Privacy Policy

Privacy Policy

Last updated: 2024-11-13

1. Introduction

Welcome to Inoyu ("we," "us," or "our"). We respect your privacy and are committed to protecting your personal data. This privacy policy informs you about how we handle your personal data when you visit our website and tells you about your privacy rights and legal protections.

We operate under both the Swiss Federal Act on Data Protection (FADP/LPD) and the EU General Data Protection Regulation (GDPR) where applicable. For the purposes of these laws, we are the data controller responsible for your personal data:

Inoyu Route des Cuvaloups 7, 1264 St-Cergue, Switzerland contact@inoyu.dev Data Protection Officer: dpo@inoyu.dev

3. Data We Collect

3.1 Information You Provide to Us

  • Account information (name, email address)
  • Profile information (avatar, preferences)
  • Team-related information
  • Communication data (when you contact us)

3.2 Automatically Collected Information

We use various tracking technologies to automatically collect:

  • IP address
  • Browser type and version
  • Device information
  • Usage data and analytics
  • Cookies and similar technologies

3.3 Behavioral Data Collection

With your explicit consent, we collect detailed information about your interactions with our services, including:

  • User interface interactions
  • Feature usage patterns
  • Time spent on different sections
  • Workflow patterns
  • Preferences and settings
  • Service utilization metrics
  • Performance and error data

This behavioral data collection is implemented through our analytics and tracking systems, which are only activated after receiving your explicit consent through our consent management platform.

Additional data processing purposes include:

  • Training and improving machine learning models
  • Developing artificial intelligence capabilities
  • Creating predictive algorithms
  • Enhancing automated features
  • Developing new AI-powered services
  • Sharing anonymized data with AI development partners

This processing is based on:

  • Our legitimate interest in improving our services
  • Your consent provided through service usage
  • The necessity for modern service development

3.4 Artificial Intelligence and Machine Learning Data Usage

We collect and process data for advanced AI/ML purposes, including:

3.4.1. Data Collection Scope

  • All user interactions and behaviors

  • Feature usage patterns and preferences

  • Performance metrics and system interactions

  • User-generated content and metadata

  • Error logs and debugging information

  • Integration patterns and workflows

  • Custom configurations and settings

    3.4.2. AI Development Purposes

  • Training machine learning models

  • Developing new AI capabilities

  • Creating predictive algorithms

  • Enhancing automated features

  • Developing competitive intelligence

  • Market analysis and trend prediction

  • Service optimization and automation

    3.4.3. Data Sharing and Usage

  • Sharing with AI development partners

  • Cross-product feature development

  • Industry-wide pattern analysis

  • Competitive product development

  • Commercial applications of insights

  • Third-party model training

  • Patent and IP development

    3.4.4. Future Applications We reserve the right to use collected data for:

  • Any future AI/ML applications

  • New product development

  • Market expansion

  • Feature innovation

  • Competitive analysis

  • Industry research

  • Commercial partnerships

4. How We Use Your Data

We process your personal data for:

  • Providing and maintaining our services
  • Improving our website and user experience
  • Communicating with you
  • Analytics and performance monitoring
  • Legal obligations and protecting our rights
  • Personalizing your experience based on behavioral data (with consent)
  • Creating aggregated usage statistics
  • Optimizing service functionality and features
  • Providing customized recommendations and content

We process your personal data under the following legal bases:

  • Consent
  • Contract performance
  • Legal obligations
  • Legitimate interests

6. Analytics and Tracking

We use various analytics tools to understand how our services are used. These may include:

  • Website analytics
  • Performance monitoring
  • Usage patterns
  • Feature adoption

You can control tracking through our cookie consent banner. We only enable tracking after receiving your explicit consent.

7. Data Sharing

We may share your data with:

  • Service providers and processors
  • Team members (if applicable)
  • Legal authorities when required
  • Business partners (with your consent)

8. International Transfers

We may transfer your data to countries outside the EEA. When we do, we ensure appropriate safeguards are in place through:

  • EU Standard Contractual Clauses
  • Adequacy decisions
  • Other legal mechanisms

9. US Privacy Rights

9.1. California Residents (CCPA/CPRA)

  • Right to know what personal information is collected

  • Right to delete personal information

  • Right to opt-out of sale of personal information

  • Right to correct inaccurate personal information

  • Right to limit use of sensitive personal information

  • Right to data portability

    9.2. Other US State Privacy Rights

  • Virginia (VCDPA) consumer privacy rights

  • Colorado (CPA) privacy protections

  • Utah (UCPA) consumer rights

  • Connecticut Data Privacy Act compliance

    9.3. Children's Privacy (COPPA)

  • We do not knowingly collect data from children under 13

  • Parental consent requirements

  • Special handling of children's data

  • Deletion rights for children's data

    9.4. Financial Services Compliance

  • GLBA Privacy and Safeguard Rules compliance

  • Fair Credit Reporting Act requirements

  • Payment processing security standards

  • Financial data handling procedures

    9.5. Healthcare Data

  • HIPAA compliance measures (where applicable)

  • Special categories of health data processing

  • Medical information privacy safeguards

  • Healthcare provider data handling

    9.6. International Data Rights

  • APEC CBPR compliance

  • ASEAN Framework requirements

  • OECD Guidelines implementation

  • Global data portability standards

10. Data Retention

We retain your personal data for as long as necessary to:

  • Provide our services
  • Comply with legal obligations
  • Resolve disputes
  • Enforce agreements

11. Your Rights

Under GDPR, you have the right to:

  • Access your data
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten")
  • Restrict processing
  • Data portability
  • Object to processing
  • Withdraw consent

To exercise these rights, contact us at [Your Privacy Email].

12. Specific Rights Under Swiss Law

Under Swiss data protection law, you have the following rights:

  • Right to information about the processing of your personal data
  • Right to access your personal data
  • Right to data correction
  • Right to object to data processing
  • Right to be forgotten
  • Right to data portability

These rights may be limited by Swiss law or overriding public or private interests.

We use cookies and similar technologies to:

  • Maintain your preferences
  • Enable certain features
  • Analyze usage patterns
  • Provide targeted content

You can manage cookie preferences through our consent banner or browser settings.

14. Children's Privacy

Our services are not intended for children under 16. We do not knowingly collect data from children.

15. Security

We implement appropriate technical and organizational measures to protect your data, including:

  • Encryption
  • Access controls
  • Regular security assessments
  • Staff training

While we implement industry-standard security measures, we explicitly:

  • Make no guarantees about the absolute security of your data
  • Cannot guarantee prevention of all potential security breaches
  • Provide security on a best-effort basis only
  • Accept no liability for breaches beyond our reasonable control

16. Limitations and Disclaimers

16.1. Service Reliability

  • Our services are provided on an "as is" and "best effort" basis

  • We do not guarantee uninterrupted or error-free operation

  • System availability and performance are provided without warranties

    16.2. Data Processing

  • While we implement appropriate safeguards, we cannot guarantee:

    • Zero data loss or corruption

    • Continuous data availability

    • Perfect accuracy of data processing

    • Complete prevention of unauthorized access

      16.3. Analytics and Tracking

  • Behavioral data collection may be incomplete or imperfect

  • Analytics results are provided on a best-effort basis

  • We make no representations about the accuracy of usage statistics

    16.4. Intellectual Property and Feature Development

  • Our collection of usage data and feedback may influence feature development

  • Similar features may be developed independently

  • User suggestions do not create any ownership rights

  • Analytics data may inform product direction

  • We maintain independent records of feature development processes

    16.5. International and US Compliance

  • California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)

  • Virginia Consumer Data Protection Act (VCDPA)

  • Colorado Privacy Act (CPA)

  • Utah Consumer Privacy Act (UCPA)

  • Children's Online Privacy Protection Act (COPPA)

  • US Electronic Communications Privacy Act (ECPA)

  • US Computer Fraud and Abuse Act (CFAA)

  • US Digital Millennium Copyright Act (DMCA)

  • US Federal Trade Commission Act Section 5

  • US State Data Breach Notification Laws

  • Canadian Personal Information Protection and Electronic Documents Act (PIPEDA)

  • Brazilian General Data Protection Law (LGPD)

  • Australian Privacy Principles (APPs)

  • Japanese Act on Protection of Personal Information (APPI)

    16.6. Export Control

  • US Export Administration Regulations (EAR)

  • International Traffic in Arms Regulations (ITAR)

  • Wassenaar Arrangement controls

  • UN Security Council sanctions

  • Swiss sanctions and export controls

    16.7. Industry Standards

  • ISO 27001/27701 Information Security Standards

  • NIST Cybersecurity Framework

  • SOC 2 Trust Service Principles

  • PCI DSS (where applicable)

  • Cloud Security Alliance guidelines

17. Changes to This Policy

We may update this policy occasionally. We will notify you of significant changes through our website or direct communication.

18. Contact Us

For privacy-related inquiries: Email: dpo@inoyu.dev Address: Route des Cuvaloups 7, 1264 St-Cergue, Switzerland

You have the right to lodge a complaint with your local data protection authority.

For Swiss residents: You can contact the Federal Data Protection and Information Commissioner (FDPIC): Federal Data Protection and Information Commissioner Feldeggweg 1 CH - 3003 Berne Switzerland