This is a public draft for review. The final version will be prepared with legal counsel and may differ in wording, operator details, and contractual annexes.
Leya is an enterprise knowledge platform: search over approved sources, an assistant with evidence, a knowledge library, and admin tools for access control.
This document explains what data is processed when you use Leya, for what purposes, on what grounds, how it is protected, and what rights you have. Leya does not use customer corporate data to train public AI models and does not sell personal data to third parties.
Scope
This policy covers the Leya web app, sign-in, corporate authentication, APIs, assistant, knowledge library, admin consoles, and related services provided to your organization.
- Work accounts for employees, contractors, and other users with granted access
- Knowledge content and metadata uploaded and governed by organization administrators
- Dialogs, search queries, assistant artifacts, and related evidence within granted permissions
- Audit logs, security events, and technical logs required to operate the platform
- Public pages (sign-in, legal documents, contact-admin form) when contact details are submitted
Roles of the parties
In a typical B2B setup, your organization is the controller/operator of employee and other data subjects’ personal data. The Leya platform processes data on the customer’s instructions as a processor, or is provided as software/infrastructure inside the customer perimeter (on-premise / private cloud).
- Tenant admins define users, roles, spaces, access policies, retention, and integrations
- Leya provides technical controls: authentication, ACL before retrieval, space isolation, audit, and administration tools
- For on-premise, infrastructure, network, and backup control remain with the customer
- Data subjects should first contact their organization admin or DPO
Data we process
Exact fields depend on tenant configuration, connected IdP/SCIM, and uploaded sources. Common categories include:
- Account identifiers: email, name, username/UPN, IdP identifiers, employee numbers, and other login identifiers enabled by the admin
- Profile and org structure: department, position, roles, groups, space and policy bindings
- Knowledge content: documents, courses, media, extracted fragments, source versions, and related metadata
- Usage data: search queries, assistant dialogs, selected sources/evidence, saved results and artifacts
- Administration data: tenant settings, branding, policies, ingestion/processing jobs, knowledge-quality records
- Technical and security data: sessions, cookies, IP/user-agent, access timestamps, privileged-action audit trails
- Contact data from support forms (e.g. contact administrator): name, email, topic, and message body
Purposes of processing
Data is processed only to deliver and protect the enterprise knowledge service and to perform the customer agreement.
- Authentication, session management, and login methods (SSO / local login)
- Search, assistant answers, and artifacts under ACL with source grounding
- Knowledge library operations: upload, processing, versioning, publishing, and retirement
- Tenant administration: users, roles, spaces, policies, knowledge quality, demand analytics
- Security: abuse prevention, incident response, access audit
- User support and handling contact-admin / support requests
- Legal compliance and contractual obligations to the customer
Legal bases
Specific legal bases depend on the customer’s jurisdiction, agreement, and internal policies. Common approaches include:
- Performance of an employment, contractor, or other relationship with your organization
- The organization’s legitimate interest in secure, controlled access to corporate knowledge
- Performance of the agreement between the customer and the Leya platform provider
- Consent — only where required by applicable law, a cookie banner, or tenant policy
- Compliance with legal obligations (including lawful requests via the customer’s process)
Knowledge access control
Leya’s core rule: permissions are enforced before retrieval. Materials a user cannot access must not appear in answers, search results, or exports.
- Roles, spaces, ACL, and policies determine source and fragment visibility
- Privileged and break-glass actions are audited
- Exports, integrations, and APIs follow administrator settings
- Admins may restrict local login, login identifiers, and SSO providers
AI processing
Leya uses models and processing pipelines for search, summarization, answers, and artifact preparation. Processing runs inside the approved tenant perimeter under the organization’s access rules.
- Customer corporate data is not used to train public / external foundation models
- Prompts, context, and answers are processed to fulfill the user request and related service functions
- Answers are accompanied by evidence / source references within materials available to the user
- Admins can manage sources, quality policies, and assistant feature availability
- AI answers do not replace expert review against primary documents in critical scenarios
Retention
Retention is set by the customer’s policies and agreement. While an account is active, profile and work-session data support the service. After deactivation, an admin request, or expiry, data is deleted, archived, or anonymized — subject to legal holds.
- Dialogs, search results, and artifacts are kept per tenant policy
- Audit logs may be retained longer for compliance and investigations
- Backups rotate on a limited cycle
- For on-premise, retention and deletion are fully controlled by customer infrastructure
- Contact-admin submissions are kept as needed to handle the request and related obligations
Security measures
We apply organizational and technical measures appropriate for enterprise knowledge systems and the customer’s threat model.
- TLS in transit, environment segmentation, and tenant/space isolation
- Least privilege, service-account controls, and secrets policies for integrations
- Auditing of critical operations, anomaly monitoring, and incident response procedures
- Session protection, password policies, and corporate SSO controls
- For SaaS/private cloud — platform-side controls; for on-premise — customer controls in their perimeter
Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection. For corporate data, requests usually go to your organization admin / DPO — the organization owns the tenant and responds to data subjects.
- Employee or contractor → tenant admin / organization DPO
- Organization admin → privacy@leya.work for platform and contractual privacy questions
- We may verify the requester’s identity and authority
- Response timelines follow your organization’s policy and applicable law
Transfers and subprocessors
In SaaS and private cloud, infrastructure and service providers may process data strictly under the customer agreement. Subprocessors are listed in contractual documents. For on-premise, data does not leave the customer perimeter unless integrations are explicitly configured by an admin.
- International transfers only with valid mechanisms (including contractual clauses / local law requirements)
- Models, gateway, and storage operate inside the approved tenant perimeter
- Admins control external integrations and export destinations
Policy changes
We may update this document when platform features, processed data, or legal requirements change. The current version is published in-product with an update date. Material changes are communicated to tenant admins as provided by the agreement or product notices.
- Continued use after changes take effect may constitute acceptance of the updated version if provided by the customer agreement
- Historical versions may be provided to an admin on request
Contact
For privacy and data-processing questions:
- Your organization admin in Leya — first contact for data-subject requests
- privacy@leya.work — platform and contractual privacy questions
- “Contact administrator” form on the sign-in screen — operational access requests
- legal@leya.work — legal requests about platform documents
This document applies to Leya deployments (SaaS, private cloud, on-premise). Tenant policies may add requirements but must not weaken access control or audit. If there is a conflict, the customer agreement and applicable law prevail.
← Back to sign in