Legal

Privacy Policy

Effective 26 July 2026. All legal documents

Sovryk is operated ahead of company incorporation in Romania. The registered company name, address and registration number will be published here as soon as incorporation completes. Until then the operator is reachable at contact@sovryk.com.

Effective date: 26 July 2026

Controller: Sovryk, registered address to be published on incorporation, Romania (registration number pending). Contact: contact@sovryk.com.

Our approach: collect as little as possible. We designed Sovryk so that we cannot read your communications and so that we hold minimal data about you. This policy explains what little we do process, and why.

1. What we DON'T do

2. What we DO process, and why

DataPurposeLegal basis (GDPR)
Username, password hashProvide your accountContract (Art. 6(1)(b))
Optional email (if you add one)Account recovery you requestConsent (Art. 6(1)(a))
Minimal technical/operational metadata (e.g. account creation date, last connection, delivery routing needed to operate the service)Operate and secure the ServiceLegitimate interests / Contract
Payment metadata (via our processor, e.g. Stripe)Take payment, comply with tax lawContract / Legal obligation
Security/abuse signals (e.g. rate-limiting)Prevent abuse and protect the ServiceLegitimate interests

We aim to keep metadata to the minimum required to run the Service. We do not store the content of your communications in a form we can read.

3. Payments

Payments are handled by third-party processors (e.g. Stripe), who are independent controllers for card data under their own policies. We receive only the minimum needed to confirm payment and meet tax/accounting obligations. Where offered, anonymous vouchers let you activate a subscription without linking payment to your account.

4. Retention

We keep account data only while your account exists and for as long as legally required (e.g. tax records). When you delete your account, we delete associated data within a reasonable period, except where retention is legally required.

5. Sharing and disclosure

5.1 We share data with service providers strictly as needed to run the Service (e.g. hosting, payment), under appropriate agreements.

5.2 Law enforcement / legal requests: we disclose data only in response to valid, legally binding requests, and only to the extent we actually hold the requested data. Because of our minimal-data design and end-to-end encryption, the data we are able to provide is very limited (we cannot provide message content). See our Law Enforcement Guidelines.

6. International transfers

Our infrastructure may be hosted in Iceland (1984 Hosting, Reykjavik). Where data is transferred outside the EEA, we rely on appropriate safeguards as required by GDPR.

7. Your rights

Under GDPR you may request access to, correction or deletion of your personal data, restriction or objection to processing, and portability, and you may withdraw consent. To exercise these, contact contact@sovryk.com. Note that for some requests (e.g. message content) we may be technically unable to comply because we do not hold readable data. You may also lodge a complaint with your data protection authority (in Romania, ANSPDCP).

8. The website and the demo form

Our website does not use analytics, advertising or tracking cookies, and sets no cookies at all. The web server keeps no access logs, so we do not retain visitor IP addresses.

If you submit the demo form, we store the email address you typed, the language of the page, the page path and the time of the request, so that we can reply to you. Legal basis: your request to take steps before entering a contract (Art. 6(1)(b)) and our legitimate interest in responding to business enquiries (Art. 6(1)(f)). We use that address only to reply to you and to follow up about Sovryk. We do not sell it, rent it, or pass it to advertisers, and we do not add it to any marketing list without asking you first.

To limit abuse of the form we count requests per visitor for one hour, using a keyed hash of the IP address held only in memory. It is never written to disk and disappears when the service restarts.

Enquiries are deleted within 24 months, or sooner on request. To have yours removed, write to contact@sovryk.com.

9. Security

We use end-to-end encryption for communications and apply technical and organisational measures to protect the limited data we hold. No system is perfectly secure; security is an ongoing process.

10. Changes

We may update this policy and will notify you of material changes.

11. Contact

Data protection: contact@sovryk.com · Sovryk, registered address to be published on incorporation