Privacy PolicyTerms of ServiceCookie Policy

© 2026 Lyniti. All rights reserved.

Privacy Policy

Last updated: 10 August 2026

1. Controller

Lyniti is the controller for account, billing, support, security, and service-usage data processed for its own purposes:

  • Service: Lyniti
  • Operator: Lyniti - Finland, Helsinki
  • Location: Finland, Helsinki
  • Email: support@lyniti.com

Controller and processor roles

  • Lyniti acts as controller for account registration, authentication, billing, support, security, legal compliance, and service-usage data that Lyniti determines how and why to process.
  • For personal data contained in customer workspace content, the customer or organization that controls the workspace generally acts as controller and Lyniti acts as processor on that customer's documented instructions.
  • The customer is responsible for selecting a lawful basis, giving required notices, and managing data-subject requests for workspace content. Our Data Processing Agreement and Trust Center describe Lyniti's processor obligations.

2. Data We Collect

We may collect the following categories of data:

  • Account information
  • Authentication and login-related data
  • Workspace content
  • Uploaded files and attachments
  • Messages, comments, and collaboration data
  • Device, browser, and service usage metadata
  • Billing and contact details if you use paid features
  • Support communications

Lyniti is intended for business and organizational use and is not directed to children under 16.

3. Why We Use It

Each purpose below is tied to its legal basis. For customer-controlled workspace content, Lyniti processes data under the customer's instructions and the customer determines the applicable legal basis:

Create accounts, authenticate users, and provide requested service features.
Contract - GDPR Article 6(1)(b). Processing is necessary to enter into or perform the service contract with you.
Process subscriptions, payments, invoices, and plan administration.
Contract and legal obligation - Articles 6(1)(b) and 6(1)(c). We process payment and account data to perform paid plans and retain required tax and accounting records.
Answer support requests and diagnose reported problems.
Contract - Article 6(1)(b); legitimate interests - Article 6(1)(f) for service improvement and dispute handling. Support access to workspace content occurs only when necessary, authorized, or otherwise legally permitted.
Protect accounts and infrastructure, prevent fraud and abuse, investigate incidents, and establish or defend legal claims.
Legitimate interests - Article 6(1)(f); legal obligation - Article 6(1)(c) where a binding duty applies. This includes proportionate security logs, access controls, fraud checks, and incident evidence.
Send service, security, verification, billing, and legally required notices.
Contract and legal obligation - Articles 6(1)(b) and 6(1)(c). These operational messages are not optional advertising.
Measure optional website usage, run session replay, and measure Google Ads or Meta conversions.
Consent - Article 6(1)(a). These tools activate only after the relevant analytics or advertising choice, and consent may be withdrawn at any time.
Maintain aggregated or de-identified operational statistics that do not require optional browser storage.
Legitimate interests - Article 6(1)(f). Our interest is understanding reliability, capacity, feature adoption, and general service performance with minimal privacy impact.

Our specific legitimate interests are securing Lyniti and customer accounts, preventing fraud and misuse, maintaining reliable infrastructure, diagnosing and improving service performance, supporting users, managing disputes, and protecting or enforcing legal rights. We balance these interests against users' rights, minimize the data used, and honor the right to object where it applies.

We may generate aggregated, statistical, or de-identified usage analytics for service reliability and product planning. Optional analytics, session replay, and advertising measurement rely on consent and are not used by Lyniti for cross-site behavioral profiling.

4. Sharing and Transfers

We may share data with service providers, payment providers, other workspace members where collaboration requires it, and authorities when required by law. Data is primarily processed in the EU. If data is transferred outside the EU/EEA, we use appropriate safeguards.

Our infrastructure and service providers may include Hetzner for hosting, Cloudflare for delivery and security-related services, Resend for transactional emails, and Stripe for payments. We may update providers over time where needed to operate the service.

5. Retention

We keep personal data for as long as needed to operate the service, maintain workspaces, comply with law, resolve disputes, and enforce agreements.

Workspace content is generally stored while the workspace exists. If a workspace is deleted, related workspace data is deleted with it, subject to limited retention required for legal compliance, billing records, security logging, fraud prevention, dispute handling, and backup expiration. Different categories of data may be kept for different time periods depending on those needs.

Where technically feasible, users may export workspace data before deletion. Some residual copies may remain temporarily in backups until normal backup rotation expires.

Category-specific periods, deletion triggers, and backup windows are listed in the Trust Center retention schedule .

6. Security

We use reasonable technical and organizational measures designed to protect personal data and workspace content, including access controls, encryption in transit, logging, and infrastructure security practices. However, no method of transmission or storage is completely secure.

7. Your Rights

Under GDPR, you may have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of data
  • Restrict processing
  • Object to processing
  • Receive your data in a portable format
  • Withdraw consent where processing relies on consent

To exercise these rights, contact support@lyniti.com.

8. Automated Decision-Making

We do not currently use personal data for solely automated decision-making that produces legal or similarly significant effects.

9. Cookies and Similar Storage

We use cookies and similar browser storage for authentication, security, preferences, and service functionality. With consent, we use Umami analytics, strictly masked session replay for anonymous homepage visits, and Google Ads or Meta conversion measurement. Session replay masks all text and inputs and records only censored page structure and interactions such as pointer movement, clicks, scrolling, and navigation. See the Cookie Policy for exact storage names, providers, durations, and controls.

10. Contact and Complaints

For privacy questions or complaints, contact support@lyniti.com.

You also have the right to lodge a complaint with the Finnish Data Protection Ombudsman.

  • Website: tietosuoja.fi
  • Email: tietosuoja@om.fi
  • Address: PL 800, 00531 Helsinki