GDPR check

Is Litmaps GDPR compliant? What universities should check

Litmaps is a literature discovery and citation-mapping tool from Wellington, New Zealand, popular with doctoral students and research groups for building and monitoring literature maps. This page sets out what Litmap Limited publicly documents about data protection and what a university should check before licensing it.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

Litmaps is run by Litmap Limited, a company registered in Wellington, New Zealand, a country the European Commission recognises as providing adequate protection. Litmaps publishes a privacy policy, a Data Processing Addendum and a subprocessor list, all last modified on 23 June 2026. The DPA makes Litmaps a processor for customer data, with a 48-hour breach notice, a 14-day objection right for new subprocessors and deletion within 30 days after the contract ends. The application is hosted in the United States on Microsoft Azure and AWS, under SCCs and the UK Addendum. Litmaps works from citation data rather than generative AI, so the questions are mostly the classic ones: hosting, analytics and retention. We found no security certification in public documentation.

Prefer a tool built in the EU? Kahubi, from Avidemic AB in Sweden, covers AI research assistance with EU hosting and, for institutions, only European subprocessors. See how Kahubi handles research data

What Litmaps documents publicly

All sources were read on 7 October 2026. "Not found publicly" means we did not find it in the sources listed; it does not mean the safeguard does not exist.

TopicWhat the vendor statesSource
Company and establishmentDocumented Litmap Limited (New Zealand company number 6019409), Level 5, Rutherford House, 33 Bunny Street, Pipitea, Wellington, operates litmaps.com. The privacy policy refers to the New Zealand Privacy Act 2020 and the GDPR. The DPA gives privacy@litmaps.com as the data protection contact. The website terms are governed by New Zealand law. Not found publicly A named DPO or an EU representative.[1], [2], [4]
Where data is stored and processedDocumented The DPA says the platform is hosted in the United States. The subprocessor list gives the US for Microsoft Azure (application, database, cache, storage, logging) and AWS (identity and authentication, transactional email, file storage).[2], [3]
Data processing agreementDocumented A public Data Processing Addendum (last modified 23 June 2026) between Litmap Limited as processor and the customer as controller. It covers researchers, students, academic staff and customer personnel, and includes security measures in an annex. It says it forms part of the Terms of Service.[2]
SubprocessorsDocumented Seven named subprocessors: AWS, Microsoft Azure, Intercom (support), Mixpanel (product analytics) and Stripe (payments) in the US; Brevo (marketing email, France) and Hotjar (session replay with text fields masked, Malta) in the EEA. Customers may object to a new subprocessor within 14 days; if no solution is found within 30 days, they may suspend or terminate the affected service. Public metadata sources such as Semantic Scholar, OpenAlex, ORCID and LibKey receive search terms and identifiers such as DOIs, not personal data, according to Litmaps.[3], [2]
International transfersDocumented New Zealand has an EU adequacy decision, so transfers from the EEA to Litmaps itself need no further safeguard. Transfers to US subprocessors rely on the 2021 SCCs and the UK International Data Transfer Addendum, "together with supplementary technical measures", according to the DPA. New Zealand appears on the European Commission's adequacy list.[1], [2], [9]
AI model training on customer contentNot found publicly A generative AI feature or any statement on training AI models with user content. Litmaps describes its search as based on citations and references. The privacy policy says aggregate, de-identified information may be used for research and statistics to improve its services.[5], [1]
Retention and deletionPartly documented Personal data is kept as long as reasonably necessary, without fixed periods. Under the DPA, account deletion removes the user record and associated workspaces, maps, collections, searches, documents and notes, with backup copies purged on the normal backup cycle; data is deleted or returned within 30 days after the agreement ends. The DPA notes that self-service data export is not yet automated; export is provided on request.[1], [2]
Security certificationsNot found publicly ISO 27001, SOC 2 or a similar certification. The DPA lists technical measures: TLS in transit, encryption at rest through the cloud providers, bcrypt-hashed passwords, AWS Cognito authentication, role-based access, an isolated Azure network and regular backups. Breaches are notified within 48 hours.[2]
Institution and enterprise controlsPlan-dependent Free and Pro plans for individuals (Pro listed at $10 per month, with education pricing requiring an academic email address), Team plans, and institutional licensing through sales. Sign-in options include Google and ORCID. Not found publicly SAML single sign-on or an admin console for institutions.[6], [7], [1]

What this means for a university

Validemic's analysis

Limited personal data, clearly described. Litmaps processes account details, academic status, the papers and maps a user saves, notes, and usage data [1]. That is modest compared with tools that ingest manuscripts or interview data. The main sensitive element is research direction: a map of saved papers shows what a doctoral student or research group is working on, which matters for unpublished work but is rarely special category data.

Adequacy covers Litmaps, SCCs cover the hosting. New Zealand's adequacy decision [9] makes the first transfer simple under Article 45 GDPR [8], but the application itself runs on US infrastructure [2], [3]. The university's transfer assessment therefore rests on the SCCs between Litmaps and its US subprocessors. Microsoft, AWS and Stripe are widely assessed providers, and many DPOs will already have positions on them.

Analytics and session replay. Mixpanel, Hotjar session recordings (with text fields masked) and website tools such as Google Analytics are listed [1], [3]. For an institutional licence, ask which of these run inside the logged-in app and whether they can be limited for the university's users.

Paperwork is ahead of many peers. A public DPA with a 48-hour breach notice, a 14-day objection right and a cascading deletion procedure, and a subprocessor list that names the transfer safeguard for each entry, is more than many research tools of this size publish. The DPA says it forms part of the Terms of Service, while the public terms on the website are website terms dated 2024 [4]; an institutional contract should state which agreement the DPA attaches to.

Individual versus institutional use. Students on Free or Pro accounts use Litmaps under its privacy policy. A university that pays for licences, or requires Litmaps in a course, should do so under the DPA so that it can give instructions and rely on the processor terms that Article 28 GDPR requires [8].

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Questions to ask Litmaps before approving it

  1. Which agreement does the DPA attach to for an institutional licence, and can it be signed as a separate document?
  2. Is EU hosting available, or can the Azure deployment be moved to an EU region for institutional customers?
  3. Which analytics and session-replay tools run inside the logged-in application, and can they be disabled for our users?
  4. Do you have, or plan, an independent security certification or a HECVAT, and can we see a recent penetration test summary?
  5. Can you offer SAML single sign-on and central account management for an institution?
  6. How long are account data, maps and logs kept for inactive users, and how quickly are backups purged after deletion?
  7. When will self-service data export be available for users who leave the university?

The EU AI Act angle

Citation-based literature discovery is not among the high-risk uses in Annex III of the AI Act, Regulation (EU) 2024/1689 [10]. Point 3 of that annex covers AI used to decide admission, evaluate learning outcomes, assess the level of education a person will receive, or monitor students during tests. Whether Litmaps' recommendation algorithms count as an AI system under Article 3(1) depends on how they work; either way, research support of this kind would not be high-risk.

For any AI tools it deploys, a university has had AI literacy duties under Article 4 since 2 February 2025. Regulation (EU) 2026/1744 (the Digital Omnibus on AI), in force since 27 July 2026, turned these into a duty to take measures to support AI literacy and moved the Annex III high-risk rules to 2 December 2027 [11].

Sources

  1. Litmaps, Privacy Policy (last modified 23 June 2026), retrieved 7 October 2026
  2. Litmaps, Data Processing Addendum (last modified 23 June 2026), retrieved 7 October 2026
  3. Litmaps, Subprocessors (last modified 23 June 2026), retrieved 7 October 2026
  4. Litmaps, Terms and Conditions (last modified 10 June 2024), retrieved 7 October 2026
  5. Litmaps, Features, retrieved 7 October 2026
  6. Litmaps, Pricing, retrieved 7 October 2026
  7. Litmaps, Litmaps for Institutions, retrieved 7 October 2026
  8. Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 28 and 45, retrieved 7 October 2026
  9. European Commission, Adequacy decisions (New Zealand listed), retrieved 7 October 2026
  10. Regulation (EU) 2024/1689 (Artificial Intelligence Act), Articles 3, 4 and 113 and Annex III, Official Journal text read via the Publications Office, retrieved 7 October 2026
  11. Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal text read via the Publications Office, retrieved 7 October 2026

About this page

We read Litmaps' privacy policy, Data Processing Addendum, subprocessor list, terms, features, pricing and institutions pages, the European Commission's adequacy list and the EU legal texts on 7 October 2026. We did not test the product or review any non-public contract. This page is not legal advice and not a verdict on whether Litmaps or any university's use of it complies with the GDPR; that depends on your plan, your contract and your use.

If you work at Litmaps and something here is out of date or incomplete, please contact us and we will review it promptly.

Frequently asked questions

Where is Litmaps data stored?

Litmaps' DPA says the platform is hosted in the United States, and its subprocessor list gives the US as the location for Microsoft Azure (application, database and storage) and Amazon Web Services (authentication, email and file storage). Litmaps says these transfers rely on the EU Standard Contractual Clauses and the UK Addendum (checked 7 October 2026).

Is New Zealand adequate under the GDPR?

Yes. New Zealand is on the European Commission's list of countries with an adequacy decision, so transfers from the EEA to Litmap Limited itself need no additional safeguard. Transfers onwards to US subprocessors are a separate step, covered in Litmaps' case by SCCs.

Does Litmaps sign a DPA?

Litmaps publishes a Data Processing Addendum (last modified 23 June 2026) in which the customer is controller and Litmaps is processor. It includes a 14-day objection right for new subprocessors, breach notification within 48 hours and deletion or return within 30 days after the agreement ends.

Does Litmaps use AI or train models on my data?

Litmaps describes its search as based on citations and references. We found no generative AI feature and no statement about training AI models on user content in its public documentation (checked 7 October 2026). The privacy policy says aggregate, de-identified information may be used for research and statistics to improve its services.

Is there an institutional Litmaps licence?

Yes. Litmaps offers discounted education pricing for individuals with an academic email address, Team plans, and institution-wide licensing through its sales team. The DPA is written for a customer entity, so an institutional licence is the natural place to sign it.