At a glance
glemio is a business-to-business SEO workspace operated by Growing Lemon B.V. We use personal data to run secure customer accounts, connect services chosen by customers, generate customer-specific content, provide support, and protect the platform. We do not sell personal data.
1. About this policy
This Privacy Policy applies when you visit portal.glemio.io or the legacy lemonai.nl domain, create or use a glemio account, contact us, or connect an external service to a glemio workspace. Growing Lemon B.V. is the controller for account, website, support, and platform-administration data described here.
Customers may add business content that contains personal data about their own staff, customers, authors, or other people. For that data, the customer normally determines why it is processed and Growing Lemon acts as its processor. Customers remain responsible for having a valid basis to provide that information to glemio.
2. Personal data we collect
Depending on how you use glemio, we may process:
- Account data: name, business email address, company, role, account status, accepted policy versions, and authentication identifiers.
- Workspace data: websites, keywords, notes, brand story, product or service descriptions, brand colours, image instructions, excluded terms, focus country and language, source URLs, and generated drafts or images.
- Integration data: selected Search Console property, Google account email, encrypted authorization tokens, public Google Drive folder details, and performance or keyword metrics returned by connected services.
- Security and usage data: login and audit events, administrator support access, timestamps, error information, IP address, browser or device information, and technical request logs.
- Communications: information you include in support requests, emails, demonstrations, or other conversations with us.
We receive most information directly from you or your organisation. We also receive data from services you deliberately connect, from public folders or websites you provide, and from normal security and server logging.
3. Why we use personal data
We process personal data for the following purposes and legal bases:
- Providing the service: creating accounts, keeping workspaces separated, storing setup information, retrieving chosen metrics, and generating content. This is necessary to perform our agreement with the customer.
- Security and reliability: authenticating users, preventing misuse, recording administrator actions, diagnosing errors, and maintaining backups. We rely on our legitimate interests in operating a secure and dependable service.
- Support and communication: answering questions, handling requests, and sending essential service notices. This is based on the agreement and our legitimate interests.
- Optional integrations: accessing a Google service only after an authorised user connects it or supplies a public folder. Where consent is the applicable basis, it can be withdrawn by disconnecting the integration.
- Legal obligations: keeping information required for tax, accounting, compliance, dispute resolution, or lawful authority requests.
We do not use customer workspace data to create content for another customer. We do not make decisions that produce legal or similarly significant effects about people solely through automated processing.
4. Connected services and AI processing
glemio sends only the information needed for the feature you choose:
- Google Search Console: after you authorise a Google account and select a property, glemio retrieves and stores search-performance data for that customer workspace. Authorization tokens are encrypted before storage.
- Google Drive: glemio reads image files and folder metadata only from the public folder URL a customer supplies. A Google Drive sign-in is not stored for this integration.
- SE Ranking: the platform may send an exact focus keyword and focus country to SE Ranking's Data API to retrieve monthly search-volume and estimated average-CPC data. The saved focus language remains glemio context but is not sent as a language filter because this endpoint is country-based. Customers do not connect an advertising account.
- OpenAI API: glemio may send the selected keyword, relevant setup instructions, approved source material, and selected reference images to generate an article draft or image. OpenAI states that API data is not used to train its models by default unless the API customer opts in. Standard API abuse-monitoring retention may be up to 30 days.
glemio's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
6. International data transfers
Some providers or their subprocessors may process data outside the European Economic Area. Where the destination is not covered by an adequacy decision, we rely on an appropriate transfer mechanism such as the European Commission's Standard Contractual Clauses and apply supplementary safeguards where required.
7. How long we keep data
We keep personal data only for as long as needed for the purpose for which it was collected. Account and workspace information is generally kept while the customer account is active. After termination or a valid deletion request, we delete or anonymise data unless it must be retained for security, legal claims, accounting, or another legal obligation.
Technical logs, audit records, support correspondence, and backups can follow separate retention cycles. Deleted information may remain temporarily in protected rolling backups until those backups expire. Connected providers may also retain limited copies under their own documented retention schedules.
8. How we protect data
We use technical and organisational safeguards designed for the sensitivity of the data and the risks involved. These include encrypted network connections, encrypted integration credentials, server-side authorization, tenant-scoped database access, restricted administrator functions, audit logging, managed secrets, and provider access controls. Passwords are handled by Supabase Auth and are not stored in the glemio application database.
No online service can guarantee absolute security. If we identify a personal-data breach, we will investigate it and notify affected parties and regulators when the law requires us to do so.
10. Your privacy rights
Subject to the conditions in applicable law, you may ask us to:
- confirm whether we process your personal data and provide access to it;
- correct incomplete or inaccurate personal data;
- delete personal data that is no longer required or was processed unlawfully;
- restrict processing in certain circumstances;
- provide data you supplied in a structured, machine-readable format;
- stop processing based on legitimate interests when your rights outweigh those interests;
- withdraw consent at any time, without affecting earlier lawful processing; and
- object at any time to direct marketing.
We may ask for information needed to verify your identity. We normally respond within one month. Some rights are not absolute; if an exception applies, we will explain it.
11. Children and automated decisions
glemio is a business service and is not directed to children. We do not knowingly create accounts for, or collect personal data directly from, anyone under 18.
AI-generated articles, images, keyword metrics, and suggestions are working materials for business users. They do not make legal or similarly significant decisions about individuals, and customers remain responsible for reviewing generated output before using or publishing it.
12. Third-party websites
glemio may contain links to external websites or customer-provided sources. We do not control those websites and are not responsible for their privacy practices. Review the relevant privacy information before providing personal data to another organisation.
13. Changes to this policy
We may update this policy when glemio, our providers, or legal requirements change. We will publish the revised version here and update the date at the top. If a change materially affects how we use personal data, we will provide an additional notice where appropriate.
14. Contact and complaints
To ask a privacy question or exercise a right, contact:
Growing Lemon B.V.Haaksbergerstraat 67
7554 PA Hengelo
The Netherlands
Chamber of Commerce: 90674049
Email: hello@growinglemon.nl
You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens, or with the data-protection authority in your country. We would appreciate the opportunity to address your concern first.
For the contractual rules that apply to the platform, see our Terms.