Skip to main content
Yao Dao

Privacy

Last updated: September 2026

Data controller

Yao Dao AD — VAT ID: BG208909878
Simeonovsko Shose 85, Sofia 1700, Bulgaria
Email: contact@yao-dao.com

What personal data do we collect?

We collect the following categories of data:

  • Identification data: surname, first name, email address, telephone number, postal address, login credentials.
  • Professional data (therapists only): identity documents and qualifications in Traditional Chinese Medicine, VAT number.
  • Order data: order history, delivery address.
  • Communication data: messages exchanged with us by email.
  • Technical data: date and time of your last login, server logs — collected automatically by our systems.

Why and on what legal basis do we process your data?

Each processing activity relies on a legal basis under Article 6 of the General Data Protection Regulation (GDPR):

  • Performance of a contract (Art. 6(1)(b)): processing your order, delivery, invoicing, managing your account, sending transactional emails related to your order (order summary, confirmation, tracking). These communications are an integral part of the service and cannot be disabled.
  • Legal obligation (Art. 6(1)(c)): retention of invoices and accounting data in accordance with applicable tax obligations.
  • Consent (Art. 6(1)(a)): sending commercial communications (offers, news, courses and training related to Traditional Chinese Medicine). These communications are only sent if you have given your consent. You may withdraw your consent at any time via the unsubscribe link in each email.
  • Legitimate interest (Art. 6(1)(f)): fraud prevention, site security, improvement of our services.

Who receives your data?

Your data may be shared with the following recipients, strictly to the extent necessary for the purposes described above:

  • Internal departments of Yao Dao: customer service, accounting, order preparation.
  • Shipping providers: DHL, Colissimo and other carriers depending on the destination.
  • Payment providers: PayPal, SystemPay, Stripe. These providers process your payment data under their own privacy policies.
  • Hosting: our servers and data are hosted in France (European Union).

We do not sell or rent your personal data to third parties.

Data transfers outside the European Union

Your data is primarily processed within the European Union. If a transfer to a third country is necessary (for example through a payment provider), it is safeguarded under the provisions of the GDPR: an adequacy decision by the European Commission or standard contractual clauses.

Retention periods

We retain your data for the following periods:

  • Account data: as long as your account is active. Upon a deletion request, your account and personal data (name, email, phone, address) are deleted within 30 days. If your account has associated orders, your personal details are anonymised instead, and the order and invoice records are retained as required by law (see below).
  • Order data and invoices: at least 10 years from the close of the accounting year, in accordance with legal accounting obligations, and for as long as necessary for the management of potential claims. This data cannot be deleted before the end of the applicable retention period, even upon request.
  • Technical data (server logs): less than 12 months.

Your rights

Under the GDPR, you have the following rights:

  • Right of access (Art. 15): obtain a copy of your personal data.
  • Right to rectification (Art. 16): correct inaccurate or incomplete data.
  • Right to erasure (Art. 17): request the deletion of your data, subject to our legal retention obligations.
  • Right to restriction of processing (Art. 18): request that we suspend the processing of your data in certain circumstances.
  • Right to data portability (Art. 20): receive your data in a structured, commonly used and machine-readable format.
  • Right to object (Art. 21): object to processing based on legitimate interest. For direct marketing, you may object at any time and without giving a reason.
  • Withdrawal of consent: withdraw your consent at any time for processing based on it, without affecting the lawfulness of processing carried out before the withdrawal.

To exercise your rights, write to us at contact@yao-dao.com. We will respond within one month.

You also have the right to lodge a complaint with the Commission for Personal Data Protection (CPDP) of Bulgaria:
2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria — www.cpdp.bg

Automated decisions

We do not use automated processing that produces legal or similarly significant effects on you. No profiling is carried out.

Cookies

Our use of cookies is described in our cookie policy.

Security

We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss, destruction or alteration: encrypted connections (HTTPS), restricted data access, regular backups.

Changes to this policy

This policy may be updated. In the event of a substantial change, we will inform you by email or by a visible notice on the site. The date of the last update is shown at the top of this page.