Trust & Security

The one page your security team will ask for. Lynx Seek AB · updated 2026-07-16.

Your data, your instance
Every customer runs in an isolated, single-tenant instance. Person data is never pooled or shared across customers — and never sold.
Data at rest in the EU
Primary storage in Supabase EU-West; application compute pinned to Stockholm (Vercel arn1).
B2B professional data only
Name, title, company, business contact details, public professional signals. No consumer data, no special categories, no facial images.
Human in the loop
AI drafts and scores as decision support. A person reviews every message before it is sent — Lynx never sends outreach automatically.

Architecture & isolation

Lynx is managed and single-tenant: each customer’s workspace is a separate, isolated instance. Your prospect data lives in your instance, is exportable at any time (CSV/Excel), and is handed over and deleted at termination. Lynx’s business model is delivering intelligence — not owning or monetizing personal data. For customers with sovereignty requirements (e.g. public sector), a dedicated deployment on EU-owned infrastructure is available on request.

Sub-processors & international transfers

Data at rest stays in the EU. Where a provider has a US parent, transfers are covered by the EU–US Data Privacy Framework and/or Standard Contractual Clauses, and what crosses is minimized to the professional fields above.

ProviderRoleRegion / mechanism
SupabaseDatabase & storageEU-West region · DPA with SCCs
VercelApplication hostingCompute pinned Stockholm (arn1) · DPF
Google (Gemini)AI processing (enrichment, drafting)DPF · paid tier — no training on data
AnthropicAI processing (fallback only)DPF · API data not used for training
FullEnrichBusiness contact enrichmentFrance (EU)

The current full list and change notifications are part of our Data Processing Agreement.

Encryption & access control

TLS 1.2+ in transit; AES-256 at rest. Database access is server-side only, with service credentials that never reach the browser; client-side database access is denied entirely. Team members authenticate with individual tokens; workspaces are provisioned and approved by an administrator — there is no open self-service into a tenant.

GDPR operations — built in, not bolted on

A signed Data Processing Agreement (art. 28) comes with every commercial agreement. Every record carries provenance: source, capture time and who captured it. Erasure is real: a “forget person” request hard-deletes all data about the person and adds a hashed identifier to a suppression list so they can never re-enter through any capture path — only the hash is kept. Objections (art. 21) are honored immediately the same way. DSAR search and export are built into the product, and automated retention cleanup runs weekly.

AI use

AI is used to enrich company intelligence, score opportunities, and draft outreach suggestions. Scoring is decision support — no automated decisions with legal or similar effect are made about individuals (GDPR art. 22), and every outgoing message is reviewed and sent by a human. AI processing has daily budget caps, and our AI providers do not train on your data.

Incident response & continuity

We operate a documented breach runbook (contain → assess → notify). Customers are notified of a personal-data breach within 48 hours per the DPA — ahead of the GDPR 72-hour authority deadline. Provider status feeds (Supabase, Vercel, Google Cloud) are monitored. Automated daily database backups with point-in-time recovery [active at commercial launch].

What Lynx does not do

No selling or sharing of your data. No pooling of person data across customers. No training of AI models on your data. No automated sending of outreach. No consumer profiling, no special-category data, no facial recognition. No dark-pattern collection — capture is user-driven, by your own team, of professional content they actually view.

Security practices

Security at Lynx is documented and verifiable practice: recurring security audits with a logged trail of findings and fixes, a security checklist every new feature must pass before it ships, minimal-data design (professional fields only), and EU-first infrastructure choices. This page is kept current as the architecture evolves — and security questions are answered directly by the team, not a ticket queue: hello@lynxseek.com.

Related: Terms of Service · DPA and legitimate-interest assessment template available on request · Lynx Seek AB, Sweden.