Lab08 Privacy Policy

Last updated: 14 September 2026

This Privacy Policy describes how Lab08 ApS (“Lab08,” “we,” “us,” or “our”) handles personal information in connection with Lab08, our platform for investment conviction & due diligence (the “Platform”).

I. Who We Are

This policy applies to Lab08 ApS and to all of its 100% owned subsidiaries.

We process information. We do not control it. Our customers use the Platform to keep their own records and to run their own due diligence. They decide what goes into their workspace, what analysis is run, what it is used for, and how long it is kept. For all of that content the customer is the controller and Lab08 acts solely as their processor, on their instructions. We do not use it for our own purposes.

The narrow exception is the administrative information we need in order to operate the Platform itself: your account details, sign-in records, and the technical logs described in section 2. We are the controller of that limited set, because nobody else determines it.

So if you want information held in a customer’s workspace corrected or deleted, the decision is the customer’s, not ours. Write to us and we will pass your request on and support them in acting on it. Section 9 explains this.

II. Information We Handle

Information we control. Your name, email address, sign-in credentials or single sign-on identifier, your role and organisation, and error reports, performance data, and a sample of interface sessions recorded by our monitoring provider so that we can diagnose faults.

Information we process for our customers. Everything a customer puts into or generates inside their workspace: the documents, notes, comments, and messages they create or upload; the deals their team is assigned to and the analyses they run; their chat sessions with the assistant. These records may contain personal information about people who do not use the Platform. The customer decides what goes in; we hold it for them.

Research the Platform carries out on a customer’s instructions. When a customer asks us to evaluate a company, the Platform gathers professional information about that company and the people who work there and produces written analysis of the team for that customer. The customer decides that this research happens and what is done with the result. Section 9 explains how to object.

We do not deliberately collect special categories of personal information, such as health, biometric, ethnic origin, political opinion, religious belief, trade union membership, or sexual orientation data. If you tell us that such information has appeared, we will act to remove it.

III. The Slack App

Lab08 for Slack (the “Slack app”) lets a customer receive notifications from their Lab08 workspace in Slack channels they choose, and lets members of their team ask Lab08 questions from Slack. It is optional. This section describes what the Slack app handles in addition to everything above; the rest of this policy applies to it in full.

What we receive from Slack. When a customer’s administrator installs the Slack app, Slack gives us the workspace’s identifier and name, a bot user identifier, and a bot access token. We store the token encrypted, bound to that customer’s record. When the administrator chooses channels for Lab08 to post in, we store those channels’ identifiers and names. When a team member links their Slack account, we store their Slack user identifier alongside their Lab08 account. When someone asks Lab08 a question, we receive the text of that message, the channel and thread it was posted in, and the Slack identifier of the person who asked.

What we do not receive. The Slack app does not request permission to read channel history, direct messages, files, or your workspace’s member directory or anyone’s email address. It receives a message only when that message mentions Lab08 or is a /lab08 command, and it acts only in channels the administrator has bound. It holds no permissions tied to the person who installed it.

How we use it. To post the notifications the administrator configured, to answer questions, and to act on buttons pressed in Slack. To answer a question, the question is sent together with the relevant company’s workspace content to the artificial intelligence provider described in section VI, which generates the answer. The question and the answer are saved as a conversation in the customer’s Lab08 workspace, exactly as a chat typed in the Platform would be. We do not use Slack content to train models, and our providers may not either. We do not use it for anything else.

Who controls it. The customer, as in section I. The administrator decides which channels Lab08 posts in and what about. Everyone in a bound channel can read what Lab08 posts; only people who have linked a Lab08 account can ask questions or take actions, and Lab08 will not show anyone something they could not already see in Slack or in Lab08. Messages Lab08 posts into Slack are then held by Slack under the customer’s own agreement with Slack.

How long we keep it. Questions and answers are part of the customer’s workspace content and are kept for as long as the customer instructs. Transient copies used to process a question are deleted within 24 hours. When the Slack app is uninstalled or its access is revoked, we stop using the token immediately, revoke it with Slack where we can, and disable every channel binding and account link. We erase the remaining Slack records, including the token, within fourteen business days.

Your rights. As set out in section IX. A team member can unlink their own Slack account at any time with /lab08 unlink. Questions about the Slack app can also go to support@lab08.com.

IV. How We Use It

We use the administrative information we control to create and manage your account, let you sign in, send service emails such as invitations and password resets, respond to your support requests, keep the Platform secure and diagnose faults, and meet our legal and accounting obligations.

Everything else we process only on our customers’ instructions and only for the purposes they set. We do not use their workspace content for our own purposes, we do not use it for advertising, and we do not sell personal information.

The analyses the Platform produces are there to help investors think, not to decide anything on their behalf. We do not make decisions about you by automated means alone that produce legal or similarly significant effects.

V. Legal Basis

For the workspace content and research we process on our customers’ behalf, the customer is the controller and determines the legal basis. We act on their instructions.

For the administrative information we control, we rely on:

VI. Who We Share It With

We use a small number of service providers to run the Platform. Where they handle personal information on our behalf they act as our sub-processors, engaged with our customers’ authorisation and under a written contract that bars them from using the information for their own purposes. They are:

Where your organisation enables single sign-on, your identity provider also processes your sign-in, under your organisation’s own agreement with it. Connected services you choose to use, such as Slack, process information under your own agreement with them, as section III describes. We will update this list when it changes.

We may also share information where the law requires it, and with our professional advisers under a duty of confidentiality. If Lab08 is ever acquired or merged, information may transfer to the acquirer, who would remain bound by this policy until it lawfully tells you otherwise.

We do not use advertising networks or third-party product analytics, and we do not sell or rent personal information.

VII. Where We Store It

Our infrastructure is hosted in the European Union. Some of our service providers may process personal information outside the European Economic Area. Where that happens we rely on the European Commission’s Standard Contractual Clauses. You can ask us for a copy of the safeguards we rely on by writing to hello@lab08.com.

VIII. Security and Retention

We take reasonable measures to protect personal information from unauthorised access, loss, and misuse. Each customer’s data is logically separated within our systems so that one customer cannot reach another’s. We encrypt information in transit and at rest, use role-based access control, serve files through short-lived links, and limit access to production systems to named people who need it. No system is completely secure. If a breach happens we will notify the affected customers without undue delay, and the supervisory authority within 72 hours where we are required to.

We keep the information we control for as long as necessary for the purposes described in this policy, or as required by law. Workspace content is kept for as long as the customer instructs, and is deleted or returned when their agreement with us ends.

IX. Your Rights

You may have the right to access your personal information, to have it corrected or deleted, to restrict or object to how it is used, to receive it in a portable format, to withdraw consent where it is relied on, and to complain to a supervisory authority.

Where those rights concern the administrative information we control, write to hello@lab08.com and we will handle your request. We will respond within one month.

Where they concern information held in a customer’s workspace, including research and analysis about you, the customer is the controller and the decision is theirs. Write to us anyway: we will identify the customers concerned as far as our systems allow, pass your request on, support them in acting on it, and tell you honestly what we found and what we could not reach. Our own default is to act on an objection rather than argue against it, so we will also stop collecting further information about you.

You have the right to complain to a supervisory authority. Ours is the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark, dt@datatilsynet.dk. You may also complain to the authority in the country where you live or work.

X. Cookies

The Platform does not use advertising or marketing cookies, and we do not use third-party analytics in it. Our sign-in system sets cookies that are strictly necessary to keep you signed in, and your browser holds an access token for the length of your session. We serve fonts from our own servers. Our monitoring provider records a sample of interface sessions to help us reproduce faults; the recording masks text and blocks images, so the documents and deal information you are looking at are not captured.

This website is separate from the Platform and does use two third-party services, but only if you agree to them. Google Analytics tells us which pages are read and how people arrive. HubSpot lets us recognise a returning visitor so a conversation already under way is not started again from scratch. Both set cookies in your browser and both send data outside the EU.

Neither one loads until you choose Accept on the cookie banner. Choosing Decline means they are never requested at all, and the site behaves the same either way. Your choice is remembered in your browser rather than in a cookie, and you can change it whenever you like through Cookie settings at the bottom of any page. Withdrawing consent reloads the page so nothing keeps running; cookies already set by those services can be cleared through your browser.

XI. Changes to This Policy

We may update this policy from time to time. The date at the top shows when it was last changed. Where a change materially affects you, we will let you know by email or through the Platform before it takes effect.

XII. Contact Us

If you have any questions about this policy, or you would like to exercise any of your rights, please contact us: