Privacy Notice — LEM / Lem Cloud
Version: 1.1 | Last updated: 2026-09-08 | Effective date, version and SHA-256 of the published version: recorded in the publication manifest that governs this notice.
This Privacy Notice explains how Novus Point Limited, a company incorporated in England and Wales (company no. 08146241, registered office 124 City Road, London, England, EC1V 2NX) ("Vendor", "we", "us"), processes personal data in connection with the LEM / Lem Cloud personal AI operator service (the "Service") and the websites on which this notice is published (the "Site").
The Service is sold to business customers only ("Customers"). We do not offer the Service to consumers, sole traders or unincorporated partnerships. This notice nevertheless applies to the individuals whose personal data we process — site visitors, prospects, Customers' representatives, billing contacts and authorised users.
The English notice is the only proposed authoritative version. No translation forms part of the public legal set. Novus Point Limited does not offer a Polish-law contract route.
Summary
This summary is a reading aid. The numbered sections that follow are the notice itself, and they govern wherever the two differ.
- We act in two capacities. For our own business records — enquiries, contracting, billing, authentication, support, and the operational data of the servers we run — we are the controller, and Sections 2, 3, 5, 6.1, 7 and 8 to 13 describe that processing. For the content a Customer connects to its Workspace, the Customer is the controller and we are its processor under the DPA; Sections 4 and 6.2 summarise it.
- We do not advertise to you, profile you, or sell your data. We set no advertising or analytics cookie, we build no marketing or scoring profile about any individual, and we do not train AI models on Service Data.
- Most of our controller processing rests on legitimate interests (Article 6(1)(f)); accounting and tax records rest on a legal obligation (Article 6(1)(c)). Section 2.2 states the basis for each purpose, and Section 8 explains how to object.
- We keep data no longer than the periods in Section 6, which states either a period or the criteria for setting one for every category disclosed here.
- Some facts in this notice are still being evidenced. Where an entity, location, transfer instrument or retention figure has not yet been verified against a primary record, this notice says so rather than asserting it. Nothing is described as operative before that evidence exists.
Defined terms used throughout. "Vendor", "we", "us" — Novus Point Limited. "Service" — the LEM / Lem Cloud personal AI operator service. "Site" — the websites on which this notice is published. "Customer" — the business that contracts for the Service. "Workspace" — the dedicated, isolated hosted workspace in which a Customer's Service runs. "Controller Data" — personal data we process as controller (Section 1.1). "Service Data" — personal data a Customer connects to its Workspace, for which the Customer is the controller (Section 1.2). "DPA" — the Data Processing Agreement entered into with each Customer.
1. Our two roles: controller and processor
We process personal data in two distinct capacities. Which parts of this notice apply to you depends on which capacity is engaged.
1.1 Novus Point Limited as controller ("Controller Data")
We are the controller of personal data relating to:
- Site visitors — data collected through the Site (see Section 11, Cookies);
- Prospects and enquirers — people who contact us, request a demo, or engage in pre-contractual discussions;
- Customer representatives — the individuals who sign the Order Form, manage the commercial relationship, receive invoices ("billing contacts"), and act as the single Workspace user (including the contact details, optional-channel identifier and login/authentication records we hold to run the account);
- Support and service correspondence — messages exchanged with us about onboarding, support, billing, refunds, offboarding and deletion confirmations.
Sections 2, 3, 5, 6.1, 7 and 8 to 13 describe this controller processing (Articles 13 and 14 GDPR / UK GDPR), save that Section 7's description of Workspace container isolation is Service Data information given for transparency only. Sections 4 and 6.2 concern Service Data, for which the Customer is the controller.
1.2 Novus Point Limited as processor ("Service Data")
When a Customer uses the Service, the AI operator running in the Customer's dedicated, isolated hosted workspace (the "Workspace") processes the content the Customer connects to it — for example email (connected through the OAuth scopes the Customer grants in the provider's own consent screens), calendar data (including attendee details), files, a markdown vault and personas, finance and invoice data, contacts, messaging content (only where an optional channel is activated and recorded), and — where the Customer opts in to the voice add-on — call audio and transcripts, together with the prompts and completions exchanged with the configured large-language-model provider ("Service Data").
If an optional connected-account integration is activated, OAuth tokens (including refresh tokens where the provider issues them) are also Service Data. The integration remains disabled until the applicable provider, purpose, scopes, storage location, access controls, retention and deletion route are recorded in the Order Form, DPA and live activation evidence.
For Service Data, the Customer is the controller and Novus Point Limited is the processor. We process Service Data only on the Customer's documented instructions, under the Data Processing Agreement (the "DPA") entered into with each Customer. The DPA — not this notice — governs Service Data, including the authoritative subprocessor list, security measures, breach notification, audit and deletion terms. Section 4 below summarises the recipients of Service Data for transparency only.
If you are an employee, client or correspondent of one of our Customers and your personal data appears in Service Data (for example, because you emailed a Customer or attended a meeting in a Customer's calendar), the Customer's own privacy notice applies to that processing, and requests concerning that data should be directed to the Customer. We will refer any such request we receive to the relevant Customer without undue delay.
2. Controller Data: what we collect, why, and on what legal basis
2.1 Categories and sources
| Category | Examples | Source |
|---|---|---|
| Identity and contact data | Name, business email, phone, job title, company, the messaging-channel handle or identifier of the Workspace operator where an optional channel is used | You; your employer (the Customer) |
| Contract and account data | Order Form details, tier, add-ons, onboarding records, account configuration, deletion confirmations | You; generated by us |
| EULA and Order Form acceptance-audit data | The Workspace identifier, the EULA version and its SHA-256, the acceptance timestamp, each of the affirmations given on acceptance, a non-secret acceptance identifier and a tamper-evident record hash; and, in the linked contract file, the Order Form signer, the envelope reference, the complete-bundle hash and the EULA approval-manifest hash. Neither record stores a plaintext activation token, password, TOTP value, recovery code or session identifier (EULA clause 2.3) | Generated by use of the Service when the Order Form and the EULA are accepted |
| Billing data | Billing contact details, tax identifiers, invoices, invoice delivery, payment evidence and reconciliation references. Where the Order Form records the hosted subscription checkout route, this also includes the payment provider's customer, checkout, subscription, invoice, payment-status, refund, dispute and reconciliation references. We never receive or store a card number, payment-method credential, bank-account credential or online-banking credential: those are supplied directly to the payment provider through its own hosted checkout pages | You; the Customer; the payment provider; generated by us |
| Authentication and security data | Account identifier, password verifier, encrypted TOTP seed and hashed recovery codes (where a second factor is enabled), hashed activation/reset challenges, hashed session identifiers, login timestamps and lockout records | Generated by use of the Service |
| Correspondence | Support requests, pre-sales enquiries, complaints, refund requests | You |
| Site data | IP address, requested URL, timestamp, user agent and strictly necessary security/session information; no advertising or analytics profile is maintained by the Vendor at the version date | Your device; hosting provider |
| Operational hosting telemetry | Hourly server capacity measurements: check timestamp, the server's own hostname, number of Workspaces on it, load average, RAM and disk used percentages, and — where the Customer has not objected — the Workspace identifier with that container's CPU and memory figures. No Workspace content; see Section 11.1 | Generated by the servers that run the Service |
| Host operational log | Timestamp, host label, Workspace identifier and an operational condition code written by the servers' maintenance jobs; no Workspace content | Generated by the servers that run the Service |
Where we obtain your data from the Customer rather than from you directly (typically billing contacts and authorised users nominated by the Customer), Article 14 GDPR may require us to provide this notice actively. We will provide or link this notice at first communication or, at the latest, within one month of receipt unless a documented exemption applies; merely publishing it on the Site is not treated as delivery.
2.2 Purposes and legal bases
Clause 2.2 of the Master Services Agreement is the operative statement of the Vendor's independent-controller activities — corporate administration, contracting, invoicing, tax, fraud prevention, security, legal compliance and support relationship records — and provides that this notice cannot expand, vary or otherwise alter that list. Most purposes in the table below are sub-instances of those activities, and this notice describes them for information only. Where a purpose in the table is not squarely within one of the categories named in clause 2.2, the row says so and states what has to happen before the Vendor relies on it; nothing in this notice amends clause 2.2 in the meantime.
The Service is sold to business customers only, so the contracting party under an Order Form is the Customer company and not the individual signatory, billing contact or operator. Article 6(1)(b) is therefore not relied on for the purposes below; where a legitimate interest is stated, that interest is the operative basis.
| Purpose | Data used | Legal basis (GDPR / UK GDPR) |
|---|---|---|
| Responding to enquiries and pre-contractual steps | Identity, contact, correspondence | Art. 6(1)(f) (legitimate interest: responding to business enquiries and developing our business) |
| Providing and administering the Service: account setup, white-glove onboarding, password authentication (plus TOTP where a second factor is enabled), support and hypercare | Identity, contact, account, authentication data, correspondence | Art. 6(1)(f) (legitimate interest: performing our contract with the Customer and administering its account) |
| Billing, invoicing and payment collection | Billing data | Art. 6(1)(f) (legitimate interest: invoicing and collecting payment from the Customer); Art. 6(1)(c) (accounting obligations) |
| Tax and accounting record-keeping | Billing data, contract data | Art. 6(1)(c) |
| Service communications: maintenance, security notices, fleet updates, offboarding and deletion confirmations | Identity, contact | Art. 6(1)(f) (legitimate interest: keeping Customers informed about the Service) |
| Security: authentication, abuse and fraud prevention, per-tenant isolation monitoring | Authentication and security data | Art. 6(1)(f) (legitimate interest: securing the Service) |
| Keeping hosted Workspaces available, sizing each Workspace container's CPU and memory limits, and planning server capacity | Operational hosting telemetry | Art. 6(1)(f) (legitimate interests: continuity, availability and security of the hosted Service). Not analytics, advertising or profiling. The legitimate-interests assessment supporting per-Workspace attribution specifically is being finalised and is made available to a supervisory authority on request once recorded; until then this notice does not represent that balancing test as complete. We honour objections to Workspace-level attribution as a matter of policy; the Article 21 right itself applies subject to the conditions in that Article — see Section 11.1. This notice does not assert that continuity, availability and capacity planning fall within one of the categories named in clause 2.2 of the Master Services Agreement; clause 2.2 governs, and this notice cannot expand or vary it |
| Business-to-business marketing | Disabled at the version date. If activated later: identity/contact data only, documented recipient classification, Art. 6(1)(f) legitimate-interest assessment or consent as applicable, PECR/e-privacy compliance, sender identification, one-step opt-out and suppression control before first message. This purpose is not squarely within any of the clause 2.2 categories named above, so before it is activated the Vendor confirms which of them it instantiates, or varies that clause, so that the notice and the Master Services Agreement continue to state the same list | |
| Establishing, exercising or defending legal claims | Any of the above | Art. 6(1)(f) (legitimate interest: protecting our legal position) |
| Operating and securing the Site | Site data | Art. 6(1)(f) (legitimate interests: providing, defending and securing the Site); consent before any non-essential storage or access where PECR requires it |
Aggregated, de-identified technical and usage statistics derived from Service Data are not an independent Vendor purpose and are not listed above: that processing is carried out only on the Customer's documented instruction under clause 4.4 of the DPA, as permitted by clause 11.5 of the Master Services Agreement, and is described in Section 4.
We do not intentionally request special-category data as controller and do not knowingly offer the Service to children. If such data appears in correspondence, we process it only where an applicable Article 9 condition and lawful basis exist, or delete it where it is not required.
2.3 Whether you must provide personal data
To enter into and perform an Order Form we need identity and contact data for the Customer's signatory, billing contact and Workspace operator, billing data, and the authentication data generated when the operator's account is created. Providing that data is a contractual requirement, not a statutory one; you are not obliged to provide it, but without it we cannot provision, authenticate, support or invoice an account. Providing any other data described in this notice is optional and has no consequence if you decline.
3. Recipients of Controller Data
We share Controller Data with the following categories of recipient:
- Financial institutions and bookkeeping systems used for invoicing, described here by category: our bank, which executes payments, and a bookkeeping and invoicing provider, which holds invoice and ledger records. The legal entity, country of establishment, controller or processor role and retention period of each recipient are identified on request. LEM does not collect card data, bank-account credentials or online-banking credentials;
- The payment provider used for the hosted subscription checkout route, where the Order Form records that route (DPA Annex 3 Part B, row B7). It receives the billing contact's name and email, billing and tax identifiers, and the payment-method details the payer enters directly into the provider's own hosted checkout pages, and it generates the subscription, invoice, payment-status, refund, dispute and reconciliation references we retain. Its exact contracting entity, country of establishment, controller or processor role, processing locations, transfer position and retention period are recorded in DPA Annex 3 Part B row B7 and are stated in this notice, and identified on request, before this notice is approved for publication with that route enabled. This notice does not represent any payment provider as active;
- Infrastructure, email, CRM and accounting providers used to run our own back-office systems, described here by category: a business email and collaboration provider; a customer-relationship-management provider; an accounting provider; and the code and website hosting provider that serves the Site, which is GitHub Pages (the deployment recorded in
lem/legal/public-deployment.json). The contracting entity and country for the GitHub account, and the legal entity, country, role and retention period of each other provider, are identified on request and are stated in this notice at approved publication; - Professional advisers (lawyers, accountants, auditors) under confidentiality obligations;
- Public authorities where disclosure is required by law;
- The infrastructure hosting provider on whose servers the Workspace, the dashboard authentication records and the operational hosting telemetry reside (see Section 4 and Section 11.1) — Hostinger Global S.à r.l., 6 Avenue Pasteur, L-2310 Luxembourg (RCS Luxembourg B296195), processing at a data centre in Frankfurt, Germany, as evidenced and recorded in Part A of Annex 3 to the DPA. Its retention of hosting-side records, the executed provider data-processing agreement and the provider's written statement of support and intra-group access geography remain outstanding and are identified on request;
- A transactional-email or notification provider used to deliver account activation and reset links (DPA Annex 3 Part B). The legal entity, country, role and retention period are identified on request;
- Infrastructure-adjacent technical services — DNS and uptime/heartbeat monitoring (DPA Annex 3 Part B) — which receive server-side technical and origin metadata. The legal entity, country, role and retention period are identified on request;
- An operational alerting recipient which receives the host label, the Workspace identifier and a condition code, and no Workspace content (DPA Annex 3 Part B). The legal entity, country, role and retention period are identified on request;
- A customer-login identity provider, once one is configured for a tenant, which receives credential, sign-in-event and second-factor data (DPA Annex 3 Part B). No identity provider is configured at the version date.
Which of these are already receiving data. The bank, the bookkeeping and invoicing provider, the back-office providers, the infrastructure hosting provider and the Site hosting provider are in use at the version date. Annex 3 to the DPA records the transactional-email provider and the customer-login identity provider as disabled, and records the DNS service, the uptime/heartbeat monitoring service and the operational alerting recipient with a status of unverified rather than disabled: those three may therefore already be receiving the data described for them above, while their contracting entity, country, role, retention period and transfer position are still being verified. Section 5 states the transfer position for each of these routes.
We do not sell personal data and we do not use personal data for third-party advertising.
4. Service Data: subprocessors (transparency summary)
The following summarises, for transparency, the third parties that may process Service Data when a Customer uses the Service. The authoritative, contractually binding subprocessor list, and the mechanism for objecting to changes, are set out in the DPA.
| Subprocessor / recipient | Role | Location / transfer safeguard |
|---|---|---|
| Hostinger Global S.à r.l. (6 Avenue Pasteur, L-2310 Luxembourg; RCS Luxembourg B296195) — infrastructure hosting | Hosts the Customer's isolated hosted workspace, its container and its data volume | Processing at a data centre in Frankfurt, Germany. The entity and the processing location are evidenced (the Vendor's own account invoice HLU-59787 of 2026-08-08, with the data-centre location independently verified on 2026-08-10) and recorded in DPA Annex 3 Part A. The provider is established in an EU Member State and processes within the EU, so no Chapter V transfer instrument is required for this recipient. The executed provider data-processing agreement and the provider's written support and intra-group access geography remain outstanding; this notice does not represent them as held |
| Large-language-model (LLM) API provider (category) | Processes the prompts and completions required for inference | The contracting entity, endpoint region, executed DPA, model-training setting, retention tier and transfer mechanism must be evidenced before the provider is activated. This notice does not represent any LLM provider as active |
| Backblaze, Inc. (United States) — off-host backup storage, as recorded in DPA Annex 3 Part A | Stores the encrypted per-Workspace and fleet backup archives. Archives are encrypted on the host before upload; the repository keys are generated on the host, held root-only, and are never transmitted to the storage provider, which holds ciphertext only and cannot read the archives | Active since 2026-07-31. The storage region recorded in DPA Annex 3 Part A is US West, United States — outside the UK and the EEA. The transfer instrument recorded there is the EU Standard Contractual Clauses, Module Three, with the UK Addendum, as incorporated by the provider's standard data-processing addendum, together with the transfer risk assessment at legal/transfer-risk-assessment-backblaze.md. That addendum has not yet been accepted for this account, and this notice does not represent it as executed. Annex 3 also records a plan to move this repository to an EU bucket; the entity and region stated here are re-verified against DPA Annex 3 Part A immediately before this notice is published |
Optional OAuth gateways, voice providers, messaging channels and the hosted subscription checkout payment provider are not recipients while disabled. Off-host backup storage is not in that group: it is active and is described in the third row of the table above. Where DPA Annex 3 records a recipient's status as unverified rather than disabled, that recipient may already receive the data described for it in Annex 3 and is listed in Section 3 above. Before any disabled service is activated, the Vendor will update the applicable notice and DPA/subprocessor schedule with the account-specific entity, role, location, retention and transfer mechanism, and will complete the corresponding activation evidence.
We do not use Service Data for advertising. Novus Point Limited does not train AI models on Service Data. We may generate aggregated, de-identified technical and usage statistics from the operation of the Service, as permitted by clause 11.5 of the Master Services Agreement and instructed under clause 4.4 of the DPA. The output does not identify the Customer or any individual, and no Workspace content is used to produce it. The configured LLM provider's training and retention settings are contractually fixed and evidenced before that provider is activated (see the DPA, clause 4.4 and Annex 3).
5. International transfers
Workspace hosting. Each Workspace is hosted at the provider and location recorded for that Customer in Section 3B of its Order Form and in Annex 3 to the DPA, after account-specific verification. At the version date that provider is established in Luxembourg and the production data centre is in Frankfurt, Germany (Section 4), so Workspace hosting involves no transfer to a third country and needs no Chapter V instrument. No residency claim is published for an account whose own Order Form record has not yet been completed and verified.
Vendor access from the United Kingdom. Novus Point Limited is established in the United Kingdom and may access Workspaces from the UK for provisioning, support, security and maintenance. Personal data transferred from the EEA to the United Kingdom in connection with this processing relies on the European Commission's adequacy decision for the United Kingdom — Commission Implementing Decision (EU) 2021/1772, its period of application extended to 27 December 2031 by Commission Implementing Decision (EU) 2025/2574 — for as long as such a decision remains in force. If that decision lapses, is suspended or is repealed, the EU Standard Contractual Clauses, Module Two, apply as the fallback recorded in clause 9.2 of the DPA. No other adequacy or clause-based statement is treated as operative without the current evidence and instrument.
Off-host backup archives. Encrypted backup archives are stored outside the UK and the EEA, with the storage subprocessor, in the region and on the transfer instrument recorded in DPA Annex 3 Part A and summarised in Section 4. The archives are encrypted on the host before upload and the storage provider holds ciphertext only, with no key. Encryption does not take the transfer outside Chapter V, which is why an instrument and a transfer risk assessment are recorded for it rather than treated as unnecessary; the provider's own data-processing addendum has not yet been accepted for this account and that acceptance is an open item.
Site data. Site data (Section 2.1) is processed by the third-party provider that serves the Site, which is GitHub Pages (Section 3). Whether that processing occurs inside or outside the UK/EEA, and the applicable safeguard if it occurs outside, are stated in this section once the contracting entity and the provider's data locations are captured from the account record and the provider's published data-protection documentation (see the Section 6.1 Site data row). Until then no location or safeguard is represented as a fact for that route.
Other recipients. No optional recipient outside the UK/EEA may be enabled until the Vendor has documented the exact entity and data route and put in place the applicable safeguard, such as a valid adequacy mechanism, the EU Standard Contractual Clauses and/or the UK Addendum/IDTA, together with the required transfer assessment and supplementary measures. That statement describes recipients recorded as disabled. Where DPA Annex 3 instead records a recipient's status as unverified — at the version date the DNS service, the uptime/heartbeat monitoring service and the operational alerting recipient described in Section 3 — that recipient may already be receiving the data described for it, its contracting entity and country are not yet verified, and no international-transfer safeguard is yet documented for it. Closing those three items is an open priority; none of them receives Workspace content or Service Data. This notice does not claim that a safeguard is operative before that evidence exists. Copies of operative safeguards may be requested through Section 13.
6. Retention
6.1 Controller Data
| Data | Retention period |
|---|---|
| Pre-sales enquiries and prospect data | 24 months after the last substantive contact, unless a shorter period is requested or a longer period is required for a documented legal claim |
| Contract, account and Order Form records | Duration of the contract plus six years, subject to any documented legal hold |
| EULA and Order Form acceptance-audit record | Duration of the contract plus six years, subject to any documented legal hold — the same basis as the contract, account and Order Form records, which this record evidences |
| Billing, invoicing and tax records | Six years from the end of the relevant UK financial year, or longer where law specifically requires it |
| Support and service correspondence | 24 months after ticket closure; material contractual, security or dispute records may be retained with the contract file for up to six years |
| Marketing contact data (applicable only if and when the Section 2.2 marketing purpose is activated — no marketing contact-data processing takes place at the version date) | Until objection or unsubscribe, and otherwise deleted or revalidated after 24 months without engagement; a minimal suppression record may be kept to honour an opt-out |
| Operational hosting telemetry | 90 days. The collector prunes lines older than that on every hourly run, on the server itself. The period is machine-enforced: the collector clamps any operator override to the declared ceiling of 90 days recorded in lem/cloud/telemetry.json. See Section 11.1 |
| Site data | The Site is served by GitHub Pages, a third-party static-site hosting provider that generates request and security logs. Those logs are generated and used only to operate and secure the Site and are not used for advertising or analytics. That provider's specific request/security-log retention period, together with the source URL and the date on which it was checked against the provider's current published data-protection documentation, is stated in this row before this notice is approved for publication; no specific period is asserted in the interim. The Vendor sets no advertising or analytics cookie, maintains no separate advertising or analytics profile, and self-hosts its fonts, so no third-party font request is made |
| Authentication and security data (account identifier, password verifier, encrypted TOTP seed and hashed recovery codes where a second factor is enabled, hashed activation/reset challenges, session identifiers, login timestamps and lockout records) | Retained for the life of the Workspace and deleted with it. Activation and reset challenges are single-use and valid for 10 minutes; recovery codes are held as hashes until use or reset; sessions last up to 7 days with a 24-hour inactivity timeout and are revocable server-side. Annex 2 §6 of the DPA states that backup jobs exclude session files, logs and named secret/auth stores; this notice does not restate that exclusion as a separate claim of its own. Whether every field in this row falls inside it — and, if any does not, under which retention tier of the off-host backup described in Section 6.2 it is held — is confirmed against the live backup allowlist and stated here before this notice is approved for publication |
| Authentication and security audit log — the separate append-only record of authentication and account-security events, for example failed sign-in attempts, lockouts, and privileged or support access to the Workspace, kept apart from the live records in the row above | Retained for the life of the Workspace and deleted with it, subject to the same backup-scope confirmation as the row above |
| Host operational log | Daily rotation, 30 rotations retained |
6.2 Service Data (summary — the DPA governs)
| Data | Retention |
|---|---|
| Workspace content, including the agent's stored message and session history in the Workspace database | Retained within the Customer's isolated Workspace for the duration of the subscription, unless deleted earlier by or at the direction of the Customer |
| Workspace backups | The same-host secondary ZIP code prunes archives older than 14 days and excludes named secrets/runtime stores. The encrypted off-box implementation has daily/weekly/monthly tiers and is held by the off-host backup storage subprocessor, in the region and on the transfer instrument stated in Section 4 and Section 5. Only the exact schedule activated in the Order Form and supported by live run/restore evidence applies; source code is not evidence that a backup exists. Whether or not a tenant-specific retention schedule has been activated, all backup copies containing Customer Personal Data are in any event overwritten or destroyed no later than 400 days after the deletion date, reflecting the Vendor's live daily (14-day), weekly (8-week) and monthly (12-month) restic forget schedule (DPA clause 13.4). That figure is a ceiling rather than a target, and it falls only if the Vendor first shortens its live retention configuration |
| On offboarding | Return or deletion according to the Customer's written election under DPA Clause 13. Active-system expedited erasure targets five Business Days. A completion certificate is issued only after the required local/provider readbacks and separately disclosed backup expiry/lawful-retention evidence; an integrity signature alone does not prove deletion |
Vendor authentication and security records are Controller Data and are excluded from the DPA by Annex 1 §4; their retention is stated in Section 6.1.
7. Security
Each Customer's Workspace is an isolated container with dedicated storage and network boundaries. Exactly one fixed agent_user authenticates with a password, plus TOTP or a recovery code where a second factor is enabled for the workspace; sessions are revocable and bounded. Passwords use a one-way verifier, TOTP seeds are encrypted, and challenge/recovery/session identifiers are hashed. No Customer administrator role, user-management interface or tenant switcher exists. Further technical and organisational measures, and the Vendor's current security-remediation register, are set out in the DPA (clause 6.2 and Annex 2) and are made available to Customers under it. Where an external identity provider is configured for a tenant, authentication for that tenant is performed by that provider under the evidence gate in DPA Annex 3 Part B, and this Section and Section 11 are updated before the first tenant is configured.
8. Your rights
Where the UK GDPR, EU GDPR or equivalent applicable law grants them, you have the following rights in respect of Controller Data, subject to the conditions and exemptions in that law:
- Access (Art. 15) — a copy of your personal data and information about the processing;
- Rectification (Art. 16) — correction of inaccurate or incomplete data;
- Erasure (Art. 17) — deletion, where a ground applies;
- Restriction (Art. 18) — limiting processing in certain circumstances;
- Portability (Art. 20) — receiving data you provided to us in a structured, commonly used, machine-readable format, where processing is based on contract or consent and carried out by automated means;
- Objection (Art. 21) — to processing based on legitimate interests, and at any time and without justification to direct marketing;
- Withdrawal of consent (Art. 7(3)) — where processing is based on consent, without affecting processing before withdrawal.
How to exercise your rights: write to us by post at our registered office (124 City Road, London, England, EC1V 2NX), or by email to jakub@novus-point.com — the address clause 3.1 of the SLA names as the Vendor's support channel and clause 15.4 of the DPA names for notices to the Vendor. That is a general business mailbox, not a dedicated privacy channel, and no response target attaches to it merely because it is published here; a dedicated privacy email address is added here once that mailbox is live (see Section 13). We will respond within one month, extendable by two further months for complex or numerous requests (with notice). We may need to verify your identity before acting. Exercising these rights is free of charge, except that manifestly unfounded or excessive requests may be refused or charged as permitted by law.
Exercise your data subject rights under GDPR through our representative in the Union. We provide you with an easy way to submit a privacy-related request, such as a request to access or erase your personal data. If you want to make use of your data subject rights, please visit our Trust Center: https://app.prighter.com/portal/16315401859 — the request form itself is at https://app.prighter.com/dsr/16315401859. This route is in addition to the postal and email routes above and does not replace them; the response times, verification and charging conditions stated above apply whichever route you use, and quoting ID-16315401859 helps us match your request. A request submitted this way reaches Prighter EU Rep GmbH, our Article 27 representative (Section 13), which receives and forwards it as our processor acting on our instructions; Prighter states that it removes a request from that system 30 days after the request is closed. That statement is Prighter's, published on its own compliance pages, and is not represented here as independently verified by us.
If your data is in Service Data (you are, for example, a correspondent or contact of one of our Customers), the Customer is the controller: please direct your request to the Customer. We will pass on any request we receive and will assist the Customer as required by the DPA.
9. Complaints
You have the right to lodge a complaint with a supervisory authority, in particular in the UK or EEA member state of your habitual residence, place of work, or the place of the alleged infringement:
- United Kingdom: Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF; ico.org.uk; helpline 0303 123 1113.
- Poland: Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stanisława Moniuszki 1A, 00-014 Warszawa; uodo.gov.pl.
- Elsewhere in the EEA: your local supervisory authority.
You may first submit a data-protection complaint through the privacy contact in Section 13. We will acknowledge it within 30 days, investigate it without undue delay, keep you appropriately informed and communicate the outcome without undue delay. We keep a complaint record and do not require you to contact us before complaining to a supervisory authority.
10. Automated decision-making
In our capacity as controller of Controller Data, we do not currently make solely automated decisions that produce legal or similarly significant effects concerning an individual. This statement is made under EU GDPR Article 22 where applicable and the UK automated-decision provisions as amended by the Data (Use and Access) Act 2025. It does not describe or guarantee decisions made independently by a Customer as controller of Service Data.
For the Service, the fail-closed approval control requires a Customer human to authorise outbound email/message actions. The Customer remains responsible for determining whether its wider use of AI Output involves automated decision-making and for implementing any additional safeguards required by law.
11. Cookies, Site analytics and operational telemetry
At the version date, the Vendor does not use advertising or analytics cookies and does not maintain a Site analytics profile. The hosting provider may generate security logs containing IP address, requested URL, timestamp and user agent; exact provider retention remains a publication gate.
The dashboard uses the following browser storage when the user requests the relevant function:
| Technology | Purpose | Duration | Basis (PECR reg. 6 / e-privacy) |
|---|---|---|---|
__Host-lem_session cookie | Authenticated dashboard session; Secure, HttpOnly, SameSite and server-revocable | Up to 7 days, with 24-hour inactivity timeout | Strictly necessary: without it the authenticated session the operator asked for cannot be maintained. No consent is required |
__Host-lem_pending cookie | Carries a pending pre-EULA login between sign-in and acceptance; Secure, HttpOnly, SameSite=Strict | 5 minutes | Strictly necessary: without it the sign-in the operator started cannot be completed. No consent is required |
lemlang cookie | Remembers the language selected by the operator | Up to 1 year | Operator-preference storage, not advertising or analytics. It is set only after the operator actively selects the language, so the Vendor treats it as strictly necessary to deliver the feature just requested |
lemTheme local storage | Remembers the selected dashboard theme | Until the operator clears site data or changes the preference | Operator-preference storage, on the same reasoning as lemlang |
lemcalh local storage | Remembers the operator's calendar display preference | Until the operator clears site data or changes the preference | Operator-preference storage, on the same reasoning as lemlang |
These technologies are not used for advertising or cross-site tracking. The three preference entries are treated as strictly necessary because each is written only in response to a choice the operator has just made, and none is read by any third party; if that characterisation changes, a consent and withdrawal mechanism is implemented before their use continues. Before any analytics, advertising or other non-essential storage is activated, the Vendor will update this notice and implement any PECR/e-privacy consent and withdrawal mechanism required for the actual technology and jurisdiction. Before any tenant is configured with an external identity provider, this table is extended with the identity-provider and bot-protection storage actually set, the third-party origins the login page contacts are named with the purpose of each, and the PECR/e-privacy analysis for any bot-protection script is recorded and implemented.
11.1 Operational hosting telemetry
Separately from the Site and from the browser storage above, the Vendor records host capacity telemetry on the servers that run Customer Workspaces. This is infrastructure monitoring — it is not Site analytics, advertising or profiling. No message, mailbox, calendar, file, transcript or other Workspace content is read, and no behavioural, marketing or scoring profile is built about any individual.
Once an hour the server appends one line per Workspace to a capacity file kept on that server. The only values recorded are: the timestamp of the check; the server's own hostname; how many Workspaces run on it; the server's one-minute load average, RAM used percentage and disk used percentage; the Workspace identifier; and that Workspace container's CPU percentage, memory in use and memory as a percentage of its limit. Nothing else is recorded in that capacity file. The servers' maintenance jobs additionally write a host operational log containing a timestamp, the host label, a Workspace identifier and an operational condition code, and no Workspace content; it rotates daily and 30 rotations are retained.
| Item | Position |
|---|---|
| Purpose | Keeping Workspaces available, sizing each Workspace container's CPU and memory limits, and planning server capacity |
| Legal basis | Article 6(1)(f) legitimate interests — continuity, availability and security of the hosted Service. The legitimate-interests assessment supporting per-Workspace attribution specifically is being finalised and is made available to a supervisory authority on request once recorded; this notice does not represent that balancing test as already performed |
| Retention | 90 days; the collector prunes older lines automatically on every run and clamps any operator override to the declared ceiling of 90 days |
| Storage | The production server's own filesystem, plus the encrypted off-host fleet backup described in Section 6.2, which copies the server's monitoring state and which the storage provider cannot read. Not published, not sold, and not sent unencrypted to any analytics, advertising or other third-party service. Through that backup this data shares the storage subprocessor, region and retention tail stated in Section 4 and Section 5 |
| Attribution | The individual Workspace operator, or the Customer acting on that person's behalf, may object to Workspace-level attribution under Section 8 (Article 21). We honour such objections as a matter of policy; the Article 21 right itself applies subject to the conditions in that Article. Where the objection is upheld, that Workspace is excluded from the per-Workspace lines and only server-wide capacity figures continue, with no effect on the Customer's own service. Objecting is not itself recorded against the Workspace: the server's operational log notes only how many Workspaces were excluded, never which |
The per-Workspace figures are a resource measurement, but because they are recorded hourly they can show when a Workspace is busy. They are not used to draw inferences about any individual; the retention limit and the objection route above exist to keep that residual signal contained.
12. Changes to this notice
We may update this notice from time to time. Material changes — those affecting the purposes, legal bases or retention of Controller Data — will be notified: to Customers through the Service or by email, and to other individuals covered by this notice by email where we hold contact details for the individual concerned, or otherwise by a prominent notice on the Site. Other, non-material updates may be notified through the same channels at our discretion. The "Last updated" date above will be revised. Earlier versions are available on request.
13. Contact
Novus Point Limited, company no. 08146241, registered office: 124 City Road, London, England, EC1V 2NX
Privacy contact. Write to us by post at the registered office above, marked for the attention of "Data Protection", or by email to jakub@novus-point.com — the address clause 3.1 of the SLA names as the Vendor's support channel and clause 15.4 of the DPA names for notices to the Vendor. That address is a general business mailbox rather than a dedicated privacy channel, and publishing it here activates no response target of its own. A dedicated privacy email address is stated here in addition once that mailbox exists, has passed a recorded inbound-delivery and reply test, and has a named owner and deputy. A privacy-related request may also be submitted through our representative in the Union, at the Trust Center named below; that route is offered in addition to the postal and email routes in this paragraph and in Section 8, and does not replace either.
Data Protection Officer. The Article 37(1) criteria were assessed on 2026-08-10 (assessment record owner-assessment:2026-08-10-art37-dpo-not-designated). No mandatory trigger is met, and no Data Protection Officer is designated, whether by obligation or voluntarily. The privacy contact given above is an ordinary controller contact and is not a Data Protection Officer within the meaning of Article 37; nothing in this notice designates one. The assessment record is made available to a supervisory authority on request, and the assessment is repeated if the processing changes materially.
Representative in the Union (Article 27 EU GDPR). Our representative in the Union under Article 27 EU GDPR is Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Vienna, Austria. Novus Point Limited is established in the United Kingdom, outside the EU/EEA, and appointed that representative in writing on 2026-08-17 pursuant to Article 27 GDPR. The representative is established in the EU-27 and may be addressed, in addition to or instead of the Vendor, by supervisory authorities and data subjects on all issues related to the processing of personal data described in this notice, for the purposes of ensuring compliance with the GDPR. The appointment is made under Prighter's Letter of Appointment and is delivered through the Prighter Group representation service described below.
- Representative: Prighter EU Rep GmbH
- Address: Schellinggasse 3/10, 1010 Vienna, Austria
- Contact: app.prighter.com/portal/16315401859 — please quote ID-16315401859 in all correspondence
- Data subject requests: the same Trust Center, https://app.prighter.com/portal/16315401859 (request form: https://app.prighter.com/dsr/16315401859), in addition to the postal and email routes in Section 8
We value your privacy and your rights as a data subject and have therefore appointed Prighter Group with its local partners as our privacy representative and your point of contact for the following regions:
- European Union (EU)
Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative, Prighter, or make use of your data subject rights, please visit the following website: https://app.prighter.com/portal/16315401859
The appointment follows the Article 27 assessment of 2026-08-10 (assessment record owner-assessment:2026-08-10-art27-eu-representative-required). Article 3(2) EU GDPR is engaged by the processing described in this notice — including this notice's own EEA-facing content, the supervisory-authority entry for Poland in Section 9, the "Elsewhere in the EEA" route and the Polish election in Annex 4 of the DPA — and the Article 27(2) "occasional processing" exemption is not available. A representative does not displace the Vendor's own obligations or liability under this notice.
For Customers: requests concerning Service Data, subprocessor notices and DPA matters should be raised through the channels defined in the DPA and the Order Form.