Privacy policy
- Last updated
- 2026-07-16
- Effective
- 2026-04-19
This Privacy Policy explains what personal data Osyra, Inc. (“Osyra”, “we”, “us”) collects, why we collect it, how we use and share it, and the choices you have. For Customer Content submitted through the Service after launch, Osyra will act as a processor where the executed customer agreement and applicable law establish that role.
01Scope and roles
This policy applies to personal data we process about:
- Visitors to osyra.ai and our other public properties.
- Authorised users of the Service (the “Users”), including those configured by an administrator on a Customer's account.
- Prospects, contacts, partners, and applicants we engage with directly.
Controller / processor allocation. Osyra acts as a controller for account, billing, and marketing data. Osyra acts as a processor for Customer Content (prompts, completions, embeddings, file uploads, and routing metadata) processed on the instruction of a Customer; the Customer is the controller of that data.
02Data we collect
We collect only what we need to operate the Service, secure it, bill for it, and support you.
Personal-data categories, examples, and sources Category Examples Source Account Name, email, organization, role, password hash You, your administrator Authentication MFA token, IP address, device fingerprint, session Your device Billing At launch: payment token managed by Stripe, billing address, invoices, tax ID You, Stripe Usage telemetry Request counts, latency, token counts, response codes, cost Your interactions Customer Content Prompts, completions, embeddings, uploaded files Your applications Support Tickets, attachments, correspondence You Web analytics Planned public-site metrics: page view, referrer, and country via Plausible Your browser 03How we use data
We use personal data to:
- provide, maintain, and secure the Service;
- authenticate Users and prevent fraud or abuse;
- invoice for the Service and collect payment;
- respond to support requests and other inquiries;
- send service-related notices (security alerts, billing receipts, important product changes);
- with consent or where otherwise permitted, send product news, event invitations, and other marketing;
- comply with legal obligations and respond to lawful requests from public authorities.
Lawful basis (GDPR / UK GDPR). Our lawful basis is one of: (a) the performance of a contract with you, (b) compliance with a legal obligation, (c) our legitimate interests in operating, securing, and improving the Service (where not overridden by your interests), or (d) your consent (which you may withdraw at any time).
No model training on Customer Content. We do not use Customer Content to train Osyra models, and we do not authorize sub-processors to use Customer Content for their model training. Telemetry derived from Customer Content is aggregated and de-identified before any internal product analytics use.
05International transfers
Before a production route transfers personal data out of its country of origin, the applicable customer agreement must establish a lawful transfer mechanism and required supplementary measures. The pre-release DPA package provides for the European Commission's Standard Contractual Clauses and UK transfer terms where applicable.
06Retention
We retain personal data for as long as needed to provide the Service and as required by law. The launch policy targets the following defaults, subject to the executed Order Form and workspace controls:
- Account and billing records — 7 years from account closure (audit / tax).
- Audit logs and security receipts — 7 years (compliance: SOC 2 retention, EU AI Act Art. 12 records).
- Customer Content — for the duration of the subscription, then deleted from production within 30 days of termination (subject to backup-cycle delays).
- Usage telemetry — aggregated indefinitely; per-request rows pruned after 90 days.
- Support tickets — 3 years after last activity.
- Marketing contact data — until you unsubscribe, then archived for 18 months for suppression-list purposes.
08Security
We maintain a documented security programme aligned with SOC 2, GDPR Article 32, and the EU AI Act. Detailed controls are described on our Security page. In the event of a personal-data breach affecting your data, we will notify you without undue delay and in accordance with applicable law.
09Your rights
Depending on your jurisdiction, you may have rights to:
- access the personal data we hold about you;
- correct inaccurate personal data;
- request erasure (the “right to be forgotten”);
- request a portable copy of your personal data;
- object to or restrict certain processing;
- withdraw consent where our basis is consent;
- not be subject to solely automated decision-making with legal effect;
- lodge a complaint with your supervisory authority (in the EEA / UK) or your state attorney-general (in the United States).
If you are an end-User configured by a Customer administrator, please direct your request to that administrator first; we will assist them in fulfilling it.
To exercise a right, email dpo@osyra.ai. We acknowledge and respond within 30 days (extendable to 90 days for complex requests), and fulfil verified requests through our data-subject-request handling while direct self-serve tooling is being delivered. We may ask you to verify your identity before responding.
10Children
The Service is not directed at, and we do not knowingly collect personal data from, individuals under 16. If you believe we have collected such data, please email dpo@osyra.ai and we will promptly investigate and take the action required by applicable law.
11Changes to this policy
We may update this Privacy Policy. Material changes are posted on this page with a new “Last updated” date and, for Customers, notified to the primary account contact at least 30 days before they take effect. We will not retroactively degrade your privacy rights without your express consent.
12Contacting us
Data-protection inquiries: dpo@osyra.ai. Other privacy questions: legal@osyra.ai.