Skip to main content

Privacy policy

What personal data Deeperer handles, why, for how long, and what you can ask us to do about it. Written under UK data protection law.

Last updated

01

Who we are

Deeperer is operated by Lumman Ltd, registered in England and Wales (No. 15425759), 86-90 Paul Street, London, EC2A 4NE, United Kingdom. For the personal data described in clause 3 as ours, Lumman Ltd is the controller.

Lumman Ltd is registered with the Information Commissioner's Office under registration number ZC073658.

Questions, requests and complaints about privacy: in@deeperer.com, or write to the address above.

02

What this policy covers

This policy covers deeperer.com, the Deeperer dashboard, the reports we publish, and the API and MCP endpoints. It applies to four groups of people: visitors to the site, account holders and the people they invite into a workspace, individuals who appear in research, and people who email us.

It does not cover our own staff and job applicants, other Lumman products, which have their own policies, or a third-party site a report links to.

03

Our role: controller and processor

UK data protection law separates the controller, who decides why and how personal data is used, from the processor, who acts on the controller's instructions.

We are the controller for

  • account and identity data, and the sign-in events behind it;
  • billing and subscription records;
  • usage, security, audit and rate-limit data we hold to run and protect the platform;
  • correspondence with us;
  • personal data in the editorial reports we publish under our own brand.

We are a processor, acting on a customer's instructions, for

  • the research requests, knowledge-base material, uploads and edits a workspace submits;
  • the reports a workspace produces, including the personal data inside them and in the sources they cite.

For that second set the customer is the controller and decides what to research and what to publish. Our handling of it is governed by the Data Processing Agreement. If your personal data appears in a customer's report, that customer is the organisation to approach first; clause 14 explains what we can do directly.

04

What we collect about visitors

  • Technical request data handled by our hosting provider when you load a page, such as your IP address, user agent and the page you asked for.
  • Cookieless measurement. Aggregate page views and page-load performance, collected without cookies and without a cross-site identifier. See Cookies and similar technologies.
  • Bot-detection signals gathered when you submit a form or start a conversation, to tell a person from an automated client.
  • An anonymous preview account if you begin a research conversation before signing up. This is a real account record with no identity attached, holding your draft so it survives sign-up.
05

What we collect about account holders

  • Identity and contact. Email address, name where you give one, and an avatar if you upload one.
  • Sign-in data. Where you sign in with Google, Google passes us your email address, your name and your profile picture, and confirms the sign-in. We do not receive your Google password and we ask for no access to your Gmail, Drive, Calendar or contacts. Where you sign in with a one-time email link, we hold the address and the sign-in record. We store no password, because there is none.
  • Workspace data. Workspaces you belong to, your role in each, your default workspace, and invitations you sent or received. Inviting someone means giving us their email address to send them the invitation.
  • Billing data. A customer and subscription identifier from Polar, your plan, your balance, the ledger of what each run drew from it, and, where a billing owner turns automatic funding on, that instruction and the figures set with it. We never see or hold your card or bank details - Polar takes the payment and holds those.
  • Content you submit. Research requests and the conversation that shapes them, dictated audio and its transcript, files you attach, knowledge-base material, brand voices, and your edits to a report.
  • Usage and security data. Reports and versions your workspace produced, API keys as an irreversible hash plus a short recognisable prefix, an append-only audit log of compliance-relevant events, rate-limit counters, and server logs.
06

Why we process it, and our legal bases

PurposeLegal basis
Providing the service: authenticating you, running research, storing and publishing reportsPerformance of our contract with you
Billing, tax records and refundsContract, and legal obligation for the records we must keep
Support and correspondenceContract, and legitimate interest in answering you
Security, abuse and bot prevention, rate limiting, audit loggingLegitimate interest in keeping the platform safe, and legal obligation where security law applies
Aggregate measurement of how the site performsLegitimate interest in a service that works, using data that does not identify you
Improving the service, including reviewing failuresLegitimate interest, on the least data that answers the question
Complying with law, and responding to a lawful requestLegal obligation
Sanctions and designation screening where a research request calls for itLegitimate interest of the customer requesting the research, on data published by the designating authority

Where we rely on legitimate interest we have weighed it against your interests and rights, and we will explain the assessment if you ask. We do not sell personal data, we run no advertising, and we do not profile you for marketing.

07

How research is produced, and what leaves the platform

A run sends material to third parties, and you should know which and why:

  • Model providers. Your research request, the conversation around it, attachments, relevant knowledge-base material and the draft under revision are sent to our model provider to be processed. Dictated audio is sent to a speech-to-text provider to be transcribed and is not retained by us after transcription. Neither provider uses this material to train its models - both are contractually barred from it. Each may hold what we send for a short period for its own abuse monitoring, under its own terms, and then deletes it.
  • Sources. The pipeline reads public registers, official statistics, scholarly databases, sanctions lists, news and the open web. A lookup carries the terms the research needs, which can include a person's or a company's name taken from your request. Those sources are not our processors: we send them a query, and they answer.
  • Nothing else. Your research material is not shared with any other customer, is not used to answer anyone else's question, and is not used to train our own models.

No decision with a legal or similarly significant effect on a person is made about them by the platform alone. A report is written by software, but what anyone does with it is a human decision.

08

People who appear in research

A research report can name people: a company's directors and persons of significant control from a public register, an author of a cited paper, a person quoted in a news article, a person designated on a sanctions list. Where a customer commissions that report, the customer is the controller and we process it on their instructions.

Three limits apply:

  • The service is not to be used to compile a profile of a private individual. That is a breach of the Acceptable Use Policy and we will act on it.
  • We do not seek special category data - health, religion, political opinion, sexual life, biometrics - and we ask customers not to submit it.
  • Sanctions and designation data is criminal-offence-adjacent, comes from lists published by the designating authority, and is reported as what that list says on the day it is read.

If a report about you is published on deeperer.com and you want it corrected or taken down, write to in@deeperer.com with the URL. Clause 14 explains what happens next.

09

Reports we publish

A report that is public is published at a canonical URL, open to search engines, and readable over our API and MCP endpoint. What it contains is what its workspace put in and what its sources said. A report's owner chooses its visibility before the run and can change it afterwards; making it private takes down the URL and withdraws it from indexing, but we cannot clear a third party's cache or archive.

Reports published under Deeperer's own brand are ours as controller, and the same route applies for correction or removal.

10

Who else handles it

We use a small number of service providers, each under contract, each acting only on our instructions, and each listed with what it does and where it processes on the Sub-processors page. That page is the list, so it stays current when a vendor changes.

Beyond them: Polar takes your payment as Merchant of Record and is a controller in its own right for the payment; and we disclose personal data where the law requires it, to establish or defend a legal claim, or to a buyer of the business, in which case we will tell you.

11

Transfers outside the United Kingdom

Some of our providers process personal data outside the United Kingdom, or reach it from outside, as the Sub-processors page records. Where they do, we rely on a transfer mechanism recognised under UK data protection law - an adequacy determination where one covers the country, or the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, with a transfer risk assessment behind it. Ask us at in@deeperer.com for the detail on a particular provider.

12

How long we keep it

WhatHow long
Account and workspace dataWhile the account is open. Deleting your account removes it immediately.
Reports, versions and their citationsWhile the workspace keeps them. Deleted with the workspace.
Anonymous preview accounts never converted30 days, then deleted with the workspace and the draft
Dictated audioNot retained by us after transcription; the transcript lives in the conversation. The transcription provider may hold the clip briefly for abuse monitoring under its own terms.
Archived page snapshots behind citationsWhile the report version that cites them exists. A snapshot no version references is collected daily.
Live run activity feedCleared when the run starts and again when it finishes
Billing, balance ledger and tax recordsSix years from the end of the accounting period, as UK law requires
Audit log of compliance-relevant eventsRetained as our record of who did what, beyond account closure where the law or a legal claim requires
Rate-limit counters and idempotency keysMinutes to 24 hours, then they expire on their own
Server and security logsOur provider's retention window, then deleted

Where we must keep a record after you leave, we keep only that record and nothing around it.

13

How we protect it

Every tenant table is protected at the database level, so a workspace's data is reachable only by its members. There is no password to steal, because sign-in is Google or a one-time email link. API keys are stored as an irreversible hash and shown once. Traffic is encrypted in transit and data is encrypted at rest by our providers. Browser-facing writes pass a bot-detection gate, requests are rate-limited, and a firewall sits in front of the application. Staff access is least-privilege and the internal console is role-gated. Annex 2 of the Data Processing Agreement is the fuller list.

No system is beyond compromise. If a breach affects your personal data and the law requires it, we will tell you and the Information Commissioner's Office within the statutory deadlines.

14

Your rights

Under UK data protection law you may ask for access to your personal data, correction of it, erasure, restriction of processing, portability, and you may object to processing based on legitimate interest. There is nothing to withdraw consent for, because we do not rely on consent to run the service.

Two of these are self-service

  • Export. Your settings produce a machine-readable export of your own account and workspace data. It never contains a secret such as an API key.
  • Deletion. Your settings delete your account immediately, along with your solely-owned workspaces and their reports. Deletion is refused where an owned workspace has other members or a live subscription, so one person cannot destroy a team's work: cancel the subscription or hand the workspace over first, then delete.

For anything else, write to in@deeperer.com. We answer within one month and will tell you if a request needs longer or if an exemption applies. We may ask you to confirm who you are.

If your personal data appears in a report a customer published, the customer decides what the report says. Approach them where you can; write to us where you cannot, and we will pass the request on, act ourselves where we are the controller, and restrict or take down content while a serious complaint is examined.

15

Complaints

Tell us first, at in@deeperer.com. We will look at it and reply. If you are not satisfied, you can complain to the Information Commissioner's Office at ico.org.uk, by telephone on 0303 123 1113, or at Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. You can also seek a remedy through the courts.

16

Children

Deeperer is not for children. An account holder must be at least 18. We do not knowingly collect personal data from a child, and will delete it if we learn we have.

17

Changes to this policy

This policy changes as the service changes. The current version always lives at this address and carries the date it was last updated. Where a change materially affects how we handle your personal data, we will tell account holders.

Back to landing.