Trust Centre
One place for the security, privacy and compliance information your legal and security teams need to approve Laya.
Last updated
This is the Laya Trust Centre: everything a security or legal reviewer normally asks for, published rather than handed out on request. Each document below is a page you can read, link to, and print or save as PDF for your records.
Documents
| Document | What it covers | Who usually asks for it |
|---|---|---|
| Security programme | Technical and organisational measures: encryption, access control, authentication, monitoring, secure development, vulnerability handling | Security review, IT |
| GDPR compliance | Controller and processor roles, lawful bases, data subject rights, and how Laya meets its obligations | Legal, privacy, DPO |
| Data Processing Agreement | The Article 28 processor terms that govern our handling of your data, in full | Legal, procurement |
| Sub-processors | Every third party that may process customer data, what for, and where — plus how changes are notified | Legal, privacy, security |
| International data transfers | Where data is hosted, the transfer mechanisms relied on, and the safeguards applied | Legal, privacy |
| Data retention and deletion | What is kept, for how long, what deletion actually removes, and how to export first | Legal, records management |
| Incident response | How we detect, contain and notify — including breach notification commitments | Security, legal |
| Privacy rights requests | How to make and how we handle access, erasure, correction and portability requests | Privacy, support |
| Security questionnaire answers | The questions vendor assessments ask most often, answered in advance | Security review, procurement |
| Privacy policy · Terms of service | The binding public agreements | Everyone |
Laya at a glance
| Item | Detail |
|---|---|
| Service | Laya — work management and cross-tool board mirroring (laya.net) |
| Operated from | United Kingdom |
| Hosting location | United States, on Amazon Web Services |
| Role under GDPR | Processor for the customer content you put in Laya; controller for account and billing data — see GDPR compliance |
| Data encryption | In transit on all traffic; credentials and secrets encrypted at rest |
| Authentication | Email and password, magic links, or social sign-in; optional two-factor with passkeys, authenticator apps and recovery codes |
| Customer content used to train AI models | No — never, by any provider we use |
| Data sold or shared for advertising | No |
| Sub-processors | Published list with change notification |
| Security contact | support@laya.net (subject: Security report) |
| Privacy contact | privacy@laya.net |
Was this page helpful?
Still stuck?
Contact supportEmail support@laya.net — include what you expected, what happened, and a link to the affected board or item so we can help quickly.