01 Who we are
North Lemma Inc. ("North Lemma", "we", "us") provides a decision-intelligence platform that connects the reasoning behind an investment decision to its outcome. This policy covers our marketing site, the application at the dashboard, and related services (together, the "Service").
For the material your firm imports (trades, theses, memos and the analysis derived from them), your firm is the data controller and North Lemma acts as your data processor, handling it only on your instructions. For account and site data described below, we are the controller. Where you require it, our Data Processing Agreement governs the processor relationship.
02 Information we collect
Account information
To provision a firm we collect the workspace name, the contact details of the people who administer it, and the access credentials used to sign in. We do not ask for more than is needed to stand up and secure an account.
Firm content you import
You import position and trade records from your order management system and upload investment theses, memos and research documents. North Lemma stores and processes this content solely to produce the analytics you have asked for. These documents may contain personal data (for example, an analyst's name in a memo); where they do, you remain the controller and we act on your instructions.
Derived analysis
The Service generates evaluations, scores, calibration statistics and other derived records from your content. This derived material is treated with the same confidentiality and isolation as the source content it came from.
Technical and usage data
We record the minimum operational telemetry needed to run the Service securely: authentication events, access and write logs tied to your workspace, approximate request metadata (such as IP address and timestamp) and error diagnostics. We use this for security, rate limiting, debugging and reliability, not for advertising.
We do not knowingly collect special-category personal data, and the Service is not directed to anyone under 16. We do not build advertising profiles, and we run no third-party product analytics, session replay, experimentation, or ad and social tracking. The only telemetry we keep is the operational security and reliability data described above. If we ever introduce optional analytics, it will be opt-in and disclosed here first.
03 How we use information
- Provide the Service. Process your content to generate evaluations, calibration, risk and portfolio analytics, and to keep your workspace populated and current.
- Secure and operate it. Authenticate sign-ins, isolate each firm's data, enforce rate limits, maintain audit logs, and detect and respond to abuse or incidents.
- Support and improve. Respond to your requests, diagnose issues, and improve reliability and features. We do not use one firm's confidential content to build features for another.
- Communicate. Send account, security and service messages. Product or marketing updates are opt-in and easy to stop.
- Comply with law. Meet legal, tax and regulatory obligations and enforce our agreements.
04 Legal bases
Where the GDPR or UK GDPR applies, we rely on: performance of a contract to deliver the Service you have signed up for; legitimate interests to secure, operate and improve it (balanced against your rights); consent for optional communications; and legal obligation where the law requires processing. You can withdraw consent for optional communications at any time.
05 AI processing
The analysis engine reads your firm's own theses and decision records and turns them into structured evaluations. It reasons over the material you import, your actual trades and memos, rather than generating generic opinions. That is what makes the output specific to how your firm invests.
This processing runs through Anthropic's API, a commercial provider we chose for its enterprise privacy posture. Three commitments govern it. Your content is never used to train Anthropic's models or anyone else's. It is retained by the provider only briefly for abuse monitoring and then deleted, under their commercial terms. And we send only the content being analyzed, your trade and thesis material, not your account credentials or separate investor records.
Market reference data (company names, sectors, prices, logos) is retrieved from Polygon.io using ticker symbols; your positions and theses are never sent to that provider. Outputs of the Service are analytical and informational, not investment advice, as set out in our Terms of Service.
07 Security
Security is the point of the product, not an afterthought. Our current measures include:
- Per-firm isolation. Each workspace's data lives in its own isolated store; requests are scoped to a single tenant so one firm can never reach another's data.
- Encryption in transit. All traffic is served over TLS. Managed storage is encrypted at rest.
- Scoped, signed sessions. Access uses signed, expiring session tokens, with rate limiting and brute-force protection on authentication.
- Audit logging. Access and write events are recorded per workspace to support review and incident response.
- Least privilege and secret hygiene. Credentials and keys are held in a secrets manager, never in source code, and access is limited to personnel who need it.
As the platform matures we are extending this program to include encryption-at-rest key management options, single sign-on (SAML/SSO), independent penetration testing, an SOC 2 examination, and configurable data-residency. We will describe these here as they become available rather than claim them before they are in place.
08 Retention
We keep your content for as long as your workspace is active so the Service can function. When a workspace is closed, we delete its data, including its isolated store and derived analysis, within 30 days, except where a longer period is required by law. Operational logs are kept for a limited window for security and then rotated. You can request earlier deletion at any time.
09 Your rights
Depending on where you are, you may have the right to access, correct, export, delete or restrict the processing of your personal data, and to object to certain processing. Because your firm controls the content you import, requests about that content are handled through your firm's administrator; we assist our customers in responding. For account and site data we control, contact us and we will respond within the timeframe the law requires. You may also lodge a complaint with your local data-protection authority.
10 International transfers
North Lemma and its sub-processors operate in the United States. If you access the Service from outside the US, your information will be transferred to and processed there. Where required, we rely on the European Commission's Standard Contractual Clauses (and the UK addendum) and appropriate safeguards for these transfers.
11 Changes to this policy
We may update this policy as the Service evolves or the law changes. We will revise the "Last updated" date above and, for material changes, notify workspace administrators. Continued use of the Service after an update means you accept the revised policy.
12 Contact
Questions, or want to exercise a right? Reach us at privacy@northlemma.com. Postal mail can be sent to North Lemma Inc., Attn: Privacy.