Last updated: 10 August 2026
Lyniti is the controller for account, billing, support, security, and service-usage data processed for its own purposes:
We may collect the following categories of data:
Lyniti is intended for business and organizational use and is not directed to children under 16.
Each purpose below is tied to its legal basis. For customer-controlled workspace content, Lyniti processes data under the customer's instructions and the customer determines the applicable legal basis:
Our specific legitimate interests are securing Lyniti and customer accounts, preventing fraud and misuse, maintaining reliable infrastructure, diagnosing and improving service performance, supporting users, managing disputes, and protecting or enforcing legal rights. We balance these interests against users' rights, minimize the data used, and honor the right to object where it applies.
We may generate aggregated, statistical, or de-identified usage analytics for service reliability and product planning. Optional analytics, session replay, and advertising measurement rely on consent and are not used by Lyniti for cross-site behavioral profiling.
We may share data with service providers, payment providers, other workspace members where collaboration requires it, and authorities when required by law. Data is primarily processed in the EU. If data is transferred outside the EU/EEA, we use appropriate safeguards.
Our infrastructure and service providers may include Hetzner for hosting, Cloudflare for delivery and security-related services, Resend for transactional emails, and Stripe for payments. We may update providers over time where needed to operate the service.
We keep personal data for as long as needed to operate the service, maintain workspaces, comply with law, resolve disputes, and enforce agreements.
Workspace content is generally stored while the workspace exists. If a workspace is deleted, related workspace data is deleted with it, subject to limited retention required for legal compliance, billing records, security logging, fraud prevention, dispute handling, and backup expiration. Different categories of data may be kept for different time periods depending on those needs.
Where technically feasible, users may export workspace data before deletion. Some residual copies may remain temporarily in backups until normal backup rotation expires.
Category-specific periods, deletion triggers, and backup windows are listed in the Trust Center retention schedule .
We use reasonable technical and organizational measures designed to protect personal data and workspace content, including access controls, encryption in transit, logging, and infrastructure security practices. However, no method of transmission or storage is completely secure.
Under GDPR, you may have the right to:
To exercise these rights, contact support@lyniti.com.
We do not currently use personal data for solely automated decision-making that produces legal or similarly significant effects.
We use cookies and similar browser storage for authentication, security, preferences, and service functionality. With consent, we use Umami analytics, strictly masked session replay for anonymous homepage visits, and Google Ads or Meta conversion measurement. Session replay masks all text and inputs and records only censored page structure and interactions such as pointer movement, clicks, scrolling, and navigation. See the Cookie Policy for exact storage names, providers, durations, and controls.
For privacy questions or complaints, contact support@lyniti.com.
You also have the right to lodge a complaint with the Finnish Data Protection Ombudsman.