1. Data controller
LUMI BED TIME SRL, with its registered office in Cluj-Napoca, Romania, is the controller of personal data collected via the Lumi website and mobile app.
2. What we collect
- Order data: first name, last name, email, phone, shipping address, county, city, postal code, courier notes. For business invoices: company name, VAT ID, and trade register number.
- Account and subscription data: the email address used to subscribe to the newsletter or to create an account in the app.
- Technical data: IP address, user agent, and technical logs strictly required for security and fraud prevention.
- User-generated content in the app: voice recordings used for voice cloning, photos uploaded for AI characters, and story prompts. The cloned voice stays local on the Lumi device.
3. Purpose of processing
- Processing and shipping orders.
- Communicating with the Customer (order status, support).
- Marketing and newsletter, only with explicit consent.
- Meeting tax and accounting obligations.
- Improving the product and preventing abuse.
4. Legal basis
We process your data on one of the following legal bases: contract performance (your order), legitimate interest (security, fraud prevention, support), consent (newsletter and marketing), or legal obligation (invoicing, tax reporting).
5. Who we share data with
We use providers that process data strictly on our behalf: courier (Sameday or equivalent), payment processor (Stripe), hosting (Vercel + Neon Postgres in the EU), transactional email providers. All are contractually bound to comply with GDPR.
We do not sell or trade your data with third parties for marketing purposes.
6. Retention
- Order data and invoices: 10 years (tax requirement).
- Newsletter email: until you unsubscribe.
- App-generated content: until you delete it or request deletion.
7. Your rights
Under GDPR you have the right of access, rectification, erasure ("right to be forgotten"), restriction, portability, objection, and withdrawal of consent. You can exercise these by writing to contact@lumibedtime.com. We respond within 30 days at the latest.
You may also lodge a complaint with the Romanian Data Protection Authority (dataprotection.ro).
9. Security
Data is encrypted in transit (TLS) and stored in our EU-hosted database. The cloned voice stays on the Lumi device and is never uploaded to the cloud.
Contact
LUMI BED TIME SRL · Cluj-Napoca, Romania
Email: contact@lumibedtime.com