This Privacy Policy explains how LumiCodex, SIRET 981 087 513 00017, Annemasse, France ("we") collects and processes personal data when you use the LumiCodex platform, websites, admin app, APIs, embeds, and WordPress plugin (the "Service").
1. Our two roles
- We are the controller for personal data we process to run our business: your account, authentication, billing, support, and Service-usage data.
- We are a processor for personal data contained in the Content you upload (for example, people depicted in your photographs). For that Content, you are the controller and decide why and how it is processed; we process it on your instructions. You are responsible for having a lawful basis and any consents/releases for the people in your images.
2. Data we process
- Account data: name, email, phone, password (hashed), organization, language, country, and account settings.
- Billing data: plan, subscription status, currency, country, and invoice records. Card payments are handled by Stripe; we do not store full card numbers.
- Content: photographs and files you upload, plus associated metadata (which may include EXIF, location, or other personal data). Content may depict third parties.
- Usage and technical data: log data, device/browser information, IP address, approximate location (via IP geolocation), API usage and metering, and diagnostic events.
- Support and communications: messages you send us and related records.
- Cookies / local storage: see the Cookie Policy.
3. Purposes and legal bases (controller data)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide the Service, accounts, and delivery | Contract |
| Billing and fraud prevention | Contract; legal obligation |
| Security, abuse prevention, service integrity | Legitimate interests |
| Support and communications | Contract / legitimate interests |
| Legal compliance (incl. content reporting) | Legal obligation |
Where we rely on legitimate interests, we balance them against your rights.
4. Content and AI processing
We process Content only to operate and deliver the Service to you (hosting, encoding/transcoding, tiling, color management, CDN delivery, backups). To keep the platform safe and to provide features, Content may be analyzed by automated/AI systems for content moderation, detection of illegal content, categorization, tagging, and optimization. This involves third-party AI providers, including OpenAI and Google (Gemini). We do not sell your Content and do not allow it to be used to train those providers' models, to the extent contractually available.
5. Sharing and processors (sub-processors)
- Stripe — payments and billing.
- Amazon Web Services (AWS) — hosting, storage, database, key management, and content delivery.
- OpenAI and Google (Gemini) — content moderation/analysis as in Section 4.
- Postmark — transactional email.
- Twilio — SMS/OTP delivery.
- MaxMind — IP geolocation for fraud prevention and localization.
We also disclose data where required by law or to protect rights, safety, and the Service.
Where we process personal data in your Content on your behalf, our Data Processing Agreement (GDPR Art. 28) applies automatically as part of the Terms.
6. International transfers and regions
The Service runs on cloud and CDN infrastructure, so personal data and Content may be stored, processed, and delivered from data centers and edge locations in multiple countries, including outside the EEA. Where data leaves the EEA, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and adequacy decisions where applicable.
7. Retention
We keep personal data for as long as your Account is active and as needed for the purposes above, then delete or anonymize it, subject to backup cycles and legal retention obligations under French law (for example, accounting and invoice records). Content is retained while your Account is active and deleted after termination per the Terms, subject to routine backups.
8. Security
We use technical and organizational measures (encryption in transit, access controls, key management, logging) to protect personal data. No system is perfectly secure; we work to detect and respond to incidents and to notify as required by law.
9. Your rights
Subject to law, you may access, rectify, erase, restrict, port, or object to processing of your personal data, and withdraw consent. To exercise your rights, contact support [at] lumicodex [dot] com. No Data Protection Officer has been formally appointed; privacy requests are handled directly by LumiCodex at the address above. You may also lodge a complaint with the CNIL (www.cnil.fr) or your local supervisory authority. If your personal data is in another customer's Content, contact that customer (the controller); we will assist them as processor.
10. Children
The Service is not directed to children under 15, and we do not knowingly process their data for our own purposes.
11. Changes
We may update this Policy and will post the new version with an updated date; material changes will be communicated where required.
12. Company
LumiCodex — SIRET 981 087 513 00017 — Annemasse (74100), France. Email: support [at] lumicodex [dot] com. See also the mentions légales.