LEMA Chat Privacy Policy
Last updated: 28 August 2026
We value your privacy. This Privacy Policy explains how LEMA Logic Limited collects, uses, shares, and protects personal data in the LEMA Chat service (the "Service"). LEMA Logic Limited is incorporated in the Isle of Man (Company No. 137753C) and is also a trading name of Gallagher Innovations, Inc. (Maryland, USA; Isle of Man Company No. 006459F) (together "LEMA Logic", "we", "us" or "our"). We process personal data in accordance with the Isle of Man's applied data protection framework (the Data Protection Act 2018 and the GDPR and LED Implementing Regulations 2018).
1. Who is the controller
LEMA Logic Limited is the data controller for personal data we process to operate and provide the Service. Where the Service is deployed by or for a customer organisation, that organisation is the controller of the workspace, member, and content data within its deployment, and LEMA Logic acts as its processor for that data under the applicable agreement. For any privacy question, you can contact both us and your workspace administrator.
2. What personal data we process
Depending on how you use the Service, we and the sub-processors that operate it may process the following categories of personal data:
- Identity and account data - your name and email address (including from Google sign-in, where used), your display name, your Google account identifier, and your avatar image.
- Conversation content - the messages, threads, reactions, and read state you create in chats.
- Documents and canvases - the collaborative documents and canvas objects you create, including their titles and content.
- Brain content - findings you or your colleagues promote into curated, versioned knowledge bases, including who created each record.
- Uploaded files - files and images you share, and text extracted from them for search and agent context.
- Interview material - where an agent conducts a voice, web, or text interview, the interview subject, prompt, transcript, and summary. Voice audio is held by our interview provider (Retell) and is not stored in our database.
- Push notification data - if you enable browser or device push notifications, the push endpoint and keys minted by your browser and your device's user-agent string.
- Provider credentials (bring your own key) - where you or your workspace connect your own AI provider, the API key you supply, which is encrypted at rest.
- Security and audit data - a tamper-evident audit log of actions (recording the actor, the action, and limited detail such as display names and chat names, but not message bodies), together with technical data such as IP address and request metadata.
- Dictation audio - where your deployment enables browser dictation in the composer, the audio of your dictated speech (see Section 5).
Any individual named or described within conversation, document, Brain, file, or interview content may also be a data subject. You are responsible for having a lawful basis to include personal data about other people.
3. Why we process it, and our legal bases
| Purpose | Legal basis (applied GDPR) |
|---|---|
| Authenticate you and manage your account and workspace membership | Performance of a contract (Art. 6(1)(b)) |
| Provide chat, threading, documents, canvases, files, and Brains | Performance of a contract (Art. 6(1)(b)) |
| Let AI agents participate, generate embeddings, and generate images over your content | Our legitimate interests in providing agent functionality (Art. 6(1)(f)), subject to a legitimate-interests assessment |
| Retain curated knowledge in Brains | Performance of a contract and our legitimate interest in knowledge retention (Art. 6(1)(b) and (f)) |
| Conduct agent-run interviews | Our legitimate interests, or consent, assessed per interview (Art. 6(1)(f) or (a)) |
| Send workspace invitation emails | Performance of a contract and legitimate interests (Art. 6(1)(b) and (f)) |
| Deliver push notifications | Consent, via your browser permission (Art. 6(1)(a)) |
| Maintain a tamper-evident security audit log | Our legitimate interests in security and integrity, and legal obligation where applicable (Art. 6(1)(f) and (c)) |
| Store provider credentials you supply | Performance of a contract (Art. 6(1)(b)) |
Where we rely on consent (for example, for push notifications or certain interviews), you may withdraw it at any time. Where we rely on legitimate interests, you may object; see Section 8.
4. AI processing of your content
Because AI agents are a core part of the Service, content you submit - including messages, Brain content, prompts, image prompts, and text extracted from files - may be sent to third-party AI providers to generate responses, embeddings, and images. Depending on how your deployment is configured, these providers include OpenAI, Amazon Web Services (AWS Bedrock, EU region), and Anthropic, and may include a provider you or your workspace connect with your own API key. These providers process the content only to return a result to the Service and, under their agreements with us, do not use it to train their models except as permitted by those agreements.
Our target configuration routes AI inference through the AWS Bedrock EU region on a zero-data-retention basis, which keeps inference within the EU and prevents provider-side retention. The current default provider and region depend on your deployment's configuration. The operative list of AI and other sub-processors is in Section 6.
5. Dictation (speech to text)
Where your deployment enables browser dictation in the message composer, your browser uses its built-in Web Speech feature to convert speech to text. In that case, the audio of your dictated speech is sent by your browser to the browser vendor's speech-recognition service (for example, Google) and is processed under that vendor's terms, outside our control. If you prefer not to use it, do not use the dictation control; typed input is not sent to a speech provider.
6. Who we share personal data with (sub-processors)
We share personal data only with the service providers that help us operate the Service, and with authorities where legally required. We do not sell your personal data. Our current sub-processors are:
| Sub-processor | Role in the Service | Location |
|---|---|---|
| Railway | Application hosting and database (data at rest) | United States (EU region planned) |
| Cloudflare | DNS, content delivery, and TLS at the network edge | United States / global edge |
| Supabase GoTrue (authentication) | Identity store, sessions, and Google sign-in brokering | Self-hosted with our hosting |
| Google sign-in (identity only); and browser speech recognition where dictation is used | United States | |
| OpenAI | AI inference, embeddings, and image generation over content | United States |
| Amazon Web Services (AWS Bedrock, EU) | Sovereign EU, zero-data-retention AI inference | European Union |
| Anthropic | AI model provider (direct or via AWS Bedrock) | United States / EU via Bedrock |
| Resend | Transactional email (workspace invitations) | United States |
| Retell AI (and its sub-processors) | Voice, web, and text interview capture and transcription | United States / mixed |
| Web push endpoints (Apple, Google, Mozilla and other browser vendors) | Delivery of push notifications to your browser or device | Mixed, per vendor |
| Bring-your-own-key providers (optional) | Additional AI backends only if you or your workspace connect one | Per chosen provider |
Each of these providers processes personal data on our (or your organisation's) behalf under a data processing agreement or an equivalent safeguard, or under a self-hosted arrangement. We keep this list current as our providers change.
7. International transfers
Some of our sub-processors are located in the United States or process data in mixed locations, which means your personal data may be processed outside the Isle of Man, the United Kingdom, and the European Economic Area. Where that happens, we rely on appropriate safeguards such as the UK/EU-US Data Privacy Framework, standard contractual clauses, and additional measures. Our target posture keeps data at rest and AI inference within the European Union (Railway EU region and AWS Bedrock EU), which reduces these transfers.
8. Your rights
Subject to the applicable data protection law, you have the right to:
- access the personal data we hold about you;
- ask us to correct inaccurate or incomplete data;
- ask us to delete your personal data (see the note below on how erasure currently works);
- ask us to restrict, or object to, certain processing, including processing based on our legitimate interests;
- withdraw consent where we rely on it (for example, push notifications);
- receive certain data in a portable format; and
- lodge a complaint with a supervisory authority.
How erasure currently works. We are honest about a current limitation: LEMA Chat does not yet offer fully automated, self-service account deletion or content erasure. Some parts of the Service are versioned or tamper-evident by design (Brain records and the security audit log), which means we handle erasure carefully rather than by a single delete button. We are building a mechanism (based on per-record encryption and key destruction) that will allow us to irreversibly de-identify your content while preserving the integrity of the audit trail. In the meantime, if you ask us to erase your data, we will action your request manually and, where a technical constraint means we cannot fully delete a particular item, we will tell you what we can and cannot do and why. We aim to respond to rights requests within one month.
9. How long we keep data
We keep personal data only as long as needed for the purpose we collected it. In general: account and identity data are kept for the life of your account; conversation, document, and file content are kept for the life of the workspace or until deleted; Brain records are retained as durable knowledge unless erasure is requested; interview transcripts are kept in the conversation for up to 12 months; interview voice audio is retained by our interview provider on its own schedule; push subscriptions are kept until you unsubscribe or the token expires; and the security audit log is retained for integrity. Some retention periods are targets we are still enforcing in the product; see the erasure note in Section 8.
10. How we protect your data
We use technical and organisational measures to protect personal data, including TLS encryption in transit, encryption at rest of the AI provider credentials you supply (AES-256-GCM), a tamper-evident, hash-chained security audit log, workspace-scoped access controls, and limiting the personal data in notification payloads. Content-at-rest encryption with per-record key destruction is part of the erasure mechanism we are building (Section 8). No method of transmission or storage is completely secure, and we cannot guarantee absolute security. During pre-launch development, the Service is operated with synthetic (non-real) data until the EU-resident, zero-data-retention configuration and the erasure mechanism are in place.
11. Cookies and local storage
The Service uses cookies and browser local storage only as needed to run the application - for example, to keep you signed in, hold your session, and remember interface preferences. It does not use advertising or cross-site tracking cookies. You can control cookies through your browser settings, though disabling essential cookies may prevent the Service from working. The lemalogic.com marketing website has its own cookie practices described in the LEMA Logic Privacy Policy.
12. Children
The Service is intended for use by organisations and adults and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided personal data through the Service, please contact us so we can address it.
13. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated policy here and, where changes are material, take reasonable steps to notify affected users.
14. Contact and complaints
For any privacy question or to exercise your rights, contact our data protection contact:
Data Protection, LEMA Logic Limited
Email: privacy@lemalogic.com
Telephone: +44 7624 277717
Castletown, Isle of Man, British Isles
We will need to verify your identity before actioning a request. If you are not satisfied with our response, you have the right to lodge a complaint with the Isle of Man Information Commissioner (First Floor, Prospect House, Douglas, Isle of Man, IM1 1ET; telephone +44 1624 693260; inforights.im), or with the supervisory authority in your country of residence. We would appreciate the chance to address your concerns first.