Privacy Policy
Last updated: October 7, 2025
1. Introduction
Welcome to Lumsi.io (“we,” “our,” or “us”). We are committed to protecting your personal data and respecting your privacy rights. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.
This policy is designed to comply with the General Data Protection Regulation (GDPR) and other applicable European data protection laws.
2. Data Controller
Lumsi.io
Dublin
Ireland
Email: privacy@lumsi.io
Website: https://lumsi.io
3. Information We Collect
3.1 Personal Data You Provide
We collect personal data that you voluntarily provide to us when you:
- Register for an account
- Use our services
- Contact us for support
- Subscribe to our newsletter
- Participate in surveys or promotions
This may include:
- Identity Data: name, username, title
- Contact Data: email address, telephone number, postal address
- Account Data: username, password, and other security credentials
- Financial Data: payment card details, billing address
- Transaction Data: details about payments and services you have purchased
- Profile Data: preferences, feedback, survey responses
- Marketing Data: your preferences for receiving marketing communications
3.2 Information Automatically Collected
When you access our services, we automatically collect:
- Technical Data: IP address, browser type and version, time zone setting, browser plug-in types, operating system and platform
- Usage Data: information about how you use our website and services
- Location Data: general location inferred from your IP address
- Cookie Data: information collected through cookies and similar technologies (see our Cookie Policy)
3.3 Information from Third Parties
We may receive personal data about you from:
- Analytics providers
- Advertising networks
- Payment and delivery service providers
- Publicly available sources
4. Legal Basis for Processing
We process your personal data under the following legal bases:
4.1 Contractual Necessity
Processing necessary to perform our contract with you or to take steps before entering into a contract.
4.2 Legitimate Interests
Processing necessary for our legitimate interests, including:
- Improving our services
- Detecting and preventing fraud
- Network and information security
- Internal administration
- Marketing and business development
4.3 Legal Obligation
Processing necessary to comply with legal obligations under EU or Member State law.
4.4 Consent
Where you have given explicit consent for specific processing activities, such as:
- Marketing communications
- Use of non-essential cookies
- Special categories of personal data (if applicable)
You may withdraw your consent at any time by contacting us.
5. How We Use Your Information
5.1 Service Delivery
- To provide, maintain, and improve our services
- To create and manage your account
- To process transactions and send related information
- To provide customer support
5.2 Communication
- To send administrative information, updates, and security alerts
- To respond to your inquiries and requests
- To send newsletters and marketing communications (with your consent)
5.3 Business Operations
- To monitor and analyze usage trends
- To detect, prevent, and address technical issues and security threats
- To enforce our terms and conditions
- To comply with legal obligations
5.4 Improvement and Development
- To develop new products and services
- To conduct research and analysis
- To personalize user experience
6. Data Sharing and Disclosure
We do not sell your personal data. We may share your information with:
6.1 Service Providers
Third-party vendors who perform services on our behalf, including:
- Hosting and infrastructure providers
- Payment processors
- Analytics services
- Customer support tools
- Marketing platforms
6.2 Business Transfers
In connection with any merger, sale of company assets, financing, or acquisition of all or part of our business.
6.3 Legal Requirements
When required by law, court order, or governmental authority, or to:
- Comply with legal processes
- Enforce our agreements
- Protect our rights, property, or safety
- Protect the rights, property, or safety of others
6.4 With Your Consent
When you have given explicit consent for specific disclosures.
7. International Data Transfers
We are based in Europe. If we transfer your personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses: approved by the European Commission
- Adequacy Decisions: transfers to countries deemed to provide adequate protection
- Binding Corporate Rules: for intra-group transfers
- Your Explicit Consent: where applicable
8. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
Retention Periods:
- Account Data: retained while your account is active and for 2 years after account closure
- Transaction Data: retained for 7 years for accounting and tax purposes
- Marketing Data: retained until you withdraw consent or for 12 months of inactivity
- Technical and Usage Data: typically retained for 12 months to 2 years
When personal data is no longer needed, we will securely delete or anonymize it.
9. Your Rights Under GDPR
As a data subject in the EU, you have the following rights:
9.1 Right of Access
You have the right to request copies of your personal data.
9.2 Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data.
9.3 Right to Erasure (Right to be Forgotten)
You have the right to request deletion of your personal data under certain circumstances.
9.4 Right to Restriction of Processing
You have the right to request restriction of processing your personal data under certain conditions.
9.5 Right to Data Portability
You have the right to request transfer of your data to another organization or directly to you.
9.6 Right to Object
You have the right to object to our processing of your personal data, including for direct marketing purposes.
9.7 Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal or similarly significant effects.
9.8 Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw consent at any time.
9.9 Right to Lodge a Complaint
You have the right to lodge a complaint with your local supervisory authority if you believe we have violated data protection laws.
To exercise these rights, please contact us at: privacy@lumsi.io
We will respond to your request within one month, though this may be extended by two additional months for complex requests.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption of data in transit and at rest
- Regular security assessments and penetration testing
- Access controls and authentication mechanisms
- Employee training on data protection
- Incident response procedures
- Regular backups and disaster recovery plans
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your personal data, we cannot guarantee absolute security.
11. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to collect and track information. For detailed information about the cookies we use and your choices, please see our Cookie Policy.
- Essential Cookies: necessary for the website to function
- Analytics Cookies: help us understand how visitors use our site
- Marketing Cookies: track visitors across websites for advertising purposes
You can control cookies through your browser settings and our cookie consent tool.
12. Third-Party Links
Our services may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to read their privacy policies.
13. Children’s Privacy
Our services are not intended for individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16, we will take steps to delete such information.
14. Marketing Communications
With your consent, we may send you marketing communications about our products and services. You can opt out at any time by:
- Clicking the “unsubscribe” link in any marketing email
- Adjusting your account preferences
- Contacting us at privacy@lumsi.io
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new Privacy Policy on this page
- Updating the “Last Updated” date
- Sending you an email notification (for significant changes)
We encourage you to review this Privacy Policy periodically.
16. Data Protection Officer
If you have questions about this Privacy Policy or our data practices, you may contact our Data Protection Officer:
Data Protection Officer
Email: dpo@lumsi.io
17. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Lumsi.io
Email: privacy@lumsi.io
18. Supervisory Authority
You have the right to lodge a complaint with your local data protection supervisory authority. A list of EU supervisory authorities can be found at: https://edpb.europa.eu/about-edpb/board/members_en