Relynt

GDPR Notice

Last updated July 1, 2026

How we process personal data for individuals in the EEA, UK, and Switzerland, and your GDPR rights.

This GDPR Privacy Notice ("Notice") explains how Relynt, Inc. ("we," "us," and "our") processes your personal data when the EU General Data Protection Regulation (the "EU GDPR"), the UK GDPR, or the Swiss Federal Act on Data Protection (the "FADP") applies to you. It supplements, and — for the individuals it protects — prevails over, our Privacy Policy. If you have questions, contact us at privacy@getrelynt.com.

1. Who is the controller of your personal data?

In Short: Relynt is the controller for our own site, marketing, and customer-relationship data; for Customer Data we act as a processor.

For personal data of website visitors, prospective and current customers and their representatives, partners, event attendees, and job applicants, the controller (Article 4(7)) is Relynt, Inc., Scottsdale, Arizona, United States (privacy@getrelynt.com). When our customers use the Platform to send email and manage their contacts, we process their recipients' and contacts' personal data as a processor (Article 4(8)) on the customer's documented instructions under our Data Processing Addendum (Article 28). If you received email sent through Relynt, please direct rights requests to the organisation that sent it; we will refer your request and assist as required.

2. What personal data do we process, and from where?

In Short: Identity and contact, account and transaction, communications, technical and usage, marketing, and recruitment data.

Consistent with Articles 13 and 14, we process the following categories of personal data:

CategoryExamplesSource
Identity & contactName, business email, phone, company, job titleYou; your employer; enrichment providers; partners
Account & transactionSubscription, billing, and payment detailsYou; our payment processors
Communications & supportMessages, inquiries, and support recordsYou
Technical & usageIP address, device data, site interactions, cookie dataCollected automatically via cookies and similar technologies
Marketing & preferencesInterests, engagement, and communication preferencesYou; your interactions with us
RecruitmentApplication and background informationYou; recruiters; references you provide

We do not intentionally process special categories of personal data (Article 9) through our websites. Please do not provide such data unless specifically requested and a lawful condition under Article 9(2) applies.

3. What legal bases do we rely on?

In Short: Consent, contract, legitimate interests, and legal obligation, as set out in Article 6(1).

Purpose of processingLegal basis (Art. 6(1))
Providing our websites and responding to inquiries, demos, and sales requestsContract or pre-contractual steps (6(1)(b)); legitimate interests (6(1)(f))
Providing, supporting, and securing the PlatformContract (6(1)(b)); legitimate interests (6(1)(f))
Billing, payments, and record-keepingContract (6(1)(b)); legal obligation (6(1)(c))
Marketing communications and eventsConsent (6(1)(a)) where required; legitimate interests (6(1)(f))
Analytics and website improvementConsent (6(1)(a)) for non-essential cookies; legitimate interests (6(1)(f))
Advertising and retargeting cookiesConsent (6(1)(a))
Security, fraud prevention, and protecting our rightsLegitimate interests (6(1)(f)); legal obligation (6(1)(c))
Complying with law and defending claimsLegal obligation (6(1)(c)); legitimate interests (6(1)(f))

Where we rely on legitimate interests (Article 6(1)(f)), we have conducted a balancing assessment concluding that our interests are not overridden by your interests, rights, and freedoms. You may request more information about that assessment.

4. Who do we share your personal data with?

In Short: Processors and sub-processors, advertising and analytics partners, affiliates, advisors, authorities, and transaction parties.

Consistent with Article 13(1)(e), we disclose personal data to the categories of recipients below under appropriate contractual and security safeguards. We do not sell personal data.

Category of recipientExamplesPurpose
Processors / sub-processorsHosting, email infrastructure, analytics, payments, support, securityOperate, secure, and support the Services (Article 28)
Advertising & analytics partnersAd networks and measurement providersDeliver and measure advertising (with consent)
AffiliatesRelynt corporate affiliatesPurposes consistent with this Notice
Professional advisorsLawyers, auditors, accountants, insurersAdvice, audits, and compliance
AuthoritiesRegulators, courts, law enforcementComply with law or protect rights and safety
Transaction partiesAcquirers, investors, advisorsIn connection with a corporate transaction

5. Is your personal data transferred internationally?

In Short: Yes — we use Standard Contractual Clauses, the UK Addendum/IDTA, and Swiss safeguards under Articles 44–49.

We are established in the United States and may process personal data in the U.S. and other third countries. Where we transfer personal data to a country without an adequacy decision under Article 45, we rely on appropriate safeguards under Article 46, including the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, and the Swiss addendum recognised by the FDPIC, supplemented by additional measures informed by a transfer impact assessment. We flow down equivalent safeguards to sub-processors for onward transfers. You may request a copy of the relevant safeguards by contacting privacy@getrelynt.com.

6. How long do we keep your personal data?

In Short: Only as long as necessary for the purposes described, consistent with Article 5(1)(e).

Consistent with Article 5(1)(e), we keep personal data only for as long as necessary for the purposes for which it is processed, including to satisfy legal, accounting, and reporting requirements and to establish, exercise, or defend legal claims. Detailed retention guidelines are set out in our Privacy Policy. When no longer needed, personal data is deleted or anonymised.

7. What are your privacy rights?

In Short: Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent.

Subject to the conditions and exemptions in applicable law, you have the following rights:

  • Access (Article 15) — to obtain confirmation of processing and a copy of your personal data.
  • Rectification (Article 16) — to have inaccurate personal data corrected and incomplete data completed.
  • Erasure (Article 17) — to have personal data deleted in the circumstances specified.
  • Restriction (Article 18) — to restrict processing in the circumstances specified.
  • Portability (Article 20) — to receive personal data you provided in a structured, machine-readable format.
  • Objection (Article 21) — to object to processing based on legitimate interests, and to direct marketing at any time.
  • Withdraw consent (Article 7(3)) — to withdraw consent at any time, without affecting prior processing.

To exercise your rights, contact privacy@getrelynt.com. We will respond within one (1) month under Article 12(3), extendable by two further months for complex or numerous requests. We do not charge a fee unless a request is manifestly unfounded or excessive (Article 12(5)). We may request information necessary to confirm your identity (Article 12(6)).

8. How do we handle direct marketing?

In Short: We send electronic marketing only with your consent or as permitted, and you can object at any time.

Where required, we send electronic marketing only with your consent or as otherwise permitted by law (including the ePrivacy rules), and you may object or withdraw consent at any time under Article 21(2)–(3) using the unsubscribe link or by contacting us.

9. Do we use automated decision-making?

In Short: No — we do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.

We do not make decisions producing legal or similarly significant effects concerning you based solely on automated processing within the meaning of Article 22(1). We may analyse engagement to improve our marketing, but not so as to produce such effects. If this changes, we will provide the information and safeguards required by Article 22.

10. How do we secure your data and handle breaches?

In Short: Appropriate technical and organisational measures under Article 32, with breach notification under Articles 33–34.

We implement appropriate technical and organisational measures under Article 32, as further described in our Privacy Policy. We maintain an incident-response process and, where required, will notify the competent supervisory authority under Article 33 and affected individuals under Article 34. Where we act as a processor, we will notify the relevant controller without undue delay under Article 33(2) and our Data Processing Addendum.

11. What if you do not provide your data?

In Short: We may be unable to provide the requested Services or respond to your request.

Consistent with Article 13(2)(e), where we require personal data to enter into or perform a contract or to comply with a legal obligation and you do not provide it, we may be unable to provide the requested Services or respond to your request. We will indicate at the point of collection where provision is mandatory and the consequences of failing to provide it.

12. Do we have a Data Protection Officer or EU/UK representative?

In Short: We have not appointed a Data Protection Officer or an EU/UK representative; we will designate them if and when the law requires, and update this Notice accordingly.

You may contact our privacy team at privacy@getrelynt.com regarding this Notice or our processing of your personal data. We have not appointed a Data Protection Officer under Article 37, as we are not currently required to do so, and we have not appointed a representative under Article 27 of the EU GDPR or the UK GDPR. If our activities later require us to designate a representative or a Data Protection Officer, we will update this Notice with their details.

13. How can you lodge a complaint?

In Short: With your local supervisory authority under Article 77, such as the ICO or the Swiss FDPIC.

Without prejudice to any other remedy, you have the right to lodge a complaint with a supervisory authority under Article 77 — for example, the UK Information Commissioner's Office (ICO), the Swiss Federal Data Protection and Information Commissioner (FDPIC), or the supervisory authority of your EU member state. We ask that you contact us first so we may try to resolve your concern. You may also have the right to an effective judicial remedy under Articles 78–79.

14. Do we make updates to this notice?

In Short: Yes — as necessary to stay compliant with relevant laws.

We may update this Notice from time to time. The updated version will be indicated by a revised date, and material changes may be notified to you.

15. How can you contact us?

If you have questions or comments about this Notice, email us at privacy@getrelynt.com or contact us by post at: Relynt, Inc., Scottsdale, Arizona, United States.