Privacy

Personal Data Processing Policy

 

1. General provisions

 

This personal data processing policy has been drawn up in accordance with the requirements of the Singapore Personal Data Protection Act 2012 (hereinafter — the Personal Data Law) and defines the procedure for processing personal data and the personal data security measures taken by YESSA PTE. LTD., a company incorporated in Singapore (hereinafter — the Operator).

 

1.1. The Operator considers its most important goal and condition of its activities to be the observance of human rights and freedoms in the processing of personal data, including the protection of the rights to privacy, personal and family secrets.

 

1.2. This Operator's policy regarding the processing of personal data (hereinafter — the Policy) applies to all information that the Operator may obtain about visitors of the website http://yessa.app/.

 

2. Key terms used in the Policy

 

2.1. Automated processing of personal data — processing of personal data by means of computer technology.

 

2.2. Blocking of personal data — temporary suspension of the processing of personal data (except where processing is necessary to clarify personal data).

 

2.3. Website — the collection of graphic and informational materials, as well as computer programs and databases, that make them available on the internet at the network address http://yessa.app/.

 

2.4. Personal data information system — the collection of personal data contained in databases together with the information technologies and technical means that enable their processing.

 

2.5. Anonymization of personal data — actions as a result of which it becomes impossible, without the use of additional information, to determine that personal data belongs to a specific User or another personal data subject.

 

2.6. Processing of personal data — any action (operation) or set of actions (operations) performed on personal data with or without the use of automation, including collection, recording, systematization, accumulation, storage, clarification (updating, modification), retrieval, use, transfer (dissemination, provision, access), anonymization, blocking, deletion and destruction of personal data.

 

2.7. Operator — a legal entity or individual that, independently or jointly with other persons, organizes and/or carries out the processing of personal data, and determines the purposes of personal data processing, the scope of personal data to be processed, and the actions (operations) performed on personal data.

 

2.8. Personal data — any information relating directly or indirectly to an identified or identifiable User of the website http://yessa.app/.

 

2.9. Personal data permitted by the personal data subject for dissemination — personal data to which the personal data subject has granted access to an unlimited number of persons by giving consent to the processing of personal data permitted for dissemination (hereinafter — personal data permitted for dissemination).

 

2.10. User — any visitor of the website http://yessa.app/.

 

2.11. Provision of personal data — actions aimed at disclosing personal data to a specific person or a specific group of persons.

 

2.12. Dissemination of personal data — any actions aimed at disclosing personal data to an indefinite number of persons (transfer of personal data) or at making personal data available to an unlimited number of persons, including publishing personal data in mass media, posting it in information and telecommunication networks, or providing access to personal data in any other way.

 

2.13. Cross-border transfer of personal data — the transfer of personal data to the territory of a foreign state, to an authority of a foreign state, a foreign individual or a foreign legal entity.

 

2.14. Destruction of personal data — any actions as a result of which personal data is destroyed irretrievably, with no possibility of further restoring the content of the personal data in the personal data information system, and/or the physical media of the personal data are destroyed.

 

3. Principal rights and obligations of the Operator

 

3.1. The Operator has the right to:

 

— receive from the personal data subject accurate information and/or documents containing personal data;

 

— in the event that the personal data subject withdraws consent to the processing of personal data, or submits a request to cease the processing of personal data, continue processing the personal data without the subject's consent where grounds specified in the Personal Data Law exist;

 

— independently determine the composition and list of measures necessary and sufficient to ensure fulfilment of the obligations provided for by the Personal Data Law and the regulations adopted pursuant to it, unless otherwise provided by the Personal Data Law or other applicable law.

 

3.2. The Operator is obliged to:

 

— provide the personal data subject, at their request, with information concerning the processing of their personal data;

 

— organize the processing of personal data in the manner established by applicable law;

 

— respond to inquiries and requests from personal data subjects and their legal representatives in accordance with the requirements of the Personal Data Law;

 

— report the necessary information to the Personal Data Protection Commission of Singapore (PDPC), at that body's request, within the timeframes established by the Personal Data Law;

 

— publish this Policy on personal data processing or otherwise ensure unrestricted access to it;

 

— appoint a Data Protection Officer and make their contact details available;

 

— take legal, organizational and technical measures to protect personal data from unlawful or accidental access, destruction, modification, blocking, copying, provision, dissemination, as well as from other unlawful actions with respect to personal data;

 

— notify the personal data subjects and the PDPC of personal data breaches in the cases and in the manner provided for by the Personal Data Law;

 

— cease the transfer (dissemination, provision, access), cease the processing and destroy personal data in the manner and in the cases provided for by the Personal Data Law;

 

— perform other obligations provided for by the Personal Data Law.

 

4. Principal rights and obligations of personal data subjects

 

4.1. Personal data subjects have the right to:

 

— receive information concerning the processing of their personal data, except in cases provided for by applicable law. The information is provided to the personal data subject by the Operator in an accessible form and must not contain personal data relating to other personal data subjects, except where there are lawful grounds for disclosing such personal data. The list of such information and the procedure for obtaining it are established by the Personal Data Law;

 

— demand that the Operator clarify their personal data, block it or destroy it if the personal data is incomplete, outdated, inaccurate, unlawfully obtained or not necessary for the stated purpose of processing, and take measures provided by law to protect their rights;

 

— impose a condition of prior consent for the processing of personal data for the purpose of promoting goods, works and services on the market;

 

— withdraw consent to the processing of personal data and submit a request to cease the processing of personal data;

 

— lodge a complaint against unlawful actions or inaction of the Operator in the processing of their personal data with the Personal Data Protection Commission of Singapore (PDPC), with the data protection authority of their country of residence where applicable law so provides, or with a court;

 

— exercise other rights provided for by applicable law.

 

4.2. Personal data subjects are obliged to:

 

— provide the Operator with accurate information about themselves;

 

— inform the Operator of any clarification (updating, modification) of their personal data.

 

4.3. Persons who have provided the Operator with inaccurate information about themselves, or information about another personal data subject without the latter's consent, are liable in accordance with applicable law.

 

5. Principles of personal data processing

 

5.1. Personal data is processed on a lawful and fair basis.

 

5.2. The processing of personal data is limited to the achievement of specific, predefined and lawful purposes. Processing of personal data that is incompatible with the purposes of its collection is not permitted.

 

5.3. It is not permitted to combine databases containing personal data processed for purposes that are incompatible with each other.

 

5.4. Only personal data that meets the purposes of its processing is subject to processing.

 

5.5. The content and scope of the personal data processed correspond to the stated purposes of processing. The personal data processed must not be excessive in relation to the stated purposes of its processing.

 

5.6. In processing personal data, the accuracy of the personal data, its sufficiency and, where necessary, its relevance to the purposes of processing are ensured. The Operator takes the necessary measures, and/or ensures that they are taken, to delete or clarify incomplete or inaccurate data.

 

5.7. Personal data is stored in a form that makes it possible to identify the personal data subject for no longer than the purposes of processing require, unless a storage period for the personal data is established by applicable law or by a contract to which the personal data subject is a party, beneficiary or guarantor. The personal data processed is destroyed or anonymized once the purposes of processing have been achieved or if achieving those purposes is no longer necessary, unless otherwise provided by applicable law.

 

6. Purposes of personal data processing

 

Purpose of processing:

 

providing the User with access to the services, information and/or materials contained on the website.

 

Personal data:

 

email address;

 

date of birth, gender.

 

Legal grounds:

 

the Personal Data Law (Personal Data Protection Act 2012); the consent of the personal data subject; the agreement between the Operator and the User.

 

Types of personal data processing:

 

collection, recording, systematization, accumulation, storage, destruction and anonymization of personal data;

 

sending informational emails to the email address.

 

7. Conditions of personal data processing

 

7.1. Personal data is processed with the consent of the personal data subject to the processing of their personal data.

 

7.2. Personal data processing is necessary to achieve the purposes provided for by applicable law, or to perform the functions, powers and duties imposed on the Operator by applicable law.

 

7.3. Personal data processing is necessary for the administration of justice, or the execution of a judicial act or an act of another body or official subject to enforcement in accordance with applicable law.

 

7.4. Personal data processing is necessary for the performance of a contract to which the personal data subject is a party, beneficiary or guarantor, as well as for the conclusion of a contract at the initiative of the personal data subject or a contract under which the personal data subject will be a beneficiary or guarantor.

 

7.5. Personal data processing is necessary for the exercise of the rights and legitimate interests of the Operator or third parties, or for the achievement of socially significant goals, provided that the rights and freedoms of the personal data subject are not violated.

 

7.6. Processing is carried out of personal data to which access has been granted to an unlimited number of persons by the personal data subject or at their request (hereinafter — publicly available personal data).

 

7.7. Processing is carried out of personal data subject to publication or mandatory disclosure in accordance with applicable law.

 

8. Procedure for the collection, storage, transfer and other types of personal data processing

 

The security of the personal data processed by the Operator is ensured through the implementation of the legal, organizational and technical measures required for full compliance with the applicable legislation on personal data protection.

 

8.1. The Operator ensures the safekeeping of personal data and takes all possible measures to prevent access to personal data by unauthorized persons.

 

8.2. The User's personal data will never, under any circumstances, be transferred to third parties, except in cases related to compliance with applicable law, or where the personal data subject has given the Operator consent to transfer data to a third party for the performance of obligations under a civil-law contract.

 

8.3. If inaccuracies in the personal data are identified, the User may update it themselves by sending the Operator a notice to the Operator's email address help@yessa.app marked "Update of personal data".

 

8.4. The period of personal data processing is determined by the achievement of the purposes for which the personal data was collected, unless a different period is provided for by a contract or applicable law.

The User may withdraw their consent to the processing of personal data at any time by sending the Operator a notice by email to the Operator's email address help@yessa.app marked "Withdrawal of consent to the processing of personal data".

 

8.5. All information collected by third-party services, including the Patreon and Boosty platforms, communication tools and other service providers, is stored and processed by those parties (operators) in accordance with their User Agreement and Privacy Policy. The User undertakes to review those documents independently. The Operator is not responsible for the actions of such third parties. Data is transferred to those parties to the extent necessary for the purposes defined by this Policy, the Operator's User Agreement and/or the law.

 

8.6. Prohibitions established by the personal data subject on the transfer (other than the provision of access) of personal data permitted for dissemination, as well as on its processing or the conditions of its processing (other than obtaining access), do not apply where the personal data is processed in state, public or other public interests defined by applicable law.

 

8.7. In processing personal data, the Operator ensures the confidentiality of the personal data.

 

8.8. The Operator stores personal data in a form that makes it possible to identify the personal data subject for no longer than the purposes of processing require, unless a storage period for the personal data is established by applicable law or by a contract to which the personal data subject is a party, beneficiary or guarantor.

 

8.9. The processing of personal data may be terminated upon achievement of the purposes of processing, expiry of the personal data subject's consent, withdrawal of consent by the personal data subject or a request to cease the processing of personal data, as well as upon the discovery of unlawful processing of personal data.

 

9. List of actions performed by the Operator on the personal data obtained

 

9.1. The Operator carries out the collection, recording, systematization, accumulation, storage, clarification (updating, modification), retrieval, use, transfer (dissemination, provision, access), anonymization, blocking, deletion and destruction of personal data.

 

9.2. The Operator carries out automated processing of personal data, with or without the receipt and/or transfer of the obtained information via information and telecommunication networks.

 

10. Cross-border transfer of personal data

 

10.1. The Operator carries out cross-border transfers of personal data provided that the recipient of the personal data ensures a standard of protection comparable to the requirements of the Personal Data Law, including on the basis of contractual safeguards, as required by the transfer limitation obligation of the Personal Data Law.

 

10.2. Cross-border transfer of personal data is carried out to the extent necessary for the purposes defined by this Policy.

 

11. Confidentiality of personal data

 

The Operator and other persons who have obtained access to personal data are obliged not to disclose the personal data to third parties or disseminate it without the consent of the personal data subject, unless otherwise provided by applicable law.

 

12. Final provisions

 

12.1. The User may obtain any clarification on matters of interest concerning the processing of their personal data by contacting the Operator by email at help@yessa.app. This address is the contact of the Operator's Data Protection Officer.

 

12.2. Any changes to the Operator's personal data processing policy will be reflected in this document. The Policy is valid indefinitely until replaced by a new version.

 

12.3. The current version of the Policy is freely available on the internet at https://en.yessa.app/privacy.

 

13. Data related to support via third-party platforms (Boosty, Patreon)

 

The User may support the Operator through third-party platforms — by taking out a paid support subscription or making a one-off contribution. Depending on the tier, support may include access to additional content on the relevant platform.

 

13.1. Data the Operator does not process.

The Operator does not receive or store the full details of the User's payment instruments (card number, expiry date, CVC, etc.). Such data is processed by the Patreon and/or Boosty platforms in accordance with their privacy policies and terms of use.

 

13.2. Data the Operator may receive from the platforms:

a) the user's identifier on the platform, public name/nickname;

b) email address (if it is transferred by the platform and the User has consented to such transfer);

c) support details: subscription type/tier/plan, frequency and status (subscription/one-off contribution), amount and currency, date and status of transactions (without payment instrument details);

d) technical metadata provided by the platform (for example, billing country), where required for reporting and legal compliance.

 

13.3. Purposes of processing such data:

a) providing the User with access to content and other benefits associated with the relevant support tier;

b) communications regarding support (service notifications, responses to inquiries);

c) analytics and statistics on the operation of the Service;

d) fulfilment of the Operator's legal obligations (accounting and tax records, responses to requests from authorized bodies).

 

13.4. Legal grounds for processing:

performance of a contract (providing access to content and other benefits), the Operator's legitimate interest (ensuring security and analytics), legal obligation (record-keeping and document retention). Publication of a name in the list of supporters and the sending of marketing communications are carried out only on the basis of the User's separate consent.

 

13.5. Transfer to third parties:

data may be transferred to the Operator's service providers (hosting, analytics, accounting), as well as to the Patreon/Boosty platforms as independent data operators. Cross-border transfer is possible; the Operator ensures the necessary legal safeguards for such transfer in accordance with applicable law.

 

13.6. Retention periods:

support-related information is stored for the period necessary to achieve the stated purposes and fulfil the Operator's obligations (as a rule, 5–7 years for financial/accounting data), unless a longer period is required by law. Marketing data is stored until consent is withdrawn.

 

13.7. Marketing:

the fact of taking out support does not in itself constitute consent to receive marketing communications. Subscription to the newsletter requires separate consent (opt-in) and may be withdrawn at any time.

 

13.8. Platform policies:

when support is taken out, the documents of the relevant platform apply (its Privacy Policy and Terms of Use/User Agreement), as published on the relevant platform's website:

— Patreon — Privacy Policy, Terms of Use;

— Boosty — Privacy Policy, User Agreement.

 

14. Personal data processing in the mobile application

 

14.1. The provisions of this Policy apply in full to the processing of personal data of users of the Yessa mobile application (hereinafter — the App). The terms used in this Policy with respect to the website and its visitors apply to the App and its users accordingly.

 

14.2. When the User uses the App, the Operator processes the same categories of personal data as on the website (email address, date of birth, gender), and additionally:

 

a) technical device data: device model, operating system version, App version and build number, device language;

 

b) de-identified information about the use of the App (interaction events, including story playback events) and technical App installation identifiers, which do not by themselves make it possible to identify the User;

 

c) the device token used to deliver push notifications;

 

d) subscription status information received from Apple: subscription type, period and status — without payment details.

 

14.3. Analytics. The Operator uses Google Firebase Analytics to collect de-identified statistics on the use of the App. The relevant data is processed by Google in accordance with its Privacy Policy and Terms of Service; the User undertakes to review those documents independently. Cross-border transfer of such data is possible; the Operator ensures the necessary legal safeguards for such transfer in accordance with applicable law.

 

14.4. Subscription and payments. Paid subscriptions in the App are processed through Apple's in-app purchase mechanism (App Store). The Operator does not receive or store the full details of the User's payment instruments (card number, expiry date, CVC, etc.); such data is processed by Apple in accordance with its Privacy Policy and terms of use. The User manages and cancels the subscription in the settings of their Apple account.

 

14.5. Push notifications. Push notifications are sent only with the User's permission granted via the operating system prompt. The User may disable push notifications at any time in the device settings, in which case the processing of the device token for the purpose of sending notifications ceases.

 

14.6. Retention and deletion of data. Personal data associated with the User's account is stored until the account is deleted. The User may delete the account directly in the App (Profile → "Delete account") or by sending a request to the Operator's email address help@yessa.app. After the account is deleted, personal data is destroyed or anonymized within no more than 30 days, except for data whose further retention is required by law (including the information referred to in clause 13.6 of this Policy). De-identified analytics data may be retained in aggregated form that does not make it possible to identify the User.

 

Last updated: 05.08.2026