How Sorvyn handles personal data, for accounting firms and for their clients.
Sorvyn is software for accounting firms (fiduciaires). Firms use Sorvyn to collect bookkeeping documents from their clients, have those documents read and checked automatically, and chase the missing ones. Sorvyn is a professional, business-to-business service. It is not aimed at consumers.
Sorvyn is operated by MR.MEDIA S.A.R.L-S, a company established in Luxembourg, European Union, trading as Sorvyn.
Data Controller (for the data covered by this policy): MR.MEDIA S.A.R.L-S (trading as Sorvyn)
Registration: RCS Luxembourg B291701
Contact: patrick@sorvyn.ai
Jurisdiction: Luxembourg, European Union
This policy applies to the sorvyn.ai website and to the Sorvyn application at books.sorvyn.ai. The legacy Sorvyn dashboard at app.sorvyn.ai is governed by the separate policy published there.
Under the GDPR, a controller decides why and how personal data is used. A processor only handles data on a controller's instructions. Sorvyn wears both hats, for different data:
Visitors to this website, people who book a demo or email us, newsletter subscribers, and our customers' own account and billing data. This policy covers this data.
Everything inside the product: the documents an accounting firm's clients send in, the data extracted from them, anomaly flags, and reminder emails. The accounting firm is the controller of this data.
The important carve-out: this policy does not apply to personal data contained in documents uploaded to Sorvyn by an accounting firm or its clients. For that data, the accounting firm is the data controller and Sorvyn acts strictly as its processor, under a Data Processing Agreement (Article 28 GDPR) signed with the firm. We process it only on the firm's instructions, and never for our own purposes.
Your accountant uses Sorvyn and invited you to send your bookkeeping documents through a personal upload page or a dedicated email address. Here is what happens with them, always on your accounting firm's instructions:
Your rights over this data: because your accounting firm is the controller, please contact your accounting firm to access, correct or delete this data, or to object to the processing. We assist the firm in responding to every such request. Your firm's own privacy notice governs this processing.
For accounting-firm users: firm name, user name and email, password (stored hashed), language and product settings, firm logo.
Invoicing contact and address, VAT number, payment records. We invoice manually and do not store card numbers.
Name, email and anything you tell us when you book a demo or contact us. Demo bookings run on Cal.com under its own privacy policy; we receive the details you submit.
Email address, if you subscribed on one of our pages. Kept until you unsubscribe (one click in every email).
Pages visited, clicks, approximate location derived from IP, browser and device type. Collected without storing identifiers on your device (see Section 10).
Emails and messages you exchange with us, so we can help you and keep a record of what was agreed.
One table, four answers: what we use, why we may use it, and how long we keep it.
| Purpose | Data | Legal basis (GDPR) | Retention |
|---|---|---|---|
| Providing and administering the Sorvyn service | Account data | Contract, Art. 6(1)(b) | Life of the contract, deleted within 30 days of account closure |
| Invoicing and company accounting | Billing data | Legal obligation, Art. 6(1)(c) | 10 years (Luxembourg Code de commerce, Art. 16) |
| Answering demo requests and following up with professional prospects | Prospect data | Legitimate interest, Art. 6(1)(f) (B2B contact you initiated or could reasonably expect) | 24 months after last contact |
| Sending the newsletter | Newsletter data | Consent, Art. 6(1)(a) | Until you unsubscribe |
| Understanding how the website is used, improving it | Website usage data | Legitimate interest, Art. 6(1)(f) | Up to 12 months |
| Security, abuse prevention, establishing or defending legal claims | Technical logs, correspondence | Legitimate interest, Art. 6(1)(f) | 12 months for logs; duration of the dispute where a claim exists |
Where we rely on legitimate interest, you can object at any time (see Section 11). Providing account and billing data is necessary to use the service; the rest is optional.
For transparency, here is how document processing works inside Sorvyn. Remember: for all of this data the accounting firm is the controller, and the details are governed by our Data Processing Agreement with the firm.
Our AI commitments: we do not allow any AI provider we use to train its models on your data. Document reading uses Anthropic's Claude under commercial terms that prohibit training on customer content, and Anthropic does not retain this content long-term. Text recognition on photographed bank statements runs directly in the accountant's browser; its results are not sent to our servers. Sorvyn makes no automated decisions with legal or similar significant effect (GDPR Art. 22): a human accountant always reviews and decides.
When an accounting firm deletes a document or a client, the stored files themselves are deleted, not just the database entry. Accounting firms remain responsible for their own legal retention duties (in Luxembourg, generally 10 years for accounting documents).
We use a small number of carefully chosen providers. Each one is bound by a data processing agreement, and we never sell personal data or share it for advertising.
| Provider | What it does | Company location | Data location and safeguard |
|---|---|---|---|
| Supabase | Database, file storage and login for the application | USA | Data hosted in Frankfurt, Germany (EU); Standard Contractual Clauses cover any remote access |
| Anthropic | AI reading of documents (Claude) | USA | Standard Contractual Clauses; no training on customer data; no long-term retention |
| Postmark (ActiveCampaign) | Sending and receiving product email (reminders, document intake) | USA | EU-U.S. Data Privacy Framework certified, plus Standard Contractual Clauses |
| Vercel | Hosting of the website and application front-end | USA | EU-U.S. Data Privacy Framework certified, plus Standard Contractual Clauses |
| PostHog | Website analytics | USA | Data hosted on PostHog's EU cloud (Frankfurt) |
| Loops | Newsletter delivery | USA | EU-U.S. Data Privacy Framework certified |
| Cal.com | Demo call scheduling | USA | Bookings are made on Cal.com under its own privacy policy |
Other possible recipients: our accountant and professional advisers (bound by confidentiality), and public authorities where the law requires it. We will inform accounting-firm customers before adding or replacing a subprocessor that touches product data, as set out in the DPA.
Your documents and product data are stored at rest in the European Union (Frankfurt, Germany). Some of our providers are established in the United States. Where personal data is transferred to the USA, we rely on the safeguards listed in the table above: the EU-U.S. Data Privacy Framework for certified providers (Postmark, Vercel, Loops), and the European Commission's Standard Contractual Clauses for the others (Anthropic, Supabase remote access).
You can request a copy of the relevant safeguards by writing to patrick@sorvyn.ai.
No system is perfectly secure. If a breach were ever to affect your personal data, we would notify the CNPD and, as applicable, the affected individuals or controllers, as required by GDPR Articles 33 and 34.
We keep this simple:
For the data where Sorvyn is the controller (Sections 4 and 5), you can exercise these rights free of charge by emailing patrick@sorvyn.ai. We respond within one month.
Get a copy of the personal data we hold about you.
Have inaccurate or incomplete data corrected.
Have your data deleted where there is no legal reason to keep it.
Limit how we use your data while a question is resolved.
Receive your data in a structured, machine-readable format.
Object to processing based on legitimate interest, including prospecting.
Where processing is based on consent (the newsletter), you can withdraw it at any time; every newsletter contains a one-click unsubscribe link.
Complaints: you can lodge a complaint with Luxembourg's supervisory authority, the Commission nationale pour la protection des données (CNPD), 15 Boulevard du Jazz, L-4370 Belvaux, Luxembourg, cnpd.public.lu, or with the authority of your habitual residence.
A reminder: for personal data inside documents processed for an accounting firm, please address your request to that firm (see Section 3). We assist the firm with every request.
If we make material changes to this policy, we will post the new version here and inform account holders by email. The date at the top always shows the latest revision.