LEMO

Privacy Policy

LEMO Venture GmbH · lemo.social

Version: 1.0

Effective Date: 1 June 2026

Jurisdiction: Switzerland (nDSG) | European Union (GDPR)

Controller: LEMO Venture GmbH, Zürich, Switzerland

1. Introduction and Controller Identity

This Privacy Policy describes how LEMO Venture GmbH ("LEMO", "we", "our", or "us") collects, uses, stores, and shares your personal data when you use the LEMO social networking application and related services (collectively, the "Service").

LEMO is a verified social network for European university students. We are committed to protecting your privacy and processing your personal data in full compliance with applicable data protection law.

1.1 Data Controller

EntityLEMO Venture GmbH
Registered OfficeZürich, Switzerland
Websitelemo.social
Emaillemo@lemoventure.com

1.2 Applicable Law

This Policy is governed by and reflects obligations under:

  • The Swiss Federal Act on Data Protection (nDSG / revDSG), in force since 1 September 2023
  • The EU General Data Protection Regulation 2016/679 (GDPR), to the extent our processing falls within its territorial scope (Art. 3 GDPR)
  • The Swiss Ordinance on Data Protection (DSV / VDSG)
  • Any other applicable cantonal or national data protection law

2. Personal Data We Collect

We collect personal data in the following categories. We collect only what is necessary for the stated purpose (data minimisation principle).

2.1 Account and Identity Data

  • Full name
  • Email address (used for verification and communications)
  • University affiliation and student status
  • Student email address (.edu or university domain) used for institutional verification
  • Profile photograph (optional)
  • Year of study, academic programme, and graduation year (optional)
  • Username

2.2 Profile and Content Data

  • Bio, interests, skills, and professional aspirations you choose to share
  • Posts, comments, reactions, and other user-generated content
  • Direct messages (end-to-end encrypted in transit; stored encrypted at rest)

2.3 Verification Data

LEMO is a verified network. To confirm university enrollment we process:

  • Your university email address (verified via confirmation link)

2.4 Device and Technical Data

  • Device type, operating system, and app version
  • App session data and crash reports
  • Cookie identifiers and similar tracking technologies (see Section 8)

2.5 Usage Data

  • Feature interactions (e.g., pages visited, searches performed)
  • Engagement metrics (likes, shares, click-through)

2.6 Communications Data

  • Emails or messages you send to us (support, feedback, complaints)
  • Survey responses and research participation data

2.7 Special Category Data

We do not intentionally collect special category data (Art. 9 GDPR / Art. 5 nDSG), including data on racial origin, health, political opinions, religion, sexual orientation, or biometric data. If such data is incidentally included in user-generated content, we will delete it upon becoming aware of it. Do not upload or share such data on LEMO.

3. Legal Basis for Processing

Under the GDPR, every processing activity requires a lawful basis under Art. 6 GDPR. Under the Swiss nDSG, processing must be justified by a legitimate purpose, consent, or statutory obligation. The table below sets out our bases for each major processing activity.

Processing ActivityGDPR Legal BasisnDSG Basis
Account creation and service deliveryArt. 6(1)(b) – Contract performanceContractual necessity
University verificationArt. 6(1)(b) – Contract; Art. 6(1)(c) – Legal obligationContractual necessity
Personalised content and feedArt. 6(1)(f) – Legitimate interestsLegitimate interests
Security monitoring and fraud preventionArt. 6(1)(f) – Legitimate interestsLegitimate interests
Marketing emails (opted-in users)Art. 6(1)(a) – ConsentConsent
Analytics and product improvementArt. 6(1)(f) – Legitimate interestsLegitimate interests
Compliance with legal requestsArt. 6(1)(c) – Legal obligationStatutory obligation
Optional surveys and researchArt. 6(1)(a) – ConsentConsent

Where we rely on legitimate interests, we have conducted a Legitimate Interests Assessment (LIA) and determined that our interests do not override your fundamental rights and freedoms, given the nature of the processing and the reasonable expectations of users of a professional student network.

4. How We Use Your Personal Data

4.1 Service Delivery

  • Creating and managing your account
  • Verifying your university affiliation
  • Enabling connections, messaging, and community features
  • Showing you relevant profiles, events, and opportunities

4.2 Safety and Security

  • Detecting and preventing fraud, abuse, spam, and unauthorised access
  • Enforcing our Terms of Use and Community Guidelines
  • Responding to reports of harmful or illegal content

4.3 Product Improvement

  • Analysing aggregated, anonymised usage patterns to improve features
  • Conducting A/B testing on new features (no automated decision-making with legal effect)
  • Bug detection and performance monitoring

4.4 Communications

  • Sending transactional messages (account confirmation, password reset, security alerts)
  • Sending service updates and policy changes
  • Sending marketing and promotional messages where you have consented (opt-out available at any time)

4.5 Legal and Regulatory Compliance

  • Responding to lawful requests from Swiss or EU/EEA authorities
  • Exercising or defending legal claims
  • Maintaining records required by law

5. Data Sharing and Disclosure

We do not sell, rent, or trade your personal data. We share data only in the following circumstances:

5.1 Within LEMO

Founders, technical leads, and designated staff who need access to perform their role, subject to confidentiality obligations.

5.2 Service Providers (Processors)

We engage carefully selected third-party processors under binding Data Processing Agreements (DPAs). Current categories include:

CategoryPurposeLocation
Cloud InfrastructureApp hosting, database, storageEU / Frankfurt, Germany (as per AWS zone)
Email DeliveryTransactional and marketing emailsEU
AnalyticsAggregated, anonymised app analyticsEU
Error MonitoringApp crash and error trackingEU
Customer SupportHelp-desk ticketing (if applicable)EU

5.3 University Partners

We may share aggregated, anonymised engagement statistics with partner universities as part of institutional agreements. No individual personal data is shared without your explicit consent.

5.4 Legal Disclosures

We may disclose your data to law enforcement, courts, or regulators when required by Swiss or EU law, provided we have verified the legal basis for the request. Where possible and legally permitted, we will notify you of such requests.

5.5 Business Transfers

In the event of a merger, acquisition, or sale of all or substantially all assets, your data may be transferred to the successor entity. We will notify you at least 30 days in advance and you will have the right to delete your account before any transfer takes effect.

5.6 Aggregated / Anonymised Data

We may share aggregated or anonymised data (which cannot identify you) for research, benchmarking, or marketing purposes. This is not personal data for the purposes of applicable law.

6. International Data Transfers

LEMO stores and processes data primarily in the European Union and Switzerland. Switzerland is recognised by the EU as a country with adequate data protection (adequacy decision). For any transfers outside the EU/EEA and Switzerland, we rely on one or more of the following safeguards:

  • EU Standard Contractual Clauses (SCCs) as approved by the European Commission
  • Swiss-approved transfer mechanisms under the nDSG
  • Adequacy decisions by the EU Commission or the Swiss FDPIC
  • Binding Corporate Rules (where applicable)

We do not transfer personal data to countries that do not offer an adequate level of protection without appropriate safeguards. Where SCCs are used, we conduct a Transfer Impact Assessment (TIA) prior to transfer.

7. Data Retention

We retain personal data only for as long as necessary for the purpose for which it was collected, or as required by law.

Data CategoryRetention PeriodBasis
Account data (active)Duration of account + 90 days post-deletionContract / nDSG
Account data (post-deletion)90 days (backup purge cycle)Legitimate interest
IP addresses (logs)30 days, then anonymisedSecurity / nDSG
Verification documentsUntil verification confirmed, max 14 daysMinimisation
Support communications3 years from last interactionLegal claims
Financial / transaction records10 yearsSwiss OR/CO obligations
Consent records3 years from withdrawal or account deletionLegal obligation
Anonymised analyticsIndefinite (no personal data)Legitimate interests

8. Cookies and Local Storage

We use cookies and similar technologies to operate the Service, remember your preferences, and analyse usage. We do not use third-party advertising cookies.

8.1 Cookie Categories

TypePurposeConsent RequiredRetention
Strictly NecessaryLogin session, security, core functionalityNoSession
FunctionalUser preferences, language, themeYes1 year
AnalyticsAggregated, anonymised usage analysisYes13 months
Marketing (if used)Behavioural targeting for LEMO's own promotionsYes6 months

You can manage cookie preferences through your account settings or your browser. Note that disabling strictly necessary cookies may impair Service functionality.

9. Your Rights as a Data Subject

You have the following rights under both the GDPR and the Swiss nDSG. We will respond to all rights requests within 30 days of receipt (extendable by a further 60 days for complex requests, with notification).

RightWhat This MeansHow to Exercise
Right of Access (Art. 15 GDPR / Art. 25 nDSG)Obtain a copy of all personal data we hold about you, including processing purposes, categories, recipients, and retention periods.Email lemo@lemoventure.com
Right to Rectification (Art. 16 GDPR)Correct inaccurate or incomplete personal data.Account settings or email
Right to Erasure (Art. 17 GDPR / Art. 32 nDSG)Request deletion of your data, subject to legal retention obligations.Account settings or email
Right to Restriction (Art. 18 GDPR)Restrict processing while a dispute is resolved.Email lemo@lemoventure.com
Right to Data Portability (Art. 20 GDPR)Receive your data in a structured, commonly used, machine-readable format.Account settings: 'Export my data'
Right to Object (Art. 21 GDPR)Object to processing based on legitimate interests or direct marketing at any time.Email or account settings
Right to Withdraw ConsentWithdraw consent at any time without affecting prior processing.Account settings or email
Right not to be subject to automated decision-making (Art. 22 GDPR)We do not make decisions with legal or similarly significant effects based solely on automated processing.N/A – not applicable currently

If you are located in Switzerland, you also have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) at www.edoeb.admin.ch. If you are located in the EU/EEA, you have the right to complain to your local supervisory authority.

We will never charge a fee for rights requests unless they are manifestly unfounded or excessive.

10. Minimum Age and Users Under 18

The LEMO Service is intended for university students aged 18 and above. We do not knowingly collect personal data from individuals under the age of 16 without verifiable parental consent (Art. 8 GDPR).

If we become aware that we have collected data from a person under 16, we will delete that data without undue delay. If you believe a minor has registered on LEMO, please contact lemo@lemoventure.com immediately.

Where local law requires a higher age for consent (e.g., 16 in certain EU member states), we apply the higher threshold. The university verification process provides a practical safeguard against underage registration.

11. Security Measures

We implement appropriate technical and organisational measures (TOMs) to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Our measures include, but are not limited to:

11.1 Technical Measures

  • TLS 1.2+ encryption for all data in transit (provided by our hosting providers, AWS and Supabase)
  • Encryption at rest for our database and storage (provided by Supabase/AWS infrastructure)
  • Passwordless authentication via one-time email links and codes — we do not store user passwords
  • Direct messages are protected in transit (TLS) and access is restricted by row-level security; only conversation participants can read them
  • Strictly segregated production and development/staging environments
  • Role-based access controls limiting data access by user type (student, admin, partner)

11.2 Organisational Measures

  • Role-based access control (RBAC) — staff access only what their role requires
  • Confidentiality agreements signed by all team members with data access
  • Regular internal privacy and security training
  • Documented data processing procedures
  • Vendor due diligence process for all processors

11.3 Breach Response

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours as required by Art. 33 GDPR and Art. 24 nDSG. Where the breach is likely to result in a high risk to you, we will also notify you directly without undue delay.

12. Automated Decision-Making and Profiling

We use automated systems to personalise your content feed and suggest connections. These systems analyse your usage patterns, stated interests, and university affiliation. This processing does not produce legal effects or similarly significantly affect you.

We do not use automated decision-making for account suspension or termination decisions without human review. Any moderation decision with significant consequences is reviewed by a member of the LEMO team.

13. Third-Party Links and Integrations

The LEMO app may contain links to external websites, or integrations with third-party services (e.g., LinkedIn, university portals). This Privacy Policy does not apply to those third-party services. We encourage you to read their privacy policies before providing your personal data. We are not responsible for the privacy practices of third parties.

14. Advertising and Commercial Data Use

LEMO currently operates without advertising. However, we intend to introduce advertising features in the future. This section sets out how your data may be used for advertising purposes once those features are introduced, so that you are fully informed in advance.

14.1 Future Advertising Model

When advertising is introduced, LEMO may use certain personal data to deliver relevant advertisements within the app. The types of data that may be used for this purpose include:

  • University affiliation, year of study, and academic programme (to show contextually relevant ads, e.g., graduate employers, student services)
  • Inferred interests and engagement patterns derived from your activity on LEMO (e.g., topics you follow, content you engage with)
  • General location (country or city level only — no precise geolocation)
  • Device type and language settings

14.2 What We Will Not Do

  • We will never sell your personal data to advertisers or third parties
  • We will not share individually identifiable user profiles with advertisers — advertisers select audience criteria and LEMO serves ads to matching users; the advertiser does not receive your personal data
  • We will not use special category data (health, political views, ethnicity, religion, sexual orientation) for advertising targeting
  • We will not serve ads from third-party ad networks that place their own tracking cookies without your explicit consent

14.3 Legal Basis for Advertising Processing

Personalised advertising (where ads are targeted based on your data) will only be enabled with your explicit consent (Art. 6(1)(a) GDPR). You will be given a clear, unbundled choice when this feature is introduced, and you can change your preference at any time in your account settings. Non-personalised (contextual) advertising — where ads are shown based on the content of the page only, not your personal data — may rely on our legitimate interests (Art. 6(1)(f) GDPR), as this processing carries minimal privacy impact.

14.4 Notification Before Advertising Goes Live

Before introducing any advertising features, we will update this Privacy Policy (with 30 days' prior notice as described in Section 15) and prompt you to review and confirm your advertising preferences. Advertising will not be enabled for your account until you have had the opportunity to make an informed choice.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via in-app notification and/or email at least 30 days before the changes take effect. The 'Effective Date' at the top of this document will reflect the date of the latest revision.

Continued use of the Service after the effective date of a revised policy constitutes your acceptance of the changes. If you do not agree to the revised policy, you may delete your account at any time.

We maintain an archive of all previous versions of this Privacy Policy, accessible upon request.

16. Contact and Complaints

For all privacy-related queries, rights requests, or complaints:

Primary Contactlemo@lemoventure.com or tech@lemoventure.com
Subject Line'Privacy Request' or 'Data Subject Rights'
Response TimeWithin 30 days of receipt
Postal AddressLEMO Venture GmbH, Zürich, Switzerland
Swiss Supervisory AuthorityFederal Data Protection and Information Commissioner (FDPIC) — www.edoeb.admin.ch
EU Supervisory AuthoritiesYour local data protection authority (list at edpb.europa.eu)

We are committed to resolving your concerns. If you are not satisfied with our response, you have the right to escalate your complaint to the relevant supervisory authority at any time.


End of Privacy Policy — Version 1.0 · 1 June 2026

LEMO Venture GmbH · lemo.social · lemo@lemoventure.com

← Back to lemo.socialTerms and Conditions →