Privacy Policy

LYMERA AB
Effective Date: September 22, 2025
Last Updated: September 22, 2025

1. Introduction

LYMERA AB ("we," "our," or "us") operates the Lymo platform (lymo.me) and related services ("Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

Data Controller Information:
• Company: LYMERA AB
• Country: Sweden
• Contact: lymoadsai@gmail.com

2. Information We Collect

2.1 Personal Information You Provide

When you register for and use our Service, we may collect:

  • Account Information: Email address, first name, last name, password (encrypted)
  • Profile Information: Industry, company name, job title, company size, profile image
  • Authentication Data: Google OAuth data if you sign in with Google (name, email, profile picture)
  • Payment Information: Billing address, payment method details (processed through Stripe)
  • Communications: Messages, feedback, and correspondence with us

2.2 Content and Usage Data

  • Generated Content: Scripts, images, videos, and other content you create using our AI services
  • Upload Data: Files, images, and media you upload to our creative library
  • Project Data: Product URLs, inspiration images, and project metadata
  • Usage Analytics: How you interact with our Service, features used, generation history

2.3 Automatically Collected Information

  • Device Information: Browser type, operating system, device identifiers
  • Usage Data: Pages visited, time spent, clicks, session duration
  • Technical Data: IP address, server logs, error reports
  • Location Data: General location based on IP address (country/region level)
  • Session Data: Login times, activity patterns, real-time usage statistics

2.4 Third-Party Data

  • Analytics Data: Google Analytics and Vercel Analytics data from lymo.me (cookies, session data, behavior tracking)
  • AI Service Data: Data processed through our AI partner APIs
  • Payment Data: Stripe payment processing and subscription management data

3. How We Use Your Information

3.1 Service Provision

  • Provide and maintain the Lymo platform
  • Process your requests for content generation
  • Manage your account and subscriptions
  • Store and organize your creative library
  • Provide customer support

3.2 Service Improvement

  • Analyze usage patterns to improve our Service
  • Develop new features and functionality
  • Monitor system performance and reliability
  • Conduct A/B testing and user research

3.3 Communication

  • Send service-related notifications
  • Provide customer support responses
  • Send marketing communications (with consent)
  • Notify about policy changes and updates

3.4 Legal and Security

  • Comply with legal obligations
  • Protect against fraud and abuse
  • Enforce our Terms of Service
  • Maintain security and integrity of our systems

4. Legal Basis for Processing (GDPR)

We process your personal data based on the following legal grounds:

  • Contract Performance: Processing necessary to provide our Service
  • Legitimate Interests: Service improvement, security, and business operations
  • Consent: Marketing communications and optional features
  • Legal Compliance: Compliance with applicable laws and regulations

5. Data Sharing and Disclosure

5.1 Third-Party Service Providers

We share data with trusted service providers who assist in operating our Service:

  • Supabase: Database and authentication services (EU hosting)
  • Stripe: Payment processing and subscription management
  • Google Analytics: Website analytics and performance monitoring
  • Vercel Analytics: Privacy-first website analytics and performance metrics
  • AWS: Content moderation and file scanning (EU region)

5.2 Business Transfers

In case of merger, acquisition, or sale of assets, your information may be transferred as part of the business transaction.

5.3 Legal Requirements

We may disclose your information when required by law, court order, or governmental request.

5.4 Safety and Security

We may disclose information to protect the safety of users, enforce our policies, or prevent fraud.

6. Data Retention

We retain your personal data for as long as necessary to:

  • Provide our Service to you
  • Comply with legal obligations
  • Resolve disputes and enforce agreements

Specific Retention Periods:

  • Account Data: Until account deletion or 3 years after last activity
  • Content Data: Until manually deleted by user or account termination
  • Usage Analytics: 2 years from collection
  • Payment Records: 7 years (legal requirement)
  • Security Logs: 1 year

7. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption: Data encrypted in transit and at rest
  • Access Controls: Role-based access limitations
  • Content Moderation: Automated scanning for inappropriate content
  • Security Monitoring: Continuous monitoring and incident response
  • Regular Audits: Security assessments and vulnerability testing

8. International Data Transfers

Your data may be processed in countries outside the EU/EEA. We ensure adequate protection through:

  • Standard Contractual Clauses: EU-approved transfer mechanisms
  • Adequacy Decisions: Transfers to countries with adequate protection
  • Privacy Shield: For US-based service providers (where applicable)

9. Your Rights Under GDPR

As a data subject, you have the following rights:

9.1 Access

Request access to your personal data and information about our processing

9.2 Rectification

Request correction of inaccurate or incomplete data

9.3 Erasure ("Right to be Forgotten")

Request deletion of your personal data under certain circumstances

Faster Account Deletion Available

For quicker processing, email us at contact@lymo.me to delete your account. We typically process email requests within 24-48 hours.

9.4 Restriction

Request limitation of processing under certain conditions

9.5 Data Portability

Request your data in a structured, machine-readable format

9.6 Objection

Object to processing based on legitimate interests or for marketing purposes

9.7 Withdrawal of Consent

Withdraw consent for processing (where consent is the legal basis)

To exercise your rights, contact us at lymoadsai@gmail.com

10. Cookies and Tracking Technologies

10.1 Our Website (lymo.me)

  • Google Analytics: Performance and usage analytics
  • Vercel Analytics: Privacy-first analytics and performance monitoring
  • Essential Cookies: Authentication and security
  • Preference Cookies: User settings and preferences

10.2 Cookie Management

You can control cookies through your browser settings. Note that disabling certain cookies may affect functionality. For more details, see our Cookie Policy.

11. Marketing and Communications

11.1 Email Marketing

We may send marketing emails with your consent. You can unsubscribe at any time.

11.2 Service Communications

We send essential service communications regardless of marketing preferences.

12. Children's Privacy

Our Service is not intended for users under 16 years of age. We do not knowingly collect personal data from children under 16.

13. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes via email or Service notification.

14. Data Protection Officer

For privacy-related inquiries, contact our Data Protection Officer:

Email: lymoadsai@gmail.com

15. Contact Information

For questions about this Privacy Policy or our data practices:

LYMERA AB
Email: lymoadsai@gmail.com
Privacy Contact: lymoadsai@gmail.com

This Privacy Policy is governed by Swedish law and GDPR requirements.