Privacy Policy
1. Who We Are
Lynxify (“we”, “us”, “our”) operates the Lynxify platform available at app.lynxify.me — an HR performance management tool that enables teams to run structured feedback cycles and generate AI-assisted performance summaries.
For privacy-related questions, contact us at: support@lynxify.me
2. What Data We Collect
2.1 Account & Profile Data
- Full name, work email address, and password (hashed — never stored in plain text)
- Company name and team membership
- User role within your organisation (Owner, Manager, Employee)
- Social login identity (Google or Microsoft) if you choose SSO sign-in
2.2 Feedback & Performance Data
- Feedback text submitted or drafted within feedback cycles
- Criteria ratings (1–5 scale) per feedback cycle
- AI-generated summary text produced from submitted feedback content
- Cycle status history (active, finished, archived)
2.3 Usage & Analytics Data
- Page views, feature interactions, and in-app events (e.g. feedback submitted, cycle created) collected via Amplitude Analytics
- We do not use Amplitude for advertising or sell this data to third parties
3. How We Use Your Data
| Purpose | Legal Basis |
|---|---|
| Provide and operate the platform | Contract performance |
| Authenticate your identity and manage sessions | Contract performance |
| Generate AI-assisted feedback summaries via OpenAI | Legitimate interest / contract performance |
| Send invitation and welcome emails | Contract performance |
| Analyse feature usage to improve the product | Legitimate interest |
| Comply with legal obligations | Legal obligation |
4. AI-Generated Summaries
When a feedback cycle owner requests an AI Summary, the aggregated feedback text for that cycle is sent to OpenAI’s API for processing. OpenAI processes this data according to its own API data usage policy. We use OpenAI’s API in a way that opts out of training data use. The resulting summary is stored in our database and is accessible only to users with management access to that cycle.
Before sending feedback content to OpenAI, all personally identifiable information is anonymised. Real names of employees, reviewers, and any other identifiable references are replaced with neutral placeholders so that no individual can be identified from the data transmitted to OpenAI. The original, non-anonymised text is never shared with third-party AI services.
5. Third-Party Services
| Service | Purpose | Data Shared |
|---|---|---|
| OpenAI | AI feedback summary generation | Anonymised feedback text (no personally identifiable information) |
| Amplitude (EU region) | Product analytics | User ID, name, email, role, company, events |
| Google reCAPTCHA v3 | Bot detection on registration | Page interaction signals, IP address |
| Google OAuth / Microsoft OAuth | Social sign-in | OAuth identity token (email, name) |
| Transactional email provider | Invitation and welcome emails | Recipient email address and name |
6. HRIS Integrations
Lynxify supports optional integrations with PeopleForce, BambooHR, HiBob, and Factorial. If your organisation activates an integration, employee data (such as names and email addresses) may be synchronised from your HRIS provider into Lynxify. This synchronisation is configured by your organisation’s Owner and governed by your agreement with each HRIS provider.
7. Data Retention
- Account data is retained for as long as your organisation has an active account with us.
- Feedback and cycle data is retained for the lifetime of the account and may be archived but not automatically deleted.
- Analytics events are retained in Amplitude per Amplitude’s retention policy (default: 24 months).
- Upon account termination, we will delete or anonymise personal data within 90 days, unless we are required by law to retain it longer.
8. Your Rights
If you are located in the European Economic Area (EEA), the UK, or another jurisdiction with applicable data protection laws, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Erase your personal data (“right to be forgotten”)
- Restrict or object to certain processing
- Data portability — receive your data in a structured, machine-readable format
- Withdraw consent at any time where processing is based on consent
To exercise any of these rights, contact us at support@lynxify.me. We will respond within 30 days.
9. Cookies
| Cookie | Purpose | Type |
|---|---|---|
Session cookie (sessionid) | Maintains your login session | Essential |
CSRF token (csrftoken) | Protects forms against cross-site request forgery | Essential |
| Amplitude device ID | Analytics user identification | Analytics |
You can disable non-essential cookies in your browser settings. Disabling session cookies will prevent you from logging in.
10. Changes to This Policy
We may update this policy from time to time. When we do, we will update the “Last updated” date at the top of this page. Material changes will be communicated to account Owners via email.
11. Contact
For any questions about this Privacy Policy or how we handle your data:
Email: support@lynxify.me