01

Controller and scope

The controller for Elyno is the legal entity identified below. This policy applies to the Elyno applications, api.elyno.app, this website and related support services.

Legal entity / data controller
Elyno
Registered address
Moldova, Balti
Privacy email
[email protected]
Application identifier
com.elyno.elyno

For account and service administration, Elyno acts as controller. When a business user uploads documents containing data about customers, suppliers or employees, that business may be the controller and Elyno processes the content to provide the requested service.

02

Categories of data

Elyno processes only the categories needed for account security, document workflows, AI assistance, synchronization and support.

Category Examples Main use Typical retention
Account and identity Email address, salted password hash, app and document languages, account status and user identifier. Registration, authentication, account access and administration. While the account is active; removed after verified account deletion unless a legal exception applies.
Business profile Business and owner name, address, country, currency, activity, VAT status, tax identifiers, IBAN, BIC, logo and invoice template. Localise the service, prepare invoices and reports, calculate summaries and synchronise the business workspace. Until the user updates or deletes the information or deletes the account.
Uploaded documents and media Receipt, invoice, letter, bank-statement and logo photos; PDF, XML and audio files; filenames and file metadata. Store source evidence, analyse documents, transcribe voice input and let users view, export or share files. Until the user deletes the file or account, subject to legal holds and backup rotation.
Financial and tax records Income, expenses, amounts, VAT, currencies, dates, deadlines, categories, tax treatment, notes and review status. Financial summaries, VAT estimates, reminders, document history and accountant packages. Until the record or account is deleted; the business remains responsible for statutory record retention.
Bank reconciliation data Statement transactions, dates, amounts, currency, payment references, counterparties and document matches. Match bank activity to uploaded records and identify missing or uncertain documents. Until the statement data, related record or account is deleted.
Invoices and generated files Invoice numbers, customer details, payment terms, line items, PDF or XML invoices, reports and ZIP or PDF export packages. Generate business documents and structured exports selected by the user. Until the generated item or account is deleted, with backup expiry after rotation.
AI interactions Prompts, document text and images sent for analysis, classification results, confidence values, chat messages, audio and transcripts. Document extraction, AI chat, explanations, categorisation suggestions and voice transcription. Elyno keeps saved results and chat history until cleared or deleted; provider processing follows the provider's API terms.
Support and privacy correspondence Ticket type, subject, messages, account email, replies and up to five screenshots; website email-form content. Answer questions, investigate errors, process rights requests and maintain support continuity. While active and normally up to 24 months after closure, unless law requires a different period.
Device, session and security data Access and refresh tokens, session identifiers, IP and rate-limit data, app platform, version, audit events and notification preference. Secure access, prevent abuse, diagnose failures and deliver requested reminders. Access tokens up to 24 hours, refresh sessions up to 90 days, and short-lived security records until expiry or investigation closure.
Address autocomplete data Typed address fragments, selected country, language and returned place suggestions. Provide optional address suggestions through Photon by Komoot. Requests are transient for Elyno; the selected address is retained only if saved in the business profile.
VAT validation data Country code, VAT number and the validation result returned by EU VIES. Check a VAT identifier when the user requests validation. The result may remain in the profile or related record until updated or deleted; VIES may keep operational logs under its rules.
Exchange-rate data Source and target currencies, document date, official ECB or EU InforEuro rate and converted amounts. Convert document values into the business-profile currency and preserve the rate used for review. Saved conversion results remain with the related record until that record or account is deleted.
Store and subscription data Apple or Google platform, product and subscription status, purchase or transaction reference and app installation information. Distribute the app, confirm entitlement, restore purchases and manage subscription access. While needed for the subscription, accounting, fraud prevention or legal claims; Apple and Google apply their own retention rules.

Business documents may incidentally contain personal, financial, tax or government identifier data. Users should upload only information relevant to their business workflow and must have authority to process it.

03

Purposes and legal bases

Provide the service

Account access, synchronization, document analysis, invoices, reports, bank matching and support are processed to perform the user agreement.

Security and improvement

Rate limiting, audit history, fraud prevention, troubleshooting and service reliability are based on legitimate interests, balanced against user rights.

Permission-based features

Camera, photo library, files, microphone and notifications are used only after the user chooses the feature or grants the operating-system permission.

Legal obligations

Limited information may be retained or disclosed where required by applicable law, a binding authority request, security obligations or the establishment of legal claims.

Elyno does not sell personal data, does not use it for cross-app advertising and does not currently include third-party advertising or behavioural analytics SDKs.

This public website uses browser localStorage only to remember the selected language and does not set advertising cookies. Support form content is sent through Elyno's server and email provider for delivery; privacy forms open the user's email application.

04

Service providers and recipients

Data is shared only when needed for a selected feature, infrastructure operation, legal compliance or store distribution.

OpenAI

Provides document and image analysis, AI chat and voice transcription through server-side API requests. Elyno does not place the OpenAI API key in the mobile app.

Relevant prompts, document content, images, audio and technical request metadata.

Photon by Komoot

Provides optional address autocomplete when a user types a business address.

Address fragments, language, country context and network request metadata.

EU VIES

Checks EU VAT numbers when the validation feature is used.

Country code, VAT number and validation request metadata.

European Central Bank and EU InforEuro

Supply official or institutional exchange-rate data used to convert a document amount into the profile currency.

Currencies, rate date and rate request; no source document is sent for this lookup.

Private VPS and S3-compatible storage

Hosts Elyno's API, PostgreSQL database, admin service and managed files. Private S3-compatible storage is used only when configured.

Account, business, document, financial, support and technical data required to operate the service.

Apple

Distributes the iOS app and may process device, download, subscription and payment information under Apple's terms.

Store account, device, installation, purchase and entitlement data managed by Apple.

Google

Distributes the Android app and may process device, download, subscription and payment information under Google's terms.

Google Play account, device, installation, purchase and entitlement data managed by Google.

Email and support mailbox providers

Transmit and store messages when a user contacts support or submits a privacy request by email.

Sender and recipient addresses, subject, message, attachments and delivery metadata.
05

International transfers

Some providers may process data outside the user’s country or the EEA. Where required, Elyno relies on an adequacy decision, Standard Contractual Clauses or another lawful transfer mechanism and applies data-minimisation and access controls.

06

Retention and backups

  • Account and business recordsStored while the account is active and until the user deletes the item or account, unless a legal hold applies.
  • Sessions and security dataAccess tokens last up to 24 hours; refresh sessions last up to 90 days and can end earlier on logout, revocation or account deletion. Short-lived rate-limit records are removed after expiry.
  • Support correspondenceKept while the account or ticket is active and may be retained for up to 24 months after closure for continuity, security and legal claims, unless deletion is required sooner.
  • AI provider processingRequests are retained by the configured AI provider only under its API terms and enterprise controls; Elyno keeps resulting account records until they are cleared or deleted.
  • BackupsEncrypted or access-restricted backups, when enabled, may retain deleted data for up to 90 days before rotation. Backup data is isolated and used only for disaster recovery.

A business user remains responsible for any statutory retention period that applies to its accounting or tax records. Elyno does not preserve deleted records to satisfy that obligation unless legally required to do so.

07

Security

Elyno uses encrypted network transport, salted password hashing, protected mobile credentials, authenticated user-scoped file routes, private database access, encrypted server-side API secrets, rate limits and audit records. No system can guarantee absolute security, so users should protect their devices and account credentials.

08

Your privacy rights

Subject to applicable law, users may request access, correction, portability, deletion, restriction or objection, and may withdraw consent without affecting earlier lawful processing. Users may also complain to their competent data protection authority.

Open privacy request page
09

Account and data deletion

Users can delete their account in Profile → Delete account or request deletion on the Privacy page. After verification, Elyno removes the account, profile, documents, managed files, bank transactions, chat history, generated records and support data from active systems. Processor deletion is requested where necessary. Residual backup copies expire within the backup period. Data required by law, security or legal claims may be isolated and retained only for that purpose.

10

Device permissions

Camera and photo/file access let users upload documents; microphone access records voice input for transcription; notifications provide task reminders. Elyno does not access these sources continuously, and permissions can be revoked in device settings.

11

Children

Elyno is a business service and is not directed to children. Users must be legally able to enter the service agreement and should not upload children’s data unless it is lawful, necessary and appropriately protected.

12

Apple and Google disclosures

The App Store privacy details and Google Play Data safety answers must remain consistent with this policy, including third-party processing. Apple and Google separately process store account, download, device and payment information under their own privacy policies.

13

Changes to this policy

The effective date is updated when this policy changes. Material changes may also be announced in the app or by email where required. Earlier versions may be requested from the privacy contact.

14

Contact

Contact the controller for privacy questions or exercise your rights using the details below.

Legal entity / data controllerElyno
Registered addressMoldova, Balti
Privacy email[email protected]
Support email[email protected]