Legal

Privacy Policy

Effective date: [EFFECTIVE_DATE] · Last updated: [EFFECTIVE_DATE]

Draft for review. This document is a working draft with [bracketed placeholders] to be completed and reviewed by qualified legal counsel before publication or reliance — including the subprocessor commitments, which depend on the data-processing agreements still being finalized.

This Privacy Policy explains how [LEGAL_ENTITY_NAME] ("LuciusOS", "we", "us") collects, uses, discloses, and safeguards information in connection with the LuciusOS service (the "Service"). We act as a data processor on behalf of our customers for the workspace data they bring into the Service, and as a data controller for account and billing information.

1. Who we are

The data controller / operator is [LEGAL_ENTITY_NAME], [REGISTERED_ADDRESS]. For any privacy question or to exercise your rights, contact us at privacy@luciusos.ai.

2. Data we process

We do not extract, infer, or use protected attributes (such as age, gender, nationality, or their proxies), and we do not produce candidate scores, rankings, or automated rejections.

3. How we use data

Access to your data is governed by a permission layer (the "Evidence Firewall"): no content reaches an AI model without a permissioned, minimum-necessary evidence set, and private data is never exposed in group answers, reports, or to administrators.

4. AI and subprocessors

To deliver the Service we rely on the following subprocessors under contract. We share only the minimum data necessary and require that customer data is not used to train third-party models.

An up-to-date subprocessor list is available on request at privacy@luciusos.ai.

5. Retention & deletion

We retain data only as long as needed to provide the Service. Removing a source or record starts a reversible soft-delete with a 30-day grace window, after which the data — including derived memory, embeddings, and stored files — is permanently purged, leaving only non-content audit records. You may request erasure of a person's data at any time.

6. Security

Secrets are encrypted at rest via a key-management service; data is encrypted in transit; access is org-scoped and least-privilege. We maintain audit trails of meaningful actions and encrypted backups with a documented restore procedure.

7. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, or port your personal data, and to object to certain processing. For individuals in Türkiye these rights arise under the KVKK (Law No. 6698); for individuals in the EU/EEA and UK, under the GDPR / UK GDPR. To exercise any right, contact privacy@luciusos.ai. Where we process data on behalf of a customer, we will refer your request to that customer as the controller.

8. International transfers

Where data is transferred across borders, we rely on appropriate safeguards (such as Standard Contractual Clauses) as required by applicable law.

9. Changes

We may update this policy; material changes will be posted here with an updated effective date.

10. Contact

[LEGAL_ENTITY_NAME] · [REGISTERED_ADDRESS] · privacy@luciusos.ai · Governing law: [GOVERNING_LAW / JURISDICTION].