GDPR / Security
GDPR
Luma is GDPR compliant. We take both data privacy and security seriously.
We have documentation on our site supporting our security, data, and privacy practices:
- Data Processing Addendum — luma.com/dpa
- Privacy Policy — luma.com/privacy
- Terms of Service — luma.com/terms
- Security — luma.com/security
- Subprocessor list — luma.com/subprocessors
- SOC 2 Type II and SOC 3 reports, plus live compliance status — trust.luma.com
Other Privacy Laws
Our standard DPA is written for GDPR, UK GDPR, and CCPA. It doesn’t specifically address other privacy laws such as Brazil’s LGPD, Canada’s PIPEDA, or India’s DPDP Act, and it doesn’t include country-specific transfer clauses like Brazil’s ANPD standard contractual clauses.
Luma data is hosted on AWS in the United States. We don’t offer data residency in other countries or regions.
DPA terms for a specific privacy law are part of Luma Enterprise. Contact enterprise@luma.com with your requirements.
Audit Logs and Activity Tracking
Much of what a security review asks about is available without an Enterprise plan, including per-guest activity timelines, check-in and email delivery records, and self-serve data export and deletion. See Audit Logs and Activity Tracking for what you can access on a standard or Luma Plus plan.
Security Questionnaires
We do not fill out any security questionnaires without a Luma Enterprise plan.
If you are interested in Luma Enterprise for security questionnaires and additional features, please contact enterprise@luma.com with your specific requirements to learn more.