Notice for individuals whose data we process as controller · Articles 13 and 14 GDPR · Version 4.0, in force from 10 August 2026.
The Polish version is the governing version. Translations are provided for convenience; in the event of divergence between language versions, the Polish wording prevails.
The controller of personal data within the scope of this Policy is LUMINOTE PROSTA SPÓŁKA AKCYJNA, having its registered office in Kraków, ul. Olszańska 7, 31-513 Kraków, Poland, entered in the register of entrepreneurs of the National Court Register under KRS 0001223956, VAT ID 6751824986 ("Luminote", "we").
For any matter concerning personal data, write to privacy@luminote.io. We respond without undue delay and no later than one month from receipt of the request; for particularly complex matters that period may be extended by two months, of which we will inform you together with the reasons.
We have not appointed a data protection officer — none of the conditions in Article 37(1) GDPR applies. The contact point for data protection matters is the address given above; correspondence sent there is handled by the persons responsible for compliance.
This Policy covers processing of personal data in which we determine the purposes and means. It applies to:
The Luminote platform processes the content of meetings, messages and CRM records belonging to our customers. In that respect the customer is the controller — it decided to record the meeting, to connect the CRM and to set the retention period. We act as a processor and solely on its documented instructions.
That processing is governed by the Data Processing Agreement available at luminote.io/legal, not by this Policy.
The practical consequence: if your data appears in Luminote because you attended a meeting with one of our customers, or because you are recorded in its CRM, address any request for access, rectification or erasure to that customer. If you send it to us, we will forward it to the responsible controller without undue delay and inform you that we have done so — we are not entitled to decide about data that is not ours.
The table below states why we process data, on what legal basis and for how long. Bases are given by reference to Article 6(1) GDPR.
| Purpose | Data | Basis | Period |
|---|---|---|---|
| Creating and operating an account, providing the Service | name, business email address, role in the organisation, interface settings, external account identifier where Google/Microsoft sign-in is used | Art. 6(1)(b) — performance of a contract (for a person who concluded it) or (f) — our and the employer's legitimate interest in enabling an employee to use the tool | for the term of the agreement and 30 days after it ends (the window for retrieving data), then erasure |
| Billing, invoicing, debt recovery | company details, address, VAT ID, payment and subscription history | Art. 6(1)(c) — tax and accounting obligations; (f) — pursuit of claims | 5 years from the end of the tax year (Art. 86 §1 of the Polish Tax Ordinance); claim-related data until claims become time-barred |
| Technical support and handling of enquiries | content of correspondence, description of the issue, technical account identifiers | Art. 6(1)(b) and (f) — managing the customer relationship | 24 months from closure of the enquiry |
| Security of the Service, abuse detection, fault diagnosis | access and event logs, IP address in server logs, session identifiers, error messages | Art. 6(1)(f) — ensuring security of processing (Recital 49 GDPR); Art. 32 GDPR | audit trail 30 days, connector technical logs 7–14 days, API call logs 3–7 days |
| Measuring product usage and developing features | usage events linked to an account identifier, without meeting or message content | Art. 6(1)(f) — development and maintenance of the quality of the Service | 90 days |
| Business correspondence and our own marketing | name, business email address, company, contact history | Art. 6(1)(f) — direct marketing; electronic sending only with the consent required by Art. 10 of the Polish Act on Providing Services by Electronic Means and Art. 398 of the Electronic Communications Law | until objection or withdrawal of consent, and no longer than 3 years from the last contact |
| Recording acceptance of the Terms and objections to their amendment | user and organisation identifier, document and version, date | Art. 6(1)(c) and (f) — demonstrating the terms binding the parties | for the term of the agreement and the limitation period for claims |
Where we rely on Article 6(1)(f) GDPR we have carried out a balancing test. We summarise its outcome, because the provision requires the interest to be stated rather than merely cited.
Security and diagnostics. Without access logs there is no way to detect account takeover or to establish who changed a setting and when. We limit the scope to technical identifiers and events; meeting and message content never reaches the logs. Retention periods are short and stated in §4.
Product development. We measure which features are used so that we do not maintain dead ones or break live ones. Events contain no content; we do not build behavioural profiles of individuals and do not combine this data with external sources.
Direct marketing. Recital 47 GDPR expressly recognises direct marketing as a possible legitimate interest. We address it to companies and to individuals acting in a professional capacity, not to consumers. We honour objections immediately and without asking for a reason, and every message carries a working unsubscribe link.
Most often from you: when you create an account, contact us or use the Service.
From your employer or organisation administrator — where the account was created by invitation. In that case we receive an email address and an assigned role, and we provide you with the processing information on first sign-in (Article 14 GDPR).
From an external sign-in provider (Google, Microsoft) if you choose that method — limited to the account identifier, email address and display name. You see the scope of permissions on the provider's consent screen before granting it.
From publicly available sources — strictly limited to contact details of companies and of individuals acting in a professional capacity, for the purposes of business correspondence. On request we will identify the source of specific data.
We entrust data only to providers necessary to deliver the Service, under processing agreements meeting the requirements of Article 28 GDPR. The full, current list is published at luminote.io/legal — below are those who may process data covered by this Policy.
| Provider | Location | Role |
|---|---|---|
| OVH | France | hosting of the entire platform — servers, database, backups |
| MailerSend (MailerLite UAB) | Lithuania | transactional email delivery: confirmations, invitations, notifications |
| AppSignal | Netherlands | application error monitoring — messages and technical identifiers |
| Stripe Payments Europe | Ireland | payment and subscription processing — billing data |
| Google, Microsoft | United States | external account sign-in and calendar synchronisation — only where you enable it yourself |
The rule is that data is stored and processed in the European Union. The entire platform — database, authentication, files, backups — runs on servers in France. Language models and transcription run at a French provider. This is not a marketing statement but a condition of selecting providers.
Two exceptions, both enabled by the user and both optional: sign-in with a Google or Microsoft account and calendar and mail synchronisation with those providers. Transfers take place on the basis of the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914; both providers additionally participate in the Data Privacy Framework.
Stripe Payments Europe Ltd, established in Dublin, processes payments as an EEA entity; its parent company is subject to United States jurisdiction, which is why we treat this entry as a deliberate exception and limit its scope strictly to billing data. Transcripts, CRM records and correspondence content never reach Stripe.
A copy of the safeguards applied to a transfer will be provided on request sent to privacy@luminote.io.
Periods for individual purposes are set out in the table in §4. Beyond those, three principles apply, and we follow them whenever there is doubt.
First: we erase data when the purpose for which we collected it ceases — not when we run out of disk. Erasure is automated and runs daily, not on request.
Second: where different provisions require the same data to be kept for different periods, we apply the longest one, but strictly within the scope that provision covers — the rest is erased on the shorter schedule.
Third: backups have their own, shorter life cycle. Data erased from the production system may persist in a backup for up to 30 days, after which it disappears as the backup is overwritten. We do not restore from backup data that we erased on request.
You have the following rights. Exercising each of them is free of charge, unless a request is manifestly unfounded or excessive — and in that case we will give reasons for refusal rather than stay silent.
Two of them you exercise yourself, in the product, without writing to anyone: under Settings → My privacy you can download all of your data as a JSON file (Art. 20) and delete your account together with your personal data (Art. 17). We consider that the right measure: a right whose exercise requires correspondence is a lesser right.
Send any other request to privacy@luminote.io. We respond within one month. If we cannot identify you from the data we hold, we will ask for additional information — strictly what is necessary for identification, and not in order to discourage the request.
If you consider that we process your data unlawfully, you have the right to lodge a complaint with a supervisory authority. In Poland that is the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw. You may also complain to the authority of your country of habitual residence.
We do not take decisions concerning you based solely on automated processing that would produce legal effects or similarly significantly affect you within the meaning of Article 22(1) GDPR.
The platform contains features built on language models: meeting summaries, deal health scores, next-step suggestions. Their subject is a commercial transaction, not an assessment of a person, and the output is a suggestion to the user, who approves or rejects it. None of these features determines employment, remuneration or any other entitlement of a natural person.
If a customer using the platform chooses to use its output to assess its own employees, that customer is the controller of such processing and bears the obligations under Article 22 GDPR, as well as the obligation to consult employee representatives where national law so requires. §9 of the Terms so provides.
Before content is sent to a language model we remove identifying elements and replace them with placeholders, and we restore them on our side once the response is received. The model provider does not receive data in a form that permits identification of individuals.
We apply technical and organisational measures appropriate to the risk, in accordance with Article 32 GDPR. The principal ones are:
If a breach occurs in respect of personal data for which we are the controller, we will notify the President of the Personal Data Protection Office within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons (Article 33 GDPR).
If the breach is likely to result in a high risk, we will also notify the individuals concerned — without undue delay, in clear language, stating the likely consequences and the measures we have taken (Article 34 GDPR).
For data processed on a customer's instructions we notify the customer as controller, within the time and on the terms set out in the Data Processing Agreement. It is for the customer to decide on notifying the authority and the individuals.
We accept security vulnerability reports at security@luminote.io. Reports made in good faith and without compromising third-party data will not result in legal action on our part.
The Service is a work tool intended for businesses and is not directed at persons under 16 years of age. We do not knowingly collect their data. If we learn that an account was created by a person below that age, we will delete it together with the data.
We may amend this Policy where the scope of processing, the set of providers or the applicable law changes. We give notice of a material amendment at least 30 days in advance, by message to the contact address and by notice in the Service.
Every version carries a number and an effective date stated at the top of the document. Previous versions are available on request — a document that cannot be reproduced as it read on the day of an event is of no use in demonstrating anything.
An amendment to this Policy cannot extend the scope of processing based on your consent. Any such extension requires fresh consent.
Data protection and exercise of rights: privacy@luminote.io.
Contractual and legal matters: legal@luminote.io. Security reports: security@luminote.io. Technical support: support@luminote.io.
Postal address: LUMINOTE PROSTA SPÓŁKA AKCYJNA, ul. Olszańska 7, 31-513 Kraków, Poland.
We publish this document from a single source together with the application. The Polish version governs.