Privacy policy
Effective date: 2 October 2026
This policy explains how Teyo Labs GmbH, Unterdorfstrasse 12, 8808 Pfäffikon SZ, Switzerland (“Partnex”, “we”) handles personal data on the website partnex.ai and in the Partnex application at app.partnex.ai. It is written for the Swiss Federal Act on Data Protection (FADP) and the EU General Data Protection Regulation (GDPR).
Who is responsible
For the website, for demo requests, and for the accounts of the people who use Partnex, we are the controller. Contact: privacy@teyolabs.com.
For the content our customers put into Partnex (their companies’ information, their prospects, the people they contact, the emails they forward), the customer is the controller and we are their processor. We process that data only on the customer’s instructions, under our data processing agreement. If your data is in a Partnex customer’s workspace and you want to exercise your rights, contact that customer. You can also write to us and we will pass your request on.
The website
What we collect. When you visit partnex.ai, our hosting provider (Hostinger) processes your IP address, browser details and the pages requested, to deliver the site and protect it from attacks. We do not use cookies, analytics or advertising trackers on the website, and we load no content from third parties: fonts and scripts are served from our own domain.
Legal basis. Our legitimate interest in delivering a secure website (GDPR Art. 6(1)(f)).
Demo requests and email
What we collect. When you request a demo, we receive your name, work email, company, role and anything you write in the message. When you email us, we receive your message and address.
Why. To reply to you and arrange the demo, and to follow up on the conversation you started.
How. The form is sent to our inbox through our email delivery provider (Resend), and our inbox is operated through Forward Email.
Legal basis. Steps you asked for before a possible contract, and our legitimate interest in replying to business enquiries (GDPR Art. 6(1)(b) and (f)).
How long. Up to 24 months after our last exchange, unless you become a customer, in which case the account rules below apply.
Partnex accounts
What we collect.
- Account data: your name, email address, company name, password (stored only as a one-way hash), role on your team, and your settings.
- Usage data: which features you run, when, how long they take, what they cost us, errors, and a log of the actions taken in your workspace, for example which documents were created or changed.
- Billing data: for paid plans, your billing contact and subscription status. Card details go directly to Stripe; we never see or store them.
- Messages: emails we send you (sign-up verification, password resets, notifications you can switch off in Settings) and their delivery status.
Why. To provide the service you signed up for, keep it secure, bill for it, support you, and understand how it is used so we can improve it.
Legal basis. Performance of our contract with you or your organisation (GDPR Art. 6(1)(b)), our legitimate interests in security and in improving the service (Art. 6(1)(f)), and legal obligations such as bookkeeping (Art. 6(1)(c)).
How long. For as long as the account exists. When an account is deleted, its data is removed from the live system at once and from backups within 30 days. Billing records are kept as long as accounting law requires, which in Switzerland is ten years.
Session storage. The application keeps your login session in your browser’s local storage so that you stay signed in. It is strictly necessary for the service and is not used for tracking.
People in our customers’ work
Partnex helps businesses find prospective partners and the right people to talk to there. As a result, a customer’s workspace may contain business contact data about people at other companies: name, job title, employer, business email, business phone number, LinkedIn profile, and the conversation the customer has had with them.
This data comes from the customer, from the public web, and from the data providers the customer chooses to use through Partnex (listed on the subprocessors page). An email address or phone number is only stored when a data provider supplied it or a person at the customer entered it. Partnex never constructs or guesses contact details.
The customer is the controller of this data and decides whom to contact. If you want to know whether a Partnex customer holds your data, or want it corrected or deleted, contact that customer, or write to privacy@teyolabs.com and we will forward your request.
AI processing
Partnex uses AI models to produce its deliverables. To do so, the relevant parts of a workspace (for example the company profile and the prospect being worked on) are sent to the AI provider for that task. AI providers process this data only to return the result, under terms that do not allow them to use it to train their models. We do not use customer data to train AI models.
AI is used to draft documents and analyses that people then review. It does not make decisions about individuals that have legal or similarly significant effects on them.
Who receives data
We share personal data only with the service providers that help us run Partnex, under contracts that bind them to protect it and use it only for us. They are listed, with their purpose and location, on the subprocessors page. We do not sell personal data and do not share it for advertising.
We may disclose data if the law requires it, or to protect our rights in a legal dispute.
International transfers
Our application and its data are hosted in the European Union. Some of our service providers are in the United States or other countries. Where a country does not have an adequate level of data protection recognised by Switzerland or the EU, we rely on the EU Standard Contractual Clauses (with the Swiss addendum) or on the provider’s certification under the EU-US and Swiss-US Data Privacy Frameworks.
Security
We protect data with encryption in transit, hashed passwords and access tokens, strict separation between customers’ workspaces, access limited to the people who need it, logging, and regular backups. The DPA describes our measures in more detail. No system is perfectly secure; if a breach affects your data, we will inform you and the authorities as the law requires.
Your rights
You have the right to ask for access to your data, to have it corrected or deleted, to restrict or object to its processing, and to receive it in a portable format. Where we rely on consent, you can withdraw it at any time. Account holders can export all their data and delete their account themselves in Settings.
To exercise a right, write to privacy@teyolabs.com. We will answer within 30 days.
You can also complain to a data protection authority: in Switzerland the Federal Data Protection and Information Commissioner (FDPIC), in the EU the authority in your country.
Changes
We will publish changes to this policy on this page, and tell account holders by email about changes that matter to them.