DRAFT — not yet reviewed by counsel

LUMA AI STUDIO Privacy Policy

Drafted 18 September 2026

LUMA AI STUDIO (“we”) builds software and devices for shops and restaurants. This policy says where we handle personal data, what we handle, why, and for how long.

★ We act in two different roles, and that distinction is the backbone of this document.

1. Our two roles

RoleWhose dataExample
Controller (we decide)Staff of our business customersConsole accounts, sign-in records, support requests
Processor (the customer decides; we act on their instructions)Guests in our customers’ venuesKiosk loyalty, orders, in-store camera statistics

★ For guest data, the venue decides what is collected, and we process it on their instructions. Guests exercise their rights through the venue; we provide the tools the venue needs to act on those requests (§6).

2. What we collect and why

We list only what we actually store. Anything not listed is not stored.

2-1. Customer staff (console users)

DataPurposeBasis
Email, name, password (hashed), two-factor settingsAccount creation, sign-in, identity checksPerformance of contract
Sign-in records (IP, browser, time)Security, abuse prevention, statutory access logsLegal obligation / legitimate interest
Role and venue scopeAccess controlPerformance of contract
Audit records (who did what, when)Incident response, dispute resolutionLegal obligation / legitimate interest
POS elevation PIN (hashed)Confirming sensitive actions such as price changesPerformance of contract

2-2. Guests — kiosk loyalty

★ We do not store phone numbers. There is no such column in our database. To find a member we use a one-way value (SHA-256 mixed with a secret unique to each venue) plus the last four digits so a guest can recognise their own record.

DataPurpose
One-way value derived from the phone number, last four digitsIdentifying the member, earning and spending points
Member code, point balance and historyRunning the loyalty programme
Consent version and time, marketing consent timeConsent management
Date last usedCalculating the retention period

2-3. Guests — orders

  • We store order number, table, items, amounts, payment method and time.
  • We do not store a guest’s name, phone number, address or email on an order.
  • ★ We do not store card numbers, expiry dates or CVC — there are no such columns. We keep only the reference the payment provider returns, and we do not interpret it.
  • Where a cash receipt is issued, its number may be recorded. [TO BE DECIDED — retention and masking]

2-4. In-store cameras (only where installed)

★ We do not store video. We do not store face images, face templates, identifiers that link a person across time, or movement paths. There are no such columns, and both the server and the device reject an entire batch if a value with such a name appears. Frames are turned into numbers on the device and discarded there.

  • We store: counts per time slot, total dwell time per zone, estimated aggregate age-band and gender counts, grid occupancy totals, and device health values.
  • Cells with few people are merged before storage, and smaller cells are hidden from display.
  • A notice at the entrance states that cameras are in use and why.

2-5. Devices and diagnostics

  • We store device serial, model, firmware and health signals.
  • We may collect device logs to diagnose faults. Emails, phone numbers and tokens are masked before the logs are used.
  • ★ The unmasked original log is retained in storage for a period. [TO BE DECIDED — retention]
  • If screen capture is used, the screen image is stored. On a kiosk or call display this may include order numbers. [TO BE DECIDED — retention]

2-6. Mobile manager app

  • The app is a shell around our web screens; it collects nothing of its own.
  • Your signed-in state is kept only on the device.
  • If QR scanning is enabled the camera is used. Captured images never leave the device and are not stored.
  • If notifications are enabled we store a device token used to deliver them.

3. How long we keep data

DataRetentionHow it ends
Kiosk membersAt least 12 months from last use (set by the venue)Automatic anonymisation — the derived phone value, last four digits and marketing consent are erased and any remaining points expire. The point ledger keeps only a number, for accounting.
Cameras — ad exposureKR/US 395 days / EU and elsewhere 90 daysDeleted; monthly totals kept
Cameras — zones, age/gender, dwellKR/US 90 days / EU and elsewhere 31 daysDeleted
Cameras — device health30 daysDeleted
Cameras — monthly totals25 monthsDeleted
Cameras — deletion records60 monthsKept as evidence
Price-tag display records90 days by defaultDeleted
Orders and accounting recordsAs required by law[TO BE DECIDED — per country]
Console accounts, sign-in records, audit logs[TO BE DECIDED][TO BE DECIDED]

★ Of the above, the deletions that actually run every day today are kiosk member anonymisation, camera retention, and price-tag display records. The rest are still being defined (§9).

4. Processors and disclosure

We do not sell personal data. We use the following processors to run the service.

ProcessorPurposeLocation
Render Services, Inc.Servers and databaseSingapore
Cloudflare, Inc. (R2)File storage (images, video, logs)[TO BE DECIDED — confirm region]
ResendEmail delivery (invitations, password reset, enquiries)[TO BE DECIDED — confirm]
Anthropic (Claude)AI features (diagnostic summaries, help, copy)[TO BE DECIDED — confirm]
Google (Gemini)AI features (image generation, speech)[TO BE DECIDED — confirm]
fal.aiAI features (image and video generation)[TO BE DECIDED — confirm]
Stripe, Inc.Subscription billing for our own service[TO BE DECIDED — confirm]

★ Before anything is sent to an AI provider we mask values that look like emails, phone numbers, tokens, cards or account numbers. Even so, the input sent and the result received are recorded in our database. [TO BE DECIDED — retention of those records]

Guest data is not disclosed to anyone other than the venue, except where required by law.

5. International transfers

★ Our servers and database are in Singapore. Wherever you use the service from, the data is processed in Singapore.

RecipientCountryDataWhen and howRetention
Render Services, Inc.SingaporeEverything in §2Continuously, over the network, while you use the serviceAs in §3
Other processors[TO BE DECIDED][TO BE DECIDED][TO BE DECIDED][TO BE DECIDED]

If you object to international transfer, use of the service may be limited. You can object using the contact in §6.

6. Your rights and how to use them

You may request access, correction, deletion, restriction, or withdraw consent.

WhoWhatHow, today
Guests (kiosk members)Access, deletion★ Ask the venue you visited. The venue can act immediately — deletion is available in our console. Deletion erases the derived phone value and last four digits, and any remaining points expire.
Guests (cameras)Object to processingWhen a venue pauses a camera, the camera on the device is actually closed. Individual features can also be switched off.
Customer staffAccess, correctionPartly available in console settings
Customer staffAccount deletion, data export★ No screen for this yet. Please use the contact below. [TO BE DECIDED — process and deadline]

★ Stated plainly: we do not yet have a channel where a data subject acts directly. Guests go through the venue; staff use the contact below. A direct channel is being built.

Contact: support@lumaaistudio.it

Data protection officer: [TO BE DECIDED — name, title, contact]

7. How we protect data

  • Passwords, PINs, API keys, invitation tokens and device tokens are stored only as one-way values. Two-factor secrets are stored encrypted.
  • Each organisation’s data is separated at the database level; rows belonging to another organisation cannot be read at all.
  • An account limited to a venue can see only that venue’s data.
  • Sensitive actions require a PIN, and repeated failures lock it.
  • A record of who did what, and when, is kept and cannot be erased.
  • Access by our own operators to customer data requires an approval with a stated reason and expiry, and is recorded.

8. Automated processing

  • Where cameras are installed, the advertisement shown on a screen may change according to aggregate estimated age-band and gender. No individual is identified, no one is treated differently as an individual, and no decision with legal effect is made.
  • Venues with this feature state it on their entrance notice.

9. ★ What this draft still lacks

This is a draft, not yet reviewed by counsel. The following cannot be settled from the code alone and must be decided by a person. We list them rather than hide them.

  • Name, title and contact of the data protection officer
  • Process and deadline for staff account deletion and data export (the feature must be built too)
  • Retention of audit and sign-in records (statutory minimums per country to be confirmed)
  • Statutory retention of order and accounting records per country
  • Processing region for Cloudflare R2, and countries for the other processors
  • Retention of AI inputs and results recorded in our database
  • Retention and scope of original device logs and screen captures
  • Retention and masking of cash-receipt numbers
  • Under-14 members — an “I am 14 or older” confirmation was added at sign-up (18 Sep 2026). ★ Outstanding: the threshold differs by country (13–16). Decide whether to make it a per-country setting
  • Whether to keep the option that shows the last four digits of a phone number on a call display
  • Who the controller is when cameras are operated at a trade show
  • Breach notification process and deadline, consistent with local law and the GDPR

★ Deferred (not doing this now) — actually storing data in separate regions such as Europe or the US. Today the “jurisdiction” chosen per organisation only sets retention rules; storage is in Singapore only. If a European customer requires local storage, we will build regional separation then.

10. Changes to this policy

We will post changes on this page at least 7 days before they take effect, and 30 days before for significant changes.

Document version: 2026-09-18-draft