CUSTOMER PRIVACY NOTICE

Privacy notice for the Laghmari customer service.

Effective 2026-07-27

Controller and verified contacts

yzn entertainment AB (5590834981), Örbrinken 10, 143 32 Huddinge, Sweden, is the controller for this service. Privacy and data-rights requests: privacy@laghmari.com. General support: support@laghmari.com.

Customer product scope and data

The public Audit processes an Auth account and membership, the structured identity and profile signals you voluntarily enter, your authority attestation and research mandate, public-source possible matches and provenance, your review decisions, structured data-rights requests, bounded operational status records, the validated evidence ledger, readable report, and merchant-of-record transaction references. This release does not connect Google, Facebook, or other external accounts.

No external account authorization: Laghmari does not ask for another service's password, OAuth approval, private account data, or browsing history in this release. Do not add another person's signals unless you hold and attest current authority to direct the case for that person.

Connected accounts

Connected accounts are not offered in this release. Google, Facebook, Instagram, Microsoft, and other external OAuth providers remain disabled, and Laghmari stores no access or refresh credential for them.

Purpose and legal basis

The product uses the minimized data to authenticate the verified account, secure and operate its dossier, research bounded public sources, present possible matches for human review, produce the validated evidence ledger and readable report, answer rights requests, prevent abuse, and maintain necessary security evidence.

Contract performance for requested services; consent where required for special-category data; legitimate interests and legal obligations where applicable.

Providers and transfers

Approved processors are used only for the described service; international transfers rely on applicable safeguards and are described in the Privacy Notice.

The reviewed architecture uses Vercel for the application, Supabase for Auth and durable data, AWS for managed keys, queues, the worker and a content-free review-ready notice, and only separately approved public research providers. External connected-account providers are not part of this release. Stripe/Link acts as merchant of record for the public Audit transaction and processes checkout, payment, applicable indirect tax, and transaction records under its own applicable notices and terms. Brave and each OpenAI capability remain independently gated and may process only the bounded data described by the exact approved provider, transfer, retention, mandate and release configuration. Raw bulk result sets, prompts and model responses are not customer records.

Human review and no external action

Search results are possible matches, not asserted facts. You review and classify them. The public Audit produces research and reporting only. Resolve remains invite only, Monitoring is unavailable, and no legal request or other external action is sent in this release. It makes no automated decision with legal or similarly significant effect.

Retention and deletion

Customer case data is retained for up to 365 days from case creation, subject to legal holds, active requests and verified deletion workflows.

The source-enforced customer-case deadline is exactly 365 days from case creation. Expiry never bypasses closure, open-rights-request, queue, notification, or legal-hold checks; an operator can purge only through the guarded, receipted path.

Your rights

Subject to applicable law, you may request access, rectification, erasure, restriction, objection and portability, withdraw a mandate for future research, and complain to the Swedish Authority for Privacy Protection (IMY). Use privacy@laghmari.com or the structured in-product data-rights surface. Identity verification may be required before fulfilment.

Back to Laghmari