Klyrio
Klyrio
Back to home

Klyrio

Privacy Policy

Last updated : July 15, 2026

Table of contents

  1. 1. Data controller
  2. 2. Data collected
  3. 3. Purposes of processing
  4. 4. Legal bases
  5. 5. Retention periods
  6. 6. Processors and hosting
  7. 7. Transfers outside the European Union
  8. 8. Your rights
  9. 9. Cookies and trackers
  10. 10. Data security
  11. 11. Contact
  12. 12. Supervisory authority

This privacy policy describes how Klyrio, published by SARL Infly Communication, collects, uses, retains, and protects your personal data when you use our SaaS management platform for SMBs (klyrio.io). Klyrio follows a bank-first approach: your professional banking flows form the foundation of the cockpit, complemented by your client, project, and activity data. We are committed to processing your data transparently, securely, and in compliance with the General Data Protection Regulation (GDPR) and applicable French data protection law.

1. Data controller

The data controller is SARL Infly Communication, a limited liability company with share capital of €1,500, registered with the Dijon Trade and Companies Register under number 938 211 141, whose registered office is located at 5C rue Marie-Antoinette Tonnelet, 21000 Dijon, France.

For any questions regarding your personal data or the exercise of your rights, you may contact our DPO / data protection officer at contact@klyrio.io or via klyrio.io.

2. Data collected

Identification and account data: name, email address, password (stored in hashed form), role within the organization, language preferences, and account settings.

Organization data: company name, legal identifiers (SIREN, SIRET where applicable), business settings, alert thresholds, financial categories, and VAT profiles.

Banking and financial data: bank transactions synchronized via Bridge, a PSD2-regulated bank aggregator (labels, amounts, dates, connected accounts), aggregated balances, reconciliations, categorizations, client and vendor invoices, and derived cash-flow and management indicators. Klyrio never stores your bank credentials in plain text; access relies on revocable authorizations granted through Bridge.

Client and project data: client records, contacts, projects, milestones, tasks, activity notes, and associated documents you enter or import into Klyrio.

Communication data: emails and calendar events synchronized via Nylas when you voluntarily connect these integrations, as well as messages you send to support.

Technical and security data: connection logs, IP address, session identifiers, browser type, timestamps, audit events on sensitive actions, and aggregated product usage metrics.

We do not intentionally collect special categories of data under GDPR Article 9 unless you choose to include them in free-text fields; in that case, you remain solely responsible.

3. Purposes of processing

Provide, maintain, and improve the Klyrio service: authentication, multi-tenancy, management cockpit, bank reconciliation, alerts, exports, and related features.

Synchronize your banking data via Bridge, your emails and calendars via Nylas, and send transactional communications (invitations, password reset, notifications) via Resend when necessary.

Ensure service security, prevent fraud, manage incidents, trace sensitive actions, and comply with legal obligations.

Respond to support requests, analyze aggregated product usage to improve the experience, and inform you of significant service updates.

We do not use your banking data for advertising purposes and we do not sell your personal data.

4. Legal bases

Contract performance (GDPR Article 6(1)(b)): account creation, SaaS delivery, bank synchronization, and features requested under your subscription or trial.

Legitimate interest (GDPR Article 6(1)(f)): security, abuse prevention, product improvement, customer support, technical logging, and internal audience measurement, balanced against your rights.

Legal obligation (GDPR Article 6(1)(c)): retention of certain records for accounting, tax, or regulatory purposes.

Consent (GDPR Article 6(1)(a)): optional connection of third-party services (email, calendar), non-essential cookies where applicable, and any feature explicitly subject to your agreement.

5. Retention periods

Account and organization data: retained for the duration of the contractual relationship, then archived or deleted within a maximum of three (3) years after account closure, unless a longer legal obligation applies.

Banking and financial data: retained while the account is active and the bank connector is authorized; after termination, deleted or anonymized within a reasonable period compatible with your management needs and our technical backups.

Security and audit logs: generally retained between twelve (12) and twenty-four (24) months depending on criticality.

Support messages: retained for the duration of handling, then archived for up to three (3) years for quality and evidence purposes.

Retention periods may be adjusted to comply with legal obligations or in the event of ongoing litigation.

6. Processors and hosting

Your data is hosted and processed through providers selected for their security and compliance, acting as processors under GDPR Article 28, under agreements governing confidentiality and data protection.

Supabase (PostgreSQL database, authentication, and related storage) — hosting of application data and files.

Netlify (hosting and delivery of the Klyrio web application) — front-end and serverless function execution.

Bridge API (Powens) — secure bank aggregation and synchronization of transactions you authorize.

Nylas — optional synchronization of professional emails and calendars connected by the user.

Resend — transactional email delivery (authentication, invitations, essential notifications).

OpenRouter — API provider used for select AI assistance features (text only), with no permanent storage of personal data by default.

Meta Conversions API — server-side marketing conversion events, sent only when you have consented to marketing cookies; data is hashed (SHA-256) before transmission.

Sentry — technical observability and error tracking, limited to technical data necessary for diagnostics.

PostHog — product analytics and audience measurement (page views, user journeys), activated only after consent via the cookie banner, with personal data masking. EU hosting.

The list of processors may evolve; any material change will be reflected in an update to this policy. The application database and associated files are hosted by Supabase in the EU region (eu-west-1, Ireland).

7. Transfers outside the European Union

We prioritize hosting and processing data within the European Union or European Economic Area.

Some processors (including Netlify, Resend, or observability services) may involve transfers to third countries, primarily the United States. Where this occurs, transfers are governed by appropriate safeguards under the GDPR (European Commission Standard Contractual Clauses, supplementary measures, certifications where applicable).

You may obtain further information on these safeguards, including a copy of the Standard Contractual Clauses, by contacting us at contact@klyrio.io.

8. Your rights

Under the GDPR, you have the rights of access, rectification, erasure, restriction, objection, portability (where applicable), and withdrawal of consent for processing based on consent.

For data processed within your Klyrio organization, certain requests may need to be addressed to your workspace administrator (owner) who manages access and data scope.

To exercise your rights or obtain a copy of your data, write to contact@klyrio.io stating your identity and, where relevant, your organization name. We will respond within one month, extendable depending on the complexity of the request.

You may also contact our DPO at contact@klyrio.io with the subject line 'Personal data / GDPR'.

If you believe, after contacting us, that your rights are not being respected, you may lodge a complaint with the CNIL (www.cnil.fr).

9. Cookies and trackers

Klyrio uses cookies and similar technologies strictly necessary for the service: session maintenance, security (CSRF, Supabase authentication), language preferences, and proper application operation. These cookies cannot be disabled.

Audience and marketing cookies (Meta Conversions API) are placed only when you explicitly consent through the cookie banner. They help us understand product usage and optimize campaigns without selling your data.

You may change your choice at any time via the cookie banner or by deleting the 'klyrio-consent-v1' cookie from your browser. You may also configure your browser to refuse non-essential cookies; some features may then be degraded. Cookies essential for authentication remain necessary to access your secure workspace.

10. Data security

Klyrio follows a security-by-design approach: data protection is built into the architecture, processes, and development tooling. The measures below are implemented and audited regularly.

Encryption at rest

The PostgreSQL database hosted by Supabase is encrypted at rest at the disk level. Backups and associated files inherit the same encryption.

Encryption in transit

All communications between your browser, our servers, and third-party APIs are encrypted via TLS/HTTPS. Certificates are managed and renewed automatically.

Multi-tenant isolation

Each organization has a strictly isolated data perimeter. The database applies Row Level Security (RLS) policies based on organization_id: an authenticated user can never read or modify another organization's data.

Role-based access control

Sensitive financial data (transactions, bank accounts, reconciliations) is only accessible to executives (owner) and administrators (admin). Collaborators only see data strictly necessary for their role.

Column-level encryption

IBANs and other sensitive banking data are encrypted in the database using pgcrypto and a key stored in Supabase Vault. Even if the underlying storage is accessed, this data remains unreadable.

Secret management

Authentication secrets (API keys, cron tokens, webhook secrets) are never stored in plain text in code or the application database. They are kept in Supabase Vault and injected in a controlled manner.

API and webhook protection

All application endpoints require authentication. Inputs are validated with Zod, sensitive mutations are rate-limited, and incoming webhooks are verified by HMAC signature with idempotency.

Content Security Policy (CSP)

A unique nonce is generated per request for inline scripts. The CSP policy restricts connection origins (connect-src) to an explicit allowlist and blocks unauthorized scripts.

Monitoring and observability

Sentry collects errors and performance data with personal data scrubbing (IBANs, emails, tokens) applied before sending. PostHog collects product analytics data (page views, user journeys) only after explicit consent via the cookie banner, with personal data masking before sending. Sensitive pages (settings, billing, bank connection) are excluded from tracking.

Audits and governance

Klyrio has undergone a Red Team security audit with a score of 98.5/100. A security and regression skill is applied systematically to every code change to verify impact, security rules, and tests.

GDPR compliance

Rights of access, rectification, erasure, objection, and portability are described in the 'Your rights' section. The security measures above are the technical guarantees of that compliance.

No security measure is infallible; we encourage you to protect your credentials, use strong passwords, enable two-factor authentication when available, and report any suspected unauthorized access to contact@klyrio.io.

11. Contact

SARL Infly Communication — 5C rue Marie-Antoinette Tonnelet, 21000 Dijon — RCS Dijon 938 211 141.

Email: contact@klyrio.io — Website: klyrio.io.

For data protection questions, please use the subject line 'Personal data / GDPR' and address your request to our DPO at contact@klyrio.io to help us process it promptly.

12. Supervisory authority

If a dispute remains unresolved, you may contact the French Data Protection Authority (CNIL) — 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — www.cnil.fr.

SARL Infly Communication — RCS Dijon 938 211 141PrivacyTerms