The desk's knowledge stays in the desk.
A broker's book is the business. LaycanDesk is a private desk tool, not a marketplace: nothing you forward is pooled, resold or shown to another company. This page says plainly what we hold, where, for how long, and who else touches it.
Who we are
LaycanDesk ("we") operates this website and the LaycanDesk service. For data you enter on this website we are the controller. For the emails, cargo orders, tonnage lists and counterparty records a customer desk forwards into its LaycanDesk workspace, the customer is the controller and we are the processor, acting only on its instructions under the data processing agreement below. Contact: hello@laycandesk.com.
What we collect on this website
- Contact and RFQ forms. Name, email, company, the trade or cargo you describe, and your message. We store a short hash of your IP address for abuse prevention, never the address itself.
- Login. Email address for magic-link sign-in. No passwords are stored.
- Technical. Standard server logs (request path, status, timing). We do not run advertising trackers or third-party analytics cookies on the marketing site.
What we process for a customer desk
- Emails forwarded to the desk's private ingest address, including attachments, sender and headers.
- Cargo orders, tonnage positions, enquiries, estimates and offers derived from those emails.
- Counterparty names and contact details as they appear in market correspondence.
- Corrections your brokers make to what the system extracted.
Email bodies and counterparty personal data are never written to application logs. Logs carry record ids and hashes only.
How AI is used
Email text is sent to Anthropic's API to extract structured fields (commodity, quantity, ports, laycan, rates). The API is used under terms that do not retain inputs or train on them. Every extraction is marked pending until a broker on your desk approves it. Nothing is acted on automatically.
Tenant isolation
Every customer table carries an organisation id and is protected by row-level security enforced in the database, not only in application code. A user can only ever read rows that belong to their own organisation. This is tested on every schema change.
Where data lives
Primary storage is in Switzerland (Zurich). Sub-processors we rely on:
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication, file storage | EU (Zurich, eu-central) |
| Vercel | Web application hosting | EU (Frankfurt) functions, global edge |
| Anthropic | Structured extraction of cargo and tonnage from email text | US · zero-retention API terms |
| Resend | Transactional email sending and inbound email receipt | EU (Ireland, eu-west-1) |
| Migadu | Mailbox hosting for hello@laycandesk.com | EU |
| Cloudflare | Email routing, DNS | Global edge |
We will give customers at least 30 days' notice before adding a sub-processor.
Retention
- Website form submissions: 24 months, then deleted unless a customer relationship has begun.
- Customer workspace data: for the life of the subscription, then deleted within 30 days of termination on request, or 90 days by default. Export is available at any time.
- Server logs: 30 days.
Your rights
Under the GDPR, the Swiss FADP and the UK GDPR you can ask for access, correction, deletion, restriction or portability of your personal data, and object to processing. Write to hello@laycandesk.com. If you are a contact appearing in a customer's workspace, we will pass your request to that customer and help them answer it. You may also complain to your local supervisory authority.
Data processing agreement
Customer desks receive a DPA covering the above, the EU standard contractual clauses for any transfer outside the EEA and Switzerland, breach notification within 72 hours, and audit cooperation. Ask for it at hello@laycandesk.com and it comes back countersigned.
Changes
We will note material changes here with a new date and email customer administrators before they take effect.