Primary processing
European Union
Core processing runs in the European Union across Falkenstein, Germany for core services; Nuremberg, Germany for analytics; Cloudflare R2 Eastern Europe (EEUR); and Resend Ireland (eu-west-1).
Enterprise assurance
This Trust Center explains where Lyniti processes data, which providers support the service, how data is protected, how incidents are handled, and which commitments are contractual today. Where an operational fact has not completed verification, we say so instead of publishing an unsupported claim.
Primary processing
European Union
Core processing runs in the European Union across Falkenstein, Germany for core services; Nuremberg, Germany for analytics; Cloudflare R2 Eastern Europe (EEUR); and Resend Ireland (eu-west-1).
Encryption
TLS and AES-256-GCM
Transport uses TLS. PII fields, chat data, and uploaded files have separate AES-256-GCM encryption paths.
Availability
Public status history
Operational status belongs at status.lyniti.com. Numeric contractual uptime is not published before OP-01 validation.
Security reports
Direct human contact
Reports go to support@lyniti.com and are triaged through the incident process.
Trust overview
Providers with a role in delivering Lyniti are listed with purpose, customer-data scope, region position, transfer basis, and provider data-processing terms.
| Provider | Role | Data processed | Region | Transfer position | Terms |
|---|---|---|---|---|---|
Hetzner Online GmbH | Core compute and hosting infrastructure | Application traffic, customer content, service logs, and encrypted service data hosted on Lyniti deployments | Falkenstein, Germany - Core compute; Nuremberg, Germany - Secondary | EU processing under provider DPA | Provider DPA |
Cloudflare, Inc. | CDN, network-edge services, and R2 object storage | Request metadata, IP and security signals, cached delivery data, object metadata, and file ciphertext encrypted by Lyniti with AES-256-GCM before R2 storage | Global network edge; R2 data location Eastern Europe (EEUR) | Cloudflare DPA and applicable transfer safeguards | Provider DPA |
Plus Five Five, Inc. (Resend) | Transactional email delivery | Recipient address, message content, delivery metadata, and attachments when included in an email | Ireland (eu-west-1) | Provider DPA includes EU Standard Contractual Clauses | Provider DPA |
Stripe | Payment processing, subscriptions, invoices, and billing events | Billing contacts, customer and subscription identifiers, payment and invoice records; Lyniti does not store full card numbers | EEA, United States, and other service locations described by Stripe | Stripe DPA and Data Transfers Addendum | Provider DPA |
Lyniti-operated PostgreSQL | Primary structured application database | Account, workspace, collaboration, business, billing-reference, permission, and audit records | Falkenstein, Germany | No separate SaaS processor; underlying hosting provider applies | Not applicable - Lyniti operated |
Lyniti-operated Redis | Cache, session state, coordination, and realtime support | Short-lived cached application data, authorization snapshots, session and realtime coordination records | Falkenstein, Germany | No separate SaaS processor; underlying hosting provider applies | Not applicable - Lyniti operated |
Custom Analytics Solutions | Custom privacy-focused service and website analytics solution | Page, feature, performance, and event metadata where configured and permitted by consent settings | Nuremberg, Germany | No separate analytics SaaS processor; underlying hosting provider applies | Not applicable - Lyniti operated |
Enterprise review contact
Send security questionnaires, DPA requests, residency questions, or requests for non-public evidence to this address. Include your organization, required deadline, and requested control scope.