Privacy Policy

Last updated: March 19, 2026

1. Controller and Contact

The controller for data processing under the Swiss Federal Act on Data Protection (nFADP) and the EU General Data Protection Regulation (GDPR) is:

wyrd.io AG, Zwinglistrasse 3, 9000 St. Gallen, Switzerland

If you have any questions about data protection or wish to exercise your rights, you can contact us at: legal@wyrd.io

2. Roles and Responsibilities (B2B / Corporate Users)

If you use the platform through your employer, the processing of your data is primarily carried out on behalf of your employer. In this case, your employer is the data controller, and we act as a data processor.

3. Use of Our Website

When you visit our website (without logging in), we process technical data such as your IP address, date and time of access, and information about your browser to ensure the stability and security of the website.

To analyze usage and improve our website, we use a self-hosted analytics tool (Rybbit).

We also use HubSpot to analyze user behavior and support our marketing and sales activities (e.g. prospect tracking), provided you have consented to the use of such technologies.

For more information on the use of cookies and similar technologies, please refer to our Cookie Policy.

4. Legal Bases for Processing (GDPR)

We process personal data based on Art. 6 GDPR, in particular:

  • Performance of a contract: to provide the platform and its features
  • Legitimate interests: to ensure system security and optimize the platform
  • Consent: for sending our newsletter (can be withdrawn at any time)
  • Legal obligations: to comply with applicable laws and regulations

5. Collection and Processing of Personal Data

We process data that is necessary for the use of the platform:

  • Account data: name, email address, role, team affiliation, profile picture
  • Content data: responses from assessments, feedback inputs, notes from employee conversations, goals
  • Technical data: IP address, date/time of access, browser type

Technical data is processed via a self-hosted analytics tool (Rybbit) for error analysis and to ensure the stability and performance of the platform.

6. Use of Cookies and Local Storage

We use technically necessary cookies and similar technologies (e.g. local storage) to provide the core functionality of the platform, in particular to manage login sessions and ensure session security.

Processing is based on Art. 6(1)(b) and (f) GDPR. The platform cannot be used without these technologies.

7. Use of Artificial Intelligence (OpenAI)

We use AI models provided by OpenAI via API to support platform functionality, in particular:

  • analysis of feedback and user-generated content
  • assistance in drafting and formulating text content

This may involve processing content data that you actively enter into the platform. Before transmission, such data is reduced or pseudonymized where possible.

According to our agreement with OpenAI, the transmitted data is not used for training or improving their models.

8. Data Sharing with Processors

To provide the platform, we work with carefully selected service providers who process data on our behalf and according to our instructions. These include in particular:

  • Cloud infrastructure: AWS (Luxembourg; hosting in Germany), MongoDB Atlas (Ireland; hosting in Germany)
  • Hosting and deployment: Vercel (USA; hosting in Germany)
  • Communication: Resend (USA; hosting in Ireland), HubSpot (USA)
  • Monitoring and security: Better Stack (Czech Republic; hosting in the EU)
  • AI services: OpenAI (USA)

Some of these providers are based in or process data outside the EU/EEA, particularly in the United States. In such cases, we ensure an adequate level of data protection through appropriate safeguards, in particular standard contractual clauses of the European Commission and, where applicable, participation in the EU–US Data Privacy Framework.

9. Data Security

We implement appropriate technical and organizational measures to protect personal data, including:

  • encryption during transmission (TLS) and at rest (AES-256)
  • access controls and multi-factor authentication (MFA)
  • logical separation of customer data (multi-tenancy)

10. Your Rights and Complaints

You have the right to access, rectification, erasure, and data portability (JSONL export).

You also have the right to lodge a complaint with a supervisory authority (in Switzerland: the Federal Data Protection and Information Commissioner, FDPIC).