Lemric Privacy Policy
Effective date: 9 August 2026 | Version: 2.0
1. Personal data controller
Business name: Lemric Dominik Łabudziński
Address: Weteranów 74/3, 05 250 Radzymin, Poland
Polish tax ID (NIP): 5272448444
Statistical number (REGON): 141491900
| Contact | Address |
|---|---|
| Privacy | privacy@lemric.com |
| Legal matters | legal@lemric.com |
Lemric Dominik Łabudziński, a sole trader, is the controller of data used to operate Lemric accounts, contracts, billing, security, direct contact, and the lemric.com website.
When the Customer places personal data in its help centre, portal, forms, tickets, attachments, workflows, or integrations, the Customer determines the purposes and means of processing. Lemric then acts as a processor under the Data Processing Agreement (DPA). A person whose data appear in Customer content should usually contact that Customer first.
The Service is offered only to businesses and other organisations. It may still include personal data of their representatives, staff, customers, and requesters.
The controller processes data in line with Regulation (EU) 2016/679 (GDPR) and the Polish Act of 10 May 2018 on the protection of personal data.
2. Definitions
- Controller: Lemric Dominik Łabudziński for the data described in section 1.
- Service: the Lemric platform available at lemric.com and related features.
- Customer: a business or organisation using the Service for professional activity.
- Organisation: the Customer’s workspace in the Service.
- DPA: the Data Processing Agreement.
- Subprocessor List: the current list of subprocessors published in the Service.
- GDPR: Regulation (EU) 2016/679.
- Personal data: information relating to an identified or identifiable natural person.
- Processor: a party to which the Controller entrusts processing under Article 28 GDPR.
3. Purposes, legal bases, and retention
We process personal data on the following legal bases under Article 6(1) GDPR:
| Data category | Purpose | Legal basis | Retention |
|---|---|---|---|
| Account data (name, email, language, role, organisation) | Providing the Service, access, support | Art. 6(1)(b) (contract) | While the Service is provided, then legal duties and claims |
| Account IDs, password hashes, MFA, sessions, permissions | Authentication and access security | Art. 6(1)(b); Art. 6(1)(f) (legitimate interest) | Until session expiry / account deletion; security records as needed for risk |
| Order, subscription, billing, payment correspondence | Payments and billing | Art. 6(1)(b); Art. 6(1)(c) (legal obligation) | Period required by accounting and tax law |
| Complaints, privacy requests, support correspondence | Handling requests and claims | Art. 6(1)(b); Art. 6(1)(c); Art. 6(1)(f) | Until the matter ends and limitation periods expire |
| IP address, browser, device, security events, rate limits, audit | Security, abuse prevention, evidence | Art. 6(1)(f) | As needed for risk and evidence; protected audit archive about 7 years |
| Internal help search queries and article ratings | Improving help content | Art. 6(1)(f) | Until the purpose ends or a successful objection |
| Essential cookies (sd_session, sd_cookie_consent) | Sign in, form protection, consent record | Art. 6(1)(b); Art. 6(1)(f) | Up to 30 days (session); cookie consent up to 1 year |
| Optional analytics (Google Analytics) | Site analytics | Art. 6(1)(a) (consent) | Per provider configuration; only after consent and measurement setup |
| Marketing data (information about Lemric) | Communication where allowed by law | Art. 6(1)(a) or Art. 6(1)(f) | Until consent is withdrawn, objection succeeds, or the purpose ends |
A person may object to processing based on legitimate interest. Consent may be withdrawn at any time without affecting earlier processing.
4. Data Lemric processes as controller
Depending on how the Service is used, data may include:
- name, electronic mail address, language, organisation, role, and contact details,
- account identifiers, password hashes, authentication methods, MFA records, session identifiers, and permission history,
- order, subscription, billing data, payment status, and billing correspondence,
- messages to Lemric, complaints, privacy requests, and support correspondence,
- IP address, browser and device information, request time, security events, rate limit records, and audit records,
- internal help centre search queries, selected results, and article ratings,
- cookie choices and browser preferences described below.
Lemric does not store full card data when a transaction is handled by an external payment provider.
5. Data processed for Customers
Customer content may include names, electronic mail addresses, organisation and job data, portal accounts, ticket subjects and messages, form answers, attachments, internal notes, participants, activity history, service level events, audit data, Jira references, and webhook content chosen by the Customer.
The Customer controls the scope of these data. Special category data and data about criminal convictions should not be entered unless the Customer has established that processing is necessary, lawful, and covered by appropriate safeguards.
Details of Lemric’s role as processor are set out in the DPA.
6. Sources of data
Data come from:
- the data subject,
- the Customer they represent,
- other authorised Organisation members,
- systems connected by the Customer,
- technical records created while using the Service.
Payment and billing providers may return transaction identifiers, status, and document information.
7. Recipients and providers
Access is limited to authorised persons and recipients who need the data for a defined purpose.
Summary of Lemric’s active infrastructure:
| Provider | Purpose | Region / location |
|---|---|---|
| Amazon Web Services (SES) | Sending Service electronic mail | eu-central-1 |
| Cloudflare (R2) | Storage of encrypted attachments and exports | Per provider agreement |
| OVH | Production hosting (Lemric infrastructure) | Poland (EEA) |
Conditional providers (data are transferred only after the condition is met):
| Provider | Purpose | Condition |
|---|---|---|
| Revolut Merchant | Payments | Production payments enabled |
| Google Analytics | Site analytics | Measurement ID and user consent |
| iFirma | Invoices and bookkeeping data | iFirma selected as invoice provider |
Jira and webhook destinations are chosen by the Customer. They are recipients acting under the Customer’s decision, not permanent Lemric subprocessors. Professional advisers, authorities, and courts may also receive data where needed or required by law.
The current source of truth for providers is the Subprocessor List: https://lemric.com/en/legal/subprocessors
8. International transfers
The Service does not rely on an unverified claim that every recipient processes data only in the European Economic Area. Before a provider or integration causes a transfer outside that area, the responsible party must identify the destination and apply a lawful transfer basis such as:
- an adequacy decision,
- appropriate contractual safeguards (including standard contractual clauses),
- supplementary measures where needed.
On request, Lemric will provide the information it holds about the relevant transfer. This Policy does not state that standard contractual clauses or a transfer assessment are already in place for every possible provider.
9. Retention
- Organisation policies may set a period from 7 to 3650 days for tickets, attachments, notifications, exports, and audit data.
- A legal hold prevents deletion within its scope.
- Audit records selected for the protected archive are kept for about seven years.
- Settings do not mean every record is deleted at the same instant. Timing may be affected by technical execution, dependencies, legal holds, and statutory duties.
- If data sit in a copy used to restore the Service, they remain out of ordinary use until that copy is securely overwritten or deleted.
- Account, contract, and contact data are kept for as long as needed to provide the Service, then for accounting duties, claims, protection, and evidence.
- Billing records are kept for the period required by law.
- Marketing data are kept until consent is withdrawn, an objection succeeds, or the purpose ends.
- Browser drafts remain in local storage until the form is submitted, the entry is removed, or browser storage is cleared.
10. Cookies and local browser storage
10.1 Essential cookies
| Name | Purpose | Period |
|---|---|---|
| sd_session | Session ID: sign in, access control, form protection | Up to 30 days; an inactive session may expire earlier |
| sd_cookie_consent | Stores the choice between essential use and optional analytics | 1 year |
10.2 Local browser storage
| Key | Purpose |
|---|---|
| sd-theme | Remembers light or dark appearance |
| Prefix sd-draft | Unsent text from supported forms in that browser |
Draft text may include personal data and is not sent merely because it was stored locally.
10.3 Optional analytics
Google Analytics is not loaded merely because a banner exists. It may load only after a measurement ID is configured and the user selects analytics.
Analytics consent may be withdrawn via the cookie settings control in the footer. Lemric will then stop further analytics and attempt to remove available Google analytics files. Browser settings can also clear cookies and local storage, but removing essential data may sign the user out or delete a draft.
11. Rights of individuals
11.1 Rights under the GDPR
Subject to conditions in law, a person may request:
- access (Article 15 GDPR),
- rectification (Article 16 GDPR),
- erasure (Article 17 GDPR),
- restriction of processing (Article 18 GDPR),
- data portability (Article 20 GDPR),
- objection (Article 21 GDPR),
- withdrawal of consent,
- information about processing,
- not to be subject to a decision based solely on automated processing within the scope of Article 22 GDPR.
Before acting on a request, Lemric may verify the requester’s identity and authority.
11.2 How to exercise rights
- Requests about data controlled by the Customer should go to that Customer. Lemric assists under the DPA.
- Requests about Lemric as controller: privacy@lemric.com (subject: “Rights request”).
- Response time: usually within 30 days of receipt (Article 12(3) GDPR).
11.3 Right to lodge a complaint
A person may lodge a complaint with the President of the Personal Data Protection Office or another competent supervisory authority.
President of the Personal Data Protection Office (UODO)
Address: ul. Stawki 2, 00 193 Warsaw
Telephone: (22) 531 03 00
12. Security
Lemric applies safeguards appropriate to the risk, including:
- access control,
- logical isolation of Organisations,
- encryption in transit,
- encryption of selected stored data,
- protection of access credentials,
- logging of selected privileged operations,
- incident handling procedures.
Safeguards reduce risk, but no system can eliminate it entirely.
13. Changes and contact
13.1 Changes
This Policy may change with law, technology, providers, or the Service. The effective date and version will be updated, and a material change will be communicated electronically when reasonably possible.
13.2 Contact
- Privacy and rights requests: privacy@lemric.com
- General legal notices: legal@lemric.com
- Subprocessor List: https://lemric.com/en/legal/subprocessors
- DPA: https://lemric.com/en/legal/dpa
Effective date: 9 August 2026
Document version: 2.0