Privacy Policy
Last updated: 25 August 2026
Yaya Digital Limited ("Yaya", "we", "us") runs this website at yaya.co. This policy sets out exactly what we collect, what we run on the site, who else gets to see it, and how to make us stop.
We are a design studio, not a platform. There are no accounts on this site, nothing to log into, and no product telemetry. The data we hold about you comes from three places: a form you filled in, a cookie you consented to, and the server logs that any website generates by existing.
Data controller
Yaya Digital Limited, registered in England and Wales, company number 11954846. Registered office: Fifth Floor Suite 23, 63/66 Hatton Garden, London EC1N 8LE. Privacy contact: hello@yaya.co
1. What we collect
1.1 When you fill in a form
The contact form on /contact and the newsletter sign-ups in our page footers collect:
- Your name
- Your email address
- Your company, where the form asks for it
- Whatever you write in the message field
- Your marketing opt-in, where the form offers one
- The submit button you used, so we know which request you were making
We also process, transiently, the IP address the submission came from. It is used as a rate-limit key to stop bots hammering the form, and to run the spam check described in section 3. It is not stored against your enquiry.
Forms include a hidden field that humans never see and bots usually fill in. If it comes back filled, we discard the submission silently and write nothing anywhere.
1.2 When you register for a webinar or event
Event and webinar registrations are handled by Demio. Demio collects your name, email, and attendance data, and passes registration details to us. Demio's own privacy notice applies to the registration page.
1.3 When you just browse
Our hosting provider, Vercel, writes standard server logs for every request: IP address, timestamp, requested URL, referrer, user agent, and response status. This happens whether or not you accept cookies, because it is how a web server works and how we spot abuse.
If something on the site throws an error, our error monitor, Sentry, captures a report: the URL, the browser and operating system, a stack trace, and the IP the request came from. No form content is included.
1.4 Cookies and analytics
Google Analytics 4, loaded through Google Tag Manager, runs only if you accept statistics cookies in the consent banner. It records pages viewed, session data, coarse location derived from IP, device and browser, and our Core Web Vitals performance measurements.
The full list of cookies, with names and durations, is in our Cookie Policy.
We do not run advertising or retargeting pixels. There is no Meta pixel, no LinkedIn Insight tag, no Google Ads remarketing, no session replay, and no heatmapping on this site.
We self-host our typefaces. Loading a page on yaya.co does not send a font request to Google or anyone else.
2. Why we process it, and on what legal basis
| What | Why | Lawful basis (UK GDPR) |
|---|---|---|
| Contact form submissions | To answer your enquiry and, if it goes somewhere, to scope work | Art. 6(1)(b) steps prior to a contract, and Art. 6(1)(f) legitimate interest in responding to enquiries |
| Newsletter sign-ups | To send you the newsletter | Art. 6(1)(a) consent, plus PECR |
| Webinar and event registration | To run the event and follow up on it | Art. 6(1)(b) and Art. 6(1)(a) for any marketing follow-up |
| Server logs, rate limiting, spam checks | To keep the site up and keep bots out | Art. 6(1)(f) legitimate interest in security |
| Error reports | To find and fix broken pages | Art. 6(1)(f) legitimate interest in a working website |
| Analytics cookies | To see which pages earn their place | Art. 6(1)(a) consent, plus PECR reg. 6 |
Where we rely on legitimate interest, we have weighed it against your interests and rights. You can object at any time using the contact details above.
If you fill in the contact form we may email you about your enquiry. We will not add you to a newsletter because you asked us a question. Those are separate, and the newsletter opt-in is a separate unticked box.
3. Anti-spam
Form submissions pass through Cloudflare Turnstile, a privacy-focused alternative to CAPTCHA. Turnstile scores whether a submission is automated. It does not profile you across websites and does not ask you to identify traffic lights. Cloudflare processes your IP address and browser characteristics to produce that score.
We also apply a per-IP rate limit of five submissions a minute.
4. Who else sees your data
We do not sell personal data. We do not share it with data brokers. The processors below handle it on our instructions, under contract.
| Processor | What they do | Where |
|---|---|---|
| Vercel Inc. | Hosting and CDN. Our production region is London (lhr1) | US company, EU/UK infrastructure |
| Sanity AS | The CMS holding our page content and media | Norway, with global CDN |
| Google Ireland Ltd | Tag Manager and Analytics 4, consent-gated | EU and US |
| Usercentrics A/S (Cookiebot) | The consent banner and consent record | Denmark |
| Cloudflare Inc. | Turnstile spam prevention | US company, global network |
| Functional Software Inc. (Sentry) | Error monitoring | US |
| Slack Technologies (Salesforce) | Where new enquiries are notified to our team | US |
| Productive Tools d.o.o. | Where enquiries will be stored as we move off Slack notifications | Croatia, EU |
| Banzai International (Demio) | Webinar and event registration | US |
| Marker.io | A feedback widget that runs on our pre-release preview builds only, never on the public site | EU |
We will also disclose data where the law requires it, and to a buyer and their advisers if the business is sold. If that happens, this policy travels with the data.
5. International transfers
Several of the processors above are US-based. Where personal data leaves the UK, we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or on the UK extension to the EU-US Data Privacy Framework where the processor is certified under it. Ask us at hello@yaya.co and we will tell you which mechanism covers a specific transfer.
6. How long we keep it
| Data | Retention |
|---|---|
| Enquiries that did not become a project | 24 months from your last contact with us |
| Enquiries that became a project | For the life of the engagement plus 6 years, to meet UK accounting and limitation-period requirements |
| Newsletter subscription | Until you unsubscribe, plus a suppression record so we do not re-add you |
| Consent records (Cookiebot) | 12 months, matching the consent cookie |
| Server logs (Vercel) | Per Vercel's platform retention, currently around 30 days |
| Error reports (Sentry) | 90 days |
| Google Analytics event data | Up to 14 months |
7. Your rights
Under UK GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or hand it over in a portable format. You can object to processing based on legitimate interest, and you can withdraw consent at any time without affecting what we did before you withdrew it.
- Marketing: every newsletter has an unsubscribe link, and it works on the first click.
- Cookies: reopen the consent banner with the "Manage cookie preferences" link in the footer, on any page.
- Everything else: email hello@yaya.co. We will respond within one month.
If we get it wrong, you can complain to the Information Commissioner's Office at ico.org.uk, or on 0303 123 1113. We would rather you told us first.
8. Security
The site sets HTTP Strict Transport Security, so browsers only ever talk to us over TLS. We send X-Content-Type-Options: nosniff, a strict-origin-when-cross-origin referrer policy, and a permissions policy that switches off camera, microphone, geolocation, and Topics API access for the page. We operate a content security policy and monitor violations against it.
Our CMS API accepts browser requests only from an allow-list of our own origins: yaya.co, our Sanity Studio, our Vercel deployment aliases, and local development. Credentialed cross-origin requests are restricted to that list.
Secrets are held in a password manager and injected at deploy time. No API key for any system named in this policy is present in the code you download when you load a page.
No transmission over the internet is completely secure, and we will not claim otherwise. If we suffer a breach that risks your rights, we will report it to the ICO within 72 hours and tell you where the law requires it.
9. Children
This site is aimed at founders and marketing leaders at cybersecurity companies. It is not directed at children, and we do not knowingly collect data from anyone under 16. If you think we have, email hello@yaya.co and we will delete it.
10. Automated decision-making
We do not make automated decisions with legal or similarly significant effects about you. The Turnstile spam score decides whether a form submission is processed, not whether you get a reply from a person.
11. Changes
We update this policy when what we run on the site changes, not on a schedule. The date at the top is the last substantive change. If the change is material, we will say so on the page.
12. Contact
Yaya Digital Limited Fifth Floor Suite 23, 63/66 Hatton Garden, London EC1N 8LE Company number 11954846 hello@yaya.co