Roles and relationship
This Addendum forms part of the Terms of Service between Lyhnis, Inc. ("Processor") and you ("Controller"). It applies whenever we process personal data on your behalf as part of providing the platform.
You determine the purposes and means of processing: which workflows exist, which data enters them, which activities run, which third parties are connected. We process only to provide the service and only on your documented instructions - the workflows you author being the primary instruction.
For data about your workspace members and your billing contact we are a controller, governed by our Privacy Policy. For data flowing through your workflows we are a processor, governed by this Addendum.
Scope and duration
Processing continues for the term of your subscription and for the deletion window described in §11. Annex I below sets out the categories of data subjects, categories of personal data, and the nature and purpose of processing.
You are responsible for having a lawful basis for the processing you instruct, for providing any notice your own data subjects require, and for not sending us special-category data unless your plan and configuration are appropriate for it.
Processing instructions
We will process personal data only as necessary to provide the platform, to comply with your documented instructions, and to meet our legal obligations. If we believe an instruction breaches data protection law, we will tell you and may suspend that processing.
We will not use personal data contained in Customer Data for our own purposes, and specifically will not use it to train foundation models or to build derived datasets. Aggregate operational telemetry we generate about platform performance does not contain Customer Data.
Confidentiality of personnel
Access to Customer Data is limited to personnel who need it to deliver or support the service. Those personnel are bound by written confidentiality obligations that survive their engagement, receive data protection training, and authenticate with MFA.
Support access to a customer workspace is time-boxed, requires a documented reason, and is itself written to the audit ledger - so you can see when we looked and why.
Security measures
We implement the technical and organisational measures described in Annex II, which include encryption in transit and at rest, per-tenant isolation enforced at the query layer, an encrypted credential vault whose secrets are never returned by an API read, MFA on all accounts, step-up authentication before destructive operations, and an insert-only signed audit ledger.
Measures may evolve, but we will not materially reduce the overall level of protection during your subscription. Current detail is on the security page.
Subprocessors
You authorise us to engage subprocessors to provide the platform. Each is bound by a written agreement imposing data protection obligations no less protective than those in this Addendum, and we remain liable for their performance.
The current list, including purpose and processing region, is published and versioned. We will notify workspace administrators at least 30 days before adding or replacing a subprocessor that processes Customer Data.
If you reasonably object to a new subprocessor on data protection grounds within that period, we will work with you on an alternative; if none is available you may terminate the affected service and receive a prorated refund of prepaid fees.
Data subject requests
The platform provides self-service means to search, export, correct and delete Customer Data, which in most cases lets you respond to a data subject without our involvement.
Where you cannot, we will provide reasonable assistance, at your cost where the effort is substantial. If a data subject contacts us directly about data we process for you, we will not respond substantively - we will refer them to you and tell you promptly.
Personal data breach
We will notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting Customer Data. Notification will describe the nature of the breach, the categories and approximate volume of data affected, likely consequences, and the measures taken or proposed.
We will provide the information you reasonably need to meet your own notification obligations, and will not delay notice pending complete investigation. Our notification is not an acknowledgement of fault.
International transfers
Customer Data is stored in the region you select at provisioning - EU (Frankfurt) or US (Virginia) - including backups. Support and engineering access may occur from other locations under the safeguards below.
Where personal data is transferred out of the EEA, UK or Switzerland, the parties rely on the Standard Contractual Clauses, incorporated by reference: Module Two (controller to processor) where you are a controller, and Module Three (processor to processor) where you are a processor for your own customer. The UK Addendum applies to UK transfers.
For the purposes of those clauses: Annex I is §13 below, Annex II is §14 below, the governing law and forum follow the Terms, and Clause 9 option 2 (general written authorisation) applies with the 30-day notice period in §06.
Audits and information rights
On reasonable written request, and no more than once a year unless required by a supervisory authority, we will provide the information necessary to demonstrate compliance with this Addendum, including current security documentation and answers to a reasonable security questionnaire.
Where that is genuinely insufficient for a mandatory audit, we will cooperate on a scoped on-site or remote audit under confidentiality, at your cost, arranged so it does not compromise other customers' data or platform security.
Return and deletion
You can export Customer Data at any time during your subscription through the dashboard and API - runs, ledger entries, files, communications and workflow definitions.
On termination we delete Customer Data within 30 days, except audit ledger entries retained for the statutory or plan-based retention period, and backups which age out on their normal cycle within 35 days. Retained data remains subject to this Addendum for as long as we hold it.
We will confirm deletion in writing on request.
Precedence and changes
If this Addendum conflicts with the Terms of Service, this Addendum controls for matters of personal data processing. If it conflicts with the Standard Contractual Clauses, the Clauses control.
We may update this Addendum to reflect legal or operational change, with 30 days notice for material changes, provided the update does not materially reduce your protections.
Annex I - processing details
Categories of data subjects
Your workspace members; and any individuals whose personal data appears in documents, records, messages or datasets your workflows process - typically your customers, employees, suppliers or applicants.
Categories of personal data
Determined by you. Commonly: names, contact details, employment or account identifiers, transaction and invoice data, document contents submitted to OCR or a model, message contents sent through notification activities, approval decisions and their attribution.
Special categories
Only if you choose to process them. You must configure appropriate controls, including human approval gates and restricted tool vocabularies, where you do.
Nature and purpose
Hosting, executing and durably pausing workflows; running agent loops within budgets; routing approval requests to named humans; storing files and artifacts with lineage; and recording every action in an insert-only audit ledger.
Duration
The subscription term plus the deletion and retention windows in §11.
Annex II - technical and organisational measures
- Access control. MFA on all accounts; SSO and SCIM available; role-based permissions; step-up authentication before destructive actions; scoped API keys with no global keys.
- Isolation. Tenant scope applied at the query layer, per-tenant storage prefixes, per-tenant credential key derivation and per-tenant ledger signing keys.
- Encryption. TLS in transit; encryption at rest; credential vault using authenticated encryption, with secrets decrypted only inside a worker for a single activity and redacted from all log sinks.
- Integrity. Insert-only audit ledger with no UPDATE or DELETE grant for the application role; entries signed and chained so removal is detectable on export.
- Resilience. Per-turn dispatch so runs survive worker loss, engine restarts and multi-day pauses; monitored worker health; backup and restore procedures with defined recovery objectives.
- Operational security. Change management and code review; dependency and vulnerability monitoring; documented incident response; time-boxed and logged support access.
- Personnel. Confidentiality agreements, background screening where lawful, data protection training and least-privilege provisioning tied to your directory where SCIM is enabled.