Frequently asked questions
These answers describe how the product works and point at the document that governs each subject. They are a summary, not a contract.
One thing to read first. These answers are a summary of the published pages and of your executed contract set; where they disagree, the contract set wins. Read the linked page for the full text, and read your executed contract set before you rely on either.
What controls the paid relationship is the frozen contract set named in the Contract Execution Manifest: your Order Form (executed by recorded click acceptance of the versioned contract pack at first workspace activation) first, then the DPA, the Master Services Agreement, the Voice Add-On Addendum (where enabled), the EULA, the SLA, the Acceptable Use Policy and the Refund Policy. Under clause 2.5 of the Master Services Agreement, the website Terms, Privacy Notice, AI Transparency Notice, support page and this documentation are notices or information only and do not form part of the Agreement.
Several of the levels described below — availability measurement, service credits, support response targets and the backup retention guarantee — are not yet activated even in the draft. The Service Levels page lists exactly which ones, in its activation table.
The safe way to use this page: read it to understand what to ask for, then ask for the executed contract set and check the answer there before you accept.
1. Where is my data stored?
In a workspace dedicated to you: your own container, your own storage volume, your own network boundary. Nothing is shared with another customer.
The Privacy page does not publish a hosting provider or a region as a general claim. It states that each workspace is hosted in the provider and location recorded for that customer after account-specific verification, and that no residency claim is published before that evidence is complete. The Service Levels page says the same thing from the infrastructure side.
What this means for you: ask for your workspace's provider and region during onboarding and have it written into your Order Form. If a region has been recorded, your dashboard shows it as Data region at the top of the Today page. If that badge is absent, no region has been recorded for you.
Novus Point Limited is established in the United Kingdom and may access workspaces from the UK.
2. Who can see my data?
Two parties can: you, and the vendor. Be clear-eyed about the second.
On your side: one account. There is no administrator role, no second seat, no invitations and no tenant switcher. Within the customer side of the product, whoever holds your password (and authenticator, where a second factor is enabled) can see everything in the workspace, and no other customer account exists.
On the vendor's side: Novus Point Limited holds standing administrative access to the hosts that run workspaces. That access uses a separate principal, credential store, cookie and session policy from your account; it exists continuously and does not depend on you granting it. The technical and organisational measures that govern it, the controls the vendor commits to, and the vendor's current security-remediation register are set out in the Data Processing Agreement and are made available to customers under it. The DPA is where this is stated authoritatively, and it reaches you under the confidentiality terms of the agreement rather than on a public page.
What to do about it before you accept. The DPA's security schedule requires a tenant evidence pack, completed before the contract is executed, that identifies every administrator, the authentication and device/key controls, the private exposure boundary, the access log, the review interval and the emergency-access procedure. Ask for the completed pack for your tenancy, read the named-administrator and access-log sections, and have the answers written into your Order Form before you accept. Treat this as a gating item in your due diligence, not a detail to confirm later. A general assurance that access is "restricted to authorised personnel" is not the same thing.
Third parties: the workspace runs on an infrastructure hosting provider and sends prompts and completions to a large-language-model API provider. The authoritative, contractually binding list of subprocessors is in the DPA, along with the mechanism for objecting to a change. The published Privacy page deliberately names no specific provider until that evidence exists, so do not read a provider name into it.
Optional gateways, voice providers, messaging channels and off-box backup or monitoring services are not recipients of your data while they are switched off.
3. Is my data used to train AI models?
Two separate questions, with two separate answers.
Does Novus Point train models on your data? No. The Privacy page states: "Novus Point Limited does not train AI models on Service Data." The AI Transparency notice puts it as: "The Vendor does not intentionally use Customer content to train its own models."
Does the model provider train on your data? The published pages do not answer this in general terms. Privacy states that the configured provider's training and retention settings are contractually fixed and evidenced before that provider is activated. AI Transparency states that no statement about an upstream provider's training, retention, region or transfer mechanism is made until account-specific configuration readback and contract evidence are filed.
What this means for you: get the provider's configured training and retention settings recorded for your workspace, in writing, before you go live. Do not accept a general assurance; the documents themselves decline to give one.
4. What happens if I lose my authenticator device?
This question only arises where your Order Form records the second factor (TOTP) as Enabled — a password-only workspace, the default, has no authenticator device and no recovery codes.
Where it is enabled: use a recovery code. On the sign-in page press Use a recovery code, enter your password and one of the ten codes you saved during activation. Each code works once.
Then contact support immediately and ask to be re-enrolled on a new device. Do not carry on with a dwindling stack of codes.
If you have lost the codes as well, nobody can recover them for you. They are stored only as one-way hashes. The only route back is a manual re-enrolment by the LEM team, which requires them to verify who you are. Contact support and expect this to take longer than a self-serve reset would.
The safest arrangement is: password in your password manager, recovery codes in a different place, authenticator on a device you control.
5. How do I export my data?
Press ⬇ Export my data at the top of the Today page. The download starts straight away — no request, no queue, no waiting for the LEM team.
What you are owed. Clause 13.1 of the Data Processing Agreement defines the
archive as a fixed, reviewed allowlist of customer data: a transactionally
consistent snapshot of the workspace database (including message history and
search indices), the commitments database where present, your workspace
configuration files, and your content under the personas, drafts, context, vault,
memory, skills, scheduled-task and kanban roots. It excludes credentials and
.env files, dashboard authentication material, raw session files, logs,
backups, provider and runtime data, and vendor libraries. Every archive carries a
file-and-hash manifest and must pass archive, database-integrity and SHA-256
self-checks.
Read the manifest, not this page. The manifest.json at the root of your zip
is the authoritative statement of what your download actually contains. If
something you expected is not listed in it, raise that with support in writing,
quoting clause 13.1.
An in-term export is taken from a running workspace: the databases are captured consistently, other files are copied live and may be marginally inconsistent. The end-of-term export under clause 13.2 is generated from a stopped workspace and is the authoritative copy.
The Service Levels page also encourages periodic exports of business-critical content, and treats export as independent of backups. The published documents do not commit to a particular export format or a turnaround time for a vendor-produced export, so if you need something beyond the self-service zip — a specific schema, or a certified extract — agree it in the Order Form. Clause 10 of the DPA covers additional export assistance on request.
6. How do I delete my data?
Delete individual items yourself in the workspace, or ask LEM to.
To delete everything, tell the vendor in writing. The Privacy page states that on offboarding, data is returned or deleted according to your written election under the DPA, with an expedited erasure target of five Business Days for active systems, and that a deletion certificate is issued only after the required local and provider readbacks and backup expiry or lawful-retention evidence.
The Refund Policy sets out the sequence: the workspace is stopped and a final snapshot taken, you get a 30-day grace period in which you can export your data and in which offboarding is reversible, and after that the hard-deletion process runs. The final Deletion Certificate follows the readbacks and an independent completion review.
If you need erasure without waiting out the grace period — including to satisfy a GDPR obligation — you can elect that in writing.
7. What is the uptime commitment?
Today, there is no active availability commitment. That is the honest answer and it is what the Service Levels page says.
The detail:
- The stated target is a Monthly Uptime Percentage of 99.5% per calendar month for your workspace.
- Service credits are not active. They only start from the later of (a) the first full calendar month after a 90-day stabilisation period following your first paid activation, and (b) an SLA Activation Date written into an executed Order Form. They do not switch on by the passage of time.
- External uptime measurement is not activated. The current in-container health monitoring is an operational diagnostic and does not calculate the Monthly Uptime Percentage.
- The backup target — one integrity-verified backup per workspace per day, retained at least 14×24 hours — is not yet a binding guarantee.
- There is no guaranteed recovery point for loss of the host until off-box backup is active, and the service does not run multi-region or automatic failover.
The operational practices the SLA does describe are: updates go out canary-first; maintenance expected to cause material downtime carries at least 48 hours' notice with the expected duration stated; and breaking changes carry at least 14 days' notice — except where a security vulnerability, a legal requirement or a change imposed by a third-party provider forces a shorter period, in which case the vendor gives as much notice as is practicable and explains the constraint. None of these is unconditional: clause 1.2 makes every level in the SLA a good-faith target unless it is expressly stated to be binding and has been activated in an executed Order Form.
What this means for you: if you need a contractual availability number, it has to be activated in your Order Form after the evidence gates in the SLA are closed. Ask where those gates stand before you accept.
8. How do I get support, and how fast?
Channel. Email. Your support address is shown on Settings → Account and services under Support, and it is stated in your Order Form. If that row still reads Assigned during account launch, use the address in your Order Form. The published Support page lists the current inbox. Support is provided in English.
Hours. 09:00–17:00 UK time on business days (excluding weekends and English public holidays). A request received outside those hours counts as received at 09:00 on the next business day.
Speed. The planned baseline is a first response by the end of the next business day. The Service Levels page also lists priority targets — 4 business hours for P1 Critical, 1 business day for P2 Major, end of next business day for P3 Minor — but is explicit that anything shorter than the end-of-next-business-day baseline is an operational target only, and that no support target is binding until it is activated in an executed Order Form. A First Response is defined as a substantive human acknowledgement — an automated receipt does not count, and neither does a holding reply that engages with nothing.
During onboarding. Where your Order Form includes it, a 30-day hypercare period applies a faster update cadence to everything you report, regardless of priority.
Out of scope. Faults inside the third-party services you have connected, and training or consultancy beyond what your Order Form covers.
9. What happens when I cancel?
You can cancel at any time, without giving a reason, in writing to the vendor or through a cancellation control in the dashboard where one is available. There is no minimum term beyond the billing period you are in, unless your Order Form says otherwise.
Cancellation takes effect at the end of the billing period you are in when the notice arrives. You are not charged for the next one. Outside the refund window, fees for a billing period that has already started are not refundable in whole or in part.
Then: the workspace stops, a final snapshot is taken, you have a 30-day grace period to export your data, and after that the deletion process runs (see question 6).
Refunds. There is a 14-day refund window running from your Activation Date — the date your workspace is first made available for productive use, as recorded by the vendor and confirmed to you in writing.
The deadline is exact: 23:59 UK time on the calendar date 13 days after the Activation Date. That is fourteen calendar dates counting the Activation Date itself. Notice must be in writing, through the tested support address stated in your Order Form. Notice sent in time counts even if it is processed later, and a channel outage that is the vendor's fault does not shorten the window. Put the date in your calendar on day one.
The window applies once only, to the first subscription term of your first workspace. It does not cover renewals, subsequent billing periods, additional workspaces, re-subscriptions after a prior cancellation, tier upgrades, or add-ons activated after the first subscription term.
The onboarding fee is fully refundable before install day; after that, only the reasonable earned portion and identified non-cancellable costs may be retained. LEM is sold to incorporated businesses only, so no consumer cooling-off right applies. Read the Refund Policy in full before relying on any of this.
The vendor can also end the arrangement, on at least 30 days' written notice effective at the end of a billing period.
10. Can LEM send email on my behalf without asking?
No. Anything outbound is written as a draft and waits in Inbox → Drafts for you to approve it. The AI Transparency notice describes this as a fail-closed approval control: gated email or message content is not sent without a human decision, and the gate records a bounded, redacted action summary, the reviewer's identity, the decision time and a digest of the payload.
Two caveats, both stated in that notice.
The digest's binding force is not yet evidenced. The notice requires release evidence proving that the recorded digest actually binds the decision to the action that was executed, and that later mutation of the payload is rejected. That evidence is listed as outstanding. Until it is produced, treat the approval record as an operational log rather than as proof that what was sent is what you approved.
Approval is a control, not a guarantee. It does not make the output accurate, and it does not move responsibility for the content away from you. The notice is explicit that before approving you must open and review the full draft in its source surface — the dashboard shows only the opening ~400 characters — and verify the recipient and any material external effect.
More generally, AI output is probabilistic. It can be inaccurate, incomplete, out of date, fabricated, biased or inconsistent, and a plausible-looking answer is not evidence that its facts, figures, citations or calculations are right. It is not legal, tax, accounting, financial or medical advice. Verify every material output before you rely on it.
11. Can I add a second user, or an admin?
No. Version 1 is a single-operator product: one account per workspace, one workspace per customer. There is no administrator role, no invitations, no role management and no tenant switcher. Sharing an account, reselling access or running the workspace as a service for others is prohibited by the Acceptable Use Policy.
If you need more than one person working in LEM, raise it during onboarding rather than sharing credentials.
Still stuck?
- Something is broken → Troubleshooting
- You are not sure how a screen works → User guide
- Anything else → the support address on Settings, or in your Order Form.