Legal
Privacy Policy
What personal data we handle, whose it is, why, and for how long.
Last updated 28 July 2026
1. Who we are, and how to reach us
1.1 The provider and the controller. LeMans Labs OÜ, a private limited company (osaühing) incorporated under the law of the Republic of Estonia, Commercial Register code 16872044, registered address Valukoja 8/1, 11415 Tallinn, Estonia. "We", "us" and "our" mean that company. This clause and the corresponding section of the Terms of Service are where our provider information is published; there is no separate legal-notice page, and any link on this site to one is a defect.
``
1.2 We are the controller for everything described here, including reports about people who are not our customers. We decide what is analysed, how, against which rubric, and for how long the result is kept. A buyer is not a controller of what we hold about a report subject, and we do not describe them as one.
1.3 Contact, and notices. Write to [email protected] about anything in this notice, including a request under section 12 or section 13 and a complaint under section 14. Write to [email protected] about anything else, and for a formal notice, a letter from a lawyer or service of documents, which may also be sent to the registered address in 1.1. Those two addresses are the only ones we publish. No account, no fee, no form and no particular form of words.
If a message to [email protected] ever bounces, or you get no acknowledgement within two working days, write to [email protected] and say so. Every period in this notice still runs from the date of your first message, not the second.
1.4 Data protection officer. We have not appointed one. Whether we are required to is being determined with counsel before the first report about a named individual is sold. If we appoint one, the contact address appears in this clause. We will not publish an address before there is a person behind it.
``
1.5 Supervisory authority. The Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), aki.ee. Section 14 explains how to complain.
1.6 Representatives. We are established in the European Union, so we appoint no representative under the rules for controllers outside it, and we have appointed none elsewhere. If we do, we will name them here rather than describe one in the abstract.
2. How to read this notice: two audiences
2.1 This product is unusual in a way that matters. A large part of the personal data we handle is not about our customers. It is about the companies and people our customers ask us to analyse.
2.2 If you are a customer, or considering becoming one, section 3 describes what we hold about you.
2.3 If a report names you, section 4 is written for you, and there is a fuller page at If a Report Names You.
2.4 If your business is you – a sole trader, a one-person consultancy, a named partnership – a report about the business is a report about you, and section 4 applies whichever product was bought.
2.5 Sections 5 to 17 apply to both audiences. Where a rule works differently depending on which you are, it says so.
2.6 The state of the product, and what that means for every verb in this notice. The website is live. Nothing else is: there is no checkout, no account, no sign-in, no report and no email. No report has ever been generated and no order has ever been taken. The only processing that happens today is the web server request logging described in 3.6, the single item of device storage described in section 16, and any message you send us at the addresses in 1.3.
Everything else in this notice describes what will happen when the corresponding part of the product exists. It is written in the future tense for that reason, and each clause states where a control is a condition of the first sale rather than a description of something running. Where any sentence in this notice is nevertheless written in the present tense about a system that does not yet operate, that is a defect in this notice and not a claim we make: the future tense governs, and we will correct the sentence. Tell us at the address in 1.3.
2.7 Where the products are sold. Everywhere, all three, with no territorial restriction on any of them. What protects the person a report is about is not geography but clause 4: a report about a natural person is produced only where that person is the buyer, so their data is disclosed to nobody but themselves.
``
3. If you are a customer
3.1 Account. Your email address, which is also the account identifier, and optionally a display name and a language preference. There will be no password and no password hash: signing in will use a single-use code sent to that address.
3.2 The brief. What you type when you order: the subject's name, a web address, any profile links, the subject's email address where the report is about somebody other than you, and up to 600 characters of free-text context. That context will never be quoted as a finding, never cited as a source, never shown on a shared view and never included in the report data served to anyone you share with. It informs the analysis and does not leave it.
3.3 Payment, tax and location. Payment and invoice references, the amount and currency, your billing country and postal code, your card's brand, last four digits and country of issue, the country we derive from the internet address your order came from together with a one-way hash of that address, and any business tax identification number you give us with the result of validating it.
We will keep the derived country because a cross-border sale of a digital service to a consumer in the EU obliges us to hold evidence of where you were, and a one-way hash cannot show that. We will keep the hash rather than the address itself so that a readable address is not held for as long as that evidence must be, and so that we can recognise the same origin again without being able to read it. Where the billing country and the country of your card disagree we will record the disagreement against the order rather than picking one silently.
We will never receive your card number, its security code, its expiry date or your bank account number. The card form will be served by our payment processor from its own domain, and none of it is ever typed into anything we serve.
3.4 What you agreed to. When checkout exists we will record against your order the exact wording of each separate thing you were shown and actioned, as it was displayed to you, the time you actioned it, and the content-hash version identifier of every document then in force. That record will exist so that each of us can show later what you were told and when, and it is the record we would rely on if a payment for your order were later disputed or if you told us you had not been shown something. None of it exists today, because there is no checkout: no such record has ever been written about anybody.
3.5 Delivery records and reading records. Two different things, kept separately, because only one of them depends on you.
What we did: that your order was accepted and paid; the wording of each confirmation you actioned at checkout as it was displayed to you, with the time; that the report was produced and passed its release checks; the time it became available to you; and that the notification message was transmitted to the address you gave us and accepted or rejected by the receiving mail server, with the provider's reference for that transmission.
What you did: that you signed in, opened the report, created a share link and named the reader it was issued to, that the reader we sent it to confirmed their address and opened it, that you downloaded the report as a file, and when.
Every download is recorded as its own event rather than folded into "you opened it". A page you looked at leaves nothing behind; a file does. How many files exist and when they left is the one thing we could never reconstruct afterwards, so we record it at the moment it happens or not at all.
We will keep both so that we can show a report was produced and delivered, and read where it was read, if a payment is later disputed. The first set does not depend on your opening anything, because a report you never open is still a report we produced and made available to you. We say this rather than log it silently, because logging what somebody reads for an undisclosed purpose would be worse than the logging.
Two limits, because a record of what you read deserves them. It is not a condition of any refund: whether you opened a report, and how much of it you read, makes no difference to your statutory rights, to the withdrawal right described in the Terms of Service, or to any remedy under the Refund Policy. And we will not use it to argue that you had the benefit of something you have told us was not what we described. How long each set is kept is in the Data Retention schedule.
3.6 Technical records. IP address, browser identification and the page requested, in server logs, for security, abuse prevention and operation. This is the one thing in section 3 that happens today.
3.7 What we do not collect, what is required, and what is genuinely optional. We hold no special category data about you, no password, no behavioural profile built across other sites, and nothing bought from a data broker.
Required, because without it there is either no contract we can perform or no lawful sale: your email address; your brief; the subject's email address where the report is about somebody other than you, because section 4 explains that we have to ask them; and your billing country and postal code, which we need in order to work out the tax on your purchase, to keep the evidence of where you were that a cross-border sale obliges us to keep, and to check that a payment is being made by the person the card belongs to.
Also required, because a term of your purchase depends on it: each separate confirmation described in the Terms of Service, which you action yourself and which is never pre-ticked.
Genuinely optional, and refusing costs you nothing: a display name, a language preference, a business tax identification number, the 600 characters of context in your brief, and marketing email. We will not describe anything here as optional that checkout will not let you skip; if the built checkout ever blocks on something listed as optional, this clause is wrong and it changes.
4. If a report names you
4.1 The longer answer, written for you, is at If a Report Names You. This is the summary.
4.2 How a report about you can exist at all. A report about a natural person will be produced in two situations and no others.
(a) You bought it about yourself. We will satisfy ourselves of that by your control of the email address or of the profile the report is bound to.
(b) Somebody else bought it, and you told us you agree. Before anything is produced we will write to you at the address the buyer gave us. That message will name who asked and the organisation they gave, describe what the report is and what it reads, say what it will not read, say how long it lasts, say who is allowed to see it, say that nothing will be produced unless you reply, and link to the page written for you. Nothing about you beyond that message is retrieved before you answer.
You do not have to reply, you do not have to give a reason, and refusing costs you nothing. If you do not confirm within the confirmation window, the order is cancelled and the buyer is refunded in full, automatically, without you or the buyer having to ask. What we keep of that exchange either way is set out in the Data Retention schedule.
A buyer's assurance that they have your permission is not a substitute for asking you. It sits on top of asking you, never instead of it, because permission given to somebody else is not something we can demonstrate.
4.2a How you get the information the law says you are owed. Where information about a person is not collected from that person, the controller owes them a notice. The message in 4.2(b) is that notice, and it arrives before anything is produced rather than afterwards. This notice and the page at If a Report Names You are published, indexable, need no account, and are linked from the footer of every page. Where you bought the report about yourself, you gave us the information and 4.2(a) is the whole answer.
We do not rely on the argument that telling you would be disproportionate, and we do not rely on the argument that telling you would harm you. The first is not available to us now that we hold an address for you and use it. The second is the seller deciding what is good for a person it never asked.
``
4.3 What we hold. Your name, the matching key we derive from it, the profile address the buyer supplied, the address we wrote to under 4.2(b) and your reply, a short role, company and location string, and a country. The evidence behind each finding: page addresses, domains, titles, extracted text, retrieval times, content fingerprints and stored copies of the pages we read. And the report: each finding with its tone and confidence, the section text, six dimension values from 0 to 100 with a note for each, the headline score, the band label and a verdict sentence.
The matching key is how we decide that two things are about the same person, and it decides which evidence attaches to which record. A key derived from a name alone cannot do that: two people with the same name resolve to one record, and one person's evidence and score can attach to the other. No report about a named individual will be sold until that key is anchored to a resolvable profile address, a brief that supplies a name alone is refused before payment, and an order whose subject cannot be resolved to one identifiable person is cancelled and refunded in full. If you believe a report has attached somebody else's record to your name, tell us: we treat it under 12.5(a) as a finding the evidence does not support, and under section 13 if you want us to stop entirely.
4.3a What we do not do with your name. For a report about a named individual we will not ask AI assistants who you are, and no answer an assistant gives about you is retrieved, stored or scored. Your name will still reach a search provider as a query, and will reach the model providers that read the retrieved text and write the findings. That is the whole of where it goes. Assistant answers exist only for a report whose subject is a company, and where we detect that a company report's subject is in substance one individual we apply the individual rules to it.
4.4 Two layers, and the difference matters. The first is a record of what somebody else published. The second is what we wrote: our findings, our characterisations and every number. The second layer is not somebody else's error and cannot be corrected by pointing at a source. Section 12.5 treats them differently, on purpose.
4.5 What we do not read. Private or restricted accounts, anything behind a login, anything obtained by getting around a paywall, and files bought from data brokers. Where the subject is a person, we read the public professional record and nothing outside it.
4.6 We do not publish reports, and who else may read one depends on whose report it is. A report a buyer orders goes to that buyer. It is not listed, not indexed and not made public by us, and we sell no route by which a stranger can find one.
Beyond the buyer there are two answers, and they differ on purpose.
A report about the buyer themselves is theirs to show. They may give it to anyone they judge fit, their staff and their professional advisers included, and their lender, their investors and their board included too. It is an assessment of them and it is their own data, and we do not stand between a person and a document about that person.
A report about a company goes to the buyer's own personnel and to their professional advisers, who are under a duty of confidence, and no wider. That is the whole of the permitted audience, and it holds for every company report, including one whose subject our pipeline finds to be in substance one living person. Where the person assessed did not choose the audience, the narrow circle is what stands in place of that choice.
Either way, a buyer may not attribute a public statement about a person or a company to us, and may not present our writing as anything other than ours. Those restrictions are stated in full in the contract; this clause describes them and adds nothing to them.
4.6a How a report reaches a second reader, in one paragraph. There are two routes and no others: a file the buyer downloads, and a link. For a link the buyer names the reader and gives us that reader's email address, we send the link ourselves, and before the first view the reader confirms that same address with a code we email them, which is the mechanism the buyer signs in with. So there is no anonymous link and no forwardable one: an address pasted into a group chat opens nothing for whoever reads it there. Every view is served and recorded by us, no link outlives the report's ninety-day window, and revoking a report stops every link for it from the next request onwards. A file, once downloaded, is outside all of that, and 11.4(a) says so rather than hiding it.
One exception, named here rather than left to be found. Demonstration reports are published at /samples and are open to search engines. They exist to show the format and the rubric, and every number in them was written to demonstrate the layout rather than to measure anything. If you are named in one, write to us and we will remove it the same working day, without argument and without asking for a reason.
4.7 Nothing in a buyer's contract with us limits or affects your rights. A term the buyer accepted cannot bind you, and we will not argue that it does.
4.8 People who are not the subject but appear in the evidence. A page we read about one person will often name others: co-founders, colleagues, board members, the journalist who wrote the coverage, people named in it. Those people are not the subject of the report and we do not analyse them, but their names are in the material we store, so we say what happens to it.
(a) We do not build a record about them, do not score them, do not create a matching key for them, and do not carry them forward to any other report. They exist only inside the stored copy of the source that mentioned them, for as long as that source is kept for the report it belongs to, and it is destroyed with the report.
(b) A finding must be about the subject. Where a source names another person, the finding drawn from it must not characterise, rate or make an assertion about that person, and their name appears in a report only where it is part of the source being cited.
(c) The rights in section 12 and the routes in section 13 are open to them on the same terms and by the same address, with no account and no fee. Because we hold no record keyed to them, an objection is met by removing the material naming them from the evidence for the report in question rather than by adding them to a list, and we will tell them plainly that we cannot pre-emptively prevent their name appearing in a future source we read.
(d) Our basis for holding this material is the legitimate interest stated in section 5, weighed for this group separately: they are named incidentally rather than analysed, no assessment is made of them, nothing is retained about them beyond the life of the source, and the material is a copy of what a publisher already published. That separate weighing is part of the written assessment described in 5.2 and is not yet completed.
``
4.9 People under 18. We will not knowingly produce a report about a person under 18, at any price, for any buyer, for any reason. Where the public record cannot place a subject in adulthood we refuse rather than resolve the doubt in our own favour. If a parent, a guardian or the young person tells us we have produced one, we will delete it and every copy under our control immediately, we will require the buyer to do the same, we will not ask anyone to prove a relationship, and we will not argue about it. The Acceptable Use Policy states the same rule as a term binding the buyer. The eligibility check that enforces it is not built and is a condition of the first sale.
5. Lawful bases, in a table
5.1 One row per activity. Where the basis is legitimate interests, the interest is named. Nothing in this table describes something running today.
| What we do | Whose data | Basis | The interest, where relevant |
|---|---|---|---|
| Create an account and sign you in | Customer | Contract, Art 6(1)(b) | – |
| Take payment and issue an invoice | Customer | Contract, Art 6(1)(b) | – |
| Keep the tax and accounting record | Customer | Legal obligation, Art 6(1)(c) | – |
| Keep evidence of where you were when you bought, as indirect tax rules require | Customer | Legal obligation, Art 6(1)(c) | – |
| Keep the record of what you were shown and agreed to at checkout | Customer | Contract, Art 6(1)(b) while the contract runs, and legitimate interests, Art 6(1)(f), for the period afterwards | Being able to establish what you were told and agreed to if a purchase, a withdrawal or a payment dispute is questioned later |
| Keep the delivery and access records described in 3.5, and screen for payment fraud | Customer | Legitimate interests, Art 6(1)(f) | Operating your account, refusing automated abuse, and answering a question about a charge, including in your favour |
| Issue a share link to a reader the buyer names, serve that reader the report, record each view, and record each download of a report as a file | Customer; the report subject; and the named reader | Contract, Art 6(1)(b), which is also the basis where the buyer is the person the report assesses. Legitimate interests, Art 6(1)(f), for the reader's own details, for the record of what was viewed and downloaded, and for the subject of a company report who is in substance one living person | Delivering what was bought in the form it was bought in; serving every view ourselves, which is what lets a link be stopped and its readers named; and being able to say how many copies of a report left our servers and when, which is the only true thing left to say about a file we cannot reach |
| Send the link to the named reader, send that reader the code that confirms their address before the first view, and write to them again if the report is later corrected or withdrawn | The named reader | Contract, Art 6(1)(b), whose instruction the message carries, and legitimate interests, Art 6(1)(f), for the correction notice | Sending the link ourselves rather than handing a buyer a token, which is what makes a reader somebody we checked rather than whoever holds an address; and telling a reader that what they read has changed, which we can do ourselves and should not delegate |
| Check the buyer, and the person or company named in a brief, against the restricted-party lists that apply to us | Customer and report subject | Legal obligation, Art 6(1)(c) where one applies, otherwise legitimate interests, Art 6(1)(f) | Not supplying a paid analysis to, or about, a person we are prohibited from dealing with |
| Write to a named person to ask whether they agree to a report about them, and hold what we need in order to ask | Report subject | Legitimate interests, Art 6(1)(f) | Asking the person themselves rather than proceeding on somebody else's assurance about them |
| Produce and deliver a report the buyer ordered about themselves | Customer, who is also the subject | Contract, Art 6(1)(b) | – |
| Produce a report about a person other than the buyer, and retrieve and keep the evidence behind it | Report subject | Consent, Art 6(1)(a), given to us by that person and withdrawable at any time | – |
| Analyse a company whose subject is in substance one individual | Report subject | Legitimate interests, Art 6(1)(f) | Supplying an analysis of a business's public professional record where the business and the person are in substance the same |
| Put a named subject to a search provider as a query | Report subject | The same basis as the report it is part of | – |
| Ask AI assistants about a named company | Company subject, and any person an answer names | Legitimate interests, Art 6(1)(f) | Measuring how AI systems describe a company, which is part of that analysis. Not done where the subject is a natural person |
| Hold the personal data of people named incidentally inside a stored source | Third parties in sources | Legitimate interests, Art 6(1)(f) | Keeping a source as it was published, which cannot be done by editing other people's names out of it |
| Keep the record of the automated calls made while a report was produced | Report subject and customer | Legitimate interests, Art 6(1)(f) | Being able to reconstruct how a finding was produced if that finding is challenged |
| Keep a list of people who have asked us not to produce reports about them | Report subject | Legitimate interests, Art 6(1)(f) | Making a request not to be analysed effective for the future, which cannot be honoured without keeping the minimum needed to recognise a later order. The list is never published and is used for nothing else |
| Record and answer a rights request | Either | Legal obligation, Art 6(1)(c) | – |
| Keep server logs for security, abuse prevention and operation | Visitor | Legitimate interests, Art 6(1)(f) | Keeping the service available and refusing automated abuse |
| Send transactional email about something you bought | Customer | Contract, Art 6(1)(b) | – |
| Send product or marketing email | Customer | Consent, Art 6(1)(a) | – |
| Remember your storage choice on this site | Visitor | Section 16 and the Cookie Policy | – |
5.1a Accountability under Art 5(2) is a duty and not a lawful basis, and it is not relied on as one in any row above. It is why several of these records are kept; it is not the ground on which they are kept.
5.1b The permission asked for before a link is created is a control, not a basis. When a buyer creates a share link we ask them, then and there and separately from anything agreed at checkout, to permit that disclosure, and the permission can be withdrawn. It is there so that sending a report to a second reader is a deliberate act rather than a side effect of buying one. It is not the lawful basis for the disclosure, and we do not present it as one: the basis is the contract row above. Calling it a basis would mean telling you that withdrawing it is what stops a link, when what actually stops a link is that we serve every view of it.
5.2 The report-subject rows, in plain terms. Where a report is about somebody other than the buyer, what makes it lawful is that person's own consent, given to us and demonstrable by us. That changes the shape of everything downstream: consent can be withdrawn at any time, withdrawal is as easy as giving it, withdrawal is free of any detriment to the person withdrawing, and section 13 is the route.
Legitimate interests still carries three narrower things: asking you in the first place, a report about a business that is in substance one person, and the names of people who appear incidentally inside a stored source. For those the balance depends on a closed set of limits, and each is a condition of the processing rather than an aspiration:
(a) the public professional record only;
(b) no special-category material and no criminal-offence material, refused at the point material is written to storage rather than filtered out at the end;
(c) no publication by us, and a contractual bar on publication by the buyer;
(d) delivery to the buyer who ordered it, and beyond them only to the buyer's own personnel and professional advisers under a duty of confidence, whether the report is read on screen, downloaded as a file, or opened under a link issued to a named reader. We supply the file and the link, so this is a limit we operate rather than one we imposed on somebody else, and 5.2b says what that costs;
(e) the retention rules in section 11 and in the Data Retention schedule;
(f) a correction route that works, including the onward notice in 12.5;
(g) an objection, withdrawal and suppression route that works, as described in section 13; and
(h) no identity questions about a natural person put to an AI assistant.
Where any of those limits is not in operation, we do not rely on legitimate interests for a report that names an individual, and we do not produce or sell one. That is the consequence, not a plan to fix the product later.
5.2b What changed when the file and the link shipped, and why we re-did the balance instead of reusing it. Until this release limit (d) held because the product could not break it: there was no file to keep and no link to send. It now holds because we operate it. A limit somebody operates is weaker than a limit that is a fact of the build, and we would rather say so than let the same words go on carrying a stronger meaning.
So the written assessment in 5.2a was redone and re-dated before the release rather than after it. On the side against us, stated first because it is the real one: a document assessing a person can now outlive the ninety days we promised, in hands we cannot see, because a downloaded file is not ours to reach. That weighs heavier for a file than for a screen, and it weighs heaviest in one case. Where a company report's subject is in substance one living person, that person is not our customer, has agreed to nothing and has attested nothing, and legitimate interests is the whole of the basis for the file and the link as well as for the report. We considered withholding the file and the link in that case and decided, on this release, not to. The decision is dated and recorded, it is open to objection under 13.3 on its own facts, and we review it on the first objection from such a person. We are not going to describe it as a control we built.
On our side: the permission to create a link is asked for at the moment of creation and can be withdrawn; a link is issued to a reader the buyer names, we send it, and that reader confirms the address with a code before the first view, so a forwarded address opens nothing; every view is served and recorded by us, so revoking a report stops every link from the next request onwards; no link outlives the ninety-day window; every download is recorded on its own, so the number of files outside our reach is known rather than guessed; we write to the readers of link views ourselves under 12.5a instead of asking the buyer to do it for us; every page of the file carries the report version, the time it was produced, a confidentiality notice, the line saying the report must not be used to screen anyone, and a link to the page written for report subjects; and 8.3a is a route to a person who will re-examine the assessment and any dimension value in it.
5.2a The assessment itself. The written balancing assessment is dated, is reviewed at least once a year, and exists before the first report about a named individual is produced. It weighs the position of people named incidentally in the evidence as well as the subject's. Once it exists we will send you the assessment in writing if you ask, with only the redactions needed to protect another person's personal data or a specific security control, and we will tell you where we redacted and why. If a Report Names You makes the same offer in the same terms.
5.3 What we do not rely on. Not the buyer's contract, because a person a report is about is not party to it. Not a buyer's attestation that they have somebody's permission, because a third party's assertion that permission exists is not a demonstration that it does. Not consent where we have not asked the person ourselves.
5.4 Screening, set out separately because it is the one activity that reaches a report subject before any report exists. Before an order is accepted we will check the buyer's details, and the name and identifiers given for the subject, against the restricted-party lists that apply to us. The check will run against list data licensed from a screening provider named in the Sub-processors list. That is not the purchase of a profile about anybody, nothing from it is added to a report or kept as part of one, and a list entry is not a finding. A possible match will be looked at by a person before an order is refused, and no order will be refused on an automated match alone. Where an order is refused on this ground the buyer will be refunded in full and we may not be able to say why. We will keep the fact that a check was run, its outcome and the version of the list, for the period in the Data Retention schedule, and nothing else from it. Screening carried out by our payment processor is its own activity as its own controller and discharges no part of this. None of it is running today, and it is a condition of the first sale.
``
``
6. Special categories, criminal-offence material, and where the control sits
6.1 What a report will not contain. No report will contain information revealing health, political opinions, religious or philosophical beliefs, trade union membership, sex life, sexual orientation, biometric or genetic data, or racial or ethnic origin.
We write that in the future tense on purpose. The control that refuses to write such material at the point evidence is committed to storage is specified and not in service. Asking a search provider who somebody is can return material of exactly this kind, so a rule that operates only when a report is composed would leave the material retrieved and stored before the rule applied.
Until that control is in service we will produce and sell no report about a named individual. None has been produced or sold. Where this notice, the page at If a Report Names You or any other page on this site states this prohibition in the present tense, this clause governs and those statements are to be read as describing what will be true when that control operates.
6.1a The same prohibition applies to material about criminal convictions, criminal offences, allegations of an offence, and proceedings about one. That category has its own rule, stricter than the general one, and we hold no official authority and rely on no member state law that would let us handle it. It is a category a product like ours will encounter, because a search for a named person's professional record returns litigation, regulatory action and allegations. So it is named here rather than left to be inferred from the general list, and it is caught by the same control at the same point.
``
6.1b The editorial rule. A separate editorial rule will keep politics, personal life, litigation and personal temperament out of every report. It is a rule the product must enforce at the point described in 6.3, not a description of a filter that runs today. What the published rubric does score, including the one dimension that reads the tone of published coverage, is described in 8.6 and in full at /intelligence-score. Where that page and this notice differ, that page governs and this notice is the defect.
6.2 Why that is a prohibition and not a legal basis. No condition in the special-category rules is available to a commercial profiling product like this one. So the answer is not to find a basis. The answer is not to handle the material at all.
6.3 Where the control has to sit. The prohibition bites on handling the information, not on printing it, so a filter that drops a finding at the end is not enough: by then the material has been retrieved and stored. The control has to refuse to write it, at the point evidence is committed to storage, so that a page carrying such material is discarded rather than kept and later suppressed. Where such material is nevertheless found in storage it will be destroyed on discovery rather than at the end of a period. It is not built today, and no report about a named individual has ever been produced.
6.4 What we will record about it. The number of items discarded, never their content. A discard rate of zero will be treated as a fault in the control rather than a clean run, because a search for who somebody is can routinely produce material of exactly this kind. We will measure how often, across real subjects, rather than assume it does not happen.
``
7. Where the information comes from
7.1 From you, if you are a customer: what you type, and what your payment gives us.
7.2 If a report names you: what the buyer typed about you, what you told us in reply to the request in 4.2(b), and the public sources we then read. The sources, by class: public web pages we retrieve directly; search results obtained through a search provider; public review platforms; and, for a company subject only, the answers of AI assistants asked about that company. Every provider is named in section 9.
7.3 What we never use as a source. Data brokers. Private or restricted profiles. Anything needing credentials we do not have. Anything behind a paywall obtained by getting around it.
7.4 We will honour publishers' machine-readable instructions, including robots directives and reservations against text and data mining, whether expressed in a robots file, a response header or an equivalent file. A page we are asked not to read will be recorded as unread rather than quietly omitted, so a gap in a report is visible instead of invisible. No page has been fetched yet, and the fetcher that has to obey these rules is not built. Obeying them is a condition of the first report, not a refinement afterwards.
7.5 One consequence you should not have to discover. When we read a page on your own website, that site's logs will show the visit. Our fetcher will identify itself by name and give an address explaining what it is, so that whoever runs the site can see who asked and why.
7.5a We do not rely on 7.5 as the way you find out that a report about you exists. That is what 4.2 is for. A server log entry is not a notice, most people never see one, and a company that treated it as one would be relying on the subject's own vigilance to discharge its own duty.
7.6 Names are not identifiers. Two people can share a name, and matching on a name alone produces both false matches and missed ones. A report about a person must be anchored to a resolvable profile address, and a brief supplying a name only must be refused before payment. That is a change the product has to make before it sells a report about a named individual, and the accuracy of everything else depends on it. 4.3 states the same rule and adds nothing to it.
8. Automated processing, profiling and the score
8.1 This is profiling, and we call it that. A report evaluates personal aspects of an identified individual, namely how the public record describes their professional work, and expresses part of the result as a number.
8.2 How the number is produced. Six dimensions, each scored from 0 to 100 against a rubric published at /intelligence-score. The headline is the plain unweighted arithmetic mean of those six values, rounded once. No weighting and no curve. You can reproduce the arithmetic by hand from the six printed values, and if you cannot, the number is wrong. The judgement underneath the arithmetic is not reproducible in the same way, and the AI Transparency and Limitations notice says so.
8.3 No human will review a report before it is delivered. Every quality gate is automated. We say so plainly, because a buyer paying for an assessment of a named person will otherwise assume somebody looked at it. That is a statement about how a report is produced, not about what happens afterwards: 8.3a is the route to a person.
8.3a Asking a person to look at the assessment, and saying it is wrong. Every report carries a route to have its assessment examined by a person: to contest the headline figure and any one of the six dimension values, to say in your own words why you think it is wrong, and to have the assessment changed under 12.5 or marked as disputed. The arithmetic in 8.2 does not move, because it is published and you can check it yourself. What a person re-examines is the judgement underneath a value. The route is printed in the report itself and not only in this notice, because whoever needs it is reading the document rather than our policies.
We built it before we shipped the file and the link, and the order matters. Once a report can be handed to somebody else, a number about a person starts doing work inside decisions we never see. That does not make us the maker of those decisions, and 8.5 says so. It does mean that a company willing to put a number on a person and unwilling to be argued with about it would have very little to say for itself.
8.4 What we do with the result, and what we keep of it. We produce a document and deliver it to one buyer. We do not act on it, we do not rank people against one another, and we sell nothing that turns a score into an outcome.
We will keep a record of the score, and you should know its shape rather than infer it. The headline figure survives the report inside the transaction record kept for tax and accounting, which will not carry your name once the copy of the brief held with the order is reduced under the Data Retention schedule. We do not build a time series from those figures, do not display one, do not use one as an input to a later report, and do not offer one for sale. Because a subject record is destroyed with the report that created it and is never reused for a later order, we cannot tell you how many reports about you were ever produced once they have expired; while a report about you is live, if you ask, we will tell you that it exists, when it was produced and what it scored.
8.5 What a buyer does is a different question, and we do not pretend otherwise. A score, a band and a ranked set of recommendations is shaped like a decision even when it is not one. So a buyer is contractually prohibited from using a report for employment, credit, insurance, housing or tenant screening, or as the sole or determining input into a decision about a person, and is told in the contract that they are the decision-maker and may carry obligations we do not. Saying this is not an acceptance that the rules on solely automated decisions with legal or similarly significant effect apply to us.
8.6 What the score is not, and the one dimension that has to be described rather than denied. It is not a valuation, not a prediction, not a ranking, not a judgement of quality, and not a rating of you as a person. It reads how legible and consistent your public professional record is, not how good you are, and scores produced under different rubrics cannot be compared.
One of the six dimensions is called Reputation, and it is not a popularity measure and records nobody's approval of you. It reads the tone of published coverage of your professional work, including critical coverage, and it reads lower where criticism sits high in results unanswered, where sentiment splits sharply by source, or where the most recent substantial coverage is old. We describe it rather than deny it because the published rubric says so and you can check. Your politics, your personal life, your health, your temperament and litigation you are involved in are not inputs and cannot become inputs.
A confidence label measures how much material agrees, not whether it is true: four sources repeating one wrong thing will read as strong evidence. The full account is at AI Transparency and Limitations.
``
9. Who else handles the data
9.1 The recipients, named, with the role each has. Only the first handles anything today, because only the website is live; the rest take their role when the product runs. Cloudflare hosts this site, serves it and provides its DNS and bot protection. Hetzner will provide the machine in Helsinki that our database and this application both run on. Cloudflare will also hold the collected evidence, a report's preview image, and our daily encrypted database backup, which contains the full text of every live report. Cloudflare additionally terminates the encryption between a reader and this site, so it is in a position to see the pages we serve and not only the requests for them, including a report opened in an account and a report served under a share link. Stripe will process payments, tax calculation and invoicing. OpenRouter will route our requests to model providers, and those providers are recipients too. Serper will return search results for queries built from the brief, which for a report about a person includes that person's name. Resend will send transactional email, delivered through Amazon SES, which for a report about a person other than the buyer includes the request described in 4.2(b). PostHog would provide product analytics and Sentry error monitoring, and neither is switched on. PostHog applies its own AI features to the data in an analytics project and offers no setting to disable them; clause 2.8 of the Sub-processor list makes that a condition of ever enabling analytics rather than a description of anything happening now. AI assistants – ChatGPT, Claude, Gemini and Perplexity – will be asked about a named company as part of a Company X-Ray, which makes each of them a recipient of that company's name. They are not asked who a natural person is, so a natural-person subject's name does not reach them from us.
9.2 The authoritative list, with what each sees, where it is and the transfer mechanism relied on, is at Sub-processors, dated with the day each row was checked. Where this section and that page differ, that page is correct.
9.3 We do not say that every recipient is bound by a data processing agreement, because it is not true yet. No such agreement has been executed with any of them, and none will receive personal data in production until one is. Two of them receive visitor data today from the live site, and 10.3a states that position rather than leaving it inside this sentence. This clause replaces an earlier statement on this site that every recipient was already bound by an agreement.
9.4 What we never do. We do not sell personal data. We do not share it with anyone for their own purposes. We supply it to no advertising network or data broker and take part in no cross-site data-sharing arrangement.
9.5 Model training, and what we will not claim. Your brief and the evidence collected for a report will be sent to the model and search providers named above, because that is how a report is produced. We will route only through providers whose terms exclude our traffic from training their models, we will pin those providers by name rather than accept whichever one a router selects, and an automated test will assert the pin. Until that pin exists and the test passes, we make no unqualified statement that nothing we send is used for training. What we can say now without qualification is that we sell nothing a buyer submits, we train no model of our own on it, and we do not reuse the evidence collected for one report to build a general corpus.
9.5a Two claims that must not appear anywhere on this site. That inputs are never shared with third parties: that is false, and 9.5 says what actually happens. That inputs are never used to train models: that is a commitment we have not yet earned. Any surface of ours carrying either claim is corrected or taken down in the same release as this notice. A conflict rule in a legal notice is not a substitute for correcting a claim a buyer meets at the point of sale, and we do not offer one.
``
9.6 If this business is sold. We will not transfer information we hold about report subjects on a merger, an acquisition, a reorganisation or a sale of the business or of this product line unless the transferee has first agreed in writing to be bound by the retention rules in section 11, the rule against publication, the correction procedure in 12.5, the routes in section 13 and the suppression list. Where a transferee will not give that undertaking, the information is deleted before the transfer.
That is a commitment about what we will do, and we state its limits rather than imply a guarantee we could not enforce. A transfer of shares in LeMans Labs OÜ moves no information anywhere, and this notice continues to apply unchanged. A disposal by a liquidator, an administrator or a secured creditor, or a transfer compelled by a court, is not ours to condition or to prevent. In any of those events we will publish a notice at a fixed address on this site naming who holds the information and from what date, so that the people it is about can exercise their rights against whoever holds it.
Retention periods survive a change of control. This clause exists because the people that information is about have no contract with anyone and cannot negotiate with a buyer of the business.
``
9.7 Legal disclosure. We may disclose information where the law or a valid order requires it. Where we are permitted to tell you, we will.
10. Sending data outside the EEA
10.1 Yes, information will leave the EEA. Producing a report about a named person will send that person's name outside it more than once: to the search provider as a query, to the routing provider as prompt content passed on to further providers, into job payloads, and to the email provider as the address we write to under 4.2(b). For a company subject it also reaches the AI assistant providers.
10.2 The mechanism is stated per recipient in the table at Sub-processors, because a list of recipients without their mechanisms is incomplete and a mechanism without the list is unreadable.
10.3 Our posture, described rather than certified. Where an adequacy decision covers a recipient we will rely on it. Otherwise we will rely on the European Commission's standard contractual clauses for a transfer from a controller to a processor, with a written assessment of the recipient's jurisdiction held on file. We assert no provider's certification status in this notice; each will be checked, recorded and dated on the sub-processor page.
10.3a What is true today. No transfer instrument has been executed with any recipient and no jurisdiction assessment has been completed. Two recipients already handle personal data: the host that serves this website and the network provider in front of it both receive the IP address, browser identification and requested page of every visit, and both are United States companies operating global networks, so a request may be handled outside the European Economic Area. Until the clauses are executed and the assessments are on file for those two, that transfer rests on no mechanism we are willing to name, and we would rather record it here than describe a safeguard we do not have. Executing both instruments and completing both assessments is a condition of this notice being published, not a condition of the first sale.
10.4 The honest limits. The sub-processor table cannot be completed while the routing configuration is free to choose a model provider dynamically, because we cannot name a recipient we have not pinned. One recipient's region is not yet fixed, and the page will state no region until it is. Both are conditions of the first sale rather than improvements to be made later. A copy of the mechanism relied on for a particular recipient is available on request.
``
11. How long we keep things
11.1 The schedule is published separately, class by class, at Data Retention. That schedule carries every period we apply and governs on the length of any period. This notice restates exactly one figure, the ninety-day report window in 11.3, because it is part of what this notice promises to a person a report names. If a second figure ever appears here, it is a defect in both documents and the schedule is the correct one.
11.2 The criteria we apply. We keep information as long as it is needed for the purpose it was collected for. Where a legal obligation fixes a period, we keep it for that period and no longer. Where a complaint or a claim is live, we keep what is needed to deal with it.
11.3 The rule for a report. A report's content, the evidence behind it and the files generated from it on our servers will expire and be destroyed ninety days after the report is ready. That reaches the files we hold; it does not reach a file somebody downloaded while the report was live, which no period of ours governs at all, and 11.4(a) says what does. Expiry is a change of state; deletion destroys the content; the retention schedule explains what survives each and when the window is extended.
11.3a The job that gives effect to those periods is not built, and nothing expires today. Until it runs and has been observed to run end to end, including the subject-side deletion, every period is a commitment rather than a description. Building it is a condition of the first sale, and the retention schedule says so on its own face.
11.4 What outlives a report about you, and we would rather say so than let you find out. Expiry ends the report. It does not end every record connected to it. The class-by-class list is in the Data Retention schedule and governs; this is that list in short form, and where a class is added there it is added here in the same release.
(a) A file the buyer downloaded, and whatever they copied out by hand. Until this release there was no export, and this limb covered a note, a screenshot or a retyped passage. It now covers the report itself: a downloaded file is the whole document, it carries no expiry, and no period on this page or in the schedule governs it.
We can end the buyer's licence to use it, require them to destroy it and to recall what they sent, and we do. We cannot see that a copy was made, we cannot reach it, and we will not tell you that we destroyed it, because that is the one sentence here you could never check. What we can tell you, from our own records, is how many times the report was downloaded and when. That is why every download is recorded separately.
(b) The consent record described in 4.2(b) – the address we wrote to, the wording of the request as sent, the time, and whether it was confirmed, declined or left unanswered – because consent has to remain demonstrable by us, and because a record of an unconfirmed request is what stops the same request being sent to the same person again and again.
(c) Our own email delivery records, from which anything naming a report subject is removed when that report expires or is deleted. That removal is not yet running.
(d) The transaction record kept for tax and accounting. The copy of the buyer's brief held with it is reduced to a record that a brief existed, carrying no name, no profile address and no context text, automatically and without anybody asking, on the earliest of the report's expiry, its deletion, or a request from the person named in it. That reduction is a condition of this clause being published.
(e) The record of any rights request and what we did about it, and an entry on the list described in 13.5 if you asked for one, both kept because deleting them would defeat the purpose they exist for.
(f) Anything under a hold where a complaint or a claim is live and the material is evidence in it. A hold cannot be placed because of a request you made; 11.7 explains.
For a buyer, three further classes outlive a report: the order, payment, refund and dispute record; the record of what was shown and agreed at checkout; and the delivery and access records in 3.5, kept until a payment for that report can no longer be disputed. Nothing in any of these lists carries report content, findings, scores, the evidence behind a finding, or what a buyer wrote in the context field.
11.4a What the ninety-day figure does and does not do. It bounds the report and the evidence behind it. It does not bound the classes in 11.4. We state that plainly, because the ninety-day rule is the strongest thing we say about how we treat a person who did not seek this, and a figure that covers only part of what we hold is worth less than a longer figure that is accurate. A subject record will be destroyed with the report that created it and will not be reused, so a second order about the same person will not extend the first record's life.
11.5 Records of rights requests, and the one store nothing can be removed from. Every request will be recorded in a register: what was asked, how we satisfied ourselves who was asking, what we did and when. That register carries the period in the retention schedule and can be corrected and deleted like anything else we hold.
Separately, a tamper-evident system log will record that a request of a given type occurred and was completed. Entries in it cannot be edited or removed, so nothing written into it could afterwards be erased. For that reason it must not carry a name, an email address, a profile address or any other identifier that resolves to a person: it records the type of action, the identifier of the record touched, and the time. Today that is a rule for whoever writes to it rather than a control that refuses the write. Two things follow, and both are conditions of the first sale: the write path must refuse a value capable of identifying a report subject, and there must be a route to remove one if it ever appears. Until both exist, no report about a named individual will be produced, so nothing in that store can name one. If an identifier ever reaches it we will tell the person, treat it as an incident, and record in section 17 what we did about it.
11.6 Backups. Deletion propagates to backups as those backups roll off, rather than instantly. We do not reach into a backup to edit it, because a system that can edit its own history cannot show what it did.
11.7 Holds, and the one they cannot be placed for. Where a report, a finding or an order is the subject of a payment dispute, a regulatory enquiry, a claim, or a complaint made by someone other than the person the material is about, we will suspend expiry and deletion for the material relevant to that matter. A hold reaches only what is relevant, never a class or an account wholesale. It is a stop on destruction and not a permission: held material is not read for any other purpose, is not shared with the person who complained, and the fact that something is held tells that person nothing about anybody else. It ends when the matter ends.
A hold will not be placed because of something you asked us for. Where the matter arises from a correction request, an objection, a withdrawal of the agreement you gave us, an erasure request or a complaint about a report that names you, we do not hold the material on that basis, and we will not treat your exercise of a right as a reason to keep material about you for longer. One request runs the other way and only in your favour: you can ask us to preserve material about you rather than let it expire while a dispute or a correction is looked at, and where you do, we preserve it, use it only to answer that matter, give it to nobody, and destroy it when the matter ends. Ask early: once a period has run the material is gone, and after the backup cycle it is not in a backup either. The hold mechanism does not exist today and is a condition of the first sale.
``
12. Your rights, and how to use them
12.1 The rights. To see what we hold about you and how we use it. To have inaccurate information corrected. To have information erased. To restrict what we do with it. To receive a copy of what you gave us in a portable form. To object. And, where consent is the basis, to withdraw it at any time, as easily as you gave it and with no detriment for withdrawing.
12.2 How to use them. Write to [email protected]. No account, no fee, no form and no particular wording. If a report names you, you have never had an account with us and we will not ask you to create one.
What we hold today is: the server request logs described in 3.6; the storage item described in section 16; and any message you send us at the addresses in 1.3, together with our reply and any attachment. No report has been produced and no order has been taken, so we hold nothing described in 3.1 to 3.5 or in section 4 about anybody. The rights-request register in 11.5, the verification rule in 12.4 and the named person accountable for answering will be in place before the first report is sold. This clause is not published until the address named in it receives mail and is answered from.
12.3 How long we take. We acknowledge your request within one business day of it arriving. We answer without undue delay and in any event within one month of it arriving. If a request is genuinely complex, or you have made several, we may take up to two further months, and if we do we will tell you inside the first month and say why. The clock starts when your request arrives, not when we finish confirming who you are. A business day means a day other than a Saturday, a Sunday or a public holiday in Estonia, and every period stated in days across this set is counted the same way.
Inside that month these are the periods we hold ourselves to. A statement about you as an individual that you tell us is wrong is suppressed within three business days. Production of any report about you stops immediately on a withdrawal or an objection, and the deletion is completed, the buyer told and the outcome confirmed to you within fourteen days. A correction, an erasure or a restriction is completed within fourteen days. The reasoned outcome of a re-examination reaches you within twenty-one days.
These are the only periods we publish for a rights request, and they are the same periods as those in If a Report Names You. Where any other page of ours states a different period for the same act, the shorter period binds us and the longer one is a defect we will correct.
12.4 Confirming who you are. Only where we have a genuine doubt, and only so far as the request makes necessary. We do not demand identity documents as a matter of routine. Where a report is anchored to a profile address, showing that you control that address is enough; where we wrote to you under 4.2(b), a reply from that address is enough. If you decline to send us more personal information than the request itself involves, we will not treat that as a failure to identify yourself.
12.5 Correcting something that is wrong. There are three outcomes and we state all three, including the uncomfortable one.
(a) The evidence does not support the finding. We remove or amend it and regenerate the affected part of the report.
(b) The finding is our own assessment, and the assessment is wrong or cannot be derived from the evidence printed beside it. We change it. It is our statement, not somebody else's, and it is ours to correct.
(c) The evidence supports the finding, but the public source is itself wrong. We do not rewrite what we observed, because a report that quietly rewrote the record would be misdescribing what it read. We record your position alongside the finding, mark the statement as disputed, and tell you which source it came from so you can take it up with the publisher.
Where the subject is an individual and the disputed statement is damaging, the default is to suppress it first and examine afterwards, not the other way round. We do not ask you first whether the statement is unfavourable and we do not weigh how damaging it is before we act.
12.5a Corrections have to travel, and we carry the part we can carry ourselves. Where a correction, a suppression or a withdrawal is applied to a delivered report, it reaches our copy and every share link for that report at once. We serve every view of a link ourselves, so the next request after we act serves the corrected report or nothing at all.
We know who the readers are, because the buyer named each of them and gave us the address, we sent the link, and each reader confirmed that address with a code before their first view. So where a reader opened a link before we acted, we write to that reader ourselves, at the address the link was issued to, and we record that we did. We do not ask the buyer to pass that notice on for us. An obligation we can discharge ourselves is not one to hand to somebody else.
For a file the buyer downloaded we cannot do that, because we do not know who they gave it to. So we tell the buyer, record that we told them, and require them under their contract with us to pass the same notice within five days to every person they gave the file, or any finding or score from it, and to confirm to us that they have. That covenant is carried by the Terms of Service and must exist there for this paragraph to mean anything.
Where the subject is a natural person and the corrected, suppressed or withdrawn statement was unfavourable to them, we tell that person: each reader a link was issued to and the date we notified them, the categories of person the buyer was required to notify and whether the buyer has confirmed doing so, and how many times the report was downloaded and when. We can name a reader because we checked one. We hold a reader's name and address with the report and destroy both with it, so while the report is live we name them, and after it is gone we have the count and the dates and nothing else. The Data Retention schedule says the same in the same words.
Notifying the buyer alone does not discharge this clause, because a correction that reaches only the buyer leaves the wrong document with the people who acted on it.
12.6 The buyer's identity. Where somebody else bought a report about you, you already know who they are: the request in 4.2(b) names the buyer and the organisation they gave, and nothing is produced until you have read it. So this is not usually a question that arises.
Where it does arise – because you are asking again later, or because the report was about a business that is in substance you and no request was sent – we do not release another person's identity automatically, and we do not operate a blanket refusal either. On a request we weigh what you need it for against that person's rights, taking into account whether the report has been acted on to your detriment, whether the same purpose can be met another way, and any risk to either of you. We give you the outcome in writing with our reasons, we tell you what we disclosed and what we withheld, and we tell you that you may take a refusal to the Estonian Data Protection Inspectorate or to a court. Where a court or a supervisory authority directs disclosure, we disclose.
Where we withhold the identity, we will tell you at no charge: the date of the order, the category of buyer, each time the report was opened and whether the opening was the buyer's own or a view we served to a reader they named, how many times the report was downloaded as a file and when, whether the report was withdrawn or corrected, and the categories of person the buyer has told us they disclosed it to under 12.5a. We do not pass on your correspondence.
Withholding the buyer's identity does not decide the readers' names, and we do not run the two questions together. While the report is live we hold the name and address of every reader a link was issued to. The counts and the dates you get whenever you ask. A name is information about another person in the way the buyer's name is information about the buyer, so we weigh it the same way rather than hand it over because it happens to be easy: we give it where a court or a supervisory authority orders it, where that reader agrees, or where we are satisfied both that you cannot exercise or defend a legal right without it and that your interest outweighs theirs. Clause 14.1 of If a Report Names You sets out that weighing and governs. Once the report is gone the names are gone with it, and the counts and the dates are all that is left for us to give you.
``
12.6a What we hold after a report has gone. Subject to 12.6, we will tell you everything we hold about you. Once the periods in section 11 have run, what may still exist is limited to the classes listed in 11.4, and our answer will say which of them we still hold and for how much longer. It will not be an assertion that we hold nothing, because 11.4 shows that this is not always true.
We answer an unauthenticated question about whether a report about a named person ever existed in the same terms whether one existed or not. A different answer would turn this route into a way of finding out who has been reported on, which would expose far more people than it would help. That control does not apply to you once you have satisfied us who you are, and 12.4 sets out how light that check is.
12.7 Where you are. One standard for everyone, one intake address, and no separate regime by country. We apply the rights in 12.1 to anybody who asks, wherever they are, and we do not ask where you live as a condition of answering.
Where the law of your country gives you a right this notice does not describe, we will honour it. We will not require you to name a law, to prove where you are, or to send us information about yourself that the request itself does not need. If you do tell us where you are, we use that only to answer your request.
We name no country in this clause, because a list would read as a limit on the sentence above it. What we undertake instead is an ordering: where we identify a regime that requires a local representative, a named contact, a prescribed form or a response period we do not currently meet, we add it to this notice and put the route in place before we accept a request under it, rather than afterwards.
``
12.8 Marketing email. Consent, given separately, withdrawable in one click at any time. Withdrawing it does not stop messages about something you bought, which are part of performing the contract. The address a person gives us in reply to a request under 4.2(b) is never added to a marketing list.
12.9 Nothing in our terms of sale limits any right in this section, and nothing a buyer agreed to affects the rights of a person a report is about.
12.10 The one limit on erasure, stated in advance rather than improvised on the day. Where you have bought a report, an erasure request does not reach the records that show the purchase happened and what was delivered: the order, payment, refund and dispute record; the invoice; the wording of each confirmation you actioned at checkout as it was displayed to you, with the time; and the record that a report was produced, that it was made available to you, that a notification was transmitted to the address you gave, and that you signed in and opened it. We keep those for the periods in the Data Retention schedule, on two grounds we state separately: we are required by tax and accounting law to keep an accounting record, and those records are the only evidence we hold if a payment for that report is later disputed by you or by your bank. We will erase everything else we hold about you on request, and our answer will tell you exactly which records we kept and on which of the two grounds.
Three things this limit does not do. It does not reach a report, its evidence, its findings or its scores, none of which is kept on this basis and all of which is destroyed on the schedule in section 11. It does not apply to a person a report is about, whose position is section 13 and If a Report Names You, and whose erasure request reaches every store we hold. And it is not a discretion: it is the closed list above and nothing else.
13. Withdrawing, objecting, and asking us not to produce a report about you
13.1 This has its own section because it is the part that matters most to the people this product affects most.
13.2 Withdrawing the agreement you gave us. Where a report about you was produced because you told us you agreed, you can take that back at any time, in one message, with no reason and no form. Write to [email protected]. We stop. We stop any analysis in progress, we withdraw any report already delivered, we delete our copy, we require the buyer to destroy any copy they hold, and we do not produce another report about you on the strength of what you told us before.
Our contract with the buyer expressly allows us to do that and to refund them, so honouring your withdrawal costs us money and breaches nothing. Withdrawal takes effect when we decide it and does not wait for the refund to complete; how a buyer is repaid is a mechanical question dealt with in the Refund Policy and is never a reason to leave a report in circulation.
13.3 Objecting. Where a report about you rests on legitimate interests rather than on your agreement – a report about a business that is in substance you, or your name appearing inside a source stored for a report about somebody else – you can object, and the same address is the route.
There are two situations, and only two, in which we will not stop, and neither is a judgement about the merits of your objection. The first is that we cannot yet satisfy ourselves that the objection comes from you or from someone acting for you; we then tell you what we need, we suspend production while we ask, and the objection takes effect the moment we have it. The second is that a law or a valid order requires us to keep specific material; we then stop everything the law does not require, tell you what is left and why, and 11.7 governs it, a hold being a stop on destruction and not a permission to carry on using anything.
13.4 What is not a ground for refusing, stated expressly. The fact that somebody has paid us for a report about you is not a ground that overrides your withdrawal or your objection. It is our own commercial interest wearing a customer's name, and it is the same interest already weighed and found merely legitimate. We will not run that argument. Nor will we treat a buyer's remaining access period as a reason to keep processing.
13.5 What happens, and when. We acknowledge within one business day. Production stops immediately. We complete the deletion, tell the buyer and confirm to you what we have done within fourteen days. If a report about you is being produced when your message arrives, it stops, the order is cancelled and the buyer is refunded in full. If a report has already been delivered we withdraw the buyer's access, require them to destroy any copy they hold and to recall anything they sent, end their licence and refund them in full.
Withdrawing access reaches our copy and every share link for that report at once, and that part is complete rather than approximately complete: we serve every view of a link ourselves, no reader holds a storage address and nothing is cached anywhere else, so the next request after we act serves nothing. It does not reach a file downloaded while the report was live. We will tell you from our records how many times the report was downloaded and when, and how many times it was opened before your message arrived. We will not tell you that every copy is gone. 11.4(a) is why.
One consequence is ours to state rather than yours to discover. Because a subject record is destroyed with the report that created it and no standing register of the people we have been asked about is kept, your request reaches the reports that are live when you make it. A report that has already expired has been destroyed and there is nothing left to withdraw.
13.6 Asking us not to produce a report about you at all. You can ask in advance. We will keep a suppression list, checked before a report starts and again as it proceeds, keyed to a strong identifier such as a profile address rather than to your name alone: names collide, and a list keyed on a name would both block reports about other people and miss reports about you.
13.7 We will not confirm whether anyone is on that list and we will not disclose it. Confirming that a person suppressed themselves is itself a disclosure about them. We will confirm to you that we received your request and acted on it.
13.8 What is true today. None of the machinery in this section is running, because nothing has been produced yet. Every part of it is a condition of the first report about a named individual being sold, not an improvement to be made afterwards.
13.9 The fuller version, written for someone who has just been asked whether they agree, or who has just found out a report exists, is at If a Report Names You.
``
14. Complaints
14.1 Come to us first if you can, at [email protected]. You are not obliged to, and complaining to us uses up no other route.
14.2 You can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), aki.ee.
``
14.3 You can also complain to the supervisory authority in the EU country where you live, where you work, or where the thing you are complaining about happened. If you are outside the EU, your own country may have an authority that can take your complaint; tell us which and we will deal with it.
14.4 Complaining to a regulator takes away no remedy you have in court.
15. Security
15.1 What this section is, and what it does not do. This section describes what we do and what we do not do. Every sentence in it is meant to be capable of being disproved by showing that we do not do the thing described. We hold no security certification of any kind: we are not SOC 2 certified and not ISO 27001 certified, no independent party has tested or attested to our security, and we describe ourselves as compliant with nothing. The fuller statement, including what is not in place, is at Security.
Nothing in this section reduces what you are entitled to receive. If you bought a report, the statements we publish about the product form part of its description and you may rely on them, and the Terms of Service say so. If a report names you, nothing in this section limits your rights or our duty to keep information about you secure.
What this section does not do is promise that a particular outcome will never occur, or that the service is uninterrupted or error free. Availability is governed by the Terms of Service.
15.2 What is in place today, verified in a served response rather than in a configuration file. The site is served over TLS. Its response carries a content security policy that names an allow-list of origins rather than permitting any origin. That policy is not yet in its strictest form, because it still permits inline script, and tightening it is listed as an outstanding control in Security. No third-party script runs on any page you can reach. Typefaces are served from our own domain, so viewing a page discloses your address to no font provider. The site sets no cookie, and the single item it may store on your device is described in section 16.
15.2a Where this notice and the Security statement describe the same control, the security statement is the authoritative one, because it carries the date each control was verified and says plainly which controls are not in place.
15.3 What will be in place before the product runs. Provider-managed encryption of data at rest, sign-in by single-use code so there is no password to steal or reuse, row-level access controls in the database, and an append-only, hash-chained record of administrative actions verified daily. These are written and not yet in service, and we will not describe them as operating until they are.
15.4 The register of people who have been analysed is the one store composed entirely of information about people who are not our customers. Bringing it inside the same row-level controls that separate customer data is a condition of the first sale.
15.5 One person holds production credentials. At this size there is no separation of duties, and we would rather say that than imply a department. The append-only record of administrative actions is what compensates for it.
15.6 If something goes wrong. We will report a qualifying personal data breach to the Inspectorate without undue delay and within the period the law sets. Where there is a high risk to you and we hold a way to reach you, we will tell you directly. For a report subject we will usually hold a way to reach you, because the request in 4.2(b) means you gave us an address, and we will use it. Where a breach affects people we hold no address for – anyone named incidentally inside a stored source, or a subject whose report we have already deleted – the notice will be a public one at a fixed address on this site: not being able to send an email is not a reason not to tell people. We do not yet have the monitoring that makes the moment of awareness reliable and recordable, and standing that up is a condition of the first sale, because a duty running from awareness is worth nothing without the ability to know.
15.7 We hold no insurance against these risks. That is a decision taken deliberately and recorded rather than an oversight, and it is revisited at first revenue. Nothing in this notice or elsewhere on this site should be read as implying that cover exists.
``
16. Cookies and device storage
16.1 This site sets no cookie. That is a statement about what is built, not a policy. It replaces an earlier statement on this site that we used cookies to keep you signed in and to protect a checkout. There is neither, and that statement was wrong.
16.2 One item may be stored on your device: the record of your own storage choice, including a refusal, so you are not asked again on every page. It holds the choice, a version number and the date, and nothing else. It is written when you use the Cookie Settings control, it is treated as strictly necessary because a site that cannot remember a refusal has to keep asking, and the Cookie Policy carries the exact key name and its behaviour.
16.3 Nothing optional is stored before you have made a choice, and not choosing counts as a refusal. To change or withdraw a choice, open Cookie Settings in the footer of any page. The complete inventory is in the Cookie Policy.
16.4 What this site does not do, and the one exception. There is no analytics, no advertising, no cross-site tracking, no profiling of you across other sites and no session recording on this site, and none is planned.
One exception, stated now so that it is not a surprise later. When checkout opens, the page that hands you to our payment processor, and the processor's own pages, will run that processor's fraud-prevention script. It reads properties of your browser and device in order to recognise automated card testing and a payment being attempted from a device that is not the cardholder's. It is used for that and for nothing else: it is not advertising, it is not analytics, nothing it produces is used to build a profile of you, and nothing from it is shared with anyone for their own marketing. We rely on our legitimate interest in preventing payment fraud, and there is a row for it in the table at 5.1. Until checkout ships, neither that script nor any storage it sets exists on this site, and the Cookie Policy will carry the inventory for that surface before it ships rather than after.
The domain serving report files will be treated the same way: anything it stores is listed in the Cookie Policy before that domain carries traffic.
17. Changes to this notice
17.1 Changes. Material changes to this notice are dated in this section. We keep earlier versions and will send you one on request.
17.2 What a version identifier does, and what it does not do. This notice is not a term of your contract with us, and the Terms of Service say the same.
Each published version carries a content-hash identifier, and the version in force when you bought is recorded against your order and made available to you. That record is evidence of what you were told, and we do not alter it. It is not a claim that information already collected continues to be handled under an old notice: when this notice changes, the new version governs what we do from the date it takes effect, including with information we already hold. A notice cannot be frozen at the date of a purchase, because the processing it describes carries on after the purchase and has to be described accurately while it does. What protects you is the notice period in 17.3 and the ordering in 17.4, not a frozen text.
Any remedy you have under consumer law because what you were told before you bought has changed is unaffected by this clause.
17.3 Notice before a material change takes effect. A material change – to what is analysed or scored, to how long anything is kept, to who receives it, or to the lawful basis we rely on – is published at least thirty days before it takes effect. During that period we will email the address used for any order that still has a report inside its window, and the address of any person who is inside the consent window described in 4.2(b). Where a change is required by law or is needed to close a security risk we may act sooner, and we will say in this section which change that was and why.
17.4 If we introduce a processing activity this notice does not cover, this notice changes first and 17.3 applies to it. That ordering is the commitment.
This Privacy Policy is part of the LeMans Labs legal set and should be read together with If a Report Names You, the Data Retention schedule, the Sub-processors list, the Security statement, the Cookie Policy, AI Transparency and Limitations, the Acceptable Use Policy, the Refund Policy and the Terms of Service. Provider identification and the route for formal notices are in section 1 of this notice and in the corresponding section of the Terms of Service; there is no separate legal-notice page.