Privacy notice
What we collect, why we collect it, who else touches it, where it is stored, how long we keep it and what you can ask us to do about it. Written to be read rather than to be survived.
Last updated 21 September 2026
1. Who is responsible for your data
This notice covers two different relationships, and the distinction matters because it decides who answers a request about your data.
For the website, the demo and our own business contacts, Relynt is the controller. We decide what to collect and why, and requests about that data come to us.
For the content inside a customer workspace, Relynt is a processor. Your employer or client is the controller. They decide what goes in, how long it stays and who may see it. If you are a named contact inside someone else's workspace, for example a vendor responding to an assessment, address your request to that organisation. We will help them answer it and we will tell you who they are if you ask.
2. What we collect
We try to collect the minimum that makes the product work, and nothing speculative. There is no advertising network, no behavioural tracking and no data broker in this list.
| Category | What it includes |
|---|---|
| Account data | Name, work email address, job title, organisation, role in the workspace, and the timestamps of sign-in and enrolment in two-factor authentication. |
| Authentication data | A password hash held by our authentication provider, and if you enable it, a time-based one-time password secret. We never see your password. |
| Workspace content | Everything your organisation records: ICT providers, services, contracts and their text, assessments and responses, uploaded evidence documents, risks, resilience tests, register entries and board reports. |
| Audit trail | Who changed what, when, from which IP address, with the values before and after. This exists because DORA and your own auditors require it. |
| Enquiries | Name, email, organisation, role, an indication of how many ICT providers you manage, and whatever you write in the message. |
| Demo workspaces | A generated account with no real address, and whatever you enter while exploring. The whole workspace is deleted automatically. |
| Technical data | Server logs containing IP address, request path, timing and error detail, kept for operational diagnosis. |
| Error reports | When something fails: the error message, the stack trace, the path you were on and your account identifier. Never the contents of a form, a request body or a session recording. |
3. Why we use it, and on what legal basis
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use customer workspace content to train machine learning models.
| Purpose | Legal basis |
|---|---|
| Providing the platform to the customer that licensed it | Performance of a contract, or our legitimate interest in serving our customer where you are that customer's employee. |
| Authenticating you and protecting accounts, including two-factor | Performance of a contract, and our legitimate interest in keeping the service secure. |
| Keeping an audit trail of changes | Legal obligation on our customers under DORA, and our legitimate interest in being able to explain what happened. |
| Answering an enquiry you send us | Steps taken at your request before entering a contract, and our legitimate interest in replying to people who write to us. |
| Billing and tax records | Performance of a contract and compliance with accounting law. |
| Detecting and investigating abuse, fraud and security incidents | Legitimate interest in the integrity of the service. |
| Improving the product | Legitimate interest. We do this from aggregate usage and from what customers tell us, not by reading workspace content. |
4. Model-assisted review
The platform can review a contract, an assessment response or an evidence document with a language model. This is off for a new workspace until an administrator turns it on.
When it is on, the text of the document being reviewed is sent to our model provider at the moment of review, and the result comes back as a suggestion that a person accepts or rejects. Nothing else is sent: not your provider inventory, not your risk register, not the Register of Information, not account data. The provider does not use the content to train models.
When it is off, review runs a deterministic rule-based pass instead, every finding is labelled as such, and no document or response text leaves the platform. The switch can be changed at any time by an administrator, and the change is written to the audit trail.
5. Who else processes it
Five sub-processors handle personal data on our behalf. Each is published with its purpose, the data that reaches it and where it runs, on our sub-processor page at /security/sub-processors. That page is the authoritative list and it changes there first.
In summary: the database, authentication and document storage sit with Supabase in Frankfurt; the application runs on Vercel in Frankfurt; error reporting goes to Sentry in their EU region; transactional email goes through Resend; and model-assisted review, when enabled, goes to Anthropic.
Before a new sub-processor begins processing customer data we notify workspace administrators by email and update the page.
6. Where your data is stored
The database, the authentication system and every uploaded document are stored and processed in the European Union, in Frankfurt, and do not leave it. Application servers run in the same region.
Two processors operate outside the EU. Transactional email is delivered through a provider in the United States, which means a recipient address and the contents of that message leave the EU. Model-assisted review, when a workspace enables it, sends the text being reviewed to a provider in the United States.
Those transfers rely on the European Commission's standard contractual clauses together with the supplementary measures described in our security documentation. If your organisation cannot accept model processing outside the EU, leave the feature switched off; the product works without it.
7. How long we keep it
Workspace content is kept for as long as the workspace exists. Administrators can set retention periods per record type from Settings, and can place a legal hold that suspends deletion while a matter is open.
| Data | Kept for |
|---|---|
| Workspace content | The life of the workspace, or the retention period the customer configures, whichever is shorter. |
| Audit trail | The life of the workspace by default. A customer may set a shorter period, but not shorter than twelve months. |
| Account data | Until the account is removed from the workspace, or the workspace is deleted. |
| Demo workspaces | Deleted automatically twenty-four hours after creation, together with the generated account. |
| Enquiries | Twenty-four months, so we can pick up a conversation that started a year ago. |
| Billing records | Ten years, as accounting law requires. |
| Server logs | Thirty days. |
| Error reports | Ninety days, then deleted by our error reporting provider. |
8. Export and deletion
An administrator can export an entire workspace as a single JSON file at any time, and can permanently delete the workspace, every record in it and every member account, from Settings under Data and retention. Deletion is immediate and cannot be undone, which is why the export exists first.
When a customer ends their subscription, the workspace and its contents are deleted after thirty days unless they ask us to remove it sooner. Backups age out within a further thirty-five days.
9. Your rights
If we are the controller of the data in question, you may ask us to give you a copy, correct it, delete it, restrict what we do with it, or object to processing we base on legitimate interest. You may also ask for it in a portable format.
Write to support@relynt.io. We reply within one month, and we will tell you promptly if a request will take longer and why. We do not charge for this unless a request is repetitive or excessive.
If we are a processor, meaning your data sits in a customer's workspace, send the request to that organisation. We will support them in answering it within the time the law allows.
If you are not satisfied with how we have handled a request, you may complain to your national data protection authority.
10. How it is protected
Traffic is encrypted in transit and data is encrypted at rest. Workspaces are isolated from each other, enforced in the application and again at the database level. Access is role based, two-factor authentication is available to every account and can be required across a workspace, and every change is recorded in the audit trail.
Backups are restored and verified on a schedule, and the result is recorded. The full detail, including what we have not yet done, is on our security page.
12. Children
The platform is sold to organisations and is not directed at children. We do not knowingly collect personal data from anyone under sixteen.
13. Changes to this notice
When this notice changes we update the date at the top. For a change that materially affects how we handle personal data, we notify workspace administrators by email before it takes effect.
14. Contact
Questions about this notice or a request about your data: support@relynt.io. Our data processing agreement is published at /dpa.
This notice describes our actual practice and is kept current with it. It is not legal advice, and it does not replace the data processing agreement that forms part of a customer contract. Ask us for that agreement and we will send it the same day.