These terms govern the Limen Systems website and evaluation materials. For a paid engagement, the separately executed agreement controls. This is not legal advice.
This Privacy Policy explains how Limen Systems Holdings, Inc. ("Limen," "we," "us," or "our") collects, uses, shares and protects personal data in connection with our website at limen.io, our briefings, and our evaluation materials (together, the "Website"). It is written to satisfy the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA"), and comparable laws. Key takeaways:
.
Our approach: data minimisation and in-perimeter processing
Our privacy posture follows the same principle as our product: data should not travel further than it must. We collect the smallest amount of personal data needed to run an informative website and to arrange briefings with qualified organisations, and we design our systems to hold as little as possible for as short a time as possible.
The distinction that matters most is between the Website and the product. This policy governs the Website only. When the Limen platform is deployed for a customer, it runs
inside that customer's own perimeter, their virtual private cloud or a fully air-gapped environment, with personally identifying data masked or tokenised before it reaches any model. Customer operational data is not transmitted to Limen, is not processed on our infrastructure, and is not covered by this policy; it is governed by the master agreement and the
Data Processing Addendum between Limen and the customer. See
how the platform works and
how ownership works.
Who we are and the scope of this policy
The data controller for personal data collected through the Website is Limen Systems Holdings, Inc. For personal data processed on behalf of a customer through a product deployment, the customer is the controller and Limen is a processor (or, in in-perimeter and air-gapped deployments, does not process that data outside the customer's boundary at all).
This policy applies to visitors to limen.io, people who request or attend a briefing, recipients of our business communications, and those who correspond with us. It does not apply to third-party websites we link to, which have their own policies.
Cookies, analytics and product telemetry
The Website uses strictly necessary cookies to function, and, only with your consent, analytics cookies from Google Analytics 4 and product-analytics cookies from PostHog. Our cookie-consent banner lets you accept or reject non-essential cookies before they are set, and Google Consent Mode v2 is configured so that Google storage stays denied until you consent (advertising storage remains denied at all times).
For the full list of cookies, including
_ga,
_ga_*,
ph_* and the consent record, their providers, purposes and durations, and for instructions on changing or withdrawing consent, please read our
Cookie Policy.
International data transfers
Limen is based in the United States, and some of our service providers, including Google and PostHog, process data in the United States. When personal data is transferred out of the European Economic Area, the United Kingdom, or Switzerland, we put in place a lawful transfer mechanism.
For transfers to our providers and to us, we rely on the European Commission's
Standard Contractual Clauses (SCCs), supplemented for UK transfers by the UK International Data Transfer Addendum, and by the Swiss addendum where relevant, together with any additional safeguards required after a transfer-impact assessment. Where a provider is certified under the
EU-U.S. Data Privacy Framework (and its UK and Swiss extensions), we may also rely on that certification. You can request more information about the safeguards we use by writing to
hello@limensystems.com.
Your privacy rights
Depending on where you live, you have some or all of the following rights, and we will not discriminate against you for exercising them.
Under the GDPR and UK GDPR, you may request access to your personal data; rectification of inaccurate data; erasure; restriction of processing; data portability; and you may object to processing based on our legitimate interests and withdraw consent at any time. You also have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office; in the EU, your national data-protection authority), though we ask that you contact us first so we can help.
Under the CCPA/CPRA, California residents have the right to know what personal information we collect and how we use and disclose it; to access and delete it; to correct inaccurate information; and to opt out of the "sale" or "sharing" of personal information and to limit the use of sensitive personal information. Limen does not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use sensitive personal information for purposes that would trigger the right to limit. We honour opt-out preference signals, including the Global Privacy Control (GPC), as a valid request to opt out.
To exercise any right, email
hello@limensystems.com. We will verify your request, respond within the timeframes required by law (generally one month under the GDPR and 45 days under the CCPA, each extendable where permitted), and you may use an authorised agent where the law allows.
Children's privacy
The Website is intended for business users and is not directed to children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, contact
hello@limensystems.com and we will delete it.
Changes to this policy
We may update this policy to reflect changes in our practices, technology, or the law. When we make material changes, we will update the "last updated" date above and, where appropriate, provide additional notice. Your continued use of the Website after an update means you accept the revised policy.