Privacy Policy

Last updated: July 14, 2026

Leya is an organizational knowledge system. We process data only inside your organization boundary and only to deliver approved knowledge access, assistant workflows, and administration.

This document explains what data is processed, on what grounds, how it is protected, and what rights you have. Leya does not use corporate data to train public AI models.

Scope

This policy covers the Leya web app, corporate login, APIs, and admin consoles provided to your organization.

  • Employee and contractor accounts with granted access
  • Content uploaded and governed by your organization administrators
  • Audit logs required for security and investigations

Roles of the parties

Typically your organization is the controller/operator of employee personal data. Empiflow / Leya acts as a processor (or infrastructure provider for on-prem), processing data under the customer’s instructions.

  • Tenant admins define users, roles, spaces, and retention policies
  • Leya provides technical controls: authentication, ACL, audit, space isolation
  • For on-prem, infrastructure control stays with the customer

Data we process

Exact fields depend on tenant configuration; common categories include:

  • Account identifiers: email, display name, IdP / SCIM identifiers
  • Profile and org structure: department, position, roles, space bindings
  • Query content and assistant working results within granted permissions
  • Access metadata: sign-in time, IP/user-agent, action audit trail
  • Technical cookies/sessions required for secure authentication

Purposes of processing

Data is processed strictly to deliver the service and protect the knowledge perimeter.

  • Authentication and session management
  • Search, answers, and artifacts under ACL
  • Tenant administration: users, roles, knowledge quality, ingestion
  • Security: abuse detection, audit, incident response
  • Contract performance and mandatory legal obligations

Legal bases

Bases depend on customer jurisdiction and agreement. Commonly:

  • Performance of an employment/contractor relationship with your organization
  • Customer legitimate interest in secure access to corporate knowledge
  • Consent — only where required by local law or tenant policy

Access control for knowledge

Leya’s core rule: access is enforced before retrieval. Denied documents never appear in answers or exports.

  • Roles, spaces, and ACL bound content visibility
  • Break-glass and privileged actions are audited
  • Exports and integrations follow administrator policies

Retention

Retention is set by the customer’s policies. While an account is active, profile and work-session data support the service. After deactivation or an admin request, data is deleted or anonymized per configured schedules and legal holds.

  • Audit logs may be kept longer for compliance
  • Backups rotate on a limited cycle
  • On-prem retention is fully controlled by customer infrastructure

Security measures

We apply organizational and technical measures appropriate for enterprise knowledge systems.

  • TLS in transit, environment segmentation
  • Least privilege and service-account controls
  • Auditing of critical operations and anomaly monitoring
  • Tenant/space isolation and secrets policies for integrations

Cookies and local storage

Leya uses necessary cookies and browser storage for session, locale, and basic UI preferences. Third-party analytics cookies are not enabled by default in the corporate perimeter.

  • Session cookies — sign-in and browser security controls
  • Local UI preferences (e.g. cookie consent) — on the user device

Your rights

Depending on applicable law, you may request access, correction, deletion, restriction, or portability. For corporate data, requests usually go to your organization admin — they own the tenant and responses.

  • Employee → tenant admin / organization DPO
  • Admin → Leya support (privacy@leya.work) for platform questions
  • We may verify identity and authority of the requester

Transfers and subprocessors

In SaaS/private cloud, infrastructure providers may process data strictly under contract. Subprocessors are listed in the customer agreement. For on-prem, data does not leave the customer perimeter unless integrations are explicitly configured.

  • International transfers only with valid mechanisms (SCCs / local requirements)
  • Models and gateway operate inside the approved tenant perimeter

Policy changes

We may update this document when features or legal requirements change. The current version is published in-product with an update date. Material changes are communicated to tenant administrators.

Contact

For privacy questions:

  • Your Leya organization admin — first contact for data-subject requests
  • privacy@leya.work — platform and contractual questions
  • admin@leya.work — operational access requests

This text applies to Leya deployments (SaaS / private cloud / on-prem). Local tenant policies may add requirements but must not weaken access controls.

← Back to sign in