Privacy Policy
Yesepy ("Yesepy", "we", "us") provides a staff-budgeting platform at yesepy.com and app.yesepy.com (the "Service"). The Service is operated by IP Jeksenbi (individual entrepreneur), Almaty, Republic of Kazakhstan. This policy explains what personal data we collect, why, and how we handle it. We keep it short and honest – if anything is unclear, write to info@yesepy.com.
1. Data we collect
| Category | What | Why |
|---|---|---|
| Account data | Name, work email, password (stored only as a bcrypt hash – we never see or store the plain password) | Sign-in, account management, service emails |
| Workspace content | The budgeting data you enter: organisational structures, positions, headcount, salary figures, bonus and tax rules, uploaded actuals | Providing the Service – this is your data; we process it solely to run the product for you |
| Billing data | Subscription plan and payment status. Card details are collected and stored by our payment provider (Paddle), never by us | Managing your subscription |
| Waitlist / contact data | Email address and, optionally, name and company, plus the referring campaign (UTM) | Sending the invitation and product updates you asked for; unsubscribe anytime |
| Technical data | IP address and basic request logs | Security: rate limiting, abuse prevention, debugging |
We do not run advertising trackers, and we do not sell personal data to anyone.
Legal bases (GDPR Art. 6): performance of a contract – account, workspace content and billing data; legitimate interests (keeping the Service secure) – technical data; consent – waitlist and marketing emails, withdrawable at any time.
2. Your workspace content is yours
Salary and headcount data is sensitive. We treat everything you enter into a workspace as confidential customer data: we access it only to operate the Service, to fix a problem you have reported, or where the law requires. We never use your budgeting data for advertising, profiling, or training third-party models, and we never share it with other customers.
Controller and processor: for account, billing, waitlist and technical data, IP Jeksenbi is the data controller. For workspace content – the data you enter about your employees – your company is the controller, and Yesepy processes it only on your instructions as a processor. A data processing agreement is available on request at info@yesepy.com.
3. How data is protected
- All traffic is encrypted in transit (TLS/HTTPS).
- Data is stored in a managed PostgreSQL database encrypted at rest.
- Passwords are hashed with bcrypt; sessions use signed, expiring tokens.
- Every workspace is isolated: requests can only ever read or write data belonging to the authenticated workspace.
- Access to production systems is limited to authorised personnel on a least-privilege basis, protected by two-factor authentication.
No system is perfectly secure, and we will not pretend otherwise – but we apply industry-standard measures and review them regularly. If we ever become aware of a breach affecting your data, we will notify you within 72 hours of becoming aware.
4. Subprocessors
We use a small number of service providers to run Yesepy:
| Provider | Purpose |
|---|---|
| Railway (railway.com) | Application hosting and managed database |
| Paddle (paddle.com) | Payments and subscription billing (merchant of record) |
Application data is hosted on Railway in the United States. Where personal data crosses borders, we rely on appropriate safeguards, such as the EU Standard Contractual Clauses, where they are required.
5. Retention and deletion
Account and workspace data is kept while your account is active. You may request deletion of your account and all associated workspace data at any time by writing to info@yesepy.com; we delete it within 30 days, and backup copies expire within 90 days, except where we are legally required to retain billing records. Waitlist emails are deleted on unsubscribe.
6. Your rights
Depending on where you live (including under the GDPR), you have the right to access, correct, export, restrict, or delete your personal data, and to object to its processing. Write to info@yesepy.com and we will respond within 30 days. You also have the right to lodge a complaint with your local data-protection supervisory authority. You can also export your workspace data yourself at any time using the built-in Excel exports.
7. Cookies and local storage
The marketing site sets no tracking cookies. The application stores your session token and interface preferences (such as theme) in your browser's local storage – these are functional, not tracking.
8. Changes
If we change this policy in a way that matters, we will note the new effective date here and, for significant changes, notify account holders by email.
9. Contact
Yesepy · info@yesepy.com