[ Legal ] · Privacy

Privacy Policy

This policy explains what personal data Lyto collects when you use our apps and website, why we collect it, who we share it with, and the rights you have over it. We’ve tried to write it in plain language. If anything is unclear, email us.

Last updated: 8 September 2026 · Effective: 8 September 2026

1. Who we are

The data controller for the personal data described in this policy is Lyto (“Lyto”, “we”, “our”, “us”), a company registered in the Netherlands.

We have not formally appointed a Data Protection Officer, as we are not legally required to do so at our current scale. The privacy contact above is the right address for any data-protection question.

2. Scope

This policy covers personal data we process when you:

When you use a Lyto product inside an organisation that has its own Lyto account, that organisation is the controller of the business data you contribute (timesheets, invoices, project records, etc.). Lyto is the processor of that data on their behalf. This policy applies to data Lyto controls directly — such as your account credentials, billing details, support correspondence, and product-usage telemetry.

3. What we collect and why

3.1 Account data

When you create an account, we collect your name, email address, and (if you set one) a hashed password. If you sign in with Google, we receive your Google account email, name, profile picture and a unique Google identifier. We never receive your Google password.

Lawful basis: performance of a contract (Art. 6(1)(b) GDPR) — we need this to give you access to the service you’ve signed up for.

3.2 Product data

To deliver the features you use — timesheets, invoices, sales pipeline records, AI-assisted suggestions, dashboards, and so on — we store the information you and your colleagues enter into the apps, plus metadata about how that information is created and changed (timestamps, the user who made each change).

Lawful basis: performance of a contract (Art. 6(1)(b)) for the customer organisation; legitimate interest (Art. 6(1)(f)) in maintaining accurate audit trails.

3.3 Billing data

For paid plans, we store your billing email, billing address, VAT number (where applicable) and the records of invoices and payments. Card or bank details, where you provide them, are handled by our payment processor and never stored on Lyto’s own servers.

Lawful basis: performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for tax and accounting record-keeping under Dutch law.

3.4 Technical and usage data

When you use Lyto, our servers automatically receive standard request information: IP address, user-agent string, the page or API endpoint requested, the response status, and the time of the request. We log a subset of this for security, abuse-prevention, and debugging.

We also record a small set of product-usage events (for example: “user signed in”, “invoice created”) so we can understand which parts of the product are used and detect failures. These events are tied to your user ID but do not include the content of your business records.

Lawful basis: legitimate interest (Art. 6(1)(f)) in keeping the service secure, reliable and improving over time.

3.5 Support and communication data

When you email us, fill out a form, or otherwise contact us, we keep the contents of that correspondence so we can respond and so we have a record of the question if it comes up again.

Lawful basis: legitimate interest (Art. 6(1)(f)) in providing support.

4. Bank connections in Sum

Sum, our invoicing and bookkeeping app, can connect to your business bank account so that transactions arrive automatically for reconciliation instead of being imported by hand. This section describes exactly what that connection does. It applies only if you choose to make one — everything else in Sum works without it, and a bank statement file (CAMT.053 or MT940) can be imported instead.

4.1 The connection is read-only

The connection gives Sum account information access only. Sum can read your account details, balance and transaction history. It cannot initiate a payment, move money, or change anything at your bank, and it never asks for the ability to.

You authenticate at your own bank, on your bank’s own screens, using your bank’s own strong customer authentication. Lyto never sees, receives or stores your bank login credentials. What Sum receives back is a session reference, which is encrypted at rest in our database and decrypted only to fetch transactions or to revoke the consent.

Only the organisation’s owner can connect or disconnect a bank account.

4.2 Who the connection runs through

The connection is made through Enable Banking Oy, an account information service provider established and regulated in Finland (EU) under PSD2. Enable Banking holds the regulated relationship with your bank and passes the account data to Sum; it acts as our sub-processor for this purpose and is listed in the table in section 5.

4.3 What Sum stores

For each connection, Sum stores:

The first sync after you connect fetches up to 90 days of transaction history. After that, each sync only asks for what is new or changed since the last one. Sum stores no other information from your bank.

Lawful basis: your explicit consent (Art. 6(1)(a) GDPR), given at your bank under PSD2, which you can withdraw at any time as described below.

4.4 How long the consent lasts

We ask your bank for a consent lasting up to 180 days, which is the maximum PSD2 allows for account information access. Your bank may grant a shorter period. When the consent expires the feed simply stops: no further transactions are fetched until you re-authenticate at your bank. Sum tells you in the Banking settings when a connection needs renewing.

4.5 How to withdraw it

In Sum, go to Settings → Bank connections and choose Disconnect. That does two things: it asks Enable Banking to delete the session, which revokes the consent at your bank, and it deletes the connection from Sum — taking the stored accounts and every transaction fetched through them with it. Bookkeeping entries you had already created from those transactions stay in your books, because they are now part of your accounting record rather than bank data.

You can also revoke the consent from your own bank’s consent screen at any time, without going through Sum. Doing so stops the feed immediately; disconnect in Sum afterwards to remove the data Sum has already stored.

5. Sub-processors

Lyto uses a small number of trusted infrastructure providers to deliver the service. Each is bound by a written data-processing agreement, and we’ve chosen providers that process EU personal data within the EU or under appropriate safeguards.

Sub-processorPurposeProcessing region
Supabase Inc.Database, authentication, file storage, edge functionsIreland (EU)
Vercel Inc.Web and application hosting, cookieless site analyticsFrankfurt (EU)
Twilio SendGridTransactional email deliveryEU region
Enable Banking OyRead-only bank account information for Sum’s bank feed (only if you connect a bank account)Finland (EU)
Cloudflare, Inc.Bot/abuse protection (Turnstile captcha)Global edge; data-residency-aware
Google LLC“Sign in with Google” identity verification (only if you choose to use it)United States, under EU Standard Contractual Clauses
Anthropic PBCAI-assisted features across the Lyto apps (input is not used to train models)United States, under EU Standard Contractual Clauses

We update this list as it changes. If you would like to receive notice of new sub-processors before they are engaged, email lytoapp@gmail.com.

6. International transfers

Where personal data is transferred outside the European Economic Area (currently to Google and Anthropic, for the specific purposes described above), we rely on the European Commission’s Standard Contractual Clauses and, where applicable, on adequacy decisions. We do not transfer personal data to jurisdictions without an appropriate safeguard in place. Bank connection data is not transferred outside the EEA.

7. How long we keep it

8. Your rights

Under the GDPR, you have the right to:

To exercise any of these rights, email lytoapp@gmail.com. We will respond within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.

9. Cookies and similar technologies

Our marketing website uses only strictly necessary cookies, including a session cookie for the sign-in flow on auth.lytoapp.com. We do not use third-party advertising or cross-site tracking cookies. Site analytics on lytoapp.com are provided by Vercel Web Analytics, which is served from our own domain and sets no cookies and no cross-site identifier — which is why this site has no cookie banner.

10. Security

We take security seriously and apply industry-standard practices: encryption in transit (TLS 1.2+), encryption at rest for all customer databases, hashed passwords (bcrypt or stronger), least-privilege access for our team, row-level authorisation policies on the database, multi-factor authentication for administrative access, and continuous monitoring. Bank session references carry an additional layer of application-level encryption. No system is perfectly secure; if you believe you have discovered a vulnerability, please report it to lytoapp@gmail.com.

11. Children

Lyto is built for business use and is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. The “Last updated” date at the top of the page reflects the most recent change. For material changes that affect how we use existing personal data, we will give account-holders notice by email at least 30 days before the change takes effect.

13. Contact

Questions, requests, or complaints about this policy or how we handle your data: