Skip to content

Privacy policy

Last updated: 2026-09-29

1. Controller

LumeSec Technologies GmbH, Rissach 10, 6092 Birgitz, Austria
Managing director: Ing. Marcus Manfred Ziegler · Email: hello@lumesec.ai

We have not appointed a data protection officer. Please send data protection requests to hello@lumesec.ai.

2. The App does not process your content on our side

The SecureGrid desktop app processes texts, documents and the mapping between placeholders and real values exclusively on your device. It sends neither content nor telemetry to us. The App connects to two destinations only: our sign-in (section 8) and — only when you trigger it — Hugging Face for the model download. This policy therefore covers this website, the customer account and signing in to the App with that account.

3. Registration and customer account

We process name, company, business email address, chosen language, the verification status of the email address, and the version and time of the accepted terms of use. The purpose is providing the account and the download; the legal basis is Art. 6(1)(b) GDPR. We keep proof of acceptance based on our legitimate interest in defending legal claims (Art. 6(1)(f) GDPR).

These details are required for the contract; without them we cannot set up an account. There is no automated decision-making, including profiling.

If you have consented at registration or in your account, we send you information about SecureGrid and about other LumeSec products and services (terms of use, section 7). The legal basis is your consent (Art. 6(1)(a) GDPR, § 174 of the Austrian Telecommunications Act 2021). It is optional; you may withdraw it at any time with effect for the future (Art. 7(3) GDPR): in your account, via the unsubscribe link in every such email, or by email to hello@lumesec.ai. We store whether you have consented and when you last changed it for as long as the account exists. We do not pass your contact details on to third parties for this; emails are sent through the processor named in section 9.

4. Sign-in and session

Sign-in works without a password via an emailed link. Sign-in links are valid for 10 minutes, confirmation links for 60 minutes, and each can be used once; our database holds only a hash of the sign-in link.

After sign-in we store a session with its expiry, your IP address and browser identifier (user agent), to secure your account and detect misuse (Art. 6(1)(f) GDPR). A session lasts 30 days from last use and is then deleted; you can sign out on all devices in your account at any time.

5. Cookies

We only set cookies that are strictly necessary to run the website or that store a setting you chose (§ 165(3) Austrian Telecommunications Act 2021). There is no tracking, no analytics or advertising services and no third-party content.

NamePurposeDuration
sg.session_tokensign-in (session)30 days
sg.session_datasession cache5 minutes
sg-themechosen theme (light/dark)1 year
NEXT_LOCALEchosen languageend of browser session

6. Abuse protection and technical logs

To protect registration, sign-in and downloads from automated attacks, we count requests per IP address in short windows (at most one hour); the counters are deleted after one day at the latest. Our application logs contain path, status code, duration and a request ID, but no IP addresses, email addresses or links with sign-in tokens. The upstream server may keep technical access logs with IP addresses; these are deleted after 14 days at most. The legal basis is Art. 6(1)(f) GDPR.

7. Download log

For each download we store the version, your account, the time and a shortened IP address (the first three parts for IPv4, the first three blocks for IPv6), to prevent abuse and to count downloads per version (Art. 6(1)(f) GDPR). Entries are deleted after 12 months.

8. Signing in to the desktop App

Using the App requires signing in with your account. The App opens this website in your browser; after your explicit approval it receives an access token and a refresh token that may read your name and email address. When the device is online, the App renews access with the refresh token; only the tokens are transmitted, never content. We store the approval, the tokens issued (refresh tokens for at most 30 days from the last renewal) and the time of each renewal. The legal basis is Art. 6(1)(b) GDPR. You can revoke approvals at any time.

9. Email delivery

We send sign-in, confirmation and change emails via Resend, Inc., USA as a processor (Art. 28 GDPR), transmitting your email address, name and the email content. The transfer to the USA is based on the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR).

10. Hosting and installer storage

The website, database and installer files are operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Deutschland, in data centres in Germany, as a processor (Art. 28 GDPR). Installer files are kept in non-public storage; downloads use short-lived signed links.

11. Naming your company as a reference

Under section 9 of the terms of use we may name your company’s name and logo as a user of SecureGrid. We do not name individuals. If the company name contains a person’s name, we process it based on Art. 6(1)(b) GDPR. If you delete your account, we keep the company name and the version of the accepted terms for this purpose — without any person’s name or email address. You can revoke the reference at any time by email; we remove it within 30 days.

12. Retention

  • Customer account: until you delete it in your account, it is deleted on request, or the contract ends.
  • Company name for the reference (section 11): until revoked.
  • Proof of acceptance of the terms: up to three years after the contract ends (limitation period).
  • Sessions: 30 days from last use; sign-in and confirmation links: until they expire.
  • Abuse-protection counters: one day at most; technical access logs: 14 days at most.
  • Download log: 12 months.

13. Recipients

Only the processors named above receive your data. We do not sell data or share it for advertising.

14. Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability and to object to processing based on legitimate interests (Art. 15–21 GDPR). Contact hello@lumesec.ai.

You can lodge a complaint with the Austrian Data Protection Authority: Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at.

15. Changes

We update this policy when our service or the law changes. The version published here applies.

Register // Confirm email // Download

Download SecureGrid

A short account unlocks the download. The app itself needs none and sends nothing.

Already registered? Sign in