Français

Privacy Notice

Version 1.0 — Effective July 23rd 2026

This Privacy Notice explains how Limin processes personal data when you visit limin.dev, use the Limin service, receive a workspace invitation, subscribe, or contact us.

1. Who operates Limin?

Limin is operated by:

Camille Hagenbourger, Entrepreneur individuel (EI)
Trading as Limin Software
20 avenue d’Ouessant
35740 Pacé
France

SIREN: 797 691 987
SIRET: 797 691 987 00060
Privacy contact: privacy@limin.dev

Limin Software is responsible for personal data used to administer accounts, authenticate users, manage subscriptions, provide support, secure the service, and operate Limin.

No Data Protection Officer has been appointed.

2. Workspace content

The organization that owns a Limin workspace generally determines why and how personal data contained in that workspace is used.

For information entered into issues, comments, descriptions, attachments, and other workspace content:

  • the workspace customer generally acts as data controller;
  • Limin generally acts as its data processor;
  • Limin processes the content only to provide, secure, maintain, and support the service.

This processing is governed by Limin’s Data Processing Agreement.

Requests concerning workspace content should normally be directed to the organization that owns the workspace. Limin will assist its customers where required.

3. Information we process

Account and profile information

This may include:

  • email address;
  • alias or display name;
  • optional full name and profile picture;
  • workspace memberships, roles, permissions, and invitations;
  • account status and relevant dates;
  • interface and onboarding preferences;
  • acceptance of Limin’s Terms;
  • workspace activity and contributions.

Your email address is required to create and authenticate your account. Your full name and profile picture are optional.

Profile information may be visible to other members of the same workspace according to their permissions.

Workspace information

This includes workspace and team settings, issues, descriptions, comments, relations, labels, statuses, assignees, authors, timestamps, attachments, permissions, usage limits, and archived or deleted records.

Some records are soft-deleted while a workspace remains active to preserve its history and consistency.

Authentication and security information

Limin uses passwordless email authentication through AWS Cognito.

We may process email addresses, login events, failed authentication attempts, session information, IP addresses, browser or device information, and security events.

Limin does not use or store account passwords.

Billing information

Limin may store subscription identifiers and status, renewal dates, seat counts, currency, billing country, company name, VAT-validation information, and payment or invoice status.

Stripe processes payment-card details, billing addresses, tax identifiers, invoices, and transactions. Limin does not receive complete card numbers or security codes.

Support communications

When you contact Limin, we process your contact details, message, attachments, and relevant account or workspace information.

Support and privacy communications are managed through Google Workspace.

Technical and analytics information

Limin processes limited logs and diagnostic information needed to operate, protect, and improve the service.

Application logs are designed not to contain issue descriptions, comments, attachments, authentication tokens, or other private workspace content. Logged email addresses are truncated.

Limin uses Vercel Web Analytics and Vercel Speed Insights for general traffic and performance measurements.

4. Why we process personal data

Limin processes personal data to:

  • provide the service and administer accounts and workspaces;
  • authenticate users and protect the service;
  • manage invitations, subscriptions, payments, and support;
  • maintain reliable workspace and contribution histories;
  • comply with accounting, tax, and other legal obligations;
  • record contractual acceptance;
  • investigate security incidents or misuse;
  • improve the reliability and performance of the service;
  • respond to privacy requests;
  • establish or defend legal claims.

Depending on the activity, processing is based on performance of a contract, compliance with a legal obligation, consent, or Limin’s legitimate interests in operating and protecting the service.

5. Access to workspace content

Limin does not routinely inspect private workspace content.

It may be accessed where:

  • an authorized user requests support;
  • access is reasonably necessary to investigate a security incident, abuse, or technical problem;
  • access is required by law.

At present, only Limin’s operator has access to the production database and private workspace content.

6. Account and workspace deletion

User account deletion

When a non-owner deletes their account:

  • access and authentication sessions are removed immediately;
  • the user is removed from teams;
  • assigned issues are unassigned;
  • the profile picture becomes inaccessible immediately and is deleted from storage within 24 hours;
  • previous issues, comments, and contributions remain in the workspace.

While the workspace remains active, limited identity information may be retained to preserve an understandable history:

  • the former user’s alias may remain visible to workspace members;
  • their full name and email address are restricted to workspace owners;
  • their account is marked as deleted or inactive.

This information is deleted when the workspace is permanently deleted, unless further retention is required for legal, billing, security, or dispute-resolution purposes.

Former users may contact privacy@limin.dev to object to this retention or request deletion. Requests will be assessed against both the user’s rights and the customer’s need to preserve its workspace history.

Workspace owners must delete their workspace to delete their account.

Workspace deletion

When an owner schedules workspace deletion:

  • any active subscription is set not to renew;
  • the workspace remains recoverable for seven days;
  • the owner may contact support during that period to request restoration.

After seven days, active workspace data and stored assets are deleted within 24 hours.

Limin may retain limited billing, contractual, legal, security, and dispute-related records. It may also retain pseudonymized workspace statistics containing counts and general dates, but no workspace content, email addresses, or profile names.

7. Retention periods

The main retention periods are:

  • active accounts and workspaces: while active;
  • former-member identity and contribution history: while the workspace remains active;
  • expired or cancelled invitations: up to 12 months;
  • deleted profile-picture and workspace files: within 24 hours after the applicable deletion period;
  • routine logs and diagnostics: up to 30 days;
  • authentication and security records: up to 12 months;
  • ordinary support and privacy emails: up to six months after resolution;
  • dispute or security records: up to five years, or longer where legally required;
  • contractual acceptance records: up to five years after the relationship ends;
  • billing and accounting records: up to ten years;
  • pseudonymized workspace statistics: up to three years after workspace deletion;
  • newsletter records: until consent is withdrawn or up to three years after the last meaningful interaction.

Deleted information may remain temporarily in restricted infrastructure backups until those backups are overwritten through the provider’s normal processes.

8. Service providers and international transfers

Limin uses the following principal providers:

  • AWS for authentication, infrastructure, file storage, and content delivery;
  • MongoDB Atlas for the application database;
  • Vercel for frontend hosting and performance analytics;
  • Cloudflare for DNS, network delivery, and security;
  • Stripe for subscriptions, invoicing, tax information, and payments;
  • Resend for transactional emails;
  • Axiom for logs and diagnostics;
  • Google Workspace for support and privacy communications.

Further information is available in Limin’s Subprocessor List.

Limin’s principal AWS infrastructure and MongoDB Atlas database are hosted in the Paris eu-west-3 region.

Some providers may process or permit authorized access to information outside the European Economic Area. Where required, transfers are protected through an adequacy decision, standard contractual clauses, or another lawful mechanism.

Limin does not sell personal data, provide it to advertisers, or use workspace content for behavioural advertising.

9. Cookies, browser storage, and emails

Limin uses cookies and browser storage necessary to authenticate users, maintain sessions, provide access to private files, and remember interface or product preferences.

Limin does not currently use advertising cookies, social-media tracking, session recording, or cross-site behavioural tracking.

Vercel Web Analytics does not use third-party advertising cookies. Based on Limin’s current configuration, no cookie-consent banner is displayed.

Limin does not enable Resend open or click tracking and does not add tracking pixels or rewritten tracking links to its emails.

Limin may send operational emails including authentication codes, invitations, billing messages, security alerts, support replies, service updates, and legal notices.

10. Your rights

Depending on the circumstances, you may have the right to:

  • access and correct your personal data;
  • request deletion or restriction;
  • object to processing based on legitimate interests;
  • receive certain data in a portable format;
  • withdraw consent;
  • lodge a complaint with a data-protection authority.

These rights may be subject to legal conditions or exceptions.

To exercise your rights, contact privacy@limin.dev. Limin may request information needed to verify your identity and locate the relevant data.

Where a request concerns workspace content controlled by your organization, Limin may refer the request to that organization or assist it in responding.

You may also lodge a complaint with the Commission nationale de l’informatique et des libertés (CNIL).

11. Security

Limin uses measures intended to protect personal data, including encrypted connections, encryption at rest, secure authentication cookies, restricted production access, workspace-based permissions, limited logging, and automated deletion routines.

No online service can guarantee absolute security. Users should protect access to their email accounts and report suspected unauthorized access to privacy@limin.dev or support@limin.dev.

12. Changes, language, and contact

Limin may update this Notice when its services, providers, processing activities, or legal obligations change.

The latest version and effective date will remain available on this page. Material changes will be communicated by email or within the service where appropriate.

This Notice is available in French and English. The French version is the reference version if the two versions differ.

Limin Software
Camille Hagenbourger EI
20 avenue d’Ouessant
35740 Pacé
France

privacy@limin.dev