Legal . Updated 18 August 2026
Privacy policy
This is a plain-language draft, not legal advice. Have an attorney review it for your jurisdiction before you rely on it.
Two kinds of people in this policy
This covers both our customers - the businesses who pay for the product - and their clients, who fill in forms. We handle those two groups differently. For your clients' data you are the controller and we are the processor: you decide what is collected and why, and we act on your instructions.
What we collect from customers
Your email address, business name, branding, plan and billing status. Basic product analytics about which features get used, so we know what to improve. Payment card details are handled by our payment processor and never reach our servers.
What we store on behalf of your clients
Whatever your forms ask for. Typically that means name, date of birth, contact details, answers to health questions, a signature image, a photo-consent choice, and where your form requires it a photo of an identity document. We also record the time, timezone, IP address and device of each signature, because that metadata is what makes a signed record hold up later.
Why we hold it
To provide the service you are paying for: showing you the submission, flagging contraindications, emailing aftercare instructions, and keeping a searchable, exportable archive. We do not sell personal data. We do not use your clients' data to train models. We do not use it to market to your clients.
Who else touches it
A small number of processors, each doing one job: hosting and database, file storage, transactional email, payment processing and product analytics. Each is bound by contract to protect the data and to use it only to provide their service to us.
How long we keep it
Submissions stay for as long as your account is active, because your legal reason for holding them usually outlasts the appointment. After you cancel, they remain exportable for 90 days and may then be deleted. You can delete an individual client at any time, which removes their personal details and leaves an anonymised record that the submission existed.
Security
Data is encrypted in transit and at rest. Signatures, identity photos and generated PDFs are stored privately and served only through short-lived signed links. Access is scoped at the database level, so one business cannot read another's records even if application code is wrong.
Your rights
Depending on where you live you may have rights to access, correct, export or delete personal data about you. If you are a client of one of our customers, contact that business first - it is their record. If they need our help, or if you cannot reach them, write to support@lumela.co and we will help.
Contact
Questions about this policy go to legal@lumela.co.