This policy explains how Pixbots Private Limited ("we", "us") handles personal data in connection with LynxSprint: this website at lynxsprint.com and the LynxSprint platform.
1. Two different roles, and why it matters to you
We handle personal data in two distinct capacities, and your rights differ depending on which applies.
- As a controller, for people who contact us, join the early-access list, or administer an account. We decide why and how that data is processed.
- As a processor, for the employee data an organization puts into LynxSprint. The organization is the controller of that data, not us. We act on their documented instructions.
If you are an employee whose time is recorded in LynxSprint by your employer, your employer is the controller and is the first place to direct a request. The employee privacy notice is written for you and explains what is recorded and what is not.
2. What we collect
2.1 When you contact us or join the early-access list
- Your email address, and whatever you choose to put in your message.
- Your organization's name, if you tell us.
That is the complete list. This website sets no cookies, runs no analytics, and loads no third-party scripts, so there is no tracking identifier, no advertising profile and no cross-site record of your visit. Our hosting provider processes standard request metadata such as your IP address in order to serve the page and to protect against abuse.
2.2 Within the platform, on behalf of an organization
- Identity: name, work email, and authentication metadata.
- Employment: employee profile, group and team membership, reporting relationships, employment dates, work schedule and time zone.
- Work: time entries, timesheet submissions and approvals, projects and work items.
- Audit: a record of consequential changes, including who made them and what the value was before and after.
- Optional sensitive fields an organization may choose to record. These are optional, separately permissioned, redacted by default in list views, encrypted with separate key handling, and excluded from AI processing.
We do not capture screenshots, log keystrokes, monitor application or website usage, or track location. No configuration enables it, because the capability does not exist. Our privacy stance explains why.
3. Why we process it
- To provide the service an organization has asked us to provide.
- To authenticate people and enforce access controls.
- To keep an audit record, which is both a security control and a legal obligation.
- To respond when you contact us.
- To detect and prevent abuse, fraud and security incidents.
Where we act as a controller, our lawful basis is generally our legitimate interest in operating and securing the service, or performance of a contract with you. Where we act as a processor, the lawful basis is the controlling organization's to determine.
4. Automated decision-making, and AI
We do not make automated decisions that produce legal or similarly significant effects about anyone. LynxSprint does not score employees, rank them, or generate a performance assessment.
AI features are an organization-level opt-in and are off by default. When an organization enables them: an agent can only reach data the person invoking it could already see; sensitive fields are excluded before the data reaches a model; consequential actions require a recorded human approval; and each run is logged. When AI is disabled, no data is sent to a model provider at all.
5. Who else is involved
We do not sell personal data, and we do not share it for advertising. We use a small number of service providers to operate the platform; each is listed with its purpose and what it touches on our sub-processors page, which is the page to watch for changes.
We may disclose data where we are legally required to, and we will tell the affected organization unless we are prohibited from doing so.
6. Where data is processed
We do not publish a blanket region list, because the answer depends on the deployment. Ask us about your specific residency requirement and we will answer it directly, in writing, as part of contracting. Any international transfer relies on an appropriate safeguard.
7. How long we keep it
- Early-access and enquiry email: until you ask us to remove it, or until it is clearly stale.
- Platform data: for as long as the controlling organization's account is active, then according to the retention period agreed with them.
- Audit records: retained for a defined window because their value depends on not being editable or selectively deletable.
Specific retention periods are set out per category in the data-processing agreement we sign with each customer.
8. Security
Technical and organizational measures include encryption in transit, application-layer encryption of the most sensitive fields, tenant isolation enforced in multiple independent layers, least-privilege access, and an append-only audit trail. Our security page describes the outcomes these are intended to produce, and is equally explicit about what we do not yet claim.
No system is perfectly secure. If you believe you have found a vulnerability, our responsible-disclosure page explains how to tell us.
9. Your rights
Subject to applicable law you may request access to your personal data, correction, deletion, a portable copy, or restriction of processing, and you may object to processing based on legitimate interests.
Where we act as a processor, direct your request to your employer or the organization operating the account. They control the data and we are not permitted to act on it unilaterally. If you contact us anyway, we will pass it on and tell you we have.
Employees always have direct, self-service access to their own time entries, profile and history within the product, without having to ask an administrator. That is a design constraint rather than a setting.
10. Children
LynxSprint is a workplace tool and is not directed at children. We do not knowingly collect data from anyone under 16.
11. Changes
We will update the effective date at the top of this page when this policy changes. For changes that materially affect how personal data is handled, we will notify affected organizations rather than relying on you to re-read the page.
12. Contact
Email contact@lynxsprint.com, addressed to the LynxSprint Team. Our registered postal address is available on request and is set out in the data-processing agreement.
If you are in a jurisdiction with a data-protection supervisory authority, you have the right to complain to it.