Privacy Policy
1. Data Controllers
The data controllers responsible for processing data on this website are:
Lundrim Hyseni & Tobias Eigenmann
Im Buchfeld 10A
8500 Frauenfeld
Switzerland
Contact: Please use our contact form for all inquiries.
The controllers decide on the purposes and means of processing personal data.
2. Data Protection at a Glance
The following notes provide an overview of what happens to your personal data when you visit or use our Lynara platform. The processing is carried out on the basis of Swiss data protection legislation (nDSG) and, where applicable, the European General Data Protection Regulation (GDPR).
3. Data Collection on this Website
Registration and User Account
When you create a user account, the following data is processed:
- Name
- Email Address
- Authentication Data (Login Provider)
- Account ID
These data are necessary to create a user account, provide you with access to the platform, and save your projects. The legal basis for this processing is Art. 6(1)(b) GDPR (performance of a contract).
Student Verification
If you apply for the Student Plan, we process your provided university or school email address to verify your eligibility against a public database of educational institutions (fetched via the GitHub API). In cases of manual verification, we process the submitted enrollment documents. This processing is necessary to provide you with the educational discount (Art. 6(1)(b) GDPR). Any manually submitted documents will be deleted immediately after verification.
4. Login via Google, Microsoft & GitHub (Single Sign-On)
We offer login via Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), Microsoft Corporation (One Microsoft Way, Redmond, WA 98052, USA), and GitHub Inc. (88 Colin P Kelly Jr St, San Francisco, CA 94107, USA). We exclusively receive your name and your email address to associate your account. No other data is processed.
The use of this service is based on Art. 6(1)(b) GDPR. These providers may transfer data to the USA; in this case, the Standard Contractual Clauses of the EU Commission and the Data Privacy Framework apply.
5. Cookies, Local Storage, Web Analytics & Application Monitoring
We use Local Storage (e.g. JWT Token) to temporarily store login sessions and preferences. These data remain in your browser for technical reasons and are not used for tracking purposes. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure operation).
For statistical analysis of website usage, we use Umami Analytics. Umami is a privacy-focused, open-source analytics tool. It strictly operates without using any tracking cookies and does not collect or store any personal data. All data is anonymized. The legal basis is Art. 6(1)(f) GDPR.
To improve platform stability, we use the error tracking service Sentry (Functional Software, Inc., USA). In the event of software errors, Sentry collects crash reports which may include IP addresses, browser information, and limited session data. This serves our legitimate interest in providing a stable and secure application (Art. 6(1)(f) GDPR). Sentry processes data under the EU-U.S. Data Privacy Framework.
6. Cloudflare Turnstile (Spam Protection)
To secure our platform against bots, we use Cloudflare (101 Townsend St, San Francisco, CA 94107, USA). Technical browser information is analyzed.
The processing is carried out on the basis of Art. 6(1)(f) GDPR. Cloudflare is certified under the Data Privacy Framework, which guarantees an adequate level of data protection.
7. Hosting and Infrastructure
Our platform is hosted by Hostinger (Server location: Frankfurt, Germany). We have concluded a Data Processing Agreement (DPA) with Hostinger, which guarantees the instruction-bound and secure handling of your data. The legal basis is Art. 6(1)(f) GDPR.
8. Payment Processing
Our order process is conducted by our online reseller and Merchant of Record, Paddle.com (Paddle.com Market Limited, Judd House, 18-29 Mora Street, London, EC1V 8BT, United Kingdom). When you purchase a subscription, Paddle collects and processes your payment information to securely complete transactions. Paddle acts as an independent data controller for your payment data. We do not store full credit card numbers. See Paddle's Privacy Policy at paddle.com for more details. The legal basis is Art. 6(1)(b) GDPR (performance of a contract).
9. Storage of Project Data
Content such as architecture diagrams and documentation is stored on our servers to provide the platform's functions. We recommend that you do not process sensitive personal data of third parties within the diagrams.
10. Atlassian Confluence Plugin (Forge App)
If you use the Lynara Confluence Plugin, different data storage rules apply: The plugin is built on Atlassian's Forge framework. All architecture diagrams and related data created within Confluence are processed and stored strictly within Atlassian's Forge infrastructure (Key-Value Store) tied to your Atlassian Cloud tenant.
Lynara does not transmit, host, or store any of this Confluence-specific node-content on its own external servers.
11. Storage Duration
Personal data are only stored as long as necessary for their respective purpose (e.g. active account management). After account deletion, data is removed unless legal retention obligations (e.g. tax law) stand in the way.
12. Your Rights as a Data Subject
You have the right at any time to:
- Information about your stored data
- Correction of inaccurate data
- Deletion of your data
- Restriction of processing
- Data portability (Export in a common format)
- Objection to processing
Contact: Please use our contact form for all inquiries.
In addition, you have the right to lodge a complaint with a supervisory authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern.
13. Data Security
We use modern security measures, including HTTPS encryption and strict access controls, to protect your data from unauthorized access.
14. Changes
We reserve the right to adapt this declaration in the event of technical or legal changes. The current version is always available at lynara.io.