How we collect, use and protect personal data · Last updated 1 August 2026
Okyra provides AI-assisted qualitative research interviews. Interview audio is processed transiently to create a transcript and is not permanently stored by Okyra. Transcripts and AI-generated summaries and insights are stored for the customer’s research project. We do not use customer data to train general-purpose AI models.
This policy applies to the Okyra website, platform and related services (together, the “Service”). It should be read together with any privacy notice supplied by the customer that invited you to participate in research.
The Service is operated by ENIN BV, trading as Okyra (“Okyra”, “we”, “us” or “our”).
Okyra acts as a data controller when it decides why and how personal data is processed for its own business purposes. This generally includes data relating to visitors to our website, prospective and existing customers, account users, billing contacts, support requests, security, service administration and our own legal obligations.
When a customer uses Okyra to conduct research interviews, the customer generally determines the research purpose, selects participants and decides how the resulting research data will be used. The customer is therefore normally the data controller for participant data, and Okyra processes that data on the customer’s documented instructions as a data processor. Our processing in that role is governed by our agreement with the customer, including any applicable data processing agreement.
Customers are responsible for providing appropriate information to participants, identifying a valid legal basis and honouring participant rights. If you participated in an interview arranged by one of our customers, please contact that customer first about the research purpose or a rights request. We will assist the customer as required by applicable law and our contract.
Audio is captured and transmitted only as needed to run the voice-based interview and generate a transcript. Okyra processes this audio transiently and does not permanently store the audio recording. The resulting transcript may be stored as described in this policy. Participants should avoid providing information that is not relevant to the research or that they do not wish the customer to receive.
Customers may provide contact details for colleagues or research participants. Customers must ensure that they are permitted to provide this data and that recipients receive any notices required by law. We may also receive limited information from service providers, such as payment status from Stripe or authentication events from Supabase Auth.
Where Okyra acts as controller, we rely on the legal bases below. The applicable basis depends on the context and the data involved.
| Purpose | What this includes | Legal basis |
|---|---|---|
| Provide and administer the Service | Create accounts, authenticate users, operate projects, provide support and deliver requested features. | Performance of a contract; steps requested before entering a contract. |
| Operate AI-assisted interviews | Conduct interviews, transcribe responses and generate summaries, themes, sentiment indicators and research insights. | For customer research data, processing on the customer’s instructions; for our own account/service data, performance of a contract and legitimate interests. |
| Communicate | Send invitations, service messages, security notices, support replies and necessary administrative communications. | Performance of a contract; legitimate interests in operating and supporting the Service; consent where required. |
| Payments and subscriptions | Administer plans, invoices, transaction status, accounting and fraud prevention. | Performance of a contract; legal obligations; legitimate interests in preventing fraud. |
| Analytics and improvement | Understand use of the website and Service, measure performance and improve usability and reliability. | Legitimate interests; consent for non-essential cookies or trackers where required. |
| Security and compliance | Protect accounts and systems, investigate abuse, enforce terms, establish or defend claims and comply with law. | Legitimate interests; legal obligations; establishment, exercise or defence of legal claims. |
Where we rely on legitimate interests, we balance those interests against the rights and freedoms of the people concerned. You may object to this processing in the circumstances described in section 13. Where consent is the legal basis, consent may be withdrawn at any time without affecting earlier lawful processing.
Okyra uses artificial intelligence to conduct voice-based research interviews, transcribe participant responses, generate summaries, identify themes, analyse sentiment and organise research insights. AI-generated outputs support qualitative research; they may contain inaccuracies or miss context and should be reviewed alongside the underlying transcript where appropriate.
Okyra’s AI features are not intended to make decisions that produce legal or similarly significant effects about participants. Customers remain responsible for their research decisions and any action they take based on research outputs.
We use carefully selected providers to operate the Service. Depending on the feature used and Okyra’s role, a provider may act as our processor or as a subprocessor supporting services we provide to a customer. Providers may process only the data reasonably required for their function and are subject to contractual confidentiality, security and data-protection obligations.
| Provider | Purpose | Data involved |
|---|---|---|
| Vercel (EU deployment) | Frontend hosting, content delivery and platform operation | Website, device/connection and limited service data |
| Supabase (EU) and Supabase Auth | Database, storage, authentication and account management | Account, project, transcript, output and authentication data |
| Render (EU) | Application and backend hosting | Service, project and technical data |
| Hetzner (EU) | Infrastructure and hosting | Service, project and technical data |
| Mistral AI (EU) | AI model processing supporting transcription and research outputs, as applicable | Transient interview content, transcripts, prompts and generated outputs |
| TWIPLA (EU) | Website and product analytics | Cookie, usage, device and connection data |
| Brevo (EU) | Transactional and operational email delivery | Name, email address and message metadata/content |
| Stripe Payments Europe (Ireland) | Subscription, payment and billing services | Contact, billing, transaction and fraud-prevention data |
This list may change as the Service evolves. Where required, we will provide notice of material changes to subprocessors through our contractual or product communication channels.
We do not sell personal data. We may disclose personal data only as described below:
We seek to host core Service infrastructure in the European Union where indicated above. Some providers or their support operations may nevertheless process personal data from, or transfer it to, countries outside the European Economic Area. Where a transfer is not covered by an adequacy decision, we use an appropriate transfer mechanism, such as the European Commission’s Standard Contractual Clauses, together with supplementary measures where appropriate. Information about relevant safeguards may be requested at privacy@okyra.io, subject to confidentiality restrictions.
We retain personal data only for as long as needed for the purposes described in this policy, to meet contractual commitments and legal requirements, and to resolve disputes or enforce agreements. Retention depends on the category of data and our role.
When Okyra acts as processor, deletion and return of customer data are governed primarily by the customer’s instructions and our agreement with that customer. We may retain limited data where required by law, provided it remains protected and is used only for that legal requirement.
We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures are selected with regard to the nature of the processing and the risks involved and include access controls, authentication, encryption in transit, provider due diligence, logging, backups and operational security practices where appropriate.
No service can guarantee absolute security. Customers and users should protect their credentials, use strong authentication practices and promptly notify us of suspected unauthorised access. If a personal-data breach occurs, we will investigate and notify affected controllers, individuals or authorities where required by law.
We use cookies and similar technologies that are necessary to operate the website and Service, for example to maintain sessions, authenticate users, remember preferences and protect against abuse. We also use privacy-friendly analytics technologies, including TWIPLA configured in a manner that does not require non-essential cookies where applicable, to understand website and product usage, such as visits, interactions, device information and session statistics.
Where we use analytics or other technologies that require consent under applicable law, we will request that consent before activating them. Where applicable, you will be able to manage your choices through the consent mechanism provided on the website, in addition to your browser settings. Blocking necessary cookies may prevent parts of the Service from working. Cookie availability, duration and exact names may change as the website and Service evolve; the cookie interface is the current source for those details.
We use Brevo to send account invitations, authentication or security messages, interview invitations, service notices, support communications and other operational emails. These communications are necessary to provide or administer the Service and generally cannot be opted out of while the relevant account or interaction remains active.
If we send optional marketing communications, we will do so on an appropriate legal basis and include a way to unsubscribe. Opting out of marketing does not stop operational or transactional messages.
Subject to the conditions and exceptions in applicable law, you may have the right to:
To exercise a right concerning data for which Okyra is controller, contact privacy@okyra.io. We may ask for information needed to verify identity and locate the relevant data. We will respond within the period required by law. Requests may be limited or refused where permitted by law, and we will explain the relevant reason.
For participant data processed for a customer’s research project, contact the customer that invited you. If you contact us, we will route or support the request as appropriate without acting beyond the customer’s instructions.
In Belgium, the lead supervisory authority is the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données). You may also complain to the supervisory authority in the EEA country where you live, work or believe an infringement occurred.
The Service is intended for business customers and research arranged by those customers. Okyra does not knowingly offer accounts directly to children. Customers must ensure that any research involving minors is lawful, age-appropriate and supported by any required parental or guardian authorisation. If you believe we have processed a child’s personal data unlawfully, contact privacy@okyra.io.
The website or Service may link to websites or services controlled by others. Their privacy practices are governed by their own notices, not this policy. We encourage you to review those notices before providing personal data.
We may update this policy to reflect changes to the Service, our providers, legal requirements or our processing practices. We will post the revised policy with a new “Last updated” date and, where required, provide additional notice through the Service or by email. Material changes take effect on the date stated in the updated policy unless a later date is specified.
Questions, requests or concerns about this policy or Okyra’s privacy practices may be sent to:
ENIN BV (trading as Okyra)
Meersstraat 43
9000 Gent
Belgium
Company / VAT number: BE0808506381
Email: privacy@okyra.io