Lemric Privacy Policy
Release 1 · Published 6 August 2026, 16:23
Effective from: sixth August two thousand twenty six
1. Who is responsible
Lemric Dominik Łabudziński, a sole trader with the address Weteranów 74/3, 05 250 Radzymin, Poland, Polish tax identification number 5272448444 and statistical number 141491900, is the controller for data used to manage Lemric accounts, contracts, billing, security, direct contact and the lemric.com website.
When a Customer places personal data in its help centre, portal, forms, requests, attachments, workflows or integrations, the Customer decides the purposes and means of that processing. Lemric then acts as processor under the DPA. People whose data appears in Customer content should normally contact that Customer first.
This service is offered only to businesses and other organisations. Personal data of their representatives, staff, customers and requesters may still be processed.
2. Data processed as controller
Depending on how a person uses Lemric, controller data may include:
- name, electronic mail address, language, organisation, role and contact details
- account identifiers, password hashes, authentication methods, multifactor authentication records, session identifiers and permission history
- order, subscription, billing, payment status and billing correspondence
- messages sent to Lemric, complaints, privacy requests and support correspondence
- IP address, browser and device information, request time, security events, rate limit records and audit records
- internal help centre search queries, selected results and article feedback
- cookie choices and browser preferences described below
Full card data is not stored by Lemric when an external payment provider handles the transaction.
3. Data processed for Customers
Customer content may include names, electronic mail addresses, organisation and job details, portal accounts, request subjects and messages, form answers, attachments, internal notes, participants, activity history, service level events, audit information, Jira references and webhook payloads selected by the Customer.
The Customer controls the scope of this data. Special categories of data and data about criminal convictions should not be entered unless the Customer has established that the processing is necessary, lawful and covered by suitable safeguards.
4. Purposes and legal bases
Lemric processes controller data to:
- take steps requested before an agreement and perform an agreement
- create accounts, verify access and provide requested support
- administer subscriptions, payments and billing
- comply with accounting, tax and other legal duties
- secure the service, prevent abuse, investigate incidents and maintain evidence
- handle correspondence, complaints and legal claims
- improve help content using internal search and feedback information
- send information about Lemric where permitted by law
The legal basis is performance of an agreement where the person is a party, a legal obligation, consent where required, or legitimate interests. Those interests include providing a business service, contacting Customer representatives, securing systems, preventing misuse, improving help content and establishing or defending claims. A person may object to processing based on legitimate interests. Consent can be withdrawn at any time without affecting earlier processing.
5. Sources
Data comes from the person, the Customer they represent, other authorised organisation members, systems connected by the Customer and technical records created when the service is used. Payment and billing providers may return transaction identifiers, status and document information.
6. Recipients and service providers
Access is limited to authorised persons and recipients that need data for a defined purpose. Active infrastructure includes Amazon Web Services SES in region eu central 1 for electronic mail and Cloudflare R2 for encrypted attachments and exports.
The production environment is described internally as Flero hosting. Before publication, the full legal name of the hosting provider and the data centre location must be confirmed.
Revolut Merchant receives payment data only after production payments are enabled. Google Analytics receives analytics data only if a measurement identifier is configured and the user accepts analytics. iFirma receives billing data only if that invoice provider is enabled.
Jira and webhook destinations are chosen by the Customer. They are recipients acting under the Customer’s decision, not permanent Lemric subprocessors. Professional advisers, authorities and courts may receive data where needed or required by law.
The current provider details and status are set out in the Subprocessor List.
7. International transfers
The service does not rely on an unverified promise that every recipient processes data only in the European Economic Area. Before a provider or integration causes a transfer outside that area, the responsible party must identify the destination and apply a lawful transfer basis, such as an adequacy decision or valid contractual safeguards, together with supplementary measures where needed.
Lemric will provide available information about a relevant transfer on request. This Policy does not state that standard contractual clauses or a transfer assessment are already in place for every possible provider.
8. Retention
Customer organisation policies can set periods from seven to three thousand six hundred and fifty days for tickets, attachments, notifications, exports and audit data. A legal hold prevents deletion within that scope. Audit records selected for the protected archive are retained for about seven years.
These settings do not mean that every record is automatically removed at the same moment. Technical execution, dependencies, legal holds and mandatory duties can affect the actual time. If data is held in a copy used to restore the service, it remains outside ordinary use until that copy is safely overwritten or removed.
Account, contract and contact data is kept for as long as needed to provide the service and afterwards for accounting duties, claims, security and evidence. Billing records are kept for the period required by law. Security records are kept according to risk and evidential need. Marketing data is kept until consent is withdrawn, a valid objection is made or the purpose ends.
Browser drafts remain in local storage until the related form is submitted, the entry is removed or browser storage is cleared. Other browser preferences remain until changed or cleared.
9. Cookies and local browser storage
The sd_session cookie contains a session identifier used for sign in, access control and form security. Its configured lifetime can be up to thirty days and an inactive session can expire sooner.
The sd_cookie_consent cookie records the choice between essential use and optional analytics for one year. Google Analytics is not loaded merely because the banner exists. It can load only when a measurement identifier is configured and the user chooses analytics.
The local storage theme entry, technically named by joining sd and theme with a hyphen character, remembers a light or dark appearance. Draft entries use a prefix formed by joining sd and draft with the same character and keep unfinished text from supported forms on that browser. Draft text may contain personal data and is not sent merely because it is saved locally.
Essential storage is used to provide requested functions and secure the service. Optional analytics requires the choice presented by the service and can be refused. Analytics consent can be withdrawn through the cookie settings button in the footer. Lemric will then stop further analytics and attempt to remove accessible Google analytics cookies. Browser controls can also clear cookies and local storage, although clearing essential data can sign the user out or remove a draft.
10. Rights
Subject to the conditions in data protection law, a person may request access, rectification, erasure, restriction, portability or information about processing, and may object or withdraw consent. Lemric may verify identity and authority before acting.
Requests concerning data controlled by a Customer should be addressed to that Customer. Lemric assists the Customer as required by the DPA. Requests concerning Lemric as controller may be sent to privacy@lemric.com.
A person may complain to the President of the Personal Data Protection Office in Poland or another competent supervisory authority.
11. Security
Lemric uses safeguards appropriate to risk, including access controls, logical organisation isolation, encrypted transmission, encryption of selected stored data, protected credentials, logging of selected privileged operations and incident procedures. Safeguards reduce risk but no system can eliminate it.
12. Contact and changes
Privacy questions and requests may be sent to privacy@lemric.com. General legal notices may be sent to legal@lemric.com.
This Policy may change when law, technology, providers or the service changes. The effective date will be updated, and a material change will be communicated electronically where reasonably possible.