Privacy Policy
Last updated 5 July 2026
This policy explains what personal data Svitrio collects, why, and the rights you have over it. Svitrio is built to be inspectable — the same principle applies to how we handle your data.
1Who we are
Svitrio is a product of Syrakon, a studio based in Barcelona, Spain ("we", "us"). For anything in this policy, and to exercise the rights described below, contact us at privacy@svitrio.com. We are the data controller for the personal data described here.
2Data we collect
- Account data — your email address and display name, created when you sign in. We use passwordless sign-in (magic links and passkeys), so we never store a password.
- Usage & audit logs — actions taken in the operator console (who did what, when), your IP address and user agent at sign-in, kept as a tamper-evident audit trail for security and account safety.
- Billing data — plan, subscription status and invoices. Card details are handled by our payments provider (Paddle); we never see or store your full card number.
- Content you create — the projects, pages, members and settings you manage inside Svitrio. This is your data; we process it only to provide the service.
- Support — the contents of messages you send us.
3How we use it & legal bases
Under the GDPR we rely on the following bases:
- Performance of a contract — to provide the service, authenticate you, and manage your subscription.
- Legitimate interests — to keep the service secure, prevent abuse, and maintain the audit log.
- Legal obligation — to keep billing and tax records.
- Consent — for any optional communications, which you can withdraw at any time.
We do not sell your personal data, and we do not use it for advertising or third-party tracking.
4Processors we use
We share data only with the providers needed to run the service:
| Provider | Purpose | Data |
|---|---|---|
| Paddle | Payments & billing (Merchant of Record) | Name, email, billing/tax info |
| Brevo | Transactional email (magic links, notices) | Email address |
| OVHcloud | Hosting infrastructure (EU) | All service data at rest |
Each acts as a processor under a data-processing agreement and may only use the data to provide their service to us.
5International transfers
We host in the EU. Where a processor transfers data outside the EEA, that transfer is covered by an adequacy decision or the EU Standard Contractual Clauses.
6Retention
We keep account and content data while your account is active. After you close your account we delete or anonymise personal data within 90 days, except records we must keep by law (e.g. invoices, typically 6 years). Audit-log entries are retained for the security window described in your plan.
7Your rights
You may access, rectify, erase, restrict or object to the processing of your personal data, request portability, and lodge a complaint with your supervisory authority (in Spain, the AEPD). To exercise any right, email privacy@svitrio.com; we respond within one month.
8Security
Sign-in is passwordless. Project AI provider keys are sealed with AES-256-GCM at rest. Access is scoped by membership and enforced by middleware, and every privileged action is written to an audit log. No system is perfectly secure, but we design for transparency so problems are visible, not hidden.
9Changes
We may update this policy; material changes will be announced in the console or by email, and the date above will change. Continued use after an update means you accept the revised policy.
Questions? privacy@svitrio.com