Legal
Privacy policy
Effective date: 24 August 2024
Last updated: 18 July 2025
This is a translation of the Spanish original, provided for convenience. In the event of any discrepancy between language versions, the Spanish version prevails.
1. Introduction and Information about the Data Controller
1.1 Data controller
- Company name: Yeshcube Tech, S.L.
- Tax ID (CIF): B21900543
- Registered office: C. de la Travesía, SN, Poblados Marítimos, 46024 Valencia, Spain
- Commercial Registry: Commercial Registry of Valencia, Volume [S 8], Sheet [V 225222], Entry [I/A 1 (23.04.25)]
- Contact email: hello@yeshcube.com
- Data Protection Officer (DPO): legal@yeshcube.com
- Website: https://yeshcube.com
1.2 Our privacy commitment
At Yeshcube Tech, S.L. we respect and prioritize the privacy of our users and visitors. This Privacy Policy explains how we collect, use, protect and share your personal data when you visit our website, use the yesh app, or interact with Vesta-powered experiences, in accordance with:
- Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR)
- Spanish Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD)
- Law 34/2002 on Information Society Services and Electronic Commerce (LSSI-CE)
2. Scope
This Privacy Policy applies to all personal data processing activities carried out by Yeshcube Tech, S.L. on the following platforms and services:
2.1 Digital platforms
- Corporate website: https://yeshcube.com and all its subdomains
- Mobile application: “yesh app” for emotional wellbeing (iOS and Android)
- Web applications and interactive platforms
2.2 Immersive experiences
- Experiences with the Vesta AI system across all interfaces
- Qyos³ immersive booths and physical installations
- VVAVVE™ sensory devices and wearable technology
- Any future authorized interface or hardware device
2.3 Business services
- Customer support and technical assistance
- Corporate consultancy services
- Commercial and marketing communications
- Newsletters and informational content
3. Categories of Personal Data We Collect
3.1 Identification and contact data
- Full name and preferred name
- Email address
- Postal address (where required for service delivery)
- Age or date of birth (for age verification)
- Country and preferred language
3.2 Account and authentication data
- Username and password (encrypted)
- User preferences and settings
- Account creation and last access dates
- Two-factor authentication information
- Device identifiers for security purposes
3.3 Technical and usage data
- IP address and geolocation (city/country level)
- Browser type, version and operating system
- Device model, screen resolution and capabilities
- Pages visited, time spent and browsing patterns
- Referring website and search terms
- Session duration and interaction history
- Error reports and performance data
3.4 Communications and support data
- Customer service inquiries and responses
- Form submissions and feedback
- Chat logs and support ticket history
- Survey responses and participation in user research
3.5 Commercial and subscription data
- Subscription status and billing information
- Payment method information (processed by external providers)
- Purchase history and transaction records
- Promotional codes and discount usage
3.6 Biometric and emotional wellbeing data (special categories)
IMPORTANT: This data is only collected with your explicit, specific consent when you choose to use optional biometric devices.
- Physiological data: Heart rate, heart rate variability, breathing patterns
- Activity data: Movement patterns, sleep quality indicators (when shared)
- Emotional state indicators: Stress levels, relaxation metrics (derived from physiological data)
- Voice patterns: Tone, rhythm and emotional indicators (when voice interactions are used)
- Interaction preferences: Preferred experience types, session duration
Collection methods:
- Wearable devices (rings, sensors) – only when explicitly enabled by the user
- Voice analysis during interactions with Vesta – with separate consent
- Self-reported wellbeing and mood data – provided voluntarily
4. Legal Basis for Processing
We process your personal data on the following legal bases under article 6 GDPR:
4.1 Consent (Article 6.1.a GDPR)
- Newsletter subscriptions and marketing communications
- Collection of biometric and emotional wellbeing data
- Optional features and advanced personalization
- Participation in user research and surveys
4.2 Performance of a contract (Article 6.1.b GDPR)
- Creation and management of user accounts
- Service delivery and app functionality
- Subscription and billing management
- Customer support and technical assistance
4.3 Legal obligation (Article 6.1.c GDPR)
- Compliance with tax and accounting requirements
- Responding to law enforcement requests
- Age verification for minors (LOPDGDD requirements)
- Security breach notification obligations
4.4 Legitimate interest (Article 6.1.f GDPR)
- Website security and fraud prevention
- System performance monitoring and improvement
- Analytics to improve the service
- Business development and strategic planning
4.5 Special categories of data (Article 9 GDPR)
For biometric and health-related data, we rely on:
- Explicit consent (Article 9.2.a GDPR): Free, specific and informed consent for the processing of biometric data
- Substantial public interest (Article 9.2.g GDPR): Where applicable for wellbeing research and improvement
5. Purposes of Processing
5.1 Core service provision
- Account creation, authentication and management
- Delivery of yesh app functionality and Vesta experiences
- Content personalization and recommendations
- Progress tracking and session history
- Cross-device synchronization
5.2 Technical operations
- System security and access control
- Performance monitoring and optimization
- Error detection and resolution
- Software updates and maintenance
- Data backup and recovery
5.3 Customer relationship management
- Customer support and technical assistance
- Handling inquiries and complaints
- Collecting and analyzing user feedback
- Community management and engagement
5.4 Business development
- Service improvement and new feature development
- Market research and user behavior analysis
- Quality assurance and testing
- Strategic planning and business intelligence
5.5 Marketing and communications
- Sending newsletters and personalizing content
- Promotional campaigns and special offers
- Educational content and wellbeing tips
- Event invitations and company updates
5.6 Compliance and legal matters
- Regulatory compliance and reporting
- Legal proceedings and dispute resolution
- Supporting audits and regulatory inspections
- Age verification and parental consent management
6. Data Sharing and Third-Party Recipients
We do not sell, rent or trade your personal data with third parties. Data sharing only occurs in the following circumstances:
6.1 Service providers and processors
We may share data with trusted service providers under strict data processing agreements (Article 28 GDPR):
- Cloud hosting providers: For secure data storage and application hosting
- Payment processors: For subscription and purchase management
- Analytics services: For usage analysis and service improvement
- Customer support tools: For efficient support ticket management
- Email service providers: For sending newsletters and transactional emails
- Security services: For fraud detection and prevention
6.2 Legal and regulatory requirements
- Law enforcement agencies (with valid legal requests)
- Regulatory authorities (for compliance purposes)
- Courts and judicial proceedings
- Tax authorities (for tax obligations)
6.3 Business transfers
In the event of a merger, acquisition or asset sale, personal data may be transferred as part of the business assets, with appropriate notice and safeguards.
6.4 Emergency situations
In exceptional circumstances, to protect the vital interests of users or prevent imminent harm, we may share relevant data with emergency services or healthcare providers.
6.5 Allies Network: data that crosses between partner organizations
The Allies private area is a network between partner organizations, so there is data that one organization sees about another. What crosses is bounded and decided case by case:
-
Network record. An organization appears in the network only if it authorizes it, and it authorizes field by field what is shown about it: logo, description, partner roles, capabilities, fields of work, territories, working languages, what it brings, what it is looking for, the projects yeshcube has published and a contact person with their name and role. Presence stays off until it is authorized.
-
No personal email address circulates through the network. The network record does not show one, and contact between two organizations stays inside the channel of the system.
-
Connections. A connection request carries the name of the organization requesting it, the object it refers to —a need, an offer or a project— and the reason in writing. The connection requires acceptance by both organizations, and until both are on record no channel opens between them.
-
Channels. A project channel is read by the organizations taking part in it, within the scope of their participation; a channel between two organizations is read by those two. Each message carries the name of whoever writes it, their organization, the text, the attachments and the date.
-
Access by yeshcube to a channel between two organizations. This is not ordinary. It requires a reason in writing, expires within an hour and is recorded together with the person who opened it and their reason.
-
Individual profile. A person with an Allies account may publish their photograph, a profile cover, their role, a short biography, their fields of knowledge, their working languages and verifiable professional links (ORCID, institutional page, LinkedIn). Each of those fields is authorized separately and is switched off until it is authorized, with three degrees: their organization only, the organizations with an accepted connection, or any Allies account. What is not authorized does not leave their organization.
-
The photograph and the cover are re-encoded on the server before being stored, so the metadata of the original image — including geolocation where present — is not kept. The images are not published on the site: they live outside the public directory and are served through an access point that checks the session and the authorization before returning them.
-
The legal basis for the individual profile is their consent (Article 6.1.a GDPR), given by filling in each field and authorizing its visibility, and withdrawn by clearing the field or withdrawing the authorization. Withdrawing it does not affect their access to the area or their participation in projects.
-
Erasure. The photograph, the cover and the biography are erased when the person removes them, when they close their account and when their organization ceases to be an Allies partner; no copy is kept. What is kept is what sustains a project record and the obligations of the collaboration agreement: who wrote a message, who signed the confidentiality undertaking, who submitted or reviewed a document, and the dates of all of it. Those records carry the name and email address of the account, not the profile, and their legal basis and retention period are those of section 8.
The legal basis for this processing is performance of the collaboration agreement with the partner organization (Article 6.1.b GDPR) for what sustains the shared project, legitimate interest in the operation of the network (Article 6.1.f GDPR) for the network record and the connections, whose visibility the organization turns on and off by itself, and the person’s consent (Article 6.1.a GDPR) for their individual profile.
7. International Data Transfers
7.1 Transfer policy
We do not routinely transfer personal data outside the European Economic Area (EEA). Our main data processing takes place within the EU/EEA.
7.2 Safeguards for international transfers
Where transfers outside the EEA are necessary, we ensure adequate protection through:
- Adequacy decisions: Transfers to countries recognized by the European Commission as providing adequate protection
- Standard Contractual Clauses (SCCs): EU-approved contractual safeguards with external processors
- Binding Corporate Rules: For transfers within multinational organizations
- Certification schemes: Where available and appropriate
7.3 User rights regarding international transfers
You have the right to:
- Be informed about international transfers
- Obtain copies of the safeguards in place
- Object to transfers in certain circumstances
8. Data Retention Periods
8.1 General retention principles
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, taking into account:
- Legal and regulatory requirements
- Contractual obligations
- User preferences and duration of consent
- Legitimate business needs
8.2 Specific retention periods
Account and service data:
- Active user accounts: For the duration of the service relationship
- Inactive accounts: 2 years after the last activity, then anonymised
- Deleted accounts: 30-day retention for recovery, then permanent deletion
Allies Network data:
- Network record of an organization: for as long as the organization keeps it authorized
- Connections between organizations, with their reason: duration of the collaboration agreement + 5 years
- Closed channels and their messages: the retention period configured in the system, counted from the last message
- Record of exceptional accesses to a channel: with the audit log
Communication and support data:
- Customer support records: 3 years after the case is resolved
- Marketing communications: Until consent is withdrawn
- Newsletter subscriptions: Until you unsubscribe
Financial and commercial data:
- Billing and payment records: 6 years (Spanish accounting law)
- Tax information: 4 years (Spanish tax law)
- Contractual information: Duration of the contract + 5 years
Technical and analytics data:
- Usage logs: 12 months, then anonymised
- Security logs: 2 years
- Error reports: 6 months
Biometric and emotional data:
- Raw biometric data: Processed immediately and deleted within 24 hours
- Aggregated information: 12 months or until consent is withdrawn
- Voice recordings: Deleted within 48 hours unless the user explicitly saves them
8.3 Automated deletion
Retention periods are enforced by automated deletion and anonymisation routines, reviewed periodically.
9. Your Rights under the GDPR and the LOPDGDD
9.1 Right of access (Article 15 GDPR)
You have the right to:
- Know whether we process your personal data
- Access your personal data and receive a copy
- Receive information about processing purposes, recipients and retention periods
- Receive details about the source of the data (if not collected directly from you)
9.2 Right to rectification (Article 16 GDPR)
- Correct inaccurate personal data
- Complete incomplete personal data
- Update outdated information
9.3 Right to erasure – “right to be forgotten” (Article 17 GDPR)
You can request deletion of your data when:
- The data is no longer necessary for the original purpose
- You withdraw consent and no other legal basis applies
- The data has been processed unlawfully
- Deletion is necessary to comply with a legal obligation
9.4 Right to restriction of processing (Article 18 GDPR)
You can request restriction when:
- You contest the accuracy of the data (during verification)
- Processing is unlawful but you prefer restriction to deletion
- We no longer need the data but you need it for legal claims
- You have objected to processing (pending verification of legitimate grounds)
9.5 Right to data portability (Article 20 GDPR)
- Receive your data in a structured, machine-readable format
- Transfer the data to another service provider
- Applies to data processed on the basis of consent or contract
9.6 Right to object (Article 21 GDPR)
- Object to processing based on legitimate interests
- Object to direct marketing at any time
- Object to automated decision-making and profiling
9.7 Right to withdraw consent
- Withdraw consent at any time for consent-based processing
- Withdrawal does not affect the lawfulness of processing before it
- Easy-to-use withdrawal mechanisms
9.8 Rights regarding automated decision-making (Article 22 GDPR)
- Not to be subject to decisions based solely on automated processing
- Obtain human intervention in automated decisions
- Express your point of view and contest decisions
9.9 How to exercise your rights
To exercise any of these rights:
- Email: hello@yeshcube.com or legal@yeshcube.com
- Postal mail: C. de la Travesía, SN, Poblados Marítimos, 46024 Valencia, Spain
- In-app requests: Through the yesh app settings (for certain rights)
Response time: We respond within one month of receiving your request (extendable to 3 months for complex requests).
10. Specific Processing for Vesta Experiences
10.1 Types of interaction with Vesta
When you interact with Vesta through any interface (web, app, Qyos³ booths, VVAVVE™ devices), we may process:
- Interaction metadata: Session duration, preferred experience types, time of day of use
- Voice data: Analysis of tone, rhythm, emotional indicators (with separate consent)
- Response patterns: How you engage with guided experiences
- Preference learning: Personalization data for future sessions
10.2 Processing of biometric data
Explicit consent required: Biometric data is only collected when:
- You have explicitly enabled biometric sensors
- You provide separate, specific consent for each type of data
- You are using optional devices (rings, wearables)
Processing characteristics:
- Real-time processing for immediate experience personalization
- No permanent storage of raw biometric data
- Aggregated (anonymised) information only
- Secure local processing wherever possible
10.3 Voice processing
- Purpose: Analysis of emotional tone and natural interaction
- Processing: Real-time analysis, immediate deletion of recordings
- Consent: Separate consent required for voice processing
- Control: You can disable voice processing at any time
10.4 Anonymisation and privacy protection
- Personal identifiers removed from experience data
- Aggregation techniques to prevent re-identification
- Strict application of the data minimisation principle
- Regular data purge protocols
10.5 No medical or therapeutic claims
Important disclaimer: Vesta is designed for wellbeing and relaxation only. We do not:
- Provide medical diagnoses or therapeutic treatment
- Store data for medical purposes
- Share data with healthcare providers (except in emergencies)
- Make health-related recommendations
11. Minors and Parental Consent
11.1 Age requirements
- Minimum age: 14 years
- Ages 14 to 17: Parental consent required
- Age 18 and over: Independent consent
11.2 Parental consent process
For users aged 14 to 17, we require:
- Verified parental consent before the account is created
- A parent’s email address for ongoing communication
- The ability for parents to access and control the minor’s data
- Regular renewal of consent
11.3 Enhanced protection for minors
- No biometric data is collected for users under 16
- Simplified privacy controls
- Regular review of consent status
- Priority support for parental inquiries
11.4 Parental rights
Parents or guardians may:
- Access their child’s personal data
- Request the correction or deletion of data
- Withdraw consent on their child’s behalf
- Control data-sharing preferences
12. Data Security Measures
12.1 Technical safeguards
- Encryption: AES-256 encryption at rest and TLS 1.3 in transit
- Access controls: Role-based access with multi-factor authentication
- Network security: Firewalls, intrusion detection and monitoring
- Secure development: Regular security code reviews and testing
- Data backup: Encrypted, geographically distributed backups
12.2 Organizational measures
- Staff training: Regular privacy and security training for all employees
- Access limitations: Need-to-know access
- Incident response: Documented procedures for security breaches
- Vendor management: Security assessments for all external providers
- Regular audits: Internal and external security audits
12.3 Physical security
- Secure data centers with 24/7 monitoring
- Restricted physical access to servers
- Environmental controls and redundancy
- Secure hardware disposal
12.4 Security breach procedures
In the event of a security breach, we will:
- Notify the Spanish Data Protection Agency (AEPD) within 72 hours
- Inform affected users without undue delay where there is a high risk
- Provide clear information about the breach and mitigation measures
- Implement immediate containment measures
- Carry out a thorough investigation and report
13. Cookies and Tracking Technologies
13.1 Use of cookies
We use cookies and similar technologies for:
- Essential website functionality
- Storing user preferences
- Security and authentication
- Analytics and performance monitoring
- Personalization and user experience
13.2 Cookie categories
- Strictly necessary cookies: Required for basic website operation
- Functional cookies: Remember your preferences and settings
- Analytics cookies: Help us understand how you use our services
- Marketing cookies: Used for targeted advertising (with consent)
13.3 Cookie control
You can control cookies through:
- Our cookie consent banner
- Browser settings
- Account preferences
- Opt-out links for specific services
For more information, see our Cookie Policy.
14. Marketing and Communications
14.1 Email marketing
We may send you marketing emails if you have:
- Explicitly consented to receive marketing communications
- Purchased our services (soft opt-in for similar services)
- Requested information about our services
14.2 Types of communication
- Transactional emails: Service updates, billing, security alerts
- Newsletters: Company news, feature updates, wellbeing content
- Promotional emails: Special offers, event invitations
- Educational content: Tips, guides and resources
14.3 Opt-out rights
You can opt out of marketing communications:
- Using the unsubscribe link in every email
- Updating preferences in your account settings
- Contacting us at hello@yeshcube.com
- Replying “STOP” to text messages (where applicable)
14.4 Communication preferences
You can control:
- Types of communication
- Frequency of communications
- Communication channels (email, app notifications)
- Language preferences
15. Data Complaints and Supervisory Authority
15.1 Internal complaints process
If you have concerns about our data processing:
- Contact us at legal@yeshcube.com
- We will acknowledge your complaint within 48 hours
- The investigation will be completed within 30 days
- You will receive a written response with our findings and the actions taken
15.2 Supervisory authority
You have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD):
- Website: www.aepd.es
- Address: C/ Jorge Juan, 6, 28001 Madrid, Spain
- Telephone: 901 100 099 / 912 663 517
- Electronic register: Available on their website
15.3 European Data Protection Board
For cross-border matters, you may also contact the European Data Protection Board at www.edpb.europa.eu.
16. Changes to this Privacy Policy
16.1 Policy updates
We may update this Privacy Policy to reflect:
- Changes in applicable laws and regulations
- New features or services
- Better data protection practices
- User feedback and requirements
16.2 Notice of changes
For significant changes, we will notify you through:
- Email notification to registered users
- A prominent notice on our website
- In-app notifications
- An updated “Last modified” date in this policy
16.3 Continued use
Continued use of our services after notification constitutes acceptance of the updated Privacy Policy. If you do not agree with the changes, you may:
- Contact us to discuss your concerns