GDPR, retention, deletion, and export
Privacy contact and DPO status
Lyniti has not designated a Data Protection Officer. Privacy matters and data-protection requests are handled through the privacy contact below.
Privacy contact: support@lyniti.com
Retention schedule
Periods below distinguish verified product behavior from retention still requiring an operational record. Legal holds, fraud prevention, disputes, billing law, and security obligations may require limited longer retention.
| Data category | Current period | Deletion or retention rule |
|---|---|---|
| Active account profile and authentication data | While account is active | Removed or anonymized after the verified 30-day account-deletion window, subject to records that must remain. |
| Scheduled account deletion | 30 days | Request signs the user out and schedules deletion. A reminder is sent near deletion. Product behavior permits cancellation before execution. |
| Workspace content | While workspace exists | Workspace deletion removes related content subject to legal, billing, security, dispute, fraud-prevention, and backup-expiration exceptions. |
| Shared messages and files after personal-account deletion | Follows workspace retention | Content remains available to the organization where it belongs to the workspace; the deleted user identity is anonymized. |
| Billing and legally required records | Applicable statutory period | Kept only as required for accounting, tax, payment, dispute, fraud, or other legal duties. Exact category schedule requires legal-record verification. |
| Security and service logs | Operational period not yet published | Kept only as needed for security, reliability, abuse prevention, and investigation. A numeric production log-retention period has not been approved. |
| Backups | 7 days locally; 90 days in R2 | Deleted customer data may remain in database backups until the applicable rotation expires. |
| Support communications | For request handling and defensible follow-up | Deleted when no longer needed unless security, dispute, or legal requirements apply. |
Controller and processor roles
Lyniti is controller for account, billing-contact, support, security, and service-usage data used to operate Lyniti. A customer organization is generally controller for personal data it places in its workspace, while Lyniti processes that workspace data to provide the service.
Roles can differ for a specific deployment or use case. Signed customer terms and DPA control over this summary where applicable.
Personal data breach handling
Where Lyniti acts as a processor, Lyniti notifies the affected controller without undue delay after becoming aware of a personal data breach concerning Customer Personal Data and provides reasonably available information needed for the controller's GDPR obligations. The applicable signed DPA controls any additional notice and cooperation requirements.
Export process
Users should use built-in exports for supported records before deleting an account or workspace. Where a complete built-in export is not available, an authorized workspace representative can request assistance through the privacy contact.
- Identify requester and verify account or workspace authority.
- Confirm scope, date range, data subjects, and required format.
- Use available product exports first, then assess a supported administrative export where technically feasible.
- Deliver through an authenticated or otherwise agreed secure channel.
- Record completion and any data that could not be included because it belongs to another controller, user, or legal restriction.
Deletion process
Personal-account deletion is requested from account settings after active subscriptions owned by the user are resolved. The account enters a 30-day pending-deletion period, active refresh tokens are removed, and sessions are invalidated.
At execution, authentication links, password material, encryption-key records, profile metadata, workspace memberships, and direct personal identifiers are removed or anonymized. Sole-member workspaces are deleted; ownership of workspaces with other members is transferred. Shared messages and files remain with those workspaces under organization retention.
- Account deletion does not silently delete organization records owned by a shared workspace.
- Workspace deletion and personal-account deletion are separate actions with different scope.
- Backup copies expire through normal rotation and are not restored to active service except for recovery purposes.
- Requests subject to a legal hold or statutory duty may be restricted or delayed only to that extent.
Data subject requests
Requests may cover access, correction, deletion, restriction, objection, portability, or withdrawal of consent where applicable. Lyniti verifies identity and authority before disclosing or changing data.
Where Lyniti acts as controller, Lyniti responds to applicable data-subject requests without undue delay and in any event within one month of receipt. Where permitted by GDPR because of the complexity or number of requests, Lyniti may extend this period by two further months and will notify the requester of the extension and reasons within the initial one-month period.
For workspace content controlled by a customer organization, Lyniti may direct the requester to that organization or assist it as processor. Complaints may also be filed with the Finnish Data Protection Ombudsman.