PRIVACY POLICY
Last updated: June 23, 2026
INTRODUCTION
This Privacy Policy for Lyssin Inc. (doing business as Blyndspot) ("Licensor," "we," "us," or "our"), a Delaware corporation authorized to do business in Oregon, describes how and why we collect, store, use, and process your information when you use our services ("Services"), including when you:
- Visit our website at https://blyndspot.com (including associated domains operated by Lyssin Inc. that redirect to this platform, such as https://lyssin.com, https://lyssin.app, and https://myvoyce.app).
- Download, install, and use our mobile applications, software development kits (SDKs), web platforms, or any software platforms that link to this Privacy Policy.
- Engage with us in other related ways, including system optimization, testing, customer support, or technical interactions.
Reading this Privacy Policy will help you understand your privacy rights and choices. If you do not agree with our policies and practices, you must immediately cease all use of our Services. Questions or concerns? Contact us at info@lyssin.com.
SUMMARY OF KEY POINTS
No Direct PII Collected: We do not collect, prompt for, or store direct real-world personal identifiers such as names, email addresses, phone numbers, or physical addresses.
System and Usage Tracing: We automatically process pseudonymous technical identifiers and interaction characteristics strictly for platform optimization, performance auditing, and service improvement.
No Data Monetization: We do not sell, rent, lease, or share your usage data with third-party advertisers or data brokers under any circumstances.
No AI Training: We do not use your data to train, fine-tune, test, or develop any artificial intelligence or machine learning system, and our analytics partners are contractually prohibited from doing so.
Data Processor Integration: We utilize dedicated analytics infrastructure (specifically PostHog) to process application interaction metrics under strict, protective Data Processing Agreements that forbid external data reuse or AI training.
TABLE OF CONTENTS
SECTION 1 - WHAT INFORMATION DO WE COLLECT AND PROCESS?
SECTION 2 - HOW DO WE PROCESS YOUR INFORMATION?
SECTION 3 - LEGAL BASES FOR PROCESSING
SECTION 4 - WHEN AND WITH WHOM DO WE SHARE YOUR INFORMATION?
SECTION 5 - COOKIES AND OTHER TRACKING TECHNOLOGIES
SECTION 6 - HOW LONG DO WE RETAIN YOUR INFORMATION?
SECTION 7 - HOW DO WE KEEP YOUR INFORMATION SAFE?
SECTION 8 - DO WE COLLECT INFORMATION FROM MINORS?
SECTION 9 - YOUR PRIVACY RIGHTS
SECTION 10 - CONTROLS FOR DO-NOT-TRACK FEATURES
SECTION 11 - UNITED STATES RESIDENTS - SPECIFIC PRIVACY RIGHTS
SECTION 12 - OTHER REGIONAL PRIVACY RIGHTS
SECTION 13 - UPDATES TO THIS POLICY
SECTION 14 - HOW TO CONTACT US
SECTION 15 - HOW TO REVIEW, UPDATE, OR DELETE YOUR DATA
SECTION 1 - WHAT INFORMATION DO WE COLLECT AND PROCESS?
1.1 - Information Voluntarily Disclosed by You
Our application architecture is specifically designed to operate without the collection of direct Personally Identifiable Information (PII). You do not register with a personal account, and we do not collect or store names, email addresses, or phone numbers. To configure and route your workspace experience, the system may process the following non-identifying operational parameters: job titles, roles, corporate departments, organizational structures, assigned work regions, or geographic business territories.
1.2 - Information Automatically Collected
Whenever you navigate or interact with our Services, our servers and third-party systems automatically capture standard electronic and performance data, including: Internet Protocol (IP) address (processed to determine generalized regional routing only), browser characteristics, device configurations, operating system version, system event logs, hardware settings, and timestamps of application use. This collection is necessary for system functionality.
1.3 - System-Wide Usage Telemetry
We perform monitoring of how you interact with our platform. This includes feature activation, menu navigation, clickstream data, scroll depth, session durations, interface modifications, and application paths utilized.
1.4 - Technical Pseudonymous Identifiers
We utilize persistent and non-persistent automated tokens, including cookie identifiers, random hardware-generated IDs, and system tokens designed to maintain secure user sessions, prevent system duplication, and compute aggregate analytics.
SECTION 2 - HOW DO WE PROCESS YOUR INFORMATION?
We process technical and system information collected through our Services for legitimate, protected business operations. We do not engage in profiling that produces legal or significant individual effects. Processing is restricted to:
2.1 - Platform Maintenance and Administration: Maintaining system uptime, monitoring software execution, diagnosing backend bugs, and deploying operational code updates.
2.2 - Product Optimization and Analytics: Reviewing aggregated system usage patterns, evaluating feature utilization, and engineering application upgrades tailored to specific corporate departments, divisions, or regions.
2.3 - Corporate and Infrastructure Security: Auditing system log data to detect, prevent, and mitigate cyber threats, malicious activities, software abuse, and fraudulent behaviors.
2.4 - Enforcement of Terms and Legal Defense: Protecting our intellectual property, fulfilling statutory requirements, and enforcing our enterprise agreements and Terms of Use.
SECTION 3 - LEGAL BASES FOR PROCESSING
3.1 - European Union (EEA) and United Kingdom
In compliance with the GDPR and UK GDPR, our processing of your technical data is legally justified under Legitimate Interests (Art. 6(1)(f) GDPR). Processing is essential to fulfill our legitimate interests in maintaining network safety, ensuring stable software performance, resolving technical defects, and continuously optimizing platform features.
3.2 - Canadian Regulations
To the extent applicable under PIPEDA and provincial frameworks, your technical data is processed under a baseline understanding of functional system usage, which you may configure or restrict via browser and operating system privacy controls.
SECTION 4 - WHEN AND WITH WHOM DO WE SHARE YOUR INFORMATION?
We do not sell, trade, barter, or commercially distribute your technical or system usage information to any third parties. Disclosures are limited to the following scenarios:
4.1 - Authorized Third-Party Service Providers
We share automated system metrics and device telemetry exclusively with trusted infrastructure partners and data processors (such as PostHog) who are contractually bound to handle data solely under our written directions and are prohibited from using it for any independent purpose, including AI model training.
4.2 - Corporate Restructuring and Business Transfers
We reserve the right to share or transfer compiled technical data, log histories, and system analytics in connection with any corporate merger, financing, acquisition, or sale of company assets, subject to the same confidentiality obligations applicable herein.
4.3 - Compulsory Legal Disclosures
We may disclose technical data where legally compelled by applicable law, binding regulatory demands, court orders, judicial subpoenas, or enforceable government requests.
SECTION 5 - COOKIES AND OTHER TRACKING TECHNOLOGIES
5.1 - General Tracking Infrastructure
Our platforms utilize first-party and third-party cookies, local storage scripts, web beacons, and embedded analytics tokens to ensure stable application environments and capture performance telemetry.
5.2 - PostHog Analytics Integration
We deploy PostHog (operated by PostHog, Inc.) as our primary product analytics engine to track application clickstreams, review interface events, and audit platform functionality. All technical data, IP processing, and interaction metrics transmitted via this pipeline are governed by a formal, legally binding Data Processing Agreement (DPA) executed between us and PostHog, Inc., in compliance with Art. 28 GDPR and applicable US state privacy regulations. PostHog acts strictly as a Data Processor on our behalf.
5.3 - AI and Machine Learning Safeguard
Pursuant to the explicit terms of our executed DPA, PostHog and all its underlying sub-processors are contractually prohibited from using, retaining, reviewing, or repurposing our system data to fine-tune, train, test, or develop any third-party artificial intelligence engines, machine learning tools, or Large Language Models (LLMs). For full details on PostHog's security controls, visit https://posthog.com/privacy.
SECTION 6 - HOW LONG DO WE RETAIN YOUR INFORMATION?
6.1 - Retention Schedules
We retain automated technical data, usage logs, and network identifiers only for the minimum duration required to achieve system optimization, security auditing, and product improvement. Analytical usage data and performance telemetry are purged, overwritten, or anonymized within a maximum window of three (3) months following the conclusion of active application sessions, except where an extended retention period is required to resolve an active infrastructure exploit, defend against a legal claim, or satisfy enforceable statutory obligations.
SECTION 7 - HOW DO WE KEEP YOUR INFORMATION SAFE?
7.1 - Security Measures
We have implemented reasonable and appropriate technical, structural, and organizational security measures designed to preserve the integrity of our systems and safeguard your data from unauthorized interception, modification, or exposure. Because our architecture bypasses the collection of direct personal credentials, names, financial data, and email addresses, the systemic risk of consumer identity theft on our platform is fundamentally reduced.
7.2 - Security Disclaimer
Despite our protective protocols, no electronic data transmission over the Internet or cloud storage configuration can be guaranteed as completely infallible. All transmissions of technical data to and from our Services are made at your own risk. You must only access our platforms within verified, secure, and protected network environments.
SECTION 8 - DO WE COLLECT INFORMATION FROM MINORS?
8.1 - Age Restrictions
Our platforms and enterprise services are designed strictly for professional, corporate use by adults. We do not knowingly solicit, process, or track information from children under eighteen (18) years of age. If we discover that any minor data has been automatically indexed, we will immediately isolate and permanently purge it from our systems.
SECTION 9 - YOUR PRIVACY RIGHTS
9.1 - Regional Frameworks
Depending on your jurisdiction (such as the European Economic Area, United Kingdom, Switzerland, and Canada), you may possess statutory rights regarding access to and erasure of your data.
9.2 - Identity Verification Requirement
Because our platform does not collect names, emails, or personal identifiers, we maintain no direct mechanism to link a specific real-world individual to any particular log entry or session token. To protect our systems and prevent malicious data phishing, we cannot fulfill data access, portability, or deletion requests unless you can provide the exact, verified system-generated token or technical device identifier matching the logs in question.
9.3 - International Data Transfers
Blyndspot utilizes secure server infrastructure deployed within the United States. To provide appropriate legal protection for cross-border data movements originating from the EEA, UK, or Switzerland, our data transmissions are protected by the European Commission's approved Standard Contractual Clauses (SCCs). All rights requests must be formally submitted to info@lyssin.com.
SECTION 10 - CONTROLS FOR DO-NOT-TRACK FEATURES
10.1 - Do-Not-Track Signals
Many web browsers feature built-in Do-Not-Track ("DNT") indicators. Because global technology bodies and legal frameworks have not established a uniform, binding standard for evaluating DNT signals, our platforms do not alter their automated tracking or data collection routines upon encountering a browser DNT indicator.
SECTION 11 - UNITED STATES RESIDENTS - SPECIFIC PRIVACY RIGHTS
11.1 - Categories of Information Collected
In accordance with applicable state frameworks, including the California Consumer Privacy Act (CCPA), we disclose that we collect the following categories of information:
Category A (Identifiers): Limited to IP addresses, unique network tokens, random cookie identifiers, and hardware tokens. No real names, emails, or physical addresses are collected.
Category F (Internet or Network Activity): Application clickstreams, interface interactions, user pathways, feature utilization, and scrolling behaviors.
Category G (Geolocation Data): Restricted to imprecise regional routing data computed from IP addresses only.
Category I (Professional or Employment-Related Information): User-declared corporate job titles, professional roles, departments, and corporate regions.
11.2 - Categories Not Collected
We do not collect or process Category B (Personal Information under CA Customer Records), Category C (Protected Classifications), Category D (Commercial Information), Category E (Biometric Information), Category H (Audio/Sensory Information), Category J (Education Information), Category K (Inferences), or Category L (Sensitive Personal Information).
11.3 - No Sale or Sharing of Data
We have never sold, shared, rented, or leased any data category collected through our Services to third-party ad networks, data brokers, or marketing entities, nor will we ever do so. We do not participate in cross-context behavioral advertising. To request deletion of your technical footprint, contact info@lyssin.com or visit blyndspot.com/contactus.
SECTION 12 - OTHER REGIONAL PRIVACY RIGHTS
12.1 - Australia and New Zealand
We manage automated network logs, system interaction telemetry, and structural workplace parameters in alignment with the Australian Privacy Act 1988 and the New Zealand Privacy Act 2020. You may contact our legal team to request structural telemetry audits or deletion, subject to the identity verification criteria defined in Section 9.
SECTION 13 - UPDATES TO THIS POLICY
13.1 - Revisions
We reserve the right to modify or amend this Privacy Policy at our sole discretion to maintain compliance with emerging laws, global regulatory frameworks, and changes in our product infrastructure. Any material modification will be indicated by an updated "Last updated" date at the top of this document. Your continued use of our platforms following an update constitutes your acceptance of the revised policy.
SECTION 14 - HOW TO CONTACT US
14.1 - Communication Channels
If you require clarification regarding our zero-PII usage tracing systems, or wish to appeal a denied data verification request, contact our legal compliance team at:
Lyssin Inc. PO Box 1362 Lake Grove, OR 97035 United States info@lyssin.com
SECTION 15 - HOW TO REVIEW, UPDATE, OR DELETE YOUR DATA
15.1 - Review and Deletion Rights
Based on the applicable laws of your country, province, or US state of residence, you may possess the right to request access to the technical logs we maintain, review how they are utilized, or request their permanent deletion.
15.2 - Verification Requirement
As specified in Section 9.2, because our Services operate without direct personal details, we have no structural method to connect a real-world user identity to our anonymous telemetry data. To safeguard platform privacy, we will not execute an access or deletion request unless you can provide the specific, verified device identifier or system session token matching our data logs. To initiate a request, visit blyndspot.com/contactus or email info@lyssin.com.