Scope of this policy
This policy covers personal data we process as a controller: information about visitors to our website, people who contact us, and members of Lyhnis workspaces.
When your workflows process personal data - an invoice, a customer record, a document sent to OCR - we act as a processor on your instructions. That relationship is governed by our Data Processing Addendum, not by this policy.
Who we are
Lyhnis, Inc., a company registered in [jurisdiction] at [registered address], is the controller for the processing described here. Lyhnis is a product of Adopt Intelligence.
For data protection questions, write to privacy@lyhnis.com. [EU/UK representative, if appointed]
What we collect
Account and workspace data
Name, work email, hashed password or federated identity, MFA enrolment state, workspace name and role, and the members you invite.
Usage and diagnostic data
Pages viewed, features used, API request metadata, job counts, error traces, browser and device type, approximate location derived from IP, and authentication events including IP address - the last of which is also written to your audit ledger.
Billing data
Plan, seat count, invoices and billing contact. Card details are handled by our payment processor; we never see or store full card numbers.
Communications
Support tickets, sales enquiries, security reports and anything else you send us, along with our replies.
Why we use it
- To provide the platform - authenticate you, execute your workflows, enforce plan limits, and keep the audit ledger accurate.
- To secure it - detect abuse, investigate incidents, enforce MFA and step-up policies, and maintain the tamper-evident record.
- To support you - answer tickets and diagnose why a run behaved the way it did.
- To bill you - invoicing, dunning, tax compliance.
- To improve the product - aggregate feature usage and performance analysis. We do not use Customer Data to train foundation models.
- To communicate - service notices, release digests you subscribe to, and security advisories.
Legal bases
Where the GDPR or comparable law applies, we rely on: contract for providing and billing the service; legitimate interests for security, abuse prevention and product improvement; consent for non-essential analytics and marketing email; and legal obligation for tax, accounting and lawful requests.
Where we rely on consent you can withdraw it at any time, without affecting processing already carried out.
Sharing and subprocessors
We do not sell personal data and we do not share it for advertising. We share it with vendors who help us run the service - cloud hosting, payment processing, transactional email, error monitoring and support tooling - each bound by contract to process only on our instructions.
Our full subprocessor list, including what each one does and where it runs, is published and versioned. Material additions are announced at least 30 days in advance.
We may also disclose data where legally compelled, to enforce our terms, or in connection with a merger or acquisition - in which case we will notify you before your data becomes subject to a different policy.
International transfers
Your workspace is provisioned in a region you choose - EU (Frankfurt) or US (Virginia) - and Customer Data stays in that region, including backups. Controller-level data described in this policy may be processed in the United States by our vendors.
Where personal data leaves the EEA or UK we rely on Standard Contractual Clauses or an adequacy decision, together with encryption in transit and at rest, and we assess each transfer for supplementary measures.
How long we keep it
- Account data - for the life of the account, then 90 days after closure.
- Audit ledger entries - per your plan: 90 days on Starter through 7 years on Enterprise. The ledger is insert-only, so entries are not edited during that period.
- Billing records - 7 years, as required for tax and accounting.
- Support correspondence - 24 months.
- Diagnostic logs - 30 days, then aggregated or deleted.
Deletion requests are executed within 30 days and confirmed in writing, except where we are legally required to retain a record.
Security
Encryption in transit and at rest, per-tenant isolation applied at the query layer, credentials stored in an encrypted vault and never returned by an API read, MFA on every account, and step-up authentication before destructive actions.
Every action is written to a signed, insert-only ledger, which means an intrusion is reviewable rather than reconstructed. Details are on the security page; documentation is available on request from security@lyhnis.com.
Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to our processing, to receive your data in a portable format, and to withdraw consent. Members can access and correct most account data directly in the dashboard.
To exercise a right, write to privacy@lyhnis.com. We will respond within 30 days, and we will not discriminate against you for asking. If you are unsatisfied you may complain to your supervisory authority; we would rather you told us first.
If your request concerns data inside a customer workspace, we will refer you to that customer, who is the controller for it.
Cookies
We use a small number of cookies, and no advertising trackers. What they are and how to control them is set out in our Cookie Policy.
Children
Lyhnis is a business tool and is not directed at anyone under 16. We do not knowingly collect their data; if we learn that we have, we delete it.
Changes to this policy
We will post material changes here with a new effective date and version, and notify workspace administrators by email at least 30 days ahead where the change affects how we use existing data. Previous versions are available on request.