PRIVACY POLICY
PART I INTRODUCTION, SCOPE, DEFINITIONS, AND ROLES
Effective 17th July, 2026
INTRODUCTION
Lumenci, Inc. and its affiliates ("Lumenci," "we," "our," or "us") respect your privacy and are committed to protecting Personal Data entrusted to us. This Privacy Policy explains how Lumenci collects, uses, stores, transfers, discloses, and otherwise processes Personal Data through the iLumos platform and related services. iLumos is an artificial-intelligence-enabled intellectual property intelligence platform that assists enterprise users with patent portfolio analysis, infringement assessment, patent validity review, damages estimation, portfolio prioritization, natural-language portfolio exploration, and related intellectual property analytics. This Privacy Policy applies to: • the iLumos platform; • Lumenci websites that link to this Privacy Policy; • customer accounts and workspaces; • communications between Lumenci and users; • AI-powered services and analysis features offered through iLumos; and • any related services, support offerings, integrations, or professional services provided by Lumenci. This Privacy Policy does not apply to third-party websites, services, or platforms that may be linked from or integrated with iLumos. Such services are governed by their own privacy policies and terms.
2. IMPORTANT NOTICE REGARDING AI-POWERED SERVICES
iLumos incorporates artificial intelligence technologies, including large language models and machine-learning systems provided by Lumenci and third-party AI providers. These technologies assist in generating:
patent infringement analyses;
patent validity assessments;
damages estimations;
litigation and licensing prioritization recommendations;
evidence summaries;
claim-coverage analyses;
portfolio intelligence reports;
natural-language responses to user queries; and
other analytical outputs.
The outputs generated by iLumos are intended solely as decision-support tools.
They:
do not constitute legal advice;
do not constitute professional advice;
do not create an attorney-client relationship;
do not replace independent legal review; and
should not be relied upon as the sole basis for legal, commercial, licensing, litigation, or investment decisions.
Users remain responsible for evaluating and validating all outputs generated by the platform.
WHO THIS PRIVACY POLICY APPLIES TO
Depending on how you interact with iLumos, references to "you" may include:
3.1 Workspace Users
Individuals who access iLumos through an organization account, including:
• attorneys;
• in-house counsel;
• patent analysts;
• licensing professionals;
• portfolio managers;
• consultants;
• support personnel; and
• other authorized users.
3.2 Organization Administrators
Individuals responsible for administering a customer workspace, managing user permissions, subscriptions, and organizational settings.
3.3 Visitors
Individuals who visit Lumenci websites, attend events, communicate with Lumenci, request information, or otherwise interact with Lumenci without accessing an iLumos workspace.
3.4 Customer Representatives
Individuals acting on behalf of prospective, current, or former customers, including procurement personnel, legal representatives, privacy officers, and authorized contacts.
SCOPE OF PROCESSING
Lumenci processes information relating to:
customer account administration;
authentication and identity verification;
workspace administration;
patent portfolio analysis;
AI-assisted processing;
billing and subscription management;
customer support;
platform security;
compliance and legal obligations;
service improvement; and
fraud prevention and abuse detection.
The categories of information processed and the purposes of processing are described in subsequent sections of this Privacy Policy.
DEFINITIONS
For purposes of this Privacy Policy:
"Personal Data"
means any information relating to an identified or identifiable natural person, including information that directly or indirectly identifies an individual. Depending on applicable law, Personal Data may also be referred to as:
personal information;
personal data;
consumer information; or
personally identifiable information.
"Customer Data"
means information submitted to, uploaded to, generated through, or processed by iLumos on behalf of a customer.
Customer Data includes:
patent portfolios;
patent identifiers;
claims;
patent specifications;
company identifiers;
analysis parameters;
prompts;
chat submissions;
reports; and
generated analytical outputs.
"Patent Data"
means patent-related information processed through iLumos, including:
patent numbers;
applications;
patent claims;
specifications;
abstracts;
prosecution materials;
prior-art references;
citations; and
related intellectual property records.
"AI Output"
means content generated by an artificial intelligence model or AI-powered functionality made available through iLumos.
Examples include:
recommendations;
summaries;
infringement findings;
damages estimates;
prioritization rankings;
explanations;
evidence summaries; and
generated reports.
"Workspace"
means a dedicated organizational environment within iLumos through which authorized users access and manage Customer Data.
"Organization"
means the legal entity that subscribes to or otherwise uses iLumos.
"Subprocessor"
means a third-party service provider engaged by Lumenci to process Personal Data on Lumenci's behalf in connection with providing the Services.
"AI Provider"
means a third-party provider of artificial intelligence, machine learning, or large language model technologies utilized by Lumenci in connection with the Services.
"Services"
means iLumos, related software applications, APIs, support services,professional services, websites, communications, and associated offerings provided by Lumenci.
DATA CONTROLLER AND DATA PROCESSOR ROLES
The role Lumenci assumes depends on the nature of the processing activity.
6.1 When Lumenci Acts as a Data Controller
Lumenci acts as a data controller (or equivalent legal concept under applicable law) when Lumenci determines the purposes and means of processing Personal Data.
Examples include:
account registration;
user authentication;
subscription management;
billing administration;
security monitoring;
fraud prevention;
compliance activities;
marketing communications;
customer relationship management;
product analytics; and
legal and regulatory compliance.
In these situations, Lumenci determines how and why Personal Data is processed.
6.2 When Lumenci Acts as a Data Processor
Lumenci acts as a data processor, service provider, or equivalent legal role when processing Customer Data on behalf of a customer.
Examples include:
uploaded patent portfolios;
patent analysis requests;
target-company analysis;
AI-assisted review activities;
natural-language portfolio interactions;
report generation;
workspace-hosted content; and
customer-directed processing activities.
In such circumstances, Lumenci processes Customer Data solely on behalf of and pursuant to instructions from the customer, subject to applicable law and contractual obligations.
6.3 Customer Responsibilities
Customers are responsible for:
obtaining any permissions, authorizations, notices, or consents required
under applicable law;ensuring lawful collection and submission of Customer Data;
determining whether Customer Data contains Personal Data;
ensuring compliance with professional responsibility obligations;
ensuring compliance with attorney-client privilege requirements where
applicable; anddetermining the appropriateness of using AI-generated outputs in legal or
commercial decision-making.
COMPLIANCE COMMITMENT
Lumenci seeks to comply with applicable privacy, data protection, cybersecurity, and artificial intelligence laws that apply to its operations and the Services. Nothing in this Privacy Policy limits any rights that individuals may have under applicable law.
PART II INFORMATION WE COLLECT, SOURCES OF INFORMATION, AI PROCESSING DATA, AND CUSTOMER CONTENT
INFORMATION WE COLLECT
To provide, secure, improve, and support the Services, Lumenci collects and processes information from various sources. The categories of information collected depend on how you interact with the Services, your organization’s configuration, the features utilized, and the nature of the content submitted to the platform.
Lumenci follows principles of data minimization and purpose limitation and seeks to collect only information reasonably necessary for the operation, security, support, and enhancement of the Services.
INFORMATION YOU PROVIDE DIRECTLY TO US
9.1 Account Registration Information
When users create an account, accept an invitation, or otherwise register to use the Services, Lumenci may collect:
full name;
business email address;
organization name;
job title or professional role;
workspace affiliation;
profile image or avatar;
account preferences; and
other information voluntarily submitted during account creation.
This information is used to establish and administer user accounts and facilitate access to the Services.
9.2 Authentication and Identity Information
To authenticate users and maintain platform security, Lumenci may collect and process:
password hashes;
authentication credentials;
encrypted session tokens;
OAuth tokens;
identity-provider claims;
multifactor authentication information;
login timestamps;
login history; and
account recovery information.
Passwords are never stored in plaintext.
Where single sign-on ("SSO") services are utilized, Lumenci receives only the identity attributes provided by the relevant identity provider.
9.3 Organization and Workspace Information
When an organization subscribes to the Services, Lumenci may collect:
organization name;
workspace identifiers;
subscription details;
user roles and permissions;
workspace settings;
invitation records;
administrator information;
authorized user lists; and
organizational preferences.
9.4 Communications Information
When users communicate with Lumenci, Lumenci may collect:
support requests;
help desk submissions;
email correspondence;
customer success communications;
survey responses;
webinar registrations;
event registrations;
feedback submissions;
product suggestions; and
other communications voluntarily provided to Lumenci
CUSTOMER CONTENT AND INTELLECTUAL PROPERTY DATA
A core function of the Services is the processing of intellectual property and patent-related information supplied by customers.
Accordingly, Lumenci processes Customer Content submitted by users or authorized representatives of customer organizations.
Customer Content may include:
10.1 Patent Portfolio Information
patent numbers;
patent application numbers;
patent families;
patent ownership information;
filing information;
maintenance information;
patent classifications;
patent metadata; and
portfolio management information.
10.2 Patent Documents and Technical Content
patent claims;
specifications;
abstracts;
figures;
citations;
prosecution histories;
office action references;
prior-art references;
claim charts; and
related intellectual property materials.
10.3 Target Company Information
Users may provide identifiers relating to companies for analysis purposes, including:
company names;
ticker symbols;
subsidiaries;
products;
business units;
publicly available business information;
market information; and
publicly available disclosures.
10.4 User-Generated Inputs
Users may submit:
analysis requests;
search queries;
prompts;
instructions;
portfolio review requests;
natural-language questions;
comments;
notes;
annotations; and
workflow inputs.
10.5 Generated Reports and Outputs
Lumenci may generate and store:
infringement findings;
patent validity assessments;
damages estimates;
tier rankings;
evidence summaries;
portfolio analytics;
claim coverage analyses;
AI-generated summaries;
exportable reports; and
other generated content.
AI INTERACTION DATA
To provide AI-powered functionality, Lumenci collects and processes information associated with user interactions with AI features.
This information may include:
prompts submitted by users;
contextual instructions;
retrieved source material;
model responses;
generated outputs;
system prompts;
analysis parameters;
model metadata;
token consumption data;
latency information;
processing logs; and
quality assurance information.
AI interaction data may contain Customer Content supplied by users.
AI AUDIT TRAILS AND TRACEABILITY RECORDS
To support security, reproducibility, quality assurance, troubleshooting, compliance, model governance, and auditability, Lumenci maintains records relating to AI processing activities.
Such records may include:
prompt histories;
model responses;
model versions;
timestamps;
user identifiers;
workspace identifiers;
analysis identifiers;
token usage metrics;
cost metrics;
workflow execution logs; and
related system metadata.
These records are maintained to support platform integrity, investigation of errors, security monitoring, customer support, compliance obligations, and service improvement.
INFORMATION COLLECTED AUTOMATICALLY
When users access the Services, Lumenci automatically collects certain technical and usage information.
Such information may include:
13.1 Device Information
browser type;
operating system;
device identifiers;
language settings;
display settings;
application version information; and
device configuration data.
13.2 Log and Usage Information
IP addresses;
login records;
session activity;
page views; feature utilization;
user interactions;
clickstream information;
access timestamps;
navigation information; and
performance metrics.
13.3 Diagnostic and Telemetry Information
Lumenci may collect diagnostic information regarding:
errors;
crashes;
failed requests;
API activity;
performance issues;
latency measurements;
debugging information; and
system health metrics.
Certain diagnostic information may be processed through third-party monitoring providers.
INFORMATION RECEIVED FROM THIRD PARTIES
Lumenci may receive information from third-party sources in connection with providing the Services.
14.1 Identity Providers
When users authenticate through Microsoft Entra ID or other approved identity
providers, Lumenci may receive:
name;
email address;
organization information;
profile image;
user identifier; and
authentication claims.
14.2 Public Intellectual Property Sources
Lumenci may retrieve publicly available information from:
patent offices;
patent registries;
patent databases;
government repositories;
public intellectual property databases; and
other publicly accessible sources.
Such information may include patent records, ownership information, filing histories, prior-art references, and related intellectual property information.
14.3 Public Company and Market Information Sources
To support analysis functionality, Lumenci may collect publicly available information from:
securities filings;
annual reports;
investor presentations;
public websites;
regulatory filings;
corporate disclosures; and
publicly accessible business records.
14.4 Payment and Billing Providers
Lumenci may receive information from payment processors and subscription management providers, including:
customer identifiers;
subscription status;
billing status;
invoice information;
transaction confirmations; and
payment verification information.
Lumenci does not store full payment card numbers or payment card security codes.
SENSITIVE PERSONAL DATA
The Services are not intended to collect or process sensitive personal data. Users should not upload sensitive personal data unless such processing is necessary, lawful, and authorized.
Sensitive personal data may include:
government identification numbers;
passport numbers;
driver's license numbers;
financial account credentials;
payment card information;
biometric information;
precise geolocation data;
health information;
medical records;
genetic information;
information concerning racial or ethnic origin;
religious or philosophical beliefs;
trade union membership;
sexual orientation;
information concerning sex life;
political opinions; or
other categories recognized as sensitive under applicable law.
Where sensitive personal data is inadvertently received, Lumenci may take steps to restrict, delete, anonymize, or otherwise manage such information in accordance with applicable law and internal policies.
INFORMATION WE DO NOT INTENTIONALLY COLLECT
The Services are designed for professional and enterprise users and are not intended to collect:
children's personal information;
information from individuals under the age of eighteen (18);
biometric identification data;
facial recognition data;
voiceprints;
audio recordings;
video recordings; or
special category personal data except where incidentally included in Customer Content.
Users should not upload such information unless specifically authorized by Lumenci and permitted by applicable law.
CHILDREN'S PRIVACY
The Services are intended solely for professional and enterprise use. Lumenci does not knowingly collect, solicit, or process personal information from children or individuals under eighteen (18) years of age. If Lumenci becomes aware that personal information of a child has been submitted to the Services, Lumenci may take steps to delete such information and terminate the associated account.
CATEGORIES OF PERSONAL DATA PROCESSED
Depending on how the Services are used, Lumenci may process the following categories of Personal Data:

SOURCES OF PERSONAL DATA
Lumenci may collect Personal Data from:
users;
customer organizations;
organization administrators;
authorized representatives;
identity providers;
payment providers;
public patent databases;
public company databases;
publicly available sources;
customer communications;
monitoring and telemetry systems; and
third-party service providers acting on behalf of Lumenci.
DATA MINIMIZATION COMMITMENT
Lumenci seeks to collect and retain only the information reasonably necessary
to:
provide the Services;
fulfill contractual obligations;
maintain platform security;
comply with legal obligations;
support customer requests;
improve service functionality; and
conduct legitimate business operations.
Lumenci does not sell Personal Data and does not collect information for unrelated purposes inconsistent with the disclosures contained in this Privacy Policy.
PART III
HOW WE USE INFORMATION, LEGAL BASES FOR PROCESSING, AI PROCESSING ACTIVITIES, AUTOMATED ANALYSIS, AND DISCLOSURE OF INFORMATION
HOW WE USE INFORMATION
Lumenci uses Personal Data and Customer Data only for legitimate business purposes, to provide the Services, fulfill contractual obligations, comply with legal requirements, maintain platform security, and improve user experience. The manner in which information is used depends on the nature of the information, the Services being utilized, the customer's instructions, and applicable legal requirements.
21.1 Confidentiality of Customer Content
Lumenci treats Customer Content as confidential information and implements measures designed to prevent unauthorized access, use, or disclosure. Customer Content is accessed only by authorized personnel and authorized service providers with a legitimate business need to know.
PURPOSES OF PROCESSING
Lumenci may process information for one or more of the following purposes.
22.1 Provision of the Services
Lumenci processes information to provide, operate, maintain, and support the Services.
This includes:
account creation and administration;
workspace management;
user authentication;
subscription management;
access control;
customer support;
report generation;
data hosting;
workflow execution; and
platform functionality.
22.2 Patent Portfolio Analysis
Lumenci processes Customer Content to perform patent and intellectual property analyses requested by users.
Such processing may include:
patent portfolio review;
patent ranking;
infringement analysis;
claim mapping;
prior-art review;
patent validity assessment;
portfolio categorization;
litigation readiness analysis;
licensing analysis;
damages assessment;
portfolio valuation support; and
other intellectual property analytics.
22.3 AI-Assisted Processing
Lumenci uses artificial intelligence technologies to process Customer Content and generate outputs requested by users.
Such processing may include:
• summarization;
• classification;
• comparison;
• ranking;
• recommendation generation;
• natural-language interaction;
• evidence extraction;
• structured data generation;
• report drafting;
• patent analytics; and
• decision-support functionality.
AI processing is performed solely to provide the Services requested by customers.
22.4 Customer Support and Service Administration
Lumenci may process information to:
• respond to support requests;
• investigate technical issues;
• resolve customer complaints;
• communicate regarding subscriptions;
• provide training;
• provide implementation assistance; and
• improve customer experience.
22.5 Security and Fraud Prevention
Lumenci processes information to:
• authenticate users;
• verify account ownership;
• prevent unauthorized access;
• detect misuse;
• investigate suspicious activity;
• prevent fraud;
• maintain platform integrity;
• protect intellectual property; and
• enforce contractual obligations.
22.6 Compliance and Legal Obligations
Lumenci may process information to:
• comply with applicable laws;
• comply with regulatory obligations;
• respond to legal requests;
• enforce agreements;
• establish, exercise, or defend legal claims;
• satisfy recordkeeping obligations; and
• fulfill audit requirements.
22.7 Product Development and Service Improvement
Lumenci may process information to:
• improve platform functionality;
• develop new features;
• evaluate performance;
• conduct testing;
• improve reliability;
• troubleshoot issues;
• optimize workflows; and
• enhance user experience.
Where possible, Lumenci uses aggregated, anonymized, or de-identified information for these purposes.
22.8 Communications
Lumenci may use information to:
• send service-related notices;
• communicate security alerts;
• provide subscription information;
• notify users of analysis completion;
• communicate policy updates;
• provide training materials; and
• send administrative communications.
Where permitted by law, Lumenci may also send marketing communications regarding products, services, events, or educational content.
Recipients may opt out of marketing communications at any time.
LEGAL BASES FOR PROCESSING
Where required under applicable law, Lumenci relies on one or more of the
following legal bases for processing Personal Data.
23.1 Performance of a Contract
Processing may be necessary to:
• provide the Services;
• manage subscriptions;
• perform contractual obligations;
• authenticate users;
• deliver requested analyses; and
• provide customer support.
23.2 Legitimate Interests
Lumenci may process information where necessary for legitimate business
interests, including:
• maintaining platform security;
• preventing fraud;
• improving services;
• conducting analytics;
• ensuring operational continuity;
• managing customer relationships;
• protecting intellectual property; and
• enforcing legal rights.
Where required, Lumenci balances such interests against the rights and
freedoms of affected individuals.
23.3 Consent
Lumenci may rely on consent where required by law, including for:
• certain marketing communications;
• certain cookies or tracking technologies;
• processing of sensitive information where legally required; and
• other activities requiring consent under applicable law.
Consent may be withdrawn at any time, subject to legal and contractual limitations.
23.4 Legal Obligations
Lumenci may process information where necessary to comply with:
• applicable laws;
• regulatory requirements;
• court orders;
• governmental requests;
• tax obligations;
• compliance investigations; and
• lawful enforcement actions.
23.5 Protection of Vital Interests
Where necessary and permitted by law, Lumenci may process information to protect the vital interests of individuals or organizations.
AI PROCESSING DISCLOSURES
Lumenci believes users should understand when and how artificial intelligence technologies are used.
Accordingly, Lumenci provides the following disclosures regarding AI-assisted processing.
24.1 Use of Artificial Intelligence
The Services utilize artificial intelligence, machine learning technologies, and large language models to assist users in analyzing patent portfolios and related information.
Users interacting with AI-powered features may receive responses, recommendations, analyses, rankings, summaries, or reports generated wholly or partially through automated processing.
24.2 Data Submitted to AI Systems
Information submitted to AI systems may include:
• patent claims;
• patent specifications;
• patent identifiers;
• portfolio information;
• publicly available company information;
• user prompts;
• instructions;
• supporting evidence;
• contextual information; and
• other Customer Content required to perform requested analyses.
24.3 Purpose of AI Processing
AI processing may be performed to:
• analyze patent portfolios;
• identify potential infringement indicators;
• assess patent validity;
• estimate damages ranges;
• generate reports;
• summarize evidence;
• rank opportunities;
• answer user questions;
• facilitate research; and
• improve workflow efficiency.
24.4 Human Review
Access to Customer Content by authorized Lumenci personnel is limited to circumstances reasonably necessary to provide requested services, customer support, security, compliance, troubleshooting, or optional expert-review services authorized by the customer.
24.5 Limitations of AI Systems
Artificial intelligence systems are probabilistic technologies and may generate:
• inaccurate results;
• incomplete results;
• outdated information;
• incorrect assumptions;
• inaccurate legal conclusions; or
• misleading recommendations.
Users should independently evaluate all outputs before relying upon them. Customers should not rely exclusively on AI-generated outputs when making legal, licensing, litigation, commercial, or business decisions.
AUTOMATED DECISION-MAKING AND PROFILING
Lumenci may use automated processing to generate analyses, rankings, recommendations, scores, classifications, or predictions.
Examples may include:
• patent prioritization scores;
• infringement likelihood assessments;
• validity assessments;
• damages estimation;
• licensing opportunity rankings;
• portfolio segmentation; and
• analytical recommendations.
These outputs are intended solely to assist users in evaluating information.
Lumenci does not use such automated processing to make legally binding decisions on behalf of customers, nor does Lumenci independently determine legal rights, legal claims, litigation outcomes, employment decisions, credit decisions, insurance eligibility, housing eligibility, or other decisions producing legal or similarly significant effects on individuals.
Customers remain solely responsible for all decisions made based upon platform outputs.
NO TRAINING OF FOUNDATION MODELS USING CUSTOMER CONTENT
Unless expressly authorized by the customer, Lumenci does not use Customer Content to train publicly available general-purpose foundation models.
Lumenci may use Customer Content, AI interaction data, and generated outputs to provide, maintain, secure, improve, evaluate, monitor, troubleshoot, and develop the Services, subject to applicable law and contractual commitments.
Customer Content includes:
• uploaded patent portfolios;
• patent claims;
• prompts;
• chat interactions;
• reports;
• generated outputs; and
• associated analysis data.
Where third-party AI providers are utilized, Lumenci seeks to utilize commercial services configured so that Customer Content is not used to train the providers' general-purpose models, subject to the applicable terms of the relevant provider.
DISCLOSURE OF INFORMATION
Lumenci does not sell Personal Data. Lumenci does not disclose Personal Data to third parties for cross-context behavioral advertising. Lumenci may disclose information only as described in this Privacy Policy or as otherwise authorized by applicable law.
DISCLOSURES TO SERVICE PROVIDERS AND SUBPROCESSORS
Lumenci may disclose information to trusted service providers that assist in operating the Services.
Such providers may include:
• cloud hosting providers;
• infrastructure providers;
• database providers;
• authentication providers;
• payment processors;
• monitoring providers;
• analytics providers;
• communication providers;
• customer-support providers; and
• artificial intelligence providers.
Such disclosures occur only to the extent reasonably necessary for the provision of the Services.
DISCLOSURES TO AI PROVIDERS
To provide AI-powered functionality, Lumenci may disclose Customer Content to AI providers engaged by Lumenci.
Such disclosures may include:
• patent information;
• claims;
• supporting evidence;
• user prompts;
• contextual information; and
• analysis instructions.
AI providers process such information solely for purposes of providing AI functionality requested through the Services. Lumenci does not authorize AI providers to use Customer Content for advertising purposes.
DISCLOSURES TO IDENTITY, PAYMENT, AND COMMUNICATION PROVIDERS
Lumenci may disclose limited information to:
Authentication Providers: for identity verification and account security.
Payment Processors: for subscription management, billing, fraud prevention, and payment processing.
Communication Providers: for email delivery, notification services, and customer communications.
DISCLOSURES FOR LEGAL COMPLIANCE
Lumenci may disclose information where required to:
• comply with legal obligations;
• respond to subpoenas;
• respond to court orders;
• comply with governmental requests;
• comply with regulatory investigations;
• enforce agreements;
• protect rights;
• investigate violations; or
• prevent harm.
Where legally permitted, Lumenci may attempt to notify affected customers before disclosing Customer Data.
BUSINESS TRANSFERS
Lumenci may disclose information in connection with:
• mergers;
• acquisitions;
• financing transactions;
• asset sales;
• reorganizations;
• insolvency proceedings; or
• other corporate transactions.
Any successor entity receiving information will remain subject to obligations substantially consistent with this Privacy Policy.
AGGREGATED AND DE-IDENTIFIED INFORMATION
Lumenci may create, use, disclose, and retain aggregated, anonymized, or de identified information for lawful business purposes.
Such purposes may include:
• service improvement;
• benchmarking;
• analytics;
• security analysis;
• operational reporting;
• product development; and
• industry research.
Lumenci will not attempt to re-identify de-identified information except where permitted or required by law.
PURPOSE LIMITATION COMMITMENT
Lumenci processes Personal Data only for purposes that are:
• disclosed in this Privacy Policy;
• reasonably necessary to provide the Services;
• compatible with the original purpose of collection;
• required by law; or
• expressly authorized by the customer or affected individual.
Lumenci does not process Personal Data for materially different purposes without an appropriate legal basis and, where required, appropriate notice or consent.
DATA MINIMIZATION COMMITMENT
Lumenci seeks to collect, use, retain, and disclose only the information reasonably necessary to achieve the purposes described in this Privacy Policy. Personal Data will not be retained or processed beyond what is reasonably necessary for the applicable business, contractual, security, compliance, or legal purpose.
PART IV
INTERNATIONAL DATA TRANSFERS, DATA RETENTION, DATA SECURITY, PRIVACY RIGHTS, REGIONAL DISCLOSURES, AND CONTACT INFORMATION
INTERNATIONAL DATA TRANSFERS
Lumenci operates globally and may transfer, store, access, or process Personal Data in jurisdictions other than the jurisdiction in which the information was originally collected.
In particular, Lumenci's primary hosting infrastructure, operational systems, artificial intelligence providers, support systems, and sub-processors may be located in or operate from the United States and other countries. As a result, Personal Data may be transferred to and processed in jurisdictions whose data protection laws may differ from those of the country in which the data was originally collected.
Where required by applicable law, Lumenci implements appropriate safeguards designed to ensure that transferred Personal Data remains protected.
36.1 United States Data Processing
The Services are principally hosted and operated in the United States. By using the Services, users acknowledge that information may be transferred to, stored in, and processed within the United States and other jurisdictions where Lumenci or its authorized sub-processors operate.
36.2 Appropriate Transfer Mechanisms
Where required under applicable law, Lumenci may rely on one or more of the following transfer mechanisms:
• Standard Contractual Clauses approved by the European Commission;
• UK International Data Transfer Addendum;
• EU-U.S. Data Privacy Framework;
• UK Extension to the EU-U.S. Data Privacy Framework;
• Swiss-U.S. Data Privacy Framework;
• contractual safeguards;
• adequacy decisions;
• legally recognized transfer mechanisms; or
• other safeguards authorized by applicable law.
36.3 Cross-Border Transfers by Customers
Customers remain responsible for ensuring that their use of the Services complies with any cross-border transfer requirements applicable to information submitted to the Services.
DATA RETENTION
Lumenci retains Personal Data and Customer Data only for as long as reasonably
necessary to:
• provide the Services;
• comply with contractual obligations;
• maintain security;
• satisfy legal obligations;
• resolve disputes;
• enforce agreements;
• protect rights and interests; and
• fulfill legitimate business purposes.
Retention periods may vary depending on the category of information and applicable legal requirements.
Lumenci determines retention based on contractual requirements, legal obligations, security needs, and operational requirements.
37.1 Account Information
Account and user profile information may be retained for the duration of the customer relationship and for a reasonable period thereafter to:
• maintain records;
• address disputes;
• comply with legal obligations; and
• support security investigations.
37.2 Customer Content
Customer Content may be retained for the duration of the applicable subscription or service relationship. Following termination, Customer Content may be deleted or returned in accordance with contractual commitments, customer instructions, legal obligations, backup schedules, and operational requirements.
37.3 AI Processing Records
AI audit logs, prompts, outputs, processing metadata, and related traceability records may be retained for:
• reproducibility;
• quality assurance;
• compliance;
• fraud prevention;
• platform security;
• dispute resolution; and
• operational integrity.
Retention periods shall be limited to what is reasonably necessary for those purposes.
37.4 Billing and Financial Records
Billing, accounting, taxation, and financial records may be retained for periods required by applicable law and accounting standards.
37.5 Security and Operational Logs
Security logs, authentication records, access records, and operational telemetry may be retained for security, compliance, fraud prevention, and incident investigation purposes.
37.6 Aggregated and De-Identified Data
Aggregated, anonymized, and de-identified information may be retained indefinitely where permitted by applicable law and where such information cannot reasonably identify an individual.
ACCOUNT TERMINATION AND DATA DELETION
Customers may request deletion of Customer Data or closure of accounts by contacting Lumenci through the methods identified in this Privacy Policy.
Subject to applicable law, contractual obligations, security requirements, backup schedules, and legitimate business needs, Lumenci will take commercially reasonable steps to:
• delete Customer Data;
• delete account information;
• remove user access;
• terminate subscriptions; and
• dispose of retained records when no longer required.
Unless a longer period is required by law or contract, Lumenci generally aims to complete verified deletion requests within a commercially reasonable period and subject to applicable legal requirements.
Certain information may be retained where required to:
• comply with legal obligations;
• resolve disputes;
• prevent fraud;
• enforce agreements;
• maintain security records; or
• preserve backup integrity.
DATA SECURITY
Lumenci maintains administrative, technical, organizational, and physical safeguards designed to protect Personal Data and Customer Data against unauthorized access, disclosure, alteration, destruction, loss, misuse, or
compromise.
No security measure can guarantee absolute security; however, Lumenci strives to maintain security measures appropriate to the nature, scope, context, and sensitivity of the information processed.
39.1 Security Measures
Security measures may include:
• encryption in transit;
• encryption at rest;
• role-based access controls;
• identity and access management systems;
• authentication controls;
• multi-factor authentication;
• secure development practices;
• vulnerability management;
• audit logging;
• network monitoring;
• security testing;
• employee confidentiality obligations;
• incident response procedures; and
• vendor risk management processes.
39.2 Encryption
Lumenci employs industry-standard encryption technologies for:
Data in Transit
Transport Layer Security (TLS) or equivalent protocols.
Data at Rest
Encryption mechanisms designed to protect stored information, databases,backups, and storage systems.
39.3 Customer Responsibilities
Customers are responsible for:
• maintaining credential confidentiality;
• restricting account access;
• protecting authentication information;
• configuring workspace permissions appropriately; and
• promptly reporting suspected unauthorized access.
SECURITY INCIDENTS
Lumenci maintains procedures designed to detect, investigate, respond to, and remediate security incidents. Where required by applicable law or contractual commitments, Lumenci may notify affected customers of confirmed security incidents involving Customer Data.
The timing, content, and method of notification may depend upon:
• legal requirements;
• law-enforcement considerations;
• technical circumstances; and
• risk assessments.
YOUR PRIVACY RIGHTS
Depending upon applicable law and your jurisdiction, you may have one or more of the following rights.
41.1 Right of Access
You may request access to Personal Data maintained by Lumenci regarding you.
41.2 Right to Correction
You may request correction of inaccurate or incomplete Personal Data.
41.3 Right to Deletion
You may request deletion of Personal Data, subject to applicable exceptions.
41.4 Right to Data Portability
You may request a copy of certain Personal Data in a structured, commonly used, and machine-readable format where required by applicable law.
41.5 Right to Restrict Processing
You may request restriction of certain processing activities where permitted by applicable law.
41.6 Right to Object
You may object to certain processing activities, including processing based upon legitimate interests, where applicable.
41.7 Right to Withdraw Consent
Where processing is based on consent, you may withdraw consent at any time. Withdrawal of consent does not affect processing conducted before withdrawal.
41.8 Right to Opt Out of Certain Processing
Where required by applicable law, individuals may have rights to opt out of:
• targeted advertising;
• profiling;
• sales of personal information; or
• certain automated processing activities.
Lumenci does not currently sell Personal Data or disclose Personal Data for cross-context behavioral advertising.
41.9 Right to Appeal
Where required by applicable law, individuals may appeal decisions relating to privacy rights requests.
EXERCISING YOUR RIGHTS
Requests concerning privacy rights may be submitted through:
• designated privacy request portals;
• customer support channels;
• the contact information identified below; or
• other methods made available by Lumenci.
Lumenci may request additional information to verify identity before processing a request.
Where permitted by law, Lumenci may decline requests that:
• cannot be verified;
• are excessive;
• are repetitive;
• are abusive; or
• are otherwise exempt under applicable law.
CALIFORNIA PRIVACY DISCLOSURES
For California residents, Lumenci provides disclosures intended to comply with the California Consumer Privacy Act ("CCPA"), as amended by the California Privacy Rights Act ("CPRA"). California residents may have rights relating to:
• access;
• deletion;
• correction;
• portability;
• disclosure;
• non-discrimination; and
• limitation of sensitive personal information processing.
Lumenci does not sell Personal Information and does not share Personal Information for cross-context behavioral advertising. Accordingly, Lumenci does not currently offer a "Do Not Sell or Share My Personal Information" mechanism because no such activity occurs, based on Lumenci's current processing activities. Should Lumenci's practices change in the future, this Privacy Policy will be updated accordingly.
EUROPEAN ECONOMIC AREA, UNITED KINGDOM, AND SWITZERLAND
Individuals located within the European Economic Area, the United Kingdom, and Switzerland may have rights under applicable data protection laws including:
• access;
• rectification;
• erasure;
• restriction;
• portability;
• objection; and
• complaint rights.
Individuals may also have the right to lodge complaints with competent supervisory authorities.
JAPAN DISCLOSURES
Where Lumenci processes Personal Data subject to the Act on the Protection of Personal Information ("APPI"), Lumenci will process such information in accordance with applicable APPI requirements and will implement appropriate safeguards for international transfers where required.
AI TRANSPARENCY DISCLOSURE
Users interacting with AI-powered functionality should be aware that:
• responses may be generated by artificial intelligence systems;
• outputs may contain errors or inaccuracies;
• outputs may require independent verification;
• outputs should not be treated as legal advice;
• outputs are intended as decision-support tools only; and
• human review may be available for certain services.
Where required by applicable law, Lumenci will provide additional transparency
notices regarding AI processing activities.
DATA PROTECTION ASSESSMENTS
Where required by applicable law, Lumenci may conduct privacy, security, or AI impact assessments.
Such assessments may address:
• AI processing;
• automated decision-making;
• profiling;
• cross-border transfers;
• sensitive information processing;
• vendor risk;
• security controls; and
• customer data processing activities.
THIRD-PARTY WEBSITES AND SERVICES
The Services may contain links to third-party websites, applications, products, or services.
Lumenci is not responsible for the privacy practices of such third parties.
Users should review the privacy policies of third-party services before providing information to them.
CHANGES TO THIS PRIVACY POLICY
Lumenci may modify this Privacy Policy from time to time.
When material changes are made, Lumenci may:
• update the "Last Updated" date;
• provide notice through the Services;
• provide email notice; or
• provide other legally required notifications.
Continued use of the Services after changes become effective constitutes acceptance of the revised Privacy Policy to the extent permitted by law.
CONTACT INFORMATION
For questions regarding this Privacy Policy, privacy practices, data protection
matters, or privacy rights requests, please contact:
Privacy Team
Lumenci, Inc.
compliance@lumenci.com
9050 N. Capital of Texas Highway Building 3 Suite 350 Austin Texas, 78759
DATA PROTECTION CONTACT
Individuals may contact Lumenci regarding:
• privacy rights requests;
• access requests;
• deletion requests;
• correction requests;
• international transfer questions;
• AI transparency inquiries;
• data protection concerns; or
• complaints regarding processing activities.
Requests may be directed to:
Data Protection Contact
Email: compliance@lumenci.com
EFFECTIVE DATE
This Privacy Policy is effective as of the date identified at the beginning of this
Privacy Policy and supersedes all prior privacy notices relating to the Services.

By using this website, you agree to our use of cookies. We use cookies to provide you with a great experience and to help our website run effectively.