(b) Job applicants
(i) What personal data do we collect from you?
We process your contact details (name, address, email, telephone), CV, cover letter, certificates and qualifications, references, right-to-work documentation, and any other information you provide during the application process (including responses to any skills assessment or test). If you voluntarily disclose special-category data (for example, information about a disabled status, we process that on the basis of Article 9(2)(b) EU GDPR in combination with local employment-laws.
Where a background check is conducted, we also process the results of that check. Where you participate in an interview that we record (only with your consent), we process audio and video data together with an AI-generated transcript.
(ii) How do we collect it?
You provide most of this data directly through our applicant management system (Greenhouse). Our recruitment team and hiring managers may also contact you directly by email or telephone. Where you attend an interview, we use Microsoft Bookings or Demodesk to schedule it and may use Microsoft Teams, or a similar platform to conduct it. For some roles we use BrightHire to record and transcribe interviews — only with your specific consent under Article 6(1)(a) GDPR.
Where we perform a background check, we engage Zinc Work as a processor. Zinc may collect employment-history, education, reference, and right-to-work data on our behalf, directly from you or from the referees, educational institutions, and former employers that you nominate. Our legal basis for background checks is our legitimate interest in ensuring a fair, secure, and compliant hiring process (Article 6(1)(f) GDPR).
(iii) Why do we use it and what is our legal basis?
We use applicant data to do the following:
- assess your application, administer the hiring process, and communicate with you – Article 6(1)(b) EU GDPR (pre-contractual measures);
- verify identity, right to work, and references – legitimate interests (Article 6(1)(f) EU GDPR) and, where required, legal obligation (Article 6(1)(c) EU GDPR);
- plan travel and reimburse expenses – Article 6(1)(b) EU GDPR (pre-contractual measures);
- record and transcribe interviews – Article 6(1)(a) EU GDPR (consent), which you may withdraw at any time;
- retain unsuccessful applications for future vacancies – Article 6(1)(a) EU GDPR (consent);
- generate anonymous statistics about our recruitment activities – Article 6(1)(f) EU GDPR (on anonymised records only); and
- defend against claims under equality and anti-discrimination laws – Article 6(1)(f) EU GDPR (our legitimate interest in the establishment, exercise, or defence of legal claims).
(iv) Who do we share your data with?
Within Lucanet, only staff who need your data to perform their tasks will have access to it (typically your potential manager, HR business partner, and where relevant – interview panel members).
Outside Lucanet, we share applicant data with:
| Recipient | Purpose |
| Greenhouse | Applicant management system |
| Microsoft and Demodesk | Interview scheduling |
| BrightHire | Interview recording and AI transcription (with consent) |
| Zinc Work | Background checks |
| Hosting, maintenance, support, archiving, and shredding providers | General IT and records-management support |
Further information on how we process your personal data during the application process is available here: Data processing during application process here.
(c) Customers and customer users
(i) What personal data do we collect from them?
We process the following data:
- Administrative data about the customer organisation: company name, tax/VAT registration details, contract terms, invoice and banking data, and support-ticket data.
- Identification and contact data of authorised users: name, business email, telephone, job title, authentication credentials, user-role, session metadata, and log data (including records of actions taken in the service for audit and troubleshooting purposes).
- Customer-uploaded personal data: any personal data that the customer uploads, creates, or processes in the Lucanet.Cloud, AMANA, or through Lucanet.Consulting services. This may include names and contact details of the customer's employees, officers, shareholders, and counterparties contained in financial accounting systems. We do not seek to receive any credit-card data, or personal health information – and our services are not designed to collect these, as confirmed in our Trust Center.
(ii) How do we collect it?
We collect administrative and user-account data from the customer directly (during onboarding, via our customer/partner portal, or during support interactions). Customer-uploaded personal data is collected by the customer and uploaded into our services by the customer; in relation to that data, Lucanet acts as a processor on the customer's documented instructions, with the customer remaining the controller.
(iii) Why do we use it and what is our legal basis?
We use customer data for the following purposes, in each case on the legal basis set out:
- Contract performance (Article 6(1)(b) EU GDPR) – providing the Lucanet.Cloud and AMANA services; performing Lucanet.Consulting services including planning, technical advice, guidance/training, data collection and validation, data migration, implementation, troubleshooting, and customer-specific software development; providing updates; ensuring reliability, quality, and security of the licensed products.
- Legitimate interests (Article 6(1)(f) EU GDPR) – contacting existing customers, administering the customer and partner portals, product improvement, internal auditing, IT-security operations, and defending legal claims.
- Legal obligations (Article 6(1)(c) EU GDPR) – retaining contract, invoicing, and accounting records to comply with the local laws.
- For customer-uploaded personal data, we process strictly on the customer's documented instructions under Article 28 EU GDPR and the applicable Standard Contractual Clauses. We do not use customer-uploaded data to train, fine-tune, or improve any AI models.
(iv) Who do we share your data with?
Within the Lucanet group, customer data is shared between Lucanet AG and the relevant sales subsidiary acting as a processor. The sales subsidiary identified in the customer agreement acts as a processor. To deliver the Lucanet.Cloud, Lucanet AG also engages authorised sub-processors. As at the date of this Privacy Notice, these include, for example
- Amazon Web Services EMEA SARL (Luxembourg) – cloud services and AI model inference (processed solely for inference; not used to train, fine-tune, or improve AI models).
- Microsoft Ireland Operations Limited – hosting and AI model inference (not used to train, fine-tune, or improve AI models).
- Google Cloud EMEA Limited (Ireland) – AI model inference (not used to train, fine-tune, or improve AI models).
The current list of sub-processors is maintained in the Lucanet Trust Center and in Annex IV of the applicable Standard Contractual Clauses.
We notify customers in writing at least one month in advance of any intended addition or replacement of sub-processors, giving the customer sufficient time to object; we will provide information necessary to enable a customer to exercise that right.
(d) Business contacts and prospects
(i) What personal data do we collect from them?
We collect name, job title, employer, business email, business telephone number, professional profile links (e.g. LinkedIn), communication history, marketing preferences, and information about your interest in our services (for example, demo requests, webinar or event attendance, white-paper downloads, and campaign engagement).
(ii) How do we collect it?
Directly from you (for example, when you contact us, book a demo, register for a webinar or event, subscribe to our newsletter, or visit our stand at an event); from publicly available sources (such as corporate websites, business directories, or professional networks); or from third-party lead-generation, referrer, and data-enrichment providers, where permitted by applicable law. Where we run joint events or co-marketing with our partners, we may also receive attendee details from the partner under the applicable event terms.
(iii) Why do we use it and what is our legal basis?
We use business-contact data for:
- pre-contractual communications – Article 6(1)(b) EU GDPR.
- marketing, business development, and nurture campaigns – Article 6(1)(a) EU GDPR (consent, where required by law or Article 6(1)(f) EU GDPR (legitimate interest in marketing to existing and prospective B2B customers, subject to the right to object).
- customer-relationship management and sales activity tracking – Article 6(1)(f) EU GDPR.
- account-based marketing and segmentation – Article 6(1)(f) EU GDPR, subject to right to object.
- press and public relations – Article 6(1)(a) EU GDPR (consent, for the press mailing list).
(iv) Who do we share your data with?
Within Lucanet, our sales, marketing, and customer-success teams have access. Externally, we share business-contact data with our marketing-automation providers (such as HubSpot), CRM, analytics, advertising networks, event-management tools (such as XING Events (New Work SE)), webinar platforms (such as GoTo Webinar), and event-show organisers, where applicable.
(e) Suppliers and partners
(i) What personal data do we collect from them?
We collect name, job title, company name, business contact details, contract data, invoice data, bank-account and tax-identification details where required for payment, sanctions-screening and due-diligence records, communication records, and any other data necessary to onboard and manage the supplier or partner relationship. For partners using our affiliate or reseller programme, we also collect programme-related usage and performance data.
(ii) How do we collect it?
From the supplier or partner directly (via contracting, onboarding forms, or our partner portal), from third-party registries and sanctions-screening databases where integrity checks are required (including, where applicable, checks against EU,
UN, US, and UK sanctions lists), from our accounting and Enterprise Resource Planning (“ERP”) systems, and from our own interactions with the supplier or partner during the engagement.
(iii) Why do we use it and what is our legal basis?
We use supplier and partner data to:
- perform the contract (Article 6(1)(b) EU GDPR).
- comply with legal obligations (Article 6(1)(c) EU GDPR) – tax, accounting, anti-money-laundering, sanctions-screening, and anti-bribery obligations.
- pursue legitimate interests (Article 6(1)(f) EU GDPR) – supplier due diligence, integrity checks, fraud prevention, credit-check, operational management, partner-performance tracking, and defence of legal claims.
- administer the affiliate/reseller programme – Article 6(1)(b) EU GDPR (contract performance).
(iv) Who do we share your data with?
Our accounting and ERP providers, tax advisers, auditors, banks and payment processors, sanctions-screening providers etc. and where required – competent public authorities or regulators.
(f) Further information
Information on processing of data from customer/partner: Read now