This Privacy Policy explains how relyd processes personal data when relyd itself decides why and how the data is processed. This applies, for example, when you visit our websites, register, buy a subscription, contact us or apply for a job.
Data that our customers store in their relyd workspace is different. For that data (for example their customers, employees or suppliers), our customer is the controller and relyd acts as its processor. This is governed by our Data Processing Agreement. If you are an employee, customer or other contact of a company that uses relyd, please contact that company about your data.
1. Who is responsible
The controller is the relyd company that you deal with:
- relyd Limited, 3 Ballsbridge Park, Dublin, D04 C7H2, Ireland, for customers and prospects in the European Union, the European Economic Area, the United Kingdom, Switzerland and Liechtenstein, and for our websites;
- relyd Inc., 28-07 Jackson Ave, New York, NY 11101, USA, for customers and prospects in all other countries.
Contact for all data protection matters: privacy@relyd.co.
2. Which data we process, for what purpose and on what legal basis
We refer to the EU General Data Protection Regulation (GDPR). The same principles apply under the UK GDPR and the Swiss Federal Act on Data Protection (FADP).
2.1 Visiting our websites and the relyd application
When you visit www.relyd.co, legal.relyd.co or the relyd application, our systems process technical data:
-
IP address;
-
date and time;
-
requested page;
-
browser and operating system;
-
referring page;
-
security-related events (for example failed log-ins).
-
Purpose: delivering the pages, ensuring security, detecting and preventing attacks and misuse.
-
Legal basis: our legitimate interest in the secure operation of our services (Art. 6(1)(f) GDPR).
2.2 Registration and account
When you register, we process:
- your name;
- business e-mail address;
- company name;
- country;
- optionally a telephone number;
- your password, which is stored only as a bcrypt hash;
- your two-factor authentication settings.
If you sign in with Google or Microsoft, we receive your name, e-mail address and account identifier from that provider.
- Purpose: creating and managing your account, authenticating you, communicating with you about the service.
- Legal basis: performance of a contract and pre-contractual steps (Art. 6(1)(b) GDPR).
2.3 Subscription, billing and payment
We process:
- company and billing address;
- VAT or tax number;
- contact person;
- plan, modules and number of users;
- invoices and payment history.
Card and direct-debit payments are processed by our payment service provider. We receive only a reference, the card type and the last digits. We never receive the full card number or security code.
- Purpose: invoicing, collecting payments, accounting.
- Legal basis: performance of a contract (Art. 6(1)(b) GDPR) and legal obligations under tax and accounting law (Art. 6(1)(c) GDPR).
2.4 Operating and securing the platform
To keep the service secure and available, we process:
-
log-in events;
-
two-factor events;
-
IP addresses;
-
device and browser information;
-
error reports;
-
audit records of administrative actions.
-
Purpose: detecting and preventing unauthorised access and misuse, investigating incidents, error analysis, and enforcing our Acceptable Use Policy.
-
Legal basis: our legitimate interest in the security and integrity of the service and of our customers' data (Art. 6(1)(f) GDPR), and legal obligations where we must report or document incidents (Art. 6(1)(c) GDPR).
2.5 Support and communication
When you contact us by e-mail, chat, support ticket or telephone, we process:
-
your contact details;
-
the content of your request;
-
our correspondence.
-
Purpose: answering and resolving your request.
-
Legal basis: performance of a contract (Art. 6(1)(b) GDPR) or our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR).
2.6 Product news and marketing
We send news about relyd and our offers to customers by e-mail. You can object at any time using the link in every e-mail or by writing to privacy@relyd.co.
- Legal basis: our legitimate interest in direct marketing to existing customers, or your consent where required (Art. 6(1)(f) and (a) GDPR).
We do not sell personal data. We do not use advertising or tracking technologies on the relyd application.
2.7 Job applications
We process the data you send us in your application to assess it and, if successful, to prepare the employment contract. We keep it only as long as the application process requires and delete it as soon as the process is completed.
- Legal basis: pre-contractual steps (Art. 6(1)(b) GDPR, Art. 88 GDPR in conjunction with national law).
2.8 Legal claims and obligations
We process data to the extent necessary to establish, exercise or defend legal claims and to comply with legal obligations, for example requests from authorities.
- Legal basis: Art. 6(1)(c) and (f) GDPR.
3. Cookies and similar technologies
The relyd application uses only cookies that are necessary for its operation or that you set yourself, such as your language choice. We do not use analytics, advertising or social-media cookies in the application. These cookies do not require your consent.
| Name | Provider | Purpose | Lifetime |
|---|---|---|---|
relyd-session |
relyd | Keeps you signed in during a session (encrypted session identifier) | until you sign out, at most 2 hours of inactivity |
XSRF-TOKEN |
relyd | Protection against cross-site request forgery | same as the session |
remember_web_… |
relyd | "Stay signed in", only if you select this option | up to 12 months |
locale |
relyd | Remembers your language choice | 12 months |
__cflb |
Cloudflare | Routes your requests to the same server (load balancing) | 24 hours |
__cf_bm, cf_clearance |
Cloudflare | Bot and attack protection, only set when needed | 30 minutes |
The application also stores display preferences in your browser's local storage, for example collapsed menus. This data stays on your device.
Our website www.relyd.co
The website www.relyd.co is hosted by relyd on its own servers. Fonts are delivered from our servers; no requests are sent to font providers. Your language choice is stored in your browser's local storage.
- Consent management: we use Usercentrics (Usercentrics GmbH, Munich, Germany) to ask for and store your consent. Usercentrics stores your choice in your browser.
- Google Tag Manager: the website loads Google Tag Manager (Google Ireland Limited). Tag Manager itself does not set cookies. It currently does not load any analytics or advertising tools. If we add such tools in the future, they will only run after your consent, and we will list them here beforehand. Until you consent, Google's Consent Mode keeps all analytics and advertising storage switched off.
- Contact form: when you send us a message through the contact form, we process your name, e-mail address, company (if provided), the topic you select and your message to answer you. The message is delivered to us by e-mail through Resend (Resend, Inc., USA; EU-US Data Privacy Framework and standard contractual clauses). Legal basis: pre-contractual steps or our legitimate interest in answering enquiries (Art. 6(1)(b) and (f) GDPR).
You can change or withdraw your consent at any time through the privacy settings (Usercentrics) on the website.
4. Recipients
Within relyd, only the people who need your data for the purposes above have access to it.
We use carefully selected service providers ("processors"), for example for:
- hosting;
- network protection;
- e-mail;
- payments;
- customer support.
They process personal data only on our instructions and under data processing agreements. The current list, with the purpose and location of each provider, is published at legal.relyd.co/subprocessors.
We disclose data to authorities, courts or advisers (for example auditors and lawyers) only where we are legally required to or where it is necessary to protect our rights.
5. International transfers
We store our customers' application data in data centres of our hosting provider in the EU: application and database servers and backups in Germany (Frankfurt), files, the retention archive and the cache service in France (Gravelines). We also use a secondary application server in the United Kingdom (London).
Some of our service providers are located in, or may access data from, countries outside the EU, the EEA, the UK and Switzerland, in particular the United States:
- for countries with an adequacy decision (for example the United Kingdom and, for certified companies, the United States under the EU-US Data Privacy Framework and its UK and Swiss extensions), we rely on that decision;
- otherwise we use the European Commission's standard contractual clauses (with the UK Addendum and the Swiss adaptations), together with additional measures where needed.
You can request a copy of the safeguards at privacy@relyd.co.
6. How long we keep data
| Data | Retention |
|---|---|
| Account data | for the duration of the contract; after its end as described in the Data Processing Agreement for workspace data |
| Contract and billing records | as long as required by commercial and tax law (generally up to 10 years) |
| Security and application logs | up to 30 days; longer only if needed to investigate a specific incident |
| Support correspondence | 3 years after the request is closed |
| Marketing | until you object or withdraw consent |
| Job applications | only as long as the application process requires; deleted as soon as it is completed |
| Backups | encrypted backups expire automatically, at the latest after 12 months |
7. Security
We protect personal data with technical and organisational measures appropriate to the risk. These include:
- encrypted connections;
- separation of each customer's data, with a separate database for new workspaces;
- role-based access control;
- two-factor authentication;
- encrypted, write-protected backups stored in a separate location;
- regular security reviews and testing.
Details are set out in Annex 2 of our Data Processing Agreement.
8. Your rights
You have the right to:
- access your data;
- have it rectified;
- have it erased;
- restrict processing;
- data portability;
- object to processing based on legitimate interests, including direct marketing at any time.
Where we rely on your consent, you may withdraw it at any time with effect for the future.
To exercise your rights, write to privacy@relyd.co. We may ask you to verify your identity.
You also have the right to lodge a complaint with a supervisory authority, in particular:
- Ireland: Data Protection Commission, www.dataprotection.ie
- Switzerland: Federal Data Protection and Information Commissioner (FDPIC), www.edoeb.admin.ch
- United Kingdom: Information Commissioner's Office (ICO), www.ico.org.uk
- or the authority in the country where you live or work.
9. Automated decisions
We do not make decisions based solely on automated processing that have legal or similarly significant effects on you.
10. Children
Our services are intended for businesses. We do not knowingly process data of children.
11. Changes
We update this Privacy Policy when our processing changes. The current version and all previous versions, with their effective dates, are available at legal.relyd.co.