Security
How Lemmpo protects your data
This page sets out the principles Lemmpo is built on. The detailed material — architecture diagrams, our completed security questionnaire, recovery objectives and procedures — is shared on request, with a named contact.
Secure by design
EU-hosted data, GDPR-ready, no data resale
No-pressure demo
30 minutes, no sales script
No credit card
Evaluate before you commit
Reply within 24 hours
A named contact, not a ticket queue
In short
The essentials
Encrypted in transit
All traffic between your browsers, the mobile app and our servers is encrypted.
Passwords are irreversible
No password is stored in clear text or in any reversible form. Even in a breach, they are not usable as-is.
Isolated per organization
Each customer organization has its own isolated data perimeter. Access is then restricted by team, project and role.
No files on disk
Your documents are never written to a server file system. They stay inside your organization's perimeter, with no public URL.
Audit trail
Submissions, approvals and business changes are recorded and can be reviewed.
Your data stays portable
You can export your data at any time. Nothing about the format is designed to keep you here.
Encryption and access protection
In transit. All traffic between workstations, mobile apps and the Lemmpo infrastructure is encrypted, with certificates renewed automatically.
Passwords. They are never stored in clear text or in any reversible form. They are hashed using a recognized key derivation function, with a distinct random salt per account. Even if the database were compromised, the passwords would not be usable as they stand.
Files and attachments. No user file is written to a server file system. Job photos, reports and documents are held in a perimeter attached to your organization and reachable only by authorized users. There is no file accessible through a guessable URL.
Isolation. Separation is applied at two levels: between customer organizations first, then inside your organization by team, project, site or role. An employee only sees the perimeter assigned to them.
Logging and retention
We keep two kinds of records, with different purposes and different lifespans.
Technical logs (application and infrastructure): kept for a short period, limited to what incident diagnosis and anomaly detection require.
Business transaction log: the history of functional events — submissions, approvals, changes — is kept over the long term, subject to the rights GDPR grants to data subjects, including the right to erasure. This is the log that reconstructs precisely who did what, and when: the auditability that regulated buyers ask for.
Where your data lives
Your data is hosted in the European Union, with OVHcloud. No operational data leaves that perimeter.
Why this matters if you operate in Europe. Employee scheduling and time-tracking data is personal data under the GDPR. Keeping it inside the EU means your processing sits inside the regulatory perimeter by default, rather than depending on a transfer mechanism you have to document and defend. If your legal team has ever had to fill in a transfer impact assessment, they will recognize what that saves.
If you operate only in North America, this is simply a neutral fact: your data is held in a jurisdiction with strong statutory data-protection guarantees, by a vendor whose revenue comes from subscriptions rather than from data. We do not sell your data, and we do not use it to train third-party models.
Stricter requirements. If your situation calls for a dedicated hosting arrangement — a customer imposing a specific standard, an internal security requirement — that can be discussed under the Enterprise plan, after assessment and quote. Tell us at the first conversation and we will tell you plainly whether we can meet it, rather than costing you a procurement cycle.
Backups, continuity and recovery
Disaster recovery relies on two complementary layers.
A system baseline. The infrastructure is snapshotted regularly at our host, which allows a working server to be rebuilt quickly.
Frequent data backups. The database is backed up at short intervals to external storage, and it is that backup which is restored on top of the system baseline. The consequence: even when the infrastructure snapshot returns the server to an earlier state, your data is brought back to the most recent point available.
All customer data lives in that database, so this level of service applies to every feature without exception — schedules, hours, time off, projects, reports and attachments follow the same process. Our recovery objectives (RPO and RTO) and our restore-testing procedures are shared on request.
Subprocessors and third-party services
Like any online software vendor, Lemmpo relies on a limited number of third-party services. We keep that list current and share it in full — role, location and status of each — with your security or compliance team.
The principle we apply: operational data — schedules, hours, time off, projects, field reports and your employees' information — stays within the EU. It is not passed to any third-party service.
The few services located outside the European Union sit at the edge of the product: subscription payment processing, company-directory enrichment from domain names, and push notification delivery to phones — the last of which is inherent to mobile operating systems and cannot be avoided by any iOS or Android application.
Data portability
Your data belongs to you. It remains exportable throughout the contract and at its end, with no exit fee and no proprietary format designed to keep you. Portability is not a commercial favor — it is a clause you should demand from any SaaS vendor, and we would rather put it in writing than be asked.
Going further than this page
This page covers principles. The detail — a pre-completed security questionnaire, architecture diagram, quantified recovery objectives, the full subprocessor register, material for your vendor assessment — is shared on request, with a named contact.
Running a security review or a vendor assessment? Write to us with your context: we will send our security questionnaire, or complete your own template directly.
Reporting a vulnerability
If you believe you have found a security flaw in Lemmpo, write to security@lemmpo.com. We acknowledge receipt within two business days and keep you informed as we work on it.
We ask that you do not publicly disclose the vulnerability before a fix is deployed, and that you do not access or alter other users' data during testing. Our contact details are also published in the standard format at /.well-known/security.txt.
Questions fréquentes
Les réponses aux questions que vous vous posez.
Is the data encrypted?+
Traffic between your workstations, the mobile apps and our servers is encrypted. Passwords are hashed irreversibly, with a random salt unique to each account. The specific mechanisms are documented in our security questionnaire, shared on request.
Where are the files my crews upload from the field stored?+
Inside your organization's data perimeter, never on a server file system. Each file is reachable only by authorized users: there is no public URL that would allow access.
How long do you keep logs?+
Technical logs are kept for a short period, limited to diagnostic needs. The business transaction log — who did what, and when — is retained long term, subject to the rights granted by the GDPR, including the right to erasure.
What are your recovery objectives?+
The database is backed up at short intervals to external storage, which sharply limits data loss in a disaster scenario. Our quantified RPO and RTO figures, and our restore-testing procedures, are shared on request.
Can I get the list of your subprocessors?+
Yes. We share the complete list — role, location and status of each — with your security or compliance team. The governing principle: your operational data stays within the EU and is not passed to any third-party service.
Is our data subject to the GDPR?+
Your data is hosted in the European Union and processed in line with the GDPR. If you have employees or customers in Europe, that keeps the processing inside the regulatory perimeter by default. If you operate only in North America, it means your data sits with a vendor that does not sell it and does not use it to train third-party models.
Can I get my data back if I leave Lemmpo?+
Yes, at any time, during the contract and at its end, with no exit fee.
How do I report a security flaw?+
By email to security@lemmpo.com. We acknowledge receipt within two business days. Our contact details are also published at /.well-known/security.txt.
Security question, or a questionnaire to fill in?
Ask for our pre-completed security questionnaire, or send us your own template — we'll complete it.
Reply within 48 business hours • A named technical contact