Privacy Statement
How Lumenore Collects, Uses, and Protects Your Information Covering the Lumenore Platform - Insights, Ask Me, Data Magnet, and AI Agents
Version 2.0 | Effective Date: August 21, 2026 | Supersedes Version 1.0
(August 18, 2025)
Lumenore, Inc. - 999 Tech Row, Madison Heights, MI 48071, USA
Questions?
support@lumenore.com |
Privacy: dpo@lumenore.com
At a Glance
This is the plain-language short version. Every point below is explained fully later in this notice, use the table of contents to jump to the details that matter to you.
Who we are: Lumenore, Inc. runs the Lumenore analytics platform dashboards, the Ask Me conversational AI assistant, Data Magnet pipelines, and a set of AI Agents that help you understand your data.
What we collect: Account details you give us (name, email, company), how you use the platform, and only if you turn it on, the questions you ask Lumenore Ask Me.
About your business data: The data your organization connects to Lumenore for analysis belongs to your organization, and we process it only on their instructions. See Section 1.
AI, in one sentence: Most of Lumenore's AI features (the AI Agents) never send your business data anywhere, they work on metadata only. Two features, Generative AI Insights and Generative AI Advance Mode, share data with our AI provider, and both only do so with your explicit, revocable consent. See Section 5.
Selling data: We do not sell your personal information, and we do not share it for cross-context advertising. Ever.
Your rights: Wherever you're located, you can access, correct, delete, or export your personal data, and object to or restrict how we use it. See Section 13.
Table of Contents
- 1. Who This Notice Covers, and Our Role as Controller or Processor
- 2. Information We Collect
- 3. How We Use Your Information
- 4. Our Legal Bases for Processing (EEA / UK)
- 5. Lumenore's AI Features - Full Transparency
- 6. Cookies and Similar Technologies
- 7. How We Share Your Information
- 8. Data Residency, Localization, and International Data Transfers
- 9. How Long We Keep Your Information
- 10. How We Protect Your Information
- 11. Automated Decision-Making and Your AI Rights
- 12. Children's Privacy
- 13. Your Privacy Rights
- 14. Notice for Healthcare Customers (HIPAA)
- 15. Do-Not-Track Signals
- 16. Changes to This Notice
- 17. How to Contact Us
- Appendix A - CCPA / CPRA Personal Information Categories
- Appendix B - Revision History
- Appendix C - Intellectual Property / Copyright (DMCA) Notice
1. Who This Notice Covers, and Our Role as Controller or Processor
Lumenore wears more than one hat, and which hat we are wearing changes what this notice means for you. Read this section first; it tells you which part of this notice applies to you.
1.1 If you visit our website (lumenore.com)
We collect basic information about your visit: the pages you view,
cookies, and any details you submit through a form, such as a demo
request. Lumenore is the controller, the party that decides why and
how this data is used for this information.
1.2 If you are a registered Lumenore user (a subscriber, or a
subscriber's employee)
We collect your account details, such as your name, email address, and
login activity, to run your account and the Services you use. Lumenore
is the controller for this account data.
1.3 If your organization connects its own data to Lumenore
("Business Data")
Lumenore's platform is built for your organization to connect,
analyze, and ask questions about its own data like customer records,
sales figures, operational files, and similar business information. If
that data includes personal information about other people (your
customers, employees, or patients, for example), your organization is
the controller of that data, and Lumenore is a processor (sometimes
called a "service provider"), acting only on your organization's
instructions and under the data processing terms in your
organization's agreement with us.
If you are one of those individuals, for example, an employee or
customer of a company that uses Lumenore, please direct any privacy
request about your data to that company directly. We will support them
in responding to you, but we do not have a direct relationship with
you and generally cannot act on your request ourselves.
1.4 If you use an application that embeds Lumenore's analytics
Some of our customers embed Lumenore's dashboards and AI features
inside their own products through our Embedded Analytics and Decision
Intelligence capabilities. If that is how you are encountering
Lumenore, the company whose application you are using is the
controller, and its own privacy notice, not this one, governs how your
data is used. Lumenore acts as that company's processor.
1.5 What this notice does not cover
This notice doesn't cover personal information we collect in the
context of employment (job applicants and Lumenore employees have a
separate notice), or information collected by third-party websites and
services we merely link to.
2. Information We Collect
What we collect depends on how you interact with us. Here's the full picture, in plain terms:
- Account and contact details. Your name, work email address, and company, collected when you register, request a demo, or contact us.
- Usage data. How you use the platform, pages viewed, features used, login times, device and browser type. This helps us run the Services and fix problems.
- Social login data. If you use social login (e.g., signing in through a third-party account), we receive basic profile details from that provider, typically your name, email, and profile picture. See Section 7 for how we handle this.
- Business Data you or your organization connect. The data your organization connects to the platform through Data Magnet, our 50+ connectors, or file uploads. This is your organization's data, controlled by your organization (see Section 1.3), and we process it under their instructions.
- Prompts and questions you ask Lumenore Ask Me. If your organization enables Generative AI Insights, the questions and prompts you type into Lumenore Ask Me. This only leaves the Lumenore environment with your explicit consent, see Section 5.
- Cookies and similar technologies. Small files stored on your device to run and secure the website and, if you agree, to understand site usage and show relevant content. See Section 6.
We do not knowingly collect sensitive categories of personal information, such as data about health, race, religion, or sexual orientation, as part of your Lumenore account. If your organization's own Business Data happens to include such categories, for example, a healthcare customer's patient records that data is controlled and classified by your organization, and Section 14 explains our role under HIPAA.
All personal information you give us should be accurate and current. Please let us know if anything changes.
3. How We Use Your Information
We use the information above for the following purposes:
- To run your account. Creating and managing your account, keeping you logged in, and keeping your account secure.
- To deliver the Services. Providing the dashboards, pipelines, and AI features you and your organization subscribe to.
- To support you. Responding to your questions and resolving issues you report.
- To power AI features you choose to use. Generating answers and insights when you use Lumenore Ask Me with Generative AI Insights turned on always with your consent. See Section 5.
- To keep the platform secure. Detecting fraud, securing our systems, and investigating misuse.
- To market to you, if you've agreed to hear from us. Sending product updates or promotional messages, only where permitted and always with an opt-out.
- To improve our products. Understanding how our products are used, in aggregate, so we can improve them.
- To comply with the law. Meeting our obligations under law, regulation, or legal process.
If we ever want to use your information for a new purpose that isn't listed here, we'll ask for your consent first or update this notice and tell you.
4. Our Legal Bases for Processing (EEA / UK)
If you're in the European Economic Area, the UK, or another jurisdiction with similar requirements, we rely on one of the following legal grounds each time we process your personal information:
Where we rely on consent, we keep the choice clear and separate from the rest of the service. This includes consent for non-essential cookies, marketing communications, and Generative AI Insights where business data may be shared with the secure AI provider. You can withdraw consent at any time using the same channel where you gave it, by changing cookie settings, disabling the relevant product feature, unsubscribing from marketing, or contacting us.
- Consent. For anything that needs your permission, such as enabling Generative AI Insights or sending you marketing emails. You can withdraw consent at any time, and doing so will not affect anything we did before you withdrew it.
- Performance of a contract. To provide the Services you've signed up for, under our contract with you or your organization.
- Legitimate interests. Where processing is reasonably necessary for running our business, for example, keeping the platform secure or understanding aggregate product usage, and this doesn't override your own rights and interests.
- Legal obligation. Where we're required by law, for example, responding to a lawful request from a regulator or court.
- Vital interests. In rare cases, to protect someone's life or safety.
If you're located in Canada, we rely on your express or implied consent for most processing, which you may withdraw at any time, subject to the limited legal exceptions (such as fraud prevention or legal compliance) that Canadian privacy law recognizes.
5. Lumenore's AI Features - Full Transparency
Lumenore uses artificial intelligence throughout the platform to answer your questions in plain English, to explain why a metric moved, to build charts, and to forecast what's coming next. This section explains, feature by feature, what data each one uses and where that data goes. If you take away one thing from this notice, we'd like it to be this section.
5.1 The AI features on the platform
- Lumenore Ask Me - A conversational assistant. Ask it a question in plain English about your data, and it will pull the answer, chart, or explanation together for you.
- AI Agents - A team of specialized AI Agents work behind Ask Me: an NLQ Agent that turns your question into a data query, a Root-Cause Analysis Agent that explains why a number moved, a Visualization Agent that builds and edits charts, and a Data Science Agent that runs forecasts and detects anomalies. A Master Agent routes your question to the right one.
- Predictive Analytics and AutoML - Machine-learning forecasting and anomaly detection built into your dashboards.
- Generative AI Insights - Generates plain-language narrative summaries of your data using a large language model. This is the one feature where your business data can leave the Lumenore environment, see 5.3 below.
- Generative AI Advance Mode - A more powerful mode for complex business questions that need multi-step reasoning, for example, "why did our profit margin decline last quarter, and which product lines drove it?" Answering questions like this means analyzing across several metrics and data sources at once, more than our metadata-only AI Agents are built for. This is the other feature where your business data can leave the Lumenore environment, see 5.4 below
When you're chatting with Lumenore Ask Me, you're interacting with an AI system, not a human being. We want that to always be obvious to you, and it's why Ask Me identifies itself as an AI assistant in the product.
5.2 What each feature does with your data
This is the single most important table in this notice. Most of
Lumenore's AI runs on metadata only that means it works with the shape
and structure of your data (schema, statistics, query patterns), not
the underlying records themselves. Only one feature is different.
| Feature | Does data leave Lumenore? | What actually happens |
|---|---|---|
| AI Agents (NLQ, Root-Cause Analysis, Visualization, Data Science, Master) | No | These agents work on metadata only. They don't transmit your underlying business records outside the Lumenore environment. |
| Generative AI Insights | Yes, securely, and only with your consent | Your prompt and the relevant business data are sent to Microsoft's Azure OpenAI Service to generate a narrative answer. See 5.3–5.4. |
| Generative AI Advance Mode | Yes, securely, and only with your consent | For complex, multi-step business questions (e.g., profit/loss driver analysis), your prompt and the broader business data needed to reason through the question are sent to Microsoft's Azure OpenAI Service. See 5.4. |
| Every other platform feature (dashboards, Data Magnet, storage, embedded analytics) | No | No business data leaves your organization's Lumenore environment. |
5.3 Generative AI Insights - your consent, your control
Before any business data is shared for AI-insight generation, we ask
you to explicitly agree to it. You can withdraw that consent at any
time for sensitive data, and turn it back on for non-sensitive data,
right from the same screen where the insight is generated. If you
never turn this on, this data flow never happens.
"Business data shared for generating AI insights is protected by a secure AI layer and is never used to train any model."
That's the exact notice you'll see in the product, and it's a commitment we stand behind. Here's what it means in practice, once you've given consent:
- Encrypted in transit. Your prompt and the business data needed to answer it travel over encrypted connections to Microsoft's Azure OpenAI Service.
- Not the public OpenAI service. We use Azure OpenAI Service, hosted inside Microsoft's enterprise Azure environment. We do not use the public OpenAI consumer product, and your data is not shared with OpenAI.
- No training, limited retention. Microsoft does not use your prompts or data to train or improve its models. Data is kept only as long as needed to generate your answer; plus a short window Microsoft uses to monitor for abuse of the service.
5.4 Generative AI Advance Mode - advanced business reasoning
Advance Mode exists for questions that go beyond a single chart or
metric; the kind of logical, multi-step reasoning a financial analyst
would do by hand, like tracing a profit or loss back to the product
lines, regions, or cost centres driving it. To reason through a
question like that, Advance Mode needs a wider view of your business
data than our standard metadata-only agents work with, so it uses the
same generative AI pathway as Generative AI Insights, described in
5.3.
- Same consent standard. Advance Mode is off by default. Turning it on requires the same explicit, revocable consent as Generative AI Insights, set separately from the screen where you use it. If you never turn it on, no data is shared for this feature.
- Same infrastructure. Advance Mode queries are processed by Microsoft's Azure OpenAI Service, the same enterprise environment described in 5.3, never the public OpenAI product, and never shared with OpenAI directly.
- Same no-training commitment. Data shared through Advance Mode is not used to train or improve any model and is retained only as long as needed to generate your answer, on the same terms as Generative AI Insights.
- A practical note. Because Advance Mode reasons across a broader set of business data to answer complex questions, we'd recommend it for less sensitive, aggregate-level business questions (like margin or profitability analysis) rather than queries that pull in granular personal data about individuals.
5.5 The agreements standing behind that promise
This isn't just a policy statement; it's backed by contract:
- Microsoft's Data Protection Addendum (DPA). Microsoft processes this data as our sub-processor under the Microsoft Products and Services Data Protection Addendum, which builds in the EU Standard Contractual Clauses for international transfers and reflects GDPR and UK GDPR requirements.
- Business Associate Agreement (BAA) for health data. If your organization is a healthcare customer and Business Data may include protected health information, we rely on Microsoft's Business Associate Agreement covering the Azure OpenAI Service. Lumenore, in turn, can act as a business associate or service provider to you for that data. See Section 14.
5.6 Extra control, if you want it
- Bring Your Own Key (BYOK). Bring your own AI provider API key and manage your own relationship with the model provider, giving you direct control over your data and costs.
- Local LLM Integration. If your organization needs to keep sensitive data fully in-house, Lumenore supports connecting Ask Me to a self-hosted or on-premises model instead of a cloud-hosted one. In this mode, no data leaves your environment at all.
- The Firewall Policy Engine. Every request is checked against your organization's own data-governance rules by content type, data type, and intended use before it's allowed to proceed. If a request doesn't meet your organization's policy, it's blocked automatically.
5.7 AI outputs can be wrong - please double-check anything
important
Like any AI system, Lumenore's AI Agents and Generative AI Insights
can occasionally get things wrong, miss context, or misinterpret a
question. We design these features to show their work, the underlying
numbers, charts, and reasoning behind an answer so you can verify it
rather than take it on faith. Please review AI-generated output before
relying on it for an important decision, and treat it as a starting
point, not a final word.
5.8 Automated decisions about you
Lumenore's AI features are built to support human decision-making, not
replace it. We do not use AI to make fully automated decisions that
produce legal or similarly significant effects about you, for example,
decisions about hiring, credit, insurance, or medical treatment
without a human being involved. If your organization has configured
its own workflow to act on Lumenore's output without human review,
that configuration and its consequences are your organization's
responsibility, not Lumenore's. See Section 11 for your rights around
automated decision-making.
6. Cookies and Similar Technologies
Cookies are small text files stored on your device when you visit our website. They help the site work properly, keep it secure, and let us understand how it's used.
6.1 The kinds of cookies we use
| Type | What it's for | Can you turn it off? |
|---|---|---|
| Strictly necessary | Lets you log in, navigate the site, and use secure areas. | No, these are required for the site to function. |
| Preference | Remembers choices you've made, like language or display settings. | Yes |
| Statistics / performance | Aggregated, anonymized data on how the site is used, so we can improve it. | Yes |
| Marketing | Helps us show you relevant content and measure campaign performance. We do not use these to build advertising profiles for sale to third parties. | Yes |
Cookies can also be classified by how long they last (session cookies disappear when you close your browser; persistent cookies stay until they expire or you delete them) and by origin (first-party cookies come from lumenore.com directly; third-party cookies come from a partner we work with, like an analytics provider).
6.2 Managing your preferences
- Use the Cookie Settings button on the lumenore.com homepage at any time to review, accept, reject, or change choices for non-essential cookies, including preference, statistics/performance, and marketing cookies.
- Your browser can also block or delete cookies directly, check your browser's support pages (Chrome, Safari, Firefox, or Edge) for instructions.
- If you're in California or another state that recognizes the Global Privacy Control (GPC), we honor GPC signals as a valid request to opt out of the "sharing" of your information for cross-context advertising purposes, described further in Section 13.2.
Turning off non-essential cookies won't stop you from using the platform, but some website features may work less smoothly.
7. How We Share Your Information
We share personal information only in the limited situations below. We do not sell your personal information, and we never have.
- Microsoft Azure OpenAI Service (only for Generative AI Insights and Advance Mode). Microsoft processes prompts and business data on our behalf, strictly to generate Generative AI Insights and Generative AI Advance Mode answers, and only when you've consented. This is governed by the Microsoft DPA and, for regulated health data, a HIPAA Business Associate Agreement. See Section 5.4.
- Other service providers. We use a small number of vetted vendors to run the platform for hosting, email delivery, customer support, and analytics, each bound by a written contract that limits their use of your data to the services they provide us.
- Social login providers. If you sign up using a third-party account, that provider shares basic profile information with us (typically your name, email, and profile picture). We only use it as described in this notice.
- Business transfers. If Lumenore is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to the same protections described here.
- Legal and regulatory requests. We may disclose information where required by law, for example, in response to a valid subpoena, court order, or regulatory request.
We don't disclose personal information to any other third party outside these situations.
8. Data Residency, Localization, and International Data Transfers
This section explains where your data physically lives, and what happens when it needs to cross a border.
8.1 Where your data is stored
Lumenore's primary servers are located in the United States, and
that's where most account data, Business Data, and platform content is
stored and processed by default.
8.2 Other locations your data may be processed in
Depending on the specific service you use, your information may also
be processed in India or other countries where Lumenore or our service
providers operate for example, for customer support or specific
infrastructure functions. Section 7 lists the categories of providers
involved.
8.3 Where AI processing happens
When you use Generative AI Insights or Generative AI Advance Mode
(Section 5), your prompt and the relevant business data are processed
by Microsoft's Azure OpenAI Service. This runs on Microsoft's global
Azure infrastructure; if your organization's agreement with Lumenore
specifies a particular Azure region for this processing, that
commitment governs. If nothing specific is contracted, processing may
occur in any region where Azure OpenAI Service operates, subject to
the same Microsoft DPA protections described in Section 5.5.
8.4 If your organization needs data to stay in a specific
jurisdiction
Some organizations particularly in government, healthcare, or
financial services, operate under a legal or contractual requirement
that data stay within a specific country or region. If that applies to
you, contact us at
dpo@lumenore.com to discuss what
data-localization options are available under your agreement. Local
LLM Integration (Section 5.6) is also worth considering here, since it
can keep AI processing entirely within your own environment.
8.5 Backups
Backup copies of your data may be stored in the same locations
described above, or in additional secure locations used for disaster
recovery. Backups follow the same retention and deletion commitments
as your primary data, see Section 9.
8.6 Cross-border transfer safeguards
If you're in the European Economic Area, the UK, or Switzerland, your
information may be transferred to a country that doesn't have the same
data protection laws as your own. When that happens, we put safeguards
in place, most often the European Commission's Standard Contractual
Clauses to require anyone receiving that data to protect it to the
same standard as European law requires. You can request a copy of
these safeguards by contacting
dpo@lumenore.com.
9. How Long We Keep Your Information
We keep personal information only as long as we need it for the purposes in this notice, or as long as the law requires.
- Account data. If your account is deactivated, we retain your account data for up to four weeks (28 days), after which it's automatically deleted.
- After a deletion request. Once we complete an approved deletion request, your data is removed from active systems and fully purged from backups within 30 days.
- AI insight data. Data shared for Generative AI Insights isn't retained by Microsoft for model training and is kept only for the limited period described in Section 5.3.
Where we can't delete data outright, for example, because it's needed for a legal or tax requirement, we securely isolate it from further use until deletion becomes possible.
10. How We Protect Your Information
We use a combination of organizational and technical safeguards to protect your data, built around recognized security frameworks:
- Certified cloud infrastructure. Our platform runs on Microsoft Azure, which holds its own ISO/IEC 27001, SOC 1, SOC 2, and PCI DSS certifications for the infrastructure we build on.
- Our own security assurance. Lumenore has achieved SOC 2, reflecting an independent assessment of our controls for security and data protection. Our internal security program is also structured with reference to the ISO/IEC 27001 information-security management standard.
- Access control. Role-based access control and row-level security mean users only see the data they're authorized to see, whether they reach it through a dashboard or an AI Agent conversation.
- Encryption. Data in transit for Generative AI Insights, and account authentication, are protected using industry-standard encryption.
- Incident response. We follow a defined process to detect, contain, investigate, and communicate about security incidents, and to apply lessons learned. If you suspect a security issue, contact security@lumenore.com.
No system connected to the internet can be 100% secure, and we can't guarantee that unauthorized third parties will never defeat our safeguards. But we work continuously to reduce that risk, and we'll notify affected customers promptly if we ever become aware of a breach affecting their data, consistent with our legal obligations.
11. Automated Decision-Making and Your AI Rights
As explained in Section 5.8, Lumenore does not use AI to make fully automated decisions with legal or similarly significant effects on you without a human being involved. If you believe an AI-influenced decision has been made about you without appropriate human review, whether by Lumenore directly or by an organization using Lumenore, you can:
- Ask us (or the organization responsible for the decision) to explain the reasoning behind it.
- Request that a human review the decision.
- Contest the decision and ask for it to be reconsidered.
If Lumenore is the party responsible, contact dpo@lumenore.com. If the decision was made by an organization using the Lumenore platform, we'd encourage you to raise it with them directly, since they control how AI-generated output is used in their own processes.
12. Children's Privacy
Lumenore is a business platform, and it isn't directed at children. We don't knowingly collect personal information from anyone under 18. By using the Services, you confirm that you're at least 18, or that you're a parent or guardian consenting to a minor's use of the Services on their behalf.
If we learn that we've collected personal information from someone under 18 without appropriate consent, we'll deactivate the account and delete that data. If you believe this has happened, please contact support@lumenore.com.
13. Your Privacy Rights
If your request relates to personal information in your Lumenore account, website interaction, or direct relationship with us, we will respond as the controller. If your request relates to Business Data that your organization connected to Lumenore, your organization is usually the controller, and we will support them in responding to you under our contract with them.
13.1 If you're in the EEA, UK, or Switzerland
| Right | What it means |
|---|---|
| Access | Get a copy of the personal information we hold about you. |
| Rectification | Ask us to correct inaccurate or incomplete information. |
| Erasure | Ask us to delete your personal information, in certain circumstances. |
| Restriction | Ask us to pause processing your information while a concern is resolved. |
| Objection | Object to processing based on our legitimate interests, including for marketing. |
| Portability | Receive your data in a portable format, or have it sent directly to another provider. |
| Withdraw consent | Withdraw any consent you've given us, at any time, without affecting past processing. |
We will respond to your request within one month of receiving it. If your request is complex, we may extend this by up to two further months, and we will let you know if that is necessary. If you believe we are processing your data unlawfully, you also have the right to complain to your local data protection authority. For the EEA, you can find contact details at ec.europa.eu/justice/data-protection/bodies/authorities; for the UK, at ico.org.uk; and for Switzerland, at edoeb.admin.ch.
13.2 If you're in California or another US state with privacy
rights
California's CCPA and CPRA, and similar laws in a growing number of
other states, give you the following rights. We apply this same
standard across the United States as a matter of practice:
- Right to know. Know what personal information we've collected about you, and why.
- Right to delete. Ask us to delete personal information we've collected from you, subject to certain legal exceptions.
- Right to correct. Ask us to fix inaccurate personal information.
- Right to opt out of sale or sharing. We don't sell personal information, and we don't share it for cross-context behavioral advertising, so there's nothing to opt out of, but you can confirm this in writing at any time.
- Right to limit use of sensitive personal information. We've told you in Section 2 that we don't knowingly collect sensitive personal information through your Lumenore account, so this right doesn't apply to account data. If that ever changes, we'll update this notice and give you a way to limit its use.
- Right to non-discrimination. We won't charge you more, or provide worse service, because you exercised a privacy right.
- "Shine the Light" and minors' erasure rights. If you're a California resident and under 18, you can ask us to remove content you've publicly posted through the Services.
We'll act on a request to opt out as soon as feasible, and no later than 15 business days. For access, deletion, and correction requests, we'll respond within 45 days, with a possible 45-day extension for complex requests. See Appendix A for the full CCPA personal information category disclosure.
13.3 If you're in Canada
You can access the personal information we hold about you, ask us to
correct it, and withdraw any consent you've given us, subject to
limited legal exceptions (such as fraud investigation or legal
compliance).
13.4 How to exercise any of these rights
- Visit lumenore.com/privacy-dsar to submit a request directly.
- Or email us at support@lumenore.com, or dpo@lumenore.com for privacy-specific questions.
To protect your information, we'll need to verify your identity before acting on a request, usually by matching details you provide against what we already have on file. We'll only use what you give us for verification, and we'll delete any extra information you provide for that purpose once we're done. You can also name an authorized agent to submit a request on your behalf, provided they can show proof of that authorization.
14. Notice for Healthcare Customers (HIPAA)
Some Lumenore customers work in healthcare and connect data that includes protected health information (PHI) under the U.S. Health Insurance Portability and Accountability Act (HIPAA). This section explains our role.
- Our role. Where a customer connects PHI to the platform, Lumenore acts as that customer's business associate, under a signed Business Associate Agreement (BAA), and processes PHI only as permitted by that agreement and HIPAA's minimum-necessary standard.
- AI processing and PHI. Microsoft offers a BAA that extends to the Azure OpenAI Service, which underpins both our Generative AI Insights and Generative AI Advance Mode features. This means the same HIPAA-grade protections apply when a healthcare customer chooses to use that feature with health data.
- Breach notification. If we become aware of a breach involving PHI, we'll notify the affected covered entity without unreasonable delay, consistent with HIPAA's breach notification requirements.
- If you're a patient. As a patient, Lumenore isn't your healthcare provider and doesn't have a direct relationship with you. If you have a question about how your health information was handled, please contact your healthcare provider or health plan (the "covered entity") directly, they can involve us if needed.
15. Do-Not-Track Signals
Some browsers offer a "Do Not Track" (DNT) signal. There is currently no industry-agreed standard for how websites should respond to it, so we do not currently respond to DNT signals. If a common standard emerges, we will update this notice to explain how we handle it. Note: we do honor the Global Privacy Control signal, see Section 6.2.
16. Changes to This Notice
We will update this notice as our practices or the law changes. The "Effective Date" at the top always reflects the current version. If we make a material change, we will post a prominent notice or notify you directly, and we will keep a full history of changes in Appendix B. We encourage you to check back periodically.
17. How to Contact Us
We want to hear from you if you have questions, concerns, or a request relating to this notice.
| Purpose | Contact |
|---|---|
| General questions about this notice | support@lumenore.com |
| Privacy-specific questions and data subject requests | dpo@lumenore.com | lumenore.com/privacy-dsar |
| Security incident reporting | security@lumenore.com | +1 (248) 204-8881 |
| Whistleblower / ethics reporting (confidential) | whistleblower@lumenore.com | +1 (248) 204-8881 |
| Copyright / DMCA notices | dpo@lumenore.com (see Appendix C) |
| Postal address | Lumenore, Inc., 999 Tech Row, Madison Heights, MI 48071, USA |
Appendix A - CCPA / CPRA Personal Information Categories
California law asks us to disclose, by defined category, what personal information we've collected in the past 12 months. This reflects our good-faith assessment, not every example within a category applies to every user, since much depends on what you've chosen to share with us.
| Category | Examples | Collected? |
|---|---|---|
| A. Identifiers | Name, email address, IP address, account name | Yes |
| B. Customer records (Cal. Civ. Code §1798.80(e)) | Name, contact details; we do not collect Social Security numbers, financial account numbers, or medical information as account data | Partial, see note |
| C. Protected classifications | Age, race, religion, sex, disability, and similar characteristics | No |
| D. Commercial information | Records of products or services considered or purchased (e.g., subscription plan) | Yes |
| E. Biometric information | Fingerprints, voiceprints, and similar data | No |
| F. Internet / network activity | Interaction with our website and Services | Yes |
| G. Geolocation data | Precise physical location | No |
| H. Sensory data | Audio, visual, or similar recordings | No |
| I. Professional / employment information | Job title, employer (as provided at account setup) | Yes |
| J. Education information | Records covered by FERPA | No |
| K. Inferences | Profiles reflecting preferences or characteristics | No |
We haven't sold or disclosed personal information for a business or commercial purpose in the preceding 12 months, and we don't intend to.
Appendix B - Revision History
We keep a record of material changes to this notice, so you can see what's changed and when.
| Version / Period | Product and Solution Progression | Privacy Notice Update |
|---|---|---|
| Foundation phase | Lumenore established its core business intelligence and analytics platform, focused on dashboards, reporting, governed access, and self-service analytics for enterprise teams. | Baseline privacy commitments covered account data, customer-controlled Business Data, use of service providers, security practices, and customer support channels. |
| Data integration phase | Lumenore expanded into enterprise data integration through Data Magnet, enabling low-code extract, transform, and load workflows and connections to multiple enterprise data sources. | Notice language was strengthened to explain customer-controlled Business Data, processor/service-provider roles, connected data sources, retention, deletion, and data-security safeguards. |
| Conversational analytics phase | Lumenore introduced Ask Me, allowing authorized users to ask business questions in natural language and receive governed answers, charts, and explanations without writing queries. | The notice was updated to cover prompts, conversational interactions, AI assistant transparency, user controls, and the distinction between account data and customer-controlled analytics data. |
| AI and automation phase | Lumenore added AI Agents, including natural-language querying, root-cause analysis, visualization support, data-science forecasting, anomaly detection, and routing through a Master Agent. | The notice was expanded with feature-level AI transparency, human review expectations, automated decision-making safeguards, role-based access, row-level security, and AI output verification language. |
| Generative AI and enterprise-control phase | Lumenore developed Generative AI Insights and Generative AI Advance Mode and enterprise controls such as BYOK, local LLM integration, policy-based blocking, and secure AI-layer governance for sensitive deployments. | The notice was updated to make consent, data minimization, secure AI processing, non-training commitments, revocable consent, and customer-controlled AI configuration clearer. |
| Version 2.0 - August 21, 2026 | Current audit-ready SaaS privacy notice covering Lumenore's full platform context: Insights, Ask Me, Data Magnet, AI Agents, Generative AI Insights, embedded analytics, healthcare use cases, and enterprise security controls. | Full plain-language refresh aligned to GDPR, UK GDPR, CCPA/CPRA, HIPAA where applicable, ISO/IEC 27001-aligned practices, SOC 2 assurance expectations, cookie consent, privacy rights, AI transparency, and customer due-diligence needs. |
Appendix C - Intellectual Property / Copyright (DMCA) Notice
This appendix is a copyright notice, not a data-privacy matter. We have kept it here because it uses the same contact channel as the rest of this notice. If you believe content on our site infringes your copyright or other intellectual property rights, please send a notice to dpo@lumenore.com or by post to Lumenore, Inc., 999 Tech Row, Madison Heights, MI 48071, USA, including:
- A description of the copyrighted work you claim has been infringed, and where it appears on our site.
- A statement that you have a good-faith belief the use is unauthorized.
- A statement, made under penalty of perjury, that your notice is accurate and that you're the rights holder or authorized to act on their behalf.
- Your contact details and signature (physical or electronic).
We'll respond consistent with the Digital Millennium Copyright Act of 1998. Please note that under 17 U.S.C. § 512(f), knowingly misrepresenting that content is infringing can create liability for damages, including our costs and attorneys' fees.