Data Processing Addendum
1. Scope & Acceptance
This Data Processing Addendum (“DPA”) forms part of the Lumina Terms of Service and applies whenever Customer Content includes personal data of individuals located in the EEA, the United Kingdom, or Switzerland, or where the GDPR, UK GDPR, or Swiss FADP otherwise applies to the processing. In the event of a conflict between the Terms and this DPA regarding such processing, this DPA prevails.
2. Roles
You (the workspace owner) are the controller of respondent data you collect through your forms. Lumina is the processor. Each party complies with its own obligations under applicable data-protection law.
3. Subject Matter & Purpose
Lumina hosts and processes form definitions, responses, attachments, and operational metadata for the duration of your use of the Service, solely to provide the Service: collecting, storing, displaying, exporting, and (where configured) forwarding or transmitting that data on your behalf.
4. Data Subjects & Categories
Data subjects: your workspace members and your respondents. Categories of personal data: account and profile data for members; the answers, contact details, attachments, and submission metadata (timestamps, IP address, user agent, campaign attribution) that your forms collect from respondents. Special categories are processed only if you choose to collect them through your own form fields — Lumina does not request them.
5. Subprocessors
The current list of subprocessors is published at /legal/subprocessors. We will give at least 14 days’ notice on that page before adding a subprocessor that processes respondent data, and you may object on reasonable data-protection grounds by contacting legal@luminaforms.app within the notice period. If an objection cannot be resolved, you may export your data and terminate the affected workspace in accordance with the Terms.
6. International Transfers
Lumina runs on Cloudflare’s global network; processing is not restricted to a single jurisdiction. Transfers of personal data outside the EEA or the United Kingdom are made pursuant to the EU Standard Contractual Clauses (Module 2: controller to processor) and the UK International Data Transfer Addendum, incorporated here by reference, with the Cloudflare Customer DPA and its incorporated transfer mechanisms as the operative safeguards at the infrastructure layer.
7. Security
Lumina applies the technical and organizational measures described in the Privacy Policy and on the status page, including encryption in transit (TLS), access control, session security, bot protection on authentication flows, and audit logging of administrative actions.
8. Assistance & Breach Notification
Taking into account the nature of the processing, Lumina assists you with data-subject requests, data-protection impact assessments, and prior consultations. Lumina notifies you without undue delay after becoming aware of a personal-data breach affecting your Customer Content, and provides reasonable detail to help you meet your own notification obligations. Requests and notifications run through legal@luminaforms.app.
9. Deletion & Return
On termination or on your instruction, you can export your workspace data and delete it through the Workspace Settings panel; deletion extends to stored attachments in object storage. After provider backup windows elapse (approximately 30 days for the managed database), remaining copies are unrecoverable.
10. Audit
On request, Lumina provides the information needed to demonstrate compliance with this DPA, including the subprocessor list, the security description above, and answers to written audit questions through the contact below.
Contact
Questions or a signed copy for your records: legal@luminaforms.app.