Y/DIRECTION · Privacy
What happens to what you tell us?
ماذا يحدث لما تُخبرنا به؟
A plain account of the little we collect, why we collect it, and how to get it back. No analytics, no advertising, no tracking you didn’t ask for — the only personal data we hold is what you choose to send us.
Last updated

On this page
The short version
If you read nothing else here, read this.
We built this site to start conversations, not to harvest data. There are no analytics, no advertising trackers, and no cookies that follow you around. The only personal information we hold is what you deliberately send us — through the form on Start, or by email.
We use it to reply to you and to keep the site safe from abuse. We don’t sell it, we don’t profile you, and we delete it once it’s no longer doing either of us any good. Everything below is the detail behind those three sentences.
Who’s responsible for your data
Y/DIRECTION, operating from Cairo as part of Da’er Al-A’mal.
The practice responsible for the personal data described here — the “data controller” — is Y/DIRECTION, the creative and strategy practice operating from Cairo as part of Da’er Al-A’mal. If you have a question about your data, or you want us to act on it, the fastest route is to email hello@ydirection.co.
This notice covers ydirection.co. Once we’re working together, a signed engagement agreement — and, where relevant, a separate data-processing agreement — governs how we handle anything you share inside a project. This page never overrides what we’ve signed.
What we collect
What you send through the form or by email — and the little your browser reveals.
When you book a discovery call through Start, we collect what you put in the form: your name and email, your company, an optional LinkedIn link, the question or brief on your mind, a rough budget band, and how you heard about us. If you email us instead, we have your address and whatever you write.
Like any website, ours also sees a few technical basics your browser sends with each request — your IP address and a user-agent string. We use the IP only in the moment, to rate-limit the form against spam, and we keep the user-agent alongside a submission to help us read it in context. None of this is used to build a profile of you.
Please don’t send sensitive personal information — health, beliefs, government IDs, and the like. We don’t need it to have a first conversation, and we’d rather you didn’t put it in a web form.
Why we use it
To reply, to talk, and to keep the site safe — nothing else.
We use what you send for three plain purposes: to read your message and reply; to have the conversation that follows and prepare for the discovery call; and to protect the site and other visitors from spam and abuse.
We don’t sell your data, share it with advertisers, or use it to target you anywhere else. There’s no automated decision-making and no profiling — a person reads what you send, and a person replies.
The legal basis, for those who want it
Consent for the conversation; a legitimate interest in keeping the site safe.
When you send us a brief or an email, we rely on your consent and on taking steps at your request before any agreement — you’ve reached out, and we’re responding. You can withdraw that consent at any time by asking us to delete what you sent.
For the security basics — rate-limiting, spam traps, server logs — we rely on our legitimate interest in keeping a small site online and unabused. We’ve kept that footprint deliberately light.
How long we keep it
While the conversation is live, and a reasonable while after — then it goes.
We keep what you send for as long as the conversation is active, and for a reasonable period afterwards in case it picks back up. If a thread plainly goes nowhere, we delete it. If it turns into a project, your data moves under the engagement agreement and is kept according to that.
You don’t have to wait for us. Ask us to delete what you sent and we will, unless we’re genuinely required to keep it.
How we protect it
Encrypted in transit, hardened against abuse, seen by the few who need it.
Everything you send travels over an encrypted connection. The form is hardened against spam and automated abuse, and access to what you send is limited to the few people who actually need it to reply.
No system is perfectly secure, and we won’t pretend otherwise. If something ever went wrong in a way that affected you, we’d tell you and the relevant authority as the law requires — plainly, and quickly.
Your choices and your rights
See it, correct it, delete it, or tell us to stop — just ask.
You can ask us what personal data we hold about you, correct it if it’s wrong, delete it, or tell us to stop using it. You can withdraw your consent at any time, and you can ask for a copy of what you sent. The way to exercise any of these is the same: email hello@ydirection.co, and we’ll act on it promptly.
If you think we’ve handled your data badly, we’d like the chance to put it right first — but you’re also entitled to complain to the data-protection authority where you live.
Children
This isn’t a site for children, and we don’t collect their data.
ydirection.co is a site for people choosing a creative and strategy partner — it isn’t directed at children, and we don’t knowingly collect data from them. If you believe a child has sent us something, tell us and we’ll delete it.
Changes to this notice
When it changes, the date at the top changes with it.
As the site and the practice evolve, we may update this notice. When we do, we change the date at the top of the page — that line is the version. If a change ever materially affects what we do with data you’ve already sent, we’ll take reasonable steps to tell you rather than rely on you noticing.
Want to see it, change it, or have it deleted?
Any question about your data — what we hold, why, or how to get it back — goes to the same place. Ask, and a person will answer. We’d rather settle it now than bury it in the fine print.
less to keep, less to lose.