This Privacy Policy explains how GuusLab, trading as Nemi ("we", "us", "our"), collects, uses, stores, and protects your personal data when you use our file sharing platform at nemilab.com (the "Service"). It applies to account holders as well as to people who interact with the Service without an account, such as recipients of share links, people who upload files through an upload link, and people who fill in a Nemi form.
We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection legislation. We process your personal data lawfully, fairly, and transparently. The Service can be used worldwide; Section 10 explains what this means for users outside the European Economic Area.
The data controller responsible for your personal data is:
GuusLab (trading as Nemi)
Utrecht, the Netherlands
KVK: 95954600
Email: support@nemilab.com
If you have questions about data processing or wish to exercise your rights, please contact us using the details above.
Where a Nemi user shares files with you, requests files from you, or sends you a form, that user decides what is collected and why; for that content we act as a processor on the user's behalf, and the user may be an independent controller of your data.
We collect and process the following categories of personal data:
On the Business plan you can create or join a company organization. For that organization we process:
Organization owners and admins manage seats and members. When you leave or are removed, organization-linked entitlements end for your account.
If you interact with the Service without an account, we process a limited amount of data about you:
Under the GDPR, we process your personal data on the following legal bases:
| Purpose | Legal Basis |
|---|---|
| Providing the Service | Performance of contract (Art. 6(1)(b) GDPR) |
| Processing payments | Performance of contract (Art. 6(1)(b) GDPR) |
| Sending transactional emails | Performance of contract (Art. 6(1)(b) GDPR) |
| Sending marketing emails to existing customers | Legitimate interest (Art. 6(1)(f) GDPR), with opt-out at any time |
| Security, malware scanning & abuse prevention | Legitimate interest (Art. 6(1)(f) GDPR) |
| Download & open analytics for senders | Legitimate interest (Art. 6(1)(f) GDPR) |
| Referral program | Legitimate interest (Art. 6(1)(f) GDPR) |
| Analytics & service improvement | Legitimate interest (Art. 6(1)(f) GDPR) |
| Legal obligations (tax, accounting, lawful requests) | Legal obligation (Art. 6(1)(c) GDPR) |
Where we rely on legitimate interest, we have conducted a balancing test to ensure your rights and freedoms are not overridden. You can request details of these assessments, or object to any legitimate-interest processing, by contacting us.
We use your personal data to:
We do not use your files or documents to train AI models, we do not sell your personal data, and we do not show advertising.
We share your personal data only with the following categories of third parties, and only to the extent necessary:
| Provider | Purpose | Data Location |
|---|---|---|
| Google (OAuth) | Authentication | EU/US (EU-US Data Privacy Framework, SCCs) |
| Stripe | Payment processing | EU/US (EU-US Data Privacy Framework, SCCs) |
| Wasabi | File storage (encrypted at rest) | EU (Amsterdam) |
| AWS SES | Email delivery | EU (Frankfurt) |
File conversion, compression, and malware scanning run on infrastructure we operate ourselves; your files are not sent to external conversion or scanning companies. Web fonts are served through our own servers, so your IP address is not sent to font providers.
When you share a file or document, the recipients you choose can see the shared content and your name as the sender. Where applicable they may also see your username, verified badge, and (for Business-linked accounts) your organization name or logo. When someone downloads your shared file, you can see download analytics about that download (see Section 3.6).
Exact username lookup for sharing is only available to signed-in users and only returns a match when the handle exists. It is not a browseable public user list.
On eligible plans you can connect a third-party AI assistant (for example through our MCP integration) to your workspace. This never happens automatically: it requires your explicit authorization. When you connect an assistant, the content you let it access is processed by that assistant's provider under its own privacy policy, and we record which changes were made through the integration. We never send your data to AI providers on our own initiative, and you can revoke a connection at any time in your account settings.
We store files and send email within the EU. Where personal data is transferred outside the European Economic Area (EEA), for example to Google or Stripe in the US, we ensure adequate safeguards are in place: an adequacy decision such as the EU-US Data Privacy Framework, or Standard Contractual Clauses (SCCs) approved by the European Commission.
We may disclose your data if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Nemi, our users, or the public. Where the law allows, we will inform you of such requests.
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
We use the following cookies and similar technologies:
| Cookie | Type | Duration | Purpose |
|---|---|---|---|
| Session cookie | Strictly necessary | Session | Authentication and session management |
| CSRF token | Strictly necessary | Session | Security: prevents cross-site request forgery |
| Referral cookie | Functional | 24 hours | Remembers a referral code you followed, only set when you open a referral link |
We also use your browser's local storage to remember interface preferences (such as view settings) on your own device; this data is not sent to us. We do not use third-party tracking cookies, advertising cookies, or third-party analytics scripts. Because we only use strictly necessary and low-impact functional cookies, no cookie consent banner is required under the Dutch Telecommunications Act and the ePrivacy rules.
As a data subject under the GDPR, you have the following rights:
To exercise any of these rights, contact us at support@nemilab.com. We will respond within one month, as required by the GDPR. We may ask you to verify your identity before acting on a request. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. In the Netherlands, this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
The Service can be used from anywhere in the world, and we apply the protections described in this policy to everyone, regardless of where you live. Your data is processed in the EU (and by the providers listed in Section 6) no matter where you use the Service from.
We send the following types of emails:
Marketing emails may contain measurement of opens and clicks so we can improve our communications; unsubscribing stops both the emails and this measurement. Every marketing email includes our name, a working unsubscribe link, and our location, in line with the GDPR, the Dutch Telecommunications Act, and comparable rules elsewhere (such as CAN-SPAM).
If you choose to connect an AI assistant to your workspace (see Section 6.3), the following applies:
We do not make decisions based solely on automated processing that produce legal effects for you or similarly significantly affect you. Uploaded files may be automatically scanned for malware, and files identified as malicious may be automatically blocked; if you believe a file was wrongly blocked, contact us at support@nemilab.com and a human will review the decision.
We implement appropriate technical and organizational measures to protect your personal data, including:
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected users without undue delay, as required by GDPR Articles 33 and 34.
The Service is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without parental consent, we will take steps to delete that data promptly.
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. If we make material changes, we will notify you by a prominent notice in the Service (which you can acknowledge) and, where appropriate, by email. The "Last updated" date at the top of this page indicates when this policy was last revised.
For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
GuusLab (trading as Nemi)
Utrecht, the Netherlands
KVK: 95954600
Email: support@nemilab.com
You also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.