Skip to content

Trust Centre

One place for the security, privacy and compliance information your legal and security teams need to approve Laya.

Last updated

Print-optimised — choose “Save as PDF” in the dialogue

This is the Laya Trust Centre: everything a security or legal reviewer normally asks for, published rather than handed out on request. Each document below is a page you can read, link to, and print or save as PDF for your records.

Documents

The Laya trust and compliance document set
DocumentWhat it coversWho usually asks for it
Security programmeTechnical and organisational measures: encryption, access control, authentication, monitoring, secure development, vulnerability handlingSecurity review, IT
GDPR complianceController and processor roles, lawful bases, data subject rights, and how Laya meets its obligationsLegal, privacy, DPO
Data Processing AgreementThe Article 28 processor terms that govern our handling of your data, in fullLegal, procurement
Sub-processorsEvery third party that may process customer data, what for, and where — plus how changes are notifiedLegal, privacy, security
International data transfersWhere data is hosted, the transfer mechanisms relied on, and the safeguards appliedLegal, privacy
Data retention and deletionWhat is kept, for how long, what deletion actually removes, and how to export firstLegal, records management
Incident responseHow we detect, contain and notify — including breach notification commitmentsSecurity, legal
Privacy rights requestsHow to make and how we handle access, erasure, correction and portability requestsPrivacy, support
Security questionnaire answersThe questions vendor assessments ask most often, answered in advanceSecurity review, procurement
Privacy policy · Terms of serviceThe binding public agreementsEveryone

Laya at a glance

Summary facts for a vendor record
ItemDetail
ServiceLaya — work management and cross-tool board mirroring (laya.net)
Operated fromUnited Kingdom
Hosting locationUnited States, on Amazon Web Services
Role under GDPRProcessor for the customer content you put in Laya; controller for account and billing data — see GDPR compliance
Data encryptionIn transit on all traffic; credentials and secrets encrypted at rest
AuthenticationEmail and password, magic links, or social sign-in; optional two-factor with passkeys, authenticator apps and recovery codes
Customer content used to train AI modelsNo — never, by any provider we use
Data sold or shared for advertisingNo
Sub-processorsPublished list with change notification
Security contactsupport@laya.net (subject: Security report)
Privacy contactprivacy@laya.net
Still stuck?

Email support@laya.net — include what you expected, what happened, and a link to the affected board or item so we can help quickly.

Contact support