Legal
Privacy Policy
Effective 26 July 2026. All legal documents
Sovryk is operated ahead of company incorporation in Romania. The registered company name, address and registration number will be published here as soon as incorporation completes. Until then the operator is reachable at contact@sovryk.com.
Effective date: 26 July 2026
Controller: Sovryk, registered address to be published on incorporation, Romania (registration number pending). Contact: contact@sovryk.com.
Our approach: collect as little as possible. We designed Sovryk so that we cannot read your communications and so that we hold minimal data about you. This policy explains what little we do process, and why.
1. What we DON'T do
- We do not read, scan, or analyse the content of your messages, calls, or files. They are end-to-end encrypted and we do not hold the keys to read them.
- We do not sell or rent your data.
- We do not run advertising or build advertising/behavioural profiles.
- We do not require your phone number, and email is optional.
2. What we DO process, and why
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Username, password hash | Provide your account | Contract (Art. 6(1)(b)) |
| Optional email (if you add one) | Account recovery you request | Consent (Art. 6(1)(a)) |
| Minimal technical/operational metadata (e.g. account creation date, last connection, delivery routing needed to operate the service) | Operate and secure the Service | Legitimate interests / Contract |
| Payment metadata (via our processor, e.g. Stripe) | Take payment, comply with tax law | Contract / Legal obligation |
| Security/abuse signals (e.g. rate-limiting) | Prevent abuse and protect the Service | Legitimate interests |
We aim to keep metadata to the minimum required to run the Service. We do not store the content of your communications in a form we can read.
3. Payments
Payments are handled by third-party processors (e.g. Stripe), who are independent controllers for card data under their own policies. We receive only the minimum needed to confirm payment and meet tax/accounting obligations. Where offered, anonymous vouchers let you activate a subscription without linking payment to your account.
4. Retention
We keep account data only while your account exists and for as long as legally required (e.g. tax records). When you delete your account, we delete associated data within a reasonable period, except where retention is legally required.
5. Sharing and disclosure
5.1 We share data with service providers strictly as needed to run the Service (e.g. hosting, payment), under appropriate agreements.
5.2 Law enforcement / legal requests: we disclose data only in response to valid, legally binding requests, and only to the extent we actually hold the requested data. Because of our minimal-data design and end-to-end encryption, the data we are able to provide is very limited (we cannot provide message content). See our Law Enforcement Guidelines.
6. International transfers
Our infrastructure may be hosted in Iceland (1984 Hosting, Reykjavik). Where data is transferred outside the EEA, we rely on appropriate safeguards as required by GDPR.
7. Your rights
Under GDPR you may request access to, correction or deletion of your personal data, restriction or objection to processing, and portability, and you may withdraw consent. To exercise these, contact contact@sovryk.com. Note that for some requests (e.g. message content) we may be technically unable to comply because we do not hold readable data. You may also lodge a complaint with your data protection authority (in Romania, ANSPDCP).
8. The website and the demo form
Our website does not use analytics, advertising or tracking cookies, and sets no cookies at all. The web server keeps no access logs, so we do not retain visitor IP addresses.
If you submit the demo form, we store the email address you typed, the language of the page, the page path and the time of the request, so that we can reply to you. Legal basis: your request to take steps before entering a contract (Art. 6(1)(b)) and our legitimate interest in responding to business enquiries (Art. 6(1)(f)). We use that address only to reply to you and to follow up about Sovryk. We do not sell it, rent it, or pass it to advertisers, and we do not add it to any marketing list without asking you first.
To limit abuse of the form we count requests per visitor for one hour, using a keyed hash of the IP address held only in memory. It is never written to disk and disappears when the service restarts.
Enquiries are deleted within 24 months, or sooner on request. To have yours removed, write to contact@sovryk.com.
9. Security
We use end-to-end encryption for communications and apply technical and organisational measures to protect the limited data we hold. No system is perfectly secure; security is an ongoing process.
10. Changes
We may update this policy and will notify you of material changes.
11. Contact
Data protection: contact@sovryk.com · Sovryk, registered address to be published on incorporation