This Privacy Policy explains how GuusLab, trading as Nemi ("we", "us", "our"), collects, uses, stores, and protects your personal data when you use our file sharing platform at nemilab.com (the "Service"). It applies to account holders as well as to people who interact with the Service without an account, such as recipients of share links, people who upload files through an upload link, and people who fill in a Nemi form.
We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection legislation. We process your personal data lawfully, fairly, and transparently. The Service can be used worldwide; Section 10 explains what this means for users outside the European Economic Area.
The data controller responsible for your personal data is:
GuusLab (trading as Nemi)
Utrecht, the Netherlands
KVK: 95954600
Email: support@nemilab.com
If you have questions about data processing or wish to exercise your rights, please contact us using the details above.
Where a Nemi user shares files with you, requests files from you, or sends you a form, that user decides what is collected and why; for that content we act as a processor on the user's behalf, and the user may be an independent controller of your data.
If you use Nemi for a business or organization and upload personal data about other people (client files, form responses, documents containing customer data), you are the controller of that data and we process it only on your behalf. Article 28 GDPR requires a written agreement for that relationship. Our Data Processing Agreement provides it: it is part of our Terms of Service and applies automatically, with no separate signature needed. It covers our processing instructions, confidentiality, security measures, sub-processors, assistance with data subject requests, breach notification, audits, international transfers, and deletion at the end of the contract. If your organization needs a signed copy for its records, email support@nemilab.com.
This Privacy Policy describes the data we process as a controller in our own right: your account, billing, technical, and communication data. Where the two overlap, the Data Processing Agreement governs the content you upload on behalf of others.
We collect and process the following categories of personal data:
On the Business plan you can create or join a company organization. For that organization we process:
Organization owners and admins manage seats and members. When you leave or are removed, organization-linked entitlements end for your account.
If you interact with the Service without an account, we process a limited amount of data about you:
Nemi Calendar can connect to an external calendar so your events appear alongside the ones you create in Nemi. Connecting an account is always your choice, it never happens automatically, and you can disconnect at any time in your calendar settings. We support:
For a connected account we store the calendar list, the event data needed to display and sync your calendar (title, description, location, times, recurrence, attendees, and the provider's event identifiers), and the access and refresh tokens for the connection. Tokens are encrypted with AES-GCM before they are written to our database, so a database dump alone cannot read your calendar.
Calendars are bound to your personal account rather than to a workspace, so connecting a calendar does not expose it to the other members of a workspace you belong to. Sync is two-way: changes you make in Nemi are sent back to the connected provider, and changes made in the provider are pulled into Nemi. When you disconnect an account or delete your Nemi account, the stored tokens, calendars, and events for that connection are deleted.
Photographs can carry more about you than the picture itself. Nemi Gallery is built around that fact, so this section sets out exactly what happens to a photo you add.
Photographs of identifiable people are personal data about those people, and a photograph can also reveal things that count as a special category of personal data under Article 9 GDPR. You decide what you upload, so Section 5a applies to Gallery as it does to the rest of the Service: we do not analyze, index, or profile what your photos contain, and Gallery is not the place for photographs that carry medical or comparably sensitive information.
Under the GDPR, we process your personal data on the following legal bases:
| Purpose | Legal Basis |
|---|---|
| Providing the Service | Performance of contract (Art. 6(1)(b) GDPR) |
| Processing payments | Performance of contract (Art. 6(1)(b) GDPR) |
| Sending transactional emails | Performance of contract (Art. 6(1)(b) GDPR) |
| Sending marketing emails to existing customers | Legitimate interest (Art. 6(1)(f) GDPR), with opt-out at any time |
| Security, malware scanning & abuse prevention | Legitimate interest (Art. 6(1)(f) GDPR) |
| Download & open analytics for senders | Legitimate interest (Art. 6(1)(f) GDPR) |
| Referral program | Legitimate interest (Art. 6(1)(f) GDPR) |
| Analytics & service improvement | Legitimate interest (Art. 6(1)(f) GDPR) |
| Legal obligations (tax, accounting, lawful requests) | Legal obligation (Art. 6(1)(c) GDPR) |
Where we rely on legitimate interest, we have conducted a balancing test to ensure your rights and freedoms are not overridden. You can request details of these assessments, or object to any legitimate-interest processing, by contacting us.
We use your personal data to:
We do not use your content to create, train, or improve AI or machine learning models, we do not sell your personal data, and we do not show advertising. This covers your files, documents, spreadsheets, forms, canvases, and the data from any calendar account you connect, in raw form as well as aggregated, anonymized, or derived form. Section 6.4 sets out the specific commitment that applies to data received from Google Workspace APIs.
We do not knowingly or intentionally process special categories of personal data within the meaning of Article 9 GDPR: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and genetic data, biometric data used to identify a person, data concerning health, or data concerning a person's sex life or sexual orientation. We also do not process data on criminal convictions and offences under Article 10 GDPR.
None of our own processing requires this kind of data. We never ask you for it, no feature depends on it, and we do not derive it from your content: we do not analyze, index, or profile the contents of your files, documents, or form responses.
Your responsibility as a user. Because you decide what you upload, our Terms of Service (Section 7) prohibit using Nemi for special category data and for data subject to sector-specific rules such as HIPAA, the Dutch Wgbo, or NEN 7510. This applies to files you share, to documents and spreadsheets you create, and to the questions you ask in a Nemi form or upload link. If you need to handle medical records, patient data, or comparable sensitive data, use a platform that is built and certified for it.
If special category data reaches our servers anyway, we still protect it with the measures in Section 14, we do not use it for any purpose of our own, and we will delete it on request. We may also remove it and inform the account holder, as described in our Terms of Service.
We share your personal data only with the following categories of third parties, and only to the extent necessary:
| Provider | Purpose | Data Location |
|---|---|---|
| Google (OAuth, Calendar API) | Sign-in, and calendar sync if you connect it (Section 3.7) | EU/US (EU-US Data Privacy Framework, SCCs) |
| Stripe | Payment processing | EU/US (EU-US Data Privacy Framework, SCCs) |
| Wasabi | File storage (AES-256 at rest) | EU (Amsterdam) |
| AWS SES | Email delivery | EU (Frankfurt) |
File conversion, compression, and malware scanning run on infrastructure we operate ourselves; your files are not sent to external conversion or scanning companies. Web fonts are served through our own servers, so your IP address is not sent to font providers.
These providers are also our sub-processors when we process personal data on your behalf. The current list, including what each provider does and where it stores data, is Annex 3 of our Data Processing Agreement, together with the notice period that applies before we add a new one.
When you share a file or document, the recipients you choose can see the shared content and your name as the sender. Where applicable they may also see your username, verified badge, and (for Business-linked accounts) your organization name or logo. When someone downloads your shared file, you can see download analytics about that download (see Section 3.6).
Exact username lookup for sharing is only available to signed-in users and only returns a match when the handle exists. It is not a browseable public user list.
Nemi contains no built-in AI features. We do not run, host, or call any AI or machine learning model as part of the Service, and we have no contract with any AI provider, aggregator, or model gateway. Nothing you store in Nemi is sent to such a service by us.
On eligible plans you can connect your own third-party AI assistant (for example through our MCP integration) to your workspace. This never happens automatically: it requires your explicit authorization, the assistant acts under your account and your credentials, and the content you let it access is processed by that assistant's provider under the agreement between you and that provider. We record which changes were made through the integration so collaborators can see them. We never send your data to AI providers on our own initiative, and you can revoke a connection at any time in your account settings.
Connected calendars are outside this integration. The MCP integration reaches only files, folders, documents, spreadsheets, forms, and canvases. It has no ability to read, write, or search calendar accounts, calendars, or events, so data obtained from Google Calendar or any other connected calendar provider cannot be passed to an AI assistant through Nemi. This is a property of the integration itself, not a setting: no such capability exists in it.
Nemi's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
In practice this means that data we receive from Google Workspace APIs, which for Nemi is Google Calendar data only:
We store files and send email within the EU. Where personal data is transferred outside the European Economic Area (EEA), for example to Google or Stripe in the US, we ensure adequate safeguards are in place: an adequacy decision such as the EU-US Data Privacy Framework, or Standard Contractual Clauses (SCCs) approved by the European Commission.
We may disclose your data if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Nemi, our users, or the public. Where the law allows, we will inform you of such requests.
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
We use the following cookies and similar technologies:
| Cookie | Type | Duration | Purpose |
|---|---|---|---|
| Session cookie | Strictly necessary | Session | Authentication and session management |
| CSRF token | Strictly necessary | Session | Security: prevents cross-site request forgery |
| Referral cookie | Functional | 24 hours | Remembers a referral code you followed, only set when you open a referral link |
We also use your browser's local storage to remember interface preferences (such as view settings) on your own device; this data is not sent to us. We do not use third-party tracking cookies, advertising cookies, or third-party analytics scripts. Because we only use strictly necessary and low-impact functional cookies, no cookie consent banner is required under the Dutch Telecommunications Act and the ePrivacy rules.
As a data subject under the GDPR, you have the following rights:
To exercise any of these rights, contact us at support@nemilab.com. We will respond within one month, as required by the GDPR. We may ask you to verify your identity before acting on a request. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. In the Netherlands, this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
The Service can be used from anywhere in the world, and we apply the protections described in this policy to everyone, regardless of where you live. Your data is processed in the EU (and by the providers listed in Section 6) no matter where you use the Service from.
We send the following types of emails:
Marketing emails may contain measurement of opens and clicks so we can improve our communications; unsubscribing stops both the emails and this measurement. Every marketing email includes our name, a working unsubscribe link, and our location, in line with the GDPR, the Dutch Telecommunications Act, and comparable rules elsewhere (such as CAN-SPAM).
If you choose to connect an AI assistant to your workspace (see Section 6.3), the following applies:
We do not make decisions based solely on automated processing that produce legal effects for you or similarly significantly affect you. Uploaded files may be automatically scanned for malware, and files identified as malicious may be automatically blocked; if you believe a file was wrongly blocked, contact us at support@nemilab.com and a human will review the decision.
We implement appropriate technical and organizational measures to protect your personal data, including:
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected users without undue delay, as required by GDPR Articles 33 and 34.
The Service is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without parental consent, we will take steps to delete that data promptly.
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. If we make material changes, we will notify you by a prominent notice in the Service (which you can acknowledge) and, where appropriate, by email. The "Last updated" date at the top of this page indicates when this policy was last revised.
For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
GuusLab (trading as Nemi)
Utrecht, the Netherlands
KVK: 95954600
Email: support@nemilab.com
You also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.