Compliance & Privacy

GDPR, SOC 2 readiness, and data privacy — how LumenFlow handles your data responsibly.

Data privacy#

What we collect#

DataPurposeRetention
Email addressAuthenticationAccount lifetime
ConversationsSidekick functionalityConfigurable
Audit trailCompliance, debuggingPer plan
Usage metricsBilling, analytics2 years

What we don't collect#

  • Conversation content for model training
  • Browsing behavior outside the dashboard
  • Data from connected services beyond what you request

GDPR compliance#

LumenFlow supports GDPR requirements:

RightHow to exercise
AccessExport all data from Settings → Privacy
RectificationEdit profile in Settings → Account
ErasureDelete account from Settings → Account
PortabilityExport data as JSON/CSV
ObjectionContact hello@hellm.ai

Data residency#

ComponentLocation
ApplicationGlobal edge network (nearest region)
DatabaseUS East by default
LLM callsLumenFlow managed inference or your chosen provider's infrastructure

Enterprise customers can work with us on data residency requirements and compliance export expectations.

SOC 2 readiness#

LumenFlow is building toward SOC 2 Type II readiness:

  • Controls in product — action history, evidence capture, access posture
  • Operational baseline — encryption, monitoring, and recovery practices
  • Audit preparation — export and review surfaces that support formal assurance work

Responsible AI#

  • All AI actions go through governance (no uncontrolled execution)
  • Audit trail provides explainability for AI decisions
  • Users control autonomy levels per action type

info For enterprise compliance requirements (HIPAA, FedRAMP), contact hello@hellm.ai for custom arrangements.