GDPR & Data Protection

Last updated: 2 August 2026

This statement explains how LimeLai Limited (“we”), operator of LimeOrigin, complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It complements our Privacy & Cookies Policy, which is the primary and more detailed document.

Controller and processor roles

  • We are the controller for the personal data we process to run the Service — your account, billing, workspace content you provide, activity records and connected-service credentials.
  • We are your processor for personal data that visitors submit through websites we host for you (enquiry forms, bookings, shop orders, membership sign-ups). For that data you are the controller. Our processing of it on your behalf is governed by these terms and the Privacy Policy, which together form our processing instructions; a separate Data Processing Agreement is available on request at privacy@limeorigin.com.

Lawful bases

  • Contract — to provide the account, workspace, hosted websites, business email and features you sign up for.
  • Legal obligation — to keep billing and tax records.
  • Legitimate interests — security, fraud/abuse prevention, audit logging, and product analytics keyed to your organisation (not to individual browsing).
  • Consent — where we ever ask for it explicitly (for example connecting a third-party service at your request, or any future optional analytics cookies).

Your rights

Under UK GDPR you have the right to:

  • be informed about how your data is used (this statement and the Privacy Policy);
  • access a copy of your personal data;
  • rectify inaccurate data;
  • erase your data (“right to be forgotten”);
  • restrict or object to processing;
  • data portability — receive your data in a structured, machine-readable format;
  • not be subject to solely automated decisions with legal or similarly significant effects. LimeOrigin’s AI produces drafts for your review and does not make such decisions about individuals.

Exercising your rights

Much of this is self-service: Settings → Data & privacy in the app provides a full machine-readable export of your workspace and permanent deletion of your organisation. You can also email privacy@limeorigin.com and we will respond within one month, as required by UK GDPR. We may need to verify your identity first. If visitor data we process on a customer’s behalf is involved, we will refer you to that customer (the controller) or assist them in responding.

International transfers

Some of our sub-processors are located outside the UK. Where that happens, transfers are protected by UK adequacy regulations or by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, together with appropriate technical safeguards (encryption in transit and at rest).

Retention

  • Workspace data is kept for as long as your account exists; deleting your organisation permanently erases it.
  • Billing records are retained for 6 years to meet UK tax law.
  • Authentication tokens expire automatically and are single-use.

Security & breach notification

We protect personal data with the measures described on our security page (encryption, hashing, tenant isolation, access control and audit logging). In the event of a personal data breach that meets the risk threshold, we will notify the ICO within 72 hours of becoming aware, and affected individuals or controllers without undue delay.

Sub-processors

We use a limited set of vetted sub-processors to run the Service, listed with their purpose on our sub-processors page. We maintain data-processing terms with each, and we’ll give notice of material changes so you can object.

Contact & complaints

Data-protection enquiries: privacy@limeorigin.com (or write to LimeLai Limited, 86-90 Paul Street, London, EC2A 4NE). You also have the right to complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk, though we’d appreciate the chance to resolve your concern first.

GDPR & Data Protection · LimeOrigin