Skip to contentleitvik

Legal

Privacy policy

Last updated: 6 October 2026

This policy explains how we process personal data when you visit leitvik.com, request access or use Leitvik. It also explains the different role we play for the CRM data that customers keep in their workspaces.

1. Who is responsible

The controller is Pharosyne Tech SLU, NIF B25961095; full company details are in the legal notice. For any privacy question or request write to hello@pharosyne.tech. We have not appointed a data protection officer because the law does not require one for this activity.

2. Two different roles

For website visitors, access requests, user accounts and billing, we decide how data is used and act as controller.

For the CRM data a customer keeps in its workspace (its leads, contacts, notes, signals and files), the customer is the controller and we act as its processor under the data processing terms. If your details are in a customer's CRM, contact that customer to exercise your rights; we will help them answer.

3. What we process, why and on what basis

  • Access requests: the email address you leave on the request form, to reply and set up your workspace. Basis: steps you ask us to take before a contract (art. 6.1.b GDPR). We delete it when we handle or dismiss the request.
  • Accounts: name, email, workspace memberships and roles, sign-in records (sessions with IP address and browser, passkeys, and recovery codes stored as hashes). Purpose: to provide the service and keep accounts secure. Basis: the contract (art. 6.1.b).
  • Transactional email: sign-in links and invitations sent to your address. Basis: the contract (art. 6.1.b).
  • Billing: plan, subscription status, Paddle customer identifier and billing email. Paddle processes the payment data itself. Basis: the contract and our accounting and tax obligations (art. 6.1.b and 6.1.c).
  • Security and abuse prevention: rate limiting and a Cloudflare Turnstile check on sign-in and request forms. Basis: our legitimate interest in protecting the service and its users (art. 6.1.f).
  • Messages you send us: their content and your contact details, to answer you. Basis: our legitimate interest in replying, or the contract if you are a customer.

4. Cookies and local storage

We only use what the service needs to work: the session cookie that keeps you signed in, a cookie that remembers the selected workspace, one for your language, and local storage for the display theme. Cloudflare Turnstile may store data in your browser to tell people from bots on the forms. We do not use analytics, advertising cookies or tracking pixels, so no consent banner is needed. If that changes, we will ask for consent first.

5. Who receives data

We do not sell personal data. These providers process data on our behalf to run the service:

  • Vercel: hosting of the website, the application, the API and the MCP endpoint.
  • Neon: the PostgreSQL database.
  • Cloudflare: bot protection (Turnstile), domain DNS and background jobs; file storage (R2) only if attachments are enabled.
  • Resend: delivery of sign-in and invitation emails.
  • Paddle.com: payment processing, invoicing and tax as merchant of record. Paddle acts as an independent controller for the purchase.

6. Features that are not active

Connecting a Google mailbox and AI features run by Leitvik itself exist in the code but are switched off. If we turn either on, we will add the provider to this list and notify customers beforehand. An assistant that you connect with your own token is your choice and is not our provider.

7. International transfers

The CRM database is hosted in Frankfurt (Germany): Neon runs it in the AWS eu-central-1 region. Hosting and email providers may process data outside the European Union, always under the safeguards described below.

Some providers are established in the United States or the United Kingdom, or may process data there. Those transfers rely on an adequacy decision of the European Commission (including the EU-US Data Privacy Framework for certified companies, and the decision for the United Kingdom) or, failing that, on the Commission's standard contractual clauses.

8. How long we keep data

Account data is kept while the account exists. A workspace and its CRM data are kept until an owner deletes it from Settings, or until we delete it at your written request after the contract ends. Billing records are kept for the period required by tax law. Access requests are deleted once handled. Backups and logs held by our providers expire according to their own schedules.

9. Your rights

You can ask for access to your data, its rectification or erasure, the restriction of its processing, its portability, or object to processing based on legitimate interest. Write to hello@pharosyne.tech; we will answer within one month. If you are not satisfied, you can complain to the Spanish Data Protection Agency (Agencia Española de Protección de Datos, aepd.es).

10. Security

Every workspace query runs with database row-level security bound to that workspace. API tokens and recovery codes are stored as hashes, connections use HTTPS, and passkeys are available for sign-in.

11. Changes

If we change this policy in a way that matters, we will tell users by email or in the app before it applies.

Back to home