Privacy Policy
Effective date: 1 September 2026
Last updated: 16 September 2026
This policy explains what personal data Clynto collects, how we use it, and the choices you have. It covers our website and the Clynto platform.
Clynto is operated by Clynto AI INC, 8 The Green STE B, Dover, DE 19901 ("Clynto", "we", "us").
1. Two different roles
We handle personal data in two distinct capacities, and your rights differ depending on which applies.
As a controller — for people who visit our website, request a demo, sign up for an account, or contact us. We decide why and how that data is used, and this policy governs it.
As a processor — for the customer records our customers load into the platform. A customer's account list, their contacts, their support history and their email correspondence belong to that customer. We process it only on their instructions, under our agreement with them. If you are an end customer of a Clynto customer and want your data corrected or deleted, contact that company directly; they control it, and we will support them in responding to you.
2. Data collected via the website
| What | Why | Basis |
|---|---|---|
| Name, work email, company, role | To respond to demo requests and enquiries | Legitimate interest / steps toward a contract |
| Message content you send us | To answer you | Legitimate interest |
| Pages visited, referrer, approximate location from IP, device and browser type | To understand which pages are useful and to keep the site secure | Legitimate interest, or consent where required |
| Cookie and similar identifiers | Session management, analytics | Consent where required |
We use a small number of cookies. Strictly necessary cookies keep you signed in and protect against cross-site request forgery; these cannot be switched off without breaking sign-in. Analytics cookies are optional and are only set where you have agreed, if your jurisdiction requires that.
We do not sell personal data, and we do not share it with advertising networks.
3. Data processed on behalf of customers
When a customer uses the platform, the data they load or connect may include:
- business contact details for their customers — names, work email addresses, job titles, phone numbers
- account and commercial records — company names, contract values, renewal dates, subscription and invoice status
- support correspondence — tickets, email threads, notes
- product usage figures drawn from the customer's own analytics or billing systems
- files a customer uploads, such as contracts and reports
We do not require, and ask customers not to load, special category data — health data, biometric data, government identifiers, payment card numbers, or similar. The platform is built for business-to-business customer success records. If a customer loads such data anyway, they do so as controller and are responsible for having a lawful basis.
Each customer's data is logically separated from every other customer's, and access is restricted to the people that customer has invited and the permissions they have granted them.
4. AI processing
The platform uses large language models to summarise accounts, draft emails for review, classify incoming messages, and answer questions a user asks about their own data.
What that means in practice:
- Prompts contain customer business data. To summarise an account or draft a reply, the relevant records are sent to the model. This can include contact names and email addresses, message text, and commercial figures.
- We use enterprise AI services, not consumer ones. Our model provider is contracted so that customer content is not used to train their models, and is not retained by them beyond what is needed to return a response and meet their abuse-monitoring obligations.
- AI output is a suggestion, not an action. By default the platform proposes work — a draft email, a suggested task — and a person approves it before anything leaves the system. Customers may raise that autonomy level themselves; where they do, they control that decision.
- We keep a record of AI activity — which feature ran, for which account, what it produced and whether it was approved — so a customer can audit how an automated decision was reached.
- No solely automated decisions with legal effect. Nothing in the platform makes decisions about individuals that produce legal or similarly significant effects on them.
Customers who prefer not to use AI features can disable them for their workspace.
5. Sub-processors
We use a small number of providers to run the service. Each is bound by a written agreement with confidentiality and security obligations at least as protective as those in our own customer terms.
| Sub-processor | Purpose | Region |
|---|---|---|
| Microsoft Azure | Cloud hosting, database, and the AI services described above | Azure East US 2 |
| Resend | Transactional and customer-initiated email delivery | Azure East US 2 |
Services a customer connects themselves are not our sub-processors. When a customer links their own help desk, CRM, billing, messaging, analytics or mailbox account, they are instructing us to exchange data with a provider they have chosen and contracted with. Those providers act for the customer, not for us, and the customer's own agreement with them governs.
One detail worth naming because it is not obvious: to display a company logo beside an account, the user's browser requests an icon for that company's web domain from a public icon service. That service therefore sees the domains of accounts rendered on screen. No names, contact details, or account content are sent. Customers who would rather avoid this can ask us to disable logo lookup for their workspace.
We will give customers advance notice before adding a sub-processor, and a mechanism to object.
6. Data retention and deletion
Website enquiries. Kept while we are in contact and for a reasonable period afterwards, then deleted.
Platform data. Kept for as long as the customer's account is active. Within the product, deletion happens in two stages by design: a deleted record is first moved to a recoverable state for a short window so an accidental deletion can be undone, and is then permanently erased. Customers control this.
On termination. A customer may export their data before their account closes (see our terms). After the wind-down period in the agreement, we permanently erase customer data from our production systems. Backups are on their own rotation and are overwritten in the ordinary course; we do not restore a closed customer's data from backup except where we are legally required to.
Security and audit records — sign-in events, administrative actions, and similar — are kept on a limited, fixed schedule, because keeping them is how we can investigate a security incident and answer a customer's question about who did what. They are then deleted automatically.
Legal holds. Where we are required to retain something to comply with a legal obligation, resolve a dispute, or enforce an agreement, we retain only what is necessary and for no longer than required.
7. International transfers
Our production systems are hosted in Azure East US 2. Where personal data is transferred outside the region in which it was collected — including to a sub-processor — we rely on an appropriate transfer mechanism, such as the European Commission's Standard Contractual Clauses, the UK Addendum, or an adequacy decision, together with additional technical and organisational measures where needed.
Customers who require data residency in a specific region should contact us before signing; we will tell you plainly what we can and cannot offer today.
8. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you, and receive a copy
- correct data that is inaccurate or incomplete
- delete your data, in the circumstances the law provides
- restrict or object to processing, including profiling
- portability — receive your data in a structured, machine-readable format
- withdraw consent at any time, where we rely on consent
- complain to your local data protection authority
If you are in California, you additionally have the right to know what personal information is collected and disclosed, to delete it, to correct it, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined under the CCPA/CPRA.
How to exercise them. Write to the address in section 10. We will respond within the period the law requires — generally one month — and will tell you if we need longer and why. We may need to verify your identity first.
If your data is in a customer's workspace, we will refer you to that customer and support them in responding, because they control it and we do not have the standing to act on it alone.
9. Security
We protect data in transit and at rest, restrict access to those who need it, require named individual accounts with role-based permissions for administrative access, and keep audit records of significant actions. Credentials for connected services are encrypted before storage.
No system is perfectly secure, and we will not claim otherwise. If a breach affects your personal data and the law requires notification, we will notify the relevant authority and affected individuals within the required timeframe.
A summary of our security practices is available to customers and prospects on request under NDA.
10. Google API Services User Data Policy
Current position. Clynto does not currently request access to Google user data through Google OAuth. Where a customer connects a Google mailbox or calendar, they do so using credentials they generate themselves in their own Google account and supply to us; we never see their Google password and never ask for Google account access on their behalf.
If and when we offer a Google OAuth integration, the following will apply and this section will be updated with the specific scopes requested:
> Clynto's use and transfer of information received from Google APIs will adhere > to the [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy), > including the Limited Use requirements.
Specifically, we will:
- request only the narrowest scopes needed for the feature a user has enabled
- use Google user data only to provide or improve that user-facing feature
- not transfer Google user data to others except as necessary to provide the feature, for security purposes, or to comply with applicable law
- not use Google user data for advertising
- not allow humans to read Google user data, unless we have the user's explicit consent for specific messages, it is necessary for security or to comply with law, or the data has been aggregated and de-identified
- allow a user to revoke access at any time, from their Google account or from within Clynto, and delete the associated data on revocation
11. Children
The platform is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
12. Changes to this policy
We will post any change here and update the date at the top. If a change materially affects how we handle personal data, we will give notice by email or in the product before it takes effect.
13. Contact for privacy requests
Privacy enquiries and data subject requests: privacy@clynto.ai Postal: Clynto AI INC, 8 The Green STE B, Dover, DE 19901 Security issues: security@clynto.ai
We aim to acknowledge privacy requests within 5 business days.