LYNX ยท Last updated: 13 July 2026
This Privacy Policy governs the processing of personal data carried out by LYNX, in compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and with Spanish Organic Law 3/2018 of 5 December on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).
This is a translation provided for convenience. In the event of any discrepancy, the Spanish version shall prevail as the legally binding text.
The controller of your personal data is LYNX, the company that operates the mobility platform. To exercise your rights or raise any question about the processing of your data, you may contact us through the support email address available on the platform.
LYNX collects only the data strictly necessary to provide the on-demand transport service and to manage its relationship with passengers, drivers and fleet managers. The data processed includes:
The purposes of the processing include providing the transport service, invoicing and payment collection, communication between users, compliance with legal obligations and fraud prevention.
The processing of your data is based on the performance of the service contract (Art. 6(1)(b) GDPR), compliance with legal obligations (Art. 6(1)(c) GDPR) and, where applicable, the consent of the data subject (Art. 6(1)(a) GDPR) for marketing communications and non-essential cookies.
Your data is not disclosed to third parties except where required by law or where necessary to provide the service. Our processors include payment service providers (Stripe), cloud infrastructure, communications and mapping providers. All of them act under contract and with the safeguards required by the GDPR.
Some technology providers may be located outside the European Economic Area. In such cases, LYNX ensures that these transfers are carried out under the appropriate safeguards provided for in the GDPR, such as European Commission adequacy decisions or standard contractual clauses.
Data will be retained for as long as necessary to provide the service and for the periods required by law in order to address potential claims or requests from authorities. Invoicing data is retained for the minimum period of five years required by tax legislation.
Under the GDPR and the LOPDGDD, you have the right to access your data, rectify it, erase it, object to its processing, and request its portability and the restriction of processing. To exercise these rights, please contact the data controller through the support email address available on the platform.
If you believe that the processing of your data infringes applicable law, you have the right to lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
LYNX applies appropriate technical and organisational measures to protect your data against unauthorised access, loss or accidental destruction, including password encryption, HTTPS connections and secure storage of session tokens.
LYNX uses strictly necessary technical cookies for the operation of the service. For more information, please see our Cookie Policy.
LYNX reserves the right to amend this policy in order to adapt it to regulatory or service changes. Significant changes will be communicated through the platform or by email.