limapoint.ai Contact us
Limapoint | Privacy (combined preview)

Legal · Privacy

Privacy notice

How Limapoint handles personal data and customer material across scope sessions, engagements and the platform itself. The same governance we apply to your artifacts applies to your data: a named owner, a retained record, and a traceable change.

DOC-PRIV-03 Effective 1 September 2026 Supersedes DOC-PRIV-02

01 · Controller

Who is responsible

Limapoint is the controller for data we collect about prospects, clients and site visitors, and a processor when we handle personal data inside a client’s own artifacts during an engagement. Which role applies is recorded in the engagement agreement before work starts.

Questions, requests and complaints go to privacy@limapoint.ai. A named privacy owner is accountable for every response, in the same way a named approver is accountable for every artifact.

02 · Scope

What we collect

  • CONTACTIdentity and contact detailsName, role, employer, email and phone, given when you book a scope session or correspond with us.
  • ENGAGEEngagement materialDocuments, models, tickets and specifications you share so we can trace one initiative. These may contain personal data belonging to your staff or customers.
  • USAGEPlatform and site usageAuthentication events, artifact history, approvals, and aggregate page metrics. Approval records are deliberately attributable — that is the product.
  • TECHTechnical dataIP address, device and browser type, and error diagnostics captured when something fails.

03 · Purpose

Why we process it

We process personal data to respond to enquiries, run scope sessions and engagements, operate and secure the platform, maintain the traceability and approval records our clients rely on, meet legal and accounting obligations, and improve the product.

Our lawful bases are contract performance for engagement delivery, legitimate interests for security, service improvement and business correspondence, consent where you opt into marketing, and legal obligation for statutory records. We do not sell personal data and do not use client engagement material to train third-party models.

04 · Recipients

Who we share it with

We share personal data with sub-processors that host, secure and support the platform, with professional advisers where necessary, and with authorities where the law requires it. Each sub-processor is under a written agreement with confidentiality, security and audit terms, and the current list is available on request.

  • HOSTInfrastructure and hostingCloud regions agreed with you in advance; dedicated, hybrid or on-premise deployments are available where your risk model requires them.
  • SUPPSupport toolingTicketing, email and observability providers, limited to what is needed to operate the service.

05 · Location

Where data is held

Data residency is fixed per engagement and recorded before onboarding. Where personal data leaves its home jurisdiction, we rely on adequacy decisions or standard contractual clauses together with a transfer risk assessment, and we can keep processing entirely within your chosen region on request.

06 · Retention

How long we keep it

Enquiry correspondence is kept for 24 months from last contact. Engagement material is kept for the term of the agreement and then returned or deleted within 90 days, unless you ask us to retain it for a follow-on phase. Approval and version records are retained for the period stated in the engagement agreement, because their evidential value depends on being complete. Statutory financial records are kept for the period the law requires.

07 · Security

How we protect it

Access is least-privilege and individually attributable, transport and storage are encrypted, changes to production are reviewed, and access to client material is logged. Personnel are bound by confidentiality obligations and receive role-appropriate security training. If a breach affects your data, we notify you without undue delay with what we know, what we are doing, and what we need from you.

08 · Rights

Your rights and choices

Depending on where you live, you may have rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent or complain to your supervisory authority. Marketing emails carry an unsubscribe link in every message; withdrawing consent does not affect service correspondence.

This notice is versioned. When it changes materially we update the version identifier, publish the effective date, and notify active clients in writing.

Exercising your rights

Write to our privacy team to access, correct, export or erase personal data, or to object to a processing activity. We acknowledge within five working days and respond substantively within one month. If we act as processor for your employer, we route the request to that controller and tell you we have done so.