LUMEO

Policy and assurance

Privacy Policy

How information moves through the Lumeo Agent Gateway and the choices available to customers and data subjects.

Last updated August 2026

This policy is written to describe the current product architecture. Customer order forms or data-processing terms may add deployment-specific details.

01

Scope and roles

This policy covers the Lumeo website, control plane, gateway, and support channels. For account and website administration data, Lumeo acts as a controller. For source content and business data a customer directs Lumeo to process, the parties may have separate controller and processor responsibilities defined by their agreement.

Customers must have authority to connect each domain, document, API, and underlying dataset.

02

Information processed

We process account email addresses, organization membership, verified domains, configuration, support messages, billing references, security logs, usage records, approval records, and the content or metadata of connected sources.

Agent requests may include client identifiers, operation names, domain, status, latency, billed units, and limited request or response data needed for execution and auditability.

  • —Do not connect unnecessary health, financial, employment, or other sensitive personal data.
  • —API client secrets and sign-in tokens are stored as hashes; source credentials can be encrypted with a deployment-provided key.
03

Purposes and legal bases

We process information to provide and secure the service, verify domains, ingest sources, execute configured tools, meter usage, support customers, prevent abuse, comply with law, and improve reliability.

Depending on the context, processing may rely on contract performance, legal obligations, consent, or legitimate interests such as service security and fraud prevention. Customers determine the lawful basis for data they instruct Lumeo to process.

04

AI and model providers

Lumeo does not use customer source content to train a Lumeo general-purpose model. A deployment may use a configured model or embedding provider to process selected content for extraction or retrieval. The applicable provider, region, retention behavior, and training terms depend on that configuration and customer agreement.

Instruction-like or suspicious source content may be excluded from retrieval as a security measure.

05

Service providers and transfers

Lumeo may use infrastructure, database, object-storage, email-delivery, payment, monitoring, and model-service providers. Information is shared only as needed for the configured service. Provider locations may involve international transfers; applicable transfer safeguards should be documented in the relevant customer agreement.

06

Retention and deletion

Retention depends on the record type, customer configuration, legal obligations, security needs, and active service agreement. Source data and derived records are removed or returned according to the applicable agreement and available deletion workflows. Billing, security, or dispute records may be retained where reasonably necessary or legally required.

Deletion requests may require identity and domain-authority verification. Backups can persist for a limited recovery cycle before expiring.

07

Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, and to complain to a supervisory authority. Rights are subject to identity verification and applicable exceptions.

Send privacy requests to privacy@lumeoagent.com. We will acknowledge and respond within the timeframe required by applicable law.

08

Security and contact

Security controls and configuration boundaries are described in the Trust Center and Security page. No internet service can promise absolute security.

Privacy questions can be sent to privacy@lumeoagent.com. Security reports should be sent to security@lumeoagent.com.