Privacy Policy
Pyyne LLC
Effective Date: June 11, 2026 | Version 1.1
1. Introduction
Pyyne LLC ("Pyyne," "we," "us," or "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you visit https://www.pyyne.com (the "Website"), interact with us as a client, prospect, partner, vendor, or job applicant, or otherwise engage with our business. For the processing described in this Policy, Pyyne LLC is the data controller (or the equivalent under applicable law), acting together with the Pyyne affiliates described in Section 6 where indicated.
Pyyne is a technology consulting and staff augmentation firm with operations in the United States, Sweden, Brazil, and other jurisdictions. This Policy applies globally and is supplemented, where applicable, by jurisdiction-specific notices below.
If you have questions about this Policy or our privacy practices, contact us at privacy@pyyne.com. We have designated a privacy contact to oversee our privacy practices; for any privacy-related inquiries, please contact us at privacy@pyyne.com. Based on the nature and scale of our processing activities, we have not appointed a Data Protection Officer under Article 37 of the GDPR; our designated privacy contact is responsible for overseeing our privacy program.
2. Scope
This Policy applies to personal information we collect from:
-
Visitors to our Website;
-
Prospective and current clients, and the personnel of client organizations;
-
Vendors, suppliers, partners, and their personnel;
-
Candidates and applicants who apply for roles at Pyyne; and
-
Other individuals who communicate with us in the course of our business.
This Policy does not cover personal information we process on behalf of our clients under a services agreement. In those engagements, our client is the data controller and their privacy notice applies. We act as a processor or sub-processor and handle that information only as instructed by the client and as governed by the applicable contract and data processing addendum.
Health information. Similarly, where Pyyne provides services to clients in the healthcare sector and receives protected health information (“PHI”) subject to the U.S. Health Insurance Portability and Accountability Act (“HIPAA”), Pyyne acts as a business associate (or subcontractor of a business associate). Our handling of PHI is governed by HIPAA and the applicable Business Associate Agreement, not this Policy.
3. Information We Collect
We collect personal information in the following categories:
3.1 Information You Provide
-
Contact and inquiry data: name, business email, company, phone number, country, and the content of messages you send via our contact form or by email.
-
Job application data: name, contact details, résumé/CV, work history, education, qualifications, eligibility to work, and any other information you choose to provide as part of an application. Additional information about our handling of candidate data may be provided in a separate Candidate Privacy Notice at the time you apply.
-
Commercial and contract data: information exchanged when negotiating, entering into, or performing a services agreement, including billing contacts, signatory information, and procurement details.
3.2 Information Collected Automatically
When you visit the Website, we and our analytics providers automatically collect certain technical information, including:
-
IP address (which may be truncated or anonymized by our analytics provider);
-
Device type, browser type and version, operating system, and language settings;
-
Referring URL, pages viewed, links clicked, and approximate session duration;
-
Approximate geographic location derived from IP address (typically city or region level); and
-
Cookie identifiers and similar technologies.
We use Google Analytics to understand Website usage. Google Analytics typically acts as a processor of data on our behalf, although it may act as an independent controller for certain purposes if specific advertising features are enabled. You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on or by using the cookie controls described in Section 7.
3.3 Information from Third Parties
We may receive information about you from publicly available sources (e.g., LinkedIn, company websites), referral partners, recruiters, professional references, and background-check providers (for candidates, where permitted by law and with appropriate notice and consent).
4. How We Use Personal Information
We use personal information for the following purposes:
-
To respond to inquiries submitted through the Website or by email.
-
To pursue and manage business relationships with clients, prospects, vendors, and partners, including proposals, scoping, contracting, service delivery, invoicing, and account management.
-
To evaluate job applications, communicate with candidates, conduct interviews and assessments, and (where permitted) perform background checks.
-
To operate, secure, and improve the Website, including analytics, performance monitoring, debugging, and protecting against fraud, abuse, and unauthorized access.
-
To comply with legal obligations, respond to lawful requests from authorities, and enforce our agreements.
-
To protect our rights, property, and the safety of Pyyne, our personnel, our clients, and others.
Artificial intelligence. Pyyne uses artificial intelligence (“AI”) tools in the course of operating its business, including to support research, drafting, software development, and internal productivity. Where personal information is processed using AI tools, we apply appropriate privacy controls, including limiting the personal information shared with such tools to what is necessary for the purpose, preferring de-identified, pseudonymized, or aggregated data where feasible, and maintaining human review of material outputs. Our use of AI in client engagements is governed by the applicable services agreement.
We do not use personal information for automated decision-making, including profiling, that produces legal or similarly significant effects concerning individuals.
5. Legal Bases for Processing (EU/EEA/UK Residents)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under the EU/UK General Data Protection Regulation ("GDPR"):
-
Performance of a contract — to enter into and perform a services agreement with you or the organization you represent.
-
Legitimate interests — to operate and grow our business (including B2B marketing, business development, Website analytics, and security), provided those interests are not overridden by your rights and freedoms.
-
Consent — where we ask for it, such as for non-essential cookies or certain marketing communications. You may withdraw consent at any time.
-
Compliance with legal obligations — to meet tax, accounting, employment, and other legal requirements.
You may request additional information about the legitimate interests we rely on by contacting us at the email above.
6. How We Share Personal Information
We do not sell personal information. We share personal information only in the following circumstances:
-
Service providers and sub-processors that support our operations, such as cloud hosting, email and productivity tools, customer relationship management, applicant tracking, analytics, payment processing, professional services, and IT security. These providers are bound by contract to use personal information only as instructed by us and to maintain appropriate security.
-
Clients and partners, where you are a candidate being proposed for a client engagement, a member of a client's personnel, or where sharing is otherwise necessary to deliver services.
-
Pyyne affiliates operating in the United States, Sweden, Brazil, and other jurisdictions, for the purposes described in this Policy. Our affiliates include Pyyne LLC (United States), Pyyne Digital Sweden AB (Sweden/ EU), and PYYNE BRASIL CONSULTORIA EMPRESARIAL LTDA (Brazil)
-
Professional advisors, such as auditors, lawyers, and accountants, under duties of confidentiality.
-
Authorities and other parties when required by law, court order, or legal process, or where necessary to protect our rights, property, or safety, or that of others.
-
Successors in interest in connection with a merger, acquisition, financing, reorganization, or sale of assets.
A current list of categories of sub-processors is available on request from privacy@pyyne.com.
7. Cookies and Similar Technologies
Our Website uses cookies and similar technologies for the following purposes:
-
Strictly necessary — to enable core Website functionality. These cannot be disabled.
-
Analytics — to understand how visitors use the Website (e.g., Google Analytics).
Most browsers allow you to refuse or delete cookies through their settings. If you are visiting from a jurisdiction that requires it, we will request your consent for non-essential cookies through a cookie banner before they are set. You can change your preferences at any time using the cookie banner or your browser controls.
We engage third-party suppliers to assist with analytics and other website services. You can manage your preferences regarding these services using our cookie banner and browser controls.
8. International Data Transfers
Because Pyyne operates internationally, personal information may be transferred to, stored in, or accessed from countries other than the one in which it was collected, including the United States, Sweden, Brazil, and other countries where we or our service providers operate. The data protection laws of these countries may differ from those in your country.
Where we transfer personal information from the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and supplementary measures where required. You may request a copy of the safeguards we use by contacting us at the email above.
9. Data Retention
We retain personal information for as long as necessary to fulfill the purposes described in this Policy, including to provide services, comply with legal obligations, resolve disputes, and enforce our agreements. Typical retention periods include:
-
Website analytics data: up to 26 months;
-
Inquiry and contact data: up to 24 months after last contact, unless an active relationship continues;
-
Candidate data: up to 24 months following an application, unless you ask us to keep it longer for future opportunities or longer retention is required by law;
-
Client and vendor relationship data: for the duration of the relationship and as required for legal, tax, and accounting purposes (typically 7–10 years after the relationship ends).
When personal information is no longer needed, we delete, anonymize, or securely archive it.
10. Security
We implement administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, alteration, disclosure, or destruction. These include access controls, encryption in transit, secure development practices, vendor due diligence, employee training, and incident response procedures. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. Our information security program is informed by recognized industry frameworks and standards, including ISO/IEC 27001:2022 and the AICPA Trust Services Criteria (SOC 2).
11. Your Privacy Rights
Depending on where you are located, you may have some or all of the following rights with respect to your personal information:
-
Access — request a copy of the personal information we hold about you.
-
Correction — request that we correct inaccurate or incomplete information.
-
Deletion — request that we delete your personal information, subject to legal exceptions.
-
Restriction or objection — request that we restrict or stop certain processing, including processing based on legitimate interests or direct marketing.
-
Portability — receive your information in a structured, commonly used, machine-readable format.
-
Withdraw consent — withdraw consent where processing is based on consent, without affecting prior processing.
-
Lodge a complaint — file a complaint with a supervisory authority.
To exercise these rights, email privacy@pyyne.com. We may need to verify your identity before responding and may decline requests as permitted by law. We will respond within the timeframes required by applicable law.
11.1 EU/EEA, UK, and Swiss Residents
If you are located in the EU/EEA, UK, or Switzerland, you have the rights described above under the GDPR and equivalent laws. You may lodge a complaint with the data protection authority in your country of residence, place of work, or place of the alleged infringement. In Sweden, the supervisory authority is the Integritetsskyddsmyndigheten (IMY).
11.2 California Residents
If you are a California resident, you have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA"), including:
-
The right to know the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of third parties with whom we share it;
-
The right to delete personal information we have collected from you, subject to exceptions;
-
The right to correct inaccurate personal information;
-
The right to opt out of the sale or sharing of personal information; and
-
The right to limit the use of sensitive personal information.
Pyyne does not sell personal information and does not share personal information for cross-context behavioral advertising, as those terms are defined under the CCPA. We do not knowingly collect sensitive personal information for purposes that require a limitation right.
To exercise your California rights, email privacy@pyyne.com. You may also designate an authorized agent to submit a request on your behalf, subject to verification. We will not discriminate against you for exercising any of these rights. To the extent required by applicable law, we treat opt-out preference signals, such as the Global Privacy Control (GPC), as valid requests to opt out of the sale or sharing of personal information.
11.3 Brazilian Residents
If you are located in Brazil, you have rights under the Lei Geral de Proteção de Dados ("LGPD"), including the rights of confirmation, access, correction, anonymization or deletion of unnecessary or excessive data, portability, information about sharing, information about the consequences of refusing consent, and revocation of consent. We process personal data in accordance with LGPD Article 7, relying on legal bases such as consent, fulfillment of legal or regulatory obligations, and our legitimate interests. To exercise these rights, contact us at the email above. You may also contact the Brazilian data protection authority, the Autoridade Nacional de Proteção de Dados (ANPD).
11.4 Other U.S. State Residents
Residents of certain other U.S. states (including, for example, Virginia, Colorado, Connecticut, Texas, and Oregon) may have rights under comprehensive state privacy laws, including the rights to access, correct, delete, and obtain a copy of personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. Pyyne does not sell personal data and does not process personal data for targeted advertising. To exercise rights available to you under applicable state law, email privacy@pyyne.com. If we decline to act on your request, you may appeal our decision by replying to our response; if your appeal is unsuccessful, you may contact your state Attorney General.
12. Children's Privacy
Our Website and services are directed to businesses and professionals, not to children. We do not knowingly collect personal information from individuals under the age of 16. If we learn that we have collected personal information from a child, we will delete it promptly. If you believe we have collected information from a child, please contact us at the email above.
13. Third-Party Links
The Website may contain links to third-party websites and services. We are not responsible for the privacy practices of those third parties, and this Policy does not apply to them. We encourage you to review the privacy notices of any third-party site you visit.
14. Changes to This Policy
We may update this Policy from time to time. When we do, we will revise the "Effective Date" above and, where the changes are material, provide additional notice (such as a banner on the Website or direct communication). Your continued use of the Website or services after the Effective Date constitutes acceptance of the updated Policy.
15. How to Contact Us
If you have any questions, concerns, or requests regarding this Policy or our privacy practices, please contact us:
Email: privacy@pyyne.com
Mail: Pyyne LLC, Attn: Privacy, 447 Broadway, 2nd Floor #1691, New York, NY 10013
Website: https://www.pyyne.com
Version History
Version 1.0 — May 14, 2026 — Initial publication.
Version 1.1 — June 11, 2026 — Added controller identification (Section 1); HIPAA business associate statement (Section 2); Candidate Privacy Notice cross-reference (Section 3.1); AI processing disclosure and automated decision-making statement (Section 4); affiliate entity list (Section 6); DPO clarification (Section 1); security framework alignment (Section 10); opt-out preference signals (Section 11.2); other U.S. state privacy rights (Section 11.4).
