Back to home

Privacy Policy

Last updated: July 18, 2026

1. Introduction

This Privacy Policy explains how GuusLab, trading as Nemi ("we", "us", "our"), collects, uses, stores, and protects your personal data when you use our file sharing platform at nemilab.com (the "Service"). It applies to account holders as well as to people who interact with the Service without an account, such as recipients of share links, people who upload files through an upload link, and people who fill in a Nemi form.

We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection legislation. We process your personal data lawfully, fairly, and transparently. The Service can be used worldwide; Section 10 explains what this means for users outside the European Economic Area.

2. Data Controller

The data controller responsible for your personal data is:

GuusLab (trading as Nemi)
Utrecht, the Netherlands
KVK: 95954600
Email: support@nemilab.com

If you have questions about data processing or wish to exercise your rights, please contact us using the details above.

Where a Nemi user shares files with you, requests files from you, or sends you a form, that user decides what is collected and why; for that content we act as a processor on the user's behalf, and the user may be an independent controller of your data.

3. What Data We Collect

We collect and process the following categories of personal data:

3.1 Account Data

  • Name and email address. Depending on how you sign in, these come from your Google account (Google sign-in) or directly from you (email verification code).
  • Optional public username (@handle), used for sign-in, invites, and your optional public Nemi card.
  • Profile picture (from Google or a photo you upload; optional animated photo on eligible plans).
  • Passkey credentials, if you register a passkey: we store the public key and related metadata, never the private key, which stays on your device.
  • Account creation date and authentication tokens.
  • Plan status used for product features such as verified badges (blue or gold checkmarks) shown next to your name where the Service displays senders and collaborators.

3.2 Billing Data

  • Subscription status and plan type.
  • Payment information is processed directly by Stripe and is never stored on our servers. We only store your Stripe customer ID and subscription ID.

3.3 Content & Usage Data

  • Files you upload, and documents, spreadsheets, forms, and canvases you create.
  • File metadata: name, size, type, upload date, expiry date, and malware scan status.
  • Authorship information in collaborative documents: edits are attributed to the account (or connected AI assistant) that made them, so collaborators can see who wrote what.
  • Share link settings and analytics: number of downloads and opens, and timestamps.
  • Workspace information, folder structure, and contacts.
  • Contacts: email address, optional name, optional username, and (when known) a link to a Nemi account. Contacts are private to your account. We may create or update a contact when you share files, invite someone to a workspace or folder, or add a collaborator by email or @username. We do not operate a global public directory of all users.

3.3a Business organizations

On the Business plan you can create or join a company organization. For that organization we process:

  • Organization name, optional logo, seat limits, and membership roles (owner, admin, member).
  • Invites sent by email or username, and acceptance or decline of those invites.
  • Linked membership so storage and plan entitlements can be pooled for the organization while membership is active.
  • Display of the organization name and logo next to verified badges for members, on profiles and share pages where applicable.

Organization owners and admins manage seats and members. When you leave or are removed, organization-linked entitlements end for your account.

3.4 Technical Data

  • IP address (for security, rate limiting, and abuse prevention).
  • Browser type and version, and device information.
  • Cookies and similar technologies (see Section 8).

3.5 Communication Data

  • Email address for transactional and marketing emails.
  • Email interaction data (opens, clicks) for improving our communications.
  • Your email preferences and unsubscribe choices.

3.6 Data About Recipients & Visitors (No Account Needed)

If you interact with the Service without an account, we process a limited amount of data about you:

  • When you download a shared file: the download timestamp. The sender sees download counts and timestamps as analytics. We do not store your IP address or browser details with downloads.
  • When you open or preview a shared file: an open event with a salted, truncated hash of your IP address (we do not store your raw IP address for open analytics) and the timestamp.
  • When you upload files through an upload link or Beam: the files themselves and technical data about the upload. These files belong to the workspace of the Nemi user who requested them.
  • When you fill in a Nemi form: the answers you submit, which are delivered to the Nemi user who created the form.

4. Legal Basis for Processing

Under the GDPR, we process your personal data on the following legal bases:

PurposeLegal Basis
Providing the ServicePerformance of contract (Art. 6(1)(b) GDPR)
Processing paymentsPerformance of contract (Art. 6(1)(b) GDPR)
Sending transactional emailsPerformance of contract (Art. 6(1)(b) GDPR)
Sending marketing emails to existing customersLegitimate interest (Art. 6(1)(f) GDPR), with opt-out at any time
Security, malware scanning & abuse preventionLegitimate interest (Art. 6(1)(f) GDPR)
Download & open analytics for sendersLegitimate interest (Art. 6(1)(f) GDPR)
Referral programLegitimate interest (Art. 6(1)(f) GDPR)
Analytics & service improvementLegitimate interest (Art. 6(1)(f) GDPR)
Legal obligations (tax, accounting, lawful requests)Legal obligation (Art. 6(1)(c) GDPR)

Where we rely on legitimate interest, we have conducted a balancing test to ensure your rights and freedoms are not overridden. You can request details of these assessments, or object to any legitimate-interest processing, by contacting us.

5. How We Use Your Data

We use your personal data to:

  • Provide, maintain, and improve the Service.
  • Process your file uploads, conversions, and compressions.
  • Scan uploaded files for malware to protect recipients and the Service.
  • Manage your account and subscriptions.
  • Process payments through Stripe.
  • Send transactional emails (account confirmations, download notifications, billing receipts).
  • Send marketing communications about new features and offers (with easy opt-out, see Section 11).
  • Monitor for abuse, fraud, and security threats.
  • Enforce our Terms of Service.
  • Comply with legal obligations.

We do not use your files or documents to train AI models, we do not sell your personal data, and we do not show advertising.

6. Data Sharing & Third Parties

We share your personal data only with the following categories of third parties, and only to the extent necessary:

6.1 Service Providers (Data Processors)

ProviderPurposeData Location
Google (OAuth)AuthenticationEU/US (EU-US Data Privacy Framework, SCCs)
StripePayment processingEU/US (EU-US Data Privacy Framework, SCCs)
WasabiFile storage (encrypted at rest)EU (Amsterdam)
AWS SESEmail deliveryEU (Frankfurt)

File conversion, compression, and malware scanning run on infrastructure we operate ourselves; your files are not sent to external conversion or scanning companies. Web fonts are served through our own servers, so your IP address is not sent to font providers.

6.2 People You Share With

When you share a file or document, the recipients you choose can see the shared content and your name as the sender. Where applicable they may also see your username, verified badge, and (for Business-linked accounts) your organization name or logo. When someone downloads your shared file, you can see download analytics about that download (see Section 3.6).

Exact username lookup for sharing is only available to signed-in users and only returns a match when the handle exists. It is not a browseable public user list.

6.3 AI Assistants You Connect (Optional)

On eligible plans you can connect a third-party AI assistant (for example through our MCP integration) to your workspace. This never happens automatically: it requires your explicit authorization. When you connect an assistant, the content you let it access is processed by that assistant's provider under its own privacy policy, and we record which changes were made through the integration. We never send your data to AI providers on our own initiative, and you can revoke a connection at any time in your account settings.

6.4 International Transfers

We store files and send email within the EU. Where personal data is transferred outside the European Economic Area (EEA), for example to Google or Stripe in the US, we ensure adequate safeguards are in place: an adequacy decision such as the EU-US Data Privacy Framework, or Standard Contractual Clauses (SCCs) approved by the European Commission.

6.5 Legal Disclosure

We may disclose your data if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Nemi, our users, or the public. Where the law allows, we will inform you of such requests.

7. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:

  • Account data: Retained for the duration of your account. When you delete your account in your settings, your account, files, and associated data are deleted immediately; residual copies in backups are removed within 30 days.
  • Files (free plan): Automatically deleted 30 days after upload.
  • Files (paid plans): Retained while your subscription is active. After cancellation and downgrade, files exceeding free-tier limits become subject to the free plan's 30-day expiry.
  • Download logs & share analytics: Retained for the lifetime of the related share and deleted together with it.
  • Billing data: Retained for as long as required by tax and accounting regulations (in the Netherlands, 7 years).
  • Email send log & preferences: Retained for the duration of your account, so we can honor your unsubscribe choices.
  • Server logs: Retained for up to 90 days for security and debugging purposes.

8. Cookies & Similar Technologies

We use the following cookies and similar technologies:

CookieTypeDurationPurpose
Session cookieStrictly necessarySessionAuthentication and session management
CSRF tokenStrictly necessarySessionSecurity: prevents cross-site request forgery
Referral cookieFunctional24 hoursRemembers a referral code you followed, only set when you open a referral link

We also use your browser's local storage to remember interface preferences (such as view settings) on your own device; this data is not sent to us. We do not use third-party tracking cookies, advertising cookies, or third-party analytics scripts. Because we only use strictly necessary and low-impact functional cookies, no cookie consent banner is required under the Dutch Telecommunications Act and the ePrivacy rules.

9. Your Rights Under GDPR

As a data subject under the GDPR, you have the following rights:

  • Right of access (Art. 15): You can request a copy of all personal data we hold about you.
  • Right to rectification (Art. 16): You can request correction of inaccurate or incomplete personal data.
  • Right to erasure (Art. 17): You can request deletion of your personal data ("right to be forgotten"). You can also delete your account yourself at any time in your account settings.
  • Right to restrict processing (Art. 18): You can request that we limit how we process your data.
  • Right to data portability (Art. 20): You can request your data in a structured, commonly used, machine-readable format. You can also download your files and export your documents directly from the Service.
  • Right to object (Art. 21): You can object to processing based on legitimate interest, including marketing.
  • Right to withdraw consent: Where processing is based on consent, you can withdraw it at any time.

To exercise any of these rights, contact us at support@nemilab.com. We will respond within one month, as required by the GDPR. We may ask you to verify your identity before acting on a request. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. In the Netherlands, this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

10. Users Outside the EEA

The Service can be used from anywhere in the world, and we apply the protections described in this policy to everyone, regardless of where you live. Your data is processed in the EU (and by the providers listed in Section 6) no matter where you use the Service from.

  • United Kingdom: If you are in the UK, the rights in Section 9 apply to you under the UK GDPR, and you can complain to the Information Commissioner's Office (ico.org.uk).
  • United States (including California): We do not sell or share your personal information for advertising purposes, and we honor requests to access, correct, and delete your data as described in Section 9, regardless of your state of residence.
  • Other countries: Where your local data protection law grants you rights similar to those in Section 9, you can exercise them through the same contact details, and you keep any additional mandatory protections of your local law.

11. Email Communications

We send the following types of emails:

  • Transactional emails: Account confirmations, sign-in codes, download notifications, billing receipts, and security alerts. These are necessary for the Service and cannot be opted out of.
  • Marketing emails: Product updates, new features, and promotional offers about Nemi, sent to you as an existing customer. You can unsubscribe at any time using the link in every email or through your email preferences page, and we honor all unsubscribe requests promptly.

Marketing emails may contain measurement of opens and clicks so we can improve our communications; unsubscribing stops both the emails and this measurement. Every marketing email includes our name, a working unsubscribe link, and our location, in line with the GDPR, the Dutch Telecommunications Act, and comparable rules elsewhere (such as CAN-SPAM).

12. AI Assistant Integrations

If you choose to connect an AI assistant to your workspace (see Section 6.3), the following applies:

  • Connections are opt-in and authorized by you through an explicit consent screen.
  • The assistant can only access what its authorization allows, and only in your workspace.
  • Content the assistant reads or edits is processed by the assistant's provider under that provider's privacy policy. Review it before connecting.
  • Edits made by an assistant are marked as AI edits in document authorship history, so collaborators can see what was written by a person and what was not.
  • You can revoke the connection at any time in your account settings, which immediately stops further access.

13. Automated Decision-Making

We do not make decisions based solely on automated processing that produce legal effects for you or similarly significantly affect you. Uploaded files may be automatically scanned for malware, and files identified as malicious may be automatically blocked; if you believe a file was wrongly blocked, contact us at support@nemilab.com and a human will review the decision.

14. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Encrypted data transmission using TLS/HTTPS.
  • Encryption at rest at our storage provider.
  • Optional password protection on share links, and optional password encryption of exported .nemi documents.
  • Automated malware scanning of uploaded files.
  • Hashing of viewer IP addresses for share open analytics.
  • Access controls and the principle of least privilege for administrative access.
  • Regular security reviews and updates.

In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected users without undue delay, as required by GDPR Articles 33 and 34.

15. Children's Privacy

The Service is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without parental consent, we will take steps to delete that data promptly.

16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. If we make material changes, we will notify you by a prominent notice in the Service (which you can acknowledge) and, where appropriate, by email. The "Last updated" date at the top of this page indicates when this policy was last revised.

17. Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

GuusLab (trading as Nemi)
Utrecht, the Netherlands
KVK: 95954600
Email: support@nemilab.com

You also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.