Privacy & Security

Privacy Notice

How Lua collects, uses, and protects personal data

Version 1.2July 22, 2026

Effective date: 2026-05-18 Last updated: 2026-07-22

This Privacy Notice explains how Lua handles personal data. It is written in plain English on purpose. If anything is unclear, please email [email protected] and we will explain — or fix it.


1. Who we are

Lua is a B2B platform that lets companies build, deploy, and run AI agents. Our product is a TypeScript-based agent and CLI framework — not the Lua programming language, which is unrelated and predates us by several decades.

The legal entity responsible for the personal data described in this notice is:

  • Lua Global Inc (a Delaware C corporation incorporated in the State of Delaware)
  • Registered office: 3 Germany Drive, Unit 4 #1816, Wilmington, Delaware 19804, United States
  • Trading address: Wilmington, Delaware, United States (remote-first)
  • Website: https://heylua.ai

For most data flows described below, Lua is the data controller — we decide why and how personal data is used. For agent transcripts, vector-database content, and end-user identifiers that our customers route through our platform, Lua is the data processor — our customers are the controller and decide why and how that data is used. We explain which role applies for each activity in section 4 below.


2. How to contact us about privacy

The fastest way to reach us about anything in this notice is [email protected].

Lua's acting Data Protection Officer (DPO) is Stefan Kruger (CTO). A dedicated, externally-appointed fractional DPO is in the process of being engaged; once that appointment lands, this notice will be updated to reflect the change.

Our UK and EU representatives under Article 27 (UK GDPR / EU GDPR) are appointed. EU- and UK-based data subjects can reach us directly at [email protected], or via the representatives, and we respond on the same timelines in all cases.


3. Who this notice covers

This notice is written for the people whose personal data Lua handles directly as a controller:

  • Visitors to heylua.ai and connected subdomains.
  • Lua customers — the staff at our B2B customers who sign up for and administer Lua accounts.
  • Prospects and leads who fill in our contact, demo, or newsletter forms.
  • Job applicants who apply to roles at Lua.
  • Recipients of support and sales correspondence from us.

If you are an end-user of an AI agent built on Lua by one of our customers — for example, you are chatting with a support bot that a Lua customer has deployed — then Lua is a processor of your conversation data on that customer's instructions. The customer is the controller and is the right place to direct questions about how and why your data is being processed. We will help our customer respond, but the legal relationship is with them, not us.


4. What personal data we collect and why

The complete record of every processing activity we run is kept internally in our Record of Processing Activities (ROPA). The summary below is structured for readability and covers the categories most relevant to the people reading this notice.

4.1 Account and authentication data (Lua-as-controller for customer admins; Lua-as-processor for end-users)

  • Data we collect: email address; display name; password hash (we never store passwords in clear text); single sign-on identifiers if you log in via SSO; session and refresh tokens; multi-factor authentication factors; login timestamps; IP address; user-agent.
  • Why we collect it: to authenticate you into the Lua console or SDK, to keep your session secure, and to deliver the service you have signed up for.
  • Legal basis (Art. 6): performance of a contract (Art. 6(1)(b)) for our direct customer admins; our customer's chosen basis when they route their end-users through our authentication layer.
  • Where it's stored: Neon (Postgres) hosted in the EU (London, eu-west-2). Session caches in AWS (eu-west-1).
  • How long we keep it: for the life of the account, then deleted within 30 days of contract termination, with limited retention for billing-linked identifiers per section 7.

4.2 Billing and subscription data (Lua-as-controller)

  • Data we collect: billing contact name; billing email; billing address; VAT or other tax identifier; payment-method identifier (a Stripe token — we never see or store your full card number); invoice line items; subscription state.
  • Why we collect it: to invoice you, collect payment, comply with UK tax and accounting law, and prevent fraud.
  • Legal basis (Art. 6): performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for statutory record-keeping; legitimate interests (Art. 6(1)(f)) for fraud prevention.
  • Where it's stored: Stripe (US) for card processing; our own systems on AWS (eu-west-1) for subscription state; an accounting platform (to be selected — TBD).
  • How long we keep it: seven years from the end of the relevant financial year, as required by IRS retention guidance and Delaware corporate record-keeping rules.

4.3 Support correspondence (Lua-as-controller, with some Lua-as-processor overlap)

  • Data we collect: your name; email address; the contents of your tickets and replies; attachments; ticket metadata.
  • Why we collect it: to answer your questions, troubleshoot problems, and keep a record of how an issue was resolved.
  • Legal basis (Art. 6): performance of contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) in keeping evidence of issue resolution.
  • Where it's stored: Google Workspace (Gmail) for the [email protected] inbox until we adopt a dedicated ticketing platform.
  • How long we keep it: two years from ticket closure by default.

4.4 Product analytics inside the Lua console (Lua-as-controller)

  • Data we collect: a pseudonymous user identifier (a hash of your Stack Auth subject ID); page-view events; feature-interaction events; user-agent; truncated IP address (last octet removed); timestamps.
  • Why we collect it: to understand which features are useful, which are confusing, and where to improve the product.
  • Legal basis (Art. 6): legitimate interests (Art. 6(1)(f)) in improving the product. You can opt out via the console preferences.
  • Where it's stored: PostHog (EU region preferred — region verification is in flight).
  • How long we keep it: 13 months rolling.

4.5 Marketing data (Lua-as-controller)

  • Data we collect: name; business email; job title; company; consent timestamp and source; engagement events (opens, clicks); unsubscribe state.
  • Why we collect it: to deliver newsletters and event invitations you have asked for, and to manage B2B prospecting where the lawful basis allows.
  • Legal basis (Art. 6): consent (Art. 6(1)(a)) for the newsletter and marketing emails — you can withdraw consent at any time using the unsubscribe link in any email; legitimate interests (Art. 6(1)(f)) for B2B prospecting where UK ICO direct-marketing guidance and the soft-opt-in regime applies.
  • Where it's stored: HubSpot CRM (residency verification in flight).
  • How long we keep it: while consent is valid plus three years from last engagement; an unsubscribe record (email hash only) is kept indefinitely so we do not contact you by mistake.

4.6 Website visitor data (Lua-as-controller)

  • Data we collect: IP address; user-agent; referrer; pages visited; session duration; CMP consent state; form-submitted contact details (handed off to section 4.5 if you submit a demo or contact form).
  • Why we collect it: to operate the website, measure aggregated traffic, and route inbound demo requests.
  • Legal basis (Art. 6): consent (Art. 6(1)(a)) for non-strictly-necessary cookies under UK PECR; legitimate interests (Art. 6(1)(f)) for strictly-necessary operation (session, security).
  • Where it's stored: Cloudflare (global edge) and AWS (origin); analytics provider TBD; cookie consent records in our consent management platform (Osano or Cookiebot — selection in flight).
  • How long we keep it: edge / CDN access logs for 30 days; aggregated analytics for 13 months; consent records for two years.
  • More detail on cookies: see section 11 below.

4.7 Job-application data (Lua-as-controller)

  • Data we collect: name; contact details; CV / resume; cover letter; interview notes and scorecards; references; right-to-work evidence (UK roles).
  • Why we collect it: to consider you for a role and, if you accept an offer, to onboard you.
  • Legal basis (Art. 6): pre-contractual steps at the data subject's request (Art. 6(1)(b)) for active applications; legitimate interests (Art. 6(1)(f)) for talent-pool retention with your consent.
  • Where it's stored: Google Workspace (Gmail / Drive) until we adopt a dedicated applicant-tracking system.
  • How long we keep it: six months from rejection by default; two years if you have consented to talent-pool retention; longer for right-to-work evidence as required by UK Home Office rules.

4.8 Agent conversation logs and vector-database content (Lua-as-processor)

When you interact with an AI agent built on Lua by one of our customers, the customer is the controller and Lua is the processor. We process the conversation and any documents the customer has indexed for retrieval-augmented generation strictly on the customer's instructions, as set out in the Data Processing Agreement (DPA) we sign with each customer.

  • Data categories: conversation transcripts (prompts and completions); tool-call traces; invocation metadata; indexed source documents and embeddings; any personal data the end-user or the customer's tools introduce into the conversation.
  • Legal basis: the customer's basis as controller. Lua's basis as processor is legitimate interests in delivering the contracted service, underpinned by the DPA.
  • Where it's stored: MongoDB Atlas in the EU (eu-west-1).
  • How long we keep it: 30 days hot, 12 months total by default; customer DPAs may shorten or extend this. All per-tenant data is deleted within 30 days of contract termination.
  • If you are an end-user with questions about this data, please contact the Lua customer whose product you used. We will support that customer in responding to you.

4.9 Security and audit logs (Lua-as-controller)

  • Data we collect: IP addresses; user-agent; user IDs (for legitimate actors); request paths; timestamps; HTTP headers (we deliberately exclude request bodies and authentication headers to minimise personal-data exposure); CloudTrail and Kubernetes audit events.
  • Why we collect it: to detect, investigate, and respond to security events; to demonstrate the integrity of our processing under GDPR Art. 5(2); to support SOC 2 and ISO 27001 evidence requirements.
  • Legal basis (Art. 6): legitimate interests (Art. 6(1)(f)) in the security of our systems; legal obligation (Art. 6(1)(c)) where audit evidence is statutorily required.
  • Where it's stored: AWS CloudWatch (eu-west-1) and Better Stack (EU region).
  • How long we keep it: target 12 months for security logs, six years for audit-trail records. Some retention values are currently in flight; we are tightening them as part of our ongoing security workstreams.

4.10 Special-category data (GDPR Art. 9)

We do not solicit or process special-category personal data (health, biometric, racial or ethnic origin, sexual orientation, religious or political views) for any of the activities listed above. If a customer's end-user incidentally includes special-category data in a conversation with one of our customers' agents, that data is handled under the customer's instructions in their role as controller.

The one exception is our HR records for our own employees, which may include sickness-absence data under the employment-law derogation in Art. 9(2)(b). This applies only to Lua's own employees and is handled by our People function.


5. Who we share personal data with

We share personal data with three types of recipient:

  1. Internal teams at Lua — only the people who need access to do their job. Engineering on-call sees production logs; the People function sees HR data; Finance sees billing data; the support rota sees support correspondence.
  2. Subprocessors — third-party service providers that process personal data on Lua's behalf under a Data Processing Agreement. Examples include AWS (hosting), Anthropic and OpenAI (LLM inference), MongoDB Atlas (database), and Deel (HR). The complete and current list is published at https://heylua.ai/legal/subprocessors.
  3. Authorities and professional advisers — where we are required to disclose data by law (e.g. tax authorities, courts, regulators) or where we need to take advice from our auditors, accountants, or lawyers under their own confidentiality obligations.

We do not sell personal data. We do not share personal data with advertising networks.


6. International transfers

Lua is based in the United States (Delaware), with EU and UK personal data covered via our UK and EU representatives (UK GDPR / EU GDPR Art. 27). The UK and EEA are in scope of our processing through our UK + EU customers and UK + EU-based staff. Most of our subprocessors are also US-based. The transfers that matter most:

  • LLM providers (Anthropic and OpenAI, both US) for agent inference and embeddings.
  • Hosting and edge (parts of AWS and Cloudflare global posture) where data may transit US-based control planes.
  • HR and finance (Deel, Stripe, HubSpot) where the vendor is US-headquartered.

For every cross-border transfer to a third country without an adequacy decision, we rely on a combination of:

  • UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs) for UK-originating transfers.
  • EU SCCs (2021 module set) for EU-originating transfers.
  • Transfer impact assessments documenting the legal regime in the destination country and any supplementary technical and organisational measures.

For UK ↔ EU transfers we rely on the UK government's adequacy decision for the EEA and the European Commission's adequacy decision for the UK.

Detail on the legal mechanism for each subprocessor — including which transfer instrument applies — is in our public Subprocessor List.


7. How long we keep personal data

We keep personal data only for as long as we need it for the purpose we collected it. Our default retention windows are listed against each data category in section 4 above. The full retention schedule is in our internal Data Retention & Disposal Policy and the headline rules are:

Data categoryDefault retention
Active account dataDuration of contract + 30 days for deletion sweep
Login logs90 days rolling (some longer-tail retention TBD)
Customer agent transcripts30 days hot, 12 months total (subject to per-customer DPA)
Customer billing dataSeven years (UK statutory)
Support ticketsTwo years from closure
Product analytics13 months rolling
Marketing dataWhile consent is valid + three years from last engagement
Website / edge logs30 days
Job applications (rejected)Six months, or two years with consent
Employee HR recordsDuration of employment + six years
Security logsTarget 12 months hot, six years for audit-trail evidence

We may keep data longer where we have a legal obligation (statutory record-keeping), where it is needed for the defence of legal claims, or where a legal hold has been placed on it. When data reaches the end of its retention window it is either deleted or, for restricted data sets, cryptographically erased.


8. Your rights

If you are in the UK or the EEA, you have the following rights over your personal data under the UK GDPR and EU GDPR:

  • Right of access (Art. 15) — ask us to confirm whether we process your personal data and, if so, send you a copy.
  • Right to rectification (Art. 16) — ask us to correct personal data that is inaccurate or incomplete.
  • Right to erasure (Art. 17) — ask us to delete your personal data when there is no good reason for us to continue processing it.
  • Right to restriction of processing (Art. 18) — ask us to pause processing in defined circumstances (e.g. while we investigate an accuracy challenge).
  • Right to data portability (Art. 20) — ask us to send you, or a third party of your choice, the personal data you have provided to us in a structured, commonly-used, machine-readable format. This right applies where the processing is based on consent or on the performance of a contract.
  • Right to object (Art. 21) — object to processing based on legitimate interests, including profiling, and to direct marketing at any time.
  • Right to withdraw consent (Art. 7(3)) — withdraw consent at any time where we rely on consent as the lawful basis (e.g. marketing). Withdrawing consent does not affect the lawfulness of processing before the withdrawal.
  • Rights related to automated decision-making (Art. 22) — Lua does not make solely automated decisions producing legal or similarly significant effects on data subjects. Outputs from agents built on Lua are always intermediated by our customer's product. We have documented this position internally.

If you are an end-user of one of our customers' agents, please direct rights requests to the customer running that agent. We will assist that customer in responding to you, but the legal relationship sits with them.


9. How to exercise your rights

To make a request, email [email protected] with:

  • The right you want to exercise.
  • Enough information for us to identify you and find your data (typically the email address you use to log in or correspond with us).
  • For requests on behalf of another person, evidence of your authority to act for them.

We will respond within one calendar month of receiving a complete request, as required by the UK GDPR. If your request is complex or you make several requests, we may extend this by a further two months and will tell you within the first month if we need to do so. We will not charge a fee for a request unless it is manifestly unfounded, excessive, or repetitive; if we do, we will explain why before we proceed.

We may need to ask you to verify your identity before responding. This is to protect your data from being disclosed to someone else.

A dedicated DSAR portal is on our roadmap. Until it lands, email is the channel.


10. Your right to lodge a complaint

You have the right to complain to a data protection supervisory authority about how Lua handles your personal data.

  • United Kingdom — Information Commissioner's Office (ICO) Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF ico.org.uk | 0303 123 1113

  • European Economic Area — you may complain to the supervisory authority in the EU member state where you live, where you work, or where the alleged infringement took place. A list of national supervisory authorities is at edpb.europa.eu.

We would always appreciate the chance to address your concerns before you go to a regulator. Email [email protected] and we will respond on the same one-month clock as a rights request.


11. Cookies and similar tracking

On our marketing website (heylua.ai and its subdomains) and the Lua product console we use a small number of cookies and similar technologies. Strictly-necessary cookies (session, security, load-balancing) are set without a consent prompt because UK PECR and the EU ePrivacy Directive permit them. All other cookies — including analytics and any marketing cookies — are set only after you give consent through our consent management platform (CMP).

The CMP is being deployed. When it goes live, the cookie banner on heylua.ai will be the operational front door for cookie consent and will surface the full per-category list, lawful-basis declarations, and a vendor-by-vendor consent withdrawal control. Alongside strictly-necessary cookies, the website currently uses PostHog product analytics, which records page views, click interactions, and device/browser information and stores identifiers in cookies and browser local storage to distinguish visitors. Until the CMP is live, visitors can limit this through their browser's cookie controls, and may contact [email protected] with any request regarding analytics data.

Inside the authenticated Lua console we do not use cookies for analytics — product analytics inside the console use a hashed user identifier issued at sign-in (see section 4.4).


12. Google User Data and API Services

When you connect a Google account to a Lua agent, the agent accesses your Google data only through the Google services and permission scopes you authorize on Google's consent screen. Access is limited to the scopes you grant and is used solely to provide the features you have configured your agent to perform on your behalf.

Lua's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We do not use data obtained through Google Workspace APIs to develop, improve, or train generalized or non-personalized artificial intelligence and/or machine learning models. Google user data is not sold, and is not transferred to third parties except as necessary to provide or improve the user-facing features you have enabled, to comply with applicable law, or as part of a merger or acquisition.

You can revoke Lua's access to your Google data at any time by disconnecting the integration within the app or through your Google Account permissions.


13. Children

Lua's products are B2B. We do not knowingly market to or collect personal data from children under 13. If you believe we have inadvertently collected such data, please email [email protected] and we will delete it.

If one of our customers operates an agent aimed at children, the customer is the controller and is responsible for any age-appropriate-design obligations (UK ICO Age Appropriate Design Code, COPPA in the US, equivalents elsewhere). The DPA we sign with each customer requires the customer to comply with the law applicable to their data subjects.


14. Security

We take the security of personal data seriously. The detailed framework is in our internal information-security policy bundle and a public summary is available on request. Headline points:

  • Encryption in transit — TLS 1.2 or higher everywhere; mutual TLS or AWS PrivateLink for sensitive intra-service links where supported.
  • Encryption at rest — platform-default encryption on every database and object store; KMS-managed keys for confidential and restricted data.
  • Access controls — least privilege, role-based access controls, MFA required for staff, named-individual + break-glass for restricted data sets.
  • Independent assurance — Lua is working toward SOC 2 Type II and ISO 27001 certification (in flight).
  • Incident response — a documented incident-response policy and runbook with a 72-hour GDPR Art. 33 notification commitment to the ICO and a 24-hour customer-notification commitment in our DPAs.

If we discover a personal data breach that is likely to result in a risk to your rights and freedoms we will notify the relevant regulator within 72 hours of becoming aware of it, and we will notify you directly without undue delay if the breach is likely to result in a high risk to you.


15. Changes to this notice

We will update this notice when our processing changes, when new subprocessors are added, when retention windows shift, or when the law moves. Every change is version-tracked in our repository.

  • Material changes (new categories of data, new lawful basis, new sub-processors that handle your personal data, retention changes that extend the window) will be notified to you in advance by email where we hold your email, by a banner on the website, or in the product. Customers also receive notification via the channel set out in their contract.
  • Non-material changes (typos, clarifications, formatting) are made without notification but are version-tracked.

When we change this notice, the version and last-reviewed fields at the top of this document are updated and the change is recorded in the revision history below.


16. Effective date and revision history

Effective date of this version: 2026-07-22

VersionDateAuthorChange
1.0 (Draft)2026-05-18Stefan KrugerInitial draft. Awaiting DPO review and legal-counsel sign-off before publication.
1.1 (Draft)2026-07-22Stefan Kruger§11 updated to truthfully disclose current PostHog analytics on the marketing website pending the CMP; §2/§6 updated to reflect that UK and EU Article 27 representatives are appointed. Owner decisions of 2026-07-22.
1.2 (Draft)2026-07-22Stefan KrugerNew §12 "Google User Data and API Services" ported verbatim from the live site (lua-website PR #178, commit 0b18bb8) — Google Limited Use disclosure required for OAuth verification; subsequent sections renumbered 13-16. Repo-relative references removed for public publication (§5 register path, §7 data-retention path). Awaiting DPO review and legal-counsel sign-off before publication.