Privacy Policy

Last updated: 12 July 2026

This policy explains how [LEGAL ENTITY NAME]("Lyngdesk", "we") collects and uses personal data when you use our website and platform. We are the data controller. Contact: [PRIVACY EMAIL].

What we collect

  • Application data you submit — name, company, email, phone, WhatsApp/Telegram, website, business details.
  • Account data — email and role, if we provision you a login.
  • Documents you upload during onboarding (e.g. incorporation certificates), stored on encrypted object storage with access logging.
  • Technical data — IP address and browser info, used for security, rate-limiting, and the click-through acceptance record.
  • We use only essential cookies to keep you signed in. No advertising or third-party tracking cookies.

Why we use it (legal bases)

  • Contract / pre-contract steps — to evaluate and run a potential partnership you asked us to facilitate.
  • Legitimate interests — operating a deal desk, preventing fraud/abuse, and keeping an audit trail. We balance these against your rights.
  • Consent — where you tick a box to submit an application; you may withdraw it at any time.
  • Legal obligation — where we must keep records for compliance.

Who we share it with

We disclose your identity to a counterparty (a PSP or merchant) only after you consent, on a per-counterparty basis, and you can revoke that consent. We use processors including Supabase (database, auth, storage), Vercel (hosting), and email/AI providers listed on request. We do not sell personal data.

International transfers

Our infrastructure may process data outside your country (e.g. EU, US, Asia-Pacific regions of our providers). Where required, transfers rely on Standard Contractual Clauses or an adequacy decision. [CONFIRM PROVIDER REGIONS WITH COUNSEL.]

How long we keep it

We keep application and deal data for as long as needed for the partnership and our legal/audit obligations, then delete or anonymise it. Audit records (acceptances, document-access logs) are retained as immutable evidence for [RETENTION PERIOD].

Your rights

If you are in the EEA/UK you have rights to access, rectify, erase, restrict, port, and object to processing of your personal data, and to lodge a complaint with your supervisory authority. To exercise any right, email [PRIVACY EMAIL].

Security

Row-level security on every table, encrypted storage, short-lived signed document URLs, access logging, and least-privilege access. No system is perfectly secure, but we take reasonable measures appropriate to the sensitivity of the data.

Template notice: bracketed items and retention periods must be completed and this document reviewed by qualified counsel before it is relied upon for EU/UK residents.