Skip to Content

Privacy Policy

Introduction

Effective Date: June 2026 | Last Updated: September 2026

This Privacy Policy explains how Y-Institute, trading as Y-Institute ("Y-Institute", "we", "us"), collects and uses personal data when you visit y-institute.com, create an account, or use the Y Intelligence platform ("Y") on the web, in WhatsApp, in Microsoft Teams, through connectors or through the API. It is written to meet Articles 13 and 14 of Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and the Dutch GDPR Implementation Act (Uitvoeringswet AVG, "UAVG"). It forms part of our Terms of Service

1 Who is responsible for your data

1.1 We are the controller for personal data about account holders, Workspace owners and administrators, billing contacts, website visitors, people who contact us, and the account and usage data of every Named User. Our details are in section 17.

1.2 The Workspace owner is the controller and we are the processor for personal data contained in Client Data: the documents, knowledge, conversations, lessons, assessments, results and messages that a Workspace's users upload to or create in Y. The Workspace owner (for example your school, employer or club) decides why and how that data is processed and is responsible for informing its users. If you are a Named User and want to know how your organisation uses Y, ask your Workspace owner first. The processor terms that bind us are in section 12 of the Terms of Service, as Article 28(3) GDPR requires.

1.3 Independent controllers. Meta Platforms Ireland Limited (WhatsApp) and Microsoft Ireland Operations Limited (Microsoft 365 and Teams) are independent controllers for the data they process on their own platforms under their own privacy policies.

1.4 Resellers. If you bought Y through an authorised reseller, the reseller is an independent controller for the contact, contract and billing data it holds about you. Where the reseller administers your Workspace on your behalf, it acts on your instructions, not ours.

2 What we collect

CategoryExamplesSource
Identity and contact dataName, email address, mobile number (WhatsApp users), organisation, role, profile picture, preferred languageYou; your Workspace administrator; your Microsoft or Google sign-in provider
Account and security dataHashed password or sign-in provider identifier, multi-factor settings, session and refresh tokens, sign-in history, IP address, device and browserYou; generated by Y
Billing dataPlan, Credit purchases and balance, invoices, VAT number, billing address, payment token issued by our payment processor (we never hold your full card number)You; [PAYMENT PROCESSOR]
Client Data (we are processor)Documents and knowledge you upload, prompts and conversations, generated lessons, courses, images, audio and video, assessment answers and scores, connector data, WhatsApp and Teams messagesYou and your Workspace's users; systems your Workspace connects
Usage and telemetry dataFeatures used, Credits consumed per action, errors, performance metrics, interaction log (section 4.4)Generated by Y
Channel identifiersWhatsApp phone number and message identifiers; Microsoft Entra tenant and user identifiers; API key identifiersMeta; Microsoft; you
Support and communicationsEmails, support tickets, complaint correspondence, meeting notesYou
Voice dataAudio you record for voice questions or WhatsApp voice notes, and the transcriptYou

2.1 Special categories of personal data (Article 9 GDPR: health, religion, ethnic origin, sexual orientation, biometric data and similar) and data relating to criminal convictions (Article 10 GDPR) are not required to use Y. We do not collect them for our own purposes. If a Workspace owner puts such data into Client Data it must have a valid condition under Article 9(2) GDPR or the UAVG and must tell us so that we can apply appropriate settings.

2.2 You are not obliged to give us personal data, but without identity, contact and (for paid Plans) billing data we cannot provide an account or a contract.

3 Why we use it and our lawful bases

PurposeData usedLawful basis (Article 6(1) GDPR)
Create and manage your account; provide Y; authenticate you; deliver AI answers, lessons and contentIdentity, account, Client Data, usage(b) performance of a contract with you, or, where your organisation holds the contract, (f) our legitimate interest in providing the service your organisation asked for
Bill you, collect payment, issue invoices, prevent fraudIdentity, billing, usage(b) contract; (c) legal obligation under Dutch tax and accounting law; (f) legitimate interest in preventing fraud
Meter Credits and enforce Plan limitsUsage(b) contract
Keep Y secure; detect, investigate and prevent abuse and attacksAccount, security, usage, interaction log(f) legitimate interest in the security of our network and services (recital 49 GDPR); (c) legal obligation where security law applies
Provide support and respond to your requestsIdentity, support, relevant usage(b) contract; (f) legitimate interest in resolving your enquiry
Improve Y using aggregated, de-identified statisticsUsage (aggregated)(f) legitimate interest in improving our product; the output is not personal data
Send service messages (security alerts, billing notices, changes to terms)Identity(b) contract; (c) legal obligation
Send marketing about Y to existing customersIdentity(f) legitimate interest in marketing similar services to existing customers, in line with Article 11.7(3) of the Dutch Telecommunications Act; you can object at any time (section 14)
Send marketing to prospects and newsletter subscribersIdentity(a) your consent, which you can withdraw at any time
Comply with law, respond to lawful requests from authorities, establish or defend legal claimsAny(c) legal obligation; (f) legitimate interest in defending our rights
Business transfers (merger, acquisition, financing)Any, under confidentiality(f) legitimate interest in conducting our business

3.1 What we never do. We do not sell personal data. We do not use Client Data or your conversations to train AI models, ours or anyone else's. We do not show advertising in Y. Where we rely on legitimate interests we have carried out a balancing test, which you may request from our data protection contact.

4 AI features and AI model providers

4.1 Y sends your prompt, the passages retrieved from your Workspace that are relevant to it, and any file you attach to third-party AI model providers so that they can generate the answer, lesson, image, transcript or other output. The providers act as our sub-processors. The current providers are:

ProviderUsed forLocationTransfer mechanism
Anthropic PBCLanguage models (answers, tutoring, content generation, agents)United StatesStandard Contractual Clauses (Commission Decision (EU) 2021/914); EU-U.S. Data Privacy Framework where certified
OpenAI LLCEmbeddings for search, speech-to-text (Whisper), image generationUnited StatesStandard Contractual Clauses; EU-U.S. Data Privacy Framework where certified
OpenRouter IncRouting to additional language models for specific tasksUnited StatesStandard Contractual Clauses
Microsoft Corporation (Azure AI Speech)Text-to-speech and speech recognitionEuropean Union region where availableNot a transfer when processed in the EU; Microsoft Products and Services Data Protection Addendum otherwise

4.2 No training, limited retention. Our contracts with these providers prohibit them from using your content to train their models, limit retention to what is needed to return the output plus abuse monitoring of not more than 30 days, and require zero retention where offered. Providers receive only the content of each request, never your whole Workspace or your identity data.

4.3 Tenant isolation. Knowledge retrieved to answer a question comes only from your own Workspace and from knowledge explicitly shared with it. Content systems refer to people by identifier; names and contact details are held in a separate identity service.

4.4 Interaction log. We keep prompts, references to the context retrieved, tool calls and AI outputs for at least 12 months for security, billing, quality and dispute resolution. Workspace administrators can review conversation and agent history in the admin console; Named Users can see their own history.

4.5 Transparency. Every AI output carries the notice "Y uses AI and can make mistakes. Check important information.", and Y identifies itself as an AI system in WhatsApp and Teams conversations, as Article 50 of Regulation (EU) 2024/1689 (the AI Act) requires. AI output can be wrong; check it before relying on it.

5 Where your data is stored and international transfers

5.1 Storage in the EU. The Y platform, accounts, Client Data, search indexes, the interaction log and encrypted backups are hosted in Microsoft Azure data centres in the European Union (West Europe region, Netherlands), operated by Microsoft Ireland Operations Limited.

5.2 Transfers outside the European Economic Area. Some processing involves recipients in countries for which the European Commission has not adopted an adequacy decision, mainly the United States. In each case we rely on a Chapter V GDPR mechanism: the Standard Contractual Clauses adopted by Commission Decision (EU) 2021/914 under Article 46(2)(c), or the EU-U.S. Data Privacy Framework (Commission Decision (EU) 2023/1795) where the recipient is certified, together with a transfer impact assessment and supplementary measures such as encryption in transit, data minimisation and short retention. The transfers are:

  • AI inference by the providers in section 4, for the duration of each request and any permitted abuse-monitoring retention.
  • WhatsApp messages, which pass through Meta Platforms Ireland Limited and its affiliates, including Meta Platforms, Inc. in the United States, under Meta's Business Messaging terms and Meta's own transfer mechanisms.
  • Microsoft Teams messages, processed in the Microsoft 365 region of your own organisation's tenant, which may be outside the EU if your organisation chose that.
  • Published video assets (lesson videos) served from Cloudflare's global content delivery network so that they load quickly for viewers; the storage location is EU.
  • Payment processing by Stripe, which processes card data under PCI DSS; where it uses affiliates outside the EU it does so under its own Standard Contractual Clauses.

5.3 We will give Workspace owners at least 60 Business Days' notice before storing Client Data at rest outside the EU or adding a processing location outside the EU, and they may terminate if they do not accept the change (Terms of Service section 13.3). You can obtain a copy of the transfer safeguards we rely on from our data protection contact.

6 Who we share data with (sub-processors and recipients)

6.1 We use the following processors and sub-processors:

RecipientPurposeLocation
Microsoft Ireland Operations Limited (Azure)Hosting, databases, storage, key vault, email delivery (Azure Communication Services)European Union (Netherlands)
Anthropic PBC, OpenAI LLC, OpenRouter Inc, Microsoft (Azure AI Speech)AI model inference (section 4)United States; EU for Azure AI Speech where available
[PAYMENT PROCESSOR]Card and bank payments, payment tokens, recurring chargesEuropean Union
Cloudflare, Inc.Web security, content delivery, connector tunnels, video asset storage and deliveryGlobal network; EU storage
Meta Platforms Ireland LimitedWhatsApp Business messaging (independent controller for its own processing)Ireland; United States
Microsoft Ireland Operations Limited (Microsoft 365, Teams, Entra ID)Teams channel; Microsoft sign-in (independent controller for its own processing)Your tenant's region
Google Ireland LimitedGoogle sign-in (independent controller for its own processing)Ireland; United States

6.2 We give Workspace administrators at least 30 Business Days' notice before adding or replacing a sub-processor that processes Client Data, with a right to object and terminate (Terms of Service section 12.3). The current list is always available at this page.

6.3 Resellers receive the contact, contract and usage information needed to invoice and support the customers they serve, and administer a Workspace only where the customer has given them that role.

6.4 Your Workspace administrators can see the names, roles, activity and conversation history of the Named Users in their Workspace, as the Workspace owner's controller role allows.

6.5 Legal requirements. We disclose personal data to courts, regulators and law enforcement where EU or Dutch law requires it, and we challenge requests from authorities outside the EU that lack a basis in EU law (Article 48 GDPR).

6.6 Business transfers. If we merge, are acquired or sell assets, personal data may be transferred to the successor under confidentiality, and you will be notified of any change of controller.

7 WhatsApp, Microsoft Teams, connectors and the API

7.1 WhatsApp. When you message a Workspace's WhatsApp number, we receive your phone number, profile name, message content and media through Meta's Cloud API. We use them to identify your account, answer you and keep the conversation. Raw webhook payloads are deleted daily after processing. Meta's WhatsApp Business and consumer privacy policies apply to Meta's processing.

7.2 Microsoft Teams. We receive your Microsoft Entra user and tenant identifiers, display name and the messages you send to the Y app. Your organisation's Microsoft 365 administrator controls the app's permissions.

7.3 Connectors. Connectors read from, and where your Workspace allows it write to, systems your organisation connects through an agent it installs. Y accesses only what a Named User with the granted permissions asks for, and stores results only as part of that conversation.

7.4 API and MCP clients. API requests are logged with the key identifier, endpoint and timestamp for security and billing. Applications you connect are your responsibility.

8 Cookies

Y uses only strictly necessary cookies and local storage for sign-in, security and your display preferences, which Article 11.7a of the Dutch Telecommunications Act (implementing Article 5(3) of Directive 2002/58/EC) exempts from consent. We do not use analytics or advertising cookies. The Cookies Policy lists every cookie.

9 How long we keep data

DataRetention
Account and identity dataFor as long as your account exists, then deleted within 90 days of closure
Client DataFor the subscription plus the transition period (30 days, up to 90 under a Subscription Agreement), then deleted from live systems, and from backups within a further 90 days
Interaction log (prompts, context references, outputs)12 months, then deleted or de-identified
Trial WorkspacesDeleted 30 days after the trial ends without a subscription
Encrypted backups30 days, in the EU
Security and access logs12 months
WhatsApp raw webhook payloadsDeleted daily after processing
Invoices, payment records and VAT data7 years after the end of the financial year, as Article 52 of the Dutch General Tax Act (Algemene wet inzake rijksbelastingen) and Article 2:10 of the Dutch Civil Code require
Support correspondence3 years after the ticket is closed
Marketing consent recordsFor as long as you are subscribed, plus 3 years as evidence of consent
Data needed for a legal claimUntil the claim is resolved and limitation periods have expired

10 Security

We apply the technical and organisational measures Article 32 GDPR requires, taking account of the state of the art and the risks: encryption in transit (TLS 1.2 or higher) and at rest (AES-256); multi-factor authentication for our staff and available to every user; least-privilege, role-based access reviewed quarterly; tenant isolation at the retrieval and storage layers; identity data separated from content systems; secrets in a managed key vault; security logging retained 12 months; vulnerability remediation within 7, 30 and 90 days by severity; annual independent penetration testing; no Client Data in development or test environments; encrypted daily backups with restore tests every 6 months; staff confidentiality undertakings and training; and a documented incident response process. 

No system is perfectly secure; please use a strong, unique password and multi-factor authentication.

11 Personal data breaches

If a personal data breach is likely to result in a risk to your rights and freedoms, we notify the Autoriteit Persoonsgegevens within 72 hours of becoming aware of it, as Article 33 GDPR requires, and tell you without undue delay where the risk is high (Article 34 GDPR). Where the breach affects Client Data for which we are processor, we notify the Workspace owner within 24 hours so that it can meet its own duties. Report suspected security issues to [email protected].

12 Your rights

12.1 Under Articles 15 to 22 GDPR you have the right to:

  • access the personal data we hold about you and receive a copy (Article 15);
  • rectify inaccurate or incomplete data (Article 16); you can edit most profile data yourself in Settings;
  • erasure ("right to be forgotten") where the data is no longer needed, you withdraw consent, you object and we have no overriding grounds, or the processing is unlawful (Article 17);
  • restriction of processing while a dispute about accuracy or lawfulness is resolved (Article 18);
  • data portability: receive the data you provided to us in a structured, commonly used, machine-readable format and have it transmitted to another controller where technically feasible (Article 20); the export functions in Y provide this for your content;
  • object to processing based on legitimate interests, including profiling, and at any time to direct marketing (Article 21);
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Article 22; see section 15);
  • withdraw consent at any time where processing is based on consent, without affecting processing before withdrawal (Article 7(3)).

12.2 How to exercise them. Email [email protected] or write to the address in section 17. We may ask you to verify your identity. We respond within one month; where a request is complex or numerous we may extend by a further two months and will tell you why within the first month (Article 12(3) GDPR). Requests are free unless manifestly unfounded or excessive.

12.3 If your data is in Client Data controlled by a Workspace owner, we forward your request to the Workspace owner within 2 Business Days and help it respond, unless it has instructed us to handle such requests directly.

12.4 Complaints. You have the right to lodge a complaint with the Dutch supervisory authority: Autoriteit Persoonsgegevens, Postbus 93374, 2509 AJ Den Haag, telephone 088 1805 250, autoriteitpersoonsgegevens.nl, or with the supervisory authority of the EU Member State where you live or work (Article 77 GDPR). We would appreciate the chance to resolve your concern first.

13 Children

You must be 18 or older to create an account or place an order. Workspace owners such as schools and clubs may enrol younger learners. Where a learner is under 16, Article 8 GDPR and Article 5 UAVG require the consent of the holder of parental responsibility for any processing based on consent, and the Workspace owner is responsible for obtaining it or for relying on another lawful basis such as its public or educational task. We apply protective settings to Workspaces that tell us they include children, we do not market to children, and we delete data of a child who created an account without authorisation as soon as we learn of it.

14 Direct marketing

We send marketing about Y only 

(a) to existing customers about similar services, under Article 11.7(3) of the Dutch Telecommunications Act (Telecommunicatiewet), or 

(b) to others with your prior consent, as Article 11.7(1) of that Act and Article 13 of Directive 2002/58/EC require. 

Every marketing message contains an unsubscribe link, and you may object at any time by using it or by emailing [email protected]; we then stop within 5 Business Days. Service messages about your account, security or changes to our terms are not marketing and continue while you have an account.

15 Automated decision-making and profiling

Y uses automated processing to mark assessments, detect knowledge gaps, recommend content and classify questions. These are decision-support features. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. Where a Workspace owner uses Y's results to take such a decision about you (for example admission, certification or performance evaluation), the Workspace owner is the controller, must ensure human review and your right to contest the decision under Article 22(3) GDPR, and may be a deployer of a high-risk AI system under Annex III, point 3 of the AI Act. You may ask us or your Workspace owner for meaningful information about the logic involved.

16 Changes to this policy

We will notify account holders by email and in-app at least 30 days before a material change takes effect, and we publish the date of the latest version at the top of this page. Earlier versions are available on request.

17 Data protection contact and complaints

Controller:  Y-Institute

Chamber of Commerce (KvK): | VAT: 

Registered office:

Data protection contact: 

Email: [email protected]

Security: [email protected]

Telephone: 

Supervisory authority: Autoriteit Persoonsgegevens, Postbus 93374, 2509 AJ Den Haag, the Netherlands.