Privacy notice

What we collect, why we collect it, who else touches it, where it is stored, how long we keep it and what you can ask us to do about it. Written to be read rather than to be survived.

Last updated 21 September 2026

1. Who is responsible for your data

This notice covers two different relationships, and the distinction matters because it decides who answers a request about your data.

For the website, the demo and our own business contacts, Relynt is the controller. We decide what to collect and why, and requests about that data come to us.

For the content inside a customer workspace, Relynt is a processor. Your employer or client is the controller. They decide what goes in, how long it stays and who may see it. If you are a named contact inside someone else's workspace, for example a vendor responding to an assessment, address your request to that organisation. We will help them answer it and we will tell you who they are if you ask.

2. What we collect

We try to collect the minimum that makes the product work, and nothing speculative. There is no advertising network, no behavioural tracking and no data broker in this list.

CategoryWhat it includes
Account dataName, work email address, job title, organisation, role in the workspace, and the timestamps of sign-in and enrolment in two-factor authentication.
Authentication dataA password hash held by our authentication provider, and if you enable it, a time-based one-time password secret. We never see your password.
Workspace contentEverything your organisation records: ICT providers, services, contracts and their text, assessments and responses, uploaded evidence documents, risks, resilience tests, register entries and board reports.
Audit trailWho changed what, when, from which IP address, with the values before and after. This exists because DORA and your own auditors require it.
EnquiriesName, email, organisation, role, an indication of how many ICT providers you manage, and whatever you write in the message.
Demo workspacesA generated account with no real address, and whatever you enter while exploring. The whole workspace is deleted automatically.
Technical dataServer logs containing IP address, request path, timing and error detail, kept for operational diagnosis.
Error reportsWhen something fails: the error message, the stack trace, the path you were on and your account identifier. Never the contents of a form, a request body or a session recording.

3. Why we use it, and on what legal basis

We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use customer workspace content to train machine learning models.

PurposeLegal basis
Providing the platform to the customer that licensed itPerformance of a contract, or our legitimate interest in serving our customer where you are that customer's employee.
Authenticating you and protecting accounts, including two-factorPerformance of a contract, and our legitimate interest in keeping the service secure.
Keeping an audit trail of changesLegal obligation on our customers under DORA, and our legitimate interest in being able to explain what happened.
Answering an enquiry you send usSteps taken at your request before entering a contract, and our legitimate interest in replying to people who write to us.
Billing and tax recordsPerformance of a contract and compliance with accounting law.
Detecting and investigating abuse, fraud and security incidentsLegitimate interest in the integrity of the service.
Improving the productLegitimate interest. We do this from aggregate usage and from what customers tell us, not by reading workspace content.

4. Model-assisted review

The platform can review a contract, an assessment response or an evidence document with a language model. This is off for a new workspace until an administrator turns it on.

When it is on, the text of the document being reviewed is sent to our model provider at the moment of review, and the result comes back as a suggestion that a person accepts or rejects. Nothing else is sent: not your provider inventory, not your risk register, not the Register of Information, not account data. The provider does not use the content to train models.

When it is off, review runs a deterministic rule-based pass instead, every finding is labelled as such, and no document or response text leaves the platform. The switch can be changed at any time by an administrator, and the change is written to the audit trail.

5. Who else processes it

Five sub-processors handle personal data on our behalf. Each is published with its purpose, the data that reaches it and where it runs, on our sub-processor page at /security/sub-processors. That page is the authoritative list and it changes there first.

In summary: the database, authentication and document storage sit with Supabase in Frankfurt; the application runs on Vercel in Frankfurt; error reporting goes to Sentry in their EU region; transactional email goes through Resend; and model-assisted review, when enabled, goes to Anthropic.

Before a new sub-processor begins processing customer data we notify workspace administrators by email and update the page.

6. Where your data is stored

The database, the authentication system and every uploaded document are stored and processed in the European Union, in Frankfurt, and do not leave it. Application servers run in the same region.

Two processors operate outside the EU. Transactional email is delivered through a provider in the United States, which means a recipient address and the contents of that message leave the EU. Model-assisted review, when a workspace enables it, sends the text being reviewed to a provider in the United States.

Those transfers rely on the European Commission's standard contractual clauses together with the supplementary measures described in our security documentation. If your organisation cannot accept model processing outside the EU, leave the feature switched off; the product works without it.

7. How long we keep it

Workspace content is kept for as long as the workspace exists. Administrators can set retention periods per record type from Settings, and can place a legal hold that suspends deletion while a matter is open.

DataKept for
Workspace contentThe life of the workspace, or the retention period the customer configures, whichever is shorter.
Audit trailThe life of the workspace by default. A customer may set a shorter period, but not shorter than twelve months.
Account dataUntil the account is removed from the workspace, or the workspace is deleted.
Demo workspacesDeleted automatically twenty-four hours after creation, together with the generated account.
EnquiriesTwenty-four months, so we can pick up a conversation that started a year ago.
Billing recordsTen years, as accounting law requires.
Server logsThirty days.
Error reportsNinety days, then deleted by our error reporting provider.

8. Export and deletion

An administrator can export an entire workspace as a single JSON file at any time, and can permanently delete the workspace, every record in it and every member account, from Settings under Data and retention. Deletion is immediate and cannot be undone, which is why the export exists first.

When a customer ends their subscription, the workspace and its contents are deleted after thirty days unless they ask us to remove it sooner. Backups age out within a further thirty-five days.

9. Your rights

If we are the controller of the data in question, you may ask us to give you a copy, correct it, delete it, restrict what we do with it, or object to processing we base on legitimate interest. You may also ask for it in a portable format.

Write to support@relynt.io. We reply within one month, and we will tell you promptly if a request will take longer and why. We do not charge for this unless a request is repetitive or excessive.

If we are a processor, meaning your data sits in a customer's workspace, send the request to that organisation. We will support them in answering it within the time the law allows.

If you are not satisfied with how we have handled a request, you may complain to your national data protection authority.

10. How it is protected

Traffic is encrypted in transit and data is encrypted at rest. Workspaces are isolated from each other, enforced in the application and again at the database level. Access is role based, two-factor authentication is available to every account and can be required across a workspace, and every change is recorded in the audit trail.

Backups are restored and verified on a schedule, and the result is recorded. The full detail, including what we have not yet done, is on our security page.

11. Cookies

We set a small number of strictly necessary cookies: a session cookie so you stay signed in, and a preference cookie for light or dark appearance. The public pages are measured with PostHog, configured so that it sets no cookie at all: it counts a page view in the browser’s memory, stores no identifier on your device and keeps nothing once the tab closes. It runs on PostHog’s European infrastructure, your IP address is not stored and nothing follows you to another site. We set no advertising cookie unless you have agreed to one. While we are running advertising you are asked on arrival, refusing takes one click and sits beside accepting at the same size, and a refusal is remembered so you are not asked again. Refuse and nothing from an advertising network loads at all; the page counting above is unaffected either way, because it needs no cookie. The application itself is not measured: what a workspace does with its own register is not audience data.

12. Children

The platform is sold to organisations and is not directed at children. We do not knowingly collect personal data from anyone under sixteen.

13. Changes to this notice

When this notice changes we update the date at the top. For a change that materially affects how we handle personal data, we notify workspace administrators by email before it takes effect.

14. Contact

Questions about this notice or a request about your data: support@relynt.io. Our data processing agreement is published at /dpa.

This notice describes our actual practice and is kept current with it. It is not legal advice, and it does not replace the data processing agreement that forms part of a customer contract. Ask us for that agreement and we will send it the same day.

Privacy Notice | Relynt