Privacy Policy

Version 1.2 · In force since 2026-08-13

This policy explains what personal data TeamLayer processes, why, on what legal basis, and what rights you have. Data controller: Szymon Bodych OMERNET, Pomorska 11, 05-820 Piastów, Poland, VAT ID: PL5342310551, email hello@teamlayer.io.

1. Our two roles: controller and processor

This distinction decides who answers your questions about your data.

We are the CONTROLLER for data we need to run TeamLayer as a business: your account, the Team's subscription and billing, support correspondence, and security logs.

We are a PROCESSOR for the Content that Users put into a Team - messages, tasks, documents and files. Here the controller is the organisation that owns the Team. If you want that Content deleted or exported, ask the Team's Administrator first; we act on their instructions.

2. What data we process

3. Why we process it and on what legal basis

We do not profile you and we make no decisions about you by automated means alone. We do not sell personal data and we do not use it for advertising.

4. Who we share data with

We use the following processors, each bound by a data processing agreement: - OVH (OVH SAS) - servers on which the application and the database run, and the outgoing mail server. - Cloudflare, Inc. - storage of files and attachments (Cloudflare R2, EU location) and DNS. - Stripe, Inc. - payment processing and invoicing. - Expo (650 Industries, Inc.) - delivery of push notifications to the mobile application. - The push service of your browser or operating system (for example Google, Mozilla or Apple) - delivery of web notifications, if you enable them.

Beyond that, we disclose data only where the law requires it, for example at the demand of an authorised public authority.

5. Transfers outside the EEA

Our servers and the file storage are located in Europe. Some of our processors are established in the United States - this concerns Stripe, Cloudflare and the push notification providers.

Where data is transferred outside the European Economic Area, it happens on the basis of the European Commission's Standard Contractual Clauses or an adequacy decision, together with additional safeguards, including encryption in transit.

6. How long we keep data

7. Your rights

You have the right to access your data, to correct it, to erase it, to restrict its processing, to data portability, and to object to processing based on our legitimate interests. Where processing is based on consent, you may withdraw it at any time without affecting what was done before.

You can delete your account yourself, without writing to us: in the app, Account settings -> Delete account. Access ends at once and your personal data is erased after 30 days. What is erased, what stays with your Team and why, and how to ask us if you can no longer sign in: teamlayer.io/account-deletion.

Write to hello@teamlayer.io to exercise these rights. We reply within one month; if the matter is complex, we may extend that by a further two months and will tell you if we do.

If you believe we handle your data unlawfully, you may lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland.

If the request concerns Content inside a Team, ask the Team's Administrator - see section 1.

8. Security

Traffic is encrypted with TLS. Passwords are stored only as hashes, never in a readable form. Each Team has a separate database, which limits the consequences of any single incident. Access to production systems is limited to accounts that need it and is protected by SSH keys.

Files and attachments live in a private bucket and are served only through an authenticated route, so a link alone is not enough to reach them.

No safeguard gives absolute certainty. If a breach occurs that is likely to result in a high risk to your rights, we will notify you and the supervisory authority as the law requires.

9. Cookies and local storage

We use only cookies that are necessary for the Service to work: keeping you signed in, protecting forms against cross-site request forgery, and remembering your interface preferences. They need no consent and cannot be switched off without breaking sign-in.

We use no advertising cookies and no third-party analytics.

The application also stores a copy of part of your workspace in your browser (IndexedDB), so that it opens quickly and works offline. That data stays on your device and is erased when you sign out.

10. Calls and recordings

Voice and video calls run through our own media server. The audio and video stream is not stored - unless someone in the call starts a recording.

When a recording starts, everyone in the call sees a notice. Recordings belong to the Team and are stored in the same place as its other files.

11. AI assistants and integrations (MCP)

TeamLayer lets you connect an external AI assistant (for example Claude, Cursor or another tool supporting the MCP standard) to your Team's tasks and conversations. The feature is off by default and is only enabled by a decision of a user or a Team administrator.

If you enable it: - The assistant acts on your behalf and sees only what you have access to. It cannot see other people's private tasks or channels you do not belong to. - You choose the scope on the consent screen: tasks only, optionally attachments, optionally posting to channels. - The content the assistant requests (task content, comments, attachments) is transmitted to the provider of that assistant and is subject to their own privacy policy and terms. We do not choose that provider - you do, and you decide what data you make available to it. - We do not send anything to AI providers on our own initiative. We do not train AI models on Team content and we do not share Team content for that purpose. - We log the use of the access token (last use, write operations) for security and accountability.

You can revoke access at any time on the AI assistants page in your account, and a Team administrator can revoke the Team's API keys. Revocation takes effect immediately.

If your Team processes personal data subject to the GDPR, check before connecting an assistant whether your agreement with the AI provider allows it. In that respect your Team is the controller and decides about entrusting the data.

12. Changes to this policy

We may update this policy, for example when the Service or the list of processors changes. The current version is always published on this page with its version number and date.

Material changes are flagged here in the version note. Where a change significantly affects your rights, we also tell you in the app or by email before it takes effect.

13. Contact

Data controller: Szymon Bodych OMERNET, Pomorska 11, 05-820 Piastów, Poland, VAT ID: PL5342310551. All matters concerning personal data: hello@teamlayer.io. We have not appointed a data protection officer - write to that address.

Fragen zu dieser Seite? Kontakt