Yep.to! Privacy Policy
Version: 1.1
Effective date: 2026-09-10
1. Controller and contact details
The controller of personal data processed in connection with yep.to and the interested list is:
Yep.to! Sp. z o.o. w organizacji
a Polish limited liability company in organisation
ul. Jana Kantego Federowicza 5/43
30-392 Kraków, Poland
email: hello@yep.to
No KRS or NIP number has yet been assigned because the company is still in organisation. The identification details will be updated after registration and assignment of the relevant numbers.
For questions about personal data, consent withdrawal, objections, deletion requests or reports that an email address has been used without permission, contact hello@yep.to.
The interested List is a B2B service intended for contact connected with business or professional e-commerce activity. This does not mean that no personal data are processed: an address may belong to an individual entrepreneur, employee, contractor or another natural person acting on behalf of or for an entrepreneur.
2. Data we process
The data involved depends on how the website is used.
2.1. Joining the interested list
We may process:
- email address;
- selected language (
ploren); - current contact status, such as active, unsubscribed, administratively blocked or sending-blocked;
- server-generated sign-up time in UTC;
- form source and a technical event or sign-up-cycle identifier;
- information about how the submission was made;
- the version and reproducible wording of the purpose/consent notice shown at sign-up;
- the versions of the Terms and Privacy Policy applicable at sign-up and the ability to reproduce their content;
- history of unsubscriptions, re-sign-ups and blocks, including time, justified reason and — for manual actions — identification of the authorised operator;
- technical email-send status, attempt time, safe message identifier, error category and the relevant sign-up cycle.
In the base model we do not attach an IP address or user-agent identifier permanently to the interested-list profile and do not treat either as a universally required “proof of consent”.
2.2. Unsubscribing
The unsubscribe flow uses a high-entropy random token. The database stores a secure hash of that token. The raw token is not intended to be written to application logs or sent to analytics.
2.3. Website and form security
For security purposes we may process technical data for a short period, including:
- source IP address or a pseudonymised/HMAC identifier used for rate limiting;
- timestamps, operation identifiers and result categories;
- basic request headers and metadata needed for origin validation, abuse prevention and diagnostics;
- limited server, hosting, application-error and CRON execution logs.
Application logs are not intended to contain full form requests, passwords, Turnstile secret keys, unsubscribe tokens or full email bodies unless genuinely necessary.
2.4. Cloudflare Turnstile
The form is protected by Cloudflare Turnstile. The current configuration uses Managed mode with pre-clearance disabled. Turnstile may process technical signals needed to distinguish human traffic from automation, including IP address, browser/environment information, user-agent, TLS signals, origin/site-key information and results of technical challenges.
We do not provide the email-field content to Turnstile as form data. Our server validates the Turnstile token with Cloudflare; in the data-minimising setup the application does not submit the optional remoteip parameter.
2.5. Cloudflare DNS and web proxy
Traffic to the public website passes through Cloudflare as the DNS/web-proxy and security layer. This involves technical processing of data such as IP addresses, HTTP headers, connection data and information needed to deliver and protect traffic. Cloudflare may use strictly necessary security mechanisms, including — depending on the protection features actually enabled — technical challenge or bot-protection cookies.
2.6. Cloudflare Web Analytics
For the initial release, Cloudflare Web Analytics/RUM is disabled completely. The website does not load the Web Analytics beacon and does not use browser-based RUM to measure Polish or other traffic.
Any later enablement of Web Analytics/RUM requires a new legal and technical assessment, an update to this Policy and — where the mechanism is to operate for a user in circumstances requiring consent — prior consent before the script is loaded.
2.7. Correspondence with hello@yep.to
If a user contacts us directly, we process the data contained in the message, its headers and subsequent correspondence to the extent needed to answer, fulfil a request, handle a complaint, exercise data rights or investigate an abuse report.
3. Purposes and legal bases
| Purpose | Data | GDPR basis | Additional basis / note |
|---|---|---|---|
| Accepting and maintaining List membership as a free B2B service | email, language, sign-up status, event data | Art. 6(1)(b) GDPR where the person requests the service in connection with their own business; Art. 6(1)(f) GDPR where the person acts on behalf of or for an entrepreneur, based on the legitimate interest in handling the requested B2B contact | an email address is necessary to provide the List service |
| Sending updates about Yep.to! development and future access, questions about business needs and possible testing invitations | email, language, current consent status | Art. 6(1)(a) GDPR — consent | Polish Electronic Communications Law (PKE) Art. 398 also applies; the scope is shown before form submission |
| Informational confirmation of successful sign-up | email, language, sign-up event | Art. 6(1)(b) or (f) GDPR, depending on the person's role in the B2B relationship | operational message confirming the recorded sign-up; it does not verify ownership of the mailbox |
| Demonstrating what consent covered and how it was obtained; handling withdrawal, objection and potential claims | consent history, exact notice, document versions, times, unsubscriptions, blocks | Art. 6(1)(f) GDPR — legitimate interests in accountability, defence of claims and respecting user instructions | we keep only data needed for those purposes |
| Protecting the form, infrastructure and email systems against abuse, fraud and automated traffic | IP/pseudonymised identifier, request metadata, security logs, Turnstile | Art. 6(1)(f) GDPR — security and abuse prevention | for device-level mechanisms strictly necessary to provide the requested service, the statutory exception in PKE Art. 399(3) may apply |
| Maintaining a suppression/block after unauthorised sign-up reports, explicit objection, complaint or permanent delivery failure | minimum address identifier, block status and reason | Art. 6(1)(f) GDPR — respecting requests and preventing renewed unwanted contact | the block is not a basis for further marketing |
| Handling messages, requests and complaints | correspondence and contact data | Art. 6(1)(b), (f) or (c) GDPR depending on the matter | data are limited to what the matter requires |
We do not rely on legitimate interests to circumvent a consent requirement for commercial electronic communications or non-essential access to information on a user's device.
4. How consent to email contact is given and withdrawn
- Before the form is submitted, the user is shown the specific purposes of future contact: Yep.to! development and future-access updates, possible questions about business needs and possible testing invitations.
- The user knowingly enters an email address and selects “Dołącz do listy” / “Join the list”. In that context, providing the address is the affirmative action expressing consent to the described electronic contact.
- We do not require a mandatory checkbox or a second activation click. Single opt-in does not mean that mailbox ownership is treated as verified.
- We keep a reproducible record of when the sign-up occurred, in which language and against which wording.
- Consent can be withdrawn at any time just as easily by using the unsubscribe link in an email or by writing to hello@yep.to.
- Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
5. What happens after an unsubscribe or objection
- An ordinary unsubscribe stops further correspondence under the current sign-up cycle and cancels unsent retries belonging to that cycle.
- After an ordinary unsubscribe, the same address may be signed up again through the public form unless an administrative block applies. A re-sign-up creates a new consent event and does not erase the historical fact of the earlier unsubscribe.
- A clear report that an address was entered without its owner's permission or an explicit objection to further direct marketing may result in an administrative block. The public form cannot remove such a block.
- After withdrawal or objection, we may retain the minimum event/block record on a separate legal basis where needed to demonstrate proper handling, defend claims or prevent renewed unwanted contact.
6. Where the data comes from
Normally, data come directly from the person using the form or contacting us.
Because single opt-in does not verify mailbox ownership, another person could enter an email address belonging to someone else. In that situation, the first message sent to the address explains that a sign-up was recorded, provides an easy unsubscribe method and explains how to report unauthorised use. Where GDPR Article 14 requires information because data were obtained from another source, it is provided no later than the first communication.
7. Recipients and processors
Data may be disclosed only to the extent needed for the purposes described above:
- dhosting.pl Sp. z o.o. — provider of web hosting, MariaDB infrastructure, initial SMTP transport, logs and backups. A data-processing agreement has been entered into for the account used by the service. Actual processing locations, subprocessors, provider retention and any transfers are determined by the current agreement and dHosting documentation and are checked during configuration.
- Cloudflare, Inc. — provider of DNS/web proxy, security and Turnstile. For services it performs on our behalf, Cloudflare operates under its Data Processing Addendum. Cloudflare's Turnstile documentation also states that it processes certain signals as an independent controller for security and service-improvement purposes. Web Analytics/RUM is not an active service in this release.
- Authorised persons acting within Yep.to! Sp. z o.o. w organizacji whose access is limited to what is required to maintain the List, handle messages, maintain security and exercise data-subject rights.
- Public authorities or other recipients where disclosure is required by law or needed to establish, exercise or defend legal claims.
Google Workspace is not described as an active email processor for this release. A later production-mail migration will require an updated provider/transfer assessment and an update to this Policy before the processing is switched.
8. Cloudflare and device information
8.1. No traditional cookies does not decide whether consent is needed
Polish Electronic Communications Law covers more than cookies: it also regulates storing information on, and gaining access to information already stored on, a user's terminal equipment. Each mechanism is therefore assessed by how it actually works, not by the label “cookie-free”.
8.2. Turnstile
Turnstile protects the specific sign-up function requested by the user against automated abuse. The selected setup uses Managed mode and does not enable pre-clearance / cf_clearance solely for the form. We treat operations strictly necessary for Turnstile security as part of the security needed to provide the requested sign-up service, rather than analytics or marketing.
Before publication, the live website and Cloudflare settings must be checked to confirm that no additional features have been enabled that create non-essential identifiers or require separate consent.
8.3. Proxy and technical security cookies
Cloudflare proxy and protection mechanisms may use technical measures required to deliver or secure a request. If a challenge cookie or similar identifier appears in the live setup, its actual function and purpose will be checked. We do not automatically classify every Cloudflare mechanism as “necessary” merely because it is supplied by a security provider.
8.4. Web Analytics/RUM
For the initial release, Cloudflare Web Analytics/RUM is disabled completely. No analytics beacon is loaded, and no analytics-consent banner is needed solely for this disabled tool.
Enabling Web Analytics/RUM in the future is a change to the processing model and requires prior configuration review, legal assessment and an update to this Policy.
9. Transfers outside the EEA
- Cloudflare services may involve processing outside the European Economic Area, including in the United States.
- Cloudflare's current Data Processing Addendum (v6.4, effective 3 April 2026) provides transfer mechanisms that include — as applicable — the EU-U.S. Data Privacy Framework adequacy route and Standard Contractual Clauses (SCCs) for restricted transfers that require such safeguards.
- Commission Implementing Decision (EU) 2023/1795 concerning the EU-U.S. Data Privacy Framework was shown by EUR-Lex as being in force when this Policy was last verified. The applicable transfer mechanism and provider status should be re-checked following material service changes.
- For dHosting, actual processing locations, subprocessors and any transfers are determined by the current processing agreement and provider documentation. We do not state either that a transfer outside the EEA occurs or that none occurs without support in those materials.
10. Retention
There is no single statutory retention period for all interested-list data. We apply purpose-based storage limitation:
- Active List address: until consent is withdrawn, the List service ends, or the purpose for which the address was collected ends — whichever occurs first. The relevance of the active list is reviewed periodically.
- Evidence of consent, unsubscription and material status changes: after active contact ends, retained in a minimum form for 3 years, provided that retention is still necessary for accountability, respecting user instructions or the defence of claims.
- Suppression/block after objection, abuse report or permanent delivery failure: the minimum information required to avoid renewed contact is retained while the List or corresponding communication channel remains active and there is a real need to honour the block; it is then reviewed for accountability and claims purposes.
- Short-lived anti-spam counters: only for the rate-limit window plus a small technical buffer needed to enforce it.
- Minimised application error logs: for 14 days.
- Provider/security logs: according to the actual configured retention and provider terms, no longer than needed for security, diagnostics and accountability.
- Backups: for the period resulting from the actually configured dHosting backup rotation, limited to what is needed for recovery from failure and aligned with the adopted backup policy. The exact rotation is confirmed operationally before public sign-up is opened. Restoring a backup must not by itself reactivate withdrawn consent, remove a block or restart cancelled email sending.
- Correspondence: for as long as needed to handle the matter and, where justified, for a further period needed to document its handling or defend claims.
11. Your rights
Subject to the conditions in the GDPR, a person has the right to:
- access their data and obtain a copy;
- rectify their data;
- erasure;
- restriction of processing;
- data portability where GDPR Article 20 applies;
- withdraw consent at any time;
- object, on grounds relating to their particular situation, to processing based on legitimate interests;
- object at any time to processing for direct-marketing purposes — after such an objection, we no longer process the data for that purpose;
- lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych — PUODO).
Requests can be sent to hello@yep.to. We respond without undue delay and generally within one month, subject to the extensions allowed by the GDPR.
Using the unsubscribe link is the simplest way to stop future correspondence, but it does not limit any other GDPR right.
12. Whether data must be provided
Providing an email address is voluntary, but it is necessary if the user wants to use the B2B List service and receive the described correspondence. We do not require a name, company name, telephone number or survey answers at initial sign-up.
13. Automated decision-making and profiling
We do not make decisions about people on the List that produce legal effects or similarly significantly affect them solely by automated means. Turnstile and security rate limits automatically assess individual submissions to protect the form, but they are not used to assess a person's commercial value or create a marketing profile.
14. Security
We select security measures according to risk. The current design includes HTTPS, Cloudflare web proxy/protection, Turnstile, server-side validation, rate limiting, parameterised database queries, separated privileges, keeping secrets outside the public directory, restricted administrative access, backups and logging of key operational events without unnecessary duplication of personal data.
This description is not a guarantee that incidents can never occur and does not claim any certification that we do not hold.
15. Changes to this Policy
We will update this Policy when the actual processing changes, including changes to providers, purposes, data categories, analytics configuration or website scope. A material change to this Policy does not by itself expand a consent previously given for marketing or electronic contact.
Changes that require particular review include company registration, migrating production email to Google Workspace, enabling Web Analytics/RUM or other trackers, extending the List beyond the accepted B2B model, launching a survey that collects new data, or moving from the landing page to the SaaS application.
Privacy contact: hello@yep.to
Controller: Yep.to! Sp. z o.o. w organizacji, ul. Jana Kantego Federowicza 5/43, 30-392 Kraków, Poland.