Privacy Policy
How we handle your personal data.
This policy explains what personal data we collect, why we collect it, how we use and share it, and the rights you have over it under the EU General Data Protection Regulation (GDPR), the Spanish LOPDGDD, and equivalent regulations in LATAM jurisdictions (including Brazil's LGPD).
Document in preparation
This document is a working draft pending formal incorporation of the entity. The information published here does not constitute a binding undertaking. The final version will replace this notice once the legal entity is registered. Last updated reflects the scaffold date, not the legally binding effective date.
1. Data Controller
The data controller responsible for the personal data collected through this website is [Razón social pendiente], registered at [Dirección fiscal pendiente].
For any privacy-related request, contact legal@lumoraip.com.
2. Personal Data We Collect
- Contact forms: name, email, company, country, phone, message and any other data you voluntarily provide.
- Quote requests: jurisdiction, service type, Nice classes, urgency, company size, and contact details.
- Client portal (if you create an account): email, name, authentication metadata (sign-in events, device).
- Technical data: IP address (truncated for analytics), user agent, referrer, language preference, timestamps.
- Cookies and similar technologies: see the Cookies Policy.
3. Legal Bases for Processing
- Consent (Art. 6.1.a GDPR) — analytics cookies, marketing communications.
- Pre-contractual measures and contract performance (Art. 6.1.b GDPR) — quotes, engagement letters, ongoing matters.
- Legitimate interest (Art. 6.1.f GDPR) — fraud prevention, system security, basic non-identifying analytics.
- Legal obligation (Art. 6.1.c GDPR) — tax records, anti-money laundering compliance.
4. Retention Periods
We keep personal data only as long as necessary for the purposes described above. Specifically: contact and quote requests are kept for up to 24 months after the last interaction; client matters are kept according to applicable statutes of limitations (typically 5–10 years depending on jurisdiction); accounting records for the period required by tax law.
5. International Data Transfers
Some of the processors listed in section 7 may transfer data outside the European Economic Area, including the United States. We rely on adequacy decisions and the EU Standard Contractual Clauses (SCCs) where applicable. Several US-based processors are adhered to the EU-US Data Privacy Framework.
6. Hosting
The website and backend are hosted on Google Cloud Platform (Google LLC), primarily in europe-southwest1 (Madrid, España) and europe-west1 (Bélgica, UE). See Google Cloud compliance.
7. Processors and Subprocessors
We rely on the following third-party processors:
- Google Workspace (Gmail, Calendar, Drive) (Google Ireland Limited) — Comunicación profesional, gestión documental, calendarios. Region: EU (con SCCs para tránsito EE.UU.). Terms
- HubSpot CRM (HubSpot Ireland Limited) — Gestión comercial de leads y comunicación con clientes. Region: EU + EE.UU. (Data Privacy Framework adherido). Terms
- Firebase Authentication (Google LLC) — Autenticación del portal cliente. Region: EE.UU. (Data Privacy Framework). Terms
- Google Analytics 4 (Google Ireland Limited) — Analítica anónima de navegación (con consentimiento). Region: EU + EE.UU.. Terms
8. Your Rights
You have the right to:
- Access, rectify, and erase your personal data.
- Restrict or object to processing.
- Receive your data in a portable, structured format.
- Withdraw consent at any time (without affecting prior lawful processing).
- Lodge a complaint with the Spanish Data Protection Agency (AEPD) or the relevant local authority.
To exercise these rights, write to legal@lumoraip.com including a copy of an identification document.
9. Brazil — LGPD
For data subjects located in Brazil, this policy is read in conjunction with the Lei Geral de Proteção de Dados (LGPD, Law 13.709/2018). The legal@lumoraip.com address acts as the contact point for the Encarregado (DPO).
10. Changes to this Policy
We may update this policy. Material changes will be announced on this page and, where legally required, communicated by email to active clients.