[ Legal ] · Privacy
Privacy Policy
This policy explains what personal data Lyto collects when you use our apps and website, why we collect it, who we share it with, and the rights you have over it. We’ve tried to write it in plain language. If anything is unclear, email us.
Last updated: 8 September 2026 · Effective: 8 September 2026
1. Who we are
The data controller for the personal data described in this policy is Lyto (“Lyto”, “we”, “our”, “us”), a company registered in the Netherlands.
- Registered address: Francois Maelsonstraat 2, 2582 KC, Den Haag, Netherlands
- KvK (Chamber of Commerce) number: 99898624
- VAT number: NL005417321B70
- Privacy contact: lytoapp@gmail.com
We have not formally appointed a Data Protection Officer, as we are not legally required to do so at our current scale. The privacy contact above is the right address for any data-protection question.
2. Scope
This policy covers personal data we process when you:
- Visit our marketing website at lytoapp.com
- Create or hold an account on any Lyto product (including Workspace, Pipeline, Solve, Sum, Workstream, Tally and Pulse)
- Sign in via our authentication service at auth.lytoapp.com
- Contact us by email or by submitting a form on our website
When you use a Lyto product inside an organisation that has its own Lyto account, that organisation is the controller of the business data you contribute (timesheets, invoices, project records, etc.). Lyto is the processor of that data on their behalf. This policy applies to data Lyto controls directly — such as your account credentials, billing details, support correspondence, and product-usage telemetry.
3. What we collect and why
3.1 Account data
When you create an account, we collect your name, email address, and (if you set one) a hashed password. If you sign in with Google, we receive your Google account email, name, profile picture and a unique Google identifier. We never receive your Google password.
Lawful basis: performance of a contract (Art. 6(1)(b) GDPR) — we need this to give you access to the service you’ve signed up for.
3.2 Product data
To deliver the features you use — timesheets, invoices, sales pipeline records, AI-assisted suggestions, dashboards, and so on — we store the information you and your colleagues enter into the apps, plus metadata about how that information is created and changed (timestamps, the user who made each change).
Lawful basis: performance of a contract (Art. 6(1)(b)) for the customer organisation; legitimate interest (Art. 6(1)(f)) in maintaining accurate audit trails.
3.3 Billing data
For paid plans, we store your billing email, billing address, VAT number (where applicable) and the records of invoices and payments. Card or bank details, where you provide them, are handled by our payment processor and never stored on Lyto’s own servers.
Lawful basis: performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for tax and accounting record-keeping under Dutch law.
3.4 Technical and usage data
When you use Lyto, our servers automatically receive standard request information: IP address, user-agent string, the page or API endpoint requested, the response status, and the time of the request. We log a subset of this for security, abuse-prevention, and debugging.
We also record a small set of product-usage events (for example: “user signed in”, “invoice created”) so we can understand which parts of the product are used and detect failures. These events are tied to your user ID but do not include the content of your business records.
Lawful basis: legitimate interest (Art. 6(1)(f)) in keeping the service secure, reliable and improving over time.
3.5 Support and communication data
When you email us, fill out a form, or otherwise contact us, we keep the contents of that correspondence so we can respond and so we have a record of the question if it comes up again.
Lawful basis: legitimate interest (Art. 6(1)(f)) in providing support.
4. Bank connections in Sum
Sum, our invoicing and bookkeeping app, can connect to your business bank account so that transactions arrive automatically for reconciliation instead of being imported by hand. This section describes exactly what that connection does. It applies only if you choose to make one — everything else in Sum works without it, and a bank statement file (CAMT.053 or MT940) can be imported instead.
4.1 The connection is read-only
The connection gives Sum account information access only. Sum can read your account details, balance and transaction history. It cannot initiate a payment, move money, or change anything at your bank, and it never asks for the ability to.
You authenticate at your own bank, on your bank’s own screens, using your bank’s own strong customer authentication. Lyto never sees, receives or stores your bank login credentials. What Sum receives back is a session reference, which is encrypted at rest in our database and decrypted only to fetch transactions or to revoke the consent.
Only the organisation’s owner can connect or disconnect a bank account.
4.2 Who the connection runs through
The connection is made through Enable Banking Oy, an account information service provider established and regulated in Finland (EU) under PSD2. Enable Banking holds the regulated relationship with your bank and passes the account data to Sum; it acts as our sub-processor for this purpose and is listed in the table in section 5.
4.3 What Sum stores
For each connection, Sum stores:
- The name and identifier of your bank, and its logo.
- For each connected account: the account name, account type, currency, a masked account identifier, and the most recent balance.
- For each transaction: the booking date, the amount and currency, the description your bank supplies, the counterparty or merchant name where your bank supplies one, any category your bank supplies, whether the transaction is still pending, and the reconciliation status Sum itself assigns (unmatched, suggested, matched or ignored).
The first sync after you connect fetches up to 90 days of transaction history. After that, each sync only asks for what is new or changed since the last one. Sum stores no other information from your bank.
Lawful basis: your explicit consent (Art. 6(1)(a) GDPR), given at your bank under PSD2, which you can withdraw at any time as described below.
4.4 How long the consent lasts
We ask your bank for a consent lasting up to 180 days, which is the maximum PSD2 allows for account information access. Your bank may grant a shorter period. When the consent expires the feed simply stops: no further transactions are fetched until you re-authenticate at your bank. Sum tells you in the Banking settings when a connection needs renewing.
4.5 How to withdraw it
In Sum, go to Settings → Bank connections and choose Disconnect. That does two things: it asks Enable Banking to delete the session, which revokes the consent at your bank, and it deletes the connection from Sum — taking the stored accounts and every transaction fetched through them with it. Bookkeeping entries you had already created from those transactions stay in your books, because they are now part of your accounting record rather than bank data.
You can also revoke the consent from your own bank’s consent screen at any time, without going through Sum. Doing so stops the feed immediately; disconnect in Sum afterwards to remove the data Sum has already stored.
5. Sub-processors
Lyto uses a small number of trusted infrastructure providers to deliver the service. Each is bound by a written data-processing agreement, and we’ve chosen providers that process EU personal data within the EU or under appropriate safeguards.
| Sub-processor | Purpose | Processing region |
|---|---|---|
| Supabase Inc. | Database, authentication, file storage, edge functions | Ireland (EU) |
| Vercel Inc. | Web and application hosting, cookieless site analytics | Frankfurt (EU) |
| Twilio SendGrid | Transactional email delivery | EU region |
| Enable Banking Oy | Read-only bank account information for Sum’s bank feed (only if you connect a bank account) | Finland (EU) |
| Cloudflare, Inc. | Bot/abuse protection (Turnstile captcha) | Global edge; data-residency-aware |
| Google LLC | “Sign in with Google” identity verification (only if you choose to use it) | United States, under EU Standard Contractual Clauses |
| Anthropic PBC | AI-assisted features across the Lyto apps (input is not used to train models) | United States, under EU Standard Contractual Clauses |
We update this list as it changes. If you would like to receive notice of new sub-processors before they are engaged, email lytoapp@gmail.com.
6. International transfers
Where personal data is transferred outside the European Economic Area (currently to Google and Anthropic, for the specific purposes described above), we rely on the European Commission’s Standard Contractual Clauses and, where applicable, on adequacy decisions. We do not transfer personal data to jurisdictions without an appropriate safeguard in place. Bank connection data is not transferred outside the EEA.
7. How long we keep it
- Active accounts: for as long as the account remains active.
- Closed accounts: personal data linked to a closed account is deleted within 90 days, except where we are legally required to retain it (for example, billing records under Dutch tax law — 7 years).
- Bank connection data: for as long as the connection exists. It is deleted as soon as you disconnect the bank in Sum, or when the organisation is closed.
- Backups: backups containing your data are rotated out within 30 days after deletion from the live system.
- Security and abuse logs: up to 12 months.
- Support correspondence: up to 24 months after the conversation ends.
8. Your rights
Under the GDPR, you have the right to:
- Request a copy of the personal data we hold about you (right of access).
- Ask us to correct inaccurate or incomplete data (right to rectification).
- Ask us to delete your data, subject to the retention rules above (right to erasure).
- Ask us to restrict how we use your data while a dispute is resolved (right to restriction).
- Receive your data in a portable, machine-readable format (right to data portability).
- Object to processing we carry out under legitimate interest (right to object).
- Withdraw consent at any time, where we rely on consent — including the consent behind a bank connection (section 4.5).
To exercise any of these rights, email lytoapp@gmail.com. We will respond within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.
9. Cookies and similar technologies
Our marketing website uses only strictly necessary cookies, including a session cookie for the sign-in flow on auth.lytoapp.com. We do not use third-party advertising or cross-site tracking cookies. Site analytics on lytoapp.com are provided by Vercel Web Analytics, which is served from our own domain and sets no cookies and no cross-site identifier — which is why this site has no cookie banner.
10. Security
We take security seriously and apply industry-standard practices: encryption in transit (TLS 1.2+), encryption at rest for all customer databases, hashed passwords (bcrypt or stronger), least-privilege access for our team, row-level authorisation policies on the database, multi-factor authentication for administrative access, and continuous monitoring. Bank session references carry an additional layer of application-level encryption. No system is perfectly secure; if you believe you have discovered a vulnerability, please report it to lytoapp@gmail.com.
11. Children
Lyto is built for business use and is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top of the page reflects the most recent change. For material changes that affect how we use existing personal data, we will give account-holders notice by email at least 30 days before the change takes effect.
13. Contact
Questions, requests, or complaints about this policy or how we handle your data:
- Email: lytoapp@gmail.com
- Post: Lyto, Francois Maelsonstraat 2, 2582 KC, Den Haag, Netherlands