This Privacy Policy explains how EMYL LABS SL ("Lediv", "we", "us" or "our") collects, uses, shares and protects your personal data when you visit our marketing website at lediv.com, use our web application at lediv.app, or otherwise interact with our services (together, the "Service").
Lediv is a website builder where design and code stay in sync: a visual canvas and an integrated code editor edit the same project, made of HTML, CSS and JavaScript source files that you own and can export at any time. We have deliberately built the Service to collect as little personal data as possible; everything we store on your device, and why, is listed under "Cookies and local storage".
This policy is written to comply with the EU General Data Protection Regulation ("GDPR"), the UK GDPR, the Swiss Federal Act on Data Protection ("FADP") and, where applicable, US state privacy laws such as the California Consumer Privacy Act as amended ("CCPA/CPRA"). Please read it together with our Terms of Service.
Who we are (data controller) and how to contact us
The data controller responsible for your personal data is:
EMYL LABS SL, a Sociedad de Responsabilidad Limitada (SL) established in Spain (tax identification number (NIF) B93790822; registered address: Calle Mari Cruz Alvarez 6, Piso 3 B, 03203 Elche, Alicante, Spain).
For any privacy question or to exercise your rights, contact us at support@lediv.com. Service emails are sent from no-reply@mail.lediv.com with a reply-to address of support@lediv.com. We are not required under Article 37 GDPR to appoint a Data Protection Officer and have not appointed one; you can nonetheless raise any data protection matter with us at the same address.
Scope and our roles
This policy applies to personal data we process as a controller, that is, where we decide why and how the data is processed. This includes your account and identity data, profile, billing identifiers, transactional email, feedback, membership and collaboration data, and technical/security data.
User content and embedded personal data (dual role). The projects, files, documents and assets you create or upload ("User Content") may themselves contain personal data about other people that you choose to include (for example, names or email addresses in a design). With respect to that embedded personal data, you act as the data controller and Lediv acts as your processor, processing it only to provide the Service to you. You are responsible for having a lawful basis to include such personal data and for informing the individuals concerned. One exception runs the other way: where we assess a notice about your content, enforce our acceptable-use rules or answer an authority, we process that content to meet our own legal obligations and act as a controller for that limited purpose. The written contract that Article 28 GDPR requires for this relationship is Section 24 of our Terms of Service: it applies to every customer automatically, so there is nothing for you to sign or ask us for.
Visitors to sites you publish. When you publish a project, we serve it to the
public at an address under lediv.site and, if you connect one, at a domain of your
own. The people who visit it have no relationship with us and no account, and we do not ask them
for one: we set no cookies of our own on those sites and build no profile of the people who read
them. Three different roles meet on a single page request, so it is worth separating them.
For the content of your site, including any personal data you put in it, we act as your processor, on the terms in Section 24 of our Terms of Service. For the technical data that any web request carries, such as IP address and user agent, we are the controller: our infrastructure provider processes it to route the request and serve the content, we process it to keep the service running and to protect it from abuse, and it can appear in operational logs that are kept for at most 7 days and then deleted automatically. Our lawful basis is our legitimate interest in operating and securing a hosting service (Article 6(1)(f) GDPR). For anything your own site does, such as analytics, embeds, forms, payments or cookies you add yourself, you are the controller and this policy does not apply to it: telling your visitors about it and having a lawful basis for it is yours to do.
If you visited a site published on Lediv and want to know what it did with your data, or to exercise your rights over it, contact whoever runs that site rather than us. We do not know who a site's visitors are, we hold no profile of them, and we cannot answer for what a site we did not write chose to collect.
Some parties we work with act as separate, independent controllers rather than our processors: our Merchant of Record, Creem, for payment data (see "Payments") and the sign-in providers you may choose, Google and GitHub (see "Sharing and disclosure").
Personal data we collect and who can see it
Account and identity data. When you create an account we use passwordless authentication; we never collect or store any password. We collect your email address and, if you sign in with Google or GitHub, a stable account identifier and your name or username from that provider. During sign-in our servers technically receive your provider profile (and, for GitHub, your list of email addresses, used only to select your primary verified address); we store only the data above and discard the rest.
Profile data. Your display name and an identity color. Your theme preference is not stored on our servers: it lives in your browser, as described under "Cookies and local storage". Your display name is initially derived from the name or username provided by your sign-in provider and you can change it at any time; only your display name (not necessarily your provider name) and identity color are shown to your collaborators.
User Content and assets. Your projects, files, documents and assets. This content may contain personal data you choose to add (see "Scope and our roles").
Membership, collaboration and presence data. Membership and invitation records: who belongs to which team or project, their role and status, the accounts involved (including your email) and, for invitations, the invitee's email and a token reference. The owner of a team or project can see its members' email addresses, roles and invitation status; collaborators see each other's display name and identity color. When you are active in a shared project, presence broadcasts only your user id, display name and color to your collaborators. When you invite someone, the invitee sees the name of the target project or team. There are two cases where we hold personal data about you that you did not give us directly: an invitation, where we obtained your email address from the person who invited you, and a notice about your content, where we obtained the report from whoever sent it. In both cases we tell you when we act on it.
Billing identifiers (via Creem). We never receive, see or store your card or payment details. We store only Creem-issued identifiers and subscription metadata (such as your customer and subscription identifiers, plan, seat quantity, billing period and status), plus processed webhook event ids (used to avoid processing the same billing event twice). Your name, billing address and payment details are collected directly by Creem at its checkout (see "Payments").
Transactional email data. Your email address and the content of service emails (such as your sign-in link, invitations, a welcome message, account-deletion confirmation, two warnings when a payment fails and your paid plan is about to end, a notice before a domain you connected stops serving because your plan no longer covers it, and a notice when another account proves it controls a domain of yours and takes the connection over), processed through our email provider.
Feedback data. If you submit feedback, we collect the category you choose and your message, together with its technical context: the address you were on including its query string, the full user-agent string your browser sends, the app version, and the date. It is linked to your user id. On account deletion the user id is removed, so what is left is no longer linked to your account.
Error diagnostics. When the app hits an error we record what went wrong: the error message and stack trace, the address you were on, and your browser and app version. Error reports from your browser are linked to the internal id of your account, never to your email address and never to your content, so that we can tell how many people an error is hitting, diagnose it, and answer you if you write to us about it. Errors raised on our own servers carry no user id at all.
Authentication tokens and session data. Cryptographic hashes of your sign-in and session tokens (never the tokens themselves) with their expiry, and the cookies and local storage described in "Cookies and local storage".
Published sites, deployments and connected domains. If you publish a project, we store the address you chose for it, a record of each published version (who published it, when, and how many files and bytes it contains) and, if you connect a domain of your own, that domain name, its connection status and a verification token we generate for your account. Where a site was taken offline for breaking our acceptable-use rules, we also store that fact and its date. To check that a domain is yours, and that its records still point at us, we look it up through public DNS-over-HTTPS resolvers: Cloudflare's and, if that fails, Google's. They see the domain name and nothing about you. A domain you connect is sent to our infrastructure provider so that it can route requests and obtain a TLS certificate for it; certificates issued for a domain are recorded in public Certificate Transparency logs, as they are for any publicly trusted certificate. Those logs are append-only and run by third parties, so once a domain of yours appears in one the entry is public and permanent: neither we nor you can have it removed, and disconnecting the domain later does not undo it.
Technical and security data. Your client IP address is read transiently from the connection by our infrastructure provider to apply rate limiting and prevent abuse. This IP address is not stored in our application database, though it can appear in short-lived operational logs where a security event is recorded. Requests to the app, and requests to sites published on Lediv, are written to our infrastructure provider's operational logs, which can include an IP address and a user agent; those logs are kept for at most 7 days and are used only to operate the service and protect it from abuse (see "Scope and our roles").
What we do with your data, the legal basis, and how long we keep it
The table below maps each processing activity to the data involved, our purpose, the lawful basis under Article 6 GDPR, and our retention period. Where we rely on legitimate interests (Article 6(1)(f)), we have carried out a balancing test and concluded that our interest does not override your rights, in part because of how little data is involved and our deletion/anonymization practices.
| Activity | Data categories | Purpose | Lawful basis | Retention |
|---|---|---|---|---|
| Account creation and passwordless authentication | Email; sign-in provider identifiers (account id, name or username, email); magic-link token hash | Create and secure your account and sign you in without a password | Art. 6(1)(b) contract / pre-contract | Account data until you delete your account. Sign-in and account-deletion links are valid for 15 minutes and invitation links for 7 days; magic-link token records become unusable once they expire or are consumed, and are deleted when the account matching their email address is deleted |
| Session management | Hash of refresh token, user id, expiry; session cookies | Keep you securely signed in | Art. 6(1)(b) contract | Refresh token 30 days; session access token 5 minutes. Signing out deletes the session for that device (you can also revoke all sessions from the app); all sessions are deleted on account deletion, and expired sessions are purged automatically |
| User Content hosting, storage and real-time sync | Your projects, files, documents and assets (may contain personal data you add) | Store, render, synchronize and let you collaborate on your designs | Art. 6(1)(b) contract (we act as your processor for embedded third-party personal data) | Until you delete the content or your account. Deleting a project moves it to the trash; it is purged from storage when you empty the trash or delete your account |
| Publishing a site (including domains you connect) | The addresses a site is served at, including the private-looking one a preview link uses; deployment records (publisher user id, timestamp, file count and size); the domain names you connect, their status and your account's domain verification token; your site's search-engine visibility setting; and, where a site was taken offline for breaking our acceptable-use rules, that fact and its date | Serve your published site, check that a domain you connect is yours, and obtain and renew its TLS certificate | Art. 6(1)(b) contract; Art. 6(1)(f) legitimate interests for the record that outlives the account | Until you unpublish the site, disconnect the domain or delete the project or your account; earlier published versions are pruned to the number your plan retains, and a change of plan prunes them the same way, so when a paid plan ends the history of every published site is pruned within a day to the version that is live and anything published after it. One exception outlives all of these: where a domain of yours was provisioned for your site at our infrastructure provider, we keep that domain name, an internal account reference and the date the connection was removed, so that only someone who can prove the domain is theirs may connect it. We keep that record for as long as the domain's DNS may still point at our infrastructure; once it no longer does, we delete it on request after checking the DNS (see "Account deletion and what happens to your data") |
| Serving published sites to their visitors | Request data of visitors to your published site, or to a preview of it you shared (IP address, user agent, requested address) | Route and serve the request, and protect the service from abuse | Art. 6(1)(f) legitimate interests (operating and securing a hosting service). We are the controller for this technical data; for whatever your own site chooses to collect, you are | Processed transiently to serve the request; operational logs kept for at most 7 days and then deleted automatically |
| Handling notices and enforcing our acceptable-use rules | The notice and the name and email address of whoever sent it; the site or content it reports or that we ourselves flag; our decision and the statement of reasons we send to the affected account | Assess reports of illegal content or breaches of our acceptable-use rules, act on them whether they reach us as a notice or we find them ourselves, and answer both the sender and the account concerned | Art. 6(1)(c) legal obligation (Articles 16 to 18 of Regulation (EU) 2022/2065, the Digital Services Act); Art. 6(1)(f) legitimate interests in keeping the Service lawful and safe | Kept while we act on the notice and for as long as needed to deal with any challenge to our decision or claim arising from it, then deleted |
| Support, complaints, withdrawal notices and rights requests | Your email address, your message and our reply, and the reference we assign to a consumer complaint | Answer you, handle a withdrawal or a request under data protection law, and keep a record that we did | Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation (consumer and data protection law); Art. 6(1)(f) legitimate interests in defending a claim | Kept while we deal with the matter and for as long as a claim about it could be brought, then deleted |
| Collaboration and presence | Membership records (team or project, role, status, email); profile (display name + color); presence (user id + display name + color only) | Enable teams, roles and real-time presence | Art. 6(1)(b) contract | While the membership exists; removed when you leave or delete your account |
| Invitations | Invitation records (target team or project, accounts involved, invitee email, token reference, status, expiry) | Let you invite collaborators | Art. 6(1)(b) contract (for you); Art. 6(1)(f) legitimate interests for reaching an invitee who is not yet a user | Invitation records are kept with their status (pending, accepted, declined, revoked) while the related accounts exist, and are deleted when the inviter's or the invitee's account is deleted |
| Transactional email (via Resend) | Recipient email; message content (sign-in link, invitation, welcome, account-deletion, failed-payment and end-of-plan warnings, connected-domain expiry and domain-takeover notices) | Deliver service-critical emails | Art. 6(1)(b) contract | Not retained by us beyond sending; our email provider retains delivery logs for a limited period under its data processing agreement |
| Billing and subscription management (via Creem) | Creem-issued customer and subscription identifiers and subscription metadata (plan, seat quantity, billing period, status); processed webhook event ids | Manage your paid subscription and seats (we never receive card/payment data) | Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation for any accounting record we must keep (tax/VAT invoicing records are held by Creem as Merchant of Record) | Subscription record until account deletion; a processed webhook event id is kept to prevent double-processing of the same billing event, and is removed if processing fails so the event can be retried |
| Feedback | Your message and its technical context (the address you were on including its query string, the full user-agent string, the app version and the date), linked to your user id | Triage issues and improve the product | Art. 6(1)(f) legitimate interests (improving the Service) | Retained after account deletion with the user id removed, so it is no longer linked to your account |
| Error monitoring (via Sentry) | Error message and stack trace; the requested URL; user agent; app version; and, for errors raised in your browser, the internal id of your account | Detect, diagnose and fix application errors | Art. 6(1)(f) legitimate interests (keeping the Service working) | For 30 days, then deleted by our provider |
| Operating and securing the Lediv app | Transient client IP and rate-limit counters; request metadata written to our infrastructure provider's operational logs (requested path, status and timing, and in a security event the client IP and user agent) | Diagnose faults, protect the Service from abuse and fraud, and keep the app running | Art. 6(1)(f) legitimate interests | IP never stored in our application database; counters short-lived; operational logs kept by our infrastructure provider for at most 7 days, then deleted automatically |
| Agent access (personal access tokens and connected apps) | For a token you create: the name you gave it, its last six characters, the permissions you chose, the project you pinned it to if you pinned one, and when it was created, last used and expires. The secret itself is stored only as a hash, and is shown to you once, at creation. For an app you connect: the name and the address it returns you to that the app declares about itself, the permissions you approved, the project you chose, and when you approved it | Let an agent you authorised read and change your own projects on your behalf, and let you see and withdraw that access from your account page | Art. 6(1)(b) contract | A token you create lives until you revoke it, until the expiry you chose passes, or until you delete your account; revoked and expired tokens are deleted 30 days later. An approval you give an app expires 30 days after you give it, and the app's short-lived credential lasts one hour; the registration the app made for itself is kept for 35 days after the last time the app used it. Revoking an app, or deleting your account, destroys the approval immediately |
| Agent activity log | For each action an agent takes: which action it was, the internal id of your account, the internal id of the credential it used, the internal id of the project it acted on, whether the action succeeded, and how long it took. No file content and no page content | Let us see what an agent did on your behalf when you ask, and detect and stop abuse of the agent interface | Art. 6(1)(f) legitimate interests (keeping the Service working and safe) | Written to our infrastructure provider's operational logs and kept there for at most 7 days, then deleted automatically |
| Local device storage | The cookies and local storage listed under "Cookies and local storage" | Keep you signed in, remember your theme, enable offline use and performance | Art. 6(1)(b) and Art. 6(1)(f) (our legitimate interest in keeping you signed in and delivering a fast, offline-capable Service; storage on your device is also covered by the ePrivacy exemption explained under "Cookies and local storage") | Signing out clears the session cookies and the copy of the session access token your browser holds; the tokens you created for your agents keep working, and are revoked from your account page; your theme and your offline cache stay until you clear them |
Where you use Lediv as a business or team customer, processing of your account and billing data is performed to enter into and perform our subscription contract with the team owner, who is the billing party. Tax and invoicing records for your purchases are retained by Creem, as Merchant of Record, for the periods required by its own legal obligations, independently of us. Residual copies may persist in backups operated by Lediv on Cloudflare R2: historical versions of deleted or overwritten data and daily database exports are retained for up to 30 days and then deleted automatically.
Providing your email address is a contractual requirement: without it we cannot create your account or sign you in. You are under no statutory obligation to provide any personal data, and all other data is either generated by your use of the Service or provided at your option.
No automated decision-making or profiling
We do not carry out any automated decision-making that produces legal or similarly significant effects on you, and we do not engage in profiling, within the meaning of Article 22 GDPR. The Lediv product itself uses no artificial-intelligence features, and we do not use your content to train any model. One process outside the Lediv app does: our Merchant of Record, Creem, generates sales statistics with AI tooling, acting as our processor, over the buyer's name, email address and IP address (see "Payments"). It touches nothing in your projects.
Cookies and local storage
Lediv uses only strictly necessary cookies and functional local storage. We do not use any analytics, advertising or cross-site tracking cookies, and we do not load third-party web fonts. Because everything below is either strictly necessary to operate the Service or is functional storage set as a direct result of your own actions, it is exempt from prior consent under the ePrivacy Directive (Article 5(3) and Recital 66) and under Article 22.2 of Spanish Law 34/2002 (LSSI), which is the rule the Spanish authority applies to a provider established here, and we therefore do not display a cookie consent banner. We still disclose everything we set, for transparency.
The table below covers Lediv itself.
On a site you publish we set nothing at all: any cookie or storage there is one
your own site sets, so disclosing it, and obtaining consent where it is needed, is yours to do.
One consequence of publishing on a Lediv address is worth knowing: sites under
lediv.site share a single parent domain, so a cookie your site scopes to that
parent is visible to the other sites on it, and browsers cap how many cookies one domain may
hold. Our publishing documentation explains this and how to avoid
it. A domain you connect yourself is a domain of yours alone and is not affected.
| Name | Type | Purpose | Attributes / Duration |
|---|---|---|---|
__Host-session-token | Cookie (strictly necessary) | Authentication | HttpOnly, Secure, Path=/, SameSite=Strict; 30 days |
__Host-session-status | Cookie (strictly necessary) | UI sign-in state ("1"), readable by JavaScript | Secure, Path=/, SameSite=Strict; 30 days |
__Host-google_oauth_state, __Host-github_oauth_state,
__Host-google_code_verifier | Cookies (strictly necessary) | Securing the sign-in flow | HttpOnly, Secure, SameSite=Lax; ~10 minutes (transient) |
__Host-oauth-return | Cookie (strictly necessary) | Returning you to the app-approval screen after you sign in | HttpOnly, Secure, Path=/, SameSite=Lax; 15 minutes (transient) |
| lediv-token | localStorage (functional) | A copy of your 5-minute session access token, so the app does not have to request a new one every time it starts. What keeps you signed in is the session cookie above | Until you clear it or sign out |
| lediv:theme | localStorage (functional) | Remembers your theme preference | Until you clear it |
| lediv_kicked | sessionStorage (functional) | One-time flag to show a notice after your access to a shared project is revoked | Removed on your next dashboard visit; cleared when the browser session ends |
sveltekit:scroll, sveltekit:snapshot | sessionStorage (functional) | Scroll position and page state while you navigate the app, set by our web framework | Until you close the tab |
| db-lediv | IndexedDB (functional) | Offline cache, for offline use and performance, of the documents of your account and of your projects. Those documents include your profile, your preferences, the state of your subscription and, if you are an owner, the email addresses of the people you invited, as well as your file contents and asset blobs. Documents and file contents are stored with an integrity hash used for sync; asset blobs are identified by an immutable id instead. Your basic user record (id, email) is stored alongside them | Until you clear it |
You can clear cookies and local storage through your browser at any time; doing so may sign you out and remove your offline cache.
Sharing and disclosure; our subprocessors
We share personal data only with the service providers below, who process it on our instructions (processors/subprocessors), and with the independent parties noted (who act under their own privacy policies). We do not sell or share your personal data.
Processors (subprocessors)
| Subprocessor | Service to Lediv | Data categories | Location | Transfer safeguard | DPA / docs |
|---|---|---|---|---|---|
| Cloudflare, Inc. (USA) | Hosting, database (D1), object storage of all User Content and assets (R2), real-time collaboration sync (Durable Objects), serverless compute (Workers), background job queues (Queues), inbound mail routing for our abuse address (Email Routing), rate limiting / abuse prevention, serving published sites and arranging the TLS certificates of domains you connect (which are issued by a certificate authority Cloudflare selects, not by Cloudflare itself) | Account, membership and billing-identifier data; session token hashes; all User Content and assets; transient client IP for rate limiting; published site addresses, deployment records and the domain names you connect; request data and operational logs of visits to published sites (retained for at most 7 days) | USA / global by default | EU-U.S. Data Privacy Framework (incl. UK Extension and Swiss-U.S. DPF); EU Standard Contractual Clauses (with UK Addendum / Swiss adaptations) as fallback. Data encrypted in transit and at rest | DPA · Subprocessors |
| Plus Five Five, Inc. (Resend) (USA) | Transactional email delivery (sign-in links, invitations, welcome, account-deletion, failed-payment and end-of-plan warnings, connected-domain expiry and domain-takeover notices) | Recipient email address; email subject/content and message metadata | USA | EU-U.S. Data Privacy Framework (incl. UK Extension; not Swiss-certified) + EU Standard Contractual Clauses with Swiss adaptations for transfers the DPF does not cover | DPA · Subprocessors |
| Functional Software, Inc. (Sentry) (USA) | Error monitoring (application error and crash reporting) | Error message and stack trace; request URL; user agent; app version; and, for errors raised in your browser, the internal id of your account. Error events are retained for 30 days | EU (we use Sentry's EU data residency region) | Error event data stored in Sentry's EU region; EU-U.S. Data Privacy Framework (incl. UK Extension and Swiss-U.S. DPF) and Sentry's DPA (incorporating the EU Standard Contractual Clauses) for any transfer the EU region does not cover | DPA · Security |
| Google Ireland Limited (Ireland), for the EEA | Google Workspace: our business email on the lediv.com domain, which holds every @lediv.com mailbox, including support@ and hello@ | Everything sent to or from those mailboxes: support messages, complaints, withdrawal notices, rights requests and notices under the Digital Services Act, together with our replies | EU / global | Google's Cloud Data Processing Addendum, with the EU-U.S. Data Privacy Framework and the EU Standard Contractual Clauses for onward transfers outside the EEA | DPA · Privacy Policy |
We also use two monitoring tools that receive no personal data at all, which is why they are not in the table: Better Stack, which probes our public health endpoint from the outside, and Healthchecks.io, which receives the timestamps of our scheduled jobs and internal check identifiers. Healthchecks.io is hosted at Hetzner in the EU and uses processors outside the EEA, and we send them nothing that identifies you, so no transfer safeguard is engaged.
Merchant of Record (independent controller). Armitage Labs OÜ, trading as Creem (Estonia, EU), is our Merchant of Record for all payments and subscriptions and an independent controller of the payment, billing and tax data it collects at its checkout and billing portal (see "Payments"); a limited set of data is processed on our behalf under Creem's DPA, whose Annex 3 lists Creem's own sub-processors (Privacy Policy).
Independent identity providers (used only if you choose that sign-in method)
| Provider | Role | Data exchanged | Privacy policy |
|---|---|---|---|
| Google Ireland Limited (Ireland) for users in the EEA and Switzerland; Google LLC (USA) elsewhere | Independent controller (Google OAuth) | We receive your Google account id (sub), name and email; Google processes the sign-in under its own policy | policies.google.com/privacy |
| GitHub, Inc. or GitHub B.V. (USA and the Netherlands, a Microsoft company) | Independent controller (GitHub OAuth) | We receive your GitHub id, login/username and email; GitHub processes the sign-in under its own policy | docs.github.com/privacy |
For users in the EEA and Switzerland, the controller for a Google sign-in is Google Ireland Limited; for everyone else it is Google LLC in the United States. GitHub names GitHub, Inc. in the United States or GitHub B.V. in the Netherlands. Where the limited data exchanged during sign-in reaches the United States, it is transferred under their own safeguards (such as the EU-U.S. Data Privacy Framework or Standard Contractual Clauses), as described in their privacy policies.
The agent you connect. When you connect an AI agent, whatever you allowed it to read leaves Lediv and reaches whoever runs that agent, a company you chose and not one we picked for you. What it then does with it, including whether it keeps it or trains on it, is governed by that company's own terms and privacy policy, not by this one, and we can neither see nor control it. That company is not our subprocessor. If your project holds personal data about other people, connecting an agent means sending that data to a party you selected, and that decision is yours. You can end it at any time from Connected apps or Access tokens in your account.
The module CDN the editor preview uses. When you preview a project in the editor, your browser fetches the npm modules your project imports straight from esm.sh, a public CDN, on our instruction. It therefore sees your IP address, your browser and the names and versions of the modules your project imports. It receives nothing else about you and no part of your content, and sites you publish do not use it.
We may also disclose personal data where required by law, to enforce our Terms, to protect our or others' rights, safety and property, or in connection with a merger, acquisition or sale of assets (in which case we will continue to protect your data and notify you of any change of controller).
We maintain and update this subprocessor list. Before a new or replacement subprocessor begins processing, we email the address on your account at least 30 days in advance, and you may object on reasonable data-protection grounds within those 30 days, as Section 24 of our Terms of Service sets out.
Payments (Creem as Merchant of Record)
Payments are handled by our Merchant of Record, Armitage Labs OÜ, trading as Creem (Rotermanni 14, Tallinn 10111, Estonia). When you purchase a paid plan, Creem acts as an independent data controller of the payment, billing and tax information you provide directly to it through its hosted checkout and billing portal, including your name, email address, billing address, payment details and order/transaction details, together with technical data such as your IP address. That processing is governed by Creem's Privacy Policy, not by this policy. What we store on our side, and what we never receive, is described under "Personal data we collect", and Creem's role is set out under "Sharing and disclosure".
Creem is established in Estonia (EU), so our disclosure of data to Creem is not a transfer outside the EEA; Creem's own onward transfers to service providers outside the EEA are made under Creem's safeguards (such as the Standard Contractual Clauses), as described in Creem's Privacy Policy. Where Creem processes limited Lediv data on our behalf, it does so as our processor under Creem's Data Processing Agreement, whose Annex 3 lists its sub-processors. That processing covers the users of our merchant dashboard and, for the sales statistics Creem generates with AI tooling outside the Lediv app, the buyer's name, email address and IP address; OpenAI is one of the sub-processors Creem lists for it.
International data transfers and infrastructure
Lediv is operated from Spain. Our core infrastructure (hosting, database, storage of your User Content and assets, and real-time synchronization) runs on Cloudflare, Inc. (USA) with default global placement, and our transactional email provider, Plus Five Five, Inc. (Resend), is also established in the United States. Our error monitoring provider, Functional Software, Inc. (Sentry), is a United States company, but we use Sentry's EU data residency region, so error event data is stored in the European Union. Our business email runs on Google Workspace, where our controller is Google Ireland Limited, established in the EEA. Your account data and User Content are therefore routinely processed in the United States and may be processed in other countries.
Where personal data is transferred from the European Economic Area, the United Kingdom or Switzerland to the United States, we rely on the EU-U.S. Data Privacy Framework, which remains in force: Cloudflare is certified under the EU-U.S. DPF, its UK Extension and the Swiss-U.S. DPF; Resend is certified under the EU-U.S. DPF and its UK Extension; Sentry is certified under the EU-U.S. DPF, its UK Extension and the Swiss-U.S. DPF (and, as noted, stores our error event data in its EU region). As an additional and fallback safeguard, the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), with the UK International Data Transfer Addendum and Swiss adaptations, are incorporated into our agreements with these providers and apply to any transfer the Framework does not cover (for example, transfers from Switzerland to Resend). Should the Framework be invalidated, transfers will continue on the basis of those Clauses.
Creem (Estonia, EU) and our sign-in providers, Google and GitHub, process data under their own transfer safeguards, as described under "Payments" and "Sharing and disclosure". You may request a copy of the relevant transfer safeguards by contacting us at support@lediv.com.
Infrastructure jurisdiction (non-personal data). For the purposes of Article 28 of Regulation (EU) 2023/2854 (Data Act): the ICT infrastructure used to provide the Service is operated by Cloudflare, Inc., our email infrastructure by Plus Five Five, Inc., and our error monitoring by Functional Software, Inc. (Sentry), all United States companies subject to United States jurisdiction (Cloudflare operates a global network). To guard against governmental access to, or transfer of, non-personal data held in the Union where that would conflict with Union or Member State law, we rely on encryption in transit and at rest, per-document authorization, and the contractual commitments in our providers' data processing agreements, under which requests are challenged where possible and disclosed to us where lawful.
Security
We implement appropriate technical and organizational measures to protect your personal data,
taking into account the state of the art and the risks involved (Article 32 GDPR), including:
passwordless authentication (no stored password to breach); refresh tokens stored on our side
only as cryptographic hashes, never in plain text; short-lived session access tokens (5
minutes); cookies with the attributes shown in the table above; encryption in transit
(TLS/HTTPS) and at rest provided by our infrastructure provider; per-document authorization
controlling access to content; and rate limiting. Our API and the sites we publish enable no
cross-origin API access (no CORS grants); session cookies are restricted to same-site requests
(SameSite=Strict), while the short-lived OAuth sign-in cookies use SameSite=Lax, which the
redirect-based sign-in flow requires. Every cookie we set also carries the
__Host- prefix, which pins it to the host that set it: it cannot carry a Domain
attribute, so no other host can set or overwrite it.
Please note that your content is encrypted in transit and at rest but is not end-to-end encrypted; this means we can technically access content to provide the Service (for example, to enable real-time sync and collaboration). No method of transmission or storage is completely secure, but we work to protect your data and to keep our measures current.
If something goes wrong. Where a personal data breach is likely to result in a high risk to your rights and freedoms, we will tell you about it without undue delay, and we will notify the Spanish Data Protection Agency within 72 hours of becoming aware of it where the law requires that. If you believe you have found a security problem, write to support@lediv.com and we will look into it.
Your rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you (Article 15).
- Rectify inaccurate or incomplete data (Article 16). You can edit your display name and identity color directly in the app; your email is tied to your sign-in identity.
- Erase your data (Article 17). You can delete your account yourself (see "Account deletion"); you can also ask us to erase data at support@lediv.com.
- Restrict processing (Article 18).
- Object, at any time, to processing based on our legitimate interests (Article 21), on grounds relating to your particular situation. Where you object, we stop that processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or we need it to establish, exercise or defend legal claims. Write to support@lediv.com.
- Data portability (Article 20). You can export any project you own at any time as a ZIP with all your source files and assets, which you own and can reuse anywhere; the procedures, formats and known limitations are on our Switching and data formats page.
- Withdraw consent at any time, where we rely on consent, without affecting prior lawful processing.
How to exercise your rights. Many rights are available self-service in the app (profile editing, project export, account deletion). For anything else, email support@lediv.com. We will respond within one month of receiving your request; we may extend this by up to two further months for complex or numerous requests, and will tell you if we do (Article 12(3)). We do not charge a fee, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse it (Article 12(5)).
Right to complain. If you believe we have not handled your data properly, you may complain directly to us at support@lediv.com. We will acknowledge your complaint within 30 days and reply without undue delay, telling you the outcome and what we have done about it.
You may also lodge a complaint with a data protection supervisory authority, in particular the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD), or the authority in your country of habitual residence or place of work. You do not have to come to us first, but we would appreciate the chance to put things right.
Account deletion and what happens to your data
You can delete your account yourself from within the app. For your protection, deletion is confirmed by an email link that is valid for 15 minutes. If you have a subscription that is still live with Creem, whether active, trialing, past due, paused or already scheduled to cancel, deletion is blocked until you cancel it through the Creem-hosted billing portal. If you cannot cancel it there for any reason, write to support@lediv.com and we will handle both the cancellation and the deletion for you.
Before deleting, you can export any project you own (as a ZIP) so you keep your work. Deleting a single project moves it to the trash, and it is purged from storage when you empty the trash. When you confirm account deletion, we permanently delete your account and its records (sessions, memberships, invitations, sign-in tokens, the personal access tokens you created for your agents, the approvals you gave connected apps, and the subscription record), and we purge all projects, teams and content you own from storage, the trash included. The purge starts immediately, and if the storage system fails we retry it, once a day, until it succeeds. Any site you had published is taken offline and its address released, its published versions are deleted, and any domain you had connected is disconnected on our side (the domain itself stays yours). You are also removed from any shared projects. Work you contributed to a project owned by someone else stays in that project, because it is theirs to keep or delete; ask its owner if you want it removed. Your feedback is kept with the user id removed, so it is no longer linked to your account.
One record outlives your account. Where a domain of your own was provisioned for your site at our infrastructure provider, we keep that domain name, an internal reference to the account it belonged to, and the date the connection was removed. We keep it so that nobody else can connect that domain to a Lediv site without first proving, at the domain's own DNS, that it is theirs. The reason is the window you cannot see: the DNS record pointing at us survives your account, sometimes for years, and without this record a stranger could connect the domain and collect the traffic still arriving on it. We keep it on the basis of our legitimate interest in preventing that (Article 6(1)(f) GDPR).
That is also the criterion for how long we keep it: for as long as the domain's DNS may still point at our infrastructure. We cannot see when you remove that record at your DNS provider, so we cannot put a date on it in advance. Once the domain no longer points at us, write to support@lediv.com and ask us to delete the record: we check the DNS and delete it. The record holds nothing else about you, it stops no one who can prove the domain is theirs, and removing the DNS record at your provider ends both the exposure it exists to cover and the reason to keep it.
Children and minimum age
The Service is not directed to children. You must be at least 16 years old to use Lediv, or older still where your own law sets a higher minimum age for it. This is a precautionary eligibility rule: because we provide the Service on the basis of a contract rather than consent, it is set independently of the digital-consent age under Article 8 GDPR. We do not knowingly collect personal data from children below that age. If we become aware that we have collected such data without appropriate consent, we will delete the account and the associated data.
US state privacy rights
US state privacy laws such as the California Consumer Privacy Act (CCPA/CPRA) apply above revenue and volume thresholds we are far below, so they almost certainly do not apply to us. Three facts are worth stating anyway, because they are what a reader in the United States comes here to check.
We do not sell your personal information, we do not share it for cross-context behavioral advertising, and we do not use or disclose sensitive personal information for any purpose that would give you a right to limit it. Opt-out preference signals such as the Global Privacy Control therefore have nothing to act on. The categories we collect, where they come from and what we use them for are the ones set out above.
The rights described under "Your rights" are available to everyone, wherever you live.
Changes to this policy
We may update this Privacy Policy from time to time, for example to reflect changes to the Service, our subprocessors or the law. Because this policy forms part of your agreement with us, a material change to it follows Section 21 of our Terms of Service: at least 30 days' notice by email or in-app, and you may terminate before it takes effect. We also update the "Last updated" date at the top. We review this policy at least every 12 months. Your continued use of the Service after the updated policy takes effect means you acknowledge the updated policy.