Privacy Policy
This is a convenience translation. The German version is authoritative.
1. Controller
LuminaByte GmbH
Julius-Hatry-Straße 1, 68163 Mannheim, Germany
Email: support@luminabyte.de
2. Hosting and server logs
This website runs on our own infrastructure at Hetzner Online GmbH (Falkenstein data center, Germany). When you visit the site, our web server automatically processes technical access data (IP address, date and time, requested page, browser type) as far as necessary to deliver and secure the service. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure and stable operation). Server logs are deleted after 7 days at the latest.
3. No cookies; analytics
This website sets no cookies and stores nothing on your device. For anonymous reach measurement we use PostHog (PostHog EU, processed on servers within the EU) in cookieless mode: no cookies and no persistent identifiers are stored on your device, and measurement data (pages viewed, coarse technical properties) cannot be linked into a profile across visits. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in improving our offering). A consent banner is therefore not required.
4. Demo phone number
This website lists a demo phone number (+49 621 6374 1919). Calls to this number are answered by our AI telephone assistant, which explicitly discloses this at the start of the call. To provide the service, the conversation is transcribed in real time and processed by AI systems. The audio connection is not recorded; we store a call transcript (deleted after 21 days at the latest) and a summary (deleted after 365 days at the latest). Legal bases are Art. 6(1)(b) GDPR (pre-contractual measures at your request) and Art. 6(1)(f) GDPR (legitimate interest in demonstrating our service).
The following processors are involved in handling demo calls:
- Hetzner Online GmbH, Germany (hosting)
- Deepgram Inc., USA (speech recognition via EU endpoint; safeguarded by EU Standard Contractual Clauses)
- Gladia, France (speech recognition — failover; in failover operation the provider stores audio and transcript for up to 3 weeks)
- ElevenLabs Inc., USA (speech synthesis; EU-US Data Privacy Framework certified)
- Microsoft Ireland Operations Ltd. (Azure OpenAI, EU Data Zone; Azure Speech, Germany — conversation text is not stored there and not used for training; only content automatically flagged as potential abuse may be stored for a limited time for human review within the EU)
- Microsoft (Microsoft Graph): contact matching and calendar access within the customer’s Microsoft account — reads are free/busy times only, and booking an appointment writes an event (processing in the EU / the customer’s Microsoft tenant)
- Google LLC, USA (contact matching and calendar access where the customer connects a Google account, delegated OAuth access — reads are free/busy times only, and booking an appointment writes an event; transfers based on the EU-US Data Privacy Framework)
- seven.io (seven communications GmbH & Co. KG), Germany (SMS delivery)
- Microsoft Azure Communication Services, EU (email delivery)
Recipient: telecommunications provider (independent controller)
Telephony (line, numbers, call set-up) is provided by easybell GmbH, Berlin. easybell does not act as our processor but as an independent controller in its capacity as a provider of telecommunications services; the confidentiality of telecommunications and German telecommunications law (§ 3 TDDDG, § 166 TKG) apply to the traffic data processed in its network. easybell’s own privacy policy applies in that respect.
5. Customer account and billing (app.scoco.ai)
If you use a customer account on app.scoco.ai, we process your account and sign-in data (name, email address, role within the company, password as a hash value only, two-factor authentication details) as well as security-relevant log data (sign-in times, IP address, failed sign-in attempts). The legal bases are Art. 6(1)(b) GDPR (performance of the usage contract) and Art. 6(1)(f) GDPR (legitimate interest in protecting accounts).
For invoicing and payment processing we use Stripe Payments Europe Ltd., Ireland. Only billing data is passed on: company name, billing email address, address, VAT identification number and payment method. Call content, transcripts and summaries never reach the payment provider. The legal bases are Art. 6(1)(b) GDPR (performance of the contract) and Art. 6(1)(c) GDPR (retention obligations under commercial and tax law). Where intra-group transfers to Stripe, Inc. (USA) take place, they rely on the EU-US Data Privacy Framework or on the EU Standard Contractual Clauses under Stripe’s data processing agreement.
For the data arising from calls to our customers’ own phone numbers, the respective customer is the controller; we process it on their behalf. Callers are informed by the separate privacy notice for callers.
6. Contact by email
If you contact us by email, we process your details to handle the inquiry (Art. 6(1)(b) GDPR) or based on our legitimate interest in responding (Art. 6(1)(f) GDPR). The data is deleted once it is no longer required and no statutory retention obligations apply.
7. Transfers to third countries
Where providers established outside the EU/EEA are used (see sections 4 and 5), transfers are based either on the adequacy decision for the EU-US Data Privacy Framework — where the provider is certified — or on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). Where a transfer relies on the Standard Contractual Clauses, we additionally carry out a documented transfer impact assessment and apply supplementary measures, in particular processing on EU endpoints and continuous transport encryption (TLS) on all connections to the processing services.
8. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on Art. 6(1)(f) GDPR (Art. 21). Contact support@luminabyte.de.
You also have the right to lodge a complaint with a data protection supervisory authority. Our competent authority is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (LfDI BW), Lautenschlagerstraße 20, 70173 Stuttgart, Germany.
9. Version and changes
Version: August 2026. We update this privacy policy when processing or the legal situation changes; the version published here applies.