where required.
The User or Organization may also use Yassi features to present its own terms and conditions, privacy policies or consent notices to Contacts or End Clients and record their acceptance.
4. Categories of Personal Data We Process
Depending on how you use the Services, we may process the following categories of personal data.
4.1 Account and identity data
Including:
first and last name;
company or Organization name;
email address;
telephone number;
account login information;
role, permissions and workspace information.
4.2 Profile and configuration data
Including:
Organization information;
branding or white-label settings;
AI assistant settings;
communication preferences;
reference jurisdiction and data residency preferences;
AI model or provider preferences where supported;
storage structure;
routing settings;
enabled integrations.
4.3 User Content and operational data
When you use Yassi to manage or process files or cases, we may process:
documents;
files;
images;
PDFs;
spreadsheets;
forms;
office documents;
presentations;
attachments;
voice messages and, where applicable, their transcriptions;
associated metadata;
data contained within such content;
extracted text;
OCR results;
summaries;
classifications;
extracted structured information;
analysis results;
file names and renaming rules;
prompts, commands, instructions and workflow settings;
communications sent through or to the Services.
Such content may include sensitive personal data where such information is contained in material provided by the User, their Organization or their Contacts.
4.4 Contact and End Client data
When the Services are used to interact with a Contact, we may process:
name;
email address;
telephone number where necessary;
organization or company;
metadata relating to communications and documents;
communication history;
request status;
submitted files;
workflow-related information;
date and time of access or submission;
acceptance, refusal or other interaction with terms, policies or consent notices presented by the User or Organization;
technical information necessary for the security of the Services.
4.5 Technical, usage and device data
Including:
IP address;
browser type and version;
operating system;
technical device identifiers;
log files;
usage events;
timestamps;
security and access logs;
error reports;
performance indicators.
4.6 Billing and commercial data
Where applicable:
subscription plan;
invoices;
payment-related records;
information relating to the commercial relationship.
We generally rely on specialized payment service providers to process payments and do not intend to store full payment card details ourselves.
5. How We Collect Personal Data
We may collect or receive personal data:
directly from you when you create an account, complete a form, configure the Services, submit a prompt, deposit a file or communicate with us;
from other Users belonging to the same Organization;
from Contacts who respond to a request, submit files, complete forms, accept terms or otherwise interact with Yassi;
from connected systems where you authorize integrations with storage, email, messaging, CRM, ERP, accounting, communication or other business systems;
from an email inbox or messaging channel enabled by the User;
automatically through logs, cookies, pixels, usage analytics and technical monitoring tools;
from service and infrastructure providers supporting authentication, hosting, monitoring, communications, storage or other technical processing.
6. How We Use Personal Data
We use personal data for the following purposes.
6.1 Providing and operating the Services
Including to:
create and manage accounts and workspaces;
process prompts and instructions;
create and manage requests for documents or information;
send invitations and reminders;
receive, classify, process and organize files;
share files with Contacts;
allow Contacts to submit documents and information;
allow forms, spreadsheets, documents or presentations to be completed;
allow the AI assistant to create, modify or complete documents, files, spreadsheets, forms or presentations;
receive, where necessary transcribe, and process voice messages addressed to the AI assistant;
perform OCR, extraction, summarization, classification and analysis;
convert, compress, organize or rename files;
verify certain information;
route files to destinations configured by the User;
share or make files available;
present terms, policies or consent notices defined by the User or Organization to Contacts or End Clients and record their interaction or acceptance;
provide analysis results;
provide AI administrative assistant functionality;
provide communications and notifications;
administer permissions and access rights.
6.2 Securing, maintaining and improving the Services
Including to:
monitor availability, performance and reliability;
troubleshoot errors and incidents;
detect abuse, fraud and unauthorized access;
improve usability, workflows and feature performance;
conduct internal testing and quality controls.
6.3 Communicating with you
Including to:
provide onboarding and support;
respond to questions and requests;
send transactional and administrative communications;
inform you of important changes, issues or security events.
6.4 Complying with legal and regulatory obligations
Including to:
comply with applicable law;
respond to legally binding requests from competent authorities;
defend or enforce our rights;
manage disputes;
retain certain records for legal, accounting, audit or governance purposes.
6.5 Developing and improving models and functionality
Where permitted by applicable law and agreements, Yassi may use Service usage data, operational metadata and sufficiently minimized or anonymized information to improve the Services.
Yassi does not currently use identifiable User documents, files or other User Content to train any LLM models.
In the professional configurations currently used by Yassi, content transmitted to model providers is not intended to be used to train their general-purpose foundation models.
If Yassi were in the future to use User Content to train or improve its own models in a manner not covered by this Privacy Policy or existing agreements, affected Users would be informed in advance and, where required, appropriate authorization or agreement would be obtained.
7. Legal Bases for Processing
Where Swiss law or other applicable law requires a legal basis, Yassi may process personal data on the basis of, among other things:
performance of a contract or steps taken at your request prior to entering into a contract;
our legitimate interests in operating, securing, improving and supporting the Services;
your consent, where required;
compliance with legal obligations;
protection of our rights or the rights of others.
Where Yassi acts as a processor or sub-processor in relation to User Content, the legal basis applicable to the underlying processing is determined by the relevant data controller.
If you provide personal data relating to Contacts, End Clients, employees, counterparties or other third parties, you are responsible, to the extent applicable to your role, for ensuring that you have the necessary authority to do so.
8. Data Residency, Hosting, and Processing Locations
8.1 Reference jurisdiction and Yassi platform data
When a workspace is created or configured, Yassi determines the applicable reference jurisdiction based primarily on the location of the Organization and, where relevant, the User.
Infrastructure directly controlled by Yassi is then deployed and configured so that processing within that environment remains in the corresponding jurisdiction.
For Swiss Organizations, the Yassi environment is currently hosted on Microsoft Azure in the Switzerland North region, and processing directly controlled by Yassi is configured to take place in Switzerland.
Depending on the features used, this includes:
application infrastructure;
databases;
Yassi storage;
components required for the AI assistant;
AI and OCR processing deployed by Yassi;
certain communication services;
technical systems required to operate the Services.
For an Organization established in another supported jurisdiction, Yassi similarly configures the environment so that processing directly controlled by Yassi takes place within the jurisdiction or regulatory region appropriate to that Organization.
If a particular feature exceptionally requires processing outside the Organization’s reference jurisdiction, Yassi will formally inform the relevant Organization in writing, including by email, specifying the exception and the jurisdiction concerned.
8.2 Document storage selected by the User
A key aspect of Yassi is that Users may choose where documents and files are stored, including by connecting their own environments.
These may include:
Microsoft: OneDrive or SharePoint;
Google: Google Drive;
other supported systems.
Where external storage is configured, Yassi may temporarily process files in order to receive, analyze and transfer them to the selected destination.
Following transfer, the residence, security, retention, backups and access controls applicable to files in the destination environment depend primarily on:
the selected provider;
the Organization’s account or environment;
the configured region;
the settings and policies of the User or Organization.
Yassi does not control the underlying geographic residency of an external storage environment voluntarily selected by the User.
Where a User selects Yassi storage as the destination, files are retained within the environment corresponding to the Organization’s reference jurisdiction until deleted in accordance with applicable settings and this Privacy Policy.
8.3 AI / LLM / OCR processing locations
AI, LLM, OCR and document-processing components selected and deployed directly by Yassi are configured within the Organization’s reference jurisdiction.
For a Swiss Organization, Yassi uses AI/OCR models and services hosted or deployed in Switzerland for processing carried out within the Yassi environment.
Yassi may use multiple models, engines or technologies to optimize:
performance;
latency;
cost;
feature availability;
quality of results.
The selection of a particular model or engine should not, by default, result in a change to the processing jurisdiction defined for the Organization.
Where a specific model, engine or feature cannot exceptionally be provided within the applicable reference jurisdiction, it is not considered automatically part of the standard environment. Where Yassi intends to use it despite this exception, the relevant Organization will be formally informed in writing of the applicable jurisdiction in advance or, where prior notice is not reasonably possible, promptly thereafter.
9. Compliance frameworks and regional data protection standards
Yassi is designed to help Users and Organizations meet applicable data protection requirements, taking into account in particular the location and jurisdiction of the Organization, as well as workspace configuration, storage and enabled third-party services.
Where applicable, Yassi designs and operates its Services with consideration for, among others:
the EU General Data Protection Regulation (Regulation (EU) 2016/679 — “GDPR”);
the Swiss Federal Act on Data Protection (“Swiss FADP”);
applicable UK data protection laws, where relevant;
the California Consumer Privacy Act (“CCPA”), as amended including by the California Privacy Rights Act (“CPRA”), where applicable;
other US state privacy laws that may apply to a particular processing activity;
applicable cybersecurity, confidentiality and, where relevant, sector-specific requirements;
recognized security frameworks and good practices, including those developed by the National Institute of Standards and Technology (“NIST”).
Where the CCPA/CPRA applies and Yassi processes personal information on behalf of an Organization, Yassi structures its processing and applicable agreements so that it may act, depending on the legal context, as a service provider or contractor in accordance with applicable requirements.
Compliance of a particular processing activity depends in particular on:
the location and jurisdiction of the Organization;
where relevant, the location of the User;
the selected and connected document storage environment;
third-party systems voluntarily connected;
enabled communication channels and integrations;
the User’s or Organization’s own legal, technical and organizational measures.
Yassi does not represent that use of the Services, by itself, is sufficient to make an Organization compliant with every law, regulation or framework applicable to its activities.
Yassi nevertheless seeks to provide an environment whose location, hosting and principal processing activities are aligned, to the fullest extent reasonably possible, with the applicable jurisdiction and location of the Organization.
For this purpose, Yassi determines a reference jurisdiction when configuring the workspace and configures infrastructure directly under its control, including AI and OCR processing, according to that jurisdiction.
Where an exception to this localization is necessary for a feature or processing activity directly controlled by Yassi, the Organization will be formally informed in writing of the exception and the relevant jurisdiction.
The User and their Organization remain responsible for assessing whether their own workflows, connected systems, processed data and professional or sector-specific obligations satisfy the requirements applicable to them.
10. Connected Storage and Your Environment
Yassi may allow the User to connect various third-party services and professional environments. These integrations may serve different purposes and should in particular be distinguished between storage systems, messaging and communication systems, and other connected professional systems.
10.1 Connected Storage Systems
Yassi may allow the User to connect an external storage system intended, among other purposes, to receive, organize or retain documents and files processed through the Services.
These systems may include:
Microsoft OneDrive;
Microsoft SharePoint;
Google Drive;
or other compatible storage systems.
When an external storage system is connected:
the User or their Organization selects the provider, account, tenant and, where available, the region to be used;
files may be temporarily processed by Yassi before being transferred to the selected destination;
after transfer, the data residency, retention, backups, permissions and access controls applicable to the files depend primarily on the storage provider and the configuration selected by the User or their Organization;
Yassi does not control the underlying geographic residency of an external storage environment voluntarily selected by the User.
Specific rules relating to document storage and temporary processing are also described in Sections 8 and 15 of this Privacy Policy.
10.2 Connected Messaging and Communication Systems
Yassi may also allow the User to connect or use messaging, email or communication services in order, among other purposes, to send or receive messages, instructions, notifications, documents or attachments.
These services may include:
Microsoft Outlook and certain Microsoft 365 services;
Microsoft Teams;
Gmail and certain Google Workspace services;
WhatsApp and other supported Meta services;
Apple iMessage;
Telegram;
Slack;
telephony or transcription systems;
or other compatible communication channels.
These communication systems are separate from the document storage system configured as the destination for files.
When a message, document or attachment passes through such a service, the relevant messaging or communication provider may independently process or retain certain data in accordance with its own infrastructure, terms, privacy policies and the settings of the User’s or Organization’s account.
When Yassi receives a file through one of these channels, Yassi may temporarily process it in order to analyze, organize or transfer it to the storage system separately configured by the User.
Connecting a messaging or communication channel therefore does not necessarily mean that such channel constitutes the permanent document storage system used by Yassi.
10.3 Other Connected Professional Systems
Yassi may also allow connections to other professional tools, including:
Salesforce and other CRM systems;
ERP systems;
accounting, finance or billing systems;
other compatible business applications and tools.
Depending on the relevant integration, Yassi may receive, transmit, access or synchronize certain data necessary to perform the functionalities requested by the User or their Organization.
10.4 Responsibility for Third-Party Environments
When you connect your own third-party environment:
you select the provider and account to be used;
you are responsible for the permissions, users, sharing settings and access controls applicable to that environment;
the privacy, security, data residency and retention of data within that environment depend, among other things, on the relevant provider and your configuration;
Yassi does not control copies that may be independently retained by such providers.
Where a third-party system is voluntarily connected by the User, it may operate in a jurisdiction different from that of the Yassi environment.
This difference results from the third-party service selected and the configuration of the User’s or Organization’s account and does not mean that Yassi’s own infrastructure has been transferred to that other jurisdiction.
Any incident arising from credentials, internal permissions, sharing settings, devices, tenant settings or configurations specific to a third-party provider falls within the responsibility of the relevant environment, except to the extent that it is directly caused by Yassi’s failure to comply with its own obligations.
11. AI, Automation, and Human Review
Yassi provides artificial intelligence-based administrative assistance and processing features.
These may include:
OCR;
document identification and classification;
data extraction;
summarization;
comparison of information;
creation or modification of documents;
processing of forms, spreadsheets or presentations;
transcription or interpretation of voice instructions;
AI-generated suggestions or responses;
execution or preparation of administrative actions;
workflow actions.
You acknowledge that:
AI results may be incomplete or inaccurate;
OCR may misinterpret or omit certain information;
automated extraction and analysis may require human review;
Users remain responsible for verifying results before relying on them, particularly in regulated or high-impact contexts.
Yassi may process prompts, instructions, extracted text, files and operational metadata using providers or models configured for the workspace, in accordance with this Privacy Policy and the jurisdiction applicable to the relevant environment.
The rules concerning model training are set out in Section 6.5.
12. Cookies and Analytics
We may use cookies, pixels, tags and similar technologies on our website and, where necessary, within the Services for purposes including:
authentication;
security;
remembering preferences;
analytics;
performance monitoring;
improving the user experience.
Google Analytics may be used on the public Yassi website to measure and analyze website usage. It is not intended to analyze the contents of documents or cases processed by Users within the Yassi application.
You may manage certain cookie preferences through your browser or through consent mechanisms provided where applicable.
Certain features may not function properly if necessary cookies are disabled.
A separate Cookie Policy may be provided or incorporated into this Privacy Policy.
13. Disclosure of Personal Data
We may disclose or make personal data available to the following categories of recipients where necessary.
13.1 Service providers and sub-processors
Yassi uses or may use providers for purposes including:
cloud hosting and infrastructure;
storage and backups;
AI, LLM, OCR and document-processing services;
communications and email delivery;
monitoring and technical analytics;
authentication and identity;
support;
payment processing;
professional and legal services.
Depending on the features and configurations enabled, key technical providers currently used may include:
Microsoft Azure, for hosting, storage, certain AI and OCR functionality, communications and other technical services;
OpenAI, Google and Anthropic models, or other compatible models, where deployed or accessed within an environment configured by Yassi for the relevant jurisdiction;
Mistral AI and/or other selected document-processing engines, where deployed within the applicable environment and used for specific document-analysis functionality;
Microsoft 365, including for certain support and communication functions;
Sentry, for certain technical monitoring purposes;
Google Analytics, for public website analytics;
Cloudflare, for certain DNS, network and content-delivery services.
The list and use of these providers may evolve as the Services develop.
Where required by applicable law or commitments, Yassi will inform relevant Organizations of significant changes relating to sub-processors.
13.2 Third-party systems selected by you
Systems voluntarily enabled by a User or Organization may include:
Microsoft OneDrive, SharePoint, Outlook, Microsoft 365 and Teams;
Google Drive, Gmail and Google Workspace;
WhatsApp;
Telegram;
Apple iMessage;
Slack;
Salesforce or other CRM systems;
ERP systems;
accounting or finance systems;
messaging or telephony systems;
other integrations enabled at your request.
These services process data in accordance with their own infrastructure, terms, policies and the configuration selected by the User or Organization.
13.3 Legal and protective disclosures
We may disclose certain data where necessary to:
comply with applicable law or regulation;
respond to a legally binding request from a competent authority or court;
protect our rights, property or safety;
protect our Users or the public;
investigate fraud, abuse or security incidents;
enforce our Terms.
Where legally permitted and reasonably possible, Yassi seeks to limit any disclosure to the information actually required.
13.4 Corporate transactions
Data may also be involved in a merger, acquisition, reorganization, financing transaction or sale of assets, subject to applicable confidentiality protections and obligations.
Yassi does not sell personal data or User Content.
Where the CCPA/CPRA applies, Yassi does not “sell” or “share” personal information for cross-context behavioral advertising within the ordinary provision of its Services, as those terms are defined under those laws.
14. International Transfers
Yassi applies an approach based on the Organization’s reference jurisdiction.
The environment directly controlled by Yassi is configured so that the associated hosting and processing are carried out within that jurisdiction.
For a Swiss Organization, data and processing directly controlled by Yassi, including AI and OCR processing used within the standard environment, are configured in Switzerland.
Yassi therefore does not, by default, move AI or OCR processing for a Swiss Organization to a foreign jurisdiction merely because of the provider or model being used.
An international processing activity or transfer may nevertheless occur, in particular:
where a third-party service is voluntarily connected or enabled by the User or Organization, such as a storage, CRM, ERP, messaging, email or collaboration system whose infrastructure is located in another jurisdiction;
where the User independently selects an account, tenant, region or third-party environment located outside the reference jurisdiction;
where a competent authority or court legally requires certain data to be disclosed in accordance with applicable law;
exceptionally, where a feature directly provided by Yassi cannot be operated within the reference jurisdiction and this exception has been formally communicated to the Organization in writing, including by email.
Outside these circumstances, Yassi does not intend to transfer data from an environment to a foreign jurisdiction without an operational necessity and appropriate notice.
Where personal data must legally be disclosed or processed in another jurisdiction, Yassi applies appropriate safeguards where required under applicable law, which may include:
processing in a jurisdiction recognized as providing an adequate level of data protection;
appropriate contractual safeguards;
recognized standard contractual clauses;
data processing agreements with relevant providers;
supplementary technical and organizational measures.
The location of a third-party service voluntarily connected by the User remains determined by the relevant provider and by the configuration of the User’s or Organization’s account or environment.
15. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including:
providing the Services;
maintaining security and auditability;
complying with legal, contractual, accounting or regulatory obligations;
resolving disputes and enforcing agreements.
Retention periods may vary depending on:
the category of data;
account settings;
storage configuration;
the workflow used;
legal obligations;
the channel through which data is received;
whether data is retained by Yassi or within an external environment connected by the User.
Files submitted through the portal
Where a file is intended to be transferred to external storage connected by the User, Yassi normally retains it only for the time required to receive, process and transfer it.
Under normal operating conditions, this temporary processing generally lasts approximately 1 to 2 minutes.
Where the User selects Yassi storage as the destination, the file may instead remain stored within their workspace until deleted.
Attachments received by email
Where an attachment received by email is intended to be processed and transferred to storage selected by the User, it is normally retained temporarily by Yassi for approximately 15 to 20 minutes, allowing for receipt, processing, transfer and subsequent deletion from the temporary Yassi environment.
Files received through messaging services
For files temporarily received through services such as WhatsApp, Telegram, Microsoft Teams, Slack or other supported channels, Yassi generally applies a maximum temporary processing period of 24 to 48 hours in order to allow processing and transfer.
The relevant messaging provider may nevertheless independently retain a copy in accordance with the account settings and its own retention policy.
Failed transfers
Where a transfer to OneDrive, SharePoint, Google Drive or another configured destination fails, Yassi may temporarily retain the file to allow further transfer attempts.
The file is removed from the temporary environment after a successful transfer or when the relevant workflow or request is closed or deleted in accordance with the applicable rules.
Yassi storage
Where the User expressly selects Yassi storage, files are retained within the User’s workspace for as long as necessary for use of the Service and until deleted by the User, deletion of the corresponding request or application of another applicable retention rule.
OCR data, extracted data and analysis results
Extracted text, OCR results, classifications, summaries, structured data and other results required for the operation of a request may be retained together with that request for as long as it exists.
When the corresponding request is deleted, associated operational data is also deleted from the active system, subject to the ordinary backup lifecycle.
Messages relating to a request
Communications made within Yassi and associated with a request may be retained with that request until it is deleted.
Acceptance of terms or policies
Where Yassi allows an Organization to present its own terms, policies or consent notices to a Contact or End Client, information necessary to maintain evidence of acceptance or refusal may be retained with the relevant request or case for as long as it exists or for as long as required for the purpose determined by the Organization.
Conversations with the Yassi assistant
Prompts, messages, instructions and information required for the assistant’s context may be retained in order to provide history and functionality until deleted by the User, deletion of the relevant data or closure of the account, subject to applicable retention obligations.
Where a communication also passes through a third-party service such as WhatsApp, Telegram, Teams, Slack or another channel, a copy may be independently retained by that provider.
Technical, security and audit data
Certain technical and audit data may be retained for as long as reasonably necessary for security, traceability, abuse prevention, incident investigation and compliance with applicable obligations.
Different categories of logs may be subject to different retention cycles.
Support communications
Communications with our support team may be retained for as long as reasonably necessary to manage the relationship, resolve issues, ensure support continuity and comply with applicable obligations.
Backups
Backups of the Yassi application environment currently follow a 7-day retention cycle.
Data deleted from the active system may therefore remain temporarily present within a backup until that cycle expires.
Deletion of a request or account
When a User deletes a request, application data directly associated with that request is deleted from the active environment in accordance with the rules described above.
Where a User or Organization requests deletion of its account and data, Yassi deletes data remaining under its control that no longer needs to be retained, subject to:
legal retention obligations;
legitimate needs relating to security or disputes;
the normal backup lifecycle.
Files already transferred to storage belonging to the User or Organization, including OneDrive, SharePoint or Google Drive, remain under their control and are not deleted as a result of closing the Yassi account.
16. Security Measures
We implement technical and organizational measures designed to protect personal data under our control against unauthorized access, loss, misuse, alteration or disclosure.
These measures include or may include:
access controls;
role-based permissions;
logical separation between workspaces;
the principle of least privilege;
secure authentication mechanisms;
encryption of data stored within our environment;
encryption of data in transit using protocols such as TLS;
logging and monitoring of certain events;
incident detection and response procedures;
regular security controls and testing.
Yassi supports authentication through identity providers such as Microsoft and Google. Multi-factor authentication mechanisms may be applied in accordance with the identity functionality and policies of the User or Organization.
Security incidents
In the event of a security incident affecting personal data processed by Yassi on behalf of a User or Organization, Yassi will take reasonable steps to identify, contain and address the incident.
Yassi will inform the affected User or Organization without undue delay and, where possible, within 24 hours after becoming aware of an incident affecting data entrusted to Yassi.
Available information may be supplemented as the investigation develops.
No system or transmission method can provide absolute security, particularly where a risk arises from:
storage or identity systems connected by the User;
compromised devices or email accounts;
third-party services;
configuration choices made by the User;
phishing, malware or social engineering affecting a User or Contact.
17. Your Choices
Depending on how you use the Services, you may be able to:
access and update your account information;
manage roles and permissions for Users within your Organization where you have the required rights;
manage settings relating to Contacts and End Clients;
define or present your own terms and conditions, privacy policies or consent notices where this feature is offered;
select storage configurations;
connect or disconnect certain integrations;
configure communication and workflow settings;
delete certain requests, files or data;
request deletion of your account, subject to applicable legal and operational constraints.
Where we rely on your consent for particular processing activities, you may withdraw that consent. Doing so may, however, affect the availability of certain functionality.
18. Your Privacy Rights
Depending on your place of residence, role and the nature of the processing, you may have rights under the Swiss FADP, GDPR, CCPA/CPRA or other applicable data protection laws.
These may include, depending on the jurisdiction:
the right of access;
the right to know categories of personal data processed;
rectification;
deletion;
restriction of processing;
objection;
provision or portability of certain data;
withdrawal of consent where processing is based on consent;
certain rights relating to the sale or sharing of data where such concepts exist under applicable law;
certain rights relating to sensitive personal information;
the right not to be unlawfully discriminated against for exercising privacy rights.
Yassi does not sell personal data or User Content.
Requests made directly to Yassi
For data for which Yassi acts directly as controller, requests may be submitted to:
We may request information reasonably necessary to verify the identity and authority of the person making the request.
Where Yassi acts as processor or sub-processor
Where the data concerned is processed by Yassi on behalf of a User or Organization, the relevant controller may be:
the User or their Organization; or
in certain circumstances, the End Client or another organization on whose behalf the User or Organization provides its own services.
The data subject should normally submit their request to the relevant controller.
Where applicable, Yassi will reasonably assist the relevant User or Organization in handling such request in accordance with applicable agreements and law.
California and other US jurisdictions
Where the CCPA/CPRA or another applicable US privacy law provides specific rights to an individual, Yassi and the Organization will handle relevant requests according to their respective roles.
Where Yassi acts solely as a service provider processing personal information on behalf of an Organization, a request concerning that information may need to be submitted directly to the Organization.
19. Children’s Privacy
The Yassi Services are intended for professional use and are not directed to individuals under 18 as Users.
We do not knowingly collect personal data directly from children for consumer use.
Documents or information processed by a User may nevertheless contain data relating to minors where this is necessary for the activities of the User, their Organization or their End Client.
In such cases, Yassi processes that data as part of the Services and in accordance with the applicable instructions, in the same manner as other User Content.
If you believe that data relating to a child has been submitted or processed unlawfully, please contact us.
20. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect, among other things:
changes to the Services;
the addition or replacement of providers;
new integrations;
changes to our infrastructure;
legal or regulatory developments.
If we make changes, we will publish the updated version on our website and update the “Last updated” date.
Where changes are material, we may provide additional notice through the Services or by email where appropriate or required.
Your continued use of the Services after the updated Privacy Policy becomes effective constitutes acknowledgment of the updated Policy and, where required under applicable law, acceptance of the updated version.
21. Contact Us
If you have any questions about this Privacy Policy or our data protection practices, please contact:
myBrick SA / Yassi.ai
Chemin des Côtes-de-Montmoiret 5
1012 Lausanne
Switzerland
Email: hello@yassi.ai