Privacy Policy

Last updated: April 20, 2026

At Lyyli, we are committed to protecting your privacy and ensuring compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws. This policy explains how we collect, use, and protect your data.

1. Data Collection

We collect information that you provide to us directly, including:

  • Contact information (name, email address, phone number)
  • Company and role information
  • Communication preferences and team size
  • Messages and content you choose to share with our AI-powered communication assistant

Third-Party Integrations

If you connect Lyyli.ai to a third-party service (such as LinkedIn, Microsoft Teams, Slack, or email services), we receive data from that service with your permission. This data may include profile information (such as name and photo), network data, or message content. We use this data only to provide the service, such as creating message drafts or publishing according to customer instructions.

2. How We Use Your Data

We use the data we collect for the following purposes:

  • To provide and improve our AI communication services
  • AI-assisted work and customer service: we support client work, communications, and content preparation using AI tools and integrations; personal data may be processed through the services in use to deliver our services and ensure quality
  • To respond to your inquiries and provide customer support
  • To send service updates and important notifications
  • To analyze usage patterns to improve our platform's security and performance
  • To enable integrations with third-party services (only at the user's request and with consent)

3. GDPR Compliance and Legal Basis for Processing

As a service provider for expert organizations, we ensure full compliance with the General Data Protection Regulation (GDPR):

  • Legal basis for processing: We process personal data primarily for the performance of a contract (GDPR Art. 6(1)(b)) and on the basis of legitimate interests (Art. 6(1)(f)), for example for service delivery, security, and administration. In certain cases, such as continuous data retrieval from third-party integrations, we request separate consent (Art. 6(1)(a)). AI-assisted work and customer service is typically based on contract and/or legitimate interests; we do not make solely automated decisions that produce legal or similarly significant effects (see Section 7).
  • Data minimization: We collect only the data necessary for the stated purposes.
  • Withdrawal of consent: You can withdraw your consent (e.g., for integrations) at any time through settings or by contacting us.

4. Data Sharing and Third Parties

We do not sell or share your data with third parties for marketing purposes. Data is shared only in the following situations:

  • Service providers and AI tools: In our work we use AI tools (Anthropic Claude) and related or integrated services such as Google Workspace (Gmail, Google Drive, Google Calendar), Slack, Fireflies, and Canva. These services may process personal data in connection with delivering our services and supporting communications. For language models used in the Lyyli service, we use arrangements described as Zero Data Retention (ZDR) under our agreements and service descriptions; inputs are not used to train models as described by the provider. Technical subprocessors for the Lyyli service are listed in a separate subprocessor list.
  • Integrations: When a user publishes content to a third-party platform (e.g., LinkedIn) through Lyyli.ai, that content is transmitted to the platform at the user's direction, and its further use is subject to that platform's terms.
  • International transfers: Personal data may be transferred outside the EU or EEA via our service providers (e.g., to the United States or Australia). Transfers are carried out using EU-approved mechanisms such as the European Commission's Standard Contractual Clauses (SCCs) and/or the EU–US Data Privacy Framework, together with supplementary measures where required, in line with each provider's documentation.

Please note that Lyyli.ai is not affiliated with Meta, LinkedIn, or other social media platforms, and these platforms do not sponsor or endorse our application.

5. Data Security

We implement industry-standard security measures to protect your personal data:

  • End-to-end encryption for all data in transit
  • Strong encryption for data at rest
  • Regular security audits and testing
  • Access control and authentication requirements
  • Incident management and data breach notification procedures

Zero Data Retention Policy

In the Lyyli service we use language models where the provider describes a Zero Data Retention (ZDR) approach: inputs and outputs are not used to train models and are not retained for training purposes, as described by the provider. Processing takes place on the model provider's infrastructure (which may be located outside the EU/EEA), designed to minimize persistent retention at the model provider. Each API call to a language model is stateless: the model does not remember previous requests. Lyyli's own platform stores customer preferences, tone-of-voice guidelines, and content drafts in our EU-focused environment in line with our practices. ZDR does not mean that processing or transfers cannot occur in a third country; it describes limits on training use and retention. Legal requirements or abuse-prevention exceptions may also apply to the model provider.

6. Data Retention

We retain your personal data only as long as necessary:

  • To provide services to you
  • To comply with legal obligations
  • To resolve disputes and enforce agreements

When we no longer need your data (or when you delete an integration/account), we securely delete or anonymize the data.

7. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right to access your data
  • Right to rectification
  • Right to erasure ("right to be forgotten")
  • Right to restriction and objection to processing
  • Right to data portability
  • Automated decision-making (GDPR Art. 22): we do not make solely automated decisions based on your personal data that produce legal or similarly significant effects; AI supports human decision-making in client work and in the service

You can exercise your rights, such as requesting data deletion, by contacting us at hello@lyyli.ai or using in-app tools (if available).

8. Contact Us

If you have questions about this privacy policy or our data processing practices, please contact us:

  • Email: hello@lyyli.ai
  • Address: Petäiköntie 384, 77380 Kantala
  • Data Protection Officer: hello@lyyli.ai

9. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. We encourage you to review this policy regularly.