GDPR
GDPR: what ONYRI does, and what it does not
ONYRI Sanitize masks personal data in your documents, inside your browser. That helps you share less data. It does not make you compliant by magic. This page says plainly where the tool helps, where it stops, and who processes what.
What ONYRI does
Four facts about the way the product is built. You can check the first two yourself in your browser's developer tools.
It processes documents in your browser
Reading the file, OCR, detection and masking all run on your device. The document, the text taken from it and the values found are never sent to our servers.
It helps you minimise data
Article 5(1)(c) of the GDPR asks you to share only the data that is needed. Masking names, numbers and bank details before a document circulates is a direct way to apply that principle.
It logs no content
We never receive your content, so we cannot log it. Our servers record account events and usage counters only, such as the number of documents processed today. Never what was in them.
It stores account data only
Our backend keeps your email, your workspace, your plan, and the detection settings you save (custom rules and profiles). Tip: do not put a real person's data in a rule name.
What ONYRI does not do
A privacy tool that oversells itself is a risk. Here are the three limits you should plan for.
It does not guarantee compliance
Compliance depends on your legal basis, your retention rules, your contracts and your security. A masking tool covers one part of that. It reduces exposure; it does not certify anything.
It does not find everything
Detection relies on patterns, rules and context words. It is not exhaustive. Unusual names, indirect identifiers and images can be missed. The preview exists so that a human checks before download.
Token mode is not anonymization
Replacing a name with [NAME1] is pseudonymization. The data remains personal data under the GDPR. Only irreversible masking, combined with a check of indirect identifiers, moves towards anonymization.
Pseudonymization and anonymization are not the same thing
Recital 26 of the GDPR draws the line. Data that can be linked back to a person with additional information is pseudonymized, and it is still personal data. Data is anonymous only when the person can no longer be identified by any means reasonably likely to be used.
In ONYRI, token mode replaces each value with a label such as [NAME1]. Anyone who holds the original document can link the label back to the person. That is pseudonymization in the sense of Article 4(5). It is a useful security measure, named as such in Article 32, but the GDPR still applies to the result.
Black-marker mode removes the values from the exported file for good. That goes further. But a document can still point to a person through context: a rare job, a date, a place. Whether the result is truly anonymous is a case-by-case judgment that stays with you.
Sub-processors
These providers process account data on our behalf. None of them receives your documents, because we do not receive them either.
| Provider | Purpose | Data involved |
|---|---|---|
| Railway | Hosting of the application and its database | Account data: email, name, workspace, plan, saved detection settings, usage counters |
| Stripe | Payments, subscriptions, invoices and tax | Billing contact, payment method, invoices. Card numbers go to Stripe directly and are never stored by ONYRI |
| Resend | Transactional emails | Email address and the content of service emails (verification, password reset, billing notices) |
Audience measurement on public pages and the optional Google sign-in are described in our privacy policy. None of these services receives your documents. Read the privacy policy
How to use ONYRI in a GDPR workflow
The tool is one building block. Here is where it fits in a sound process.
- 1
Write it into your DPIA
If a processing needs a data protection impact assessment (Article 35), list masking before sharing as a risk-reduction measure. State which mode you use and who reviews the result.
- 2
Minimise before every transfer
Before a document goes to a supplier, an expert, a support desk or an AI tool, ask what the recipient really needs. Mask the rest. Use profiles to apply the same rules every time.
- 3
Set retention for both copies
The masked copy and the original are two documents. Keep the original under your normal retention rules. Delete masked copies when their purpose is over, above all token-mode copies, which are still personal data.
- 4
Keep a human in the loop
Make the preview check a written step of your procedure. The person who downloads the file confirms that names, numbers and indirect identifiers were reviewed.
This page is general information, not legal advice. Ask your data protection officer or your counsel how these points apply to your organisation.
Share the document, not the personal data.
Drop a file, review the preview and download the masked copy. Everything happens in your browser.