1. Controller
Controller for this website and Namarix's own business processing:
Young Hoon Lim (trading as „Mark Lim“) Operating under the Namarix brand Hasenburger Ring 51d 21335 Lüneburg Germany Email: mark@namarix.ai Website: https://namarix.ai
VAT ID: DE458015605
No separate Data Protection Officer has been appointed. Privacy requests can be sent to mark@namarix.ai.
2. Controller / Processor Roles
For Namarix's own website, sales, marketing, account administration, product administration, security, billing, legal, and business communications, Young Hoon Lim is the controller.
For Revont deployments operated for a client, the client is the controller for its prospect and customer data, and Young Hoon Lim / Namarix acts as a processor under the client's documented instructions and under a data processing agreement.
Where Namarix independently decides why and how personal data is used, such as for its own account administration, security, billing, legal compliance, and legally permitted marketing, Namarix acts as an independent controller for that processing.
3. Personal Data We Collect
We may collect:
- Administrator account data (our clients' staff, not website visitors): email address, sign-in method, workspace name and settings.
- Communications data: messages, demo requests, support requests, contact-form submissions, preferences, and opt-out status.
- AI agent conversation data: the work email address you choose to submit, every message in the conversation, timestamps, a session identifier we generate, and, derived from the conversation by an AI model, a short summary plus the pain point, objection, solution discussed and language detected. We do not ask you for your name, job title, seniority or department, and we do not store them.
- Client content and configuration data: the webinar, podcast, video, transcript and knowledge-base material a client uploads, together with speaker names and profile links, plus brand, prompt and agent configuration.
- Security data: your IP address, the session identifier and the event type are recorded for every request the AI agent widget makes, so we can detect abuse, rate-limit and investigate incidents. These records are kept for 180 days and then deleted.
- Widget storage on your device: a conversation thread held in your browser's local storage, described in section 8. We set no analytics or advertising cookies and run no tracking scripts.
- Embedding-site data: the web address of the page a client has installed the agent on, recorded so we can confirm the agent is only running where the client authorised it.
- Company information derived from your email domain: company name, industry, sub-industry, headquarters city, approximate employee range, product line and typical customers, gathered from publicly available web sources. We do not access private contact databases and we do not look up you personally. See section 5.
Do not submit sensitive personal data, health data, financial account data, government ID data, special-category data, confidential information, or trade secrets into the public AI agent unless we have expressly agreed in writing to handle that data.
4. How We Use Personal Data
We use personal data to:
- provide, operate, secure, maintain, and improve the website, Revont, the AI agents and the admin dashboards;
- create and manage workspaces, accounts, content pages, sessions, notifications, and client configurations;
- let visitors interact with an AI agent on a client's content page;
- record, analyze, summarize, and route AI-agent conversation history;
- deliver results to the client operating that agent, which may be a HubSpot contact and note, a row in the client's Google Sheet, a Slack message, or a webhook the client configured;
- tailor AI-agent responses to a visitor's company domain or business context;
- improve retrieval quality, prompts, evaluation and product quality using aggregated, de-identified learnings;
- conduct Namarix sales, marketing, and customer research where legally permitted;
- respond to enquiries, provide support, manage contracts and invoicing, prevent misuse, maintain security, comply with law, and enforce agreements.
We do not disclose one client's identifiable prospect data or confidential content to another client.
5. AI Agent And Email Capture
When you interact with a Revont-powered AI agent, the agent tells you at the start of the conversation that it is AI. We store the content of your conversation, and, if you choose to submit it, your work email address. The conversation record includes the questions you ask, the business problems you describe, objections you raise, the topics you are interested in, and how long you engaged.
Submitting a work email is optional and is asked for once per conversation. We use it so the agent can tailor its answers to your company context, so the client whose content you are reading can respond to your enquiry, and so the conversation can be connected to that client's CRM where the client has enabled one.
Company look-up from your email domain. After you submit a work email, we take the domain part of the address (for example „example.com“, never the part before the @) and run a public web search on it, then use an AI model to summarise the result into a short company profile: company name, industry, sub-industry, headquarters city, approximate employee range, product line, and typical customers. This describes the organisation, not you personally. We do not buy or query personal contact databases, and we do not look up your name, job title, seniority, phone number or social profiles. Free and disposable email domains are excluded from this look-up entirely. The profile is stored with your conversation and is included in what we pass to the client. Separately, if your question is one the client should answer directly, we send the text of that question to the same web-search provider, scoped to the client's own website, so we can point you at the right page. Nothing else from your conversation is sent there. Our legal basis for both is our and the client's legitimate interest in answering your enquiry properly (Art. 6(1)(f) GDPR), and you can object to it at any time using the contact details below.
If the AI agent is operated for one of our clients, your email, your conversation, a short AI-generated summary of it, and the company profile above are passed to that client so they can respond to your enquiry and understand what their audience is asking. We may use aggregated, de-identified interaction patterns across clients to improve Revont. We never share one client's identifiable prospect data with another client.
Submitting your work email does not subscribe you to anything from us. Namarix sends you no messages and adds you to no mailing list. Any reply or follow-up comes from the client operating that assistant, under its own privacy notice and its own responsibility.
The AI agent does not make decisions that produce legal effects or similarly significant effects about you. AI-generated outputs may be inaccurate and should be reviewed before important decisions are made.
6. Legal Bases
For individuals in the EEA, United Kingdom, or Switzerland, we rely on the following legal bases where applicable:
- Contract: to provide services, accounts, support, and requested product functionality.
- Legitimate interests: to operate, secure, analyze, improve, and market our B2B services; understand buyer intent and product-market signals; prevent abuse; support client sales and marketing workflows; and improve product performance, provided these interests are not overridden by your rights and freedoms.
- Consent: where we ask for consent, such as for certain marketing communications, optional cookies, or specific processing activities.
- Legal obligation: to comply with accounting, tax, corporate, regulatory, security, and legal obligations.
You may object to processing based on legitimate interests, including certain marketing and profiling activities, by contacting mark@namarix.ai.
7. Marketing Communications
We may send B2B marketing communications only where permitted by applicable law.
In Germany and much of the EU, marketing emails usually require prior consent unless a narrow legal exception applies. We treat cold outreach to Germany/EU prospects as a separate compliance-controlled workflow.
In the United States, commercial emails must identify the sender and include an opt-out method. Marketing emails will identify the sender, include a valid postal address where required, and provide an unsubscribe or opt-out method.
You can opt out of marketing communications at any time by using the unsubscribe link in an email or contacting mark@namarix.ai.
8. Cookies And Tracking
This website and the Revont AI agent use no analytics, no advertising pixels, no session replay, and no tracking cookies. The only cookies we set are strictly necessary ones for signed-in administrators of the product (a signed session cookie and the authentication provider's cookies). Because no non-essential cookies are loaded, no consent banner is shown.
The AI agent widget sets no cookies. It stores your conversation in your own browser's local storage so the thread survives a page reload, under a key beginning „kc_thread_“. That entry holds a randomly generated session id, your messages, and, if you submitted one, your email and the company profile. It is deleted automatically after seven days without activity, and immediately when you press Restart. One further entry („kc_active_tab_“) is used only to stop two browser tabs writing to the same conversation. When a source citation is shown, your browser loads that source's site icon from Google's public favicon service, which means Google sees your IP address for that request. If we ever introduce analytics or marketing cookies, we will ask for your consent first and add a preference control to the site. See our Cookie Policy for the full breakdown.
9. Sharing And Subprocessors
We may share personal data with:
- clients, when you interact with a Revont deployment operated for that client;
- service providers and subprocessors that host, store, secure, analyze, process, automate, communicate, and deliver the service;
- integration partners authorized by us or our clients, such as CRM, webhook, messaging, enrichment, email, or workflow tools;
- professional advisers, such as lawyers, accountants, auditors, insurers, and security consultants;
- authorities, courts, regulators, or other parties where required by law or necessary to protect rights, safety, security, or contractual interests;
- buyers, successors, or transaction participants in connection with a merger, financing, restructuring, asset sale, or future GmbH transition.
Our current sub-processors, by category, are: AI model providers (OpenAI, Anthropic, Cohere); web search used for the company look-up described above (Tavily); database, storage and administrator authentication (Supabase); object storage and content delivery (Cloudflare, EU jurisdiction); application hosting (Vercel); background media processing (Railway); error monitoring and operational alerting (Sentry, with email addresses redacted); marketing website hosting (Webflow); and, where a client enables them, that client's CRM and notification destinations (HubSpot, Google Sheets, Slack, or a webhook the client configures). The always-current list, with the data each one receives and the transfer safeguard that applies, is published in our Sub-processor Register.
Not every vendor receives every user's data. Which destinations receive your conversation depends on what the client operating that agent has configured.
10. International Transfers
We may process and transfer personal data in Germany, the European Union, the United States, and other countries where we or our service providers operate.
Some subprocessors are based in, or may process data from, the United States. Where we transfer personal data from the EEA, UK, or Switzerland to countries without an adequacy decision, we rely on appropriate safeguards such as standard contractual clauses, the EU-U.S. Data Privacy Framework where applicable, data processing agreements, and supplementary measures where required.
11. Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the service, maintain security, comply with law, resolve disputes, enforce agreements, and support legitimate business needs.
Unless a different period is required by law, contract, or client instruction:
- Account and workspace data: for the life of the account or client relationship, plus up to 24 months.
- AI agent conversation history and session data: up to 36 months from the last interaction.
- Prospect email and campaign engagement data: up to 36 months from last meaningful engagement.
- CRM, sales, and marketing records: up to 36 months from last engagement for inactive prospects, and for the active business relationship plus up to 24 months for customers.
- Aggregated, de-identified analytics and product learnings: indefinitely, provided they no longer identify an individual and are not used to re-identify them.
- Marketing suppression records: as long as needed to honor opt-outs.
- Security logs (IP address and request metadata): 180 days, unless a specific record is needed longer for security, abuse prevention, legal claims, or compliance.
- Contract, invoice, tax, bookkeeping, and compliance records: for the statutory period required by applicable law, which may be up to 10 years for certain business and tax records in Germany.
Our AI model providers are used under their commercial or API terms, under which content submitted to them is not used to train their models. Our own retention periods apply to copies stored in Namarix, client, CRM and backup systems. The full schedule is published as our Data Retention Schedule.
12. Security
We use technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, and disclosure. These measures may include access controls, encryption in transit, credential and secret management, logging, backups, provider security controls, and internal access restrictions.
No system is perfectly secure, and we cannot guarantee absolute security.
13. Your Rights
Depending on your location, you may have rights to:
- request access to personal data;
- request correction;
- request deletion;
- request restriction of processing;
- object to processing based on legitimate interests;
- request portability;
- withdraw consent where processing is based on consent;
- lodge a complaint with a data protection authority.
Namarix is established in Lüneburg, Lower Saxony. The competent supervisory authority is Die Landesbeauftragte für den Datenschutz Niedersachsen (the Lower Saxony Data Protection Commissioner): https://lfd.niedersachsen.de
To exercise your rights, contact mark@namarix.ai. If your data was processed on behalf of one of our clients, we may forward your request to that client or help the client respond.
14. U.S. Privacy Rights
If you are located in a U.S. state with applicable privacy rights, you may have rights to know, access, correct, delete, port, or opt out of certain uses or disclosures of personal information.
We do not sell personal information in the traditional sense. If we use advertising, analytics, enrichment, or tracking technologies that may be considered a "sale," "sharing," or "targeted advertising" under applicable law, we will provide required notices and opt-out methods.
15. Children's Privacy
Our services are intended for business users and are not directed to children. We do not knowingly collect personal data from children under 16.
16. Changes
We may update this Privacy Policy from time to time. The updated version will be posted on our website with a new "Last updated" date. If changes are material, we may provide additional notice where required.
17. Contact
Young Hoon Lim (trading as „Mark Lim“) Operating under the Namarix brand Hasenburger Ring 51d 21335 Lüneburg Germany mark@namarix.ai https://namarix.ai