1. Controller and contact
THINKBUD LTD, trading as LYNR, is the controller for the personal data described in this notice. THINKBUD LTD is a private limited company registered in England and Wales under company number 17013341, registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
Privacy and data-protection enquiries: privacy@getlynr.com. Unless LYNR separately confirms a formal appointment, use of a data-protection contact address does not mean LYNR has appointed a statutory data protection officer.
2. Personal data we may process
- Identity, contact, account and authentication information.
- Professional profile information, seniority, experience, expertise, methods, tools, industries, regions, languages and work preferences.
- Application, reviewer, decision, membership and bench-readiness information.
- For partner organisations, organisation identity, business contacts, accountable leads, team information, delivery model, subcontractor information, security/insurance information and capability claims.
- Project examples, portfolio evidence, uploaded-file metadata and files that you choose and are entitled to provide.
- Availability, capacity, geography, rates/commercial preferences and delivery preferences where supplied.
- AI capability claims, tools/platform experience, production evidence, governance experience and LYNR verification status where relevant.
- Legal-document versions, acknowledgements, acceptances, withdrawals and optional community/content-consent records.
- Private opportunity, matching, response, conflict and project-participation records if you later participate in a client workstream.
- Opportunity invitation records: the opportunities you were invited to, the match status held against you, the fit rationale shown to you, and invitation/response timestamps.
- Your response to an invitation, including the response type and any note you write.
- The existing project records and evidence references, and the expertise/capability references, you choose to select when responding to an invitation.
- The profile, capability, evidence and availability information LYNR uses to decide which members to invite, together with related engagement and response history.
- Technical, authentication, security, email-delivery and audit records required to operate, protect and investigate the service.
- Access, export, correction, restriction, objection, deactivation or erasure requests and the outcome of those requests.
3. Where Network information comes from
Most Network information comes directly from you or, for an organisation application, from the authorised organisation representative completing the application.
Where relevant to a genuine application, capability check or opportunity, LYNR may also obtain professional information from the organisation you represent, public business sources such as company websites or professional profiles, references or verification contacts you provide or authorise, and LYNR's own review, security, opportunity and service records. LYNR does not treat the existence of public information as permission to collect or use it for an unrelated purpose.
4. Why we process Network data
- To create, authenticate and secure an account and provide requested Network functions.
- To receive, save and review applications and evidence and make Network-admission decisions.
- To maintain an accurate private capability network and distinguish community membership from client-deployment readiness.
- To verify claims, references, AI evidence, delivery-team information and other material capability information where proportionate.
- To administer partner organisations, governance status, availability, data rights and member settings.
- To identify and privately assess potentially relevant capability for a genuine client problem, opportunity or Lynr engagement.
- To curate private opportunity invitations, manage invitations and responses, assess fit and progress a potential assignment.
- To keep governance, audit and security records of who was invited, what was shown and how each member responded.
- To operate audit, fraud/abuse-prevention, access-control, security, incident and service-reliability processes.
- To send transactional account, invitation, application, review, opportunity and other requested service communications.
- Where you separately opt in, to invite you to optional community, research, roundtable, content, podcast or similar activity.
- To comply with law and to establish, exercise or defend legal rights and claims.
5. Lawful bases
The lawful basis depends on the activity. LYNR may rely on steps taken at your request before entering a contract, performance of a contract, legitimate interests, legal obligations or consent.
Where legitimate interests are relied on, they may include operating a selective private professional network, assessing suitability and capability, protecting members/clients/service integrity, maintaining accurate business and audit records, and identifying appropriate capability for genuine client needs. LYNR considers necessity, reasonable expectations and impact on individuals before relying on legitimate interests.
Optional community/content contact is kept separate from required Network terms and service communications. Where consent is the basis, it can be withdrawn at any time without invalidating processing that was lawful before withdrawal.
6. Your right to object
Where LYNR relies on legitimate interests, you have the right to object to that processing. Tell LYNR what processing you object to and why it affects your particular situation. LYNR will stop the processing unless it can demonstrate a lawful reason to continue that overrides the objection, or the processing is needed to establish, exercise or defend legal claims.
You have an absolute right to object to direct marketing. Optional community/content consent can be switched off directly in Network settings or withdrawn by contacting privacy@getlynr.com.
7. Who can see Network information
Lynr Network is private by default and is not a public freelancer or partner directory. Authorised LYNR personnel and reviewers may access information where needed for their role.
Relevant information may be shown to a client or approved delivery participant only where there is a genuine workstream, the disclosure is appropriate to that purpose, and it is consistent with the selected visibility setting, these notices/terms or a project-specific agreement. Private evidence should not be disclosed more widely than necessary.
LYNR may also disclose information to professional advisers, insurers or public authorities where reasonably necessary or legally required.
8. Service providers
- Supabase — authentication, database, private storage and operational queue infrastructure.
- Resend — transactional/service email delivery and related delivery events.
- Cloudflare and deployment/hosting providers — network, security and application delivery.
- Lovable and related application-development/deployment services where used in operating getlynr.com.
- Optional analytics providers described in the Cookie & Storage Technologies Policy, only under the applicable consent model.
- Other processors or professional advisers where required for a defined operational, security, legal, accounting or insurance purpose.
9. Evidence, confidential material and third-party data
Do not submit credentials, access tokens, trade secrets, unnecessary special-category personal data, client-confidential information or other material you are not authorised to disclose. Redact evidence where disclosure rights are uncertain.
If you provide information about another person — for example a delivery-team member, reference or colleague — you are responsible for ensuring it is appropriate and lawful to provide that information to LYNR. LYNR may remove or quarantine material where there is a privacy, security, legal or permission concern.
Portfolio and evidence use is also governed by the Portfolio & Evidence Rules.
10. International transfers and security
Network members and providers may be located in different countries. Where a transfer is restricted by applicable UK data-protection law, LYNR uses or relies on an appropriate transfer mechanism and safeguards where required, such as an adequacy regulation, UK International Data Transfer Agreement, UK Addendum to EU Standard Contractual Clauses or another lawful mechanism.
You can contact privacy@getlynr.com for information about the mechanism used for a relevant transfer and, where applicable, a copy of the relevant safeguards, subject to lawful and necessary redactions.
LYNR applies proportionate access control, role separation, private storage, audit and service-security measures. No internet service can guarantee absolute security, so users should also protect credentials and avoid uploading information that is unnecessary for the Network purpose.
11. Retention
LYNR does not keep Network information indefinitely merely because it was once supplied. The retention period depends on the data category and why it is needed.
- Active account, application, membership and opportunity data is retained while needed to operate the relevant relationship or requested function.
- Unsuccessful, withdrawn, inactive or closed records are deleted, anonymised or reduced when the review/relationship and reasonable legal/security needs have ended.
- Audit, fraud/security, contractual, accounting/tax, insurance and legal-claim records may be retained longer where required or reasonably necessary.
- A minimal suppression/objection record may be retained so LYNR can continue to honour a marketing objection or opt-out.
- Private files are removed when the account/evidence is deleted unless a specific lawful reason requires preservation; active-member evidence is not retained merely for speculative future use after its purpose ends.
LYNR maintains an internal retention schedule and periodically reviews whether each category remains necessary.
12. AI, matching, profiling and human judgement
LYNR may use software, analytics or AI-assisted tools to organise information, support research, summarise evidence, search capabilities, suggest potential matches or improve administrative workflows. AI assistance does not itself determine that a person is credible, bench-ready or suitable for a client assignment.
Material Network admission, bench-readiness and client-selection decisions are subject to meaningful human judgement. LYNR does not intentionally use a public generative-AI service as an unrestricted destination for confidential member, applicant or client information.
If LYNR proposes a new profiling or automated-decision process that could create high risk or a legal/similarly significant effect, LYNR will assess the lawful basis, transparency, human-intervention/challenge safeguards and data-protection impact requirements before deployment.
13. Your rights and permanent account deletion
Subject to applicable law and the circumstances, you may have rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent where consent is relied on. These rights are not all absolute.
You can use available Network/account controls or contact privacy@getlynr.com. Where LYNR has reasonable doubts about identity, it may request proportionate verification. LYNR normally responds within one month, subject to any lawful extension or exception.
Eligible non-admin users can permanently delete their Lynr account through the account controls. This closes the login and removes account-linked profile/application/member data and private files that no longer have a lawful retention purpose. LYNR may retain only the minimum information required or permitted for legal obligations, contracts, tax/accounting, fraud/security, regulatory matters, legal claims or continuing suppression of a marketing objection. Retained records are not kept as an active member profile.
Reviewer/administrator identities require controlled offboarding before account deletion so operational ownership, security and audit responsibilities are not accidentally orphaned.
14. Complaints
Privacy complaints can be sent to privacy@getlynr.com. You may also complain to the Information Commissioner's Office in the UK or another competent supervisory authority where applicable.
15. Changes
LYNR may update this notice as the Network, law or processing changes. Material changes are reflected in the version/date. Where the product records acknowledgement or re-acceptance for a revised legal document, the live application/account flow will request it before the relevant continuing participation.