Privacy Notice and Privacy Policy
Last updated: 13.07.2026
Next review: 01.10.2026
This privacy notice comprehensively describes how Lyyli AI Oy (as data controller) collects, processes, transfers, and protects your personal data in compliance with the General Data Protection Regulation (GDPR). The notice clearly separates processing activities and cookie practices for the marketing website (lyyli.ai) and the product (lyyli.app), explains outbound communications and meeting agent data flows, and sets out your statutory rights as a data subject.
At Lyyli, we are committed to protecting your privacy and ensuring strict compliance with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws. This notice describes how we collect, use, process, and protect your personal data.
This notice covers the Lyyli service in its entirety. The public marketing website (lyyli.ai) and our application product (lyyli.app) are clearly distinguished in this notice, especially regarding cookies and tracking (see Section 7).
Data controller
- Company: Lyyli AI Oy
- Business ID (Y-tunnus): 3537519-5
- Address: Petäiköntie 384, 77380 Kantala
- Privacy contact address: hello@lyyli.ai
Lyyli AI Oy does not have a formally appointed Data Protection Officer (DPO). For privacy matters, you can contact our privacy team directly at hello@lyyli.ai.
1. Data collection
We collect information that you provide to us directly when using the service. This includes:
- Contact details: name, email address, phone number.
- Company and role information: company name, job title, and areas of responsibility.
- Communication preferences and team size: settings chosen by the user and the scope of the organisation.
- Messages and content: content you choose to share with our AI-assisted communication assistant (such as prompts, texts, and documents).
When a customer organisation stores content in the Lyyli service relating to its employees, customers, meeting participants, or other individuals, the customer acts as the data controller and Lyyli acts as a processor under the applicable Data Processing Agreement (DPA).
Third-party integrations
If you connect your Lyyli.ai account to a service provided by a third party (such as LinkedIn, Microsoft Teams, Slack, or email services), we receive information from that service in accordance with the authorisation you provide. This may include user profile information (such as name and profile picture), network information, and message content. We use this transferred information solely to provide the service, such as creating message drafts or preparing approved content in accordance with your instructions. There are no direct channel publishing APIs; approved content is taken to the destination platform.
2. How we use your data
We use the information we collect for the following specifically defined purposes:
- To provide and improve our AI-based communication services.
- AI-assisted work and customer service: we support client work, communications, and content preparation using AI tools and integrations. Personal data is protected and processed through the service routes in use to deliver the service and ensure its quality.
- To respond to your enquiries and provide technical customer support.
- To send system and service updates and important administrative notifications.
- To analyse platform usage patterns so we can improve service performance and security.
- To enable integrations with third-party services (always at the user's own request and with consent).
- To manage customer accounts, billing, and contractual obligations.
- To ensure system security, prevent misuse, and audit measures taken.
2b. Outbound communications and prospecting
In sales and marketing, we may process contact details and expressions of interest from potential customers in the following situations:
- When you complete a contact form, book a demo, register for a webinar, or otherwise contact us.
- When you use our campaign links (UTM parameters and click identifiers are stored after you give consent).
- When we synchronise potential customer information to our CRM system (such as Pipedrive) to manage sales and customer relationships.
- When we send service-related messages to which you have given consent or for which we have another lawful basis.
Sources of information
- Companies' public websites and professional social media profiles (such as LinkedIn).
- Public business registers, prior CRM history, or previous contact.
- Commercial partners and contact information services where applicable.
Purpose and legal basis for processing
The aim is to identify relevant business decision-makers (B2B contacts), offer services related to their work responsibilities, manage communication opt-outs, and measure the effectiveness of sales activities. The legal basis for processing is legitimate interest (GDPR Article 6(1)(f)). Direct electronic marketing is assessed case by case based on role and work contact details in accordance with applicable legislation.
We may use information to define an ideal customer profile (ICP), prioritise workflows, and classify outreach. This processing does not involve automated decision-making or profiling that would have significant legal effects for the data subject or lead to binding automated decisions.
You have the right to object to direct marketing at any time without giving reasons. Objection requests are processed without delay. You can send your request to hello@lyyli.ai.
2c. Meeting agent and recordings
If you enable the AI Meeting Agent or connect your calendar or video conferencing service (such as Google Meet, Microsoft Teams, or Zoom) to Lyyli, we may process the following information:
- Meeting invitations, basic participant information, and calendar event details.
- Meeting transcripts, speaker identification, and analyses and summaries derived from meeting discussions.
- Meeting recordings and related metadata to deliver the service and ensure quality.
The customer organisation is independently responsible for informing meeting participants about recording and transcription in accordance with applicable law and its own internal policies. Lyyli acts as a processor for customer-defined meeting data under the Data Processing Agreement (DPA).
2d. Public links, integrations, and external commenting
When you use different features of the service, we may process personal data in the following contexts:
- When you share produced content to third-party platforms (such as LinkedIn) at the user's explicit request.
- When you create and share a secure viewing link for external commenting or approval.
- When you enable Microsoft Teams, Slack, or email-specific integrations.
- When the Idea Collector or a similar bot collects ideas from designated chat channels in accordance with your organisation's settings.
The customer fully controls shared review links, their validity periods, and revocation of access, and is independently responsible for who links and access are shared with.
2e. Integration data
When a customer connects integrations to the system (such as email, calendar, Slack, Teams, LinkedIn, Google, or Microsoft services), we process data from these external services in accordance with the customer's instructions to provide the service (for example, creating message drafts, analysing calendar events, or content approval workflows). There are no direct channel publishing APIs. Processing of integration data is always governed by the customer's instructions and the DPA, under which Lyyli acts as a processor.
2f. Controller-side service providers
The following providers support Lyyli's own business operations and are not product subprocessors for customer workspace data. They are listed in our vendor register:
- Stripe: payment processing, fraud prevention, and subscription billing. Stripe may act as an independent controller for certain risk, fraud, and KYC processing.
- Pipedrive: B2B prospecting and CRM for sales leads and demo requests. Not a subprocessor for customer product data.
- Slack: internal team communication only. Not used to deliver the customer-facing product.
- PostHog and Cookiebot: marketing website analytics and consent management (lyyli.ai), subject to cookie consent.
Product subprocessors for the Lyyli application are listed in Annex 5 of the DPA and in the Trust Center vendor register.
3. GDPR compliance and legal bases for processing
As a partner to expert organisations and regulated industries, we ensure and verify full compliance with the General Data Protection Regulation (GDPR):
- Legal bases for processing: We process personal data primarily for the performance of a contract (GDPR Article 6(1)(b)) and on the basis of legitimate interests (GDPR Article 6(1)(f)), for example to ensure service security, functionality, and administration. In certain situations, such as continuous retrieval of data from third-party integrations, we request separate consent from the user (GDPR Article 6(1)(a)). AI-assisted work and user support are based on contract or legitimate interest. The system does not make solely automated decisions that would have significant legal effects for the data subject (see Section 8).
- Data minimisation: We collect and process only personal data that is necessary to fulfil the defined purposes of use.
- Withdrawal of consent: You may withdraw consent you have given (for example, regarding integrations or cookies) at any time directly from the service settings or by contacting us.
4. Sharing data and third parties
We do not sell, rent, or share your personal data with third parties for their direct marketing purposes. Data is shared and disclosed only in the following limited situations:
- Service providers and AI tools: Language-model requests go through Vercel AI Gateway to Anthropic, Google Vertex AI and OpenAI. Language models process requests under Zero Data Retention; Lyyli stores conversations for service functionality. Processing region is model-specific and described in the AI model register. Lyyli's product technical subprocessors are listed in our separate subprocessor list (Annex 5).
- Channel publishing: Lyyli does not provide direct publishing APIs. When a user approves ready content and publishes it themselves on a destination platform, further processing of the data is subject to that platform's own terms of use and privacy notices.
- International data transfers: Personal data may be transferred outside the EU and EEA (such as to the United States) in the infrastructure of our service providers. These transfers are implemented using lawful safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission and the EU–US Data Privacy Framework, supplemented where necessary with additional technical safeguards.
Please note that Lyyli.ai is not affiliated with Meta, LinkedIn, or other social media platforms, and these platforms do not sponsor, manage, or take responsibility for our application.
5. Data security
We implement compliant and appropriate technical and organisational security measures to protect your personal data:
- Strong TLS encryption for all data traffic and transfers.
- Infrastructure-level encryption controls for all data at rest.
- Regular system security audits, vulnerability scans, and testing.
- Strict role-based access control (RBAC) and multi-factor authentication (MFA).
- Documented incident management and data breach notification procedures.
Zero Data Retention (ZDR) policy
We use advanced language models in the Lyyli service. Requests are processed under Zero Data Retention (ZDR) via Vercel AI Gateway: the model provider does not retain the prompt or response after the request. Lyyli stores the user's conversations for service functionality in its own EU environment. Claude and Gemini model inference is locked to the EU; GPT model processing cannot currently be limited to the EU only. ZDR does not automatically cover image generation, web search, meeting recordings or abuse monitoring logs — these are described in the AI model register. Statutory exceptions arising from regulatory requirements or misuse prevention may also apply to AI partners.
6. Data retention period
We retain your personal data only for as long as necessary to fulfil the purposes of use described in this notice:
- To maintain the customer relationship and provide the service.
- To comply with statutory obligations, such as accounting legislation.
- To resolve potential disputes and enforce agreements.
When your personal data is no longer needed, or when you request deletion of your account or specific integrations, the data is deleted from active systems or permanently anonymised without undue delay.
7. Cookies and tracking on the marketing website (lyyli.ai)
On our public marketing website (lyyli.ai), we use essential cookies so that the site works correctly from a technical perspective. All other visitor tracking, such as analytics, performance monitoring, and advertising measurement, is enabled only if you give explicit consent (opt-in) in our cookie banner. You can change your settings and withdraw consent at any time.
The application environment (lyyli.app) is free of marketing cookies
In the actual Lyyli service (lyyli.app), we do not use marketing cookies or advertising tracking at all. The application does not use Google Ads, LinkedIn Insight Tag, or other remarketing solutions. In-product functional analytics, system subprocessors, and data processing are described in more detail in the application's privacy notice and subprocessor list.
Tracking solutions used on the marketing website (lyyli.ai)
- Cookiebot: Cookie consent management (CMP) (technically essential, no consent required). (essential)
- Google Analytics 4: Visitor analytics (requires acceptance of statistics cookies). (consent)
- Google Ads: Advertising conversion tracking and remarketing (requires acceptance of marketing cookies). (consent)
- LinkedIn Insight Tag: Advertising performance measurement and targeting (requires acceptance of marketing cookies). (consent)
Transfers outside the EU
Google and LinkedIn are US companies. With your consent, collected data may be transferred for processing to the United States in accordance with the EU–US Data Privacy Framework, or Standard Contractual Clauses (SCCs) with service providers are used to safeguard transfers.
Campaign and click data
Campaign parameters (UTM tags) and click identifiers (such as Google's gclid, wbraid, and gbraid or LinkedIn's li_fat_id) are stored in your browser memory only if you have given consent to tracking. This information may be transferred from the marketing website to the application (lyyli.app) via an encrypted handoff mechanism to measure sales attribution. This transfer does not set third-party marketing cookies within the application.
Retention periods
Google Analytics 4 analytics data is retained in our systems for 14 months. Retention periods for cookies and conversion data collected by advertising platforms are determined by each platform's own privacy policies. Consent information you provide in Cookiebot is stored in your browser until the cookie expires or you withdraw consent in your cookie settings.
Cookie declaration
8. Your rights as a data subject
Under the General Data Protection Regulation (GDPR), you have the following statutory rights relating to your personal data:
- Right of access: You may request confirmation of whether we process your personal data and obtain a copy of the information concerning you.
- Right to rectification: You may request correction of inaccurate or incomplete data about you.
- Right to erasure: You may request deletion of your data from our systems (right to be forgotten) within the limits of applicable law.
- Right to restriction and objection: In certain situations, you may require us to restrict processing of your data or object to processing based on our legitimate interests.
- Right to data portability: You may request transfer of data you have actively provided in a machine-readable format to yourself or another service provider.
- Automated decision-making: In accordance with GDPR Article 22, we confirm that we do not make solely automated decisions based on your personal data that would have legal effects for you. AI always acts as a support and aid to human decision-making.
- Right to lodge a complaint with a supervisory authority: If you believe that processing of your personal data violates data protection legislation, you have the right to lodge a complaint with the Office of the Data Protection Ombudsman (tietosuoja.fi).
- Right to object to direct marketing and related profiling.
We always verify the identity of the person making a request before implementing data protection rights and disclosing data to prevent misuse. You can exercise your rights by emailing us at hello@lyyli.ai or by using the application's own settings pages.
9. Contact us
If you have questions about this privacy notice, processing activities relating to your data, or wish to exercise your rights, please contact our specialists directly:
- General customer service and administration: hello@lyyli.ai
- Company address: Lyyli AI Oy, Petäiköntie 384, 77380 Kantala
10. Changes to this notice
We may update this privacy notice to reflect changes in our legal or technical practices. We will inform customers of significant and material changes by publishing a new version on this page and updating the "Last updated" date at the beginning of the notice.