Home / Legal / Privacy Policy

Privacy Policy

Last updated July 17, 2026

Terms of ServicePrivacy PolicyCookie PolicyAcceptable UseData ProcessingSubprocessorsDisclaimer
These terms govern the Limen Systems website and evaluation materials. For a paid engagement, the separately executed agreement controls. This is not legal advice.

This Privacy Policy explains how Limen Systems Holdings, Inc. ("Limen," "we," "us," or "our") collects, uses, shares and protects personal data in connection with our website at limen.io, our briefings, and our evaluation materials (together, the "Website"). It is written to satisfy the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA"), and comparable laws. Key takeaways:

  • We minimise by design. The Website collects little, and we ask you not to paste confidential third-party data into free-text fields.
  • Your operational data does not run through us. When the Limen product is deployed, it runs inside your own perimeter (VPC or air-gapped); customer operational data is not sent to Limen and is governed by your contract and our Data Processing Addendum, not this policy.
  • Analytics are consent-gated. Google Analytics 4 and PostHog run only after you accept analytics cookies in our banner; decline and they stay off.
  • We do not sell or "share" your personal information as those terms are defined under the CCPA/CPRA, and we honour Global Privacy Control signals.
  • You have rights to access, correct, delete, port, object to, and restrict processing of your data. Contact hello@limensystems.com.
For how the platform keeps data inside your boundary, see security and sovereignty.

Our approach: data minimisation and in-perimeter processing

Our privacy posture follows the same principle as our product: data should not travel further than it must. We collect the smallest amount of personal data needed to run an informative website and to arrange briefings with qualified organisations, and we design our systems to hold as little as possible for as short a time as possible.
The distinction that matters most is between the Website and the product. This policy governs the Website only. When the Limen platform is deployed for a customer, it runs inside that customer's own perimeter, their virtual private cloud or a fully air-gapped environment, with personally identifying data masked or tokenised before it reaches any model. Customer operational data is not transmitted to Limen, is not processed on our infrastructure, and is not covered by this policy; it is governed by the master agreement and the Data Processing Addendum between Limen and the customer. See how the platform works and how ownership works.

Who we are and the scope of this policy

The data controller for personal data collected through the Website is Limen Systems Holdings, Inc. For personal data processed on behalf of a customer through a product deployment, the customer is the controller and Limen is a processor (or, in in-perimeter and air-gapped deployments, does not process that data outside the customer's boundary at all).
This policy applies to visitors to limen.io, people who request or attend a briefing, recipients of our business communications, and those who correspond with us. It does not apply to third-party websites we link to, which have their own policies.

Information we collect

We collect two kinds of information: what you give us, and what is collected automatically when you use the Website.
Information you provide. When you request a briefing or otherwise contact us, we collect your name, work email address, organisation, role, and any details you choose to include in free-text fields (for example, the workflow or systems you want to discuss). We ask that you do not include confidential, privileged, or third-party personal data in these fields. We also keep records of our correspondence with you.
Information collected automatically. When you visit the Website, our servers and our analytics providers may collect your IP address (which we and our providers may truncate or treat as pseudonymous), device and browser type, operating system, referring URL, the pages and links you interact with, approximate location derived from IP, timestamps, and similar diagnostic data. This is collected through cookies and similar technologies as described in our Cookie Policy, and, for non-essential analytics, only after you consent.
Analytics identifiers. Where you have accepted analytics cookies, Google Analytics 4 (GA4) sets pseudonymous client and session identifiers (for example, in the _ga and _ga_<container-id> cookies), and PostHog assigns a pseudonymous "distinct ID" (stored in a ph_<project-key>_posthog cookie) and captures product-analytics events, including autocapture of interface interactions such as clicks, navigation and form submissions, together with associated device and session metadata. We do not enable PostHog session replay on the Website. These identifiers are pseudonymous and are not used to build advertising profiles.
We do not intentionally collect special-category data through the Website, and we ask you not to submit it.

Cookies, analytics and product telemetry

The Website uses strictly necessary cookies to function, and, only with your consent, analytics cookies from Google Analytics 4 and product-analytics cookies from PostHog. Our cookie-consent banner lets you accept or reject non-essential cookies before they are set, and Google Consent Mode v2 is configured so that Google storage stays denied until you consent (advertising storage remains denied at all times).
For the full list of cookies, including _ga, _ga_*, ph_* and the consent record, their providers, purposes and durations, and for instructions on changing or withdrawing consent, please read our Cookie Policy.

How we share information: service providers and subprocessors

We do not sell your personal data. We share it only in limited, described circumstances.
Service providers (processors). We use vetted vendors to run the Website and our operations, each bound by contract to process personal data only on our instructions and to protect it. These include our website hosting and content-delivery provider, Google (Google Analytics 4) for aggregate web analytics, PostHog for product analytics, our email and business-productivity provider, and our customer-relationship and communications tools.
Legal and protective disclosures. We may disclose personal data where required by law, court order, or regulator, or where necessary to establish, exercise, or defend legal claims, prevent fraud or abuse, or protect the rights, safety, and security of Limen, our users, and the public.
Corporate transactions. If Limen is involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction, subject to this policy and applicable law.
For product deployments, the applicable subprocessors are set out in the Data Processing Addendum; because deployments run inside the customer's perimeter, the subprocessor footprint for operational data is deliberately minimal.

International data transfers

Limen is based in the United States, and some of our service providers, including Google and PostHog, process data in the United States. When personal data is transferred out of the European Economic Area, the United Kingdom, or Switzerland, we put in place a lawful transfer mechanism.
For transfers to our providers and to us, we rely on the European Commission's Standard Contractual Clauses (SCCs), supplemented for UK transfers by the UK International Data Transfer Addendum, and by the Swiss addendum where relevant, together with any additional safeguards required after a transfer-impact assessment. Where a provider is certified under the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions), we may also rely on that certification. You can request more information about the safeguards we use by writing to hello@limensystems.com.

How long we keep your information

We keep personal data only for as long as necessary for the purposes described above, then delete or anonymise it.
  • Briefing and enquiry data: retained for the duration of our discussions and for up to 24 months after our last meaningful contact, unless a longer period is required to manage an active relationship or meet a legal obligation.
  • Server and security logs: retained for a short period, typically up to 90 days, then rotated.
  • Analytics data: GA4 event data is retained for a limited window (we configure retention at the shortest practical setting), and PostHog product-analytics data is retained under our configured retention policy; both hold pseudonymous rather than directly identifying data.
  • Records we must keep by law (for example, accounting records) are retained for the statutory period.

Your privacy rights

Depending on where you live, you have some or all of the following rights, and we will not discriminate against you for exercising them.
Under the GDPR and UK GDPR, you may request access to your personal data; rectification of inaccurate data; erasure; restriction of processing; data portability; and you may object to processing based on our legitimate interests and withdraw consent at any time. You also have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office; in the EU, your national data-protection authority), though we ask that you contact us first so we can help.
Under the CCPA/CPRA, California residents have the right to know what personal information we collect and how we use and disclose it; to access and delete it; to correct inaccurate information; and to opt out of the "sale" or "sharing" of personal information and to limit the use of sensitive personal information. Limen does not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use sensitive personal information for purposes that would trigger the right to limit. We honour opt-out preference signals, including the Global Privacy Control (GPC), as a valid request to opt out.
To exercise any right, email hello@limensystems.com. We will verify your request, respond within the timeframes required by law (generally one month under the GDPR and 45 days under the CCPA, each extendable where permitted), and you may use an authorised agent where the law allows.

How we protect your information

We use technical and organisational measures appropriate to the sensitivity of the data we hold: encryption of data in transit (TLS) and at rest, access controls on a least-privilege basis, multi-factor authentication for administrative access, network and application security controls, logging and monitoring, vendor due diligence, and an incident-response process.
We are an early-stage company building toward SOC 2 and ISO/IEC 27001 alignment, with sector-specific controls layered on for product deployments; we will not overstate our current certification status. No method of transmission or storage is perfectly secure, but we work continuously to protect personal data and to limit how much of it we hold in the first place.

Children's privacy

The Website is intended for business users and is not directed to children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, contact hello@limensystems.com and we will delete it.

Changes to this policy

We may update this policy to reflect changes in our practices, technology, or the law. When we make material changes, we will update the "last updated" date above and, where appropriate, provide additional notice. Your continued use of the Website after an update means you accept the revised policy.

Contact us and data protection contact

For any question about this policy or to exercise your rights, contact our privacy team at hello@limensystems.com. This mailbox also serves as our data-protection point of contact; if we are required to appoint a Data Protection Officer or an EU/UK Article 27 representative, we will identify them here.
You can also reach us by post at Limen Systems Holdings, Inc. General legal questions may be directed to hello@limensystems.com, and security matters to hello@limensystems.com.

Questions about this document: hello@limensystems.com