Privacy Policy
Last updated: 22 September 2026
1. # Privacy Policy
Last updated: 22 September 2026
2. Who is responsible for your data
Lumiqo is a marketing data service operated from Zurich, Switzerland. We are the controller of the personal data described in this policy. Company registration is in progress. The registered name, business ID and address appear in the "Provider details" section of this page on the day they exist. Until then we trade as Lumiqo.
Questions about personal data go to support@lumiqo.net and are answered by the founder, who runs the service. We have not appointed a data protection officer, because the law does not require one at our size.
3. What this policy covers
This policy applies to lumiqo.net, to the Lumiqo service, and to the emails, calls and form submissions we exchange with you. It covers website visitors, people at companies we contact or who contact us, and the users of customer accounts.
It does not cover the advertising, analytics and commerce data that customers connect to Lumiqo from sources such as Meta, Google, TikTok or Shopify. For that data the customer is the controller and Lumiqo is a processor. We handle it only on the customer's documented instructions and only to provide the service, under the Data Processing Agreement that forms Annex 1 of our Terms of Service. The DPA applies from the first moment we process the data, so it is in place before processing begins.
4. What we collect, at a glance
Business contact details we buy or look up: name, title, work email, company, and the software a company publicly uses. Used to contact professionals about the service. Details in section 6.
- Contact and account details: name, work email, company, and billing details, when you contact us, book a demo, submit the contact form, or open an account. Used to answer you, to run the account, and to invoice.
- Files you send for a free data audit: one export from an advertising or commerce platform. Used only to produce the audit report. Details in section 5.
- Technical records of the service: timestamps, actions taken, IP addresses, browser type. Used for security, troubleshooting and reliability.
- Correspondence: emails and form submissions, which we keep with the matter they concern.
5. Where the data comes from
Most of it comes from you: an email, a form on the website, a demo call, or an account you open. The service creates technical records as you use it. We get business contact details for prospecting from business contact databases and public sources such as company websites and LinkedIn pages.
6. The free data audit
When you send a file for a free Data Health Audit, we use it for the audit and for nothing else. The analysis works on aggregate advertising metrics, so it does not need columns that identify people, and we ask you to leave them out. We delete your file and everything derived from it within 30 days of delivering the audit, or immediately if you ask in writing. We do not share the file with anyone and we do not use it to train models.
7. How we find and contact companies
We look for companies that could use the service and contact the people there whose job involves marketing, analytics or data. We hold business details only: name, job title, work email, company, and the technologies the company publicly uses.
The legal ground is legitimate interest: telling professionals about a service that concerns their work. Our first message says where we got your details and how to stop hearing from us. One reply is enough. We remove your details and do not contact you again. You can also object at any time, without giving a reason, by writing to support@lumiqo.net.
If a prospect does not become a customer, we delete their details 12 months after the last contact.
8. Do you have to give us data?
No law obliges you to. Some data is needed to do business: without a name, an email address and billing details we cannot open an account, invoice you or answer an enquiry. Everything beyond that is optional and leaving it out has no consequence.
9. Legal grounds
Swiss data protection law applies to us because we operate from Switzerland, and the GDPR applies where we process data about people in the EU or EEA, which covers most of our customers. Where the GDPR applies we rely on these grounds.
- Performance of a contract, for providing the service you or your company signed up for.
- Legitimate interest, for securing and improving the service and for contacting business contacts as described in section 6.
- Consent, where we ask for it, for example for optional communications.
- Legal obligation, for accounting and tax records.
10. Who else sees the data
We share personal data only with providers we need to run the service and the company. We do not sell or rent it, and we do not use customer platform data for advertising or for anything other than providing the service.
Microsoft Azure hosts the Lumiqo service: storage, compute and monitoring. You choose the hosting region per customer account, and EU regions are available. Azure is the only provider with access to customer platform data. The service is built so that connected data stays inside that infrastructure instead of passing through a chain of vendors, and we intend to keep it that way.
Framer hosts lumiqo.net and runs the contact form. As the web host it receives the technical data any host receives when you load a page: your IP address, browser type and the pages requested. Its built-in visitor statistics count page views without cookies or persistent identifiers. Framer stores contact form submissions in its form inbox and emails them to us.
Our email provider handles support@lumiqo.net and the mail we exchange with you.
No payment processor is used yet. One will be named here before the first paid subscription starts.
11. If we change a provider
Customers authorise the providers above in general. If we intend to add or replace one that handles customer platform data, we update this page and notify customers at least 30 days before the change takes effect. A customer may object on reasonable data protection grounds within that period; if we cannot resolve the objection, the customer may end the affected part of the service without penalty for the rest of the term. To be notified of changes, or to receive the list in a form that suits a vendor review, write to support@lumiqo.net.
Before we engage a provider it has to meet four conditions: security appropriate to the data it handles, data protection terms at least as strict as our own DPA, an adequacy decision or safeguards such as the Standard Contractual Clauses if it processes data outside the EU or EEA, and a defined purpose with access limited to that purpose.
12. Where data is stored and transfers outside the EU
Microsoft Azure stores customer data in the region chosen for that customer, so it can stay in the EU where that is required. Where we transfer personal data outside the EU or EEA, we rely on the European Commission's Standard Contractual Clauses or another safeguard recognised under Article 46 of the GDPR.
13. How long we keep data
- Account and billing data: as long as the account is active, and afterwards for the ten years Swiss bookkeeping law requires.
- Customer platform data: the active dataset holds a rolling window of the most recent 180 days. We move older data to archive storage, under the same encryption and access controls, and keep it there for as long as the subscription is active, so year-on-year comparison stays possible. When an account closes, we delete the data from both the active dataset and the archive. Customers can export it before then. Encrypted backups lose their copies on the backup rotation schedule.
- Audit files: 30 days after the audit, or sooner on request (section 5).
- Prospect details: 12 months after the last contact (section 6).
- Technical records: up to 12 months. We then delete them or aggregate them so they no longer identify anyone.
- Correspondence: as long as the matter it concerns is open, and afterwards as long as the law requires.
14. How we protect it
We encrypt data in transit and at rest. Access is role based: only the people and systems that need the data can reach it, and administrative and infrastructure access requires multi-factor authentication. Our Security page describes the setup in more detail, and a security packet is available on request from support@lumiqo.net.
We make no automated decisions about you that carry legal or similarly significant effects. The forecasts, attribution and scenario figures the service produces are statistical estimates for our customers to use as decision support. The customer decides what to do with them.
15. Your rights and how to use them
You can ask us what personal data we hold about you and receive a copy. You can have it corrected or deleted, ask us to restrict how we use it, object to processing based on legitimate interest, and withdraw consent where consent is the ground. Where we process data by automated means on the ground of a contract or consent, you can receive the data you gave us in a machine-readable format and have us send it to another controller where that is technically possible.
You can object to direct marketing at any time, free of charge and without giving a reason. We then stop.
Write to support@lumiqo.net. We answer within one month. If your personal data sits inside a dataset we process for one of our customers, we may pass your request to that customer, because they control that data.
You can also complain to a supervisory authority. In Switzerland that is the Federal Data Protection and Information Commissioner, Feldeggweg 1, 3003 Bern, +41 58 462 43 95. If you are in the EU or EEA, you can complain to the data protection authority of the country you live or work in, or where the problem happened.
16. Cookies and what the website records
lumiqo.net sets only the cookies needed to make the site work, which do not require consent. There are no advertising or cross-site tracking cookies. Visitor statistics come from Framer's built-in counter, which records page views without cookies or persistent identifiers. Framer's content delivery network serves the fonts, images and scripts, so loading a page discloses your IP address to Framer as our hosting provider and to nobody else.
If we ever add analytics or any other non-essential cookie, we will ask for your consent first, and refusing will be as easy as accepting. Swiss law requires us to tell you about such cookies, and the EU ePrivacy rules require consent before they are set for visitors in the EU. We follow the stricter of the two, which means asking first.
17. Children
Lumiqo is a business service and is not directed at children. We do not knowingly collect personal data from anyone under 16.
18. Changes to this policy
We update this page when our practices change and change the date at the top. We also tell customers directly about changes that affect them.
Questions about this document? Contact us at support@lumiqo.net.