LUMINORIX

Privacy Policy

Last updated: September 21, 2026 · Draft for counsel review

This policy explains how Luminorix, Inc. ("Luminorix", "we") collects, uses and shares personal information when you visit our websites (luminorix.ai, app.luminorix.app and related sites), use the Luminorix platform, or communicate with us. It also describes the choices you have.

1. Two roles

We handle personal information in two ways. As a business ("controller"), we decide how to use information about visitors to our sites, prospects and the people who administer customer workspaces. As a service provider ("processor"), we handle the data inside a customer's connected systems and workspace on that customer's instructions; the customer decides how that data is used, and this policy does not replace the customer's own privacy notices. Our Data Processing Addendum governs that processing.

2. Information we collect

Information you give us: name, work email, company, phone, the problem you describe when booking an assessment, the roles you pick on the site, account and billing details, and the content of messages you send us.

Information from your use: pages visited, actions in the app, device and browser type, IP address, approximate location, timestamps and diagnostic logs.

Information from connected systems: when a customer connects a business system, the Service reads the data needed for the work the customer configures. This can include customer, order, invoice, ticket, calendar and communication records belonging to the customer. We process it only for that customer.

Information from third parties: business contact details from data providers used for sales outreach, and payment status from our payment processor.

3. How we use information

To provide and secure the Service, including operating AI agents within the permissions a customer sets; to set up and confirm assessments and respond to requests; to bill and manage accounts; to send service notices and, with your permission or where the law allows, marketing you can opt out of; to understand how the Service is used and improve it; to detect and prevent fraud, abuse and security incidents; and to comply with law. We do not sell personal information and we do not share it for cross-context behavioral advertising. We do not use customer data to train models offered to other customers.

4. AI processing

The Service sends the data needed for a task to large-language-model providers under contracts that prohibit them from using it to train their models. Agents act within the permissions a customer configures and, for actions that change data or contact people, with human approval where offered. Output can be wrong; customers review it.

5. How we share information

With sub-processors that host, run and support the Service (cloud infrastructure, model providers, voice and telephony, email delivery, payments, analytics). The current list is in the Data Processing Addendum and available on request. With a customer's own connected systems, as instructed by the customer. With professional advisers, and with authorities where the law requires. With a successor in a merger or sale, under this policy.

6. Cookies and local storage

Our sites use a small number of cookies and browser storage items for sign-in, remembering your choices and basic analytics. We do not use advertising cookies. Details and choices are in the Cookie Policy.

7. Security

Credentials for connected systems are encrypted at rest with AES-256, data moves over TLS, workspaces are isolated by tenant, agent actions are permission-gated and logged, and access to production is restricted to authorized staff. No system is perfectly secure; if we learn of a breach affecting your personal information we will notify you as the law requires.

8. Retention

We keep account and billing information while you have an account and for the period required for tax and legal purposes. We keep customer workspace data while the workspace exists and delete it within 30 days after closure, with backups expiring within 90 days. Assessment requests and site inquiries are kept for up to 24 months unless you ask us to delete them sooner. Logs are kept for up to 12 months.

9. Your rights

Depending on where you live you may have the right to access, correct, delete or receive a copy of your personal information, to object to or restrict certain processing, to withdraw consent, and to not be discriminated against for exercising these rights. California residents have these rights under the CCPA/CPRA, including the right to know the categories of information collected and shared; we do not sell or share personal information for advertising. Residents of the European Economic Area, United Kingdom and Switzerland have rights under the GDPR and may lodge a complaint with a supervisory authority. To exercise any right, email [email protected] from the address on your account or with enough detail for us to verify you. If we act as a processor for a customer, we will refer your request to that customer and help them respond.

10. International transfers

We are based in the United States and process information there. Where we receive personal information from the EEA, UK or Switzerland, we rely on standard contractual clauses or another lawful transfer mechanism, available on request.

11. Children

The Service is for businesses. We do not knowingly collect personal information from anyone under 18.

12. Changes and contact

We will post changes here and, for material changes, notify account admins by email. Questions and requests: [email protected], or Luminorix, Inc., 9477 Waples Street, Suite 120, San Diego, CA 92121.

13. Google user data

Some customers connect Google services to the Service. When a customer chooses to connect Google, we ask Google for permission to read only what the connected work requires, and Google shows the exact permissions before the customer agrees. We request read-only access to Google Analytics, read-only access to Google Search Console, access to Google Ads, and the basic profile and email address of the account doing the connecting so we can show whose account is connected and who to ask if it stops working.

We use Google user data for one purpose: to produce the findings, reports and recommended actions inside that customer's own workspace, for that customer. We do not use it to serve advertising, we do not sell or rent it, we do not use it to train generally available AI models, and we do not transfer it to others except the sub-processors that host and run the Service on our behalf, or where the law requires it.

Access and refresh tokens are encrypted at rest and are never shown in the product or to other customers. A customer can disconnect Google at any time from the connected systems screen, or revoke our access directly at myaccount.google.com/permissions; revoking stops all further access immediately. We delete stored Google tokens when a connection is removed or the account is closed, and we delete or de-identify data derived from Google services on the retention schedule in section 8.

Luminorix's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.