Luminai Privacy and Cookie Policy
Effective Date: 07/09/2026
DigitalBrain, Inc. (doing business as “Luminai”)
1. Introduction
This Privacy and Cookie Policy (“Privacy Policy”) describes how DigitalBrain, Inc. (doing business as Luminai) and its affiliates (“Luminai,” “we,” “us,” or “our”) collect, use, share, and protect personal information when you visit our public websites at luminai.com (the “Websites”) or use our hosted application services, including the application available at app.luminai.com (the “Services”).
Please read this Privacy Policy carefully. It explains what information we collect, why we collect it, the legal bases on which we process it, with whom we share it, how long we keep it, and the rights and choices available to you. If you do not agree with our practices, please do not use the Websites or the Services. Where the law requires consent for a specific processing activity (for example, non-essential cookies or marketing communications), we will ask for that consent separately rather than rely on your general use of the Websites.
Our role under data protection law. For information about visitors to our Websites and individuals who interact with us directly (for example, prospective customers), Luminai acts as a data controller (or “business” under U.S. state privacy laws). For content our enterprise customers and their authorized users submit to the Services (“Customer Content,” described in Section 3.3), Luminai acts as a data processor (or “service provider”) on behalf of the customer, and the customer's own privacy notices and instructions govern that content.
2. Who We Are and How to Contact Us
The entity responsible for the processing described in this Privacy Policy is DigitalBrain, Inc. (dba Luminai). Full contact details, including our mailing address and the contact details of our Data Protection Officer (“DPO”), are set out in Section 14 (Contact Us) at the end of this Privacy Policy.
3. Information We Collect and Why
3.1 Information from Website Visitors
Like most website operators, Luminai collects basic, non-personally-identifying information that web browsers and servers typically make available, such as browser type, language preference, referring site, and the date and time of each visitor request. We collect this information to understand how visitors use the Websites, to improve their performance and content, and to monitor the security of the Websites. From time to time, Luminai may publish aggregated, de-identified statistics about the use of the Websites (for example, overall traffic trends). Aggregated statistics never identify individual visitors.
Luminai also collects potentially personally-identifying information such as Internet Protocol (IP) addresses. We use IP addresses for security monitoring, fraud prevention, service diagnostics, and approximate (city-level) analytics. We do not use this information to build profiles of individual visitors.
3.2 Account, Contact, and Usage Information
Access to the Services is gated: users receive accounts provisioned in connection with a customer agreement. When an account is created for you, or when you interact with us (for example, by requesting a demo, contacting support, or subscribing to updates), we collect information such as your name, business email address, job title, organization, and authentication identifiers. The amount and type of information we gather depends on the nature of your interaction with us and the information you choose to share; we collect personally-identifying information only insofar as it is necessary or appropriate to fulfill the purpose of your interaction with Luminai.
When authorized users are logged in to the Services, we collect usage data about how the application is used for example, pages viewed, features used, session identifiers, and performance and error data. We use this information to operate, secure, troubleshoot, and improve the Services and to understand how different categories of users work with the product. A pseudonymous user ID may be generated for this purpose.
For details about the third-party tools and sub-processors involved in this collection and with whom information is shared, please see our Sub-processor and Vendor List at https://www.luminai.com/subprocessors, which forms part of this Privacy Policy and is described further in Section 6.
3.3 Customer Content and Uploaded Files
The Services allow authorized users to upload files, documents, and records and to submit data for processing as part of the workflows the Services automate (“Customer Content”). Depending on the customer's use case, Customer Content may contain personal information about individuals other than the user including, for customers in the healthcare sector, protected health information (“PHI”) as defined under the U.S. Health Insurance Portability and Accountability Act (“HIPAA”).
We process Customer Content solely on behalf of and under the instructions of the customer that controls the relevant account, as set out in our customer agreements and data processing terms. We do not use Customer Content for advertising, we do not sell it, and we do not use it for purposes unrelated to providing and securing the Services. Customer Content is stored on our servers in the United States (see Section 7).
3.4 Sensitive Information We Do Not Ask You to Provide Outside the Services
Outside of Customer Content submitted through the Services, Luminai does not request or intentionally collect sensitive personal information such as government identification numbers, genetic or biometric data, health information, or information about religious beliefs through our public Websites, marketing forms, or support channels. Please do not include sensitive personal information in emails, support tickets, or Website forms. Where sensitive information (including health information) is processed within the Services as Customer Content, that processing is governed by Sections 3.3 and 4 and by our agreement with the relevant customer not by implied consent.
4. Health Information and HIPAA
Some Luminai customers are health care providers, health plans, or other “covered entities” (or their “business associates”) under HIPAA. Where Luminai receives PHI in order to provide the Services to such a customer, Luminai acts as a business associate of that customer and enters into a Business Associate Agreement (“BAA”) governing the use, disclosure, and safeguarding of PHI, as required by HIPAA.
- We use and disclose PHI only as permitted by the applicable BAA and HIPAA, and only to provide and support the Services.
- We apply administrative, physical, and technical safeguards to PHI consistent with the HIPAA Security Rule and our internal HIPAA compliance, workstation security, and incident response policies.
- Personnel and contractors whose roles involve access to PHI complete HIPAA training and are bound by confidentiality obligations.
- In the event of a breach of unsecured PHI, we will notify the affected customer without unreasonable delay and within the timeframes required by the BAA and the HIPAA Breach Notification Rule, so that the customer can meet its own notification obligations.
If you are a patient or other individual whose PHI is processed in the Services, please direct requests to exercise your rights (such as access to or amendment of your health records) to the health care organization you have a relationship with; that organization is the HIPAA covered entity responsible for your records, and we will support it in responding, as required by our BAA.
5. How We Use Information and Our Legal Bases
Where the EU or UK General Data Protection Regulation (“GDPR”) or similar laws apply, we rely on the following legal bases:
- Performance of a contract. We process your information where necessary to perform a contract with you or your organization for example, to provision and administer your account, deliver and support the Services, and respond to your requests.
- Legitimate interests. We process information for our legitimate interests, such as securing and improving the Websites and Services, preventing fraud and abuse, communicating with users and the public, and for administrative and legal purposes provided those interests are not overridden by your rights and freedoms.
- Consent. We rely on your consent for certain activities, such as sending marketing communications and setting non-essential cookies (see Section 8). You may withdraw consent at any time for marketing emails, via the unsubscribe link included in every marketing message, and otherwise by contacting us using the details in Section 14. Withdrawal does not affect processing that occurred before withdrawal.
- Legal obligation. We process information where necessary to comply with applicable law, such as tax, accounting, and lawful requests by public authorities.
Special categories of data. Health information and other special categories of personal data (GDPR Article 9) are processed only within Customer Content, on behalf of the relevant customer. The customer, as controller, is responsible for establishing a valid Article 9 condition (for example, the individual's explicit consent, or processing necessary for health care provision under Article 9(2)(h)) and for providing any required notices. Luminai does not process special category data for its own purposes.
6. How We Share Information
Luminai discloses potentially personally-identifying and personally-identifying information only to those of its employees, contractors, and affiliated organizations that (i) need to know that information in order to process it on Luminai's behalf or to provide the Services, and (ii) have agreed in writing not to disclose it to others.
Sub-processors and service providers. We use a limited set of third-party service providers (for example, cloud hosting, analytics, and support tooling) to operate the Websites and Services. A current list of these vendors, the categories of information they process, and their locations is maintained at https://www.luminai.com/subprocessors. Each sub-processor is bound by contractual terms requiring confidentiality and appropriate security, and where PHI is involved by a BAA.
Within a customer deployment. Email addresses and related account details of users of a customer's Luminai deployment may be visible to other authorized users and administrators of that same deployment.
We do not sell or share your personal information. Luminai does not rent or sell personal information to anyone, and does not “sell” or “share” personal information as those terms are defined under the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), including for cross-context behavioral advertising.
Legal and safety disclosures. We may disclose information where required by law, or where we believe in good faith that disclosure is reasonably necessary to comply with a legal process, protect the property or rights of Luminai, our customers, third parties, or the public at large, or to respond to an emergency.
Corporate transactions. If Luminai is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to this Privacy Policy and applicable law. We will notify affected users of any such change in ownership or control of their personal information.
Customer logos. We may identify customers by name or logo in our marketing materials only with the customer's permission or as provided in the applicable agreement. If you have concerns about the use of your organization's logo, please contact us at the details in Section 14.
7. International Data Transfers
The Websites and Services are hosted in the United States, and information we collect is stored and processed on servers in the United States. Our employees, contractors, and affiliated organizations that process information for us may be located in the United States or other countries.
Where we transfer personal information originating from the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, we implement appropriate safeguards recognized by applicable law, such as the European Commission's Standard Contractual Clauses (and the UK Addendum or International Data Transfer Agreement, as applicable), together with supplementary technical and organizational measures. You may request a copy of the relevant safeguards by contacting us using the details in Section 14.
8. Cookies, Tracking Technologies, Do Not Track, and Global Privacy Control
8.1 Cookies
A cookie is a small string of information that a website stores on a visitor's device and that the visitor's browser provides to the website each time the visitor returns. We use the following categories of cookies:
- Strictly necessary cookies, which are required for the Websites and Services to function (for example, authentication and security). These cannot be switched off.
- Analytics and performance cookies, which help us understand how the Websites perform and how visitors navigate them, so we can improve content and performance. We do not use these services to identify you individually.
- Functional cookies, which remember your preferences (such as language).
We do not use advertising or targeting cookies on our Websites.
Where required by applicable law (including for visitors from the EEA and the UK), we set non-essential cookies only after you have given your consent through our cookie banner. You may change or withdraw your cookie choices at any time by selecting "Cookie Preferences" in the footer of our Websites, which will reopen the cookie settings panel. You may also configure your browser to refuse cookies, although disabling cookies may cause certain features of the Websites and Services not to function properly.
Certain pages may include content from third parties (for example, embedded videos) that set their own cookies. We do not control those cookies, and their use is governed by the relevant third party's privacy policy. The third-party tools we use are listed in our Sub-processor and Vendor List at https://www.luminai.com/subprocessors.
8.2 Do Not Track
Some browsers offer a "Do Not Track" (DNT) setting. There is currently no industry standard for recognizing or responding to DNT signals, and our Websites do not respond to DNT browser signals. You can instead manage cookies through the cookie preferences panel described in Section 8.1 or through your browser settings.
8.3 Global Privacy Control and Sale or Sharing of Personal Information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act (CCPA), as amended. Because we do not sell or share personal information, opt-out preference signals such as the Global Privacy Control (GPC) do not change how we process your personal information. Where we detect a GPC signal, we will treat it as a request to disable non-essential cookies for that browser where technically feasible.
California residents also have rights to know, access, correct, and delete their personal information, and the right not to receive discriminatory treatment for exercising those rights. You may exercise these rights as described in Section 11 or by contacting us at security@luminai.com.
9. Data Retention
We retain personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. In general:
- Account information is retained for the duration of the applicable customer agreement and for a limited period afterward as needed for legal, accounting, and audit purposes.
- Customer Content (including PHI) is retained in accordance with the customer agreement and, where applicable, the BAA; upon termination, Customer Content is returned or deleted in line with those terms and our data management policy, subject to legal retention obligations.
- Website analytics and log data are retained for 12 MONTHS and then deleted or aggregated.
- Marketing data is retained until you unsubscribe or withdraw consent, after which we retain only the minimum needed to honor your opt-out.
The criteria we use to determine retention periods include the nature and sensitivity of the information, the purposes for which we process it, our contractual commitments, and applicable legal requirements.
10. Security and Data Breach Notification
Luminai maintains an information security program with administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, use, alteration, or destruction. These measures include access controls, encryption in transit and at rest, secure development practices, personnel security and training, and continuous monitoring, consistent with our internal security policy framework.
In the event of a personal data breach, we will act in accordance with our incident response plan: we will assess and contain the incident and notify affected customers, individuals, and regulators without undue delay where and as required by applicable law including notification to competent supervisory authorities within 72 hours of becoming aware of a notifiable breach under the GDPR, and notification to affected customers under HIPAA and our BAAs so they can meet their own obligations.
11. Your Privacy Rights
11.1 Rights for Individuals in the EEA, UK, and Switzerland (GDPR)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights with regard to personal information for which Luminai is the controller:
- Right of access — to obtain confirmation of whether we process your personal data and a copy of it;
- Right to rectification — to correct inaccurate or incomplete personal data;
- Right to erasure (“right to be forgotten”) — to have your personal data deleted in certain circumstances;
- Right to restrict processing — to limit how we use your personal data in certain circumstances;
- Right to data portability — to receive personal data you provided to us in a structured, commonly used, machine-readable format and to transmit it to another controller;
- Right to object — to object to processing based on legitimate interests, and to object at any time to processing for direct marketing;
- Right to withdraw consent — at any time, where processing is based on consent, without affecting prior processing;
- Right not to be subject to solely automated decision-making that produces legal or similarly significant effects; and
- Right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or the place of the alleged infringement.
To exercise these rights, contact our DPO using the details in Section 14. We will respond within one month, extendable by two further months for complex requests as permitted by law. If your personal data is contained in Customer Content, we may refer your request to, or coordinate with, the customer that controls that content.
11.2 U.S. State Privacy Rights (Including California)
If you are a resident of California or another U.S. state with a comprehensive privacy law, you may have the following rights, subject to applicable exemptions (including for PHI governed by HIPAA):
- Right to know/access — to request the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of third parties to whom it is disclosed;
- Right to delete — to request deletion of personal information we have collected from you;
- Right to correct — to request correction of inaccurate personal information;
- Right to opt out of sale or sharing — Luminai does not sell personal information and does not share it for cross-context behavioral advertising, so there is nothing to opt out of; if this changes, we will provide the required “Do Not Sell or Share My Personal Information” mechanism and honor opt-out preference signals such as GPC;
- Right to limit use of sensitive personal information — we use sensitive personal information only for the purposes permitted by the CCPA/CPRA (such as providing the Services and security); and
- Right to non-discrimination — we will not discriminate against you for exercising your rights.
Categories of personal information. In the preceding 12 months, we have collected the following categories of personal information described in Section 3: identifiers (such as name, email address, and IP address); professional information (such as employer and job title); internet or other electronic network activity information (such as usage and log data); and, solely as a service provider processing Customer Content on behalf of customers, any categories contained in that content (which may include health information).
You may exercise these rights by emailing security@luminai.com or 408-412-1895. We will verify your request using the information associated with your account or interaction with us. You may designate an authorized agent to make a request on your behalf; we may require proof of the agent's authority.
12. Children's Privacy
The Websites and Services are intended for business users and are not directed to children. Individuals under the age of 13 may not create or hold an account, and Luminai does not knowingly collect personal information from children under 13. If we learn or have reason to suspect that we have collected personal information from a child under 13, we will delete it and close any associated account. Other countries set higher minimum ages for consenting to data processing (up to 16 in parts of the EU); if you are below the applicable minimum age in your country, you may not use the Websites or Services.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, or legal requirements. When we do, we will revise the “Last Updated” date at the top of this page. If we make material changes, we will provide more prominent notice for example, by email to registered users or a notice on the Websites before the changes take effect. We encourage you to review this Privacy Policy periodically. Prior versions are available on request.
14. Contact US
If you have questions or concerns about this Privacy Policy or our data practices, or wish to exercise your rights, you can reach us at:
- DigitalBrain, Inc. (dba Luminai), 311 7TH AVE STE 2 SAN MATEO, CA, US 94401
- Privacy inquiries and rights requests: security@luminai.com
- Data Protection Officer: Alex Mavrogiannis, security@luminai.com
- Security reports: security@luminai.com
- EU Representative: Instant EU GDPR Representative Limited, Office 2, 12A Lower Main Street, Lucan Co. Dublin, K78 X5P8, Ireland
- UK Representative: GDPR Local Ltd, 1st Floor Front Suite, 27-29 North Street, Brighton, England, BN1 1EB
- Contact (both): contact@gdprlocal.com