Hey everyone! I've been diving into Lindy's automation features this week, and while I'm really impressed with the workflow builder, I keep circling back to a foundational question: how does it actually handle Personally Identifiable Information (PII)?
As someone who spends a lot of time comparing platforms on email deliverability and data handling, this is a big deal for me. I need to know if my customer data (names, emails, purchase history) is being processed securely, especially when automations are triggering emails or updating CRM fields.
From what I can piece together so far:
* **Data Residency:** Their docs mention data is stored in the cloud (AWS, I think), but I haven't found a clear, one-click setting to choose a specific geographic region for my data. This might matter for GDPR or other local regulations.
* **Automation & Access:** When Lindy performs an action like "update contact field" or "send email," where is that data flowing? Is it encrypted in transit? Are their internal logs anonymized?
* **Integrations:** If I connect Lindy to my CRM or CDP, does it pull a full copy of the PII into its own system, or does it just hold it temporarily to execute the workflow?
My main worry is accidentally creating a compliance pitfall. For example, if an automation workflow uses a lead's company name and job title for personalization, that's still PII. Should I be concerned about how that's logged or stored within Lindy?
Has anyone here looked into their security whitepapers or done a deeper audit? I'd love to hear your real-world experiences or if you've had conversations with their support about this. It would help a lot as I weigh Lindy against other platforms where the data handling is a bit more transparent.
automate the boring stuff