Trust & Security
The one page your security team will ask for. Lynx Seek AB · updated 2026-07-16.
Architecture & isolation
Lynx is managed and single-tenant: each customer’s workspace is a separate, isolated instance. Your prospect data lives in your instance, is exportable at any time (CSV/Excel), and is handed over and deleted at termination. Lynx’s business model is delivering intelligence — not owning or monetizing personal data. For customers with sovereignty requirements (e.g. public sector), a dedicated deployment on EU-owned infrastructure is available on request.
Sub-processors & international transfers
Data at rest stays in the EU. Where a provider has a US parent, transfers are covered by the EU–US Data Privacy Framework and/or Standard Contractual Clauses, and what crosses is minimized to the professional fields above.
The current full list and change notifications are part of our Data Processing Agreement.
Encryption & access control
TLS 1.2+ in transit; AES-256 at rest. Database access is server-side only, with service credentials that never reach the browser; client-side database access is denied entirely. Team members authenticate with individual tokens; workspaces are provisioned and approved by an administrator — there is no open self-service into a tenant.
GDPR operations — built in, not bolted on
A signed Data Processing Agreement (art. 28) comes with every commercial agreement. Every record carries provenance: source, capture time and who captured it. Erasure is real: a “forget person” request hard-deletes all data about the person and adds a hashed identifier to a suppression list so they can never re-enter through any capture path — only the hash is kept. Objections (art. 21) are honored immediately the same way. DSAR search and export are built into the product, and automated retention cleanup runs weekly.
AI use
AI is used to enrich company intelligence, score opportunities, and draft outreach suggestions. Scoring is decision support — no automated decisions with legal or similar effect are made about individuals (GDPR art. 22), and every outgoing message is reviewed and sent by a human. AI processing has daily budget caps, and our AI providers do not train on your data.
Incident response & continuity
We operate a documented breach runbook (contain → assess → notify). Customers are notified of a personal-data breach within 48 hours per the DPA — ahead of the GDPR 72-hour authority deadline. Provider status feeds (Supabase, Vercel, Google Cloud) are monitored. Automated daily database backups with point-in-time recovery [active at commercial launch].
What Lynx does not do
No selling or sharing of your data. No pooling of person data across customers. No training of AI models on your data. No automated sending of outreach. No consumer profiling, no special-category data, no facial recognition. No dark-pattern collection — capture is user-driven, by your own team, of professional content they actually view.
Security practices
Security at Lynx is documented and verifiable practice: recurring security audits with a logged trail of findings and fixes, a security checklist every new feature must pass before it ships, minimal-data design (professional fields only), and EU-first infrastructure choices. This page is kept current as the architecture evolves — and security questions are answered directly by the team, not a ticket queue: hello@lynxseek.com.