Home Privacy Policy
Data protection

Privacy Policy

Notice for individuals whose data we process as controller · Articles 13 and 14 GDPR · Version 4.0, in force from 10 August 2026.

The Polish version is the governing version. Translations are provided for convenience; in the event of divergence between language versions, the Polish wording prevails.

Przeczytaj ten dokument po polsku  ·  All legal documents

§1

Who processes your data

The controller of personal data within the scope of this Policy is LUMINOTE PROSTA SPÓŁKA AKCYJNA, having its registered office in Kraków, ul. Olszańska 7, 31-513 Kraków, Poland, entered in the register of entrepreneurs of the National Court Register under KRS 0001223956, VAT ID 6751824986 ("Luminote", "we").

For any matter concerning personal data, write to privacy@luminote.io. We respond without undue delay and no later than one month from receipt of the request; for particularly complex matters that period may be extended by two months, of which we will inform you together with the reasons.

We have not appointed a data protection officer — none of the conditions in Article 37(1) GDPR applies. The contact point for data protection matters is the address given above; correspondence sent there is handled by the persons responsible for compliance.

§2

Who this Policy covers

This Policy covers processing of personal data in which we determine the purposes and means. It applies to:

  1. users of the Luminote platform — individuals who create an account or receive one from their employer;
  2. contact persons at our customers and prospective customers — representing the company in contractual, billing or support matters;
  3. visitors to our websites and individuals who contact us via form, email or chat;
  4. individuals reporting security vulnerabilities and individuals sending us data protection requests.
§3

What this Policy does not cover

The Luminote platform processes the content of meetings, messages and CRM records belonging to our customers. In that respect the customer is the controller — it decided to record the meeting, to connect the CRM and to set the retention period. We act as a processor and solely on its documented instructions.

That processing is governed by the Data Processing Agreement available at luminote.io/legal, not by this Policy.

The practical consequence: if your data appears in Luminote because you attended a meeting with one of our customers, or because you are recorded in its CRM, address any request for access, rectification or erasure to that customer. If you send it to us, we will forward it to the responsible controller without undue delay and inform you that we have done so — we are not entitled to decide about data that is not ours.

§4

Purposes, legal bases and retention periods

The table below states why we process data, on what legal basis and for how long. Bases are given by reference to Article 6(1) GDPR.

Purpose Data Basis Period
Creating and operating an account, providing the Service name, business email address, role in the organisation, interface settings, external account identifier where Google/Microsoft sign-in is used Art. 6(1)(b) — performance of a contract (for a person who concluded it) or (f) — our and the employer's legitimate interest in enabling an employee to use the tool for the term of the agreement and 30 days after it ends (the window for retrieving data), then erasure
Billing, invoicing, debt recovery company details, address, VAT ID, payment and subscription history Art. 6(1)(c) — tax and accounting obligations; (f) — pursuit of claims 5 years from the end of the tax year (Art. 86 §1 of the Polish Tax Ordinance); claim-related data until claims become time-barred
Technical support and handling of enquiries content of correspondence, description of the issue, technical account identifiers Art. 6(1)(b) and (f) — managing the customer relationship 24 months from closure of the enquiry
Security of the Service, abuse detection, fault diagnosis access and event logs, IP address in server logs, session identifiers, error messages Art. 6(1)(f) — ensuring security of processing (Recital 49 GDPR); Art. 32 GDPR audit trail 30 days, connector technical logs 7–14 days, API call logs 3–7 days
Measuring product usage and developing features usage events linked to an account identifier, without meeting or message content Art. 6(1)(f) — development and maintenance of the quality of the Service 90 days
Business correspondence and our own marketing name, business email address, company, contact history Art. 6(1)(f) — direct marketing; electronic sending only with the consent required by Art. 10 of the Polish Act on Providing Services by Electronic Means and Art. 398 of the Electronic Communications Law until objection or withdrawal of consent, and no longer than 3 years from the last contact
Recording acceptance of the Terms and objections to their amendment user and organisation identifier, document and version, date Art. 6(1)(c) and (f) — demonstrating the terms binding the parties for the term of the agreement and the limitation period for claims
§5

Legitimate interest

Where we rely on Article 6(1)(f) GDPR we have carried out a balancing test. We summarise its outcome, because the provision requires the interest to be stated rather than merely cited.

Security and diagnostics. Without access logs there is no way to detect account takeover or to establish who changed a setting and when. We limit the scope to technical identifiers and events; meeting and message content never reaches the logs. Retention periods are short and stated in §4.

Product development. We measure which features are used so that we do not maintain dead ones or break live ones. Events contain no content; we do not build behavioural profiles of individuals and do not combine this data with external sources.

Direct marketing. Recital 47 GDPR expressly recognises direct marketing as a possible legitimate interest. We address it to companies and to individuals acting in a professional capacity, not to consumers. We honour objections immediately and without asking for a reason, and every message carries a working unsubscribe link.

§6

Where we obtain your data

Most often from you: when you create an account, contact us or use the Service.

From your employer or organisation administrator — where the account was created by invitation. In that case we receive an email address and an assigned role, and we provide you with the processing information on first sign-in (Article 14 GDPR).

From an external sign-in provider (Google, Microsoft) if you choose that method — limited to the account identifier, email address and display name. You see the scope of permissions on the provider's consent screen before granting it.

From publicly available sources — strictly limited to contact details of companies and of individuals acting in a professional capacity, for the purposes of business correspondence. On request we will identify the source of specific data.

§7

Cookies and similar technologies

We use two categories and only two.

Strictly necessary — maintaining the session after sign-in, protecting forms, remembering the selected language and the sidebar state. Without them the Service does not work, so we store them without consent, on the basis of Article 398(4) of the Electronic Communications Law.

Diagnostic — application error reporting (AppSignal) together with the trail of events preceding a crash. These require consent and do not load before it is given. You can withdraw consent at any time under Settings → My privacy; withdrawal is as easy as granting (Article 7(3) GDPR) and does not affect the lawfulness of processing before withdrawal.

We do not use advertising cookies, cross-site trackers or advertising network pixels. We do not sell data and do not share it with data brokers.

§8

Who we share data with

We entrust data only to providers necessary to deliver the Service, under processing agreements meeting the requirements of Article 28 GDPR. The full, current list is published at luminote.io/legal — below are those who may process data covered by this Policy.

  1. Beyond that, data may be disclosed to bodies authorised under the law — law enforcement, courts, the supervisory authority — solely on a documented request and to the extent we are obliged to disclose it.
  2. In the event of a merger, division or sale of the business, data may pass to the legal successor; we will give advance notice, and where processing is based on legitimate interest you have the right to object.
Provider Location Role
OVH France hosting of the entire platform — servers, database, backups
MailerSend (MailerLite UAB) Lithuania transactional email delivery: confirmations, invitations, notifications
AppSignal Netherlands application error monitoring — messages and technical identifiers
Stripe Payments Europe Ireland payment and subscription processing — billing data
Google, Microsoft United States external account sign-in and calendar synchronisation — only where you enable it yourself
§9

Transfers outside the European Economic Area

The rule is that data is stored and processed in the European Union. The entire platform — database, authentication, files, backups — runs on servers in France. Language models and transcription run at a French provider. This is not a marketing statement but a condition of selecting providers.

Two exceptions, both enabled by the user and both optional: sign-in with a Google or Microsoft account and calendar and mail synchronisation with those providers. Transfers take place on the basis of the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914; both providers additionally participate in the Data Privacy Framework.

Stripe Payments Europe Ltd, established in Dublin, processes payments as an EEA entity; its parent company is subject to United States jurisdiction, which is why we treat this entry as a deliberate exception and limit its scope strictly to billing data. Transcripts, CRM records and correspondence content never reach Stripe.

A copy of the safeguards applied to a transfer will be provided on request sent to privacy@luminote.io.

§10

How long we keep data

Periods for individual purposes are set out in the table in §4. Beyond those, three principles apply, and we follow them whenever there is doubt.

First: we erase data when the purpose for which we collected it ceases — not when we run out of disk. Erasure is automated and runs daily, not on request.

Second: where different provisions require the same data to be kept for different periods, we apply the longest one, but strictly within the scope that provision covers — the rest is erased on the shorter schedule.

Third: backups have their own, shorter life cycle. Data erased from the production system may persist in a backup for up to 30 days, after which it disappears as the backup is overwritten. We do not restore from backup data that we erased on request.

§11

Your rights

You have the following rights. Exercising each of them is free of charge, unless a request is manifestly unfounded or excessive — and in that case we will give reasons for refusal rather than stay silent.

  1. Access (Art. 15) — confirmation whether we process your data, and a copy of that data.
  2. Rectification (Art. 16) — correction of inaccurate data and completion of incomplete data.
  3. Erasure (Art. 17) — erasure where the purpose has ceased, consent has been withdrawn or an effective objection has been raised.
  4. Restriction (Art. 18) — suspension of processing while the accuracy of the data or the merits of an objection are in dispute.
  5. Portability (Art. 20) — receipt of data in a machine-readable format, where processing is based on a contract or consent and is carried out by automated means.
  6. Objection (Art. 21) — against processing based on legitimate interest; against direct marketing the objection is unconditional and we honour it immediately.
  7. Withdrawal of consent (Art. 7(3)) — at any time, without affecting the lawfulness of processing before withdrawal.
§12

How to exercise those rights

Two of them you exercise yourself, in the product, without writing to anyone: under Settings → My privacy you can download all of your data as a JSON file (Art. 20) and delete your account together with your personal data (Art. 17). We consider that the right measure: a right whose exercise requires correspondence is a lesser right.

Send any other request to privacy@luminote.io. We respond within one month. If we cannot identify you from the data we hold, we will ask for additional information — strictly what is necessary for identification, and not in order to discourage the request.

If you consider that we process your data unlawfully, you have the right to lodge a complaint with a supervisory authority. In Poland that is the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw. You may also complain to the authority of your country of habitual residence.

§13

Automated decisions and profiling

We do not take decisions concerning you based solely on automated processing that would produce legal effects or similarly significantly affect you within the meaning of Article 22(1) GDPR.

The platform contains features built on language models: meeting summaries, deal health scores, next-step suggestions. Their subject is a commercial transaction, not an assessment of a person, and the output is a suggestion to the user, who approves or rejects it. None of these features determines employment, remuneration or any other entitlement of a natural person.

If a customer using the platform chooses to use its output to assess its own employees, that customer is the controller of such processing and bears the obligations under Article 22 GDPR, as well as the obligation to consult employee representatives where national law so requires. §9 of the Terms so provides.

Before content is sent to a language model we remove identifying elements and replace them with placeholders, and we restore them on our side once the response is received. The model provider does not receive data in a form that permits identification of individuals.

§14

Security

We apply technical and organisational measures appropriate to the risk, in accordance with Article 32 GDPR. The principal ones are:

  1. encryption in transit (TLS 1.2 or later) and encryption at rest, including credentials to external systems;
  2. isolation of data between organisations enforced at the database level, not merely in application code;
  3. role-based access control and two-factor authentication for administrative accounts;
  4. logging of security-relevant events, without writing meeting or message content into the logs;
  5. backups with regularly tested restoration;
  6. review of provider and internal permissions whenever the scope of processing changes.
§15

Personal data breaches

If a breach occurs in respect of personal data for which we are the controller, we will notify the President of the Personal Data Protection Office within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons (Article 33 GDPR).

If the breach is likely to result in a high risk, we will also notify the individuals concerned — without undue delay, in clear language, stating the likely consequences and the measures we have taken (Article 34 GDPR).

For data processed on a customer's instructions we notify the customer as controller, within the time and on the terms set out in the Data Processing Agreement. It is for the customer to decide on notifying the authority and the individuals.

We accept security vulnerability reports at security@luminote.io. Reports made in good faith and without compromising third-party data will not result in legal action on our part.

§16

Children

The Service is a work tool intended for businesses and is not directed at persons under 16 years of age. We do not knowingly collect their data. If we learn that an account was created by a person below that age, we will delete it together with the data.

§17

Changes to this Policy

We may amend this Policy where the scope of processing, the set of providers or the applicable law changes. We give notice of a material amendment at least 30 days in advance, by message to the contact address and by notice in the Service.

Every version carries a number and an effective date stated at the top of the document. Previous versions are available on request — a document that cannot be reproduced as it read on the day of an event is of no use in demonstrating anything.

An amendment to this Policy cannot extend the scope of processing based on your consent. Any such extension requires fresh consent.

§18

Contact

Data protection and exercise of rights: privacy@luminote.io.

Contractual and legal matters: legal@luminote.io. Security reports: security@luminote.io. Technical support: support@luminote.io.

Postal address: LUMINOTE PROSTA SPÓŁKA AKCYJNA, ul. Olszańska 7, 31-513 Kraków, Poland.

LUMINOTE PROSTA SPÓŁKA AKCYJNA ul. Olszańska 7, 31-513 Kraków, Polska
KRS: 0001223956 · NIP: 6751824986
Questions about this document: legal@luminote.io

We publish this document from a single source together with the application. The Polish version governs.