LumiaChatFlow
FeaturesPricingSign inGet Started

Privacy Policy

Version 1.0 · 6 August 2026

This policy explains what personal data we handle when you use LumiaChatFlow, why, and what rights you have.

1. Who we are

LumiaChatFlow is operated by AXONLUMIA S.R.L., Strada Rezervelor nr. 87, Sat Roșu, Comuna Chiajna, Ilfov 077042, Romania (trade register J2025029825009, VAT RO51692062). Full details are on our Imprint.

Contact for privacy matters: support@lumiachatflow.com. Marking your message "Data Protection Request" helps us route it faster, but is not required — we act on any request however it reaches us.

We have not appointed a Data Protection Officer; we are not required to.

2. Two different roles — please read this first

Which parts of this policy apply depends on who you are.

If you are our customer — you signed up, you build agents — we are the controller for your account and workspace data. This policy governs that.

If you are a visitor chatting with an agent on someone else's website, that business decides why your messages are collected. They are the controller and we are their processor. Ask them for their privacy notice; our DPA governs what we may do with your data, and we act only on their instructions.

3. What we process, and why

3.1 Account and workspace data

Name, email address, password credentials (hashed by our authentication provider), workspace and team membership, and security settings such as two-factor enrolment and active sessions.

Why: to create and run your account, authenticate you, and secure it. Legal basis: performance of our contract with you (Art. 6(1)(b)); our legitimate interest in securing the service (Art. 6(1)(f)) for security logging.

3.2 Content you bring

Pages we crawl from the websites you nominate, files you upload, and the agent configuration you create.

Why: to build and run your agents. Legal basis: performance of our contract with you (Art. 6(1)(b)). Where that content contains other people's personal data, you are responsible for having a lawful basis, and our DPA applies.

3.3 Conversations

Messages sent to your agents, the responses generated, and technical data needed to deliver them — including the visitor's IP address.

Why: to answer questions through your agents, and to meter usage. Legal basis: our contract with you; for end-visitor data, the basis is yours as controller.

3.4 Billing data

Received from PayPro Global, not collected by us: purchaser name, email address, country, company name and fiscal identification number where you supply them for tax or invoicing purposes, the plan bought, transaction and refund status, the purchaser's IP address, and limited card metadata used to identify a payment — the issuing-range and last four digits, and the expiry date. See section 5.

Why: to provision your plan, support you, and keep accounting records. Legal basis: performance of a contract (Art. 6(1)(b)); compliance with a legal obligation (Art. 6(1)(c)) for accounting records.

3.5 Support correspondence

What you send us when you ask for help. Legal basis: our contract with you, and our legitimate interest in running support.

3.6 Marketing communications

If you opt in at sign-up (or later), we use your email address to send you product news and marketing messages. Legal basis: your consent (Art. 6(1)(a)). You can withdraw it at any time — every message includes a way to unsubscribe, and withdrawing never affects your account or the service.

3.7 What you must provide, and what happens if you don't

Your name, email address and credentials are required to create an account — without them we cannot provide the service, and we cannot create one for you. Billing details are required by PayPro Global to complete a purchase. Everything else — two-factor enrolment, the content you index, marketing consent — is optional, and declining it only limits the corresponding feature. Marketing consent can be withdrawn at any time without affecting your account.

4. What we do not do

  • We do not train or fine-tune AI models on your data. Your content is used to answer questions through your agents, and for nothing else. Our AI providers are contractually bound not to use paid-tier content to improve their models.
  • We do not sell or rent personal data.
  • We do not use advertising or cross-site tracking.
  • We do not make decisions producing legal or similarly significant effects about you by automated means (GDPR Art. 22). Agents generate text; they do not decide anything about you.

5. Payments — PayPro Global is our Merchant of Record

Paid plans are sold by PayPro Global Inc. (225 The East Mall, Suite 1117, Toronto, ON, M9B 0A9, Canada), acting as our authorized reseller and Merchant of Record. Your contract of sale is with PayPro Global and PayPro Global issues your invoice.

PayPro Global is an independent data controller for order, billing and payment data — not our processor. Their own privacy policy governs that data: https://payproglobal.com/privacy-policy/.

We never receive or store your full card number, and we never handle your payment credentials — those stay with PayPro Global and its payment partners. What we do receive is listed in section 3.4, and it includes limited card metadata (issuing range, last four digits, expiry) that identifies a payment without being usable to make one.

PayPro Global's controller entity is Canadian. Canada holds an EU adequacy decision for commercial organizations governed by PIPEDA, so no Standard Contractual Clauses are required for this flow.

6. Where your data is stored

Our own infrastructure is in the European Union. Your account, workspace, agent configuration, conversation records and backups are stored in Google Cloud region europe-west1 (Belgium), with per-tenant encryption keys held in Google Cloud KMS.

The AI search and generation layer is different, and we want to be straightforward about it. To let your agents answer from your content, that content is indexed by Google's Gemini API, which stores the resulting search index on Google's infrastructure — and each conversation turn (the visitor's message, relevant excerpts of your content, and the generated reply) is sent to the same Google service to produce the response. Google does not offer a regional guarantee for this service, and its terms permit storage in any country where Google or its agents maintain facilities. So while we control where our systems keep your data, we cannot promise that the search index for your content — or the conversation traffic processed to generate replies — stays inside the EU.

Google remains bound by its data-protection commitments as our processor, and by the no-training terms in section 4. Where this involves a transfer outside the EEA, it is covered by Google's data-processing terms and the transfer safeguards in them, including Standard Contractual Clauses where those apply. You can ask us for a copy of, or a reference to, the safeguards relied on by contacting us at the address in section 1.

7. Who else processes your data

Our current sub-processors, what each does, and where, are listed at /sub-processors. We will give at least 30 days' notice before adding a new sub-processor with material access to customer personal data.

8. How long we keep it

DataRetention
Account and workspace dataWhile your account is active
Content you index, and agent configurationUntil you delete it, or your account is deleted
Conversation recordsUntil your workspace or account is deleted. Per-conversation deletion is not yet available in the product; a 12-month automatic retention limit is planned
Billing and transaction recordsAs long as Romanian accounting law requires
Support correspondenceFor as long as needed to resolve your request, then per our general records practice
Security and audit logsTiered by event severity, up to statutory limits
Deleted accountsRemoved after the grace period in section 9; deletion records retained as proof of erasure

Anything held only under a legal obligation is retained for that period and then deleted.

9. Deleting your account and your data

You can delete your account yourself from Settings → Privacy & GDPR. Deletion runs after a 30-day grace period, during which you can restore the account. After that it is permanent.

Erasure removes your tenant data and its encryption keys, which renders any remaining encrypted material unreadable, and purges the search index built from your content.

10. Your rights

You may request access to your data, correction, erasure, restriction of processing, or portability, and you may object to processing based on legitimate interests. Where processing rests on consent, you may withdraw it at any time without affecting prior processing.

The fastest route for access and erasure is Settings → Privacy & GDPR, which provides data export and account deletion directly. Otherwise contact us at the address in section 1. We respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extension.

You have the right to complain to a supervisory authority. Ours is:

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, Romania — https://www.dataprotection.ro/

You may also complain to the authority where you live or work.

11. Cookies and browser storage

We set no cookies — not on the marketing site, not in the app, not in the chat widget.

The application stores a small amount of data in your browser so it can function:

KeyWherePurpose
themelocalStorageRemembers light or dark mode
firebase:authUser:…localStorage or sessionStorageKeeps you signed in; sessionStorage when "remember me" is off
lcf_pending_invitesessionStorageCarries a workspace invitation through sign-up
mfa_nudge_dismissedsessionStorageRemembers you dismissed the two-factor prompt
usage_alert_dismissed_…localStorageRemembers you dismissed a usage warning

These are strictly necessary to provide a service you asked for, so no consent banner is required. You can clear them through your browser at any time; you will be signed out.

The chat widget stores nothing at all — no cookies, no localStorage, no sessionStorage. A conversation does not survive a page reload.

12. Children

LumiaChatFlow is a business service and is not directed at children. We do not knowingly collect personal data from anyone under 18. Our Acceptable Use Policy prohibits customers from deploying agents aimed at minors. If you believe a child has given us personal data, contact us and we will delete it.

13. Security

We use TLS in transit and per-tenant envelope encryption at rest (AES-256-GCM data keys wrapped by Google Cloud KMS). Access is role-based, tenant data is isolated, and security events are logged. See our Security page for more, and to report a vulnerability.

14. Changes

We will update this page when our practices change, and revise the date at the top. If a change is material we will tell you by email or in the product at least 30 days before it takes effect, in line with the change process in our Terms of Service §14.

LumiaChatFlow

AI-powered chatbot platform for businesses. GDPR-compliant and privacy-first.

A product by AxonLumia

Product

  • Features
  • Pricing

Company

  • About AxonLumia
  • Contact
  • LinkedIn

Legal

  • Privacy Policy
  • Terms of Service
  • Refund Policy
  • Acceptable Use
  • DPA
  • Imprint
  • Security
  • Sub-processors
  • Widget Visitor Notice
AxonLumia

© 2026 AxonLumia. All rights reserved.

LumiaChatFlow is a registered trademark.