Opens in a new tab

General Terms and Conditions

Parties: Lumnio INC (“Lumnio”) & Customer (individually a “Party”, collectively the “Parties”)

This Subscription Agreement (the “Agreement”) is entered into as of the Effective Date by and between the Parties. In consideration of the mutual covenants contained herein, the Parties agree as follows:

1. Definitions

TermDefinition
AffiliateAny entity that, directly or indirectly, controls, is controlled by, or is under common control with a Party (where “control” means ownership of more than 50% of voting interests).
Applicable Data Protection Law(a) EU Regulation 2016/679 (GDPR) and national laws made under it; and
(b) The Swiss Federal Act on Data Protection (as amended).
Authentication KeyAny access, application, or authentication key necessary for utilizing an Authorized API.
Authorized APIApplication programming interfaces developed and enabled by Lumnio to permit access to Subscription Services.
Beta ServicesOptional, no-charge trial features designated as beta, pilot, limited release, early access, or evaluation.
CustomerAny individual or entity who enters into an Order Form with Lumnio to use the Subscription Services.
Customer PropertyAny content (text, images, charts, tables, etc.) supplied by Customer to Lumnio directly or via Third Party Products.
DocumentationAll instructional materials and guides made available by Lumnio regarding the Subscription Services.
End-UsersAny person or entity other than Customer or Users with whom Customer or Users interact using the Service.
Order FormAn ordering document/online transaction for Subscription Services executed or electronically accepted by the Customer.
Personal DataAny information relating to an identified or identifiable natural person (“data subject”) as defined under GDPR.
ProcessingAny operation performed on Personal Data (collection, storage, disclosure, erasure, destruction, etc.).
Lumnio PropertyThe Subscription Services, the Documentation, and all content, materials, or software supplied by Lumnio.
SubprocessorAny third-party data processor (including Lumnio Affiliates) engaged to process Customer Property.
Subscription ServicesThe software platform, web interfaces, applications, Authorized APIs, and any updates or modifications.
Subscription TermThe active subscription period specified in the applicable Order Form.
Third Party ProductsThird-party applications, systems, or services (e.g., ticketing/email) integrated with the Subscription Services.
UsersAll users authorized to access the Customer’s account, including “Makers” and “Contributors.”

Confidential Information Definition

“Confidential Information” means all proprietary information disclosed by one Party (Disclosing Party) to the other (Receiving Party), whether oral or written, marked as confidential or reasonably considered confidential by nature. Lumnio’s Confidential Information includes Lumnio Property, terms of this Agreement, and all Order Forms.

Exclusions: Confidential Information does not include information that:

  1. Is or becomes public knowledge without breach of this Agreement.
  2. Was already known to the Receiving Party prior to disclosure.
  3. Was independently developed by the Receiving Party without reference to Disclosing Party’s information.
  4. Is received from a third party without breach of any confidentiality obligation.

2. Subscription Services

(a) Provision of Subscription Services

Subject to the payment of all applicable Fees and for the active Subscription Term, Lumnio grants the Customer a non-sublicensable, non-transferable, and non-exclusive right to access and use the Subscription Services.

(b) Order Forms

Each Order Form details specific limitations, Fees, the Subscription Term, and the permitted number/class of Users.

  • Email Confirmations: Automatic renewals and pricing for Subscription Upgrades can be confirmed via email by the Parties, creating a binding obligation without requiring a newly executed Order Form.

(c) Lumnio Guidelines

Customer must comply, and ensure all Users and End-Users comply, with the guidelines set forth in Annex A (the “Lumnio Guidelines”).

(d) Free Trials

If Customer registers for a Free Trial, services are provided free of charge until the earliest of:

  • The end of the designated Free Trial period.
  • The start date of any purchased Subscription Term.
  • Termination of the trial by Lumnio at its sole discretion.

⚠️ CRITICAL DATA LOSS WARNING: Any customer property, configurations, or customizations made during a Free Trial will be permanently lost unless the Customer purchases a matching subscription or exports their data before the trial period expires.

3. Fees and Payment Terms

(a) Fees & Upgrades

  • Subscription Upgrades: If Customer adds services or exceeds previously purchased usage levels during a term, incremental Fees will be prorated over the remaining term. Renewal terms will automatically reflect these upgraded levels.
  • Currency & Refunds: All fees are in USD. Payment obligations are non-cancelable and fees are non-refundable.

(b) Invoices and Payment

  • Credit Cards / Automated Payment: By providing a Payment Method, Customer authorizes Lumnio to charge all applicable Fees on a monthly basis or at intervals stated in the Order Form.
  • Invoicing: If no credit card is provided, Lumnio will issue invoices via email. Invoiced amounts must be paid within 30 calendar days of the invoice date.
  • Default Terms: Unless specified otherwise, Fees are paid on an annual, prepaid basis. Overdue balances are subject to a finance charge of 1.5% per month (or the maximum legal limit, whichever is lower) plus collection expenses.

(c) Taxes

Customer is solely responsible for all taxes, tariffs, or duties (except taxes based on Lumnio’s net income). If Lumnio is required to pay these directly, Customer will promptly reimburse Lumnio.

(d) Free Trial Billing

If billing info is provided at signup, charging will only begin after the Free Trial expires. To prevent automatic charging at Lumnio’s standard rates, Customer must cancel the service prior to the end of the trial via lumnio@lumnio.com.

(e) Promotional Credits

  • Credits (coupons, promotions, referrals) have no cash value and are non-transferable.
  • They can only be used to offset future Lumnio Subscription Service fees.
  • Unless stated otherwise, all credits expire 12 months from the date of issuance.

4. Proprietary Rights

  • Customer Property: Customer retains all rights, title, and intellectual property interest in Customer Property. No ownership is transferred to Lumnio.
  • Lumnio Property: Lumnio retains all rights, title, and intellectual property interest in Lumnio Property. No ownership is transferred to Customer.
  • Licenses Granted to Lumnio: * Data License: Customer grants Lumnio a limited, royalty-free license to use Customer Property solely to provide the Subscription Services.
    • Marketing License: Customer grants Lumnio a revocable license to use Customer’s trademark/logo to identify them as a customer (revocable at any time).
    • Feedback License: Any feedback, comments, or feature requests submitted by Customer become the property of Lumnio via a perpetual, irrevocable, worldwide, royalty-free license.

5. Data Privacy and Security

(a) Hosting and Processing

Unless agreed otherwise in writing, Customer Property may be hosted in the United States, the European Economic Area (EEA), or the United Kingdom.

(b) Transfer of Personal Data

If Personal Data originates from the EEA and is transferred to a country outside the EEA, Lumnio ensures the transfer complies with Applicable Data Protection Law via:

  1. An adequacy decision by the European Commission.
  2. Appropriate safeguards satisfying Article 46 or 49 of the GDPR.
  3. Binding corporate rules.

(c) Data Processing Agreements (DPA)

The governing DPA shall be either a separately executed agreement between the parties or, in its absence, the terms outlined in Exhibit A.

(d) Authorized Subprocessors

Customer approves the use of the following Subprocessors to provide and secure the services. Lumnio remains fully responsible for their performance:

SubprocessorService TypeLocation
MicrosoftCloud Service Provider – AzureUnited States
GoogleCloud Service ProviderUnited States
PipedriveCloud-based CRMUnited States

(e) In-Product Cookies

Lumnio automatically logs basic system information (IP addresses, browser/device types, and cookies) to run the services. Data is used anonymously or in aggregate form in accordance with the Lumnio Cookie Policy.

6. Confidentiality

Remedies: Breaches of confidentiality grant the injured Party the right to seek immediate injunctive relief, as monetary damages alone are insufficient.

Term: Obligations remain active during the contract term and for 3 years after termination.

Permitted Disclosure: Receiving Party may share information with Affiliates, officers, directors, employees, or legal/financial advisors on a strictly need-to-know basis under written confidentiality terms.

Compelled Disclosure: If forced by law/subpoena to disclose information, the Receiving Party must give the Disclosing Party prompt prior notice (if legally allowed) to let them contest the order.

Return/Destruction: Upon request, all physical/electronic pieces of Confidential Information must be destroyed. This excludes automated system backups (Backup Media), which will remain protected under these terms until permanently overwritten.


7. Warranties; Disclaimers

(a) Mutual Warranties

Each Party represents and warrants that it has the legal power and authority to enter into this Agreement.

(b) Lumnio Warranties

Lumnio warrants that the Subscription Services will, in all material respects, perform in accordance with the applicable Documentation.

Warranty Exclusions: This warranty does not apply to issues caused by:

  • Acts within the control of Customer, Users, or End-Users.
  • Customer’s negligence or improper use of the Subscription Services.
  • Unauthorized modifications made to the Subscription Services.
  • Operating the services in an unsupported environment.
  • Third-party software, systems, or Third Party Products.

(c) Customer Warranties

Customer warrants that it will not use the Subscription Services for unlawful purposes or in a manner that infringes or violates the rights of any third party.

(d) Disclaimer

⚠️ TO THE MAXIMUM EXTENT PERMITTED BY LAW (EXCEPT AS EXPRESSLY STATED HEREIN):

  • The Subscription Services are provided “AS-IS”.
  • Neither party makes any additional statutory, express, or implied warranties (including title, merchantability, non-infringement, or fitness for a particular purpose).
  • Lumnio’s sole liability for any legally unexcludable statutory warranty is strictly limited to supplying the services again or paying the cost of supplying them again.

(e) Beta Services

  • Purpose: Beta Services are for evaluation purposes only, are not for production use, and are completely unsupported.
  • Exclusion: Beta Services are not considered “Subscription Services” under Section 7 (Warranties) and Section 8(a) (Lumnio Indemnification). They are provided “AS IS” with no warranties or indemnities.
  • Expiration: Trial periods expire 1 year from the start date (or as specified in writing). Lumnio may discontinue Beta Services at any time at its sole discretion.
  • Applicability: All standard usage restrictions, Lumnio’s rights, and Customer obligations apply equally to Beta Services.

8. Indemnification

(a) Indemnification by Lumnio

Lumnio will defend and hold harmless Customer, its employees, directors, and officers (Customer Indemnified Parties) against third-party claims alleging that the use of the Subscription Services infringes a third party’s patent, copyright, trademark, or trade secret (Infringement Claim).

If an Infringement Claim occurs or is likely to occur, Lumnio may at its own expense:

  1. Procure the right for Customer to continue using the service.
  2. Substitute a functionally equivalent, non-infringing replacement.
  3. Modify the service to make it non-infringing.
  4. Terminate the Agreement/Order Form and refund any prepaid, unused Fees.

Lumnio is NOT liable if the Infringement Claim arises from:

  • Customer Property provided to Lumnio.
  • Combination of the service with hardware, software, or networks not supplied by Lumnio.
  • Any modification or alteration of the service made by anyone other than Lumnio.
  • Customer’s violation of applicable law or third-party rights.

(b) Indemnification by Customer

Customer will defend and hold harmless Lumnio, its employees, directors, and officers (Lumnio Indemnified Parties) against third-party claims arising from:

  • (i) Allegations that Customer Property or unauthorized use of the service infringes or misappropriates third-party intellectual property rights.
  • (ii) Customer’s breach of the Platform Guidelines.

(c) Indemnification Conditions

Indemnification obligations are strictly contingent upon the indemnified party:

  • (i) Giving prompt written notice of the claim to the indemnifying party.
  • (ii) Granting the indemnifying party sole control over the defense and settlement.
  • (iii) Cooperating fully in the investigation and defense.

Note: The indemnifying party cannot settle or consent to an adverse judgment affecting the indemnified party’s rights without their express written consent (which cannot be unreasonably withheld).

9. Limitation of Liability

(a) Liability Cap

💰 TOTAL LIABILITY CAP: > TO THE MAXIMUM EXTENT PERMITTED BY LAW, EITHER PARTY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT (WHETHER IN CONTRACT, TORT, OR OTHERWISE) SHALL NOT EXCEED THE TOTAL AMOUNTS ACTUALLY PAID BY AND DUE FROM CUSTOMER HEREUNDER DURING THE TWELVE (12) MONTHS PRIOR TO THE DATE OF THE CLAIM. This cap applies even if remedies fail of their essential purpose.

(b) Exclusion of Consequential Damages

🚫 EXCLUSION OF DAMAGES: > NEITHER PARTY SHALL BE LIABLE FOR ANY LOST PROFITS, LOSS OF USE, LOSS OF DATA, COSTS OF PROCUREMENT OF SUBSTITUTE GOODS, OR ANY INDIRECT, SPECIAL, EXEMPLARY, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES, REGARDLESS OF THE THEORY OF LIABILITY, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. Neither party is responsible for losses caused by the other party’s failure to comply with its obligations.

10. Term and Termination

(a) Term of Agreement

This Agreement commences on the Effective Date and remains active until terminated in accordance with Section 10(c).

(b) Term of Subscriptions & Renewals

  • Auto-Renewal: Subscriptions automatically renew for the same period as the initial term, unless either Party provides a written non-renewal notice at least 30 days prior to the expiration date (or anytime before renewal for month-to-month terms).
  • Price Increases: Per-unit pricing for renewal terms will not increase by more than five percent (5%) compared to the prior term. Lumnio must provide written notice of any increase at least 60 days prior to renewal (or 30 days for month-to-month).
  • Exception: Price caps do not apply to temporary promotional discounts or transitions from month-to-month to longer-term subscriptions.

(c) Termination for Cause

Either Party may terminate this Agreement and/or any active Order Form if the other Party materially breaches its duties and fails to:

  • (i) Cure the breach within 30 days of receiving written notice, or
  • (ii) Provide an acceptable cure plan within 10 days (if the breach cannot reasonably be cured within 30 days) and subsequently cure it.

Note: A Party may also terminate this Agreement with written notice if there are no active Order Forms in effect for more than 30 continuous days.

(d) Effect of Termination & Data Export

  • Expiration or termination of one Order Form does not affect other active Order Forms.
  • Data Export Window: Customer may request to export Customer Property in writing within 30 days after termination. Lumnio will permit data export for up to 30 days from receiving the request.
  • Deletion: After this period, Lumnio has no obligation to maintain the data and may permanently delete all Customer Property.

(e) Surviving Provisions

The following sections remain fully active after the expiration or termination of this Agreement: Sections 1, 3, 4, 6, 7(d), 8, 9, 10(d), 11, and Exhibit A.

11. Miscellaneous Provisions

(a) Relationship

The Parties are independent contractors. This Agreement does not create a partnership, franchise, joint venture, agency, fiduciary, or employment relationship.

(b) Customer Affiliates

Customer’s Affiliates may purchase services under this Agreement by executing their own Order Forms, binding them to these terms as if they were an original party.

(c) Acquired and Divested Businesses

If Customer holds an Enterprise License Agreement (ELA) for unlimited users:

  • Acquisitions: Any business acquired after the Order Form date (Acquired Business) is not entitled to services under the ELA. If they have a pre-existing agreement with Lumnio, their new status does not grant a right to terminate it, claim refunds, or extend prior favorable pricing.
  • Divestitures: Any entity that ceases to be owned or controlled by Customer (Divested Entity) loses all access rights under the ELA immediately, unless Lumnio provides prior written consent.

(d) Entire Understanding

This Agreement (including the DPA, CCPA Addendum, Exhibits, and Order Forms) constitutes the entire understanding between the Parties and supersedes all prior proposals, marketing materials, and negotiations.

  • Conflicts: In the event of an inconsistency, the terms of the Order Form shall prevail.
  • Purchase Orders: All terms stated in a Customer-issued purchase order or non-Lumnio ordering documentation are explicitly rejected, null, and void.

(e) Modification; Waiver

No modification or waiver of any right or breach under this Agreement is legally binding unless it is in writing and signed or electronically accepted by both Parties (excepting standard Lumnio updates to Documentation, services, or legal compliance policies).

(f) Governing Law & Arbitration

  • Jurisdiction: This Agreement is governed by the laws of the State of California.
  • Arbitration: Any dispute or breach will be settled by final and binding arbitration in San Francisco, California, administered by JAMS pursuant to its Comprehensive Arbitration Rules and Procedures (or Streamlined Rules, if mutually agreed).
  • Costs: Arbitration decisions will be written and binding. A court of competent jurisdiction may enforce the judgment. Each Party pays its own costs and attorneys’ fees.

(g) Assignment

Neither Party may assign its rights or obligations without prior written consent.

  • Exception: Either Party may assign this Agreement in its entirety without consent in connection with a merger, acquisition, corporate reorganization, or sale of substantially all assets related to this Agreement. Any unauthorized assignment is null and void.

(h) Notices

All formal notices must be in writing and delivered to the addresses specified on the active Order Form. The official language for all communication and notices under this Agreement is English.

(i) Anti-Corruption

Customer warrants that it has not received or been offered any illegal bribe, kickback, payment, or gift of value from Lumnio employees or representatives (excluding standard hospitality in the ordinary course of business). Customer must promptly report any violations to Lumnio.

(j) Force Majeure

Neither Party is liable for delays or performance failures (except for payment obligations) caused by events beyond its reasonable control, including fire, flood, earthquakes, utility power failures, strikes, government actions, epidemics, or third-party acts. If Lumnio is unable to provide services for more than 30 continuous days due to a force majeure event, either Party may terminate the Agreement via written notice.

(k) Export Control

The service and technical data (Controlled Technology) are subject to US import/export laws, including the US Export Administration Regulations (EAR). Customer agrees to comply with all regulations and warrants that Controlled Technology will not be exported to prohibited persons, entities, or embargoed countries (including Cuba, North Korea, Iran, Syria, and Sudan).

(l) Severability

If any provision is found by a court to be contrary to law, that provision will be modified to best accomplish the original objective to the fullest legal extent, and all remaining provisions of this Agreement will continue in full force and effect.


Exhibit A: Platform Guidelines

(1) User IDs and Access Security

  • Unique Credentials: Unless specified otherwise in an Order Form, each User will be assigned a unique user identification name and password (“User ID”).
  • No Sharing: User IDs are intended for use by the designated Users only and cannot be shared.
  • Account Accuracy: Customer must provide accurate, current, and complete account and User information, and is responsible for ensuring the security and confidentiality of all assigned User IDs.
  • Access Management: Users can add other Users or End-Users to their accounts/projects and enable them to access or modify Customer Property (including via iframes or shareable links). Customer is solely responsible for managing these permissions and for any actions taken by such Users and End-Users.

(2) Prohibited Activities

Except for uses expressly permitted in the Documentation or an Order Form, Customer will not (and will ensure Users and End-Users do not):

  • (i) Sell, resell, rent, lease, or distribute any portion of the Subscription Service.
  • (ii) Use the services in a manner that interferes with, unduly burdens, or disrupts system integrity, performance, or availability (e.g., conducting load or penetration tests without prior written consent).
  • (iii) Attempt to gain unauthorized access to the Subscription Services or related systems/networks.
  • (iv) Access the services to build a competitive product, or monitor them for benchmarking/competitive purposes.
  • (v) Introduce or enable viruses, Trojan horses, spyware, worms, malware, spam, or malicious code.
  • (vi) Copy, modify, translate, or create derivative works of any Lumnio Property.
  • (vii) Reverse engineer, disassemble, or decompile any software included in the Lumnio Property (except as required by law).
  • (viii) Restricted Personal Data: Customer agrees not to submit sensitive personal information (such as government IDs, financial accounts, payment cards, or health data). The only permitted Personal Data is contact info consisting of: first name, last name, IP address, and email address (with necessary rights obtained).
  • (ix) Alter, remove, or violate any copyright or intellectual property notices.

Note: Direct competitors of Lumnio are strictly prohibited from accessing the Subscription Services without prior written consent.

(3) Authorized APIs & Authentication Keys

  • Compliance: Customer must use Authorized APIs in accordance with the Documentation and promptly correct any non-compliant usage.
  • Key Restrictions: Authentication Keys must be restricted to authorized personnel who need them to integrate the services with other web applications.
  • Security & Ownership: Customer is solely responsible for Key security and all activities occurring under them. Lumnio retains ownership of Authentication Keys and may revoke them if customer rights are suspended. Lumnio must be notified immediately of any unauthorized use.

(4) Internet Connectivity & Network Requirements

  • High-Speed Connection: A high-speed Internet connection is required for proper service transmission.
  • Customer Responsibility: Customer must procure and maintain network connections, including browser software supporting Secure Socket Layer (SSL) or other protocols accepted by Lumnio.
  • Exclusion of Liability: Lumnio is not responsible for notifying users of browser software updates/fixes, nor is it liable for data compromises occurring across networks or telecommunication facilities (including the Internet) not owned or controlled by Lumnio.

(5) Intellectual Property Infringement

Lumnio will process, investigate, and respond to proper notices of alleged copyright or intellectual property infringement related to material submitted through the Customer’s account, in compliance with the Online Copyright Infringement Liability Limitation Act and other applicable laws.

(6) Data Control & Consent

Customer retains exclusive control and responsibility for determining what data is submitted to the services, for obtaining all necessary consents and permissions from Data Subjects, and for all Processing activities conducted by Lumnio under Customer’s instructions.

(7) Monitoring, Maintenance & Suspension

Lumnio reserves the right to monitor service use for security/operational reasons and modify features during the term. Lumnio may immediately suspend or throttle access if:

  • (i) Lumnio reasonably believes a User or Customer is breaching this Agreement.
  • (ii) Excessive utilization occurs that affects (or is likely to affect) system availability or performance.
  • (iii) Lumnio suspects in good faith that a third party has gained unauthorized access via Customer credentials.

Note: Lumnio may also temporarily suspend access during planned downtime for maintenance (using commercially reasonable efforts to provide advance notice). Lumnio is not liable for any such modifications or suspensions.

(8) Usage Information & Service Optimization

  • Usage Information: Lumnio may use aggregated and anonymous data concerning usage to compile statistical and performance metrics.
  • Service Improvement: Lumnio has the right to use Customer Property to improve the platform and develop new offerings, subject to the confidentiality terms in Section 6.
  • Public Data: Lumnio may make aggregate metrics public, provided they (i) do not incorporate actual Customer Property and (ii) do not identify the Customer or its Users. Lumnio retains all intellectual property rights in this Usage Information.

(9) Communications

Product and business-related updates (release notes, privacy updates, security notices, bug/outage info) will be sent via email, posted on the platform, or sent via other electronic means. Lumnio may legally rely and act on all instructions provided by Customer’s Users.

(10) Third Party Products

  • Licensing & Maintenance: Customer is solely responsible for acquiring licenses, credentials, installing, and maintaining Third Party Products.
  • No Warranty: Lumnio provides no warranties, guarantees, or indemnifications for Third Party Products, even if designated as “certified” or “validated”.
  • Data Exchange: Lumnio is not liable for interactions or data exchanges between the Customer and third-party providers. If platform availability relies on a Third Party Product, Lumnio is not liable for outages caused by third-party modifications (but will use reasonable efforts to maintain interoperation).
  • Data Roles: If Customer grants a Third Party Product access to its Lumnio account, Customer serves as the data controller and the third-party provider serves as the data processor. These providers are not Lumnio Subprocessors.

Exhibit B: Lumnio Data Processing Agreement (DPA)

Data Processor: Lumnio

Data Controller: The Subscriber/Customer

Note: In the event of any conflict between this DPA and the main Agreement, the terms of this DPA shall govern.

1. Definitions

  • Applicable Data Protection Law: (i) GDPR (where the Controller is established in the EEA or agents/users access services from the EEA); and (ii) The Swiss Federal Act on Data Protection (where the Controller is established in Switzerland).
  • Standard Contractual Clauses (SCCs): Schedule 3 of this DPA.
  • Sub-processor: Any third-party data processor engaged by Lumnio to process Personal Data on behalf of the Controller and under its instructions.
  • Supervisor: Any competent data protection supervisory authority.

2. Purpose

The Data Controller uses the Service under the license granted in the Agreement. In providing this Service, the Data Processor processes Personal Data stored within the platform on behalf of the Data Controller. This DPA ensures all processing complies with Applicable Data Protection Laws regarding the collection, use, and retention of personal data.

3. Ownership of Service Data

All Service Data processed under this DPA remains the exclusive property of the Data Controller. Under no circumstances will Lumnio act, or be deemed to act, as a “controller” of the data under data protection laws.

4. Obligations of Data Processor

Lumnio agrees and declares as follows:

  • Documented Instructions: To process Personal Data only in accordance with the Controller’s documented instructions or to provide the Service, unless required otherwise by applicable laws.
  • Confidentiality: To ensure all staff and management handling the data are aware of their responsibilities and are bound by appropriate confidentiality obligations.
  • Security Measures: To implement and maintain technical and organizational measures to prevent accidental/unlawful destruction, loss, alteration, or unauthorized access (Data Security Breach), balancing the state of the art and implementation costs against processing risks.
  • Breach Notification: To notify the Data Controller without undue delay of any confirmed Data Security Breach affecting their Service Data and cooperate to mitigate risks.
  • Sub-processors: To comply with Section 5 when engaging any Sub-processor.
  • Data Subject Requests: To assist the Controller (within commercially reasonable bounds) in responding to individuals exercising their rights. If Lumnio receives a request directly from an individual, it will direct them to the Controller.
  • Impact Assessments: To provide reasonable information and assistance to help the Controller conduct required data protection impact assessments or Supervisor consultations.
  • Data Erasure: To comply with Section 9 regarding data return and deletion upon termination.
  • Compliance Audits: To provide necessary information to demonstrate compliance in accordance with Section 6.
  • Security Officer: To appoint a dedicated security officer to act as a point of contact and coordinate compliance with this DPA and Schedule 2 measures.

Note: Data Processor will immediately inform the Controller if it believes any instruction infringes data protection laws, and reserves the right to refuse such an instruction.

5. Use of Sub-processors

  • Consent: Data Controller gives general consent for Lumnio to appoint Sub-processors.
  • Sub-processor Obligations: Any Sub-processor must agree to act only on instructions consistent with those given to Lumnio, and protect Personal Data to a standard consistent with this DPA and Schedule 2.
  • Liability: Lumnio remains fully liable to the Data Controller for the performance and omissions of its Sub-processors.
  • Up-to-Date List: Lumnio maintains a list of Sub-processors at https://lumnio.com/privacy-policy.html and will update the list at least 30 days before a new Sub-processor begins processing data.
  • Objections: If the Data Controller objects to a new Sub-processor, Lumnio will either:
    • (a) Instruct the Sub-processor to cease processing the Controller’s data (DPA continues unaffected), or
    • (b) Allow the Data Controller to terminate the DPA immediately with a pro-rata refund for prepaid, unused services.
  • Integrations: Third-party integrations enabled directly by the Controller are governed solely by their own terms and privacy policies. These providers are not Lumnio Sub-processors.

6. Audit

  • External Verification: Lumnio may use external auditors to verify its security measures and physical data center standards.
  • Information Provision: Lumnio will provide detailed answers to security and audit questionnaires requested by the Controller.
  • Summary Reports: Upon written request, Lumnio will provide a confidential summary of its security reports (Summary Report) to verify compliance. This document remains Lumnio’s strictly Confidential Information.

7. International Data Exports

  • Global Operations: Personal Data may be processed in countries outside the EEA and Switzerland by Lumnio or its Sub-processors to provide support or requested services, even if EEA hosting was originally selected.
  • Standard Contractual Clauses (SCCs): The SCCs (Schedule 3) apply automatically to data transferred from the EEA/Switzerland to third countries lacking an adequacy decision by the European Commission or lacking another valid framework (like binding corporate rules). In the event of a conflict, the SCCs prevail.

8. Obligations of Data Controller

  • Accuracy & Legal Ground: Solely responsible for data accuracy, legal acquisition, and ensuring that all data collection and processing instructions comply with Applicable Data Protection Law.
  • Sensitive Data: Responsible for ensuring that any “special” or sensitive categories of personal data submitted have been collected in strict compliance with the law.
  • Data Subject Notification: Must inform individuals that data processors are used and that data may be processed outside the EEA.
  • Contacts: Must provide Lumnio with contact details for their EU Representative and Data Protection Officer (DPO), if appointed.
  • Inquiries: Must respond within a reasonable timeframe to inquiries from Data Subjects or Supervisors regarding data processing.

9. Return and Destruction of Personal Data

  • Export Period: For up to 30 days following service termination, Lumnio will permit the Data Controller to export its Service Data at its own expense.
  • Permanent Deletion: Following this 30-day window, Lumnio has the right to delete all remaining Service Data in accordance with its deletion policies. Data Controller explicitly consents to this deletion.

10. Duration

This DPA remains in full force and effect for as long as Lumnio processes Personal Data on behalf of the Data Controller under the main Agreement.

11. Limitation on Liability

  • (1) Excluded Damages: Neither party (nor their affiliates, officers, or suppliers) shall be liable for lost profits, lost sales, business interruption, loss of goodwill, or lost data (occurring over the Internet or Controller’s systems through no fault of Lumnio), or any indirect, incidental, or consequential damages.
  • (2) Aggregate Cap: Lumnio’s total aggregate liability arising out of this DPA shall never exceed the liability limitations set forth in the main Terms and Conditions (the 12-month trailing cap).
  • (3) Third-Party Claims: This section does not limit either party’s liabilities regarding claims brought directly by individual Data Subjects.

12. Miscellaneous & Governing Law

  • Amendments: Must be made in writing and signed by both parties.
  • Confidentiality: DPA terms are confidential and may only be shared with officers, auditors, legal counsel, or as required by subpoenas/courts.
  • Assignment: Controller cannot assign DPA rights without Lumnio’s prior consent. Lumnio may assign this DPA without consent to an affiliate or in connection with a merger or corporate sale.
  • Governing Law: Governed strictly by the laws of the State of California, with exclusive personal jurisdiction resting in the federal and state courts of San Francisco County, California.

Schedule 1: Subject Matter and Details of the Data Processing

ProvisionDetails
Subject MatterData Processor’s provision of the Services and related technical support to the Data Controller.
Duration of the ProcessingThe applicable Subscription Term plus the period from expiry until deletion of all Service Data by the Data Processor (30 days post-termination).
Nature and PurposeProcessing of Service Data (Personal Data) submitted, stored, sent, or received by the Data Controller, Users, or End-Users to provide the platform services and technical support.
Categories of DataUser IDs, emails, documents, presentations, images, calendar entries, tasks, and other user-submitted data.
Data SubjectsUsers (including employees and contractors of the Controller), Customers, suppliers, subcontractors, and any other individual communicating/collaborating via the Services.

Schedule 2: Security Measures

  • Physical Access Controls: Reasonable measures (security personnel, secured buildings, restricted factory premises) to prevent unauthorized physical access to data centers where Personal Data is hosted.
  • System Access Controls: Protocols to prevent unauthorized system use, varying by processing nature, including secure password authentication, two-factor authentication (2FA), documented change management, and detailed multi-level access logging.
  • Data Access Controls: Measures ensuring Personal Data is accessible only by properly authorized staff. Direct database queries are restricted, and application access rights are strictly enforced so personnel can only access data within their assigned privileges. Data cannot be read, copied, modified, or removed without authorization.
  • Transmission Controls: Controls ensuring data cannot be read, copied, modified, or intercepted during electronic transmission, transport, or transfer to external entities.
  • Input Controls: Verification systems to check and establish exactly when, and by whom, Service Data has been entered, modified, or removed in the data processing systems. Secure transmission is maintained from the Data Controller’s source.
  • Data Backup: Database backups are performed on a regular, automated schedule. Backups are secured and encrypted to protect against accidental destruction or data loss.
  • Logical Separation: Subscriber data is logically segregated within separate subscriber environments on Lumnio’s systems to ensure data collected for different environments is processed completely independently.

Schedule 3: Standard Contractual Clauses

Data Exporter: The Customer / Data Controller

Data Importer: Lumnio, Inc. / Data Processor

The parties have agreed on the following Contractual Clauses (the ‘Clauses’) to adduce adequate safeguards with respect to the protection of privacy and fundamental rights and freedoms of individuals for the transfer of personal data specified in Appendix 1.

Clause 1: Definitions

For the purposes of these Clauses, the following definitions apply:

  • GDPR Terms: Personal data, special categories of data, process/processing, controller, processor, data subject, and supervisory authority have the same meaning as in the GDPR.
  • Data Exporter: The controller who transfers the personal data.
  • Data Importer: The processor who receives the personal data for processing on the exporter’s behalf in a third country lacking adequate data protection.
  • Sub-processor: Any processor engaged by the data importer (or by any other sub-processor) to process personal data exclusively on behalf of the data exporter.
  • Applicable Data Protection Law: Legislation protecting individual privacy rights applicable to the data controller in the EU Member State where the data exporter is established.
  • Technical and Organizational Security Measures: Measures aimed at protecting personal data against accidental/unlawful destruction, loss, alteration, unauthorized disclosure, or access.

Clause 2: Details of the Transfer

The details of the transfer, and particularly the special categories of personal data (if applicable), are specified in Appendix 1, which forms an integral part of these Clauses.

Clause 3: Third-Party Beneficiary Rights

Data subjects (the individuals whose data is processed) can enforce specific clauses as third-party beneficiaries under the following conditions:

  • Against the Data Exporter: Data subjects can enforce almost all key sections (Clause 3, Clause 4(b)-(i), Clause 5(a)-(e) and (g)-(j), Clause 6(1)-(2), Clause 7, Clause 8(2), and Clauses 9-12).
  • Against the Data Importer: If the data exporter has factually disappeared or ceased to exist in law (unless a successor entity has contractually assumed all legal obligations of the exporter).
  • Against the Sub-processor: If both the data exporter and the data importer have factually disappeared, ceased to exist in law, or become insolvent. The sub-processor’s liability is strictly limited to its own processing operations.
  • Representation: Data subjects have the right to be represented by an association or other representative body if they expressly wish and if permitted by national law.

Clause 4: Obligations of the Data Exporter

The data exporter agrees and warrants:

  • (a) Legal Compliance: That all data processing and the transfer itself comply with the applicable data protection laws of the Member State where the exporter is established.
  • (b) Instruction Control: To instruct the data importer to process data strictly on the exporter’s behalf and in accordance with these Clauses.
  • (c) Security Guarantees: That the data importer provides sufficient guarantees regarding technical and organizational security measures (specified in Appendix 2).
  • (d) Risk Assessment: That the security measures are fully appropriate to protect data against accidental/unlawful loss, unauthorized access, or transmission risks, taking into account the state of the art and implementation costs.
  • (e) Compliance Monitoring: To actively ensure ongoing compliance with these security measures.
  • (f) Sensitive Data Notice: If special categories of data are transferred, to inform data subjects that their data may be sent to a third country lacking adequate protection.
  • (g) Authority Notification: To forward any breach or legal notifications received from the importer to the supervisory authority if deciding to continue the transfer.
  • (h) Public Availability: To provide data subjects upon request with a copy of these Clauses (excluding Appendix 2 summary details) and copies of sub-processing contracts, with commercial information redacted if necessary.
  • (i) Sub-processing Standards: To ensure any sub-processing is carried out in accordance with Clause 11, providing at least the same level of data protection as the data importer.

Clause 5: Obligations of the Data Importer

The data importer agrees and warrants:

  • (a) Processing & Inability to Comply: To process personal data strictly on behalf of the exporter. If the importer cannot comply for any reason, it must promptly inform the exporter, who then has the right to suspend data transfer and/or terminate the contract.
  • (b) Legislation Check: That it has no reason to believe local legislation prevents it from fulfilling instructions. If a legislative change occurs that negatively impacts these clauses, it will notify the exporter immediately.
  • (c) Security Implementation: To fully implement all technical and organizational security measures specified in Appendix 2 before processing any data.
  • (d) Mandatory Notifications: To promptly notify the data exporter about:
    • (i) Any legally binding request for disclosure by a law enforcement authority (unless explicitly prohibited under criminal law).
    • (ii) Any accidental or unauthorized access (data breach).
    • (iii) Any requests received directly from data subjects (without responding directly, unless authorized).
  • (e) Inquiries & Supervision: To deal properly and promptly with all inquiries from the exporter and abide by the advice of the data exporter’s supervisory authority.
  • (f) Audit Submission: At the exporter’s request, to submit its data-processing facilities to an audit conducted by the exporter or an independent, confidential inspection body.
  • (g) Document Copies: To make a copy of these Clauses or sub-processing agreements available to data subjects upon request (redacting sensitive commercial data).
  • (h)-(j) Sub-processor Management: To obtain prior written consent from the exporter before sub-processing, ensure the sub-processor signs a Clause 11 compliant contract, and promptly send a copy of that agreement to the exporter.

Clause 6: Liability & Compensation

  • (1) Exporter Liability: The data subject is entitled to receive financial compensation from the data exporter for any damages suffered due to a breach of these Clauses by any party or sub-processor.
  • (2) Importer Liability: If the data exporter has legally disappeared or become insolvent, the data subject may bring a claim directly against the data importer as if it were the exporter.
  • (3) No Importer Escape: The data importer cannot rely on a breach by its sub-processor to avoid its own direct liabilities to the exporter.
  • (4) Sub-processor Liability: If both the exporter and importer have disappeared or become insolvent, the data subject may bring claims directly against the sub-processor, whose liability remains strictly limited to its own processing operations.

Clause 7: Mediation and Jurisdiction

In the event of a dispute or third-party beneficiary claim brought by a data subject against the data importer, the importer will accept the data subject’s decision to:

  • (a) Refer the dispute to mediation by an independent person or the supervisory authority.
  • (b) Refer the dispute to the courts in the EU Member State where the data exporter is established.

The parties agree that the choice made by the data subject will not prejudice their rights to seek other remedies under national or international law.

Clause 8: Cooperation with Supervisory Authorities

  • (1) Contract Deposit: The data exporter will deposit a copy of this contract with its supervisory authority if requested or required by law.
  • (2) Authority Audits: The supervisory authority has the right to conduct an audit of the data importer and any sub-processor with the same scope as would apply to an audit of the data exporter.
  • (3) Audit Restrictions: The importer must instantly inform the exporter if local legislation prevents an authority audit from taking place.

Clause 9: Governing Law

These Clauses shall be governed strictly by the law of the EU Member State in which the data exporter is established.

Clause 10: Variation of the Contract

The parties undertake not to vary, alter, or modify these Clauses. They may add business-related clauses as long as they do not contradict or weaken these standard terms.

Clause 11: Sub-processing

  • (1) Written Agreement: The importer must obtain prior written consent before subcontracting. The sub-processing contract must impose the exact same obligations on the sub-processor as are imposed on the importer. If the sub-processor fails its duties, the importer remains fully liable to the exporter.
  • (2) Beneficiary Clause: The sub-processing contract must include a third-party beneficiary clause mirroring Clause 3 to protect data subjects if both the exporter and importer disappear or become insolvent.
  • (3) Governing Law: Data protection aspects of the sub-processing contract are governed by the law of the Member State where the exporter is established.
  • (4) Annual List: The data exporter must maintain an updated list of all approved sub-processing agreements, updated at least once a year and available to its supervisory authority.

Clause 12: Obligations After Termination

  • (1) Return or Destruction: Upon termination of data-processing services, the data importer and sub-processor must, at the choice of the data exporter, either return all transferred personal data and copies or completely destroy them and certify destruction to the exporter.
  • Exception: If local legislation prevents data return or destruction, the importer warrants that it will guarantee strict confidentiality and will cease active data processing permanently.
  • (2) Audit Rights: The importer and sub-processor warrant that they will submit their data facilities to audits to verify compliance with this termination clause upon request by the exporter or authority.

Appendix 1 to the Standard Contractual Clauses

  • Data Exporter: The user/subscriber utilizing the services of the data importer as described in the main Agreement.
  • Data Importer: Lumnio, Inc., a provider of services described in the main Agreement.
  • Data Subjects: The categories of individuals described in Schedule 1 of the DPA.
  • Categories of Data: The specific data types transferred as described in Schedule 1 of the DPA.
  • Special Categories of Data: The transferred personal data does not concern any special/sensitive categories of data unless explicitly agreed otherwise between the exporter and importer.
  • Processing Operations: The scope of processing activities is fully detailed in Schedule 1 of the DPA.

Appendix 2 to the Standard Contractual Clauses

Technical and Organizational Security Measures: The full technical and organizational security measures implemented by the data importer in accordance with Clauses 4(d) and 5(c) are comprehensively detailed in Schedule 2 of the DPA.

Lumnio, Inc. ID (IČO): 06202365

Omlouváme se, tento příspěvek v požadovaném jazyce není dostupný.

Ospravedlňujeme sa, tento príspevok v požadovanom jazyku nie je dostupný.

Žao mi je, ova objava nije dostupna na traženom jeziku.

Przepraszamy, ten post nie jest dostępny w żądanym języku.

We apologize, this post is not available in the requested language.

Прабачце, гэтая публікацыя недаступная на патрэбнай мове.

Lo sentimos, esta publicación no está disponible en el idioma solicitado.

Es tut uns leid, dieser Beitrag ist in der gewünschten Sprache nicht verfügbar.