Skip to contentleitvik

Legal

Data processing terms

Last updated: 6 October 2026

These terms form part of the terms of service and apply whenever we process personal data on behalf of a customer in its workspace, as required by article 28 of the General Data Protection Regulation (GDPR). The customer is the controller and Pharosyne Tech SLU is the processor.

1. Subject matter and duration

We host and process the workspace data in order to provide Leitvik: storing, displaying, searching, importing, exporting and deleting it, and serving it through the API and the MCP endpoint to tokens the customer creates. Processing lasts while the contract is in force and until the workspace is deleted.

2. Data and people concerned

Business contact data about the customer's prospects, clients and contacts: names, roles, work email addresses and phone numbers, company details, notes, recorded interactions, signals with their sources, dossiers and, if enabled, attached files. Also the account data of the customer's users. The customer must not store special categories of personal data.

3. Our obligations

As processor we will:

  • process the data only on the customer's documented instructions, which are these terms, the settings chosen in the product and the requests made with its tokens, and tell the customer if we believe an instruction infringes data protection law;
  • make sure that anyone authorised to process the data is bound by confidentiality;
  • apply appropriate technical and organisational measures (art. 32 GDPR), including row-level isolation between workspaces, hashed tokens with limited permissions and expiry, encrypted connections and access limited to what is needed to operate the service;
  • help the customer answer data subject requests, mainly through the export and contact erasure tools, and with its obligations under articles 32 to 36 GDPR;
  • notify the customer of a personal data breach affecting its workspace without undue delay after becoming aware of it, with the information available at the time;
  • make available the information needed to demonstrate compliance with these obligations.

4. Sub-processors

The customer gives general authorisation for the sub-processors listed in the privacy policy. We will tell owners by email at least 30 days before adding or replacing one; if the customer objects for reasonable data protection reasons, it can terminate the contract and receive a pro-rata refund of the unused period. We impose on each sub-processor data protection obligations equivalent to these.

Assistants and tools that the customer connects with its own tokens are chosen by the customer and are not our sub-processors.

5. International transfers

Where a sub-processor processes data outside the European Economic Area, the transfer relies on an adequacy decision or on the European Commission's standard contractual clauses.

6. Return and deletion

The customer can export all workspace data as JSON at any time and delete the workspace from Settings. When the contract ends, we delete the workspace within 30 days of a written request, unless the law requires us to keep part of it. Copies in provider backups expire according to the provider's schedule.

7. Audits

We will answer reasonable written questions about our compliance. If that is not enough, the customer may carry out an audit once a year, at its own cost, with 30 days' notice and without access to other customers' data.

Back to home