GDPR compliance
How Laya meets the UK GDPR and EU GDPR: controller and processor roles, lawful bases, data subject rights and processor obligations.
Last updated
On this page
Laya is operated from the United Kingdom and is subject to the UK GDPR and the Data Protection Act 2018, and to the EU GDPR where we process the personal data of people in the EEA. This page explains how the regulation applies to Laya and what each side is responsible for.
Who is controller and who is processor
| Data | Laya’s role | Your role |
|---|---|---|
| Customer content — boards, work items, docs, comments, attachments, and mirrored copies of items from your connected tools | Processor, acting on your documented instructions | Controller |
| Workspace member records — names, email addresses, roles | Processor for the workspace context | Controller |
| Account data — the account you create, sign-in records, security settings | Controller | Data subject |
| Service operation data — request logs, error diagnostics, delivery records for our own emails | Controller | Data subject |
| Marketing-site analytics, only after consent | Controller | Data subject |
Lawful bases
- Performance of a contract — creating and running your account and workspace, and delivering the service you signed up for.
- Legitimate interests — keeping the service secure and available, preventing abuse, diagnosing faults, and communicating about the service itself. We balance these against your rights and keep the data minimal.
- Consent — analytics on our public pages, and marketing email. Both are opt-in, and withdrawing consent takes effect immediately.
- Legal obligation — where we must retain or disclose something by law.
Our obligations as your processor
Where Laya processes customer content on your behalf, we commit to the Article 28 duties in full. These are set out formally in the Data Processing Agreement:
- Process customer content only on your documented instructions, including for transfers.
- Ensure personnel with access are bound by confidentiality.
- Apply appropriate technical and organisational measures — the security programme is our stated measure set.
- Engage sub-processors only under written terms no less protective, keep a published list, and give advance notice of changes so you can object.
- Assist you in responding to data subject rights requests.
- Assist you with security, breach notification and impact assessments, taking account of the information available to us.
- Notify you without undue delay after becoming aware of a personal data breach — see incident response.
- Delete or return customer content at the end of the service, at your choice.
- Make available the information needed to demonstrate compliance with these obligations.
How the principles are applied in practice
- Data minimisation — we ask for a name and an email address to create an account. Mirrored boards store the core fields needed to render and sync them, not everything a provider could return; comments on connected boards are read live from the source tool rather than warehoused.
- Purpose limitation — customer content is used to deliver the service you asked for. It is never sold, never used for advertising, and never used to train AI models.
- Accuracy — you can correct your own profile at any time, and content you control is editable in the product.
- Storage limitation — see data retention and deletion, which explains what is kept and how deletion works.
- Integrity and confidentiality — covered by the security programme.
- Accountability — this Trust Centre, the DPA and the sub-processor list are the record.
Data subject rights
Individuals have the rights of access, rectification, erasure, restriction, portability, objection, and the right not to be subject to solely automated decision-making with legal effect (Laya makes no such decisions). Requests are handled within one month. See privacy rights requests for how to make one, and note that if your data is in a workspace, the workspace is the controller and we will support them in answering you.
International transfers
Laya is hosted in the United States, so personal data is transferred out of the UK and EEA. The mechanisms and safeguards are set out in international data transfers.
Email support@laya.net — include what you expected, what happened, and a link to the affected board or item so we can help quickly.