Controller and scope
The controller for Elyno is the legal entity identified below. This policy applies to the Elyno applications, api.elyno.app, this website and related support services.
- Legal entity / data controller
- Elyno
- Registered address
- Moldova, Balti
- Privacy email
- [email protected]
- Application identifier
- com.elyno.elyno
For account and service administration, Elyno acts as controller. When a business user uploads documents containing data about customers, suppliers or employees, that business may be the controller and Elyno processes the content to provide the requested service.
Categories of data
Elyno processes only the categories needed for account security, document workflows, AI assistance, synchronization and support.
| Category | Examples | Main use | Typical retention |
|---|---|---|---|
| Account and identity | Email address, salted password hash, app and document languages, account status and user identifier. | Registration, authentication, account access and administration. | While the account is active; removed after verified account deletion unless a legal exception applies. |
| Business profile | Business and owner name, address, country, currency, activity, VAT status, tax identifiers, IBAN, BIC, logo and invoice template. | Localise the service, prepare invoices and reports, calculate summaries and synchronise the business workspace. | Until the user updates or deletes the information or deletes the account. |
| Uploaded documents and media | Receipt, invoice, letter, bank-statement and logo photos; PDF, XML and audio files; filenames and file metadata. | Store source evidence, analyse documents, transcribe voice input and let users view, export or share files. | Until the user deletes the file or account, subject to legal holds and backup rotation. |
| Financial and tax records | Income, expenses, amounts, VAT, currencies, dates, deadlines, categories, tax treatment, notes and review status. | Financial summaries, VAT estimates, reminders, document history and accountant packages. | Until the record or account is deleted; the business remains responsible for statutory record retention. |
| Bank reconciliation data | Statement transactions, dates, amounts, currency, payment references, counterparties and document matches. | Match bank activity to uploaded records and identify missing or uncertain documents. | Until the statement data, related record or account is deleted. |
| Invoices and generated files | Invoice numbers, customer details, payment terms, line items, PDF or XML invoices, reports and ZIP or PDF export packages. | Generate business documents and structured exports selected by the user. | Until the generated item or account is deleted, with backup expiry after rotation. |
| AI interactions | Prompts, document text and images sent for analysis, classification results, confidence values, chat messages, audio and transcripts. | Document extraction, AI chat, explanations, categorisation suggestions and voice transcription. | Elyno keeps saved results and chat history until cleared or deleted; provider processing follows the provider's API terms. |
| Support and privacy correspondence | Ticket type, subject, messages, account email, replies and up to five screenshots; website email-form content. | Answer questions, investigate errors, process rights requests and maintain support continuity. | While active and normally up to 24 months after closure, unless law requires a different period. |
| Device, session and security data | Access and refresh tokens, session identifiers, IP and rate-limit data, app platform, version, audit events and notification preference. | Secure access, prevent abuse, diagnose failures and deliver requested reminders. | Access tokens up to 24 hours, refresh sessions up to 90 days, and short-lived security records until expiry or investigation closure. |
| Address autocomplete data | Typed address fragments, selected country, language and returned place suggestions. | Provide optional address suggestions through Photon by Komoot. | Requests are transient for Elyno; the selected address is retained only if saved in the business profile. |
| VAT validation data | Country code, VAT number and the validation result returned by EU VIES. | Check a VAT identifier when the user requests validation. | The result may remain in the profile or related record until updated or deleted; VIES may keep operational logs under its rules. |
| Exchange-rate data | Source and target currencies, document date, official ECB or EU InforEuro rate and converted amounts. | Convert document values into the business-profile currency and preserve the rate used for review. | Saved conversion results remain with the related record until that record or account is deleted. |
| Store and subscription data | Apple or Google platform, product and subscription status, purchase or transaction reference and app installation information. | Distribute the app, confirm entitlement, restore purchases and manage subscription access. | While needed for the subscription, accounting, fraud prevention or legal claims; Apple and Google apply their own retention rules. |
Business documents may incidentally contain personal, financial, tax or government identifier data. Users should upload only information relevant to their business workflow and must have authority to process it.
Purposes and legal bases
Provide the service
Account access, synchronization, document analysis, invoices, reports, bank matching and support are processed to perform the user agreement.
Security and improvement
Rate limiting, audit history, fraud prevention, troubleshooting and service reliability are based on legitimate interests, balanced against user rights.
Permission-based features
Camera, photo library, files, microphone and notifications are used only after the user chooses the feature or grants the operating-system permission.
Legal obligations
Limited information may be retained or disclosed where required by applicable law, a binding authority request, security obligations or the establishment of legal claims.
Elyno does not sell personal data, does not use it for cross-app advertising and does not currently include third-party advertising or behavioural analytics SDKs.
This public website uses browser localStorage only to remember the selected language and does not set advertising cookies. Support form content is sent through Elyno's server and email provider for delivery; privacy forms open the user's email application.
Service providers and recipients
Data is shared only when needed for a selected feature, infrastructure operation, legal compliance or store distribution.
OpenAI
Provides document and image analysis, AI chat and voice transcription through server-side API requests. Elyno does not place the OpenAI API key in the mobile app.
Relevant prompts, document content, images, audio and technical request metadata.Photon by Komoot
Provides optional address autocomplete when a user types a business address.
Address fragments, language, country context and network request metadata.EU VIES
Checks EU VAT numbers when the validation feature is used.
Country code, VAT number and validation request metadata.European Central Bank and EU InforEuro
Supply official or institutional exchange-rate data used to convert a document amount into the profile currency.
Currencies, rate date and rate request; no source document is sent for this lookup.Private VPS and S3-compatible storage
Hosts Elyno's API, PostgreSQL database, admin service and managed files. Private S3-compatible storage is used only when configured.
Account, business, document, financial, support and technical data required to operate the service.Apple
Distributes the iOS app and may process device, download, subscription and payment information under Apple's terms.
Store account, device, installation, purchase and entitlement data managed by Apple.Distributes the Android app and may process device, download, subscription and payment information under Google's terms.
Google Play account, device, installation, purchase and entitlement data managed by Google.Email and support mailbox providers
Transmit and store messages when a user contacts support or submits a privacy request by email.
Sender and recipient addresses, subject, message, attachments and delivery metadata.International transfers
Some providers may process data outside the user’s country or the EEA. Where required, Elyno relies on an adequacy decision, Standard Contractual Clauses or another lawful transfer mechanism and applies data-minimisation and access controls.
Retention and backups
- Account and business recordsStored while the account is active and until the user deletes the item or account, unless a legal hold applies.
- Sessions and security dataAccess tokens last up to 24 hours; refresh sessions last up to 90 days and can end earlier on logout, revocation or account deletion. Short-lived rate-limit records are removed after expiry.
- Support correspondenceKept while the account or ticket is active and may be retained for up to 24 months after closure for continuity, security and legal claims, unless deletion is required sooner.
- AI provider processingRequests are retained by the configured AI provider only under its API terms and enterprise controls; Elyno keeps resulting account records until they are cleared or deleted.
- BackupsEncrypted or access-restricted backups, when enabled, may retain deleted data for up to 90 days before rotation. Backup data is isolated and used only for disaster recovery.
A business user remains responsible for any statutory retention period that applies to its accounting or tax records. Elyno does not preserve deleted records to satisfy that obligation unless legally required to do so.
Security
Elyno uses encrypted network transport, salted password hashing, protected mobile credentials, authenticated user-scoped file routes, private database access, encrypted server-side API secrets, rate limits and audit records. No system can guarantee absolute security, so users should protect their devices and account credentials.
Your privacy rights
Subject to applicable law, users may request access, correction, portability, deletion, restriction or objection, and may withdraw consent without affecting earlier lawful processing. Users may also complain to their competent data protection authority.
Open privacy request pageAccount and data deletion
Users can delete their account in Profile → Delete account or request deletion on the Privacy page. After verification, Elyno removes the account, profile, documents, managed files, bank transactions, chat history, generated records and support data from active systems. Processor deletion is requested where necessary. Residual backup copies expire within the backup period. Data required by law, security or legal claims may be isolated and retained only for that purpose.
Device permissions
Camera and photo/file access let users upload documents; microphone access records voice input for transcription; notifications provide task reminders. Elyno does not access these sources continuously, and permissions can be revoked in device settings.
Children
Elyno is a business service and is not directed to children. Users must be legally able to enter the service agreement and should not upload children’s data unless it is lawful, necessary and appropriately protected.
Apple and Google disclosures
The App Store privacy details and Google Play Data safety answers must remain consistent with this policy, including third-party processing. Apple and Google separately process store account, download, device and payment information under their own privacy policies.
Changes to this policy
The effective date is updated when this policy changes. Material changes may also be announced in the app or by email where required. Earlier versions may be requested from the privacy contact.
Contact
Contact the controller for privacy questions or exercise your rights using the details below.