Audryo is operated by Dear Friend Digital GmbH (“we”, “us”). This policy explains how we process personal data when you visit audryo.com, use app.audryo.com, or otherwise interact with us.
It covers two distinct roles:
- Controller — for your operator account, billing identity, support messages, and website visits.
- Processor — for people, events, consent records, emails, and related customer data that you load into a workspace. You remain the controller of that data.
We do not claim ISO 27001, SOC 2, or similar certifications. Hosting of the core platform is in Germany.
1. Controller
Dear Friend Digital GmbH
Emilienstraße 9
90489 Nürnberg
Germany
Email: hello@audryo.com
Phone: +49 911 6262076
We have not appointed a data protection officer. You can contact us at the address above, or the Bavarian data protection authority (BayLDA) if you wish to lodge a complaint.
2. What this service is
Audryo is a lifecycle email platform. Teams and connected agents can build audiences, journeys, campaigns, and branded emails. Nothing is published or sent to your customers until a human in your workspace approves it. Delivery of customer mail goes through an email provider you connect (for example Resend or Mailgun). Audryo does not send that mail from its own reputation.
3. Data we process as controller
Operator accounts
When you create an account we process:
- name, work email, password (stored as a hash), and account status
- workspace and project membership, roles, and invitations
- optional onboarding answers used to create your first workspace
- session cookies necessary to keep you signed in
- API tokens you create for agents, including scope and last use
- audit records of human, agent, and system actions in your workspace
Legal basis: Art. 6(1)(b) GDPR (contract) and Art. 6(1)(f) GDPR (security, abuse prevention, product operation).
Website
The marketing site is static. We do not set advertising or analytics cookies there. The server may keep ordinary access logs (IP address, user agent, requested URL, time) for a short period to operate, secure, and debug the site. Legal basis: Art. 6(1)(f) GDPR.
Support and transactional mail to you
We use your email to send confirmation, password reset, invitation, and similar account mail, and to answer support requests. Legal basis: Art. 6(1)(b) and (f) GDPR.
Billing
During public beta the service is free. If you later subscribe, we will process billing identity, plan, usage for contact capacity and AI allowance, and payment details via a payment provider. We will update this policy before paid billing starts.
4. Data we process as processor
You (or your company) are the controller of:
- contacts and their attributes
- product events and related identifiers
- tags, audiences, and consent or suppression records
- message content, templates, journeys, campaigns, and send metadata
- open, click, bounce, and complaint events generated from mail you send
- brand, product facts, and assets you upload
We process this data only on your documented instructions: the product UI, the /v1 API, MCP, and CLI, plus this policy and the Terms of Service. A data processing agreement (Art. 28 GDPR) is available on request at hello@audryo.com.
You are responsible for having a lawful basis to collect and email those people, including consent for marketing where required, and for the accuracy of suppression and unsubscribe handling in your programmes.
5. AI features
Audryo can draft or explain lifecycle work using a language-model gateway (currently OpenRouter). We configure that gateway to request zero data retention and to deny provider use of prompts for training. The model still has to receive a prompt in order to reply.
We do not send raw contact records or event payloads to a model. Prompts use confirmed product facts, schemas you have approved, and aggregate or workspace context. Model outputs are validated before they are stored. Every proposal remains reviewable; agents cannot silently publish.
Legal basis for operator-initiated AI calls: Art. 6(1)(b) GDPR. Processing of customer personal data inside those prompts, if any residual identifiers remain, is done as processor on your instruction.
6. Email sending and tracking
- Customer mail (journeys, campaigns, transactional sends you trigger) leaves through your connected provider. That provider’s terms and region apply. Audryo records delivery, bounce, and complaint webhooks so suppressions stay consistent.
- Audryo system mail to operators (signup, reset, invites) is sent by us via Resend from an Audryo address.
- Optional open and click tracking rewrites links through
link.audryo.com. Destinations are stored without query strings or fragments. Open and click metrics can be inflated by mailbox privacy features; they are not our primary success metric.
Tracking of your recipients is processing on your behalf. Disable or avoid those features if they are not appropriate for a given send.
7. Recipients and subprocessors
We use:
| Recipient | Purpose | Typical location |
|---|---|---|
| Hosting and operations for audryo.com, app, API, and tracking | Run the service | Germany |
| Resend | Operator transactional email; optional customer sending if you connect Resend | EU (your Resend account region) |
| Your connected ESP (Resend, Mailgun, or similar) | Customer mail you approve | Your provider account |
| OpenRouter and the model provider you invoke | AI drafts and explanations | See OpenRouter’s then-current list; transfers use their safeguards |
| Professional advisers, hosts, or authorities | Legal, tax, or compulsory requests | As required |
We do not sell personal data. We do not use customer contact lists for Audryo’s own marketing.
8. International transfers
Core application data is hosted in Germany. Some subprocessors (notably AI routing) may process data in third countries. Where GDPR Chapter V applies, we rely on an adequacy decision or standard contractual clauses plus the provider’s supplementary measures.
9. Retention
- Operator accounts: for the life of the account, then as long as required for legal claims, tax, or security logs.
- Session cookies: until you sign out or the session expires.
- Customer data: until you delete it, close the workspace, or instruct erasure. Backup copies expire on a rolling cycle.
- Audit and delivery logs: kept long enough to investigate abuse, billing disputes, and your own compliance questions, then deleted or aggregated.
- Consent and suppression records: kept as long as needed to prove a send was blocked or permitted.
You can export and delete contacts and related records in the product. Account closure requests go to hello@audryo.com.
10. Security
We use TLS in transit, access control by workspace, hashed passwords, scoped API tokens, and an audit trail that distinguishes humans, agents, and the system. Sending fails closed when identity, consent, or suppression checks fail. No method of transmission or storage is perfectly secure.
11. Your rights
If we are the controller, you may request access, rectification, erasure, restriction, portability, and objection, and you may withdraw consent where processing is based on consent. Email hello@audryo.com. You also have the right to lodge a complaint with a supervisory authority, in particular in your EU member state of residence or work, or with BayLDA for Bavaria.
If we are the processor, we will forward requests that concern your contacts to the workspace owner unless you are that owner and use the product tools yourself.
12. Cookies
See the Cookie Policy. In short: the marketing site does not use non-essential cookies; the app uses a necessary session cookie (audryo_session).
13. Children
Audryo is a business service. It is not directed at children under 16. We do not knowingly create operator accounts for children.
14. Changes
We will update this page when our processing changes in a material way, and we will adjust the date above. If a change is significant for operators, we will also send a notice to the account email.
15. Contact
Dear Friend Digital GmbH
Emilienstraße 9, 90489 Nürnberg, Germany
hello@audryo.com