Last updated 25 August 2026
Data Processing Notice
Current LumicSec operating policy. Mandatory rights under applicable law continue to apply, and any enterprise or jurisdiction-specific commitment must be expressly agreed in writing.
1. Purpose and scope
LumicSec processes website URLs, scan results, findings, reports, remediation state, retest comparisons, ownership/scheduling state and related account data to provide authorized website-security workflows.
2. Customer and LumicSec roles
Operationally, the customer chooses the assets and security information submitted for review and is responsible for having authority to process that information. LumicSec processes that service data to deliver the requested product workflow. LumicSec may separately determine necessary processing for its own account administration, billing reconciliation, fraud prevention and service-security operations. This notice does not by itself allocate every legal controller/processor role for every jurisdiction.
3. Data categories
Service data can include account identifiers, target URLs, public-response evidence, scan metadata, findings, reports, remediation/retest state, ownership-verification state, Scan Access verification metadata, scheduled-scan authorization state, client-report-link metadata, support records and assisted-billing records.
4. Authorization and customer instructions
Customers control which websites they add and must own, manage or have explicit permission to assess the target. The standard workflow is designed around public website signals and does not require passwords, private keys or confidential production datasets. Customers should not instruct LumicSec to process data they are not authorized to provide.
5. Service-provider categories
Current core service-provider categories include Google-based authentication, Vercel-hosted application infrastructure and Supabase-backed authentication/database services. Providers can change as the service evolves. A separate enterprise agreement may identify additional or more specific subprocessors where required.
6. Security safeguards
Current safeguards include authenticated workspace access, server-side authorization and ownership checks, database row-level security for protected product data, authorization gates before deeper scanning, exact-origin handling for Scan Access secrets, cryptographic hash storage instead of raw Scan Access/client-report bearer tokens, and safe-scanning boundaries intended to avoid destructive testing in standard workflows.
7. Retention, deletion and return
LumicSec retains service records according to operational, evidence-history, billing, fraud-prevention and legal needs rather than promising one universal deletion date in this notice. Reasonable export or deletion requests can be submitted through support after account-security checks. Source reports may remain after a share link is revoked or expires. Where infrastructure providers keep recovery copies, deletion from those copies may follow provider recovery cycles.
8. Security incidents and international processing
LumicSec investigates material security issues affecting the service and will use appropriate account/contact channels for customer communication where notice is required or reasonably necessary. No fixed incident-notification SLA is promised here. Core providers may process data in locations where their infrastructure operates; no specific data-localization or international-transfer mechanism is promised unless separately agreed in writing.
9. DPA and enterprise terms
This Data Processing Notice is not a contractual Data Processing Agreement (DPA). Customers that require a DPA, jurisdiction-specific processor terms, data-localization commitments, audit rights or a fixed incident-notification obligation should obtain a separate written enterprise agreement before relying on those requirements.
10. AI processing boundary and model training
The current standard service does not use customer security reports or customer secrets as a training corpus for a general-purpose AI model. Any future optional AI processor that receives customer service data must be identified or described through an updated provider register, product disclosure or applicable enterprise terms before customers are expected to use that workflow. This statement does not convert the Data Processing Notice into a DPA or create unstated jurisdiction-specific processor obligations.