Privacy Policy

Last updated: 15 July 2026

1. Who we are

Verdix is a product of Lynora AB ("Lynora", "we", "us"), the data controller for personal data processed through the Verdix Revenue Intelligence platform. Lynora AB is incorporated in Sweden (Org. nr 559516-1190), with registered offices in Sweden. Our primary data infrastructure is hosted within the European Union.

2. What data we collect

We collect: (a) Account data — name, work email address, company name. (b) Contract documents you upload for analysis — these may contain personal data of your counterparties. (c) Billing records and invoices you upload. (d) Usage data and interaction logs for product improvement. (e) A timestamped record of your consent to this Privacy Policy and our Terms of Service at signup. We do not collect payment card data; payments are handled by our payment processor (Stripe).

3. Legal basis for processing

We process your data on the basis of: contract performance (to deliver the service you signed up for), legitimate interest (fraud prevention, product analytics), and consent (you explicitly agreed to this policy at account creation). Contract documents and billing records are processed solely on your instruction as our customer.

4. How we use your data — AI processing

Contract text is processed through Amazon Bedrock, a managed AI infrastructure service provided by Amazon Web Services (AWS). Before any text is sent for AI analysis, personally identifiable information (names, email addresses, and other identifiers) is detected and masked locally on our servers — tokens replace the real values, and the real values never leave our infrastructure. Extracted commercial terms (prices, dates, discounts) are stored in your organisation's account only. Verdix does not use customer contracts or customer data to train models. Contract content processed through Amazon Bedrock is not used to train foundation models.

5. Data retention

Verdix retains customer data while the customer's account and relevant agreements remain active. Customers may delete agreements and associated data through the service or request deletion. Following termination of the Verdix service, customer data is deleted within 30 days, except where certain records must be retained for legal, accounting, security or compliance purposes. Consent records are retained for 7 years for legal compliance purposes.

6. Transfers outside the EEA

AI processing is performed via Amazon Bedrock using EU-hosted AWS regions, meaning your contract data is processed within the European Economic Area and does not leave it for AI analysis. Verdix's core application processing and primary customer data storage are hosted within European infrastructure. Certain ancillary service providers, such as transactional email providers, may process limited personal data outside the EEA subject to appropriate data-transfer safeguards.

7. Your rights

Under GDPR you have the right to: access your personal data, correct inaccuracies, request erasure ("right to be forgotten"), restrict processing, data portability, and to object to processing. To exercise any of these rights, contact us at bilal@lynoraai.com. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or your local supervisory authority.

8. Security

Verdix uses encryption in transit and at rest across its core application infrastructure, together with access controls and other technical safeguards designed to protect customer data. Database access is restricted to authenticated application sessions. Access to production systems is restricted to named individuals on a need-to-know basis. PII masking is applied before any data leaves our servers for AI processing.

9. Contact

For privacy enquiries: bilal@lynoraai.com. Postal: Lynora AB, Sweden. Verdix is a trading name of Lynora AB (Org. nr 559516-1190).