1. Who is responsible
Luximio B.V., established in the Netherlands and registered with the Dutch Chamber of Commerce (KvK) under number 73161721, operates Luximio and is responsible for the controller processing described in this notice.
- VAT ID
- NL002182044B06
- Business address
- Kon. Wilhelminaplein 248
1062 KS Amsterdam
The Netherlands - Telephone
- +31 20 398 6034
- Legal and privacy email
- legal [at] luximio.com
For questions about this notice or to exercise a right, email the address above and mention “Privacy request”. Replace [at] with @ and remove the spaces when entering the address in your email app. You can also contact us by telephone or post using the details above.
For account administration, enquiries and our own service security, the operator acts as a controller: it decides why and how personal data is used. The separate role for customer-managed link data is explained below.
2. Whose data this covers
This notice covers visitors to our marketing website, people who contact us or request beta access, workspace owners and members, and information used to protect the Luximio service.
When a customer uses Luximio to manage links or receive analytics for its app or website, the customer normally determines the purposes of that processing. Luximio processes that customer data on its instructions as a processor. The customer must provide its own privacy notice, and an appropriate data processing agreement must govern our processing for that customer.
If your request concerns an app or link operated by a customer, contact that app or website’s operator first. We can help route a request received by mistake, and assist the responsible customer. We remain responsible for answering requests about processing for which we are the controller.
Links can take you to an app, app store or third-party website. Those destinations have their own privacy practices. Luximio does not control what they collect after you leave our service.
3. Data we use and why
Messages and beta requests
Data: your name, reply email, selected topic, message and subsequent correspondence. Please do not include passwords, API keys or sensitive personal information.
Purpose and legal basis: answering questions, reviewing beta requests and providing support. We rely on steps taken at your request before a contract or performance of a contract when you are the contracting individual (GDPR Article 6(1)(b)). For general enquiries or business contacts acting for an organisation, our legitimate interest is to respond and manage that business relationship (Article 6(1)(f)). Submitting the form does not subscribe you to marketing.
Accounts and workspace administration
Data: email, display name, verification status, workspace membership and role, invitations, app/domain configuration, and records of administrative changes. Account/session records can include an IP address and browser user-agent information.
Purpose and legal basis: signing you in, providing requested features, managing permissions and maintaining an accountable service. Contract performance applies for an individual customer; legitimate interests in administering the customer relationship and protecting workspaces apply for an organisation’s representatives.
Service delivery and protection
Data: IP address, request URL, request time, response/error information, browser/device information, and security signals. A URL may itself contain personal information, so avoid placing personal details or secrets in link paths and destinations.
Purpose and legal basis: delivering pages and links, limiting spam and abusive traffic, investigating faults and protecting accounts. We rely on our legitimate interests in keeping the service available and secure, subject to balancing those interests against your rights. Contact messages and inbox addresses are not included in the contact handler’s application error logs.
Customer link events and app verification
Data: link and project identifiers, hostname/path, event identifier and time, broad platform category, country code when available, referrer origin for browser redirects, and reported app-open/attestation status. The detailed link-events table does not store raw IP addresses or raw user-agent strings; this does not mean that hosting providers never process them.
App verification can also involve an installation identifier, an attestation key identifier/public key, challenges and verification results. Installation-linked records are not automatically anonymous. Customers must provide an appropriate notice and legal basis for their use of app analytics and verification. We process these records on customer instructions and use necessary security information to protect the service.
Billing and legal records
The current private beta does not take live payments. If you use its Stripe test checkout or billing portal, Stripe can still receive personal data: an account email, workspace/customer identifier, selected plan and information you enter on its hosted page. Luximio keeps subscription/customer references, status and event records. Test mode does not make these records anonymous. We use them to test the requested billing features and administer the beta, relying on our legitimate interest in validating a reliable billing service. If live billing is introduced, we will explain the additional payment processing before it starts.
Where we must keep business records or respond to a legally binding request, the legal basis is the applicable legal obligation (Article 6(1)(c)). Where records are needed for a specific dispute, our legitimate interest is establishing, exercising or defending legal claims. We do not use these exceptions to keep unrelated data indefinitely.
Providing a reply email and the information needed to understand an enquiry is necessary for us to answer it. An email address is required to create and sign in to a customer account. You can browse the marketing content without submitting a form. We do not require optional marketing consent as a condition of support or beta access.
4. Where the information comes from
We receive information directly from you when you complete a form, sign in or use the dashboard. A workspace owner or administrator may provide your email when inviting you, and your name or role as part of workspace administration.
Technical information comes from your browser or app requests and from our hosting/security services. Customer apps may submit link events and verification information. Apple or Google can return verification results when the relevant app integration uses their attestation services.
For workspace invitations, we use the email address supplied by the person inviting you to deliver the invitation and manage access. Our legal basis is our legitimate interest in administering workspace invitations. You can object to this use and contact us about your data without accepting the invitation or creating an account.
Where we obtain your personal data indirectly and act as controller, the GDPR requires us to provide the relevant privacy information within one month, at our first communication with you if sooner, or before a first disclosure if sooner, unless a lawful exception applies. Review of other collection points and verification of notice delivery remain part of finalising this draft.
7. International transfers
Our suppliers operate international networks, and data may be processed outside the European Economic Area, including in the United States. We do not promise EU-only storage or processing.
A transfer requires an applicable GDPR safeguard: for example, an adequacy decision covering the actual recipient and processing, or the European Commission’s Standard Contractual Clauses with an assessment of the destination and supplementary measures where needed. A supplier’s general privacy statement alone is not evidence that a particular transfer is covered.
Cloudflare and OpenAI publish their proposed contractual safeguards in their respective Cloudflare data processing addendum and OpenAI data processing addendum. The applicable contracts, recipient entities, countries and mechanisms for Luximio’s actual accounts must be verified before finalisation, including Stripe and the One.com mailbox account. One.com states that it hosts EU customers’ data in Denmark; this does not make the whole Luximio service EU-only.
You can ask us for information about the safeguards applying to your data and a copy of relevant safeguards, subject to necessary redaction of unrelated confidential information.
8. How long information is kept
Retention depends on the purpose and record type. We distinguish an access token becoming invalid from the underlying record being deleted.
| Information | Current position |
|---|---|
| Detailed link events | The resolver’s daily cleanup removes events older than 90 days. An event may remain until the next successful cleanup. This period does not automatically apply to account records or hosting logs. |
| Sign-in credentials | Sign-in codes expire after five minutes; customer sessions are configured for 30 days with renewal through use. Daily cleanup is configured to remove session and verification records more than 24 hours after expiry. Removal normally occurs 24–48 hours after expiry; batch limits, outages or failed runs can delay it. Valid sessions remain usable. |
| Authentication rate-limit records | Temporary records used to limit sign-in attempts become eligible for daily cleanup after more than 24 hours without a request. The same scheduling and backlog limits apply. This does not remove account or security audit history. |
| Team invitations | Unaccepted invitation links expire after seven days. Daily cleanup is configured to delete invitation records more than 30 days after acceptance or revocation, or after expiry if neither occurred. Removal normally occurs within 30–31 days of that event; batch limits, outages or failed runs can delay it. Inconsistent records are held for review. Deleting an accepted invitation makes its original link unavailable but preserves workspace membership, role and normal dashboard access. This cleanup does not erase team activity history or copies of delivered emails; those records have separate retention and rights-request handling. |
| App-verification challenges | Expired challenge rows become eligible for cleanup one hour after expiry. Installation/key registration records have a separate lifecycle; they are not covered by the 90-day event cleanup. |
| Contact and support correspondence | Ordinary enquiries are scheduled for deletion six months after resolution and removed at the next monthly retention review. Relevant correspondence may be kept longer for an active dispute or a legal obligation, with the reason recorded. One.com’s account-specific deletion and backup handling still need confirmation. |
| Accounts, workspace records and audit history | Needed during the customer relationship for service delivery and administration. Closure, deletion, audit retention and backup expiry procedures must be confirmed; no automatic account deletion period is claimed in this draft. |
| Hosting and security records | Cloudflare Workers Logs currently has a maximum seven-day retention period for its standard log product. This is not a verified retention period for every hosting, security, email or backup system. Account-specific settings and other providers remain to be checked. |
| Sandbox billing records | Test customer, subscription and webhook records can contain or link to personal data. A deletion schedule for the Stripe sandbox and local billing records must be confirmed; test activity is not automatically a statutory tax record. |
| Legal and financial records | Dutch basic business/tax records are generally retained for seven years; records subject to a specific ten-year rule are retained for that period where applicable. This does not mean that every contact message or account record is kept for seven years. Relevant evidence for an active dispute is retained only as needed for that claim and its applicable limitation period. |
Customer-controlled personal data must be returned or deleted under the agreed processing instructions and data processing agreement. Archiving a link, cancelling a subscription or removing a workspace member does not by itself erase every related record.
9. Your privacy rights
Depending on the processing and the conditions in the GDPR, you can:
- ask whether we process your data and obtain access and a copy;
- ask us to correct inaccurate data or complete incomplete data;
- ask for erasure, or for use of your data to be restricted;
- receive data you provided in a structured, commonly used, machine-readable form and, where feasible, have it sent to another controller, when portability applies;
- object to processing based on legitimate interests for reasons relating to your situation; we must stop unless the applicable legal grounds allow it to continue;
- object to direct marketing at any time, if such processing is introduced;
- withdraw consent at any time where consent is the legal basis, without affecting processing that was lawful before withdrawal.
Email legal [at] luximio.com and mention “Privacy request”; replace [at] with @ and remove the spaces. You do not need to create an account or pay to make an ordinary request. We may ask for proportionate information needed to verify your identity; please do not send an identity document unless it is necessary and we have agreed a suitable method.
We respond without undue delay and normally within one month. Where the GDPR permits an extension for complexity or the number of requests, we explain it within the first month; the extension may be up to two further months. If we cannot comply, we explain why and how you can challenge the decision. Any lawful exception or fee is assessed under the GDPR, not applied automatically.
You may complain to a supervisory authority, in particular in the EU/EEA country where you live, work or believe an infringement occurred. For the Netherlands, contact the Autoriteit Persoonsgegevens. You may complain without contacting us first, and your right to seek a judicial remedy remains available.
10. Security and automated decisions
Current safeguards include HTTPS, access controls for the dashboard, workspace permissions, server-side validation and limits on contact submissions. Secrets are kept outside public website files. Security measures reduce risk; they do not guarantee that every incident can be prevented.
Beta admission is reviewed by a person. Automated controls can reject an invalid sign-in attempt, limit a submission or enforce a plan limit. We do not use the current service to make solely automated decisions producing legal or similarly significant effects about you. If a website security control prevents you from using the contact form, you can email our legal and privacy address directly.
The service is intended for developers and organisations and is not directed at children. Customers remain responsible for the audience of their apps and for any additional requirements when processing children’s data.
11. Changes and contact
We will update this notice when our processing changes and show the revision date. Where required, we will bring a material change to your attention before it applies. A privacy notice is information about processing; it is not a blanket request for consent.
For a question or request, use the legal and privacy email above. Please include enough context to help us identify the account or processing concerned.