Skip to content

LEGAL

GDPR and data protection

How responsibilities are divided and how requests from customers are handled.

Last updated: February 2026

Roles

The business is the controller of its customer data: it decides what the receptionist collects and why. Lumora acts as processor and handles that data on the business's instructions.

Purpose limitation

Customer details are used to answer the enquiry, book or manage the appointment, notify the business and — where enabled — send reminders or place a confirmation call. They are not used for anything else.

Data minimisation

The receptionist collects the name, phone number, requested service, preferred date and time, an optional email address and any caller note the customer wants passed on. Email is optional.

Requests from customers

Access, correction and erasure requests are handled by the business, which can view its conversations and appointments and delete them permanently from the dashboard. Lumora supports the business with any request it cannot complete itself.

Deletion

Deletion in Lumora is permanent. The business selects a date range, confirms, and the conversations or appointments in that range are removed. There is no recovery window.

Access control

Every staff account belongs to one business and sees only that business's data. Roles and privileges define which screens and actions each account can use.

Sub-processors

Operating the platform requires infrastructure, telephony and AI service providers. The list applicable to your account is provided with your data-processing agreement.

Contact

For data-protection questions or to request the data-processing agreement, use the contact page.

This page describes how the Lumora platform works. The binding commercial and data-processing terms are provided in the agreement signed before your account is created.

Questions about this page?

Send us the details of your request and the Lumora team will get back to you.

Contact us