Privacy Policy
Version 1.2 · In force since 2026-08-13
This policy explains what personal data TeamLayer processes, why, on what legal basis, and what rights you have. Data controller: Szymon Bodych OMERNET, Pomorska 11, 05-820 Piastów, Poland, VAT ID: PL5342310551, email hello@teamlayer.io.
1. Our two roles: controller and processor
This distinction decides who answers your questions about your data.
We are the CONTROLLER for data we need to run TeamLayer as a business: your account, the Team's subscription and billing, support correspondence, and security logs.
We are a PROCESSOR for the Content that Users put into a Team - messages, tasks, documents and files. Here the controller is the organisation that owns the Team. If you want that Content deleted or exported, ask the Team's Administrator first; we act on their instructions.
2. What data we process
- Account data: first and last name, email address, password (stored only as a hash), profile picture if you add one, interface language.
- Team data: your membership, role, and which channels you belong to.
- Content: messages, tasks, documents, comments, files and attachments you create or upload.
- Technical data: IP address, browser and device type, application version, event timestamps, error logs.
- Billing data: the Team's billing details, invoice history and a payment identifier from Stripe. We never receive your full card number.
- Contact data: what you send us by email or through the contact form.
3. Why we process it and on what legal basis
- To provide the Service under our contract with you - Article 6(1)(b) GDPR: creating and running an account, delivering messages, storing tasks and files, sending transactional email such as invitations and password resets.
- To handle payments and keep accounting records - Article 6(1)(b) and 6(1)(c) GDPR, together with tax law.
- For our legitimate interests - Article 6(1)(f) GDPR: keeping the Service secure, preventing abuse, diagnosing faults, and defending or pursuing claims.
- With your consent - Article 6(1)(a) GDPR: push notifications on your device and, if you enable it, access to the camera and microphone for calls. You can withdraw consent at any time in your device or browser settings.
We do not profile you and we make no decisions about you by automated means alone. We do not sell personal data and we do not use it for advertising.
4. Who we share data with
We use the following processors, each bound by a data processing agreement: - OVH (OVH SAS) - servers on which the application and the database run, and the outgoing mail server. - Cloudflare, Inc. - storage of files and attachments (Cloudflare R2, EU location) and DNS. - Stripe, Inc. - payment processing and invoicing. - Expo (650 Industries, Inc.) - delivery of push notifications to the mobile application. - The push service of your browser or operating system (for example Google, Mozilla or Apple) - delivery of web notifications, if you enable them.
Beyond that, we disclose data only where the law requires it, for example at the demand of an authorised public authority.
5. Transfers outside the EEA
Our servers and the file storage are located in Europe. Some of our processors are established in the United States - this concerns Stripe, Cloudflare and the push notification providers.
Where data is transferred outside the European Economic Area, it happens on the basis of the European Commission's Standard Contractual Clauses or an adequacy decision, together with additional safeguards, including encryption in transit.
6. How long we keep data
- Account data: for as long as the account exists, and for up to 30 days after deletion, so that an accidental deletion can be reversed.
- Content in a Team: for as long as the Team keeps it. After the Team is deleted, its database is removed within 30 days.
- Backups: kept for up to 30 days and then overwritten. Data deleted from the Service may still exist in a backup until it expires.
- Billing documents: 5 years from the end of the tax year, as required by accounting law.
- Security and technical logs: up to 12 months.
- Correspondence with us: up to 3 years, or longer if it may be needed for claims.
7. Your rights
You have the right to access your data, to correct it, to erase it, to restrict its processing, to data portability, and to object to processing based on our legitimate interests. Where processing is based on consent, you may withdraw it at any time without affecting what was done before.
You can delete your account yourself, without writing to us: in the app, Account settings -> Delete account. Access ends at once and your personal data is erased after 30 days. What is erased, what stays with your Team and why, and how to ask us if you can no longer sign in: teamlayer.io/account-deletion.
Write to hello@teamlayer.io to exercise these rights. We reply within one month; if the matter is complex, we may extend that by a further two months and will tell you if we do.
If you believe we handle your data unlawfully, you may lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland.
If the request concerns Content inside a Team, ask the Team's Administrator - see section 1.
8. Security
Traffic is encrypted with TLS. Passwords are stored only as hashes, never in a readable form. Each Team has a separate database, which limits the consequences of any single incident. Access to production systems is limited to accounts that need it and is protected by SSH keys.
Files and attachments live in a private bucket and are served only through an authenticated route, so a link alone is not enough to reach them.
No safeguard gives absolute certainty. If a breach occurs that is likely to result in a high risk to your rights, we will notify you and the supervisory authority as the law requires.
9. Cookies and local storage
We use only cookies that are necessary for the Service to work: keeping you signed in, protecting forms against cross-site request forgery, and remembering your interface preferences. They need no consent and cannot be switched off without breaking sign-in.
We use no advertising cookies and no third-party analytics.
The application also stores a copy of part of your workspace in your browser (IndexedDB), so that it opens quickly and works offline. That data stays on your device and is erased when you sign out.
10. Calls and recordings
Voice and video calls run through our own media server. The audio and video stream is not stored - unless someone in the call starts a recording.
When a recording starts, everyone in the call sees a notice. Recordings belong to the Team and are stored in the same place as its other files.
11. AI assistants and integrations (MCP)
TeamLayer lets you connect an external AI assistant (for example Claude, Cursor or another tool supporting the MCP standard) to your Team's tasks and conversations. The feature is off by default and is only enabled by a decision of a user or a Team administrator.
If you enable it: - The assistant acts on your behalf and sees only what you have access to. It cannot see other people's private tasks or channels you do not belong to. - You choose the scope on the consent screen: tasks only, optionally attachments, optionally posting to channels. - The content the assistant requests (task content, comments, attachments) is transmitted to the provider of that assistant and is subject to their own privacy policy and terms. We do not choose that provider - you do, and you decide what data you make available to it. - We do not send anything to AI providers on our own initiative. We do not train AI models on Team content and we do not share Team content for that purpose. - We log the use of the access token (last use, write operations) for security and accountability.
You can revoke access at any time on the AI assistants page in your account, and a Team administrator can revoke the Team's API keys. Revocation takes effect immediately.
If your Team processes personal data subject to the GDPR, check before connecting an assistant whether your agreement with the AI provider allows it. In that respect your Team is the controller and decides about entrusting the data.
12. Changes to this policy
We may update this policy, for example when the Service or the list of processors changes. The current version is always published on this page with its version number and date.
Material changes are flagged here in the version note. Where a change significantly affects your rights, we also tell you in the app or by email before it takes effect.
13. Contact
Data controller: Szymon Bodych OMERNET, Pomorska 11, 05-820 Piastów, Poland, VAT ID: PL5342310551. All matters concerning personal data: hello@teamlayer.io. We have not appointed a data protection officer - write to that address.
Fragen zu dieser Seite? Kontakt