Data protection

The protection of your personal data is a top priority for us. Our Data Protection Terms (Website) informs you about the type, extent and purpose of the collection, processing and use of your personal data on our website.

You can also review or download our Standard Contractual Clauses (Non-EU SCC/DPA) or Standard Contractual Clauses (EU SCC/DPA), and our IT Security Guideline (TOMs).

Information on processing of data from customer/partner

Read now

Website Privacy Notice

Version: 1/2026, last updated: July 23, 2026

 

Thank you for your interest and visit to our website. The following serves to inform you about the handling of your data in accordance with Article 13 General Data Protection Regulation (GDPR).

 

1. About this privacy notice

This section explains how the Privacy Notice is structured and defines the key terms we use throughout. It gives you a reading path so you can skip to the parts that apply to you.

 

(a) What have we done to help you navigate this Privacy Notice?

We know that privacy notices can be long and technical. We have structured this notice as a series of questions and answers so that you can find the information that matters most to you quickly.

The Privacy Notice is divided into numbered sections. Sections 1 to 4 and 6 to 11 apply to everyone. Section 4 explains what personal data we collect. Section 5 contains modular parts that describe how we process data depending on who you are – a website visitor, a job applicant, a customer or customer user, a business contact, or a supplier or partner. You only need to read the part of Section 5 that applies to you.

To help you identify the parts that are most relevant, we suggest the following reading paths:

  • If you are browsing our website: read Sections 1, 2, 3, the "Website users" part of Section 5, and Sections 6, 7, 8, 9, 10, and 11.
  • If you have applied for a role: read Sections 1, 2, 3, 4, the "Job applicants" part of Section 5, and Sections 6 through 11.
  • If you are a customer or a user of our services: read Sections 1, 2, 3, 4, the "Customers and customer users" part of Section 5, and Sections 6 through 11. You may also wish to consult our Trust Center which includes our Standard Contractual Clauses and IT Security Guideline.
  • If you are a business contact, supplier, or partner: read Sections 1, 2, 3, 4, the relevant part of Section 5, and Sections 6 through 11.

 

Where we use a defined term (for example, "personal data" or "processing"), we give it the meaning set out in the applicable data protection law – primarily the EU General Data Protection Regulation ("EU GDPR"), the UK General Data Protection Regulation ("UK GDPR"), the Swiss Federal Act on Data Protection (including the revised version) ("FADP"), China's Personal Information Protection Law ("PIPL"), Japan's Act on the Protection of Personal Information ("APPI"), Singapore's Personal Data Protection Act ("PDPA"), and the applicable United States federal and state privacy laws. Where those laws give different meanings to similar concepts, we apply the definition that gives you the higher level of protection.

This Privacy Notice uses references to specific articles of the EU GDPR (for example, “Article 6(1)(a) EU GDPR”) as its primary citation format because our headquarters are located in Germany and the EU GDPR is the governing framework for our group. Where those references are relevant to individuals in the United Kingdom, they should be read to include the equivalent provisions of the UK GDPR (which retained the text of the EU GDPR as it stood immediately before it was incorporated into UK law by the European Union (Withdrawal) Act 2018 and the UK GDPR). Lucanet complies fully with the UK GDPR and all other applicable data protection laws and regulations affecting its global business operations.

 

(b) What key terms do we use in this Privacy Notice?

The following definitions apply throughout this notice:

  • "Lucanet", "we", "us" and "our" means Lucanet AG and the companies within the Lucanet group, as further described in Section 2 below.
  • "Personal data" means any information relating to an identified or identifiable natural person (a "data subject"). For the purposes of PIPL and APPI, "personal information" has an equivalent meaning. For the purposes of most US state privacy laws, "personal information" is defined more broadly and includes information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with a consumer or household.
  • "Processing" means any operation or set of operations performed on personal data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, alignment, combination, restriction, erasure, and destruction.
  • "Sensitive data" or "special category data" is commonly used to describe personal data that carries a higher risk for individuals if misused. Under the EU GDPR, it means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data processed for unique identification, data concerning health or data concerning a person’s sex life or sexual orientation; data relating to criminal convictions and offences is regulated separately but is often treated as similarly sensitive. Under PIPL, “sensitive personal information” includes, among other things, biometric data, religious beliefs, medical and health data, financial account information, tracking or location data, and any personal information of minors under 14. Under recent US state privacy laws, “sensitive” or “sensitive personal information” generally includes many of the same categories, and in many states also covers precise geolocation, citizenship or immigration status, and account access credentials such as account log in details.
  • "Controller" means the party that determines the purposes and means of processing personal data (equivalent to "business" under the California Consumer Privacy Act 2018 (“CCPA”) and "personal information handler" under PIPL).
  • "Processor" means a party that processes personal data on behalf of a controller (equivalent to "service provider" or "contractor" under many US state laws, "entrusted party" under PIPL, and "data intermediary" under the PDPA).
  • "Joint controllers" means two or more controllers that jointly determine the purposes and means of processing.
  • "Sub-processor" means a processor engaged by another processor to assist with processing on behalf of the same controller.
  • "Data Protection Impact Assessment" ("DPIA") means the risk-assessment process required for processing activities that are likely to result in a high risk to data subjects' rights and freedoms.
  • "International transfer" means a transfer of personal data from one jurisdiction to another, where this triggers additional legal requirements.
  • "Services" means Lucanet's software products and services, including the Lucanet.Cloud, Lucanet.Financial OLAP Server, Lucanet.Financial Warehouse, AMANA reporting and tax software, and Lucanet.Consulting services.

2. Who are we and how can you contact us?

This section identifies the Lucanet group entity responsible for your personal data and whether we act as controller, processor, joint controller, or sub-processor. Gives you the contact details for the relevant entity, our Data Protection Officer, and other data-protection contacts.

 

(a) Who is responsible for your personal data?

Lucanet is an international group of companies that provides financial consolidation, planning, disclosure management, lease accounting, banking, cash management, and ESG reporting software and consulting services. For over 25 years we have served as a trusted partner to more than 6,500 brands in 50 countries.

Lucanet AG and the other Lucanet group companies listed below are jointly responsible for certain common processing activities (such as intra-group administration of Human Resources (“HR”), finance, and Customer Relationship Management (“CRM”) systems).

For other processing, the Lucanet entity with whom you have a relationship — typically the Lucanet sales entity named in your customer contract — acts as a controller in its own right.

 

(b) Which Lucanet entity applies to you?

Determining which Lucanet entity is primarily responsible for the processing of your personal data depends on both your geographic location and the nature of your relationship with us. The respective group entities currently comprising the Lucanet group are set out below and may likewise be identified via the imprint or the Locations tab; whichever entity is so identified shall be deemed the controller responsible for the data processing activities described hereafter.

 

RegionEntityPrincipal address
GermanyLucanet AG (parent operating company)Karl-Liebknecht-Str. 14, 10178 Berlin
United KingdomLucanet (UK) Limited20 North Audley Street, London, W1K 6WE

 

If you are a customer, the Lucanet entity that contracted with you is named in your customer agreement. If you are a job applicant, the Lucanet entity to which you are applying is named in the job advertisement and any employment offer and contract subsequently provided to you. If you are a website visitor, the Lucanet entity responsible for your data is Lucanet AG.

 

(c) What is Lucanet's role under data protection laws?

Our role depends on the relationship and the nature of the processing:

  • As a controller – We act as a controller when we determine why and how personal data is processed – for example, when we process applicant data, manage business-contact records, run our website, administer our internal HR and finance systems, or operate our marketing programmes. Each Lucanet entity acts as controller for the individuals with whom it has a direct relationship.
  • As a processor – When we provide the Lucanet.Cloud, AMANA, or Lucanet.Consulting services to our customers, we act as a processor on their behalf. The customer is the controller of the personal data it uploads to or processes through our services. The scope of that processing is governed by the Standard Contractual Clauses we enter into with each customer. As processor, we process only on the customer's documented instructions, we engage sub-processors only with the customer's general authorisation, and we assist the customer in responding to data-subject requests and regulatory enquiries.
  • As a sub-processor – In some indirect arrangements (for example, where a reseller or implementation partner contracts with the end customer and in turn engages Lucanet), we act as a sub-processor to the partner's principal processing relationship.

 

(d) Do we have a Data Protection Officer ("DPO")?

We are supported by our data protection officer in fulfilling our obligations under data protection law. The contact details of our data protection officer are:
 

For Lucanet AG & Lucanet Software GmbH:

ASURE Legal Privacy
E-Mail: info@asurelegal.com

 

For all other Entities Data Protection Contact:

E-Mail: legal@lucanet.com

 

Please state the data controller specified in the imprint or specified here when contacting our data protection officer.

 

Not for all Lucanet group entities, a statutory DPO has been appointed. However, Lucanet takes data protection and privacy compliance seriously across all entities within its group and has implemented appropriate governance, policies and procedures to ensure personal data is handled in accordance with applicable laws.

If you have any questions about data protection or wish to exercise your rights, you can contact the Lucanet legal team at legal@lucanet.com.

3. Which data protection supervisory authorities oversee Lucanet?

This section identifies the Berlin Commissioner as our lead EU supervisory authority and lists the competent authorities in all 15 jurisdictions where we operate. Tells you where to lodge a complaint and how the one-stop-shop cross-border coordination works.

 

As Lucanet AG is established in Berlin, Germany, and operates cross-border within the EU, under the EU's "one-stop-shop" mechanism our lead supervisory authority for cross-border processing within the EU is the Berlin Commissioner. For processing strictly local to another EU Member State, the local authority may instead be competent. For processing that falls outside EU GDPR scope, the relevant non-EU authority applies.

You have the right to complain to any data protection supervisory authority. Under the EU GDPR, you can complain to the authority in the country in which you habitually reside, where you work, or where the alleged infringement occurred. Under non-EU laws, the competent authority is set out below.

 

JurisdictionSupervisory authorityContact
GermanyBerliner Beauftragte für Datenschutz und Informationsfreiheit,lead for Lucanet AG)www.datenschutz-berlin.de
AustriaDatenschutzbehördewww.dsb.gv.at
BelgiumAutorité de protection des données / Gegevensbeschermingsautoriteitwww.autoriteprotectiondonnees.be
FranceCommission Nationale de l'Informatique et des Libertéswww.cnil.fr
ItalyGarante per la protezione dei dati personaliwww.garanteprivacy.it
LuxembourgCommission nationale pour la protection des donnéeswww.cnpd.public.lu
NetherlandsAutoriteit Persoonsgegevenswww.autoriteitpersoonsgegevens.nl
RomaniaAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personalwww.dataprotection.ro
SpainAgencia Española de Protección de Datoswww.aepd.es
United KingdomInformation Commissioner's Officewww.ico.org.uk
SwitzerlandFederal Data Protection and Information Commissionerwww.edoeb.admin.ch
SingaporePersonal Data Protection Commissionwww.pdpc.gov.sg
JapanPersonal Information Protection Commissionwww.ppc.go.jp
ChinaCyberspace Administration of Chinawww.cac.gov.cn
United StatesOffice of the State Attorney General in the relevant state; Federal Trade Commissionwww.naag.org; www.ftc.gov

4. What type of personal data do we collect?

This section describes the categories of personal data we collect – from identification, contact, and account data to usage, marketing, recruitment, and customer-uploaded data. Tells you where the data comes from and which categories of individuals this notice Privacy Notice applies to.


(a) What categories of personal data do we collect?

Depending on your relationship with us, we may collect the following categories of personal data. We only collect what we need for the specific purpose, in line with the data-minimisation principle.

The level of detail varies – for a casual website visitor, the volume of data is minimal (usage log and, with consent, cookie data); for a customer authorised user, it can include account credentials and a log of actions taken in the service.

Examples of the categories of personal data that we collect are as follows:

  • Identification and contact data – first and last name, business email address, business telephone number, job title, employer, business address, professional profile (e.g. LinkedIn), and correspondence address.
  • Account and credential data – username, hashed passwords, authentication tokens, multi-factor authentication metadata, user-account permissions and roles, session information, and audit-trail metadata for the Lucanet.Cloud and customer/partner portals.
  • Communication data – the content of emails, support tickets, contact-form submissions, online-meeting chat, webinar Q&A, and recordings of webinars where you have consented.
  • Contract and invoicing data – commercial terms, purchase orders, order and payment history, bank-account details and tax-identification numbers where required for payment, VAT numbers, and credit-check data where applicable.
  • Usage and technical data – log data, IP address, device type, operating system, browser type and version, referral URL, pages visited, features used, timestamps, access status, and error data.
  • Marketing data – marketing and communication preferences, newsletter subscription status, event attendance, campaign responses, and engagement metrics.
  • Recruitment data – CV, cover letter, references and reference responses, qualifications, certifications, employment history, right-to-work documentation, salary expectations, interview notes and recordings (where you have consented), psychometric or skills-assessment results where relevant, and background-check outcomes.
  • Customer-uploaded data – where you are a customer user, the personal data you upload into the Lucanet.Cloud or AMANA for financial consolidation, planning, reporting, lease accounting, banking, cash management, tax, and ESG reporting. This may include the names of employees, officers, and counterparties contained in financial accounting systems. We process this data as data processor only.
  • Partner and supplier data – company and individual representative details, commercial performance data, affiliate-programme metrics, and due-diligence records.
  • Sensitive / special-category data – we do not intentionally collect sensitive data other than where you voluntarily provide it during a recruitment process (for example, information about a severely disabled status) or where our customers upload such data into the services. Separately, in certain jurisdictions financial information is itself classified as sensitive data – for example, financial-account information under PIPL, and a financial-account number in combination with any required security or access code under several US state privacy laws. As our services process personal data contained in our customers’ financial accounting systems, such data may constitute sensitive data in those jurisdictions. Where it does, we apply the additional restrictions and safeguards described in our Standard Contractual Clauses and IT Security Guideline (including strict purpose limitation, access restrictions, and encryption).

 

(b) Where do we get your personal data from?

We collect personal data from three types of source:

  • Directly from you – when you visit our website, submit a form, book a demo, register for an event, subscribe to our newsletter, apply for a role, or enter into a contract with us.
  • Automatically – via cookies, pixels, and similar technologies on our websites (subject to consent), via application and server logs, and via telemetry from our services used within their normal operation.
  • From third parties – from publicly available sources (such as corporate websites, professional networks, and business directories), from our customers or business partners, from our sub-processors (such as BrightHire for interview recordings), from background-check providers (such as Zinc Work), and from third-party lead-generation and data-enrichment providers were permitted by applicable law.

 

(c) What categories of individuals does this Privacy Notice apply to?

This Privacy Notice applies to:

  • Visitors to our websites (including www.lucanet.com, associated regional domains, and our Trust Center).
  • Job applicants, including spontaneous applicants and individuals we have sourced through talent searches.
  • Customers and authorised users of the Lucanet.Cloud, AMANA, and related services.
  • Business contacts, prospects, and attendees at our events, webinars, and trade shows.
  • Suppliers, consultants, resellers, implementation partners, and their staff.

 

This notice does not apply to employees of the Lucanet group; employees are given a separate Employee Privacy Notice when they join the company.

5. How do we process your personal data depending on who you are?

This section contains five modular parts describing how we process personal data for each audience: website users, job applicants, customers and customer users, business contacts and prospects, and suppliers and partners. Only the part that applies to your relationship with us needs to be read.



(a) Website users

(i) What personal data do we collect from you?

When you visit our websites, we process usage data contained in our server log files (including URLs requested, date and time of access, data volume, access status, browser and operating system description, referral link, and the IP address). We retain the IP address for one year for security purposes – specifically to identify, mitigate, and rectify attacks on our infrastructure – before it is deleted or anonymised. We also process data from cookies and similar technologies, as well as any data you voluntarily submit via our contact forms, white-paper downloads, newsletter subscriptions, demo requests, event registrations, booking tools (Microsoft Bookings, Demodesk), webinar tools (GoTo Webinar), customer/partner portals, and our press mailing list.

 

(ii) How do we collect it?

Most usage data is collected automatically when you interact with our websites. Where we use optional cookies or similar tracking technologies (for analytics, advertising, or embedded content), we only set them after you have given consent through our Usercentrics consent banner, in line with Article 6(1)(a) of the EU GDPR. Any data you actively submit (via a form, booking, or registration) is provided by you directly.

We categorise cookies and tracking technologies as follows:

  • Strictly necessary: required for basic website functionality (e.g. session management, security, consent banner); no consent required.
  • Functional: enable enhanced features (e.g. remembering your language preference); consent required.
  • Analytics: allow us to understand how our websites are used (e.g. Google Analytics, Microsoft Clarity, Hotjar); consent required.
  • Advertising and retargeting: allow us and our partners to serve targeted advertising (e.g. Google Ads, Microsoft Ads, LinkedIn Insight Tag); consent required. This may involve profiling within the meaning of Art. 4(4) EU GDPR.
  • Embedded content: for videos and similar content loaded from third-party providers (e.g. YouTube, Vimeo); consent required before third-party content loads.

 

 

Third-party tracking technologies for analysis purposes

We use web analysis tools in order to provide a website layout that caters to the requirements of our users. The web analysis tools used on our website allow for the generation of usage profiles that are compiled on the basis of pseudonyms. This is done by storing permanent cookies on your user device and reading their contents, which allows us to recognize and count return visitors.

If you have used our banner to declare your consent, the data processing is based on your declaration of consent (Section 25 (1) TTDSG, Article 6 (1 lit. a) GDPR). You may revoke your declaration of consent at any time. To revoke your consent, simply click on the link “cookie settings” in the footer of our web page, amend your consent in the new window showing the Cookie Statement, and save your new settings by clicking on the relevant button.

The respective providers make these web analysis tools available to us in the capacity of contract data processors pursuant to Article 28 GDPR. In as far as this entails the processing of data outside the EU or EEA, please take note that there is a risk of public authorities accessing the data for security and surveillance purposes without giving you prior notice or legal remedies. In cases where you have consented to us using a provider in an unsafe third country, the data is transmitted to such third country on the basis of Article 49 (1 lit. a) GDPR.

ProviderService/functionAdequate data protection level
Google LLC (USA)
Google Ireland Limited (Ireland)
Google AnalyticsStandard data protection clauses pursuant to Article 46 (2 lit. c) GDPR. The data transmission is also based on Article 49 (1 lit. a) GDPR
Google LLC (USA)
Google Ireland Limited (Ireland)
Google Optimize (functions for A/B and website testing)Standard data protection clauses pursuant to Article 46 (2 lit. c) GDPR. The data transmission is also based on Article 49 (1 lit. a) GDPR
Microsoft Corporation (USA)
Microsoft Ireland Operations Limited (Ireland)
ClarityStandard data protection clauses pursuant to Article 46 (2 lit. c) GDPR. The data transmission is also based on Article 49 (1 lit. a) GDPR
Hotjar Ltd. (Malta)HotjarProcessing exclusively within EU/EEA

Impartner Inc.

(USA)

Use of the partner portal, user usage dataStandard data protection clauses pursuant to Article 46 (2 lit. c) GDPR. The data transmission is also based on Article 49 (1 lit. a) GDPR

Snowplow Analytics Ltd

(United Kingdom)

Webtracking and Analysis serviceData Processing Addendum, Standard data protection clauses pursuant to Article 46 (2 lit. c) GDPR. The data transmission is also based on Article 49 (1 lit. a) GDPR

Third-party tracking technologies for advertising purposes

We use cross-device tracking technologies in order to serve you with targeted advertising on other Internet pages and to determine the effectiveness of our own advertising measures.

If you have used our banner to declare consent, the data processing is based on your declaration of consent. Your consent is voluntary and you may revoke your consent at any time.

 

How does tracking work?

When you visit our web pages, the third-party providers specified below may access return visitor data stored by your browser or user device (e.g. a so-called browser fingerprint), analyze your IP address, store or read return visitor identifiers on your user device (e.g. cookies), or gain access to individual tracking pixels.

The third-party providers may use the individual identifiers to recognize your user device when you visit other Internet pages. We may instruct the third-party providers to serve you with advertising content that relates to the pages you have visited on our website.

We only use anonymized data or company-level data to personalize our advertising efforts on platforms such as Google Ads. This data does not allow any conclusions to be drawn about individual persons and does not contain any personal information.

We use advertising and retargeting technologies provided by selected partners in order to measure the effectiveness of our campaigns, display advertising to users who have previously visited our website and reach new users who may be interested in our services. Where supported by the respective provider, this may include advanced advertising features such as Custom Audiences and Lookalike Audiences.

Subject to your prior consent, advertising pixels and similar technologies may collect or transmit data such as online identifiers, device and browser information, page views, referrer information and conversion events. This may enable us and our partners to recognise website visitors, assign them to advertising audiences, and identify users whose interests or behaviour may be similar to those of our existing visitors or customers. This may involve profiling within the meaning of Art. 4(4) GDPR.

Further information on the relevant providers and the associated data processing is set out in the table below.


You may withdraw your consent at any time with effect for the future via our cookie settings.

 

Which third-party providers are used in this context?

The third-party providers we work with for advertising purposes are specified below. Insofar this entails the processing of data outside the EU or EEA, please take note of the risk that public authorities may access the data for security and surveillance purposes without giving you prior notice or legal remedies. In cases where you have consented to us using a provider in an unsafe third country, the data is transmitted to such third country on the basis of Article 49 (1 lit. a) GDPR.

 

Provider

Service/function

Adequate data protection level

Google LLC (USA)
Google Ireland Limited (Ireland)

Google Ads

Standard data protection clauses pursuant to Article 46 (2 lit. c) GDPR. The data transmission is also based on Article 49 (1 lit. a) GDPR

Microsoft Corporation (USA)

Microsoft Ads

Standard data protection clauses pursuant to Article 46 (2 lit. c) GDPR. The data transmission is also based on Article 49 (1 lit. a) GDPR

Meta Platforms, Inc (USA)
Meta Platforms Ireland Ltd (Ireland)

Meta Pixel

Standard data protection clauses pursuant to Article 46 (2 lit. c) GDPR. The data transmission is also based on Article 49 (1 lit. a) GDPR

LinkedIn Corporation (USA)
LinkedIn Ireland Unlimited Company (Ireland)

LinkedIn Insight Tag

Retargeting

Standard data protection clauses pursuant to Article 46 (2 lit. c) GDPR. The data transmission is also based on Article 49 (1 lit. a) GDPR

StackAdapt Inc. (Canada)
StackAdapt UK Limited
PixelStandard data protection clauses pursuant to Article 46 (2 lit. c) GDPR. The data transmission is also based on Article 49 (1 lit. a) GDPR
Meta Platforms, Inc. (USA)
Meta Platforms Ireland Limited (Ireland)
Meta Pixel (Custom Audiences and Lookalike Audiences)Standard data protection clauses pursuant to Article 46 (2 lit. c) GDPR. The data transmission is also based on Article 49 (1 lit. a) GDPR
Reddit, Inc. (USA)
Reddit Netherlands B.V. (Netherlands)
Reddit PixelStandard data protection clauses pursuant to Article 46 (2 lit. c) GDPR. The data transmission is also based on Article 49 (1 lit. a) GDPR
Outbrain Inc. (USA)
Outbrain UK Limited
Outbrain PixelStandard data protection clauses pursuant to Article 46 (2 lit. c) GDPR. The data transmission is also based on Article 49 (1 lit. a) GDPR
New Work SE (Germany)Xing PixelProcessing exclusively within EU/EEA

 

What does cross-device tracking mean?

If you have used your personal user data to log in to your account with a third-party provider, the respective return visitor identifiers from different browsers and user devices may be linked with each other. If, for example, the third-party provider has generated a separate identifier for your laptop, desktop PC or smartphone, these identifiers may be linked with each other as soon as you use your user account data to access the service provided by the third-party provider. This enables the third-party provider to manage our advertising campaigns across different user devices.

(iii) Why do we use website data and what is our legal basis?

We use website data to do the following:

  • operate and secure our websites and IT systems – Article 6(1)(f) EU GDPR, our legitimate interest in the provision and safe operation of our IT systems, including detection and prevention of attacks, fraud, and abuse;
  • respond to enquiries and contact-form submissions – Article 6(1)(b) EU GDPR (pre-contractual steps) and Article 6(1)(f) EU GDPR (our interest in communicating with interested parties);
  • provide white papers, demos, flyers, newsletters, and press releases – Article 6(1)(a) EU GDPR (consent, including double opt-in for newsletters and newsletter tracking);
  • analyse use of the website, run advertising, and personalise content – Article 6(1)(a) EU GDPR (consent, via our consent banner; you can revoke consent at any time via the "cookie settings" link in the footer);
  • operate the customer and partner portals – Article 6(1)(b) and (f) EU GDPR;
  • organise events and online seminars – Article 6(1)(b) EU GDPR (performance of the event contract) in conjunction with Article 6(1)(f) EU GDPR (efficient organisation and delivery); and
  • conduct customer satisfaction surveys – Article 6(1)(a) EU GDPR (consent) or Article 6(1)(f) EU GDPR (our interest in improving our services).

 

 

(iv) Who do we share your data with?

We share website data with third-party service providers acting as processors, including hosting, content-delivery, analytics, marketing-automation, consent-management, CRM, and advertising providers.

Key providers include:

ProviderPurpose
uvensys GmbH and Adacor Hosting GmbH (Germany)Web hosting
Usercentrics A/S (Denmark)Consent management
Amazon Web Services, Inc. and Amazon CloudFrontContent delivery
Google LLC and Google Ireland LimitedAnalytics, Ads, Tag Manager, Photos, and YouTube
Microsoft Corporation and Microsoft Ireland Operations LimitedClarity, Ads, and Bookings
Meta PlatformsMeta Pixel (Standard, Custom, and Lookalike Audiences)
LinkedInInsight Tag
GoTo Technologies Ireland Unlimited CompanyGoTo Webinar
Vimeo.com, Inc. (USA)Vimeo

Inclusion of other technical third-party content and functions:

The presentation of our website uses the technical functions and contents from third-party providers specified below. Accessing our web pages will subsequently load contents from third-party providers for these functions and contents. The third-party provider will then receive the information that you have accessed our page together with the respectively technically necessary usage data. The further processing of data by the third-party provider is then out of our sphere of control.

If you have used our banner to grant consent, the data processing is essentially based on your declaration of consent (Section 25 (1) TTDSG, Article 6 (1 lit. a) GDPR). You may revoke your declaration of consent at any time. To revoke consent, simply click on the link “cookie settings” in the footer of our web page, amend your consent in the new window containing the Cookie Statement, and save your new settings by clicking on the relevant button.

The data processing may in certain cases also server the purpose of safeguarding our legitimate interests and is based on Article 6 (1 lit. f) GDPR. Our interest is manifest in the provision of our web pages and the safe operation of our IT systems. The list below informs you of the specific data processing that serves the safeguarding of our legitimate interests.

Please note that the embedding of third-party content and functions will lead to your data being processed outside the EU or EEA. In some countries, this may entail the risk of public authorities accessing your data for security and surveillance purposes without informing you or offering legal remedies. In cases where you have consented to us using a provider in an unsafe third country, the data is transmitted to an unsafe third country on the basis of Article 49 (1 lit. a) GDPR.

 

Provider

Service/function

Adequate data protection level

Legal basis for processing the data

Amazon Web Services, Inc (USA)
Amazon Web Services EMEA SARL (Luxembourg)

Amazon CloudFront (Content Delivery Network)

Standard data protection clauses pursuant to Article 46 (2 lit. c) GDPR. The data transmission is also based on Article 49 (1 lit. a) GDPR

The data is processed on the basis of Article 6 (1 lit. f) GDPR

Cloudflare, Inc. (USA)

Cloudflare (Content Delivery Network)

Standard data protection clauses pursuant to Article 46 (2 lit. c) GDPR. The data transmission is also based on Article 49 (1 lit. a) GDPR

The data is processed on the basis of Article 6 (1 lit. f) GDPR

Google LLC (USA)
Google Ireland Limited (Ireland)

Google Tag Manager (provision of the tag management system)

Standard data protection clauses pursuant to Article 46 (2 lit. c) GDPR. The data transmission is also based on Article 49 (1 lit. a) GDPR

The data is processed on the basis of Article 6 (1 lit. f) GDPR

Google LLC (USA)
Google Ireland Limited (Ireland)

Photos

Standard data protection clauses pursuant to Article 46 (2 lit. c) GDPR. The data transmission is also based on Article 49 (1 lit. a) GDPR

The data is processed on the basis of Article 6 (1 lit. a) GDPR

HubSpot, Inc. (USA)

HubSpot (supports our marketing and sales processes by means of automated marketing)

Standard data protection clauses pursuant to Article 46 (2 lit. c) GDPR. The data transmission is also based on Article 49 (1 lit. a) GDPR

The data is processed on the basis of Article 6 (1 lit. f) GDPR Revocation is not possible.

G2.com, Inc. (USA)

G2Crowd (provision of a software rating form)

Standard data protection clauses pursuant to Article 46 (2 lit. c) GDPR. The data transmission is also based on Article 49 (1 lit. a) GDPR

The data is processed on the basis of Article 6 (1 lit. a) GDPR

Capterra, Inc. (USA)

Capterra (provision of a software rating form)

Standard data protection clauses pursuant to Article 46 (2 lit. c) GDPR. The data transmission is also based on Article 49 (1 lit. a) GDPR

The data is processed on the basis of Article 6 (1 lit. a) GDPR

Oktopost Technologies, Inc. (USA)

Oktopost (provision of a social media management platform)

Standard data protection clauses pursuant to Article 46 (2 lit. c) GDPR. The data transmission is also based on Article 49 (1 lit. a) GDPR

The data is processed on the basis of Article 6 (1 lit. a) GDPR

Liidio Oy (Finland)

Leadfeeder (provision of a software for lead generation)

Processing exclusively within EU/EEA

The data is processed on the basis of Article 6 (1 lit. a) GDPR

Unbounce Marketing Solutions Inc. (Canada)

Unbounce (Provision of landing pages)

Adequacy decision pursuant to Article 45 (1) GDPR

The data is processed on the basis of Article 6 (1 lit. a) GDPR

PartnerStack Inc. (USA)

PartnerStack (affiliate program)

Standard data protection clauses pursuant to Article 46 (2 lit. c) GDPR. The data transmission is also based on Article 49 (1 lit. a) GDPR

The data is processed on the basis of Article 6 (1 lit. a) GDPR

(b) Job applicants

(i) What personal data do we collect from you?

We process your contact details (name, address, email, telephone), CV, cover letter, certificates and qualifications, references, right-to-work documentation, and any other information you provide during the application process (including responses to any skills assessment or test). If you voluntarily disclose special-category data (for example, information about a disabled status, we process that on the basis of Article 9(2)(b) EU GDPR in combination with local employment-laws.

Where a background check is conducted, we also process the results of that check. Where you participate in an interview that we record (only with your consent), we process audio and video data together with an AI-generated transcript.

 

(ii) How do we collect it?

You provide most of this data directly through our applicant management system (Greenhouse). Our recruitment team and hiring managers may also contact you directly by email or telephone. Where you attend an interview, we use Microsoft Bookings or Demodesk to schedule it and may use Microsoft Teams, or a similar platform to conduct it. For some roles we use BrightHire to record and transcribe interviews — only with your specific consent under Article 6(1)(a) GDPR.

Where we perform a background check, we engage Zinc Work as a processor. Zinc may collect employment-history, education, reference, and right-to-work data on our behalf, directly from you or from the referees, educational institutions, and former employers that you nominate. Our legal basis for background checks is our legitimate interest in ensuring a fair, secure, and compliant hiring process (Article 6(1)(f) GDPR).

 

(iii) Why do we use it and what is our legal basis?

We use applicant data to do the following:

  • assess your application, administer the hiring process, and communicate with you – Article 6(1)(b) EU GDPR (pre-contractual measures);
  • verify identity, right to work, and references – legitimate interests (Article 6(1)(f) EU GDPR) and, where required, legal obligation (Article 6(1)(c) EU GDPR);
  • plan travel and reimburse expenses – Article 6(1)(b) EU GDPR (pre-contractual measures);
  • record and transcribe interviews – Article 6(1)(a) EU GDPR (consent), which you may withdraw at any time;
  • retain unsuccessful applications for future vacancies – Article 6(1)(a) EU GDPR (consent);
  • generate anonymous statistics about our recruitment activities – Article 6(1)(f) EU GDPR (on anonymised records only); and
  • defend against claims under equality and anti-discrimination laws – Article 6(1)(f) EU GDPR (our legitimate interest in the establishment, exercise, or defence of legal claims).

 

 

(iv) Who do we share your data with?

Within Lucanet, only staff who need your data to perform their tasks will have access to it (typically your potential manager, HR business partner, and where relevant – interview panel members).

Outside Lucanet, we share applicant data with:

RecipientPurpose
GreenhouseApplicant management system
Microsoft and DemodeskInterview scheduling
BrightHireInterview recording and AI transcription (with consent)
Zinc WorkBackground checks
Hosting, maintenance, support, archiving, and shredding providersGeneral IT and records-management support

 

Further information on how we process your personal data during the application process is available here: Data processing during application process here.

 

(c) Customers and customer users

(i) What personal data do we collect from them?

We process the following data:

  • Administrative data about the customer organisation: company name, tax/VAT registration details, contract terms, invoice and banking data, and support-ticket data.
  • Identification and contact data of authorised users: name, business email, telephone, job title, authentication credentials, user-role, session metadata, and log data (including records of actions taken in the service for audit and troubleshooting purposes).
  • Customer-uploaded personal data: any personal data that the customer uploads, creates, or processes in the Lucanet.Cloud, AMANA, or through Lucanet.Consulting services. This may include names and contact details of the customer's employees, officers, shareholders, and counterparties contained in financial accounting systems. We do not seek to receive any credit-card data, or personal health information – and our services are not designed to collect these, as confirmed in our Trust Center.

 

(ii) How do we collect it?

We collect administrative and user-account data from the customer directly (during onboarding, via our customer/partner portal, or during support interactions). Customer-uploaded personal data is collected by the customer and uploaded into our services by the customer; in relation to that data, Lucanet acts as a processor on the customer's documented instructions, with the customer remaining the controller.

 

(iii) Why do we use it and what is our legal basis?

We use customer data for the following purposes, in each case on the legal basis set out:

  • Contract performance (Article 6(1)(b) EU GDPR) – providing the Lucanet.Cloud and AMANA services; performing Lucanet.Consulting services including planning, technical advice, guidance/training, data collection and validation, data migration, implementation, troubleshooting, and customer-specific software development; providing updates; ensuring reliability, quality, and security of the licensed products.
  • Legitimate interests (Article 6(1)(f) EU GDPR) – contacting existing customers, administering the customer and partner portals, product improvement, internal auditing, IT-security operations, and defending legal claims.
  • Legal obligations (Article 6(1)(c) EU GDPR) – retaining contract, invoicing, and accounting records to comply with the local laws.
  • For customer-uploaded personal data, we process strictly on the customer's documented instructions under Article 28 EU GDPR and the applicable Standard Contractual Clauses. We do not use customer-uploaded data to train, fine-tune, or improve any AI models.

 

(iv) Who do we share your data with?

Within the Lucanet group, customer data is shared between Lucanet AG and the relevant sales subsidiary acting as a processor. The sales subsidiary identified in the customer agreement acts as a processor. To deliver the Lucanet.Cloud, Lucanet AG also engages authorised sub-processors. As at the date of this Privacy Notice, these include, for example

  • Amazon Web Services EMEA SARL (Luxembourg) – cloud services and AI model inference (processed solely for inference; not used to train, fine-tune, or improve AI models).
  • Microsoft Ireland Operations Limited – hosting and AI model inference (not used to train, fine-tune, or improve AI models).
  • Google Cloud EMEA Limited (Ireland) – AI model inference (not used to train, fine-tune, or improve AI models).

 

The current list of sub-processors is maintained in the Lucanet Trust Center and in Annex IV of the applicable Standard Contractual Clauses.

We notify customers in writing at least one month in advance of any intended addition or replacement of sub-processors, giving the customer sufficient time to object; we will provide information necessary to enable a customer to exercise that right.

 

(d) Business contacts and prospects

(i) What personal data do we collect from them?

We collect name, job title, employer, business email, business telephone number, professional profile links (e.g. LinkedIn), communication history, marketing preferences, and information about your interest in our services (for example, demo requests, webinar or event attendance, white-paper downloads, and campaign engagement).

 

(ii) How do we collect it?

Directly from you (for example, when you contact us, book a demo, register for a webinar or event, subscribe to our newsletter, or visit our stand at an event); from publicly available sources (such as corporate websites, business directories, or professional networks); or from third-party lead-generation, referrer, and data-enrichment providers, where permitted by applicable law. Where we run joint events or co-marketing with our partners, we may also receive attendee details from the partner under the applicable event terms.

 

(iii) Why do we use it and what is our legal basis?

We use business-contact data for:

  • pre-contractual communications – Article 6(1)(b) EU GDPR.
  • marketing, business development, and nurture campaigns – Article 6(1)(a) EU GDPR (consent, where required by law or Article 6(1)(f) EU GDPR (legitimate interest in marketing to existing and prospective B2B customers, subject to the right to object).
  • customer-relationship management and sales activity tracking – Article 6(1)(f) EU GDPR.
  • account-based marketing and segmentation – Article 6(1)(f) EU GDPR, subject to right to object.
  • press and public relations – Article 6(1)(a) EU GDPR (consent, for the press mailing list).

 

(iv) Who do we share your data with?

Within Lucanet, our sales, marketing, and customer-success teams have access. Externally, we share business-contact data with our marketing-automation providers (such as HubSpot), CRM, analytics, advertising networks, event-management tools (such as XING Events (New Work SE)), webinar platforms (such as GoTo Webinar), and event-show organisers, where applicable.

 

(e) Suppliers and partners

(i) What personal data do we collect from them?

We collect name, job title, company name, business contact details, contract data, invoice data, bank-account and tax-identification details where required for payment, sanctions-screening and due-diligence records, communication records, and any other data necessary to onboard and manage the supplier or partner relationship. For partners using our affiliate or reseller programme, we also collect programme-related usage and performance data.

 

(ii) How do we collect it?

From the supplier or partner directly (via contracting, onboarding forms, or our partner portal), from third-party registries and sanctions-screening databases where integrity checks are required (including, where applicable, checks against EU,

UN, US, and UK sanctions lists), from our accounting and Enterprise Resource Planning (“ERP”) systems, and from our own interactions with the supplier or partner during the engagement.

 

(iii) Why do we use it and what is our legal basis?

We use supplier and partner data to:

  • perform the contract (Article 6(1)(b) EU GDPR).
  • comply with legal obligations (Article 6(1)(c) EU GDPR) – tax, accounting, anti-money-laundering, sanctions-screening, and anti-bribery obligations.
  • pursue legitimate interests (Article 6(1)(f) EU GDPR) – supplier due diligence, integrity checks, fraud prevention, credit-check, operational management, partner-performance tracking, and defence of legal claims.
  • administer the affiliate/reseller programme – Article 6(1)(b) EU GDPR (contract performance).

 

(iv) Who do we share your data with?

Our accounting and ERP providers, tax advisers, auditors, banks and payment processors, sanctions-screening providers etc. and where required – competent public authorities or regulators.

 

(f) Further information

Information on processing of data from customer/partner: Read now

6. What’s our position on sharing, security, data transfers and retention?

This section explains who we share your personal data with, the technical and organisational security measures we apply (including our ISO/IEC 27001/27017/27018 and SOC 1/SOC 2 certifications), the mechanisms we use for international transfers, and how long we retain each category of data.


(a) Who do we share your personal data with?

We share personal data only where necessary and only with recipients that are subject to appropriate confidentiality and data-protection obligations. Recipients fall into the following categories:

  • Other Lucanet group companies – for administrative purposes, service delivery, group IT, HR, finance, CRM, and partner-programme functions. Intra-group transfers are governed by our internal data-sharing arrangements.
  • Service providers – hosting, cloud infrastructure, CRM, marketing automation, analytics, consent management, applicant tracking, support, AI inference, auditing, background-checking, and payment services. All processors are contractually bound by Article 28 EU GDPR data processing agreements (or local equivalents).
  • Professional advisers – external lawyers, auditors (including for our ISO/IEC 27001, 27017, 27018, SOC 1 Type 2, and SOC 2 Type 2 audits), accountants, tax advisers, and insurers, where needed for professional advice and assurance.
  • Prospective buyers or investors – in connection with a corporate transaction such as a merger, acquisition, restructuring, or financing, under appropriate confidentiality undertakings. In such a case, personal data may be transferred to the acquirer or its advisers.
  • Competent authorities – where legally required to comply with a valid request from a public authority, court order, or regulatory obligation. We will challenge such requests where we consider it appropriate and lawful to do so.

 

(b) How do we ensure your personal data is protected?

We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These are set out in our IT Security Guideline and are reviewed at least every 12 months.

Key measures include:

  • Governance and organisation – a designated security team responsible for designing, coordinating, and monitoring our IT security programme; documented policies and procedures retained even when superseded; pre-engagement risk assessments; confidentiality undertakings for all employees with access to customer data; documented protocols for staff with access to customer data.
  • Training and awareness – all staff receive training on data-protection basics, our technical and organisational measures, their individual tasks relating to IT security, and the personal consequences of breaching privacy or the IT Security Guideline.
  • Physical security – restricted facility access to authorised personnel; industry-standard protections against power outages and line disruptions; contingency plans for facilities housing customer data; restoration processes to reconstruct data in its original state or most recent backup state.
  • Mobile work – employees require advance permission to store customer data on portable devices, access customer data remotely, or process customer data outside Lucanet facilities.
  • Access controls – industry-standard user authentication; password minimum requirements and regular rotation; industry-standard password protection; monitoring of repeated invalid logins; blocked user accounts not reassigned; immediate revocation of access when an employee leaves; up-to-date records of authorised users; role-based authorisation with "need to know" and "least privilege" principles; mandatory computer lock on leaving workstations unsupervised.
  • Operations – at-least-weekly backups stored in a separate location; access-controlled backups; annual review of restoration procedures; logged restoration activities; firewalls; up-to-date virus scanners at network-access points, on file servers, and on individual workstations; prohibition on installing non-approved software.
  • Encryption – TLS encryption for data transmitted over public networks; encryption of portable media carrying customer data.
  • Data destruction – documented protocols for deleting or destroying data and data media once no longer required; controls on printing of customer data and rules for storage and disposal of printed materials.
  • Incident response – mandatory immediate internal notification of any incident classified as a data-protection violation; records kept of each incident including description, timing, reporter, recipient, and remedial measures taken.

 

We are certified to ISO/IEC 27001:2022 (Information Security Management, BSI IS 714969), ISO/IEC 27017:2015 (Cloud Security, BSI CLOUD 776088), and ISO/IEC 27018:2019 (Protection of Personally Identifiable Information in the Cloud) – all successfully recertified in December 2025.

We also undergo annual SOC 1 Type 2 and SOC 2 Type 2 audits (covering financial-reporting controls and security/availability/confidentiality of customer data respectively), with the 2025 reports confirming that our internal controls are designed and operating effectively. ISAE 3402 and IDW PS 951 versions of the SOC 1 report are available to support international customers. Current audit reports and certifications can be obtained through the Lucanet Trust Center on request.

In line with Article 30 EU GDPR (and local equivalents), we maintain records of processing activities for both our controller and processor activities, including descriptions of the categories of data, purposes, recipients, transfers, retention, and technical and organisational measures. These records are made available to supervisory authorities on request.

 

(c) How do we protect personal data when it is transferred internationally?

As we operate globally, we transfer personal data between Lucanet group companies and to third-party service providers located in countries outside the European Economic Area (“EEA”), the United Kingdom, and Switzerland. We use the following mechanisms to ensure your data continues to be protected:

  • EEA adequacy decisions – for transfers to countries the European Commission has deemed to offer an adequate level of protection (currently including the United Kingdom, Switzerland, Japan (for APPI-certified recipients), Canada (commercial organisations), South Korea, Argentina, Andorra, Brazil, Guernsey, Isle of Man, Jersey, Israel, New Zealand, Uruguay, the Faroe Islands, and – subject to its continued validity – the EU–US Data Privacy Framework for certified US organisations).
  • EU Standard Contractual Clauses (“SCCs”) – for transfers to countries without an adequacy decision, we use the European Commission's SCCs (Implementing Decision (EU) 2021/914) in the appropriate module (Controller–Controller, Controller–Processor, Processor–Processor, or Processor–Controller). Our standard customer SCCs are published in our Trust Center.
  • Transfer Impact Assessments (“TIAs”) – following the Schrems II judgment, we conduct and document TIAs for transfers outside the EEA to assess the laws and practices of the destination country and to identify any supplementary measures required. TIAs are reviewed periodically and on notice of any material change and stored internally.
  • UK International Data Transfer Agreement (“IDTA”) or UK Addendum to the EU SCCs – for transfers of UK personal data to third countries.
  • Swiss‑specific SCC arrangements – For transfers of Swiss personal data, we use EU SCCs adapted for Swiss law (for example, via a Swiss addendum) in line with guidance from the Swiss authorities.
  • Supplementary measures – technical measures (encryption in transit and at rest, pseudonymisation, access restrictions), contractual measures, and organisational measures (training, vetted access lists, documented processes).
  • China’s PIPL – for transfers of personal information from our Chinese entities, we use certain pathways recognised under the PIPL including (i) CAC security assessment; or (ii) China standard contractual clauses. Where applicable, we rely on exemptions set out in law. We also obtain “separate consent” from individuals where required and provide the notice details specified by PIPL.
  • Japan’s APPI – for transfers of personal information from Japan, we rely on either (a) the recipient being in a jurisdiction recognised under APPI (currently including the EEA and the UK), (b) the recipient implementing equivalent safeguards under an APPI‑compliant contract, or (c) the individual’s informed consent, including information on the recipient country’s data protection regime.
  • Singapore’s PDPA – for transfers of personal data from Singapore, we ensure that the recipient is bound by legally enforceable obligations providing a comparable standard of protection (including through contractual clauses, binding corporate rules or recognised certification). Singapore customers are additionally subject to the PDPA Supplement to the non‑EU SCCs, which sets out the service purposes and general purposes for which data may be processed.

 

(d) How long do we keep your personal data for?

We keep your personal data only for as long as necessary for the purposes set out in this notice and in accordance with applicable data retention obligations, which vary by jurisdiction. At the end of the applicable period, we delete or anonymise the data.

The periods set out below are intended as general guidance. Where local law requires a different period, the local requirement takes precedence. The German statutory references are cited as illustrative examples of the types of obligation that commonly apply across our operating jurisdictions.

CategoryRetention period
Customer and partner contract dataTerm of the contract, plus applicable statutory retention periods (generally 6 or 10 years under §§ 147 AO and 257 HGB, or local equivalents) and statutory limitation periods (generally 3 years under § 195 BGB, up to 30 years in certain cases).
Applicant data (unsuccessful applications)Usually no later than 6 months after completion of the recruitment process. If you consent to retention for future roles, up to 12 months.
Applicant data (successful applications)Transferred into your employment record and retained for the duration of the employment relationship plus statutory periods.
Interview recordings and transcripts (BrightHire)No later than 90 days after the interview.
Website log data and full IP addresses1 year (then deleted or anonymised).
Cookie data (optional/consent-based)Per cookie duration declared in the Cookies Notice; session cookies until browser close; permanent cookies for their declared lifetime or until you withdraw consent.
Newsletter subscription dataUntil you unsubscribe, plus a short audit log for compliance purposes.
Marketing contact dataUntil you object, withdraw consent, or we determine the data is no longer relevant.
Support ticketsDuration of the contract plus applicable statutory retention periods.
Financial and tax recordsAs required by applicable law (for example, 10 years under German HGB/AO from the end of the relevant calendar year, or local equivalent)
Records of processing activities (RoPA) and DPIAsFor the duration of the processing activity and for evidential purposes thereafter.

 

Where data is no longer required for its original purpose but must be retained to satisfy a statutory obligation, we restrict processing so that it is no longer actively used. Once the statutory period expires, the data is deleted or securely destroyed.

7. What rights do you have under data protection laws?

This section sets out your rights as a data subject under EU/UK GDPR as our global baseline, with jurisdiction-specific variations under Swiss, Chinese, Japanese, Singaporean, and US law. Explains how to exercise your rights, how we verify requests, and when we will respond.

 

(a) What rights do you have in respect of your personal data?

Depending on which data protection law applies to you, you have the rights outlined below. The list below includes EU/UK GDPR rights (which we extend to all individuals globally as our baseline) together with notable variations under Swiss, Chinese, Japanese, Singaporean, and US law. In addition to the rights below, you have the right to be informed about our processing (which is the purpose of this Privacy Notice).

 

(b) What is the right of access?

You have the right to confirmation of whether we process your personal data and, if so, to a copy of the data and information about the processing (EU/UK GDPR; FADP; PIPL; APPI; PDPA; CCPA and equivalents in other US states). Under the UK Data (Use and Access) Act 2025, our search must be "reasonable and proportionate"; we may also pause the one-month clock in limited circumstances (for example, to verify your identity or clarify the scope of your request).

 

(c) What is the right to rectification?

You have the right to request the correction of inaccurate personal data and completion of incomplete data (EU/UK GDPR; FADP; PIPL; APPI; PDPA; and most US state laws).

 

(d) What is the right to erasure?

You have the right to request deletion (the "right to be forgotten") where one of the grounds set out in the EU GDPR applies – for example, where the data is no longer necessary for the purpose for which it was collected, where you have withdrawn consent, or where the processing is unlawful. Equivalents apply under UK GDPR, FADP, PIPL, APPI, and several US state laws. Exceptions apply, including where processing is necessary to comply with a legal obligation, for reasons of public interest, or for the establishment, exercise, or defence of legal claims. Where data is required only for statutory retention, we will restrict processing rather than delete.

 

(e) What is the right to restrict processing?

You have the right to request that we restrict processing in the circumstances set out in the EU GDPR – for example, where you contest the accuracy of the data, where processing is unlawful but you oppose erasure, or where we no longer need the data but you need it for legal claims. Under APPI, a narrower right to suspend use applies in specified circumstances (including where data has been obtained by deception or is being used for purposes other than those disclosed).

 

(f) What is the right to data portability?

Where processing is based on consent or contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to have it transmitted to another controller where technically feasible (EU/UK GDPR and PDPA).

 

(g) What is the right to object?

Where we process personal data on the basis of legitimate interests (Article 6(1)(f) EU GDPR) or for direct marketing, you have the right to object. If you object to direct marketing, we will stop processing your data for that purpose immediately. Where you object on grounds relating to your particular situation, we will stop processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is for the establishment, exercise, or defence of legal claims.

 

(h) What rights do you have in relation to automated decision-making?

You have the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal or similarly significant effects on you (EU/UK GDPR; FADP and PIPL). This right includes the right to obtain human intervention, to express your point of view, and to contest the decision.

Under the CCPA, you have a right to opt out of certain uses of Automated Decision-Making Technology (“ADMT”) – specifically where ADMT is used in decisions that replace or substantially replace human decision-making – and we must conduct a privacy risk assessment in advance. Lucanet does not carry out such solely-automated decision-making in connection with the core Lucanet.Cloud and AMANA services.

 

(i) How do you exercise your rights?

You can exercise your rights free of charge by contacting us at legal@lucanet.com.

Where you are exercising a right in relation to services Lucanet provides to a customer as a processor, we will refer your request to the relevant customer (acting as the data controller).

We may need to verify your identity before responding, especially where the request concerns sensitive data or could otherwise lead to disclosure to a person who is not the data subject.

Verification may involve confirming details we already hold (for example, the email address associated with an account). We will not charge a fee except in limited cases (for example, manifestly unfounded or excessive requests), and we will explain any charge in advance.

 

(j) When will we respond to your request?

We aim to respond as soon as possible and in any event within the applicable statutory timescale:

  • One month under the EU GDPR, UK GDPR, and most EU Member States (extendable by two further months for complex or numerous requests).
  • 15 business days under the PIPL (subject to extension for complex requests).
  • 45 days under the CCPA (extendable by a further 45 days where necessary), and typically 45–60 days under other US state privacy laws.
  • 30 days under the Singapore PDPA.
  • A reasonable period "without delay" under the Japanese APPI, normally within two weeks.

 

8. How can you raise concerns and make complaints to us?

This section tells you how to raise a concern with us directly including the statutory right to complain to us under the UK Data (Use and Access) Act 2025 – and how to complain to a supervisory authority. Confirms your parallel right to pursue a judicial remedy.

 

(a) What should you do if you have any concerns about how we use your personal data?

If you have a concern, we encourage you to contact us first so that we can try to address it directly. Please contact us, setting out the nature of your concern and (if possible) attaching any relevant correspondence. We will acknowledge receipt promptly and aim to provide a substantive response within one month (or as otherwise required by the applicable law).

Under the UK Data (Use and Access) Act 2025, UK data subjects have a statutory right to complain directly to Lucanet about any aspect of our processing – and we must acknowledge such complaints within one month and then provide a response without undue delay.

Similar informal pre-complaint pathways are recognised under most other laws (including the Singapore PDPA and PIPL).

 

(b) How can you complain to a supervisory authority?

You also have the right to lodge a complaint with a data protection supervisory authority. Under the EU GDPR, you can complain to the authority in the country in which you habitually reside, where you work, or where the alleged infringement took place. Under the UK GDPR, you can complain to the Information Commissioner's Office. Under other laws, the competent authority is set out in the table in Section 4 above.

Where cross-border processing within the EU is concerned, the EU's one-stop-shop mechanism means that your local authority will typically liaise with our lead authority (the Berlin Commissioner), and the two authorities will coordinate under the European Data Protection Board's consistency procedures. You may also seek judicial remedies under EU GDPR; bringing a complaint does not prejudice your ability to pursue a legal remedy in court.

9. Do we have any website specific practices?

This section covers our use of cookies and similar technologies, third-party links, embedded content, marketing communications, and anonymised data on our websites. Explains how you can manage your cookie and marketing preferences at any time.

 

(a) What other links and features are on our website?

Our website contains links to third-party websites (including social-media platforms such as LinkedIn YouTube, and Vimeo etc.). We are not responsible for the privacy practices of those third parties, and this Privacy Notice does not apply to them. We encourage you to read their privacy notices before interacting with their services. Where we embed third-party content (such as videos), that content is only loaded after you have given consent via our cookie banner.

 

(b) How do we use cookies and similar technologies?

We use strictly necessary cookies to operate the website, and (with your consent via our Usercentrics consent banner) optional cookies for analytics, advertising, and embedded content. Full details of the providers we use are available in our Cookies Statement.

Our web pages use cookies. Cookies are small text files that are stored on your computer and contain readable data. A distinction is made between session cookies, which are deleted as soon as you close your browser, and permanent cookies that are stored for longer than a single session.

Cookies that are strictly necessary for the operation of our website may contain information on certain settings. They may also be necessary for user navigation, security and layout purposes. We use these cookies on the legal basis of Section 25 (2 no. 2) TTDSG.

We also use cookies for analysis, tracking and advertising purposes. The use of these cookies is based on Section 25 (1) TTDSG (consent). Further information on the cookies used on your website can be found in our Cookies Statement.

You can adjust the settings of your browser so that you are alerted each time a cookie is placed on your computer. This assures a transparent use of cookies. You can also use your browser settings to delete cookies and prevent the placement of new cookies. Please note that this may result in difficulties displaying our website and some functions may no longer be available for technical reasons.

 

(c) How do we use your personal data for marketing purposes?

We use contact and interaction data to send you information about Lucanet products, services, events, webinars, white papers, and newsletters, but only where applicable law permits us to do so. Where required by law, we rely on your consent for email marketing. Where permitted without consent, such as for B2B communications to existing customers and contacts who have expressed an interest in our services, we may rely on our legitimate interests. Every marketing email contains a clear one-click unsubscribe link, and our preference centre allows you to adjust the types of messages you receive.

 

(d) What about anonymised and aggregated data?

We use anonymised and aggregated data (for example, statistical data about website usage, applicant numbers, conversion rates, or product performance) for business analysis, reporting, and product improvement. As this data no longer identifies any individual, data protection law does not apply once the data has been effectively anonymised.

10. Will we make any updates to this privacy notice?

This section explains how we will notify you of material changes to this Privacy Notice. Confirms that the latest version is always available on our website, dated and numbered, with a change log for material amendments.

 

We may update this Privacy Notice from time to time to reflect changes in our processing, our services, applicable law, or guidance from supervisory authorities. The current version is always available on our website at lucanet.com/en/data-protection, with the version number and "Last updated" date at the top. We maintain a change log noting material amendments.

For material changes (for example, new purposes of processing, new categories of recipients, or new international-transfer mechanisms), we will take appropriate steps to notify you in advance – by email, in-product notification, or a prominent website banner, depending on the channel available. Where the change requires your renewed consent, we will obtain that consent before applying the change to your data.

11. How can you get in touch?

This section provides every contact route in one place – Lucanet AG, the DPO, the Legal Department and the Trust Center. Your primary starting point for day-to-day data-protection queries.

 

We are always happy to hear from you. You can reach us at:

Lucanet AG (group headquarters and website controller): Karl-Liebknecht-Str. 14, 10178 Berlin, Germany. Email: legal@lucanet.com.

Trust Center: Certifications (ISO/IEC 27001:2022, 27017:2015, 27018:2019), audit reports (SOC 1 Type 2 / SOC 2 Type 2 / ISAE 3402 / IDW PS 951), policies, sub processor list, and FAQs: accessible via the Lucanet Trust Center.

Local contact: For questions concerning the Lucanet group entity that contracted with you, please contact that entity using the details in your contract; if you are unsure, contact info@lucanet.com and we will route your enquiry to the appropriate team.

 

Contact Us