Skip to content
luximioContact the team ↗

YOUR DATA. CLEAR ANSWERS.

Privacy,
explained.

What Luximio processes, why it is needed, and the choices and rights you have.

Privacy policyDraft prepared 12 September 2026

On this page

  1. Who is responsible
  2. Whose data this covers
  3. Data and purposes
  4. Where data comes from
  5. Cookies and storage
  6. Who receives data
  7. International transfers
  8. How long data stays
  9. Your rights
  10. Security and decisions
  11. Changes and contact

Review draft. Outstanding retention and processing arrangements still need finalisation. This draft is not a declaration that Luximio’s GDPR obligations have been completed.

1. Who is responsible

Luximio B.V., established in the Netherlands and registered with the Dutch Chamber of Commerce (KvK) under number 73161721, operates Luximio and is responsible for the controller processing described in this notice.

VAT ID
NL002182044B06
Business address
Kon. Wilhelminaplein 248
1062 KS Amsterdam
The Netherlands
Telephone
+31 20 398 6034
Legal and privacy email
legal [at] luximio.com

For questions about this notice or to exercise a right, email the address above and mention “Privacy request”. Replace [at] with @ and remove the spaces when entering the address in your email app. You can also contact us by telephone or post using the details above.

For account administration, enquiries and our own service security, the operator acts as a controller: it decides why and how personal data is used. The separate role for customer-managed link data is explained below.

2. Whose data this covers

This notice covers visitors to our marketing website, people who contact us or request beta access, workspace owners and members, and information used to protect the Luximio service.

When a customer uses Luximio to manage links or receive analytics for its app or website, the customer normally determines the purposes of that processing. Luximio processes that customer data on its instructions as a processor. The customer must provide its own privacy notice, and an appropriate data processing agreement must govern our processing for that customer.

If your request concerns an app or link operated by a customer, contact that app or website’s operator first. We can help route a request received by mistake, and assist the responsible customer. We remain responsible for answering requests about processing for which we are the controller.

Links can take you to an app, app store or third-party website. Those destinations have their own privacy practices. Luximio does not control what they collect after you leave our service.

3. Data we use and why

Messages and beta requests

Data: your name, reply email, selected topic, message and subsequent correspondence. Please do not include passwords, API keys or sensitive personal information.

Purpose and legal basis: answering questions, reviewing beta requests and providing support. We rely on steps taken at your request before a contract or performance of a contract when you are the contracting individual (GDPR Article 6(1)(b)). For general enquiries or business contacts acting for an organisation, our legitimate interest is to respond and manage that business relationship (Article 6(1)(f)). Submitting the form does not subscribe you to marketing.

Accounts and workspace administration

Data: email, display name, verification status, workspace membership and role, invitations, app/domain configuration, and records of administrative changes. Account/session records can include an IP address and browser user-agent information.

Purpose and legal basis: signing you in, providing requested features, managing permissions and maintaining an accountable service. Contract performance applies for an individual customer; legitimate interests in administering the customer relationship and protecting workspaces apply for an organisation’s representatives.

Service delivery and protection

Data: IP address, request URL, request time, response/error information, browser/device information, and security signals. A URL may itself contain personal information, so avoid placing personal details or secrets in link paths and destinations.

Purpose and legal basis: delivering pages and links, limiting spam and abusive traffic, investigating faults and protecting accounts. We rely on our legitimate interests in keeping the service available and secure, subject to balancing those interests against your rights. Contact messages and inbox addresses are not included in the contact handler’s application error logs.

Customer link events and app verification

Data: link and project identifiers, hostname/path, event identifier and time, broad platform category, country code when available, referrer origin for browser redirects, and reported app-open/attestation status. The detailed link-events table does not store raw IP addresses or raw user-agent strings; this does not mean that hosting providers never process them.

App verification can also involve an installation identifier, an attestation key identifier/public key, challenges and verification results. Installation-linked records are not automatically anonymous. Customers must provide an appropriate notice and legal basis for their use of app analytics and verification. We process these records on customer instructions and use necessary security information to protect the service.

Billing and legal records

The current private beta does not take live payments. If you use its Stripe test checkout or billing portal, Stripe can still receive personal data: an account email, workspace/customer identifier, selected plan and information you enter on its hosted page. Luximio keeps subscription/customer references, status and event records. Test mode does not make these records anonymous. We use them to test the requested billing features and administer the beta, relying on our legitimate interest in validating a reliable billing service. If live billing is introduced, we will explain the additional payment processing before it starts.

Where we must keep business records or respond to a legally binding request, the legal basis is the applicable legal obligation (Article 6(1)(c)). Where records are needed for a specific dispute, our legitimate interest is establishing, exercising or defending legal claims. We do not use these exceptions to keep unrelated data indefinitely.

Providing a reply email and the information needed to understand an enquiry is necessary for us to answer it. An email address is required to create and sign in to a customer account. You can browse the marketing content without submitting a form. We do not require optional marketing consent as a condition of support or beta access.

4. Where the information comes from

We receive information directly from you when you complete a form, sign in or use the dashboard. A workspace owner or administrator may provide your email when inviting you, and your name or role as part of workspace administration.

Technical information comes from your browser or app requests and from our hosting/security services. Customer apps may submit link events and verification information. Apple or Google can return verification results when the relevant app integration uses their attestation services.

For workspace invitations, we use the email address supplied by the person inviting you to deliver the invitation and manage access. Our legal basis is our legitimate interest in administering workspace invitations. You can object to this use and contact us about your data without accepting the invitation or creating an account.

Where we obtain your personal data indirectly and act as controller, the GDPR requires us to provide the relevant privacy information within one month, at our first communication with you if sooner, or before a first disclosure if sooner, unless a lawful exception applies. Review of other collection points and verification of notice delivery remain part of finalising this draft.

5. Cookies and browser storage

The authored marketing website has no advertising pixels, audience-measurement analytics or third-party font requests. Its visual examples run in the page and do not send their selections to an analytics service.

The contact form uses Cloudflare Turnstile to check for automated submissions. Cloudflare processes browser/device signals and network information for this security check. Our server sends the verification token and the client IP address supplied by Cloudflare to its verification service before delivering a message; it does not include your name, reply email or message text in that verification request. This widget does not enable Turnstile pre-clearance cookies. See Cloudflare’s Turnstile privacy information.

Hosting and security services can use cookies or similar browser checks to protect the site. Cloudflare’s challenge technology may use cf_clearance; depending on the enabled protection, it can also use bot-management cookies such as __cf_bm. These are security tools, not a promise that the website is cookie-free. Cloudflare describes their purposes in its cookie information.

The private preview additionally uses the hosting platform’s access controls. The customer dashboard uses necessary sign-in cookies; its session lifetime is configured for 30 days and may be renewed through use. Sign-in codes expire after five minutes. Cookie expiry and removal of server-side records are separate matters.

We do not ask for consent for storage that is strictly necessary to provide a service you request. Any future non-essential tracking will require an appropriate notice and, where required, a choice before it starts. You can use your browser settings to remove cookies, although blocking necessary cookies can prevent sign-in or security checks from working.

6. Who receives data

  • Authorised Luximio personnel: people who need access to operate the service, review beta requests, answer support or investigate a problem.
  • Your workspace: owners and authorised members can see information appropriate to their roles, including membership and administrative activity.
  • Cloudflare: hosting/network delivery, security, Worker execution, databases and link storage, and sending transactional email.
  • OpenAI Sites: hosting and access controls for the marketing preview and dashboard deployments.
  • Stripe: the sandbox checkout and billing portal receive the identifiers and data described above when used. Its privacy policy explains processing for its own purposes as well as its service-provider role. No live payment is collected in this beta.
  • One.com: hosts the receiving mailbox and stores contact/support correspondence. We do not routinely forward these messages to other mailboxes or external support services. Its data-protection information explains its role as processor for hosted customer email.
  • Apple and Google, when used by an app integration: native app-attestation and integrity verification. Their separate platform processing is described in their own privacy information.
  • Professional advisers or public authorities: where necessary for a specific legal matter or a lawful disclosure requirement.

Providers acting as processors must be bound by appropriate data processing terms and may use data only for the authorised purposes. A current customer subprocessor list and the applicable customer data processing agreement must be in place for processor services; this privacy notice does not replace that agreement.

7. International transfers

Our suppliers operate international networks, and data may be processed outside the European Economic Area, including in the United States. We do not promise EU-only storage or processing.

A transfer requires an applicable GDPR safeguard: for example, an adequacy decision covering the actual recipient and processing, or the European Commission’s Standard Contractual Clauses with an assessment of the destination and supplementary measures where needed. A supplier’s general privacy statement alone is not evidence that a particular transfer is covered.

Cloudflare and OpenAI publish their proposed contractual safeguards in their respective Cloudflare data processing addendum and OpenAI data processing addendum. The applicable contracts, recipient entities, countries and mechanisms for Luximio’s actual accounts must be verified before finalisation, including Stripe and the One.com mailbox account. One.com states that it hosts EU customers’ data in Denmark; this does not make the whole Luximio service EU-only.

You can ask us for information about the safeguards applying to your data and a copy of relevant safeguards, subject to necessary redaction of unrelated confidential information.

8. How long information is kept

Retention depends on the purpose and record type. We distinguish an access token becoming invalid from the underlying record being deleted.

InformationCurrent position
Detailed link eventsThe resolver’s daily cleanup removes events older than 90 days. An event may remain until the next successful cleanup. This period does not automatically apply to account records or hosting logs.
Sign-in credentialsSign-in codes expire after five minutes; customer sessions are configured for 30 days with renewal through use. Daily cleanup is configured to remove session and verification records more than 24 hours after expiry. Removal normally occurs 24–48 hours after expiry; batch limits, outages or failed runs can delay it. Valid sessions remain usable.
Authentication rate-limit recordsTemporary records used to limit sign-in attempts become eligible for daily cleanup after more than 24 hours without a request. The same scheduling and backlog limits apply. This does not remove account or security audit history.
Team invitationsUnaccepted invitation links expire after seven days. Daily cleanup is configured to delete invitation records more than 30 days after acceptance or revocation, or after expiry if neither occurred. Removal normally occurs within 30–31 days of that event; batch limits, outages or failed runs can delay it. Inconsistent records are held for review. Deleting an accepted invitation makes its original link unavailable but preserves workspace membership, role and normal dashboard access. This cleanup does not erase team activity history or copies of delivered emails; those records have separate retention and rights-request handling.
App-verification challengesExpired challenge rows become eligible for cleanup one hour after expiry. Installation/key registration records have a separate lifecycle; they are not covered by the 90-day event cleanup.
Contact and support correspondenceOrdinary enquiries are scheduled for deletion six months after resolution and removed at the next monthly retention review. Relevant correspondence may be kept longer for an active dispute or a legal obligation, with the reason recorded. One.com’s account-specific deletion and backup handling still need confirmation.
Accounts, workspace records and audit historyNeeded during the customer relationship for service delivery and administration. Closure, deletion, audit retention and backup expiry procedures must be confirmed; no automatic account deletion period is claimed in this draft.
Hosting and security recordsCloudflare Workers Logs currently has a maximum seven-day retention period for its standard log product. This is not a verified retention period for every hosting, security, email or backup system. Account-specific settings and other providers remain to be checked.
Sandbox billing recordsTest customer, subscription and webhook records can contain or link to personal data. A deletion schedule for the Stripe sandbox and local billing records must be confirmed; test activity is not automatically a statutory tax record.
Legal and financial recordsDutch basic business/tax records are generally retained for seven years; records subject to a specific ten-year rule are retained for that period where applicable. This does not mean that every contact message or account record is kept for seven years. Relevant evidence for an active dispute is retained only as needed for that claim and its applicable limitation period.

Customer-controlled personal data must be returned or deleted under the agreed processing instructions and data processing agreement. Archiving a link, cancelling a subscription or removing a workspace member does not by itself erase every related record.

9. Your privacy rights

Depending on the processing and the conditions in the GDPR, you can:

  • ask whether we process your data and obtain access and a copy;
  • ask us to correct inaccurate data or complete incomplete data;
  • ask for erasure, or for use of your data to be restricted;
  • receive data you provided in a structured, commonly used, machine-readable form and, where feasible, have it sent to another controller, when portability applies;
  • object to processing based on legitimate interests for reasons relating to your situation; we must stop unless the applicable legal grounds allow it to continue;
  • object to direct marketing at any time, if such processing is introduced;
  • withdraw consent at any time where consent is the legal basis, without affecting processing that was lawful before withdrawal.

Email legal [at] luximio.com and mention “Privacy request”; replace [at] with @ and remove the spaces. You do not need to create an account or pay to make an ordinary request. We may ask for proportionate information needed to verify your identity; please do not send an identity document unless it is necessary and we have agreed a suitable method.

We respond without undue delay and normally within one month. Where the GDPR permits an extension for complexity or the number of requests, we explain it within the first month; the extension may be up to two further months. If we cannot comply, we explain why and how you can challenge the decision. Any lawful exception or fee is assessed under the GDPR, not applied automatically.

You may complain to a supervisory authority, in particular in the EU/EEA country where you live, work or believe an infringement occurred. For the Netherlands, contact the Autoriteit Persoonsgegevens. You may complain without contacting us first, and your right to seek a judicial remedy remains available.

10. Security and automated decisions

Current safeguards include HTTPS, access controls for the dashboard, workspace permissions, server-side validation and limits on contact submissions. Secrets are kept outside public website files. Security measures reduce risk; they do not guarantee that every incident can be prevented.

Beta admission is reviewed by a person. Automated controls can reject an invalid sign-in attempt, limit a submission or enforce a plan limit. We do not use the current service to make solely automated decisions producing legal or similarly significant effects about you. If a website security control prevents you from using the contact form, you can email our legal and privacy address directly.

The service is intended for developers and organisations and is not directed at children. Customers remain responsible for the audience of their apps and for any additional requirements when processing children’s data.

11. Changes and contact

We will update this notice when our processing changes and show the revision date. Where required, we will bring a material change to your attention before it applies. A privacy notice is information about processing; it is not a blanket request for consent.

For a question or request, use the legal and privacy email above. Please include enough context to help us identify the account or processing concerned.

Terms of serviceContact usBack to Luximio
luximioLinks that land well.
ContactPrivacyTerms