Privacy Policy
Lumeo Technologies Private Limited is committed to protecting your personal data. This policy explains exactly what we collect, why we collect it, who we share it with, and the rights you hold under applicable law — including India's Digital Personal Data Protection Act, 2023 (DPDPA) and GDPR for EEA residents.
AES-256-GCM at rest
All personal and financial data encrypted at rest using AES-256-GCM with per-tenant keys.
TLS 1.3 in transit
Every connection to Lumeo servers is encrypted with TLS 1.3 and HSTS enforced.
You control your data
Access, correct, export, or request deletion of your data at any time from your account settings.
DPDPA & GDPR aware
Designed for compliance with India's DPDPA 2023 and GDPR for EEA users.
1. Information we collect
We collect personal data in three broad categories. We only collect what is necessary for the purposes stated in this policy.
1.1 Identity and KYC data
- Full legal name — as it appears on your PAN card or government ID.
- Email address and mobile number — used for authentication, notifications, and compliance correspondence.
- PAN (Permanent Account Number) — required by the Income Tax Act 1961 for ITR-4 preparation and advance tax sequestration.
- GSTIN (GST Identification Number) — required for GST reconciliation, GSTR-1/3B prep, and invoicing compliance.
- Aadhaar-linked mobile / VUID (voluntary) — only if you opt in to Aadhaar-based e-signing for filings.
- KYC documents — government-issued photo ID (passport, Aadhaar, Voter ID) and address proof, required under PMLA 2002 and RBI Master Direction on KYC 2016.
- Business registration details — firm name, LLP/company CIN, IEC code for exporters registered under FEMA.
1.2 Financial and transaction data
- Inward remittance details — amount, currency pair, exchange rate, value date, purpose code, and SWIFT/UTR reference.
- FIRA certificate data — bank name, nostro account reference, AD code, and all fields mandated by RBI for FIRA issuance.
- GST transaction ledger — IGST/CGST/SGST breakdowns, HSN codes, place of supply, invoice numbers, and reverse charge applicability.
- ITR-4 computation inputs — total foreign income, Section 44ADA/44AD presumptive amounts, TDS certificates (Form 16A), and advance tax challans.
- FX spread and fee data — the difference between the interbank rate and the rate you received, and any Lumeo platform fees.
- Advance tax ring-fence amounts — computed estimated liabilities parked per quarter per the Income Tax Act schedule.
We do not store your bank account passwords, net-banking credentials, full card numbers (PAN), or CVVs. Payment instrument tokenisation is handled entirely by your banking partner or payment gateway under PCI-DSS Level 1.
1.3 Usage and technical data
- API call metadata — endpoint, HTTP method, timestamp, response time, and error codes. We never log request or response payloads containing financial data.
- Device and browser signals — IP address (hashed after 90 days), User-Agent, viewport size, OS version, and time zone.
- Feature interaction events — which screens you visit, buttons you click, and errors you encounter — used solely for UX improvement.
- Session tokens — short-lived JWT tokens (15-minute access / 7-day refresh) stored in httpOnly, Secure, SameSite=Strict cookies.
2. How we use your information
3. Legal basis for processing
Under India's DPDPA 2023 and, where applicable, GDPR, we rely on the following legal grounds:
4. How we share your data
We do not sell your personal data. We share it only in the following circumstances:
4.1 Service providers (data processors)
- Cloud infrastructure — AWS (ap-south-1 Mumbai region) for hosting, storage, and managed databases. Governed by AWS Data Processing Addendum (GDPR-aligned).
- Banking partners — Authorised Dealer (AD) banks for FIRA retrieval and forex settlement confirmation. Only FEMA-mandated data is shared.
- KYC/AML providers — NSDL e-Gov (PAN verification), UIDAI (Aadhaar OTP, voluntary), and a SEBI-registered KRA for AML screening.
- Email and SMS delivery — Transactional notification providers operating under contractual confidentiality obligations.
- Error monitoring — Anonymised, stacktrace-only data shared with error monitoring tools. No PII or financial data in error logs.
4.2 Regulatory and legal disclosure
We may disclose your data to CBDT (Income Tax Department), GSTN, FEMA enforcement authorities, financial intelligence units, or law enforcement when required by a valid legal order, court process, or statutory obligation. We will notify you of such requests unless prohibited by law.
4.3 Business transfers
In the event of a merger, acquisition, or sale of all or substantially all of our assets, your data may be transferred to the successor entity subject to the same privacy commitments. You will be notified at least 30 days before any such transfer.
We never sell or rent your data
Your personal and financial data is never sold, rented, or auctioned to advertisers, data brokers, or any third party for commercial gain.
5. Data retention
We retain your data only as long as necessary for the purpose it was collected, or as required by law — whichever is longer.
After retention periods expire, data is securely erased using NIST SP 800-88 compliant wiping for disk and cryptographic erasure for cloud storage.
6. How we protect your data
6.1 Encryption
- AES-256-GCM encryption at rest with per-tenant envelope keys managed in AWS KMS. Keys rotated every 365 days.
- TLS 1.3 with HSTS (max-age 1 year, includeSubDomains, preload) for all data in transit.
- bcrypt (cost factor 14) for password hashing. Passwords are never stored in plaintext.
- PAN/Aadhaar numbers stored as salted SHA-3-256 hashes after KYC verification; plaintext is never persisted post-verification.
6.2 Access controls
- Role-based access control (RBAC) with principle of least privilege. Engineers access production only via time-limited break-glass procedures with full audit logging.
- Multi-factor authentication (MFA) mandatory for all internal staff with access to production systems.
- All privileged access sessions are recorded and retained for 12 months.
- Annual access reviews by the Head of Security to revoke unnecessary permissions.
6.3 Testing and audits
- Annual SOC 2 Type II audit by a Big Four-affiliated auditor.
- Semi-annual penetration testing by a CREST-certified firm covering network, API, and mobile layers.
- Quarterly automated vulnerability scans with 30-day remediation SLA for critical findings.
- Bug bounty programme — responsible disclosure rewarded; contact [email protected].
7. Your rights
Under the DPDPA 2023 and GDPR (where applicable), you have the following rights. All requests are processed within 30 days.
Exercise any right by emailing [email protected] or via Account Settings → Privacy → Data Requests.
9. Children's privacy
The Lumeo platform is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has created an account or provided personal data, please contact us immediately at [email protected] and we will delete the data promptly.
10. Cross-border data transfers
Your data is primarily stored and processed in India (AWS ap-south-1 Mumbai). In limited cases, data may transit international routes for global service delivery. We ensure adequate protection through:
- Standard Contractual Clauses (SCCs) with all sub-processors outside India where GDPR applies.
- Binding contractual data processing agreements with all third-party service providers.
- Transfers of FEMA/RBI-regulated financial data are strictly limited to India-resident or RBI-authorised entities.
- No personal data is stored in jurisdictions subject to OFAC comprehensive sanctions.
11. Changes to this policy
We may update this Privacy Policy from time to time. For material changes — those that significantly alter your rights or our data practices — we will:
- Send an in-app notification and email to the address on your account at least 30 days before the change takes effect.
- Require re-acknowledgement for consent-based processing if the consent scope expands.
- Maintain a versioned changelog of all policy revisions accessible at lumeo.co.in/legal/privacy-history.
Continued use of the platform after the effective date constitutes acceptance of the revised policy.
12. Contact our Data Protection Officer
Grievance Officer under IT Act 2000
As required by the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, our Grievance Officer can also be reached at [email protected]. Complaints will be acknowledged within 24 hours and resolved within 15 days.