Legal
Privacy Policy
WYLO Privacy Policy Lawful basis for processing: - Legitimate interests (employer use of WYLO Sync / Momentum / Command) - Consent (individual use of WYLO Spark / Focus Web / Focus) Data we collect: - Account: name, email, role, organisation domain - Derived behavioural signals: cursor velocity score, keystroke cadence score, app/website focus events (priority rank only), FACE event metadata - Hashed URLs (one-way, never readable) - Audit logs of administrative actions Data we do NOT collect: - Raw keystroke content - Readable URLs - Screen captures or recordings (the "Coming Soon: Screen Replay" toggle is non-active at launch) - Personal communications Data subject rights (GDPR Articles 15–22): - Access, rectify, export and delete your data from within Settings - Deletion requests fulfilled within 24 hours by S-Tier Data Protection Officer: - dpo@usewylo.com (to be staffed prior to public launch) International transfers: - WYLO data is stored within the EU (Ireland or EU-based cloud region). EU AI Act transparency: - AI features are clearly labelled. You may opt out of behavioural AI modelling without losing access to the base product. Retention: - Individual: duration of account + 30 days post-deletion - Enterprise workspace: duration of contract + 30 days post-cancellation