Skip to main content

Privacy statement

1. Introduction

Lyanthe B.V. ("Lyanthe", "we", "us") develops and supplies software for automating pre-accounting. When you visit our website, use our software or otherwise contact us, we process personal data. This privacy statement explains which data that is, why we process it, on what legal basis, how long we keep it and what rights you have.

Personal data means any information relating to an identified or identifiable natural person, such as a name, email address or IP address.

Lyanthe B.V. operates independently and is itself responsible for the processing described in this statement. We do not share your personal data with other companies within the group to which Lyanthe belongs.

2. Contact

Do you have questions about this privacy statement or about how we handle your personal data? Or would you like to report a possible breach? Please contact us at contact@lyanthe.com.

Lyanthe B.V.Peijerstraat 68-706101 GE EchtChamber of Commerce (KvK) number: 55579876

3. Lyanthe as processor

Lyanthe's customers use our software to process data relating to their own accounts. Examples include purchase and sales invoices and the details of suppliers, customers and employees they contain. For this data, our customer (for example your accounting firm, bookkeeping firm or employer) is the controller. Lyanthe is then the processor: we process the data solely on behalf of and in accordance with the instructions of that customer. The arrangements on this are laid down in a data processing agreement.

Would you like to exercise your rights regarding data that a Lyanthe customer processes through our software? Please address your request to that customer. If we receive your request directly, we will forward it to the customer concerned.

4. Lyanthe as controller

For the processing described in this chapter, Lyanthe itself determines the purposes and means and is the controller.

4.1 Usage data and security of the software

Using our software automatically generates data, such as log, security and performance data. We use this data to deliver, secure and improve the software, to detect and prevent misuse and security incidents, and to comply with legal obligations.

Data: username, login ID, IP address, device and browser information, timestamps and actions in the software.

Legal basis: legitimate interest (Article 6(1)(f) GDPR), namely a secure, stable and properly functioning service for our customers; where applicable, a legal obligation (Article 6(1)(c) GDPR).

Retention period: 12 months

4.2 Anonymised and aggregated data

We anonymise and aggregate data from our software on behalf of our customers. The result cannot be traced back to an individual or to a customer, so this data is no longer personal data. We use it to maintain, secure, analyse and improve our services, and to develop and train models. We carry out the anonymisation itself as a processor on behalf of the customer.

4.3 Training and improvement of recognition and matching models

Our software recognises data on invoices and makes booking suggestions. When users or service providers engaged by us correct or validate a recognition or suggestion, we may use that correction to train, test and improve our recognition and matching models. In that case, we use the correction together with the related invoice image and the data extracted from it (together: "Training Data"). We deploy these models for all our customers.

Data subjects: persons whose data appears on invoices, such as contact persons of our customers' suppliers and buyers, and the users who make the corrections.

Data: contact details (name, address, telephone, email, Chamber of Commerce and VAT number), job information, financial data on invoices and the correction or validation itself.

Legal basis: legitimate interest (Article 6(1)(f) GDPR), namely improving the accuracy of our software for all our customers.

In doing so, we observe the following safeguards:

  • We primarily train with anonymised data. If that is demonstrably insufficient for the purpose, we pseudonymise the Training Data beforehand. If that too is demonstrably insufficient, we limit the processing to what is strictly necessary.
  • We process Training Data in a separate environment with at least the same level of security as our production environment.
  • Training and hosting of the models take place exclusively within the European Economic Area (EEA).
  • We take measures to prevent the models or their output from making one customer's data available to other customers.
  • We do not use data from customers who process special categories of personal data or criminal-offence data as Training Data.
  • Customers can opt out of the use of their data as Training Data.

In the future, corrections and validations may be carried out by a service provider outside the EEA. We will only engage such a service provider for this purpose after we have concluded the EU Standard Contractual Clauses (SCCs) with it and carried out a transfer impact assessment. See also chapter 6.

You can object to this processing (see chapter 8).

Retention period: as long as necessary for training the relevant model version, with an annual review

Our software makes suggestions; our customer reviews and decides. There is no automated decision-making producing legal effects or similarly significant effects for you (Article 22 GDPR).

4.4 Customer relationship, contract management and invoicing

We process data of contact persons of our (prospective) customers in order to issue quotations, conclude and perform agreements, manage accounts and invoice.

Data: name, job title, organisation, business email address, telephone number and billing details.

Legal basis: legitimate interest (Article 6(1)(f) GDPR), namely maintaining the business relationship with our customer; for administration and invoicing, a legal obligation (Article 6(1)(c) GDPR).

Retention period: term of the agreement plus 7 years

4.5 Newsletter and marketing

We send newsletters and other marketing messages by email.

  • Prospects and website visitors: we only send you messages if you have signed up for them. The legal basis is your consent (Article 6(1)(a) GDPR). You can withdraw your consent at any time.
  • Existing customers: contact persons of customers may receive messages about similar products and services from Lyanthe. The legal basis is our legitimate interest (Article 6(1)(f) GDPR), within the limits of Article 11.7 of the Dutch Telecommunications Act. You can unsubscribe when your email address is collected and in every message.

Data: name, email address and, if you are a customer, organisation.

You can unsubscribe via the link at the bottom of every message or via contact@lyanthe.com. Even after unsubscribing, you will receive messages that are necessary for the performance of the agreement, such as service and maintenance notifications.

Retention period: until you unsubscribe, then no more than 1 month to process the unsubscription

4.6 Contact form, demo requests and support

If you contact us via the contact form on our website, request a demo or submit a support request, we process the data you provide in order to handle your question and stay in touch with you. The form is protected by Google reCAPTCHA.

Data: name, organisation, email address, telephone number, the content of your message and any further correspondence.

Legal basis: legitimate interest (Article 6(1)(f) GDPR), namely answering questions and supporting users; for support requests from customers, also the performance of the agreement with our customer.

Retention period: 2 years after the last contact

4.7 Cookies and website statistics

Without your consent, we only place cookies that are strictly necessary to remember your cookie preferences. We only place all other cookies after you have given your consent in the cookie banner (Article 11.7a of the Dutch Telecommunications Act). The legal basis for processing the data is then your consent (Article 6(1)(a) GDPR). You can change your choice per category at any time via the cookie settings at the bottom of the website.

Functional cookies (Google reCAPTCHA). Our contact and demo forms are protected against spam and abuse by Google reCAPTCHA. To do this, reCAPTCHA assesses, among other things, your IP address, browser, device and mouse movements, and may use your Google account if you are logged in to it. Google also uses some of this data for its own purposes and is itself responsible for that; see the Google privacy policy. If you do not accept these cookies, you cannot submit the forms. In that case, you can email us at contact@lyanthe.com.

Analytical and marketing cookies (HubSpot). These allow us to measure how visitors use our website, which pages they visit and how they arrive at it. If you subsequently fill in a form, we link your previous website visits to your contact details.

Data: IP address, cookie ID, device and browser information, pages visited and click behaviour.

Retention period: the HubSpot cookies expire after no more than 6 months; we keep the data in HubSpot for 24 months.

4.8 Security and management of the website

To detect problems with our website and servers and to keep the website secure, our servers keep log files containing, among other things, IP addresses.

Legal basis: legitimate interest (Article 6(1)(f) GDPR), namely a secure and available website.

Retention period: 12 months

5. Who we share personal data with

We do not sell your personal data. We only share it when necessary for the purposes set out in this statement:

  • Processors. We engage service providers for, among other things, hosting and infrastructure, email and marketing software, website statistics, website forms, customer service and ticketing software, and checking and correcting recognition results. We conclude a data processing agreement with these service providers. An overview of the processors we engage is available on request via contact@lyanthe.com.
  • Integrations on our customer's instructions. If a customer activates an integration with, for example, an accounting package, we exchange data with that party on behalf of that customer.
  • Third parties with their own responsibility. We use Google reCAPTCHA to secure our forms. Google processes some of this data for its own purposes and is itself responsible for that (see 4.7).
  • Government authorities. We only provide personal data to the police, supervisory authorities or other government bodies if we are legally obliged to do so. We assess every request in advance and provide no more than is strictly required.

6. Transfers outside the EEA

In principle, we process personal data within the EEA. Some service providers may process data outside the EEA, such as providers of marketing, analytics and form security software in the United States. When transferring data outside the EEA, we ensure an appropriate safeguard:

  • an adequacy decision of the European Commission, such as the EU-US Data Privacy Framework for companies certified under it; or
  • the EU Standard Contractual Clauses (SCCs), where necessary with supplementary measures based on an assessment of the level of protection in the recipient country.

More information about the safeguards for a specific transfer is available on request via contact@lyanthe.com.

7. Security

We take appropriate technical and organisational measures to protect your personal data against loss, unauthorised access and unlawful processing. Examples include encrypted connections (TLS), access management and logging. Lyanthe is preparing for ISO 27001 certification. We contractually require our service providers to maintain a comparable level of security.

8. Your rights

For the processing for which Lyanthe is the controller, you have the following rights:

  • Access: request a copy of the personal data we process about you.
  • Rectification: have incorrect data corrected.
  • Erasure: have your data deleted.
  • Restriction: have the processing restricted.
  • Portability: receive your data, or have it transferred, in a structured, commonly used and machine-readable format.
  • Objection: object to processing based on legitimate interest, including use as Training Data, and to direct marketing.
  • Withdrawal of consent: you can withdraw any consent you have given at any time. This does not affect processing carried out before the withdrawal.

In some cases, these rights are subject to statutory exceptions or restrictions. If so, we will explain to you which ones apply and why.

You can send your request to contact@lyanthe.com. We will respond within one month. For complex or numerous requests, this period may be extended by two months; if so, we will let you know within the first month. For data we process as a processor, please refer to chapter 3.

You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens): autoriteitpersoonsgegevens.nl.

9. Changes

We may amend this privacy statement if new developments give reason to do so. The most recent version is always available on lyanthe.com. We will actively inform you of any material changes.

Last updated: October 2026, Echt.