Gnovio
Legal

Privacy Policy

Last updated: May 2026

1. Who we are

This Privacy Policy explains how Limenio Ltd, a company incorporated in England and Wales with registered office at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ, which operates the Gnovio service ("Gnovio", the "Service"), collects, uses, shares, and protects personal data when you use the Service, visit gnovio.com or app.gnovio.com, or otherwise interact with us. In this Policy, "Limenio", "Gnovio", "we", "us", and "our" all refer to Limenio Ltd.

  • Controller (for our own data, such as website visitors and account holders): Limenio Ltd.
  • Processor (for Customer Content processed on behalf of business customers): Limenio Ltd, acting on the documented instructions of the Customer. See Section 11.

For privacy questions or requests, contact privacy@gnovio.com.

2. Scope and roles

Gnovio handles personal data in two distinct capacities, and your rights and the legal bases differ depending on which one applies.

RoleWhen it appliesWho you contact
ControllerYou are a visitor to our website, a prospective customer, an account administrator, or a User signing in to the Service.privacy@gnovio.com
ProcessorPersonal data appears inside Customer Content — for example, in meeting transcripts, in your knowledge graph, in messages, or in data flowing from connected tools.Your employer or the organization whose account you are using. We will refer such requests to the Customer.

This Privacy Policy covers both our Controller activities and, in Section 11, our role as a Processor for Customer Content handled on behalf of business customers.

3. Personal data we collect

3.1 Information you provide

  • Account information: name, work email, password (hashed), company, role.
  • Billing information: billing contact, billing address, VAT/tax ID. Card data is collected and stored by our payment processor and not by us.
  • Communications: the content of messages you send to us (support requests, sales inquiries, feedback).

3.2 Information collected automatically

  • Usage data: features used, pages viewed, clicks, queries submitted, session timestamps, performance metrics.
  • Device and connection data: IP address, browser type and version, operating system, device identifiers, referrer URL, time zone.
  • Cookies and similar technologies: see Section 13.

3.3 Information from third parties

  • Authentication providers: if you sign in with a third-party identity provider, we receive the basic profile information they share (such as name and email).
  • Connected tools: when you authorize an integration (Slack, HubSpot, Jira, Google Workspace, Microsoft, etc.), we receive data through that integration's API. Most of this data is Customer Content (see Section 11).
  • Public sources and partners: limited business contact information for sales and marketing purposes, where permitted by law.

3.4 Information we do not seek

We do not intentionally collect special categories of personal data (such as health, biometric, racial, religious, or political data), and we do not seek government identifiers, payment card numbers, or other highly sensitive information outside of fields designed for that purpose. Customers should not submit such data to the Service unless explicitly required and a valid legal basis exists. See Acceptable Use in the Terms of Service.

3.5 Children

The Service is not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@gnovio.com.

4. How we use personal data

We process personal data for the following purposes:

PurposeExamplesLegal basis (GDPR)Legal basis (LGPD)
Provide and operate the ServiceAuthenticate users, deliver features, maintain accountsPerformance of a contractExecution of a contract
Billing and paymentsCharge subscriptions, send invoices, handle refundsPerformance of a contract; legal obligationExecution of a contract; compliance with legal obligation
Security and fraud preventionDetect unauthorized access, investigate incidents, prevent abuseLegitimate interestsLegitimate interest; protection of credit
Customer supportRespond to your messages, troubleshoot issuesPerformance of a contract; legitimate interestsExecution of a contract; legitimate interest
Service improvement and analyticsUnderstand how the Service is used, identify bugs, prioritize featuresLegitimate interestsLegitimate interest
Marketing communicationsSend product updates, newsletters, event invitations to business contactsConsent (where required) or legitimate interestsConsent (where required) or legitimate interest
Compliance with legal obligationsRespond to lawful requests from authorities, retain records as requiredLegal obligationCompliance with legal obligation
Defense of legal claimsEstablish, exercise, or defend legal claimsLegitimate interestsRegular exercise of rights

You can opt out of marketing communications at any time using the unsubscribe link in any marketing message or by contacting privacy@gnovio.com.

5. AI models and improvement of the Service

We use AI models from third-party providers to deliver the Service. The current providers include Anthropic, OpenAI, and Google (Gemini).

We never use Customer Content to train any AI model — neither our own, nor those of any third-party AI providers we use to deliver the Service. The third-party AI providers we use are contractually committed not to train their models on data sent to them through the API integration we use.

We may use the following to monitor, secure, and improve the Service:

  • Aggregated and anonymized usage telemetry (e.g., counts of feature usage, error rates, latency).
  • Explicit feedback you provide (e.g., thumbs up/down ratings on Outputs).
  • Operational logs used to detect bugs, monitor performance, and investigate incidents.

This data does not contain the substance of Customer Content and is not used to reconstruct it.

6. How we share personal data

We share personal data only in the circumstances below.

6.1 Service providers (subprocessors)

We share personal data with third parties that help us operate the Service — including hosting, AI model providers, transcription, communications, analytics, support, and security tools. All subprocessors are bound by contractual obligations on confidentiality, security, and data protection. See Section 9.

6.2 Connected Third-Party Services

When you authorize an integration, data flows between the Service and that third-party platform under the scopes you grant. Their use of data is governed by their own terms and privacy notices.

6.3 Within your organization

If you use the Service under a Customer's account (for example, your employer's), the Customer controls the account and may access information about your use of the Service, including Customer Content you submit.

6.4 Corporate transactions

In the event of a merger, acquisition, financing, reorganization, or sale of all or part of our business, personal data may be transferred to the relevant counterparty, subject to confidentiality obligations and, where required, notice to you.

6.5 Legal and safety

We may disclose personal data when we have a good-faith belief that disclosure is required by law, by a binding legal request, or is necessary to protect the rights, property, or safety of Gnovio, our users, or the public.

6.6 With your consent

We may share personal data in other ways with your consent.

We do not sell personal data.

7. International data transfers

The Service is hosted on Google Cloud Platform in the United States. Personal data we process may be transferred to, stored, and processed in the United States and in other countries where we or our subprocessors operate.

When personal data is transferred from the European Economic Area, United Kingdom, or Switzerland to a country that has not been recognized as providing an adequate level of protection, we rely on appropriate safeguards, including:

  • Standard Contractual Clauses approved by the European Commission (and the UK Addendum issued by the UK Information Commissioner's Office, where applicable);
  • Supplementary measures as appropriate, such as encryption in transit and at rest, access controls, and contractual commitments by subprocessors.

For transfers from Brazil, we rely on the international transfer mechanisms permitted under LGPD Article 33, in particular Article 33(VIII) (necessity for the execution of a contract or pre-contractual procedures at the request of the data subject), with supplementary safeguards equivalent to those required for transfers from the European Economic Area.

You can request a copy of the safeguards in place by contacting privacy@gnovio.com.

8. Data retention

We retain personal data for as long as needed to provide the Service and to fulfill the purposes described in this Privacy Policy. Specific retention periods include:

CategoryRetention
Account informationFor the duration of the account, plus the retention window described below after termination
Customer Content after subscription terminationOne (1) year in inactive isolation, then deleted from active systems
Backup copiesUp to 90 days before being overwritten in the ordinary course
Billing recordsAs required by tax and accounting law (typically 5–10 years depending on jurisdiction)
Security and access logsUp to 12 months
Marketing contact dataUntil you unsubscribe or object, plus a reasonable suppression period
Records needed for legal claimsUntil the relevant limitation period expires

We may retain anonymized or aggregated data indefinitely, since it does not identify any individual.

9. Subprocessors

We use the following categories of subprocessors to operate the Service:

CategoryPurpose
Cloud hosting and infrastructureCompute, storage, networking — currently Google Cloud Platform (United States)
AI model providersGenerative AI, embeddings, language understanding — currently Anthropic, OpenAI, and Google (Gemini)
TranscriptionSpeech-to-text for the Meeting Assistant
AuthenticationSign-in with identity providers
PaymentsSubscription billing and invoicing
Transactional emailAccount notifications, password resets, billing emails
Customer supportTicketing and helpdesk
Product analytics and error trackingTelemetry, crash reports, performance monitoring
Communication platformsSales and customer communication

All subprocessors are bound by contractual obligations on confidentiality, security, and data protection no less protective than those set out in this Privacy Policy.

We may update the list of subprocessors from time to time. Customers on paid plans are notified of additions or replacements at least 30 days in advance, by email to the Customer's designated privacy contact, and may object on reasonable data protection grounds.

10. Your rights

Subject to applicable law, you have the following rights regarding your personal data:

  • Access — confirm whether we hold personal data about you and obtain a copy.
  • Rectification / correction — request correction of inaccurate or incomplete data.
  • Erasure / deletion — request deletion in defined circumstances.
  • Restriction — request that processing be limited in defined circumstances.
  • Objection — object to processing based on legitimate interests, and to direct marketing at any time.
  • Portability — receive certain personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
  • Withdraw consent — where processing is based on consent, withdraw consent at any time. Withdrawal does not affect prior processing.
  • Not be subject to fully automated decisions that produce legal or similarly significant effects, except as permitted by law.

Brazilian residents (LGPD) additionally have the right to: confirm the existence of processing; obtain information about the entities with which we share data; request portability to another service provider; obtain information about the possibility of not providing consent and the consequences; request review of fully automated decisions; and petition the National Data Protection Authority (ANPD).

To exercise any of these rights, email privacy@gnovio.com. We will respond within the time required by applicable law (generally 30 days under GDPR and 15 days under LGPD, extendable in justified cases).

If your personal data is in Customer Content under a business Customer's account, we will refer your request to that Customer, who is the controller.

11. Customer Content and our role as processor

When a business Customer uses the Service, the Customer is the controller of personal data contained in Customer Content (meetings, messages, knowledge graph entries, integration data, etc.). Limenio acts as a processor on the Customer's documented instructions.

As a processor, we commit to:

  • Process Customer Content only on the documented instructions of the Customer, which consist of the Terms of Service, this Privacy Policy, and the Customer's configuration of the Service (such as which tools are connected and which meetings are transcribed);
  • Not use Customer Content for any purpose other than providing the Service, and in particular not to train any AI model and not to sell it;
  • Ensure that our personnel are bound by appropriate confidentiality obligations;
  • Implement appropriate technical and organizational security measures (see Section 12);
  • Engage subprocessors only under written contracts imposing data protection obligations no less protective than those described here, and notify Customers of changes as described in Section 9;
  • Assist the Customer, taking into account the nature of the processing and the information available to us, in responding to data subject requests and in meeting obligations related to security, breach notification, data protection impact assessments, and consultation with supervisory authorities;
  • Notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Content;
  • Return or delete Customer Content at the end of the provision of the Service, in accordance with the retention terms in Section 8;
  • Make available information reasonably necessary to demonstrate compliance with applicable data protection law.

The responsibility for obtaining the legal bases, consents, and notices required to process personal data through the Service — including consent of meeting participants who are not Users — rests with the Customer, as set out in the Terms of Service.

Business Customers requiring a separate signed data processing agreement may contact privacy@gnovio.com.

12. Security

We implement technical and organizational measures designed to protect personal data, including:

  • Encryption in transit (TLS 1.2+) and at rest;
  • Logical isolation between Customer tenants;
  • Role-based access controls and the principle of least privilege;
  • Audit logging of administrative actions;
  • Vulnerability management and regular security testing;
  • Employee security training and confidentiality obligations;
  • Incident response procedures.

We implement and maintain controls aligned with the SOC 2 Type II framework.

No system is perfectly secure. If you believe your account has been compromised, contact security@gnovio.com immediately.

In the event of a personal data breach involving your data, we will notify you and, where required, the relevant supervisory authority and affected individuals, within the timeframes required by applicable law.

13. Cookies and similar technologies

We use only cookies that are strictly necessary to operate the Sites and to deliver the Service you have requested — for example, to keep you signed in, to protect against fraud and cross-site request forgery, and to remember basic preferences such as language. We do not use cookies for advertising, cross-site tracking, or behavioral profiling.

Because these cookies are required for the Sites to function, they do not require consent under applicable law. You can manage or block cookies through your browser settings, but blocking strictly necessary cookies will prevent parts of the Sites from working. If we introduce optional cookies (such as analytics or marketing) in the future, we will update this Policy and present a consent banner before any such cookies are set.

14. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice by email, by a banner in the Service, or by other reasonable means before the changes take effect. The "Last updated" date at the top of this page indicates when this version was published.

15. Complaints and supervisory authorities

If you believe we have not handled your personal data in accordance with applicable law, please first contact privacy@gnovio.com so we can try to resolve the issue.

You also have the right to lodge a complaint with the supervisory authority of your country of residence:

  • United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk
  • European Union: the data protection authority of the member state where you live or work
  • Brazil: Autoridade Nacional de Proteção de Dados (ANPD) — gov.br/anpd

16. Contact

Limenio Ltd (operating the Gnovio service)
71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ

Privacy: privacy@gnovio.com · Security: security@gnovio.com · Legal: legal@gnovio.com