Loading...
Loading...
Last updated: April 16, 2026
This Privacy Policy complies with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and other applicable data protection laws. We are committed to protecting your privacy and ensuring the security of your personal data.
Numonic Labs Ltd ("Numonic", "we", "us", or "our") is the data controller responsible for your personal data. We are committed to protecting and respecting your privacy in compliance with the UK GDPR and EU GDPR.
Registered company: Numonic Labs Ltd
Companies House number: 16532770
Registered office: 71-75 Shelton Street, London, WC2H 9JQ
ICO registration: ZB999870
Privacy enquiries: privacy@numonic.ai
Data Protection Officer: dpo@numonic.ai
We may collect and process the following categories of personal data:
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
We use your personal data for the following purposes:
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. The specific retention periods are set out below.
| Data Category | Retention Period | Rationale |
|---|---|---|
| Account information | Duration of account + 30 days | Contract performance; 30-day grace period for reactivation |
| Asset data (files, metadata, workflows) | Until deleted by user | Contract performance; user controls their own content |
| Transaction and billing data | 7 years after transaction | UK tax and accounting obligations (Companies Act 2006 s.386) |
| Usage analytics | 12 months (anonymised) | Legitimate interest in service improvement; anonymised after collection |
| Search interaction data | 90 days (then auto-deleted) | Legitimate interest in search relevance improvement |
| CRM contact data | Duration of business relationship + 12 months | Legitimate interest in maintaining business relationships |
| Upload validation logs | 12 months | Legitimate interest in platform security and incident response |
| Security and audit logs | 12 months | Legitimate interest in security monitoring and incident response |
| Referral links, status, and reward records | Retained indefinitely (append-only audit) | Contract performance and compliance obligation (DV 2.0 append-only audit) |
| Referral abuse-detection log (hashed IP + email domain) | 24 hours (auto-purged) | Legitimate interest in abuse prevention; no identifiers retained beyond the detection window |
When data reaches the end of its retention period, we securely delete or anonymise it. Where deletion is not immediately possible (for example, because data is held in backup archives), we isolate the data from further processing until deletion is feasible.
Under the UK GDPR and EU GDPR, you have the following rights:
To exercise any of these rights, please contact us at dpo@numonic.ai. We will respond to your request within one month as required by law.
Some of our sub-processors are based outside the UK and European Economic Area (EEA). Where personal data is transferred internationally, we ensure it is protected by one of the following safeguards:
The following sub-processors process data outside the UK/EEA:
| Provider | Data Location | Safeguard |
|---|---|---|
| Supabase | EU (Frankfurt) | EU adequacy; SCCs for US support access |
| Vercel | US (edge: global) | EU-US DPF; SCCs |
| Stripe | US | EU-US DPF; SCCs |
| Resend | US | SCCs |
| Apollo.io | US | SCCs |
| People Data Labs | US | SCCs |
You may request a copy of the relevant transfer safeguards by contacting us at dpo@numonic.ai.
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. These measures include:
Our website uses cookies to ensure proper functionality and, with your consent, to measure the effectiveness of our advertising campaigns. We use Cookiebot as our consent management platform. When you first visit our website, a consent banner allows you to choose which categories of cookies to accept.
These cookies are essential for the proper functioning of our Service and do not require your consent under GDPR and UK GDPR:
With your explicit consent, we use advertising cookies from the following providers to measure the effectiveness of our marketing campaigns:
No advertising cookies are set unless you explicitly grant consent. If you decline, no personal data is shared with these providers and the advertising scripts do not load.
You can change or withdraw your cookie consent at any time by clicking the "Cookie Settings" link in our website footer. Withdrawing consent takes effect immediately and prevents advertising cookies from being set on subsequent page loads.
You can also set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. Please note that if you disable or refuse the strictly necessary authentication cookies, you will not be able to log in or access the Service.
For more information about cookies and how to manage them, visit www.aboutcookies.org or www.allaboutcookies.org.
We use Vercel Web Analytics and Vercel Speed Insights to understand how visitors use our website and to monitor performance for improvement. These solutions are designed with privacy in mind and operate without the use of cookies.
Vercel Web Analytics collects only anonymous, aggregated data that cannot be used to identify individual users:
Vercel Speed Insights collects Core Web Vitals performance metrics to help us optimize page loading and user experience:
Both Web Analytics and Speed Insights include the following privacy-protective measures:
We process this analytics and performance data based on our legitimate interest in understanding website usage and performance to improve our Service (Article 6(1)(f) of GDPR). Given the privacy-protective nature of these solutions (no cookies, no personal identifiers, automatic data expiry), we have determined that this processing does not override your rights and freedoms.
To improve the quality and relevance of search results, we collect anonymized search interaction data when you use our search and asset browsing features. This includes:
This data is used solely to improve search result ordering and relevance for your team. It is not used for advertising or shared with third parties.
Search interaction data is scoped to your organisation (tenant) and is never combined with data from other organisations.
Search interaction data is retained for 90 days, after which it is automatically deleted.
We process this data under legitimate interest (Article 6(1)(f)) to improve core product functionality that you actively use. You can contact us at dpo@numonic.ai to object to this processing.
To support our CRM and business relationship management features, we may obtain professional and business contact information from third-party data providers. This enrichment supplements data you have provided to us or that we have collected through your interactions with our Service.
Third-party enrichment is limited to professional and business information:
We may use the following categories of data providers:
We process enrichment data based on our legitimate interest in maintaining accurate business contact records and conducting effective B2B outreach (Article 6(1)(f) of GDPR). We limit enrichment to professional and business data, apply it only to contacts within active business relationships or pipeline prospects, and provide data subjects with the ability to request access, correction, or deletion of their data at any time (see Section 6).
Numonic uses artificial intelligence to provide core platform features. This section describes how AI processes your data and the safeguards we apply.
The following AI features may process your uploaded content:
Your uploaded content is processed to deliver the platform features described above, including the generation of embeddings for semantic search and AI-assisted features such as the AI Librarian, which may access your content to generate notes, summaries, and recommendations within your organisation. All such processing is scoped to your tenant and is never combined with data from other organisations. We will never share your content with third parties for any purpose without your explicit, informed consent. If we introduce optional data licensing or model training programmes in the future, participation will always be opt-in, transparently disclosed, and subject to a separate agreement.
We perform automated security validation on all uploaded files to protect the integrity of the platform. This includes:
You may disable AI-assisted features (auto-tagging, auto-titling, auto-description, semantic search embeddings, and AI Librarian) at any time through your organisation's settings. Disabling these features will stop further AI processing of your content, though previously generated tags, titles, descriptions, and embeddings will remain unless you request their deletion. Upload security validation cannot be disabled.
AI-assisted features are processed under legitimate interest (Article 6(1)(f)), as they form part of the core service functionality that improves asset discoverability and organisation. You may object to this processing by opting out through your organisation's settings (see above). Security Upload security validation is processed under legitimate interest (Article 6(1)(f)) for protecting the integrity of the platform.
We use the following third-party service providers (sub-processors) to help us deliver our Service. Each sub-processor processes personal data only as necessary for the purposes described below.
| Provider | Purpose | Data Processed | Location |
|---|---|---|---|
| Supabase | Authentication, database, storage | Account data, content, usage data | EU (Frankfurt) |
| Vercel | Hosting, web analytics, performance monitoring | Technical data, anonymous usage metrics | US (edge: global) |
| Stripe | Payment processing | Financial data, transaction data | US |
| Resend | Transactional and marketing email delivery | Email addresses, message content | US |
| Apollo.io | Business contact enrichment | Professional contact identifiers (email, LinkedIn URL) | US |
| People Data Labs | Professional profile enrichment | Professional contact identifiers (email, LinkedIn URL) | US |
| Cookiebot (Cybot A/S) | Consent management platform | Consent preferences, anonymised IP, user agent | EU (Denmark) |
| Google (Google Ads) | Advertising conversion measurement (consent-gated) | Anonymised conversion events, click identifiers | US |
| Meta Platforms (Facebook/Instagram) | Advertising conversion measurement (consent-gated) | Pixel events (PageView, Lead, CompleteRegistration), anonymised identifiers | US |
We maintain data processing agreements with all sub-processors and ensure they provide adequate data protection safeguards. We will notify existing customers before adding new sub-processors that process personal data on their behalf. This list is updated when we add or change sub-processors.
This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements.
Our Service is restricted to users who are 18 years of age or older. We do not knowingly collect personal data from anyone under 18. If you are under 18, you may not use this Service. If we learn that we have collected personal data from anyone under 18, we will take steps to delete that information.
If you are a parent or guardian and you are aware that someone under 18 has provided us with personal data, please contact us immediately at dpo@numonic.ai.
In the event of a personal data breach:
Our CRM features use automated processing to calculate engagement scores for business contacts. These scores are based on interaction history (such as form submissions, email responses, website visits, and platform usage) and help us prioritise outreach and personalise communications.
Engagement scoring does not:
Scoring is used solely as an internal tool to help us manage business relationships more effectively. All outreach decisions based on engagement scores involve human review. You may contact us at dpo@numonic.ai to request information about any scores associated with your contact record, or to object to this processing.
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. For significant changes, we will provide a more prominent notice (including, for certain services, email notification of Privacy Policy changes).
If you have any concerns about how we handle your personal data, you have the right to lodge a complaint with a supervisory authority:
For UK residents: Information Commissioner's Office (ICO)
Website: ico.org.uk
Phone: 0303 123 1113
For EU residents: Your local data protection authority
Find your authority: edpb.europa.eu/about-edpb/board/members
When enabled for your account, the Numonic Referral Programme lets you share a personal referral link, track the status of referred accounts, and receive platform credits when those accounts activate. This section describes the specific data processing that supports the programme and supplements the general provisions of Sections 2-6 above.
a***@example.com). We do not display the full email address of a referred user to you at any point.Participation in the Referral Programme is voluntary. If you do not wish to receive referral rewards, simply do not share your referral link. If you wish to object to the legitimate-interest processing described above, contact us at dpo@numonic.ai.
If you have any questions about this Privacy Policy or our privacy practices, please contact us:
Numonic Labs Ltd
71-75 Shelton Street, London, WC2H 9JQ
Company number: 16532770
ICO registration: ZB999870
Privacy enquiries: privacy@numonic.ai
Data Protection Officer: dpo@numonic.ai
Website: https://www.numonic.ai
When contacting us, please provide as much information as possible to help us address your query efficiently. We aim to respond to all privacy-related inquiries within 30 days.