Your assets stay yours.
Brand material passes through Leyrs on its way to being checked, so keeping it confidential, intact and in the right jurisdiction is a core part of our product.
How your data is protected
Encrypted end to end
AES-256 on every S3 bucket and on the Postgres database at rest. TLS 1.2+ enforced on every connection in transit.
Isolated per customer
Every asset is tenant-scoped, and Postgres Row Level Security enforces it at the database, not just in the application.
Access controlled
Role-based access throughout. Only authorised Leyrs personnel who need it for operating or supporting the platform can reach customer data.
Audit logged
Every access to customer data is logged with timestamp, identity and action type.
Model Training
Custom vision models are fine-tuned per customer to assure a deterministic review system. We do not train or fine-tune any model serving another customer on your data.
Where your data lives
Every customer asset, meaning brand files, design material and model artifacts, is stored in the European Union, in AWS eu-north-1 (Stockholm). AI processing runs in the EU by default. Where a model we need is not yet available in an EU region, that processing may run in the United States under Standard Contractual Clauses. Operational data such as accounts, audit logs and review history may be processed in the EU or the US. Leyrs is operated by Ampfer AB, a company registered in Sweden.
Infrastructure and sub-processors
Amazon Web Services
Cloud infrastructure, S3 storage, database hosting and AI model inference, including Amazon Bedrock. EU by default; US where model availability requires it, under Standard Contractual Clauses. Covered by the AWS DPA.
Google Cloud
AI model inference and related cloud AI services, including Vertex AI. EU by default; US where model availability requires it, under Standard Contractual Clauses. Covered by the Google Cloud DPA.
Microsoft Azure
AI model inference and related cloud AI services, including Azure AI. EU by default; US where model availability requires it, under Standard Contractual Clauses. Covered by the Microsoft Azure DPA.
What we commit to
Compliance
We process personal data as your processor, on your documented instructions only, under GDPR Article 28. We do not decide the purposes of processing.
Incident response
If a breach or security incident affects your data, we notify you within 72 hours of becoming aware of it, per GDPR Article 33. You hear it from us.
Retention and deletion
Your data is kept for the life of the agreement. You can ask us to delete specific data at any time, and on termination everything is deleted or returned within 30 days, as you instruct.
Data subject rights
We help you answer access, rectification, erasure and portability requests within 30 days.
Personnel access
Access is limited to the people who need it to operate, maintain and support the platform, governed by role-based controls and covered by audit logging.
Channel monitoring
We only collect from the channels you designate, on explicit per-request authorisation. We do not select, suggest or supplement them, and collected assets stay inside your isolated storage.