Legal
Privacy Policy
Last updated: 1 August 2026
1. Data controller
This Privacy Policy explains how LemmaBase B.V. (in oprichting) ("LemmaBase", "we", "us", or "our"), a company in formation under the laws of the Netherlands, processes personal data when you use lemmabase.com and related services (the "Service").
Contact: hello@lemmabase.com or via the contact page.
2. Personal data we collect
Depending on how you use the Service, we may process:
- Account data: email address, password hash (if you register with email/password), display name, handle, profile information, and avatar.
- OAuth data: identifiers and profile details provided by Google, GitHub, or Microsoft when you sign in with those providers (as configured by you and those providers).
- Organization and collaboration data: organization membership, invitations, roles, and related settings.
- Repository and content metadata: repository names, visibility, publication history, and content you store (which may incidentally include personal data if you put it in specs or descriptions).
- Usage and technical data: IP address, user agent, request logs, timestamps, security events, and similar diagnostics needed to operate and secure the Service.
- Communications: messages you send via contact forms or support channels.
- API / token data: API tokens and related metadata you create to access repository APIs or MCP.
3. Purposes and legal bases
We process personal data for the following purposes and legal bases under GDPR Article 6:
- Providing the Service (account creation, authentication, repositories, APIs): performance of a contract (Art. 6(1)(b)).
- Security, abuse prevention, and stability (logging, rate limiting, fraud detection): legitimate interests (Art. 6(1)(f)).
- Communications you initiate (contact form replies): performance of a contract or legitimate interests, as applicable.
- Legal obligations (responding to lawful requests, retaining records where required): legal obligation (Art. 6(1)(c)).
- Product improvement (aggregated or de-identified analytics where used): legitimate interests (Art. 6(1)(f)), balanced against your rights.
4. Sharing and processors
We do not sell your personal data. We may share data with service providers that process it on our instructions (for example hosting, email delivery, object storage, or OAuth providers you choose), under appropriate agreements. We may disclose data if required by law or to protect rights, safety, or the integrity of the Service.
If you publish a public repository or public profile, information you mark as public may be visible to anyone on the internet, including search features of the Service.
5. International transfers
Where personal data is transferred outside the European Economic Area, we take appropriate safeguards as required by GDPR, such as Standard Contractual Clauses or an adequacy decision, unless a specific derogation applies.
6. Retention
We retain account and repository data for as long as your account remains active and as needed to provide the Service. After account deletion or upon request, we delete or anonymize personal data within a reasonable period, unless we must retain it for legal, security, or dispute-resolution purposes. Technical logs are typically kept for a shorter operational window unless needed for security investigation.
7. Security
We apply appropriate technical and organizational measures, including TLS in transit, access controls, and secure handling of credentials and API tokens. No method of transmission or storage is completely secure; you are responsible for protecting your passwords and tokens.
8. Your rights (GDPR / AVG)
If you are in the EEA or otherwise protected by GDPR, you may have the right to:
- access your personal data;
- rectify inaccurate data;
- erase data ("right to be forgotten"), subject to legal limits;
- restrict or object to certain processing;
- data portability, where applicable;
- withdraw consent, where processing is based on consent.
To exercise these rights, contact hello@lemmabase.com . You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl .
10. Children
The Service is not directed to children under 16. We do not knowingly collect personal data from children under 16. If you believe we have done so, contact us and we will take appropriate steps to delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page and revise the "Last updated" date. Material changes may be communicated by additional notice where appropriate.