Privacy Policy
We explain what personal data we process, why, who we share it with and what rights you have. Processing complies with Regulation (EU) 2016/679 (GDPR).
1. Controller
The controller of your data is NAKO AGENCY SRL, registration number 1020600005334, str. Mălina Mică 14, Chișinău, Republic of Moldova — the company behind Lyra. For any question about personal data, or to exercise the rights below, write to us at contact@nakoagency.com.
1-bis. Who answers for what
There are two kinds of data, with different roles. Your account and business data — email, organisation, team, sessions — we process as controller: we decide what we need in order to deliver the service, and you hold us to account for it. Your customers' data that reaches Lyra — the conversations they have with you, their contact details — is different: there you are the controller, and we process it as a processor, only on your instructions and only to make work what you asked for. In practice: if one of your customers asks for their data to be deleted or corrected, you decide and we carry it out. If a customer does not know who to ask, point them to you; if they write to us, we send them to you and let you know.
2. What we process
Account: email address and password (stored only as a hash). Business: organisation name, identifier (slug), your role in the team. Security: active sessions (browser and operating system, last activity), audit log (sign-ins, sign-outs, session revocations, invitations, suspensions), connection country code, 2FA factor and recovery codes (stored as hashes). Invitations: invited person's email and proposed role.
3. What we process from conversations, and what we do not
The AI agent reads the conversations with your customers in order to answer on your behalf — that is the service itself. We process them as a processor, on your instructions. To generate the reply, the text of the conversation reaches the language-model provider we name in section 5-bis. Beyond that it goes nowhere: we do not use conversation content to train any model, we do not send it to other third parties, and we do not use it for our own purposes. What we do not process at all: your raw IP address (we keep only the country code and a cryptographic fingerprint of the browser) and card data — payments are not active.
4. Why we process it (legal bases)
Performance of a contract (Art. 6(1)(b)): account creation, authentication, running the app. Legitimate interest (Art. 6(1)(f)): platform security, abuse prevention, audit logging, fixing errors. Legal obligation (Art. 6(1)(c)): records required by law. Consent (Art. 6(1)(a)): only where we ask for it explicitly.
5. Who else has access
Providers that help us deliver the service, each under a data processing agreement: Supabase (authentication and database, EU region), Vercel (web app hosting), Sentry (error monitoring), GitLab (continuous integration), Langfuse (observability of calls to the language model — receives only data about the call: the model, token usage, duration, error type and technical identifiers of your account and of the conversation, never the text of conversations), PostHog (measuring the pages you visit, only if you accept; hosted in the European Union). We do not sell personal data to anyone. Separately, only on the public pages and only if you accept session recording: Microsoft Corporation (Microsoft Clarity, United States) receives browsing data and also uses it for its own purposes, including advertising.
5-bis. The language-model provider
So that the agent can compose its reply, the text of the conversation reaches Anthropic. It receives only what is needed to generate the answer; we do not use it for anything else and do not send it to other third parties.
5-ter. Telegram
If you write to the salon through Telegram, your messages first pass through Telegram — it is the messaging service you use, with your own account, on its own terms. We receive there what you send us. Telegram does not process your messages at our request and does not act on our behalf: it has its own relationship with you and its own privacy policy.
6. Transfers outside the EU
Data is hosted in the European Union. Some processing takes place outside the European Union — see "Who else has access".
7. How long we keep it
Account data: for the life of the account plus up to 30 days after deletion (accidental recovery). Security audit log: 12 months. Sessions: until expiry or revocation. Unaccepted invitations: 7 days.
8. Your rights
You have the right of access, rectification, erasure, restriction, portability and objection. You can export your data directly in the app. To request erasure, or for any other request, write to our contact address. You have the right to lodge a complaint with a data protection authority. If you live in the European Union, you may address the authority of your country of residence. If you live in the Republic of Moldova, the competent authority is the National Center for Personal Data Protection (datepersonale.md).
9. Security
Encryption in transit (HTTPS), passwords stored only as hashes, optional two-step verification (TOTP), strict isolation between organisations at database level (row level security), audit logging for sensitive actions, sessions revocable from the app.
10. Minors
The service is aimed at businesses and people over 18. We do not knowingly collect minors' data. If you learn that a minor gave us data, write to us and we will delete it.
11. Usage analytics
For usage analytics and consent, see the Cookie Policy.