Subprocessors
1. What a Subprocessor Is
When Lumina processes form and response data on a workspace owner's instructions, another provider engaged to process that data on Lumina's behalf is a subprocessor. Hosting, storage, and email delivery can involve this relationship. Our Privacy Policy explains how Lumina handles account and respondent data.
A service provider's role depends on the processing involved. Payment services can also process data for their own purposes, such as compliance and fraud prevention. Listing an integration here does not mean all of its processing is on Lumina's instructions.
2. Services & Integrations
The table describes the services supported by Lumina and the data involved when each is used. Optional integrations receive data only when the deployment and relevant feature are configured. Contact us for the services and contractual terms that apply to your workspace.
| Service | Purpose | Data categories | Region & policy |
|---|---|---|---|
| CloudflareHosting and database infrastructure; additional services depend on configuration. | Workers application hosting and static assets, D1 database storage, and DNS. R2 stores attachments when enabled; Turnstile provides account and submission security checks where configured. Email Routing forwards incoming contact email where configured. Outbound account and response emails require a separately configured sending integration; forwarding setup alone does not enable them. | Account records, form definitions and submissions, request metadata including IP addresses and user-agent strings; attachments, bot-verification tokens, and incoming contact email where those services are enabled. | Global request processing. D1 storage location depends on database configuration; location hints are not residency guarantees and jurisdiction settings do not restrict Worker execution. D1 data-location policy. |
| ResendOptional outbound email integration; only used when configured. | Delivery of password resets, workspace invitations, and new-response notifications. Availability of this integration does not mean it is enabled for a Cloudflare-only deployment. | Recipient and sender addresses, account reset or invitation links, and notification content including form names, response summaries, timestamps, and inbox links. | Resend states that its primary processing operations take place in the United States. Its data processing addendum describes international transfers and safeguards. Resend data processing addendum. |
| MaxelPayPayment service; used when checkout is configured and a customer starts a payment. | Hosted cryptocurrency checkout and payment-status verification for form payments and workspace licenses. | Order and session references, payment amount and currency, purchase description, return and callback URLs, and customer email when supplied. MaxelPay also processes information collected on its hosted checkout. | The published privacy policy describes processing and retention but does not specify processing countries or promise country-specific residency. MaxelPay privacy policy. |
| Atomic MailInbound contact email; used whenever Email Routing forwarding is configured. | Hosts the mailbox that receives contact email forwarded from this domain (hello@ and legal@ aliases) so the team can read and answer privacy, legal, and support requests. | Sender names and addresses, message subjects and contents, and any personal data you choose to include in a message. Message metadata such as timestamps and routing headers. | The published privacy policy describes the provider’s processing; it does not promise jurisdiction-specific residency. Atomic Mail privacy policy. |
3. Customer-Directed Integrations
Workspace owners can configure outbound webhooks and connectors to third-party tools. These are additional destinations chosen by the workspace owner, not services required to host Lumina. Review the destination's terms and privacy policy before sending respondent data. The applicable data-processing roles depend on that arrangement.
Optional AI integrations are disabled in the default deployment configuration. If enabled for a deployment, the selected provider and the information sent to it need a separate disclosure; the infrastructure list above should not be read as covering that processing.
4. International Transfers
Processing location depends on the service and its configuration. A provider's published policy is not a guarantee that a particular residency setting is enabled for your workspace. Where a restricted international transfer applies, the relevant agreement and transfer safeguards must cover that processing.
Cloudflare publishes its Data Processing Addendum. The email and payment providers' policies are linked in the table. See also Privacy Policy § 9, or contact us to discuss a deployment-specific data-location requirement.
5. Notice of Changes
Changes to this service list are reflected on this page with an updated date. Our Privacy Policy describes notice by email or an in-app banner at least 14 days before material policy changes affecting your rights take effect. Any separate subprocessor notification or objection terms in your data processing agreement apply according to that agreement.
For questions about a provider change or the notification arrangements for your workspace, contact legal@luminaforms.app.
6. Contact
For questions about these services, privacy requests, or a data processing agreement, contact:
Lumina
Attn: Privacy & Data Protection
Email: legal@luminaforms.app