Privacy Policy
Last updated: May 2026
1. Who we are
This Privacy Policy explains how Limenio Ltd, a company incorporated in England and Wales with registered office at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ, which operates the Gnovio service ("Gnovio", the "Service"), collects, uses, shares, and protects personal data when you use the Service, visit gnovio.com or app.gnovio.com, or otherwise interact with us. In this Policy, "Limenio", "Gnovio", "we", "us", and "our" all refer to Limenio Ltd.
- Controller (for our own data, such as website visitors and account holders): Limenio Ltd.
- Processor (for Customer Content processed on behalf of business customers): Limenio Ltd, acting on the documented instructions of the Customer. See Section 11.
For privacy questions or requests, contact privacy@gnovio.com.
2. Scope and roles
Gnovio handles personal data in two distinct capacities, and your rights and the legal bases differ depending on which one applies.
| Role | When it applies | Who you contact |
|---|---|---|
| Controller | You are a visitor to our website, a prospective customer, an account administrator, or a User signing in to the Service. | privacy@gnovio.com |
| Processor | Personal data appears inside Customer Content — for example, in meeting transcripts, in your knowledge graph, in messages, or in data flowing from connected tools. | Your employer or the organization whose account you are using. We will refer such requests to the Customer. |
This Privacy Policy covers both our Controller activities and, in Section 11, our role as a Processor for Customer Content handled on behalf of business customers.
3. Personal data we collect
3.1 Information you provide
- Account information: name, work email, password (hashed), company, role.
- Billing information: billing contact, billing address, VAT/tax ID. Card data is collected and stored by our payment processor and not by us.
- Communications: the content of messages you send to us (support requests, sales inquiries, feedback).
3.2 Information collected automatically
- Usage data: features used, pages viewed, clicks, queries submitted, session timestamps, performance metrics.
- Device and connection data: IP address, browser type and version, operating system, device identifiers, referrer URL, time zone.
- Cookies and similar technologies: see Section 13.
3.3 Information from third parties
- Authentication providers: if you sign in with a third-party identity provider, we receive the basic profile information they share (such as name and email).
- Connected tools: when you authorize an integration (Slack, HubSpot, Jira, Google Workspace, Microsoft, etc.), we receive data through that integration's API. Most of this data is Customer Content (see Section 11).
- Public sources and partners: limited business contact information for sales and marketing purposes, where permitted by law.
3.4 Information we do not seek
We do not intentionally collect special categories of personal data (such as health, biometric, racial, religious, or political data), and we do not seek government identifiers, payment card numbers, or other highly sensitive information outside of fields designed for that purpose. Customers should not submit such data to the Service unless explicitly required and a valid legal basis exists. See Acceptable Use in the Terms of Service.
3.5 Children
The Service is not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@gnovio.com.
4. How we use personal data
We process personal data for the following purposes:
| Purpose | Examples | Legal basis (GDPR) | Legal basis (LGPD) |
|---|---|---|---|
| Provide and operate the Service | Authenticate users, deliver features, maintain accounts | Performance of a contract | Execution of a contract |
| Billing and payments | Charge subscriptions, send invoices, handle refunds | Performance of a contract; legal obligation | Execution of a contract; compliance with legal obligation |
| Security and fraud prevention | Detect unauthorized access, investigate incidents, prevent abuse | Legitimate interests | Legitimate interest; protection of credit |
| Customer support | Respond to your messages, troubleshoot issues | Performance of a contract; legitimate interests | Execution of a contract; legitimate interest |
| Service improvement and analytics | Understand how the Service is used, identify bugs, prioritize features | Legitimate interests | Legitimate interest |
| Marketing communications | Send product updates, newsletters, event invitations to business contacts | Consent (where required) or legitimate interests | Consent (where required) or legitimate interest |
| Compliance with legal obligations | Respond to lawful requests from authorities, retain records as required | Legal obligation | Compliance with legal obligation |
| Defense of legal claims | Establish, exercise, or defend legal claims | Legitimate interests | Regular exercise of rights |
You can opt out of marketing communications at any time using the unsubscribe link in any marketing message or by contacting privacy@gnovio.com.
5. AI models and improvement of the Service
We use AI models from third-party providers to deliver the Service. The current providers include Anthropic, OpenAI, and Google (Gemini).
We never use Customer Content to train any AI model — neither our own, nor those of any third-party AI providers we use to deliver the Service. The third-party AI providers we use are contractually committed not to train their models on data sent to them through the API integration we use.
We may use the following to monitor, secure, and improve the Service:
- Aggregated and anonymized usage telemetry (e.g., counts of feature usage, error rates, latency).
- Explicit feedback you provide (e.g., thumbs up/down ratings on Outputs).
- Operational logs used to detect bugs, monitor performance, and investigate incidents.
This data does not contain the substance of Customer Content and is not used to reconstruct it.
6. How we share personal data
We share personal data only in the circumstances below.
6.1 Service providers (subprocessors)
We share personal data with third parties that help us operate the Service — including hosting, AI model providers, transcription, communications, analytics, support, and security tools. All subprocessors are bound by contractual obligations on confidentiality, security, and data protection. See Section 9.
6.2 Connected Third-Party Services
When you authorize an integration, data flows between the Service and that third-party platform under the scopes you grant. Their use of data is governed by their own terms and privacy notices.
6.3 Within your organization
If you use the Service under a Customer's account (for example, your employer's), the Customer controls the account and may access information about your use of the Service, including Customer Content you submit.
6.4 Corporate transactions
In the event of a merger, acquisition, financing, reorganization, or sale of all or part of our business, personal data may be transferred to the relevant counterparty, subject to confidentiality obligations and, where required, notice to you.
6.5 Legal and safety
We may disclose personal data when we have a good-faith belief that disclosure is required by law, by a binding legal request, or is necessary to protect the rights, property, or safety of Gnovio, our users, or the public.
6.6 With your consent
We may share personal data in other ways with your consent.
We do not sell personal data.
7. International data transfers
The Service is hosted on Google Cloud Platform in the United States. Personal data we process may be transferred to, stored, and processed in the United States and in other countries where we or our subprocessors operate.
When personal data is transferred from the European Economic Area, United Kingdom, or Switzerland to a country that has not been recognized as providing an adequate level of protection, we rely on appropriate safeguards, including:
- Standard Contractual Clauses approved by the European Commission (and the UK Addendum issued by the UK Information Commissioner's Office, where applicable);
- Supplementary measures as appropriate, such as encryption in transit and at rest, access controls, and contractual commitments by subprocessors.
For transfers from Brazil, we rely on the international transfer mechanisms permitted under LGPD Article 33, in particular Article 33(VIII) (necessity for the execution of a contract or pre-contractual procedures at the request of the data subject), with supplementary safeguards equivalent to those required for transfers from the European Economic Area.
You can request a copy of the safeguards in place by contacting privacy@gnovio.com.
8. Data retention
We retain personal data for as long as needed to provide the Service and to fulfill the purposes described in this Privacy Policy. Specific retention periods include:
| Category | Retention |
|---|---|
| Account information | For the duration of the account, plus the retention window described below after termination |
| Customer Content after subscription termination | One (1) year in inactive isolation, then deleted from active systems |
| Backup copies | Up to 90 days before being overwritten in the ordinary course |
| Billing records | As required by tax and accounting law (typically 5–10 years depending on jurisdiction) |
| Security and access logs | Up to 12 months |
| Marketing contact data | Until you unsubscribe or object, plus a reasonable suppression period |
| Records needed for legal claims | Until the relevant limitation period expires |
We may retain anonymized or aggregated data indefinitely, since it does not identify any individual.
9. Subprocessors
We use the following categories of subprocessors to operate the Service:
| Category | Purpose |
|---|---|
| Cloud hosting and infrastructure | Compute, storage, networking — currently Google Cloud Platform (United States) |
| AI model providers | Generative AI, embeddings, language understanding — currently Anthropic, OpenAI, and Google (Gemini) |
| Transcription | Speech-to-text for the Meeting Assistant |
| Authentication | Sign-in with identity providers |
| Payments | Subscription billing and invoicing |
| Transactional email | Account notifications, password resets, billing emails |
| Customer support | Ticketing and helpdesk |
| Product analytics and error tracking | Telemetry, crash reports, performance monitoring |
| Communication platforms | Sales and customer communication |
All subprocessors are bound by contractual obligations on confidentiality, security, and data protection no less protective than those set out in this Privacy Policy.
We may update the list of subprocessors from time to time. Customers on paid plans are notified of additions or replacements at least 30 days in advance, by email to the Customer's designated privacy contact, and may object on reasonable data protection grounds.
10. Your rights
Subject to applicable law, you have the following rights regarding your personal data:
- Access — confirm whether we hold personal data about you and obtain a copy.
- Rectification / correction — request correction of inaccurate or incomplete data.
- Erasure / deletion — request deletion in defined circumstances.
- Restriction — request that processing be limited in defined circumstances.
- Objection — object to processing based on legitimate interests, and to direct marketing at any time.
- Portability — receive certain personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
- Withdraw consent — where processing is based on consent, withdraw consent at any time. Withdrawal does not affect prior processing.
- Not be subject to fully automated decisions that produce legal or similarly significant effects, except as permitted by law.
Brazilian residents (LGPD) additionally have the right to: confirm the existence of processing; obtain information about the entities with which we share data; request portability to another service provider; obtain information about the possibility of not providing consent and the consequences; request review of fully automated decisions; and petition the National Data Protection Authority (ANPD).
To exercise any of these rights, email privacy@gnovio.com. We will respond within the time required by applicable law (generally 30 days under GDPR and 15 days under LGPD, extendable in justified cases).
If your personal data is in Customer Content under a business Customer's account, we will refer your request to that Customer, who is the controller.
11. Customer Content and our role as processor
When a business Customer uses the Service, the Customer is the controller of personal data contained in Customer Content (meetings, messages, knowledge graph entries, integration data, etc.). Limenio acts as a processor on the Customer's documented instructions.
As a processor, we commit to:
- Process Customer Content only on the documented instructions of the Customer, which consist of the Terms of Service, this Privacy Policy, and the Customer's configuration of the Service (such as which tools are connected and which meetings are transcribed);
- Not use Customer Content for any purpose other than providing the Service, and in particular not to train any AI model and not to sell it;
- Ensure that our personnel are bound by appropriate confidentiality obligations;
- Implement appropriate technical and organizational security measures (see Section 12);
- Engage subprocessors only under written contracts imposing data protection obligations no less protective than those described here, and notify Customers of changes as described in Section 9;
- Assist the Customer, taking into account the nature of the processing and the information available to us, in responding to data subject requests and in meeting obligations related to security, breach notification, data protection impact assessments, and consultation with supervisory authorities;
- Notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Content;
- Return or delete Customer Content at the end of the provision of the Service, in accordance with the retention terms in Section 8;
- Make available information reasonably necessary to demonstrate compliance with applicable data protection law.
The responsibility for obtaining the legal bases, consents, and notices required to process personal data through the Service — including consent of meeting participants who are not Users — rests with the Customer, as set out in the Terms of Service.
Business Customers requiring a separate signed data processing agreement may contact privacy@gnovio.com.
12. Security
We implement technical and organizational measures designed to protect personal data, including:
- Encryption in transit (TLS 1.2+) and at rest;
- Logical isolation between Customer tenants;
- Role-based access controls and the principle of least privilege;
- Audit logging of administrative actions;
- Vulnerability management and regular security testing;
- Employee security training and confidentiality obligations;
- Incident response procedures.
We implement and maintain controls aligned with the SOC 2 Type II framework.
No system is perfectly secure. If you believe your account has been compromised, contact security@gnovio.com immediately.
In the event of a personal data breach involving your data, we will notify you and, where required, the relevant supervisory authority and affected individuals, within the timeframes required by applicable law.
13. Cookies and similar technologies
We use only cookies that are strictly necessary to operate the Sites and to deliver the Service you have requested — for example, to keep you signed in, to protect against fraud and cross-site request forgery, and to remember basic preferences such as language. We do not use cookies for advertising, cross-site tracking, or behavioral profiling.
Because these cookies are required for the Sites to function, they do not require consent under applicable law. You can manage or block cookies through your browser settings, but blocking strictly necessary cookies will prevent parts of the Sites from working. If we introduce optional cookies (such as analytics or marketing) in the future, we will update this Policy and present a consent banner before any such cookies are set.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice by email, by a banner in the Service, or by other reasonable means before the changes take effect. The "Last updated" date at the top of this page indicates when this version was published.
15. Complaints and supervisory authorities
If you believe we have not handled your personal data in accordance with applicable law, please first contact privacy@gnovio.com so we can try to resolve the issue.
You also have the right to lodge a complaint with the supervisory authority of your country of residence:
- United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk
- European Union: the data protection authority of the member state where you live or work
- Brazil: Autoridade Nacional de Proteção de Dados (ANPD) — gov.br/anpd
16. Contact
Limenio Ltd (operating the Gnovio service)
71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
Privacy: privacy@gnovio.com · Security: security@gnovio.com · Legal: legal@gnovio.com