Legal · PrivacyLast updated: July 1, 2026

Privacy Policy

Lumeo Technologies Private Limited is committed to protecting your personal data. This policy explains exactly what we collect, why we collect it, who we share it with, and the rights you hold under applicable law — including India's Digital Personal Data Protection Act, 2023 (DPDPA) and GDPR for EEA residents.

AES-256-GCM at rest

All personal and financial data encrypted at rest using AES-256-GCM with per-tenant keys.

TLS 1.3 in transit

Every connection to Lumeo servers is encrypted with TLS 1.3 and HSTS enforced.

You control your data

Access, correct, export, or request deletion of your data at any time from your account settings.

DPDPA & GDPR aware

Designed for compliance with India's DPDPA 2023 and GDPR for EEA users.

1. Information we collect

We collect personal data in three broad categories. We only collect what is necessary for the purposes stated in this policy.

1.1 Identity and KYC data

  • Full legal name — as it appears on your PAN card or government ID.
  • Email address and mobile number — used for authentication, notifications, and compliance correspondence.
  • PAN (Permanent Account Number) — required by the Income Tax Act 1961 for ITR-4 preparation and advance tax sequestration.
  • GSTIN (GST Identification Number) — required for GST reconciliation, GSTR-1/3B prep, and invoicing compliance.
  • Aadhaar-linked mobile / VUID (voluntary) — only if you opt in to Aadhaar-based e-signing for filings.
  • KYC documents — government-issued photo ID (passport, Aadhaar, Voter ID) and address proof, required under PMLA 2002 and RBI Master Direction on KYC 2016.
  • Business registration details — firm name, LLP/company CIN, IEC code for exporters registered under FEMA.

1.2 Financial and transaction data

  • Inward remittance details — amount, currency pair, exchange rate, value date, purpose code, and SWIFT/UTR reference.
  • FIRA certificate data — bank name, nostro account reference, AD code, and all fields mandated by RBI for FIRA issuance.
  • GST transaction ledger — IGST/CGST/SGST breakdowns, HSN codes, place of supply, invoice numbers, and reverse charge applicability.
  • ITR-4 computation inputs — total foreign income, Section 44ADA/44AD presumptive amounts, TDS certificates (Form 16A), and advance tax challans.
  • FX spread and fee data — the difference between the interbank rate and the rate you received, and any Lumeo platform fees.
  • Advance tax ring-fence amounts — computed estimated liabilities parked per quarter per the Income Tax Act schedule.

We do not store your bank account passwords, net-banking credentials, full card numbers (PAN), or CVVs. Payment instrument tokenisation is handled entirely by your banking partner or payment gateway under PCI-DSS Level 1.

1.3 Usage and technical data

  • API call metadata — endpoint, HTTP method, timestamp, response time, and error codes. We never log request or response payloads containing financial data.
  • Device and browser signals — IP address (hashed after 90 days), User-Agent, viewport size, OS version, and time zone.
  • Feature interaction events — which screens you visit, buttons you click, and errors you encounter — used solely for UX improvement.
  • Session tokens — short-lived JWT tokens (15-minute access / 7-day refresh) stored in httpOnly, Secure, SameSite=Strict cookies.

2. How we use your information

Service deliveryProviding FIRA generation, GST reconciliation, ITR-4 prep, advance tax sequestration, FX spread transparency, and all platform features you have subscribed to.
KYC & AML complianceVerifying identity under PMLA 2002, RBI KYC Master Direction 2016, and FEMA regulations. Screening against OFAC, UN, and GOI sanction lists.
Tax complianceGenerating FIRA certificates, auto-populating GSTR-1/3B, preparing Schedule FSI / AL for ITR-4, and computing advance tax instalments under Section 208.
Security & fraud preventionDetecting anomalous login patterns, preventing account takeover, and flagging suspicious transaction sequences for manual review.
Product improvementAnalysing aggregated, anonymised usage patterns to improve UI/UX, reduce filing errors, and build new features.
CommunicationSending transactional notifications (payment received, FIRA ready, filing deadline reminders) and, with your consent, product updates.
Legal obligationsRetaining records as required by the Income Tax Act 1961 (7 years), GST Act 2017 (6 years), FEMA 1999 (5 years), and PMLA 2002 (10 years).

4. How we share your data

We do not sell your personal data. We share it only in the following circumstances:

4.1 Service providers (data processors)

  • Cloud infrastructure — AWS (ap-south-1 Mumbai region) for hosting, storage, and managed databases. Governed by AWS Data Processing Addendum (GDPR-aligned).
  • Banking partners — Authorised Dealer (AD) banks for FIRA retrieval and forex settlement confirmation. Only FEMA-mandated data is shared.
  • KYC/AML providers — NSDL e-Gov (PAN verification), UIDAI (Aadhaar OTP, voluntary), and a SEBI-registered KRA for AML screening.
  • Email and SMS delivery — Transactional notification providers operating under contractual confidentiality obligations.
  • Error monitoring — Anonymised, stacktrace-only data shared with error monitoring tools. No PII or financial data in error logs.

4.2 Regulatory and legal disclosure

We may disclose your data to CBDT (Income Tax Department), GSTN, FEMA enforcement authorities, financial intelligence units, or law enforcement when required by a valid legal order, court process, or statutory obligation. We will notify you of such requests unless prohibited by law.

4.3 Business transfers

In the event of a merger, acquisition, or sale of all or substantially all of our assets, your data may be transferred to the successor entity subject to the same privacy commitments. You will be notified at least 30 days before any such transfer.

We never sell or rent your data

Your personal and financial data is never sold, rented, or auctioned to advertisers, data brokers, or any third party for commercial gain.

5. Data retention

We retain your data only as long as necessary for the purpose it was collected, or as required by law — whichever is longer.

KYC documents10 years from last transaction — PMLA 2002 Section 12.
FIRA records5 years — FEMA 1999 Section 10(5).
GST transaction data6 years from the last day of the financial year — CGST Act Section 36.
Income tax records7 years from the end of the relevant assessment year — Income Tax Act Section 44AA.
Account data (inactive)Deleted 90 days after account closure, unless statutory minimum applies.
Usage / analytics dataAggregated and anonymised after 12 months; raw event data deleted after 24 months.
Support tickets3 years from resolution.

After retention periods expire, data is securely erased using NIST SP 800-88 compliant wiping for disk and cryptographic erasure for cloud storage.

6. How we protect your data

6.1 Encryption

  • AES-256-GCM encryption at rest with per-tenant envelope keys managed in AWS KMS. Keys rotated every 365 days.
  • TLS 1.3 with HSTS (max-age 1 year, includeSubDomains, preload) for all data in transit.
  • bcrypt (cost factor 14) for password hashing. Passwords are never stored in plaintext.
  • PAN/Aadhaar numbers stored as salted SHA-3-256 hashes after KYC verification; plaintext is never persisted post-verification.

6.2 Access controls

  • Role-based access control (RBAC) with principle of least privilege. Engineers access production only via time-limited break-glass procedures with full audit logging.
  • Multi-factor authentication (MFA) mandatory for all internal staff with access to production systems.
  • All privileged access sessions are recorded and retained for 12 months.
  • Annual access reviews by the Head of Security to revoke unnecessary permissions.

6.3 Testing and audits

  • Annual SOC 2 Type II audit by a Big Four-affiliated auditor.
  • Semi-annual penetration testing by a CREST-certified firm covering network, API, and mobile layers.
  • Quarterly automated vulnerability scans with 30-day remediation SLA for critical findings.
  • Bug bounty programme — responsible disclosure rewarded; contact [email protected].

7. Your rights

Under the DPDPA 2023 and GDPR (where applicable), you have the following rights. All requests are processed within 30 days.

Right to accessObtain a copy of all personal data we hold about you, including the categories, purposes, and recipients.
Right to correctionRequest correction of inaccurate or incomplete data.
Right to erasureRequest deletion of your data, subject to statutory retention obligations (e.g. PMLA, GST Act). We will tell you what we cannot delete and why.
Right to data portabilityReceive your data in a machine-readable format (JSON/CSV) for transfer to another service.
Right to objectObject to processing based on legitimate interests or for direct marketing. Marketing opt-out is immediate.
Right to restrict processingRequest that we limit processing to storage only while a dispute is resolved.
Right to withdraw consentWithdraw consent for any consent-based processing at any time without affecting prior lawful processing.
Right to grievance redressalUnder DPDPA 2023, lodge a complaint with our Data Protection Officer. If unsatisfied, escalate to the Data Protection Board of India.

Exercise any right by emailing [email protected] or via Account Settings → Privacy → Data Requests.

8. Cookies and tracking

We use a minimal, purposeful set of cookies. No third-party advertising or tracking cookies are used on the Lumeo platform.

Session cookieshttpOnly, Secure, SameSite=Strict. Store your authentication token. Expire on logout or after 7 days of inactivity. Essential — cannot be disabled.
CSRF tokenPrevents cross-site request forgery attacks. Essential — cannot be disabled.
Preference cookiesStore your UI preferences (theme, language, column order). Persist for 12 months. Deletable from browser settings.
Analytics cookiesSelf-hosted, privacy-first analytics (no data leaves our infrastructure). Opt-out available in Account Settings.

We do not use Google Analytics, Meta Pixel, or any third-party advertising tracking on the platform. Our marketing site uses a cookie consent banner compliant with India's IT Rules and GDPR where triggered.

9. Children's privacy

The Lumeo platform is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has created an account or provided personal data, please contact us immediately at [email protected] and we will delete the data promptly.

10. Cross-border data transfers

Your data is primarily stored and processed in India (AWS ap-south-1 Mumbai). In limited cases, data may transit international routes for global service delivery. We ensure adequate protection through:

  • Standard Contractual Clauses (SCCs) with all sub-processors outside India where GDPR applies.
  • Binding contractual data processing agreements with all third-party service providers.
  • Transfers of FEMA/RBI-regulated financial data are strictly limited to India-resident or RBI-authorised entities.
  • No personal data is stored in jurisdictions subject to OFAC comprehensive sanctions.

11. Changes to this policy

We may update this Privacy Policy from time to time. For material changes — those that significantly alter your rights or our data practices — we will:

  • Send an in-app notification and email to the address on your account at least 30 days before the change takes effect.
  • Require re-acknowledgement for consent-based processing if the consent scope expands.
  • Maintain a versioned changelog of all policy revisions accessible at lumeo.co.in/legal/privacy-history.

Continued use of the platform after the effective date constitutes acceptance of the revised policy.

12. Contact our Data Protection Officer

Data Protection OfficerKrishnendu Samanta
Email[email protected]
Postal addressLumeo Technologies Pvt. Ltd., Kolkata, West Bengal, India — 700001
Response timeWithin 30 days of receipt. Complex requests may take up to 60 days with notice.
EscalationData Protection Board of India (DPBI) — once constituted under DPDPA 2023.

Grievance Officer under IT Act 2000

As required by the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, our Grievance Officer can also be reached at [email protected]. Complaints will be acknowledged within 24 hours and resolved within 15 days.