Privacy Policy
Last updated 23 July 2026
Who we are
LumiaChatFlow is operated by AXONLUMIA S.R.L., a company registered in Romania (VAT RO51692062). We are the data controller for the personal data described here, except where this policy says otherwise.
You can reach us via our contact page.
Payments: PayPro Global is our Merchant of Record
Payments for LumiaChatFlow paid plans are processed by PayPro Global Inc. (225 The East Mall, Suite 1117, Toronto, ON, M9B 0A9, Canada), acting as our Merchant of Record. Your contract of sale for the purchase is with PayPro Global, and PayPro Global issues your invoice.
PayPro Global is an independent data controller for order, billing, and payment data — not our processor. Their own privacy policy governs that data: payproglobal.com/privacy-policy.
What we receive from PayPro Global
For each purchase we receive:
- purchaser name
- purchaser email address
- purchaser country
- the plan purchased
- transaction and refund status
We use this to provision your account, provide support, and keep accounting records. Our legal bases are performance of a contract (GDPR Art. 6(1)(b)) for account provisioning and support, and compliance with a legal obligation (GDPR Art. 6(1)(c)) for accounting records.
What we never receive
We never receive or store full card numbers or any payment credentials. Those stay with PayPro Global and its payment partners.
International transfers
PayPro Global's controller entity is Canadian. Canada holds an EU adequacy decision for commercial organizations governed by PIPEDA, so no Standard Contractual Clauses are required for this data flow.
Retention of billing data
Billing and transaction records are retained for as long as applicable accounting law requires (Romanian fiscal retention periods). Everything outside that legal obligation is subject to erasure on request.
Where your data lives
All persistent data is stored in the European Union, in Google Cloud region europe-west1. We do not move persistent customer data to US or other non-EU regions.
We do not train models on your data
We do not train or fine-tune AI models, and customer data is never used for model training. Your content is used to answer your end users' questions through your agents, and for nothing else.
Your data and deletion
We operate GDPR data-erasure workflows. On request, we delete the workspace's tenant data and its encryption keys, which renders any remaining encrypted material unreadable. Erasure requests go through our contact page.
Beyond erasure, you retain your GDPR rights of access, rectification, restriction, objection, and data portability.
Account security and consent controls
The product includes two-factor authentication (2FA), session controls, and consent handling. Email verification is required at signup, and we do not offer social login.
Changes to this policy
Material changes will be reflected on this page with an updated date.