Legal

Privacy Policy

Last updated: April 16, 2026

1. Who we are

Lumi (“we,” “us,” or “our”) provides a cloud platform that helps professional and studio photographers deliver event photos to guests using QR codes, a mobile-friendly guest experience, and automated similarity search based on facial characteristics. This Privacy Policy explains how we handle personal data when you use our website, applications, and services (collectively, the “Services”).

Photographers and their businesses typically act as controllers of guest and event data they upload. Lumi generally acts as a processor on their instructions, except where we determine purposes and means for our own account data (e.g., billing, authentication), where we act as controller. A separate Data Processing Agreement is available for customers who require it.

2. Data we collect

Account & workspace data. When you register or manage a workspace, we collect information such as name, email, organization or studio name, role, authentication credentials (processed via our auth provider), billing-related details where applicable, and usage tied to your account.

Event & media content. Photographers upload photographs and related metadata (e.g., event names, dates). This may include images of identifiable individuals at events.

Biometric-related technical data (face vectors). To match guests to photos, the Services may derive compact numerical representations (“embeddings” or “vectors”) from faces visible in images and from a guest’s selfie submitted through the guest flow. These vectors are used only to retrieve relevant photos for that event workspace; they are not used to train generalized public facial recognition models for unrelated purposes.

Guest portal interactions. When a guest scans a QR code and uses the browser-based experience, we may process the selfie they submit, device/browser technical data, and session information needed to deliver matches and secure the experience.

Support & communications. If you contact us, we process the content of your message and contact details you provide.

3. How we use data

  • Provide, operate, and improve the Services, including hosting, security, and performance.
  • Enable face-similarity search within an event’s scope so guests can receive photos they appear in, as configured by the photographer’s workspace.
  • Authenticate users, manage workspaces, teams, and subscriptions.
  • Send transactional or service-related messages (e.g., verification, security, billing).
  • Comply with law, enforce our terms, and protect rights, safety, and integrity.

4. Retention

Retention depends on the type of data and your workspace configuration. Unless otherwise required by law or contract, biometric-related vectors and guest matching data tied to an event are scoped to the event workspace and are designed to be automatically deleted within 30 days of the event’s conclusion (for example, when it is marked ended/archived or its viewing window expires), or immediately upon workspace deletion.

Account and billing records may be retained longer where necessary for legal, tax, or dispute resolution purposes. Photographers remain responsible for their own backups and client obligations outside the platform.

5. Sharing & subprocessors

We use trusted infrastructure and service providers (e.g., cloud hosting, database, storage, email delivery, DNS, and security vendors) to run the Services. They process data only under appropriate agreements and instructions. We do not sell personal information. We may disclose information if required by law or to protect our users and the Services.

6. International transfers

Our servers and subprocessors may be located in countries other than your own. Where required, we implement appropriate safeguards (such as standard contractual clauses) for transfers of personal data subject to GDPR or similar laws.

7. Security

We implement technical and organizational measures appropriate to the risk, including access controls, encryption in transit where applicable, and separation of customer workspaces. No method of transmission or storage is 100% secure; you use the Services at your own risk beyond what we reasonably implement.

8. Your rights

Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, or object to certain processing, and to data portability. Guests should normally contact the photographer or event organizer who controls the event data; workspace administrators may use in-product tools or support to fulfill requests where available. You may also contact us as described below, and we will respond in line with applicable law.

9. Children

The Services are intended for businesses and adult guests at events. We do not knowingly collect personal information from children under 13 (or the age required in your jurisdiction) for direct marketing. If you believe we have collected such data, contact us so we can delete it where appropriate.

10. Changes

We may update this Privacy Policy from time to time. We will post the revised version and update the “Last updated” date. Continued use of the Services after changes constitutes acceptance where permitted by law.

11. Contact

For privacy inquiries, contact the email address published on our website (e.g., [email protected] or your deployed support address), or write to us at your designated physical mailing address (for example, a registered office, virtual office, or PO Box). Replace this with your legal entity’s official address before production.

← Back to home