Your assets stay yours.

Brand material passes through Leyrs on its way to being checked, so keeping it confidential, intact and in the right jurisdiction is a core part of our product.

How your data is protected

  • Encrypted end to end

    AES-256 on every S3 bucket and on the Postgres database at rest. TLS 1.2+ enforced on every connection in transit.

  • Isolated per customer

    Every asset is tenant-scoped, and Postgres Row Level Security enforces it at the database, not just in the application.

  • Access controlled

    Role-based access throughout. Only authorised Leyrs personnel who need it for operating or supporting the platform can reach customer data.

  • Audit logged

    Every access to customer data is logged with timestamp, identity and action type.

  • Model Training

    Custom vision models are fine-tuned per customer to assure a deterministic review system. We do not train or fine-tune any model serving another customer on your data.

Where your data lives

Every customer asset, meaning brand files, design material and model artifacts, is stored in the European Union, in AWS eu-north-1 (Stockholm). AI processing runs in the EU by default. Where a model we need is not yet available in an EU region, that processing may run in the United States under Standard Contractual Clauses. Operational data such as accounts, audit logs and review history may be processed in the EU or the US. Leyrs is operated by Ampfer AB, a company registered in Sweden.

Infrastructure and sub-processors

  • Amazon Web Services

    Cloud infrastructure, S3 storage, database hosting and AI model inference, including Amazon Bedrock. EU by default; US where model availability requires it, under Standard Contractual Clauses. Covered by the AWS DPA.

  • Google Cloud

    AI model inference and related cloud AI services, including Vertex AI. EU by default; US where model availability requires it, under Standard Contractual Clauses. Covered by the Google Cloud DPA.

  • Microsoft Azure

    AI model inference and related cloud AI services, including Azure AI. EU by default; US where model availability requires it, under Standard Contractual Clauses. Covered by the Microsoft Azure DPA.

What we commit to

  • Compliance

    We process personal data as your processor, on your documented instructions only, under GDPR Article 28. We do not decide the purposes of processing.

  • Incident response

    If a breach or security incident affects your data, we notify you within 72 hours of becoming aware of it, per GDPR Article 33. You hear it from us.

  • Retention and deletion

    Your data is kept for the life of the agreement. You can ask us to delete specific data at any time, and on termination everything is deleted or returned within 30 days, as you instruct.

  • Data subject rights

    We help you answer access, rectification, erasure and portability requests within 30 days.

  • Personnel access

    Access is limited to the people who need it to operate, maintain and support the platform, governed by role-based controls and covered by audit logging.

  • Channel monitoring

    We only collect from the channels you designate, on explicit per-request authorisation. We do not select, suggest or supplement them, and collected assets stay inside your isolated storage.