Legal

Privacy Policy

How Sorvyn handles personal data, for accounting firms and for their clients.

📅 Last updated: July 3, 2026 🇱🇺 Governed by Luxembourg law 🇪🇺 GDPR compliant, data hosted in the EU

Table of Contents

  1. 1. Who We Are
  2. 2. Two Roles: Controller and Processor
  3. 3. If You Are a Client of an Accounting Firm
  4. 4. Data We Collect
  5. 5. Purposes, Legal Bases and Retention
  6. 6. Inside the Product: Documents and AI
  7. 7. Subprocessors and Recipients
  8. 8. International Transfers
  9. 9. Data Security
  10. 10. Cookies and Analytics
  11. 11. Your Rights
  12. 12. Changes and Contact
Section 01

Who We Are

Sorvyn is software for accounting firms (fiduciaires). Firms use Sorvyn to collect bookkeeping documents from their clients, have those documents read and checked automatically, and chase the missing ones. Sorvyn is a professional, business-to-business service. It is not aimed at consumers.

Sorvyn is operated by MR.MEDIA S.A.R.L-S, a company established in Luxembourg, European Union, trading as Sorvyn.

Data Controller (for the data covered by this policy): MR.MEDIA S.A.R.L-S (trading as Sorvyn)
Registration: RCS Luxembourg B291701
Contact: patrick@sorvyn.ai
Jurisdiction: Luxembourg, European Union

This policy applies to the sorvyn.ai website and to the Sorvyn application at books.sorvyn.ai. The legacy Sorvyn dashboard at app.sorvyn.ai is governed by the separate policy published there.

Section 02

Two Roles: Controller and Processor

Under the GDPR, a controller decides why and how personal data is used. A processor only handles data on a controller's instructions. Sorvyn wears both hats, for different data:

Sorvyn as controller

Visitors to this website, people who book a demo or email us, newsletter subscribers, and our customers' own account and billing data. This policy covers this data.

Sorvyn as processor

Everything inside the product: the documents an accounting firm's clients send in, the data extracted from them, anomaly flags, and reminder emails. The accounting firm is the controller of this data.

The important carve-out: this policy does not apply to personal data contained in documents uploaded to Sorvyn by an accounting firm or its clients. For that data, the accounting firm is the data controller and Sorvyn acts strictly as its processor, under a Data Processing Agreement (Article 28 GDPR) signed with the firm. We process it only on the firm's instructions, and never for our own purposes.

Section 03

If You Are a Client of an Accounting Firm

Your accountant uses Sorvyn and invited you to send your bookkeeping documents through a personal upload page or a dedicated email address. Here is what happens with them, always on your accounting firm's instructions:

Your rights over this data: because your accounting firm is the controller, please contact your accounting firm to access, correct or delete this data, or to object to the processing. We assist the firm in responding to every such request. Your firm's own privacy notice governs this processing.

Section 04

Data We Collect (as controller)

Account Data

For accounting-firm users: firm name, user name and email, password (stored hashed), language and product settings, firm logo.

Billing Data

Invoicing contact and address, VAT number, payment records. We invoice manually and do not store card numbers.

Prospect Data

Name, email and anything you tell us when you book a demo or contact us. Demo bookings run on Cal.com under its own privacy policy; we receive the details you submit.

Newsletter Data

Email address, if you subscribed on one of our pages. Kept until you unsubscribe (one click in every email).

Website Usage Data

Pages visited, clicks, approximate location derived from IP, browser and device type. Collected without storing identifiers on your device (see Section 10).

Support Data

Emails and messages you exchange with us, so we can help you and keep a record of what was agreed.

Section 05

Purposes, Legal Bases and Retention

One table, four answers: what we use, why we may use it, and how long we keep it.

PurposeDataLegal basis (GDPR)Retention
Providing and administering the Sorvyn service Account data Contract, Art. 6(1)(b) Life of the contract, deleted within 30 days of account closure
Invoicing and company accounting Billing data Legal obligation, Art. 6(1)(c) 10 years (Luxembourg Code de commerce, Art. 16)
Answering demo requests and following up with professional prospects Prospect data Legitimate interest, Art. 6(1)(f) (B2B contact you initiated or could reasonably expect) 24 months after last contact
Sending the newsletter Newsletter data Consent, Art. 6(1)(a) Until you unsubscribe
Understanding how the website is used, improving it Website usage data Legitimate interest, Art. 6(1)(f) Up to 12 months
Security, abuse prevention, establishing or defending legal claims Technical logs, correspondence Legitimate interest, Art. 6(1)(f) 12 months for logs; duration of the dispute where a claim exists

Where we rely on legitimate interest, you can object at any time (see Section 11). Providing account and billing data is necessary to use the service; the rest is optional.

Section 06

Inside the Product: Documents and AI

For transparency, here is how document processing works inside Sorvyn. Remember: for all of this data the accounting firm is the controller, and the details are governed by our Data Processing Agreement with the firm.

Our AI commitments: we do not allow any AI provider we use to train its models on your data. Document reading uses Anthropic's Claude under commercial terms that prohibit training on customer content, and Anthropic does not retain this content long-term. Text recognition on photographed bank statements runs directly in the accountant's browser; its results are not sent to our servers. Sorvyn makes no automated decisions with legal or similar significant effect (GDPR Art. 22): a human accountant always reviews and decides.

When an accounting firm deletes a document or a client, the stored files themselves are deleted, not just the database entry. Accounting firms remain responsible for their own legal retention duties (in Luxembourg, generally 10 years for accounting documents).

Section 07

Subprocessors and Recipients

We use a small number of carefully chosen providers. Each one is bound by a data processing agreement, and we never sell personal data or share it for advertising.

ProviderWhat it doesCompany locationData location and safeguard
Supabase Database, file storage and login for the application USA Data hosted in Frankfurt, Germany (EU); Standard Contractual Clauses cover any remote access
Anthropic AI reading of documents (Claude) USA Standard Contractual Clauses; no training on customer data; no long-term retention
Postmark (ActiveCampaign) Sending and receiving product email (reminders, document intake) USA EU-U.S. Data Privacy Framework certified, plus Standard Contractual Clauses
Vercel Hosting of the website and application front-end USA EU-U.S. Data Privacy Framework certified, plus Standard Contractual Clauses
PostHog Website analytics USA Data hosted on PostHog's EU cloud (Frankfurt)
Loops Newsletter delivery USA EU-U.S. Data Privacy Framework certified
Cal.com Demo call scheduling USA Bookings are made on Cal.com under its own privacy policy

Other possible recipients: our accountant and professional advisers (bound by confidentiality), and public authorities where the law requires it. We will inform accounting-firm customers before adding or replacing a subprocessor that touches product data, as set out in the DPA.

Section 08

International Transfers

Your documents and product data are stored at rest in the European Union (Frankfurt, Germany). Some of our providers are established in the United States. Where personal data is transferred to the USA, we rely on the safeguards listed in the table above: the EU-U.S. Data Privacy Framework for certified providers (Postmark, Vercel, Loops), and the European Commission's Standard Contractual Clauses for the others (Anthropic, Supabase remote access).

You can request a copy of the relevant safeguards by writing to patrick@sorvyn.ai.

Section 09

Data Security

No system is perfectly secure. If a breach were ever to affect your personal data, we would notify the CNPD and, as applicable, the affected individuals or controllers, as required by GDPR Articles 33 and 34.

Section 10

Cookies and Analytics

We keep this simple:

Section 11

Your Rights Under GDPR

For the data where Sorvyn is the controller (Sections 4 and 5), you can exercise these rights free of charge by emailing patrick@sorvyn.ai. We respond within one month.

👁

Access

Get a copy of the personal data we hold about you.

✏️

Rectification

Have inaccurate or incomplete data corrected.

🗑

Erasure

Have your data deleted where there is no legal reason to keep it.

⏸️

Restriction

Limit how we use your data while a question is resolved.

📦

Portability

Receive your data in a structured, machine-readable format.

Objection

Object to processing based on legitimate interest, including prospecting.

Where processing is based on consent (the newsletter), you can withdraw it at any time; every newsletter contains a one-click unsubscribe link.

Complaints: you can lodge a complaint with Luxembourg's supervisory authority, the Commission nationale pour la protection des données (CNPD), 15 Boulevard du Jazz, L-4370 Belvaux, Luxembourg, cnpd.public.lu, or with the authority of your habitual residence.

A reminder: for personal data inside documents processed for an accounting firm, please address your request to that firm (see Section 3). We assist the firm with every request.

Section 12

Changes and Contact

If we make material changes to this policy, we will post the new version here and inform account holders by email. The date at the top always shows the latest revision.

Contact us

Entity MR.MEDIA S.A.R.L-S (trading as Sorvyn)
Register RCS Luxembourg B291701
Country Luxembourg, European Union