Privacy Policy
Version 2026-05-18 · Effective 2026-05-18
This Privacy Policy explains how Luwi Developments ("Luwi", "we", "us") collects and processes personal data when you visit luwi.dev, request a demo, or use our products LuwiPress and Semantic Bridge. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable national law.
1. Data controller
Luwi Developments
[DATA CONTROLLER LEGAL NAME & REGISTERED ADDRESS — TO BE FILLED]
Email: privacy@luwi.dev
2. EU representative (Art. 27 GDPR)
As required by Art. 27 GDPR, we have appointed an EU representative who may be contacted by data subjects and supervisory authorities on all matters relating to the processing of personal data:
EU Representative
Email: tapadum@gmail.com
Postal address: [EU POSTAL ADDRESS — TO BE FILLED]
3. What we collect and why
3.1 Demo requests
When you submit the form at /demo, we collect: your name, work email, company, country, optional phone, the product you're interested in, company size, and a free-text description of your use case. We also record your IP address, user agent, the policy version you accepted, and the timestamp of your consent.
Legal basis: your explicit consent (Art. 6(1)(a) GDPR) for the contact and the use case description; our legitimate interest (Art. 6(1)(f)) in maintaining an auditable consent record for the metadata above.
Retention: demo request records are deleted automatically 12 months after submission unless a business relationship begins, in which case the data is migrated to a customer record governed by our Data Processing Agreement.
3.2 Contact form & chatbot
Messages sent via our contact form or the on-site chatbot are processed to respond to your enquiry. Chatbot conversations are passed to our self-hosted AI agent stack (see Section 5) and retained for up to 90 days for quality and abuse-prevention purposes.
3.3 Account data (operators & partners)
If you sign in at /ops or /app, we store your email address, name (optional), the email verification token, and an audit log of administrative actions you perform. Audit entries are retained for the duration of the account plus 24 months.
3.4 Technical logs
Our web server retains short-lived access logs (IP, request path, timestamp, user agent) for up to 30 days for security and debugging.
4. Cookies and similar technologies
We use a single first-party cookie to remember your dark-mode preference and, when you sign in, a session cookie issued by NextAuth.js. We do not use third-party advertising or analytics cookies. If this changes, we will add a cookie banner and request your consent before any non-essential cookie is set.
5. Processors and sub-processors
We share personal data only with the following processors, each bound by a Data Processing Agreement:
- Resend (email delivery — magic links, transactional email). Hosted in the EU.
- [VPS PROVIDER NAME] — primary application and database hosting in [DATA CENTRE REGION].
- Luwi self-hosted agentic stack (sim.ai workflows, Hermes gateway, Paperclip agents). All instances are operated by Luwi on infrastructure under our control.
We do not transfer personal data outside the EU/EEA except where covered by an adequacy decision or Standard Contractual Clauses. The current list of cross-border transfers and safeguards is available on request from privacy@luwi.dev.
6. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- have inaccurate data rectified (Art. 16);
- have your data erased (Art. 17) — see /gdpr;
- restrict processing (Art. 18);
- data portability in a machine-readable format (Art. 20);
- object to processing based on legitimate interest (Art. 21);
- withdraw consent at any time without affecting the lawfulness of past processing (Art. 7(3));
- lodge a complaint with your supervisory authority (Art. 77).
To exercise any of these rights, email privacy@luwi.dev or use the self-service tools at /gdpr. We respond within one month of receiving a valid request.
7. Security
We apply industry-standard technical and organisational measures including TLS in transit, encryption at rest for the application database, principle-of-least-privilege access for staff, append-only audit logging, and regular backup verification. No system is perfectly secure; we report personal data breaches to the relevant supervisory authority within 72 hours where required (Art. 33).
8. Changes to this policy
We will update this policy when our processing changes. The version number at the top of this page reflects the current revision. If changes materially affect your rights, we will request renewed consent on your next interaction with the affected service.
9. Contact
Questions about this policy: privacy@luwi.dev
EU Representative: tapadum@gmail.com