Scryn Privacy Policy
Last updated: 4 August 2026
1. Who we are
This Privacy Policy explains how Scryn S.à r.l. ("Scryn", "we", "us", or "our") collects and processes personal data when you visit our website, use our software-as-a-service platform or otherwise interact with us. Scryn S.à r.l. is a private limited liability company (société à responsabilité limitée) established in Luxembourg and is generally the controller of personal data described in this Privacy Policy, except where we act as a processor on behalf of our customers.
Controller details (EU establishment)
Scryn S.à r.l.
9, avenue des Hauts Fourneaux
L-4362 Esch-sur-Alzette
Luxembourg
Email: privacy@scryn.co
If you are a customer and Scryn processes personal data on your instructions within the Scryn platform (for example, if you upload your own datasets or contact lists), you remain the controller of that personal data and Scryn acts as your processor under the applicable data processing agreement.
If required by law, we will publish the contact details of our Data Protection Officer (DPO) and communicate them to the Luxembourg National Data Protection Commission (Commission Nationale pour la Protection des Données, "CNPD").
2. Territorial scope
This Privacy Policy applies to personal data processed by Scryn in the following contexts:
- Users and visitors in the European Union, European Economic Area, the United Kingdom and Switzerland.
- Other individuals whose personal data is processed by Scryn in the context of Scryn's activities in the EU, including when Scryn targets or offers services to organisations in the EU.
Additional information for individuals in the EU/EEA and UK, including our legal bases for processing and your rights, is provided in Section 9.
3. What personal data we collect
Depending on how you interact with us, we may collect and process the following categories of personal data:
- Identity data: Name, professional title, role and company name.
- Contact data: Business email address, business telephone number and business mailing or billing address.
- Account data: Login credentials, user settings and account preferences (for example, language or notification choices).
- Transaction and billing data: Subscription details, billing records and limited payment-related information (payment card data is typically processed directly by our payment providers).
- Technical and usage data: IP address, browser type, device identifiers, operating system, pages viewed, login timestamps, session duration and similar log information.
- Marketing and communication preferences: Information about your preferences for receiving communications from us (for example, whether you have opted in or opted out of certain communications).
The Scryn platform is focused on company-level and professionally oriented information. Where we process professional contact data, Scryn may enrich such data using reputable third-party sources and public records (such as professional networking services or business registries) to maintain accuracy and relevance. Any enrichment is limited to professionally focused attributes (such as role, title, employer, publicly available professional activity or business contact details) and does not involve inferring private, sensitive or non-professional characteristics.
We do not intentionally collect "special categories" of personal data within the meaning of Article 9 GDPR (for example, health information, political opinions, religious beliefs or similar sensitive data), nor do we intentionally collect data relating to criminal convictions and offences. We do not knowingly collect information from individuals under 18.
4. How we collect personal data
We collect personal data through the following channels:
- Directly from you: When you create an account, request a demo, fill out forms, correspond with us (for example, by email or support tickets), or participate in calls or meetings with our teams.
- Automatically: When you use the website or Service, we collect certain technical and usage data via cookies and similar technologies, as described in Section 8.
- From third parties: We receive data from service providers and partners (for example, payment processors, hosting providers, customer support tools and analytics providers) and, for sales and business development activities, from business contact providers or public sources where permitted by law. For our customers' use of the contact information feature, we may retrieve professional contact details (such as name, role, business email and phone) from specialised third-party data providers on the customer's instructions and solely for that customer's use.
If you provide us with personal data about someone else (for example, a colleague), you should ensure that you are authorised to do so and that the individual is aware of how we will use their information in accordance with this Privacy Policy.
5. How we use personal data and legal bases
We use personal data for the purposes and on the legal bases set out below.
5.1 Providing and operating the Service
- Managing user accounts, providing customer support and operating the platform (including automated analysis of professionally focused data to support company discovery, classification and prioritisation within the Service).
- Legal basis: Performance of a contract (Article 6(1)(b) GDPR) and, where relevant, our legitimate interests in operating and improving the Service (Article 6(1)(f) GDPR).
5.2 Sales and business development
- Performing B2B sales and business development activities, including contacting prospective business customers using professional contact details, and maintaining our CRM.
- Legal basis: Our legitimate interests in promoting and growing our business (Article 6(1)(f) GDPR), subject to applicable rules on direct marketing.
5.3 Billing and financial administration
- Processing payments, managing subscriptions, issuing invoices and maintaining accounting records.
- Legal basis: Performance of a contract (Article 6(1)(b) GDPR) and compliance with legal obligations (Article 6(1)(c) GDPR), such as tax and accounting obligations.
5.4 Security, fraud prevention and service quality
- Maintaining and improving the security, performance and functionality of our website and Service, preventing misuse, fraud or security incidents and ensuring service quality.
- Legal basis: Our legitimate interests in ensuring the security and proper functioning of our systems (Article 6(1)(f) GDPR) and, where applicable, legal obligations (Article 6(1)(c) GDPR).
5.5 Communications and support
- Communicating with you about the Service, including operational messages, product updates, security alerts, support responses and, where permitted, marketing communications.
- Legal basis: Performance of a contract (Article 6(1)(b) GDPR) for service-related communications and our legitimate interests (Article 6(1)(f) GDPR) or your consent (Article 6(1)(a) GDPR) for certain marketing communications, depending on local law.
5.6 Analytics and product improvement
- Analysing usage patterns in an aggregated or de-identified form to help improve our products and services, develop new features and understand how the Service is used.
- Legal basis: Our legitimate interests in improving and developing our services (Article 6(1)(f) GDPR).
5.7 Compliance and enforcement
- Complying with applicable laws and regulations, responding to lawful requests or orders, and enforcing our agreements and protecting our rights, property or safety.
- Legal basis: Compliance with legal obligations (Article 6(1)(c) GDPR) and our legitimate interests in establishing, exercising or defending legal claims (Article 6(1)(f) GDPR).
We do not sell personal data and we do not use personal data for cross-context behavioural advertising or similar targeted advertising.
Where we rely on legitimate interests, we have balanced those interests against the rights and freedoms of individuals and implemented appropriate safeguards, and individuals may object to such processing as described in Section 9.
Contact information feature
For our customers' use of the contact information feature, we retrieve professional contact details from specialised third-party data providers on the customer's instructions and solely for that customer's use. In this context, the customer remains the controller of the personal data and is responsible for determining the appropriate legal basis and for informing those individuals. Scryn acts as a processor for these contacts, which are not reused across clients or for Scryn's own purposes.
6. How we share personal data
We share personal data only as described below and only where we have a lawful basis and appropriate safeguards in place.
- Service providers (processors): We share data with trusted vendors and service providers who provide services such as hosting, infrastructure, security, customer support tools, communications, analytics and payment processing. These service providers may access personal data only to perform services on our behalf and are bound by contractual obligations, including data processing agreements, to protect personal data in accordance with GDPR.
- Customers and business clients: In limited cases, we may share professional contact details (such as name, role and business email) with customers in the context of corporate transactions (for example, where customers are evaluating potential counterparties or companies of interest) and only as necessary to support specific investment, M&A, company intelligence or business relationship activities. Such sharing is limited to professionally relevant information and takes place on the basis of legitimate interests, subject to applicable law and contractual safeguards.
- AI assistant connectors: If you connect a third-party AI assistant to your Scryn account (see Section 12), the company-intelligence results you retrieve are delivered to that assistant and processed on its provider's infrastructure under the provider's own terms. We share only what is necessary to fulfil the requests you make through the connector.
- Group entities: Where applicable, we may share data within the Scryn group of companies for internal administrative purposes, service provision and support, subject to intra-group agreements and appropriate safeguards for international transfers described in Section 7.
- Business transfers: We may disclose personal data in connection with a merger, acquisition, financing or sale of all or part of our business, in which case data will continue to be protected in line with this Privacy Policy or a substantially similar policy.
- Legal and compliance: We may disclose personal data to public authorities or other third parties if required to do so by law or where necessary to protect our rights, safety or property, or the rights, safety or property of others.
We do not share personal data with third parties for their own independent marketing or advertising purposes.
7. International data transfers
Although Scryn S.à r.l. is established in Luxembourg, our core technical infrastructure and certain service providers are located outside the EU/EEA, including in the United States. This means that personal data may be transferred to countries that may not provide the same level of data protection as the EU/EEA.
When we transfer personal data outside the EU/EEA, we ensure that appropriate safeguards are in place as required by Chapter V of the GDPR, such as:
- An adequacy decision by the European Commission (for example, the EU-US Data Privacy Framework for transfers to participating US organisations, where applicable).
- Standard Contractual Clauses (SCCs) adopted by the European Commission, including any necessary supplementary measures based on the nature of the transfer and the recipient's legal environment.
If we rely on the EU-US Data Privacy Framework for transfers to a self-certified US entity, we verify the recipient's certification status on the Data Privacy Framework list maintained by the US Department of Commerce. If the US recipient is not self-certified, we typically rely on SCCs and implement supplementary measures as appropriate.
Copies or information about the relevant transfer safeguards can be obtained by contacting us at privacy@scryn.co, taking into account confidentiality and trade secret restrictions.
8. Cookies and similar technologies
We use cookies and similar technologies to operate and improve our website and Service.
- Types of cookies: We may use cookies that are strictly necessary for the operation of the website or Service (for example, for authentication and session management), as well as functional or analytics cookies that help us understand how the website and Service are used and to support customer service.
- Third-party tools: Certain third-party tools integrated into the website or Service (such as support widgets, analytics tools or communication tools) may set cookies in accordance with their own privacy practices.
Where required by applicable law (for example, in Luxembourg and other EU Member States for non-essential cookies), we will collect your consent before using non-essential cookies. You can manage your cookie preferences through the cookie banner or settings on our website and through your browser settings. If you block or delete certain cookies, some features of the website or Service may not function properly.
9. Additional information for EU/EEA and UK users (GDPR)
Controller and processor roles
When Scryn collects personal data directly from individuals (for example, account data, billing data and sales contact data), Scryn acts as a controller. When we process personal data uploaded or otherwise provided by our customers via the Service, we generally act as a processor on behalf of those customers under the terms of our data processing agreement.
Automated processing and profiling
Scryn uses automated processing and profiling techniques within the Service to analyse and organise company-related and professionally focused information (for example, to classify companies, surface relevant opportunities or prioritise results based on professional criteria). This processing is limited to professional and business-related data and does not involve inferring sensitive personal characteristics or non-professional personal information. Scryn does not use automated decision-making that produces legal effects concerning individuals or similarly significantly affects them within the meaning of Article 22 GDPR.
Your GDPR rights
Subject to applicable law and certain limitations, you have the following rights regarding your personal data:
- Right of access: To obtain confirmation of whether we process your personal data and receive a copy of it.
- Right to rectification: To have inaccurate or incomplete personal data corrected.
- Right to erasure: To request deletion of your personal data in certain circumstances (for example, where it is no longer necessary for the purposes for which it was collected or where you withdraw consent and no other legal basis applies). Where we act as processor, we will delete data as instructed by the controller, while retaining anonymised suppression records to prevent re-addition.
- Right to restriction: To request that we restrict the processing of your personal data in certain circumstances (for example, while we verify accuracy or respond to an objection).
- Right to data portability: To receive certain personal data you have provided to us in a structured, commonly used and machine-readable format and to transmit that data to another controller where technically feasible.
- Right to object: To object at any time, on grounds relating to your particular situation, to processing of your personal data that we carry out based on our legitimate interests, including profiling. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms or where processing is necessary for legal claims.
- Right to object to direct marketing: You may object at any time to the processing of your personal data for direct marketing purposes, including any related profiling, in which case we will stop processing for that purpose.
- Right to withdraw consent: Where we rely on your consent as a legal basis for processing, you may withdraw your consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal.
To exercise these rights, please contact us at privacy@scryn.co. We may need to verify your identity before responding to your request.
You also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work or place of the alleged infringement. For Luxembourg, the competent authority is the CNPD (Commission Nationale pour la Protection des Données).
10. Data retention and security
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide and support the Service, comply with legal obligations, resolve disputes and enforce agreements. Retention periods may vary depending on the category of data and the purposes for which it is processed (for example, billing records are kept for the duration required by tax and accounting laws).
We implement appropriate technical and organisational measures designed to protect personal data, including access controls, encryption in transit and logging and monitoring of our infrastructure. While we endeavour to protect personal data, no security measure is perfect or impenetrable, and we cannot guarantee absolute security.
11. Your choices
You can manage certain account-level settings directly within the Service, including updating your profile information and managing some notification preferences. You may opt out of marketing emails at any time by using the unsubscribe link included in our messages or by contacting us at privacy@scryn.co. Even if you opt out of marketing communications, we may still send you non-marketing messages relating to your account or the provision of the Service (for example, security or transactional emails).
12. AI assistant connectors (Model Context Protocol)
Scryn offers connectors that let you use the Service from third-party AI assistants (for example, Claude) via the Model Context Protocol ("MCP"). If you choose to connect an AI assistant to your Scryn account:
- Authorisation. You connect through a secure OAuth authorisation flow. We store the access and refresh tokens needed to link the AI assistant to your account, and you can revoke this access at any time from your account settings or from the AI assistant.
- Requests and responses. The AI assistant sends the queries and parameters needed to run Scryn tools on your behalf, and Scryn returns company-intelligence results to that assistant. These requests are processed in the same way as actions you perform directly in the Service and are associated with your account.
- Processing by the AI assistant provider. Once results are delivered to the AI assistant, the company records and other information you retrieve flow into that assistant's conversation context and are processed on the infrastructure of the assistant's provider (for example, Anthropic or OpenAI) under that provider's own privacy policy and retention practices. Scryn does not control how the provider processes or retains that information, and we encourage you to review the privacy policy of any AI assistant you connect.
- Legal basis. Where this processing involves personal data, we rely on the performance of our contract with you (Article 6(1)(b) GDPR) to operate the connector at your request and, where relevant, our legitimate interests in providing and securing the Service (Article 6(1)(f) GDPR).
We do not use the content of your searches, connector requests or retrieved results to train third-party foundation models.
13. Contact us
If you have questions, concerns or requests regarding this Privacy Policy or our processing of personal data, you can contact us at:
Scryn S.à r.l.
9, avenue des Hauts-Fourneaux
L-4362 Esch-sur-Alzette
Luxembourg
Email: privacy@scryn.co
If you are not satisfied with our response, you may also contact your local data protection authority or, in Luxembourg, the CNPD.