Lemric Privacy Policy
Effective date: 4 August 2026
1. Scope and roles
This Policy describes processing concerning people who use lemric.io, a Lemric account and marketing pages, or contact Lemric. The Lemric entity identified in the order, subscription confirmation or invoice is the controller of that data.
Data placed in an organisation’s requests, forms and help centre is generally processed by Lemric on that organisation’s behalf. The organisation is then the controller and Lemric is the processor under the DPA.
2. Categories of data
We may process account and contact data such as email address, first and last name, language and organisation; authentication and security data; subscription and payment information; correspondence; and technical data including IP address, session identifiers, device type, security events and audit logs.
We do not store full payment-card details when payment is handled by an external provider. Users and their organisation determine request content; unnecessary data or special-category data should not be submitted unless required and agreed.
3. Purposes and legal bases
Data is processed to enter into and perform an agreement, operate accounts, subscriptions and support; comply with tax and accounting duties; secure the service, prevent abuse and maintain audit trails; establish or defend legal claims; and provide marketing communications where consent is required or an opt-out right applies.
The legal basis is, as applicable, performance of a contract or pre-contract steps, a legal obligation, legitimate interests in securing and improving the service, or consent. Consent may be withdrawn without affecting earlier processing.
4. Recipients and processors
Access is limited to authorised personnel and providers needed for hosting, email delivery, monitoring, payments, customer support and professional advice. Providers receive only the data needed for their function and are bound by appropriate confidentiality and data-protection obligations.
The current subprocessor list is made available to the Customer with subscription documentation or on request.
5. Transfers outside the EEA
Where data is transferred outside the European Economic Area, Lemric uses a GDPR transfer mechanism, in particular an adequacy decision or Standard Contractual Clauses with required supplementary measures. Information about the applicable mechanism is available through the contact below.
6. Retention
Account data is retained while the account is active and for the period needed for billing, claims and legal duties. Security data and logs are retained for a period proportionate to risk and audit purpose. Marketing data is processed until consent is withdrawn or a valid objection is made.
The exact period may depend on the plan, organisation retention configuration and record type. At the end of the period, data is deleted or irreversibly anonymised.
7. Individual rights
Depending on the legal basis and circumstances, individuals may have rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent. They may complain to the competent supervisory authority. We may verify identity and authority before fulfilling a request.
For request data controlled by an organisation, individuals should first contact that organisation. Lemric assists it with rights requests under the DPA.
8. Security
We apply least-privilege access, tenant isolation, encryption in transit and encryption of selected database data, privileged-operation logging, abuse limits, backups and incident-response procedures. No system eliminates all risk, so safeguards are reviewed and adjusted regularly.
9. Cookies
Essential cookies maintain sessions, protect forms and remember settings. Analytics or marketing technologies not necessary for the service are activated only in line with applicable consent requirements.
10. Contact and changes
Privacy questions and requests may be sent to privacy@lemric.io. The controller’s legal identity and address applicable to an agreement are included in the order and billing documents.
This Policy may be updated for changes in law, technology or service scope. Material changes will be notified in the service or by email.