Legal

Privacy Policy

This policy covers both CEMP Life™ and CEMP Business™. Last updated: May 2026.

Effective date: 30 July 2026  |  CEMP IT Ltd

1. Introduction

This Privacy Policy explains how CEMP IT Ltd ("CEMP", "we", "our" or "us") handles information in connection with two distinct products: CEMP Life™, our consumer mobile application, and CEMP Business™, our web based business platform.

The two products are different in architecture and in purpose, and their data practices differ accordingly. Sections 3 and 4 apply according to which product you use. Sections 5 to 14 apply to both.

By downloading, installing, accessing or using either product, you confirm that you have read and understood this Policy. If you do not accept it, you must not use the products.

Data Controller

For the purposes of the UK General Data Protection Regulation, the EU General Data Protection Regulation and other applicable data protection legislation, the controller in respect of any personal data described in this Policy is CEMP IT Ltd, a company incorporated in Delaware, United States. Enquiries may be addressed to legal@cempit.com.

Where you use CEMP Business to process personal data relating to your own customers, employees or contacts, you act as the controller of that data and we act as your processor. This distinction is set out in Section 4.

2. Our Position in Summary

The following statements are made expressly and are intended to be relied upon:

These are commitments, not aspirations. They apply to both products, to all users, and in every jurisdiction in which the products are made available.

Section 3: CEMP Life, Mobile Application

📱 CEMP Life Mobile App

3. CEMP Life: Data Practices

3.1 We Collect Nothing

CEMP IT Ltd does not collect, receive, store or retain any personal data from the CEMP Life application. The application requires no account, no registration, no email address and no sign in. We do not create a user profile, we do not assign a persistent identifier to you, and we hold no record that identifies you or connects you to any activity within the application.

We do not know who you are, we do not know that you have installed the application, and we do not know what you do within it. This is a design decision, not merely a policy undertaking.

3.2 Subscription Information Held by Google

Paid features are made available through a subscription purchased and administered entirely by Google Play. Where you take out a subscription, Google collects and holds the information necessary to operate it, which may include your Google account identity, payment method, billing address, transaction history and subscription status.

That information is collected by Google, held by Google, and governed by Google's own terms and privacy policy, to which CEMP IT Ltd is not a party. We do not receive it and we cannot access it. The only information available to the application is a confirmation from Google that a valid subscription exists, used solely to unlock paid features on the device. We do not receive your name, email address, payment card details or billing address.

Questions concerning subscription records, billing, refunds or cancellation must be directed to Google Play, which is the party holding that information.

3.3 Transient Processing

Certain features send a minimal, anonymous payload to our secure backend so that a result can be generated and returned to your device. Such processing is transient in the strict sense: the payload is used to produce your result and is then discarded. It is not stored, logged, indexed, associated with you or retained in any form once the result has been returned.

These payloads contain no name, no account identifier, no device identifier and no contact information, and there is no mechanism by which they could be attributed to an individual user.

3.4 Device Sensors and Permissions

Where a feature requires it, the application uses your phone's in built sensors and hardware. Any such access takes place on your device, at the moment you open the relevant feature, and only for as long as that feature is in use.

Permissions are requested at the point of use rather than on installation, are used only for the feature you have opened, and may be refused or withdrawn at any time through your device settings. Refusing a permission disables only the feature that requires it. No sensor data is transmitted to us except as part of the transient processing described in Section 3.3, and none is retained.

3.5 No Tracking and No Advertising

The application contains no advertising, no advertising identifiers, no behavioural analytics, no third party trackers and no social media pixels. We do not build profiles, infer characteristics or measure engagement at the level of an individual user.

3.6 Emergency and Safety Features

Where a feature contacts another person, for example by sending a message or placing a call, it does so using contact details you have configured on your own device, and the action is carried out by your device. Those contact details are not transmitted to us, are not stored by us, and are not accessible to us.

Section 4: CEMP Business, Web Platform

⛶ CEMP Business Web Platform

4. CEMP Business: Data Practices

4.1 Collection Is Instructed by You and Is Inherent to the Platform

CEMP Business is a data platform. Storing and processing the information you submit is not incidental to the service; it is the service. By registering for and using the platform, you expressly instruct and authorise us to collect, store, process and display the information you submit, for the sole purpose of providing the functionality you have asked the platform to perform.

The platform cannot operate without this. It is not possible to use it while withholding that authorisation, and no alternative mode of operation is offered in which submitted information is not retained. All information submitted is collected and processed strictly as required by you in order to use the platform. We do not sell or share any information with third parties.

4.2 Categories of Information

4.3 Purpose and Lawful Basis

We process this information for the performance of our contract with you, being the provision of the platform to which you have subscribed, and, in respect of security logging and abuse prevention, on the basis of our legitimate interest in maintaining the integrity and availability of the service. Where we rely on consent, that consent may be withdrawn at any time.

4.4 Your Responsibilities Where You Submit Third Party Data

Where the information you submit contains personal data relating to any other person, including your customers, employees, suppliers or contacts, you remain the controller of that data and we act solely as your processor on your documented instructions.

You are solely responsible for establishing a lawful basis for that processing, for issuing any privacy notice required, for obtaining any consent required, for responding to requests from the individuals concerned, and for the accuracy and lawfulness of what you submit. We do not independently determine the purposes for which such data is processed.

4.5 Confidentiality, Isolation and Access

Your workspace is logically isolated. No other customer can view, access, query or export your data. We do not read your content except where strictly necessary to investigate a security incident, to prevent or address unlawful activity, or to comply with a binding legal order. Any such access is limited to what is necessary and is subject to internal authorisation.

We do not use your content to train models, to develop products, to generate benchmarks, or for any commercial purpose of our own.

4.6 Artificial Intelligence Features

Where you use an AI feature, the relevant content is transmitted for processing and a result is returned to you. That processing is transient. The content is not retained after the response is returned and is not used to train models. AI features operate only on data belonging to your own account.

Sections 5 to 14: Both Products

🌐 Both Products

5. Service Providers

We engage a limited number of established commercial service providers to perform defined functions necessary to operate the products. These fall into the following categories:

Each provider acts strictly as a processor on our written instructions, is bound by a data processing agreement, is subject to confidentiality obligations, and is prohibited from using your information for any purpose other than performing the function for which it is engaged.

We do not publish the identity, location or configuration of the systems comprising our infrastructure. Disclosure of that detail would materially assist an attacker and would itself constitute a security risk. Such information is made available to regulators, and to enterprise customers under confidentiality, where there is a legitimate need.

6. No Sale and No Sharing

We do not sell, rent, trade, licence, disclose or otherwise share personal data with third parties for marketing, advertising, profiling, analytics, enrichment, data brokerage or any other commercial purpose. We have never done so, and we do not permit our providers to do so.

For the purposes of the California Consumer Privacy Act as amended, we do not "sell" or "share" personal information as those terms are defined in that legislation, and we have no actual knowledge of selling or sharing the personal information of consumers under sixteen years of age.

Information may be disclosed only where required by binding legal process, where necessary to establish, exercise or defend legal claims, where necessary to prevent imminent harm, or in connection with a corporate transaction in which the acquiring party assumes the obligations set out in this Policy.

7. International Transfers

Where personal data is transferred across borders, we rely on appropriate safeguards recognised under applicable data protection law, including standard contractual clauses where required, supported by encryption in transit and at rest. Details of the safeguards applied are available on request to legal@cempit.com.

8. Security

We implement technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access control on a least privilege basis, credential hashing, and logging and monitoring of administrative access.

No system can be guaranteed to be impenetrable. You are responsible for maintaining the confidentiality of your credentials, for using a strong and unique password, and for notifying us promptly at legal@cempit.com if you suspect unauthorised access. Where a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, affected individuals, within the periods prescribed by law.

9. Retention

You should export any material you wish to keep before closing your account. Deletion is irreversible, and deleted content cannot be reconstructed or reissued.

10. Your Rights

Subject to applicable law, you may exercise the following rights in respect of personal data we hold about you:

Requests should be sent to legal@cempit.com and will be answered within the period prescribed by applicable law. We may require verification of identity before acting. You may also lodge a complaint with your supervisory authority, although we would welcome the opportunity to resolve the matter first.

In respect of CEMP Life, because we hold no personal data there is no record for us to retrieve, correct or erase. Requests concerning subscription records must be directed to Google Play.

11. Children

Neither product is directed at children. CEMP Life is not intended for use by persons under thirteen years of age, and CEMP Business is offered only to persons aged eighteen or over acting in a business capacity. We do not knowingly collect personal data from children. Where we become aware that we have done so, it will be deleted without undue delay.

12. Cookies and Similar Technologies

The mobile application does not use cookies. Our website and CEMP Business use strictly necessary cookies and equivalent local storage for authentication, session continuity and security. We do not use advertising cookies, behavioural tracking cookies or third party marketing pixels. Browser controls may be used to manage cookies, although disabling strictly necessary cookies will prevent the platform from functioning.

13. Changes to This Policy

This Policy may be updated to reflect changes in our products, our practices or applicable law. The effective date at the head of this page records the current version. Where a change materially affects your rights, we will give notice by a prominent statement within the product or, for CEMP Business, by email to the address on your account, before the change takes effect. Continued use after the effective date constitutes acceptance.

14. Contact

Questions, requests and complaints concerning this Policy or our handling of personal data should be addressed to legal@cempit.com.

CEMP IT Ltd, operator of CEMP Life™ and CEMP Business™.