PRIVACY POLICY
Effective Date: 05.03.2026 | Last Revised: 10.06.2026
This Privacy Policy explains how MERAKI HR SRL collects, uses, stores, and protects personal data when you access or use the LIMEN website, applications, and services. For the purposes of this Privacy Policy, "LIMEN" or the "Platform" refers to the LIMEN brand and its products, including LIMEN Energy, LIMEN Align, LIMEN Threshold (Before Commitment, Before Parenthood, Before Separation), and related tools operated by MERAKI HR SRL. This policy also covers any future LIMEN products or services launched under the MERAKI HR SRL brand.
1. Data Controller Information
MERAKI HR SRL
Bucharest, District 6, Romania
Trade Register: J2024005188408
CUI: 49743547 | VAT: RO51271373 | EUID: ROONRC.J40/5188/2024
Email: limen@merakihr.ro
For all data protection inquiries, please contact: limen@merakihr.ro
Supervisory authority: ANSPDCP — Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (dataprotection.ro)
2. Scope of This Policy
This Policy applies to:
  • The LIMEN website (limen.systems)
  • LIMEN Threshold (Before Commitment, Before Parenthood, Before Separation)
  • LIMEN Energy
  • LIMEN Align
  • Any related mobile applications
  • Any future LIMEN products operated by MERAKI HR SRL
It applies to users located in the European Union, the United States, and internationally.
3. What Data We Collect
We collect only data necessary to operate the Platform.
3.1 Website Data
When you visit our website, we may collect:
  • IP address
  • Browser type
  • Device information
  • Pages visited
  • Cookies and usage analytics
3.2 Account Information
If you create an account:
  • Email address
  • Password (encrypted)
  • First name
  • Age range (selected during onboarding)
  • Gender (optional, selected during onboarding)
  • Subscription plan and status
  • Billing information (processed by payment provider — see Section 8)
We do not store full payment card details.
3.3 LIMEN Threshold
LIMEN Threshold presents structured reflective questions only. It does not collect, store, or process personal relational responses.
3.4 LIMEN Energy & LIMEN Align
If you use these tools, we process:
  • Self-reported interaction reflections
  • Time-based entries
  • User-provided responses
  • Interaction categorizations
  • Structured summaries derived from user input
Important: LIMEN does not request medical diagnoses, clinical mental health data, or legal records. Users are responsible for avoiding inclusion of identifiable third-party personal data without consent.
3.5 Technical & Security Data
Collected for security and service improvement:
  • Login activity
  • Device type
  • Session data
  • Error logs
4. Legal Basis for Processing (EU Users)
For users in the European Union, processing is based on:
  • Article 6(1)(b) GDPR – Contract performance
  • Article 6(1)(a) GDPR – Consent (where applicable)
  • Article 6(1)(f) GDPR – Legitimate interest (security, fraud prevention)
  • Article 6(1)(c) GDPR – Legal obligation (tax, accounting, regulatory compliance)
We do not intentionally process special categories of personal data under Article 9 GDPR.
5. Purpose of Processing
We use personal data to:
  • Provide access to the Platform
  • Organize and display user-reported reflections
  • Manage subscriptions and payments
  • Improve service functionality
  • Ensure security and prevent misuse
  • Communicate service-related updates
We do not sell personal data.
We do not use personal data for automated decision-making that produces legal or similarly significant effects.
6. Marketing Communications
6.1 If you choose to subscribe to updates, waiting lists, or early access notifications related to LIMEN products (including LIMEN Align, LIMEN Energy, and LIMEN Threshold), we may use your email address to send:
  • Product updates
  • Early access invitations
  • Feature announcements
  • Research participation invitations
  • Limited promotional communications related to LIMEN products and services
Marketing communications are sent only where the user has provided consent or where otherwise permitted by applicable law.
You may withdraw your consent and unsubscribe from marketing communications at any time by clicking the unsubscribe link in our emails or by contacting limen@merakihr.ro.
7. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected. Specifically:
  • Email and marketing contact data: retained until unsubscribe or withdrawal of consent
  • Research participation data: retained for the duration of the relevant study plus 24 months
  • Purchase and transaction records: retained for 10 years in accordance with Romanian fiscal law
  • Technical logs and security data: retained for up to 12 months
  • Account data: retained while the account is active, or until the user requests deletion
Inactive accounts may be deleted after a defined inactivity period (from 12 to 24 months).
Users may request deletion at any time by contacting limen@merakihr.ro. Upon verified request, personal data will be deleted or anonymized within 30 days, subject to any overriding legal retention obligations.
8. Data Sharing and Third-Party Processors
We share personal data only with service providers acting as data processors on our behalf, strictly for the purposes described in this Policy. All processors are contractually bound by data processing agreements consistent with GDPR Article 28. We do not sell personal data. We do not share personal data with advertisers or data brokers.
Each processor is engaged under contractual obligations that require them to maintain appropriate data protection standards consistent with GDPR and applicable law. The table below is our living processor register, updated as our technology stack evolves.
Processor Register
Where a DPA has been formally requested but not yet received (marked "DPA requested — awaiting response"), MERAKI HR SRL has documented the request in its Records of Processing Activities (ROPA) and relies on the processor's published terms and independently verified security certifications as interim safeguards. This reflects a documentation gap being actively pursued — not an absence of legal protection on the processor's side. Users will be notified of material changes to processor arrangements via email or prominent notice on limen.systems.
8.1 Platform Infrastructure
MERAKI HR SRL reserves the right to change platform providers without requiring a full policy revision, provided the replacement processor offers equivalent or stronger data protection safeguards, the processor register above is updated within 30 days, and users are notified of material changes.
8.2 AI Processing
LIMEN integrates Claude, developed by Anthropic, Inc. (anthropic.com), for AI-assisted features including reflection summaries and CRM workflow automation via HubSpot. When AI-assisted features are active, user-submitted data may be processed by Anthropic.
Anthropic, Inc., San Francisco, CA, USA
Transfer mechanism: Standard Contractual Clauses (SCCs) under EU Commission Decision 2021/914
DPA: anthropic.com/legal
8.3 Payments & Billing
If you make a purchase, payment data is processed by Stripe Payments Europe Ltd, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland.
MERAKI HR SRL does not store payment card details. Stripe operates as an independent data processor under its own privacy and security standards. DPA: stripe.com/ie/legal/dpa
Romanian fiscal law requires 10-year retention of invoice records, for that, MERAKI HR SRL uses i-Tom Solutions SRL (FGO)
i-Tom Solutions SRL (FGO)
Role: Data processor — Romanian fiscal invoicing and e-Factura reporting (RO SPV)
Address: Romania Data transferred: Name, email, subscription amount, invoice details (as required by Romanian fiscal law) Legal basis for processing: Legal obligation (Article 6(1)(c) GDPR) — Romanian fiscal legislation requires invoice issuance and e-Factura reporting via ANAF SPV Data residency: EU (Amazon AWS EU servers) Certifications: ISO 27001, ISO 9001; registered personal data operator no. 18584 Note: Invoice data is retained for the legally required fiscal period (minimum 10 years under Romanian accounting law) and cannot be deleted upon user request, as retention is a statutory obligation. More information: fgo.ro/termeni/confidentialitate.
8.4 Analytics
We use Google Analytics, operated by Google Ireland Ltd, to understand how users interact with the Platform. Analytics data is anonymized where technically possible. For EU users, analytics cookies are activated only after consent.
8.5 Advertising and Remarketing
If Meta Pixel is active, interaction data may be processed by Meta Platforms Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, for the purpose of measuring advertising effectiveness and remarketing. For EU users, this is activated only after explicit consent.
8.6 Processor Responsibility and Risk Distribution
Each processor listed above bears independent legal obligations under applicable data protection law. Where a data incident, breach, or compliance failure originates with a third-party processor rather than with MERAKI HR SRL, liability is shared in accordance with GDPR Article 82 and the terms of the relevant processor's published or contracted obligations. MERAKI HR SRL maintains documented evidence of due diligence in processor selection, including DPA requests, security certifications reviewed, and formal correspondence records. This documentation is available to ANSPDCP upon request. Users who believe their data has been mishandled by a third-party processor may contact limen@merakihr.ro to receive information about the relevant processor's contact details and complaint mechanisms.
8.7 Platform Switching
LIMEN is built on modular third-party infrastructure. MERAKI HR SRL reserves the right to change platform providers without requiring a full policy revision, provided that:
— The replacement processor offers equivalent or stronger data protection safeguards
— The processor register in §8 is updated within 30 days of the switch
— Users are notified of material changes by email or prominent notice on limen.systems
8.8 General Obligations
All third-party processors are:
  • Contractually bound to process personal data only on our documented instructions
  • Required to implement appropriate technical and organizational security measures
  • Prohibited from using personal data for their own independent purposes unless required by law
  • Subject to confidentiality obligations
We do not sell personal data to any third party under any circumstances.
9. International Data Transfers
As a Romania-based company operating within the European Union, we prioritise EU data residency wherever possible.
EU-based processing:
  • Application infrastructure (Lovable/Supabase): stored in Frankfurt, Germany (AWS eu-central-1) — no transfer outside EEA
  • Fiscal invoicing (FGO): stored on AWS EU servers within the EEA
US-based processors with SCCs: The following processors are based in the United States. All transfers are governed by Standard Contractual Clauses (SCCs) adopted under EU Commission Decision 2021/914, and where applicable, certification under the EU-US Data Privacy Framework:
  • Stripe Inc. (payment processing)
  • HubSpot Inc. (customer communications)
  • Anthropic Inc.
You have the right to request information about the specific safeguards applied to your data transfers at any time by contacting limen@merakihr.ro.
Where written DPA confirmation is pending, MERAKI HR SRL relies on the processor's published privacy terms and independently verified security certifications as interim assurance, with formal requests on record in our ROPA.
10. Security Measures
We implement appropriate technical and organizational measures including:
  • SSL encryption
  • Restricted access controls
  • Secure hosting infrastructure
  • Data minimization principles
  • Error telemetry: Operational error reporting is handled via Lovable's platform infrastructure. A PII scrubber is applied to all error payloads before transmission, redacting emails, tokens, API keys, and personal identifiers. This telemetry is used solely for service stability and does not constitute behavioural profiling.
However, no system can guarantee absolute security.
11. Your Rights – EU Users (GDPR)
If you are located in the EU/EEA, you have the right to:
  • Access your data — to obtain a copy of personal data held about you
  • Rectify inaccurate data
  • Request erasure ("right to be forgotten")
  • Restrict processing
  • Object to processing based on legitimate interests
  • Data portability — to receive your data in a structured, machine-readable format
  • Withdraw consent at any time, without affecting the lawfulness of prior processing
  • Lodge a complaint with ANSPDCP (dataprotection.ro)
To exercise any of these rights, contact limen@merakihr.ro. We will respond within 30 days. Where a request involves data held by a third-party processor, we will assist in directing the request to the appropriate party.
12. US Privacy Rights
If you are a US resident, including California residents, you may have the right to:
  • Request access to personal information collected
  • Request deletion of personal information
  • Request correction of inaccurate data
  • Know whether personal data is sold or shared
  • Opt out of the sale or sharing of personal information
  • Limit use of sensitive personal information (California – CPRA)
LIMEN does not sell personal information. LIMEN does not share personal information with third parties for cross-context behavioral advertising.
To exercise rights, contact: limen@merakihr.ro. We will respond within 45 days.
12.1 Categories of Personal Information Collected
Under applicable US privacy laws, including the California Consumer Privacy Act (CCPA), we may collect the following categories of personal information:
  • Identifiers (such as email address or account information)
  • Internet or network activity (such as browsing behavior on the Platform)
  • Device and technical information (such as browser type or device identifiers)
  • User-submitted content related to reflective tools
We do not sell personal information to third parties.
Users may request disclosure or deletion of personal data as described in this Privacy Policy.
13. Cookies & Tracking
We use cookies and similar technologies. Details are provided in our separate Cookie Policy. Users may withdraw consent for non-essential cookies at any time.
14. Children's Privacy
The Platform is not intended for individuals under 18 years of age. We do not knowingly collect personal data from minors. If we become aware that data from a minor has been collected, we will delete it promptly.
15. Automated Processing & AI
AI-assisted tools are used within the Platform:
  • AI systems reorganize and respond to user-provided input
  • Outputs are generated based on user data
  • No automated decisions produce legal or similarly significant effects
  • Users remain responsible for interpretation of outputs
Details are provided in our separate AI Transparency Policy.
16. Data Breach Notification
In the event of a personal data breach likely to result in high risk to the rights and freedoms of users, MERAKI HR SRL will notify affected users without undue delay in accordance with GDPR Article 34, and will notify ANSPDCP within 72 hours in accordance with GDPR Article 33.
Where a breach originates with a third-party processor, MERAKI HR SRL will notify users of the breach and the identity of the processor involved as soon as reasonably practicable following notification from that processor.
17. Changes to This Policy
We may update this Privacy Policy or related policies from time to time.
Where changes materially affect user rights or obligations, we will provide at least 14 days' notice by email before the change takes effect.
Non-material changes such as updates to the processor register in §8 will be reflected in this document with the revision date updated, without individual notice.
Continued use of the Platform after such updates constitutes acceptance of the revised Policy.

L I M E N
LIMEN provides structured relational reflection tools intended for personal awareness and clarity. The platform does not provide therapy, psychological diagnosis, legal advice, or compatibility predictions. Learn more in our Disclaimer & Safety Policy .
© 2026 LIMEN. All rights reserved.
We use cookies: LIMEN uses essential cookies for platform functionality and Google Analytics to understand how this site is used. By continuing to use this site you accept this use. To opt out of analytics, use the Google Analytics Opt-out tool.