LumiPS Privacy Policy

Privacy Policy

This Privacy Policy explains how Alexandra Stancu, trading as LumiPS, collects and uses personal information when you visit lumips.com, complete the diagnostic at lumips.com/diagnostic, create an account, use the LumiPS workspace, subscribe, contact us or otherwise interact with LumiPS.

Effective date: 23 August 2026

1. Who is responsible for your information?

Alexandra Stancu, trading as LumiPS, is the controller of personal information collected for LumiPS’s own purposes.

Business address: 99 Oulton Street, Lowestoft, NR32 3BA, United Kingdom

Privacy contact: hello@alexandra-stancu.com

When a LumiPS business user enters personal information about its own customers, leads, staff or other people, that business normally acts as controller and LumiPS acts as its processor. Requests about that information should usually be directed to the business that entered it. We will assist that business where required.

2. Information we collect

Information you provide

  • Identity and contact information, such as your name, email address, business name and professional details.
  • Account and subscription information, such as account identifiers, plan, trial dates, subscription status and billing history.
  • Diagnostic and workspace content, including answers, prompts, business strategy, funnel information, messaging, text, uploaded material and AI-generated outputs.
  • Communications, feedback and support requests.
  • Marketing preferences and records of consent or objection.

Information collected automatically

  • Device, browser, IP address, approximate location, date and time, pages or features used, referral information and diagnostic or application events.
  • Authentication, security, audit, performance and error logs.
  • Cookies and similar technologies, as described in section 10.

Payment information

Stripe processes payment-card and billing information. We receive limited payment information such as payment status, amount, currency, billing contact details, transaction identifiers and limited card details such as brand and last four digits. We do not receive or store complete card numbers or security codes.

Information about other people

Users may enter personal information about customers, leads, staff or other people. Users must have a lawful basis and provide any required privacy information before submitting it. LumiPS asks users not to submit unnecessary personal data, children’s data, payment-card data, credentials, criminal-offence data or special-category data.

3. How and why we use personal information

We use personal information only where we have an appropriate purpose and lawful basis. Depending on the context, those bases are performance of a contract, steps requested before a contract, our legitimate interests, compliance with legal obligations or consent.

Provide the diagnostic and LumiPS service

We use account, contact, diagnostic, workspace and technical information to create and administer accounts, deliver requested features, generate AI-assisted outputs, save work, authenticate users and provide support. Lawful basis: contract or steps taken at your request before entering a contract. For the free diagnostic where no contract applies, our legitimate interest is providing the requested diagnostic and introducing relevant LumiPS services.

Process payments and manage subscriptions

We use billing and transaction information to start trials, collect payments, manage renewals and cancellations, prevent fraud and keep financial records. Lawful bases: contract, legitimate interests in administering payments and preventing fraud, and legal obligation for tax and accounting records.

Operate, secure and improve LumiPS

We use usage, device, log, support and limited content information to troubleshoot, protect accounts, detect abuse, monitor reliability, understand feature performance and improve the service. Lawful basis: our legitimate interests in running a secure, effective B2B software service. Where consent is legally required for analytics cookies, we rely on consent instead.

Communicate with you

We send service messages about your account, trial, payments, security, support and material service changes. Lawful basis: contract and our legitimate interests in administering the service.

Marketing

We may send relevant information about LumiPS to business contacts where permitted by applicable electronic-marketing law. We rely on consent where required and otherwise on our legitimate interests in marketing our B2B services. You can unsubscribe at any time. We maintain a suppression record so we can respect your choice.

Legal claims and compliance

We may use information to comply with law, respond to lawful requests, enforce our Terms, protect rights and systems, and establish or defend legal claims. Lawful bases: legal obligation and legitimate interests in protecting our business and others.

4. How AI processing works

When you request AI-assisted guidance, relevant prompts, workspace context and submitted content are processed through the AI functionality provided by Lovable. Lovable may use approved AI subprocessors to generate the response. The response is then returned to LumiPS and may be stored with your workspace history.

AI outputs can contain mistakes. LumiPS does not use AI to make legally binding or similarly significant decisions about users. Users must review outputs before relying on or implementing them.

The retention and use of prompts by Lovable and its AI subprocessors depend on Lovable’s service configuration and applicable terms. We do not intentionally authorise customer prompts or outputs to be used to train general-purpose AI models unless we clearly disclose that practice and establish an appropriate lawful basis. Lovable or its subprocessors may retain limited information for security, abuse monitoring, legal compliance, caching or service operation in accordance with their terms. Users should not submit unnecessary personal or sensitive information.

5. Who receives personal information?

We disclose information only where needed for the purposes described above. Recipients may include:

  • Supabase, for database, storage, authentication and application infrastructure;
  • Lovable and its approved AI infrastructure and subprocessors, for application and AI processing;
  • Stripe, for checkout, billing, subscription and fraud prevention;
  • HighLevel/GHL, for operational and marketing email;
  • relevant development, hosting, domain, security, monitoring and technical-support providers;
  • professional advisers, insurers, auditors and authorities where reasonably necessary; and
  • a buyer, investor or successor in connection with a proposed or completed business transaction, subject to appropriate confidentiality and legal protections.

Some providers act as processors on our instructions. Others, including payment providers in some contexts, may act as independent controllers for their own legal, fraud-prevention and service purposes. Their privacy notices explain those activities.

6. International transfers

LumiPS is operated from the United Kingdom and some providers process information in the United States or other countries. Where UK GDPR or EU GDPR transfer restrictions apply, we rely on an applicable adequacy regulation or decision, the European Commission Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, or another lawful safeguard. We assess supplementary measures where required. You may contact us for information about the safeguard relevant to a particular transfer.

7. How long we keep information

  • Active accounts and workspace content: while the account is active and needed to provide LumiPS.
  • Closed accounts and workspace content: deleted or anonymised within 30 days after closure or a valid deletion request, subject to backup cycles, legal duties and dispute or security needs.
  • Backups: retained on restricted backup cycles and deleted or overwritten according to the relevant provider’s schedule.
  • Diagnostic records without an account: kept only for as long as needed to provide the result, understand performance and invite a relevant next step, normally no longer than 24 months unless you request earlier deletion or a longer period is justified.
  • Support communications: normally up to 24 months after the matter closes, or longer where needed for a dispute or legal claim.
  • Billing, tax and transaction records: generally six years after the end of the relevant UK financial year, or longer if legally required in another applicable jurisdiction.
  • Security and technical logs: normally up to 12 months, unless needed longer to investigate an incident or protect the service.
  • Marketing records: until you unsubscribe or object; suppression records may be retained so we do not contact you again.

These are target periods. We may retain information longer where necessary to comply with law, resolve disputes, prevent fraud, enforce agreements or establish legal claims. When information is no longer required, we delete or anonymise it.

8. Security

We use reasonable technical and organisational measures designed to protect personal information, including access controls, authentication, provider security controls, encrypted transmission where supported, restricted administrative access and appropriate backups. No online system is completely secure, and we cannot guarantee absolute security.

If you believe your account or information has been compromised, contact hello@alexandra-stancu.com promptly.

9. Your choices and data-protection rights

Depending on applicable law and the circumstances, you may have rights to:

  • ask whether we process your personal information and obtain a copy;
  • correct inaccurate or incomplete information;
  • ask us to delete information;
  • restrict particular processing;
  • object to processing based on legitimate interests;
  • object at any time to direct marketing;
  • receive certain information in a structured, commonly used and machine-readable format;
  • withdraw consent at any time, without affecting earlier lawful processing; and
  • complain to a data-protection authority.

To exercise a right, email hello@alexandra-stancu.com. We may ask for information reasonably needed to verify identity and locate the relevant records. Rights are not absolute, and lawful exemptions may apply.

You can unsubscribe from marketing by using the unsubscribe link in an email. Service and security messages may still be sent while you hold an account.

Right to object: Where we rely on legitimate interests, you may object to the processing based on your particular situation. You may object to direct marketing at any time. We will stop direct marketing and will stop other objected-to processing unless we have compelling legitimate grounds or need it for legal claims.

10. Cookies and similar technologies

LumiPS may use strictly necessary cookies or local storage for authentication, security, session continuity, subscription functions and user preferences. These technologies are necessary for requested functions and cannot always be disabled without affecting the service.

If LumiPS uses non-essential analytics, advertising or similar cookies, they will be used only after any consent required by applicable law. A cookie banner or settings tool will provide more detail and allow choices. Browser controls may also block or delete cookies.

11. Children

LumiPS is a business service for adults and is not directed to children. You must be at least 18 to create an account. Do not submit children’s personal information to LumiPS. If you believe this has happened, contact us so we can investigate and delete it where appropriate.

12. External links

LumiPS may link to third-party websites or services. Their privacy practices are controlled by them, and this Policy does not cover their independent activities.

13. Complaints

Please contact us first at hello@alexandra-stancu.com so we can try to resolve your concern.

You may also complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint. If the EU GDPR applies, you may complain to the supervisory authority in the EEA country where you live, work or believe an infringement occurred.

14. Changes to this Policy

We may update this Policy to reflect service, provider, legal or operational changes. We will publish the revised version with a new effective date and give additional notice where a change is material.

15. Contact

Alexandra Stancu, trading as LumiPS

Address: 99 Oulton Street, Lowestoft, NR32 3BA, United Kingdom

Email: hello@alexandra-stancu.com