We wrote this in plain language on purpose. If any part of it is unclear, email privacy@updates.lynxrise.com and a human will answer.
The short versionLynxRise collects the minimum needed to run your workspace, never sells personal data, never uses your client files to train models, and gives you a one-click export and delete for everything you own.
01
Who this policy covers
This policy applies to lynxrise.com, the LynxRise app, every client portal we host, and our API. Two different roles show up throughout:
- Workspace owners and team members — the freelancers, studios, and agencies who create an account with us. We are the controller of your account data.
- Portal guests — the clients invited into a workspace. Their data belongs to the workspace that invited them; we only process it on that workspace's instructions.
If you were invited to a portal and want your information changed or removed, contact the business that runs the portal first. We will help them action it, and we will step in directly if they cannot.
02
What we collect
Three buckets, nothing hidden. The panel below mirrors what an export of your account actually contains.
Name, email, password hash, avatar, company name
Pages viewed, feature events, device and browser, coarse IP region
Plan, invoices, last 4 digits, billing address
Projects, tasks, messages, files, invoices you upload
Full card numbers never touch our servers — payments run through Stripe, which returns only a token and the last four digits.
03
What we never do
Commitments, not aspirations. If any of these ever change, we will tell you before it takes effect, not after.
- We do not sell, rent, or trade personal data to anyone.
- We do not use your portal content, files, or client messages to train AI models.
- We do not place advertising or cross-site tracking pixels inside client portals.
- We do not read your files except when you ask support to look at a specific item.
- We do not email your clients marketing material. They only hear from your workspace.
04
How we use information
Every purpose below maps to a lawful basis under GDPR. Where that basis is consent, you can withdraw it at any time in Settings → Privacy.
- Run the service — host portals, send portal invites and notifications, sync files. Contract.
- Billing — charge your plan, issue invoices, handle refunds and tax records. Contract & legal duty.
- Keep accounts safe — detect abuse, rate-limit, log sign-ins, investigate incidents. Legitimate interest.
- Improve the product — aggregate, de-identified usage trends to decide what to build. Legitimate interest.
- Product email — onboarding tips and release notes to workspace owners. Consent, one-click unsubscribe.
05
Client data and who controls it
When your client uploads a brief or pays an invoice, that data flows to you — we are only the pipe and the safe. Watch the direction of travel:
Our Data Processing Addendum is available on request and is signed automatically for workspaces on the Studio plan and above.
06
Who we share with
A short, deliberate list. Each partner is contractually bound to our confidentiality and security terms, and we review the list twice a year.
We also disclose data when the law genuinely requires it, and we notify you first unless we are legally barred from doing so. In a merger or acquisition, this policy travels with the data.
07
How long we keep things
Bars are drawn to scale. Anything you delete leaves live systems immediately and disappears from encrypted backups on the schedule below.
01 yr3 yr7 yr
08
How we protect it
Security is a whole discipline, not a paragraph — the full breakdown lives in our security documentation. The essentials:
- AES-256 encryption at rest, TLS 1.3 in transit, on every plan.
- Role-based access with per-portal scoping, so guests only ever see their own portal.
- Two-factor authentication, session revocation, and an immutable audit log.
- Least-privilege internal access, reviewed quarterly, with every access event logged.
- Breach notification to affected workspaces within 72 hours of confirmation.
09
Your rights
Pick your region to see what applies to you. Whichever it is, we honour every request below for everyone — we do not gate privacy by postcode.
Under the GDPR you can exercise all of these rights free of charge, and we respond within 30 days.
Settings → Privacy → Export generates a machine-readable archive of your account, projects, tasks, messages, and file index, usually within minutes. No support ticket needed.
Most fields are editable directly in the app. For anything locked, such as a billing name on a finalised invoice, email us and we will amend the record and keep an audit trail.
Deleting a workspace immediately removes it from live systems and revokes every portal link. Backups age out within 30 days, apart from invoices we are legally required to retain.
You can opt out of product analytics and non-essential email without losing any functionality. Ask us to restrict processing while a dispute is open and we will freeze the relevant records.
Exports use open formats — JSON for structured data, original formats for files — so nothing is trapped here. We will not slow-walk an export because you are leaving.
Please try us first at privacy@updates.lynxrise.com. If we cannot resolve it, you may lodge a complaint with your local data protection authority, and we will cooperate fully with their enquiry.
10
Cookies and tracking
We use a deliberately small set. Site analytics are cookieless, and client portals carry no tracking at all. Toggle the optional ones here to see how the control works.
Because we do not run advertising cookies, there is no ad-personalisation profile to opt out of. Browser Do Not Track and Global Privacy Control signals are respected automatically.
11
International transfers and children
Primary data lives in the EU. When a subprocessor moves data outside the EEA or UK, the transfer relies on Standard Contractual Clauses, the UK Addendum, or an adequacy decision, plus encryption in transit and at rest.
Workspaces on the Studio plan and above can pin storage to an EU-only region. Ask us before you migrate and we will handle it without downtime.
LynxRise is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If a portal guest turns out to be under 16, tell us and we will remove the record promptly.
12
Changes to this policy
Material changes are announced by email and in-app at least 14 days before they take effect. Every version stays available so you can see exactly what moved.
v3.1 — Added Plausible as a cookieless analytics subprocessor; clarified the 30-day backup purge window.
v3.0 — Split controller and processor roles into their own section; added EU-only storage pinning.
v2.4 — Committed in writing to never training AI models on customer or portal content.
13
Contact us
Privacy questions, data requests, and DPA copies all go to the same inbox, monitored on business days.
- Email — privacy@updates.lynxrise.com
- Data requests — Settings → Privacy, or reply to any invoice email
- Postal — LynxRise, Data Protection, 12 Harbour Lane, Dublin, Ireland