Legal

Data Processing Policy

1. Purpose

This Data Processing Policy describes the general principles YunoTK follows when handling personal information in connection with its website, enquiries and professional services.

It complements the YunoTK Privacy Policy. It does not replace any data-processing terms that may be required for a particular client engagement.

2. Data processing principles

YunoTK seeks to handle personal information according to purpose limitation, data minimization, accuracy, limited retention, security and confidentiality, transparency and accountability.

Tools, permissions and providers should be selected and managed with appropriate consideration for privacy and security.

3. Website enquiries

For website enquiries, YunoTK requests only name, email address and the visitor's request or message. The handling, purposes, retention period and rights relating to this information are described in the YunoTK Privacy Policy.

4. Client information

A professional engagement may require YunoTK to receive or access information that is not collected through YunoTK.com. Depending on the agreed service, this could include client-provided content, communications, brand materials, account access or information necessary to prepare, manage or publish authorized content.

This section does not mean that YunoTK automatically collects these categories from website visitors. The information actually required for a client project should be determined by the agreed scope of work.

5. Client-controlled information

In some engagements, YunoTK may work within accounts, systems or platforms controlled by a client. Where a client determines why and how personal information is processed and YunoTK handles that information only to perform the agreed service, the respective responsibilities may differ from those applicable to information YunoTK collects for its own purposes.

YunoTK intends to act within the authorized scope, follow documented client instructions where applicable, avoid using client-controlled information for unrelated purposes, limit access to what is reasonably necessary, and return, remove or discontinue access when reasonably appropriate after the engagement ends.

6. Account access and permissions

When a service requires access to a client's platform or account, YunoTK seeks to use the least level of access reasonably sufficient to perform the agreed work. Where supported by the platform, dedicated user access, roles or delegated permissions are preferable to unnecessary sharing of primary credentials.

Access should be reviewed when responsibilities change and removed when it is no longer reasonably necessary.

7. Service providers

YunoTK may use technology providers reasonably necessary to operate its website or deliver contracted services. Providers should be selected with consideration for purpose, security, privacy, access controls, data location or international processing where relevant, contractual protections where appropriate, and the amount and sensitivity of information involved.

8. International processing

Because YunoTK operates remotely and may work with clients and platforms in different countries, information may in some circumstances be processed across national borders. Where applicable law imposes specific requirements on an international transfer, appropriate measures should be considered according to the processing involved.

9. Security

YunoTK seeks to use reasonable technical and organizational safeguards appropriate to the information and activity involved. These may include restricted account access, strong authentication, appropriate role-based permissions, secure connections, limited collection, provider and permission reviews, and removal of obsolete access.

No technical system can provide an absolute guarantee of security.

10. Retention and deletion

Information should be retained only for as long as reasonably necessary for its purpose, subject to contractual, operational and applicable legal requirements.

Website leads that do not develop into an ongoing professional relationship are governed by the 30-day retention rule described in the Privacy Policy. Client and project information may require different retention periods depending on the service, agreement, accounting requirements, disputes, legal obligations or legitimate business needs.

11. Data incidents

If YunoTK becomes aware of unauthorized access, loss, disclosure or another material security incident involving personal information under its control, YunoTK will assess the circumstances and take reasonable steps to contain and address the incident.

Where applicable law or a client agreement requires notification, YunoTK will follow the applicable notification requirements.

12. Individual rights

Requests concerning information collected directly by YunoTK may be sent to contact@yunotk.com. Where a request concerns information controlled by one of YunoTK's clients, the individual may need to contact that client directly.

13. Changes

This Policy may be updated as YunoTK's services, systems, providers or processing activities change.

Necessary / security

Always active where required to deliver or protect the website.

Required

Optional analytics

Not currently used.

Disabled

Optional advertising

Not currently used.

Disabled

Optional behavioural or cross-site tracking

Not currently used.

Disabled