Legal
Privacy notice
Full privacy notice for Yoyaku users, service providers, and visitors.
Last updated: 2026-05-16
Controller, processor, and scope
Yoyaku is a booking, scheduling, payments, reminders, and client-management platform for service providers. This notice explains how we handle personal data when someone visits the public site, creates an account, manages a workspace, or books with a provider using Yoyaku.
When a provider uses Yoyaku to store client or patient data, the provider usually decides the purposes of processing and Yoyaku acts as a processor or technology vendor. When Yoyaku manages accounts, billing, security, support, and its own communications, Yoyaku handles that data as a controller.
Personal data we may process
We may process identity and contact data such as name, phone, email, language, role, login data, workspace details, address, profile photo, and professional details published by the provider, including licenses, specialties, institutions, and COFEPRIS notice when applicable.
For bookings and clinical records, providers may record appointment data, services, notes, vitals, medical history, allergies, medications, diagnoses, treatment plans, attachments, images, or clinical documents. This data may be sensitive and must be used by providers under their professional and legal duties.
For payments, we may receive payment status, amounts, method, references, and subscription details. Full card data is processed by providers such as Stripe, Mercado Pago, or Clip; Yoyaku should not store full card numbers.
Purposes
We use data to create and manage accounts, publish booking pages, confirm appointments, show availability, prevent schedule conflicts, register clients or patients, store records when providers enable them, send reminders, process payments, prevent abuse, comply with legal obligations, provide support, and improve service security.
Vendors and transfers
We may share data with vendors needed to operate Yoyaku: AWS for infrastructure, database, and files; Stripe for subscriptions; Mercado Pago and Clip for patient payments when configured by a provider; Sentry for observability; Twilio or Meta/WhatsApp if real reminders are enabled; and email, DNS, or support providers added to the service.
We do not sell personal data. Transfers are limited to operating, protecting, billing, and supporting the service, or complying with valid legal requests.
Rights and contact
You can request access, correction, deletion, or objection by writing to [email protected]. If the request relates to patient or client data inside a provider workspace, we may direct it to the relevant provider because the provider usually controls that data.