Lyso
Privacy notice
Last updated: 31 August 2026
Lyso is a personal organisation service operated by Aspris Media Ltd. This notice explains how we use personal information when you visit the Lyso website, create or join a workspace, use Lyso features, receive a task message, or contact us.
Who we are
Aspris Media LtdCompany number 16271290Registered in England and WalesRegistered office: 22 Battle Rise, Heybridge, CM9 4PF, UKContact us about privacy at assist@lyso.app.
Our role and your workspace
Aspris Media Ltd is the controller for account administration, service security, support, operational communications and product operation. You decide what personal information to put in your own tasks, Notes and workspace. If you add information about another person or ask Lyso to contact them, you are responsible for having an appropriate reason to do so and for sharing only what is necessary.
Information we use
- Account and workspace information: email address, password hash, account status, workspace ownership or membership, preferences and regional settings.
- Your content: tasks, Notes, checklists, dates, recurrence, reminders, links and any files or diagrams available under your plan.
- People and communications: names and email addresses you choose to add, Waiting reminders, delivery status, external task discussions and suppression choices.
- Technical and operational information: session and security records, network and device indicators, route and feature events, error information, notification delivery and storage usage.
- Support information: messages you send us and the records needed to investigate and resolve your request.
Where information comes from
Most information comes directly from you. We may also receive information from another Lyso user who invites you or adds you as a person, from an external recipient who replies to a task discussion, from your browser or device, and from service providers that report delivery, security or technical events.
Why we use it and our lawful bases
- Contract: to create your account, provide the workspace and features you request, deliver service messages and support your use of Lyso.
- Legitimate interests: to secure Lyso, prevent fraud and abuse, diagnose faults, manage capacity, understand aggregate product use, improve the service and defend legal claims. We assess necessity and the effect on people before relying on this basis.
- Legal obligation: to keep required company, tax, security or compliance records and respond to lawful requests.
- Consent: where a device permission or optional processing specifically requires it. You can withdraw that permission through the relevant device or product control.
Service operation and improvement
We process limited account, device, network, service-usage and communications-delivery metadata to operate and secure the service, prevent abuse, investigate faults, manage capacity and understand how the product is used. We do not use this information for behavioural advertising or personalised promotion, and product reporting is presented as statistical trends rather than individual marketing profiles.
This operational telemetry does not include task or Note text, message content, contact or recipient details, project information, filenames or uploaded content. Access is restricted, retention follows documented operational and security criteria, and relevant records may be preserved for longer when an incident, complaint or legal obligation requires it.
Who receives information
We do not sell personal information and do not use it for behavioural advertising. We use contracted providers for hosting and infrastructure, email delivery, storage, backups, monitoring and support. We may also disclose information to professional advisers, regulators, courts, law enforcement or another party where the law requires or permits it. Providers may use information only to supply and protect the relevant service.
International transfers
Some providers may operate from or allow authorised support access outside the UK. Before making a restricted transfer, we identify the receiving organisation and use an applicable UK adequacy regulation, approved contractual safeguards or another lawful transfer mechanism. Contact us if you need information about the safeguard used for a particular transfer.
Waiting-task reminders
A workspace user can ask LYSO to send a one-off operational reminder when a task is still waiting for someone. The message identifies the person who requested it, shows the task name and any details they chose to include, and directs replies to that person.
To deliver and audit the reminder, we process the recipient's name and email address, the supplied task information, the requesting user's identity and reply address, and delivery status and timestamps. The workspace user is responsible for choosing an appropriate recipient and task content.
Each reminder includes a link that lets the recipient stop further automatic reminders from that requester. Completing the task, clearing Waiting or disabling the follow-up also cancels an unsent reminder. These operational messages contain no advertising or tracking pixels.
Reminder records are retained for service operation, security, support and audit purposes in line with the wider retention approach in this notice. For a correction or privacy request, reply to the requester or use the privacy contact route for this service.
External task discussions
If the requester enables replies, the reminder contains a private, time-limited link to a page for that task. The recipient can post text updates without creating an account. They are a limited external participant in that discussion, not a workspace member, and the link does not give access to other tasks or workspace content.
The page shows the requester, recipient, task name and discussion messages. Task details and a due date are shown only when the requester explicitly chooses to share them. We process the discussion content, access and message timestamps, and a protected representation of the source network address for rate-limiting, security, abuse response and audit.
The private link expires, can be revoked, is bound to the product and recipient, and stops working when the discussion is closed, the task is completed, or Waiting is cleared. Anyone who receives or is forwarded the link may be able to use it until then, so recipients should not forward it or include sensitive information.
A recipient can stop only the current conversation, all task messages from that workspace, or all task messages from this product to their email address. Stopping messages is separate from reporting a concern. We retain the minimum suppression information needed to honour the chosen scope and prevent blocked messages from being queued or sent.
The workspace operator normally determines the purpose and content of the task discussion. Aspris Media Ltd provides and secures the service and may separately determine limited processing needed for fraud prevention, abuse handling, security logs and legal compliance. A recipient can ask the requester to correct or remove discussion content and can report a concern to the service operator.
How long we keep information
- Workspace content is kept while the workspace remains active and until it is deleted by an authorised user or through account closure, subject to limited backup recovery periods and legal holds.
- Ordinary structured operational telemetry is retained for up to 13 months. Records needed for an active security incident, complaint or legal claim may be held longer under a documented hold.
- Authentication-delivery records are ordinarily removed after 30 days.
- Closed external task-discussion content is ordinarily retained for up to 12 months; associated security metadata for up to 90 days; and resolved concern reports for up to 24 months.
- Transactional, support, suppression and legal records are retained for as long as needed for the service request, to honour the suppression, or to meet legal and accountability requirements.
Your rights
Depending on the circumstances, you may have rights to access, correct, erase, restrict or receive your personal information, and to object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it. Some rights have legal limits, and we may need to verify your identity.
Your right to object: you can object to processing based on our legitimate interests. Tell us what you object to and why; we will stop unless we can demonstrate compelling legitimate grounds or need the information for legal claims.
To exercise a right, email assist@lyso.app. If another Lyso user added your information, you can also contact that person directly.
You can complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint, by telephone on 0303 123 1113, or by post at Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
Cookies and browser storage
Lyso uses essential session cookies and browser storage for sign-in, security, product identity, preferences, offline capability and app state. These are necessary to provide the service you request. We do not use advertising cookies or session replay. If we introduce non-essential browser storage, we will explain it and request consent before using it where required.
Automated decisions
Lyso does not make solely automated decisions that produce legal or similarly significant effects. Automated security controls may delay or block suspicious login, signup or messaging activity. Contact us if you believe a control has affected you incorrectly.
Security
We use measures including password hashing, access controls, product and workspace separation, rate limits, restricted administrative access, audit records, backups and encrypted transport. No online service can guarantee absolute security, so keep your password and private links safe and avoid storing information you do not need.
Changes to this notice
We will update the date above when this notice changes. If a change materially affects how we use your information, we will provide a prominent notice or contact account holders where appropriate.