Privacy & Security

Privacy Notice

How Lua collects, uses, and protects personal data

Version 1.5August 11, 2026

Effective date: 2026-07-22 Last updated: 2026-07-22

This Privacy Notice explains how Lua handles personal data. It is written in plain English on purpose. If anything is unclear, please email [email protected] and we will explain — or fix it.


1. Who we are

Lua is a B2B platform that lets companies build, deploy, and run AI agents. Our product is a TypeScript-based agent and CLI framework — not the Lua programming language, which is unrelated and predates us by several decades.

The legal entity responsible for the personal data described in this notice is:

  • Lua Global Inc (a Delaware C corporation incorporated in the State of Delaware)
  • Registered office: 3 Germany Drive, Unit 4 #1816, Wilmington, Delaware 19804, United States
  • Trading address: Wilmington, Delaware, United States (remote-first)
  • Website: https://heylua.ai

For most data flows described below, Lua is the data controller — we decide why and how personal data is used. For agent transcripts, vector-database content, and end-user identifiers that our customers route through our platform, Lua is the data processor — our customers are the controller and decide why and how that data is used. We explain which role applies for each activity in section 4 below.


2. How to contact us about privacy

The fastest way to reach us about anything in this notice is [email protected].

Lua's acting Data Protection Officer (DPO) is Stefan Kruger (CTO); you can reach the DPO at [email protected]. A dedicated, externally-appointed fractional DPO is in the process of being engaged; once that appointment lands, this notice will be updated to reflect the change.

  • General privacy questions: [email protected]
  • Data Protection Officer: [email protected]
  • Postal: Lua Global Inc, 3 Germany Drive, Unit 4 #1816, Wilmington, Delaware 19804, United States

Our GDPR Article 27 representatives

Because Lua Global Inc is established in the United States, we have appointed representatives in the UK and the EU under Article 27 of the UK GDPR and the EU GDPR. UK- and EU-based data subjects, and supervisory authorities, may contact the relevant representative directly — in addition to contacting us at [email protected], to which we respond on the same timelines regardless of location.

EU representative (EU GDPR Art. 27): Instant EU GDPR Representative Ltd, for the attention of Adam Brogden — Office 2, 12A Lower Main Street, Lucan, Co. Dublin, K78 X5P8, Ireland. Email: [email protected]. Submit a request: https://luaglobalinc.gdprlocal.com/eu

UK representative (UK GDPR Art. 27): GDPRLocal Ltd, for the attention of Adam Brogden — 1st Floor Front Suite, 27–29 North Street, Brighton, England, BN1 1EB. Email: [email protected]. Submit a request: https://luaglobalinc.gdprlocal.com/uk


3. Who this notice covers

This notice is written for the people whose personal data Lua handles directly as a controller:

  • Visitors to heylua.ai and connected subdomains.
  • Lua customers — the staff at our B2B customers who sign up for and administer Lua accounts.
  • Prospects and leads who fill in our contact, demo, or newsletter forms.
  • Job applicants who apply to roles at Lua.
  • Recipients of support and sales correspondence from us.

If you are an end-user of an AI agent built on Lua by one of our customers — for example, you are chatting with a support bot that a Lua customer has deployed — then Lua is a processor of your conversation data on that customer's instructions. The customer is the controller and is the right place to direct questions about how and why your data is being processed. We will help our customer respond, but the legal relationship is with them, not us.


4. What personal data we collect and why

The complete record of every processing activity we run is kept internally in our Record of Processing Activities (ROPA). The summary below is structured for readability and covers the categories most relevant to the people reading this notice.

4.1 Account and authentication data (Lua-as-controller for customer admins; Lua-as-processor for end-users)

  • Data we collect: email address; display name; password hash (we never store passwords in clear text); single sign-on identifiers if you log in via SSO; session and refresh tokens; multi-factor authentication factors; login timestamps; IP address; user-agent.
  • Why we collect it: to authenticate you into the Lua console or SDK, to keep your session secure, and to deliver the service you have signed up for.
  • Legal basis (Art. 6): performance of a contract (Art. 6(1)(b)) for our direct customer admins; our customer's chosen basis when they route their end-users through our authentication layer.
  • Where it's stored: hosted in the UK/EU. Vendor detail is in our Subprocessor List.
  • How long we keep it: for the life of the account, then deleted within 30 days of contract termination, with limited retention for billing-linked identifiers per section 7.

4.2 Billing and subscription data (Lua-as-controller)

  • Data we collect: billing contact name; billing email; billing address; VAT or other tax identifier; payment-method identifier (a token issued by our payment processor — we never see or store your full card number); invoice line items; subscription state.
  • Why we collect it: to invoice you, collect payment, comply with applicable tax and accounting law, and prevent fraud.
  • Legal basis (Art. 6): performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for statutory record-keeping; legitimate interests (Art. 6(1)(f)) for fraud prevention.
  • Where it's stored: card processing is handled by our payment processor; subscription records are hosted in the UK/EU. Vendor detail is in our Subprocessor List.
  • How long we keep it: seven years from the end of the relevant financial year, as required by applicable tax and accounting law.

4.3 Support correspondence (Lua-as-controller, with some Lua-as-processor overlap)

  • Data we collect: your name; email address; the contents of your tickets and replies; attachments; ticket metadata.
  • Why we collect it: to answer your questions, troubleshoot problems, and keep a record of how an issue was resolved.
  • Legal basis (Art. 6): performance of contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) in keeping evidence of issue resolution.
  • Where it's stored: the [email protected] mailbox in our company email platform. Vendor detail is in our Subprocessor List.
  • How long we keep it: two years from ticket closure by default.

4.4 Product analytics inside the Lua console (Lua-as-controller)

  • Data we collect: a pseudonymous user identifier; page-view events; feature-interaction events; user-agent; truncated IP address (last octet removed); timestamps.
  • Why we collect it: to understand which features are useful, which are confusing, and where to improve the product.
  • Legal basis (Art. 6): legitimate interests (Art. 6(1)(f)) in improving the product. You can opt out via the console preferences.
  • Where it's stored: our product-analytics platform. Vendor and region detail is in our Subprocessor List.
  • How long we keep it: 13 months rolling.

4.5 Marketing data (Lua-as-controller)

  • Data we collect: name; business email; job title; company; consent timestamp and source; engagement events (opens, clicks); unsubscribe state.
  • Where the data comes from: most marketing data comes directly from you (a form you submitted or an email exchange). For B2B prospecting, we may also obtain business-contact details from public business sources and from business contacts.
  • Why we collect it: to deliver newsletters and event invitations you have asked for, and to manage B2B prospecting where the lawful basis allows.
  • Legal basis (Art. 6): consent (Art. 6(1)(a)) for the newsletter and marketing emails — you can withdraw consent at any time using the unsubscribe link in any email; legitimate interests (Art. 6(1)(f)) for B2B prospecting where UK ICO direct-marketing guidance and the soft-opt-in regime applies.
  • Where it's stored: our marketing CRM. Vendor detail is in our Subprocessor List.
  • How long we keep it: while consent is valid plus three years from last engagement; an unsubscribe record (email hash only) is kept indefinitely so we do not contact you by mistake.

4.6 Website visitor data (Lua-as-controller)

  • Data we collect: IP address; user-agent; referrer; pages visited; session duration; cookie-consent state; form-submitted contact details (handed off to section 4.5 if you submit a demo or contact form).
  • Why we collect it: to operate the website, measure aggregated traffic, and route inbound demo requests.
  • Legal basis (Art. 6): consent (Art. 6(1)(a)) for non-strictly-necessary cookies under UK PECR; legitimate interests (Art. 6(1)(f)) for strictly-necessary operation (session, security).
  • Where it's stored: our edge network and hosting infrastructure; cookie-consent records are held in our consent-management platform. Vendor detail is in our Subprocessor List.
  • How long we keep it: edge / CDN access logs for 30 days; aggregated analytics for 13 months; consent records for two years.
  • More detail on cookies: see section 11 below.

4.7 Job-application data (Lua-as-controller)

  • Data we collect: name; contact details; CV / resume; cover letter; interview notes and scorecards; references; right-to-work evidence (UK roles).
  • Why we collect it: to consider you for a role and, if you accept an offer, to onboard you.
  • Legal basis (Art. 6): pre-contractual steps at the data subject's request (Art. 6(1)(b)) for active applications; legitimate interests (Art. 6(1)(f)) for talent-pool retention with your consent.
  • Where it's stored: our company email and document platform. Vendor detail is in our Subprocessor List.
  • How long we keep it: six months from rejection by default; two years if you have consented to talent-pool retention; longer for right-to-work evidence as required by UK Home Office rules.

4.8 Agent conversation logs and vector-database content (Lua-as-processor)

When you interact with an AI agent built on Lua by one of our customers, the customer is the controller and Lua is the processor. We process the conversation and any documents the customer has indexed for retrieval-augmented generation strictly on the customer's instructions, as set out in the Data Processing Agreement (DPA) we sign with each customer.

  • Data categories: conversation transcripts (prompts and completions); tool-call traces; invocation metadata; indexed source documents and embeddings; any personal data the end-user or the customer's tools introduce into the conversation.
  • Legal basis: the customer's basis as controller. Lua's basis as processor is legitimate interests in delivering the contracted service, underpinned by the DPA.
  • Where it's stored: hosted in the EU. Vendor detail is in our Subprocessor List.
  • How long we keep it: 30 days hot, 12 months total by default; customer DPAs may shorten or extend this. All per-tenant data is deleted within 30 days of contract termination.
  • If you are an end-user with questions about this data, please contact the Lua customer whose product you used. We will support that customer in responding to you.

4.9 Security and audit logs (Lua-as-controller)

  • Data we collect: IP addresses; user-agent; user IDs (for legitimate actors); request paths; timestamps; HTTP headers; infrastructure audit events.
  • Why we collect it: to detect, investigate, and respond to security events; to demonstrate the integrity of our processing under GDPR Art. 5(2); and to meet our security-assurance obligations.
  • Legal basis (Art. 6): legitimate interests (Art. 6(1)(f)) in the security of our systems; legal obligation (Art. 6(1)(c)) where audit evidence is statutorily required.
  • Where it's stored: centralized security monitoring, hosted in the UK/EU. Vendor detail is in our Subprocessor List.
  • How long we keep it: 12 months for security logs; six years for audit-trail records.

4.10 Special-category data (GDPR Art. 9)

We do not solicit or process special-category personal data (health, biometric, racial or ethnic origin, sexual orientation, religious or political views) for any of the activities listed above. If a customer's end-user incidentally includes special-category data in a conversation with one of our customers' agents, that data is handled under the customer's instructions in their role as controller.

The one exception is our HR records for our own employees, which may include sickness-absence data under the employment-law derogation in Art. 9(2)(b). This applies only to Lua's own employees and is handled by our People function.


5. Who we share personal data with

We share personal data with three types of recipient:

  1. Internal teams at Lua — access to personal data is role-based and limited to the people who need it to do their job.
  2. Subprocessors — third-party service providers that process personal data on Lua's behalf under a Data Processing Agreement. Examples include AWS (hosting), Anthropic and OpenAI (LLM inference), MongoDB Atlas (database), and Deel (HR). The complete and current list is published at https://heylua.ai/legal/subprocessors.
  3. Authorities and professional advisers — where we are required to disclose data by law (e.g. tax authorities, courts, regulators) or where we need to take advice from our auditors, accountants, or lawyers under their own confidentiality obligations.

We do not sell personal data. We do not share personal data with advertising networks.


6. International transfers

Lua is based in the United States (Delaware). The UK and EEA are in scope of our processing through our UK + EU customers and UK + EU-based staff. Most of our subprocessors are also US-based. The transfers that matter most:

  • LLM providers for agent inference and embeddings (see the Subprocessor List for providers and regions).
  • Hosting and edge where data may transit US-based control planes.
  • HR and finance where the vendor is US-headquartered.

For every cross-border transfer to a third country without an adequacy decision, we rely on a combination of:

  • UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs) for UK-originating transfers.
  • EU SCCs (2021 module set) for EU-originating transfers.
  • Transfer impact assessments documenting the legal regime in the destination country and any supplementary technical and organisational measures.

For UK ↔ EU transfers we rely on the UK government's adequacy decision for the EEA and the European Commission's adequacy decision for the UK.

Detail on the legal mechanism for each subprocessor — including which transfer instrument applies — is in our public Subprocessor List. A copy of the relevant transfer safeguards (SCCs / IDTA) is available via [email protected].


7. How long we keep personal data

We keep personal data only for as long as we need it for the purpose we collected it. Our default retention windows are listed against each data category in section 4 above. The full retention schedule is maintained internally, and the headline rules are:

Data categoryDefault retention
Active account dataDuration of contract + 30 days for deletion sweep
Login logs90 days rolling
Customer agent transcripts30 days hot, 12 months total (subject to per-customer DPA)
Customer billing dataSeven years (applicable tax and accounting law)
Support ticketsTwo years from closure
Product analytics13 months rolling
Marketing dataWhile consent is valid + three years from last engagement
Website / edge logs30 days
Job applications (rejected)Six months, or two years with consent
Employee HR recordsDuration of employment + six years
Security logs12 months, six years for audit-trail evidence

We may keep data longer where we have a legal obligation (statutory record-keeping), where it is needed for the defence of legal claims, or where a legal hold has been placed on it. When data reaches the end of its retention window it is either deleted or, for restricted data sets, cryptographically erased.


8. Your rights

If you are in the UK or the EEA, you have the following rights over your personal data under the UK GDPR and EU GDPR:

  • Right of access (Art. 15) — ask us to confirm whether we process your personal data and, if so, send you a copy.
  • Right to rectification (Art. 16) — ask us to correct personal data that is inaccurate or incomplete.
  • Right to erasure (Art. 17) — ask us to delete your personal data when there is no good reason for us to continue processing it.
  • Right to restriction of processing (Art. 18) — ask us to pause processing in defined circumstances (e.g. while we investigate an accuracy challenge).
  • Right to data portability (Art. 20) — ask us to send you, or a third party of your choice, the personal data you have provided to us in a structured, commonly-used, machine-readable format. This right applies where the processing is based on consent or on the performance of a contract.
  • Right to object (Art. 21) — object to processing based on legitimate interests, including profiling, and to direct marketing at any time.
  • Right to withdraw consent (Art. 7(3)) — withdraw consent at any time where we rely on consent as the lawful basis (e.g. marketing). Withdrawing consent does not affect the lawfulness of processing before the withdrawal.
  • Rights related to automated decision-making (Art. 22) — Lua does not make solely automated decisions producing legal or similarly significant effects on data subjects. Outputs from agents built on Lua are always intermediated by our customer's product.

If you are an end-user of one of our customers' agents, please direct rights requests to the customer running that agent. We will assist that customer in responding to you, but the legal relationship sits with them.


9. How to exercise your rights

To make a request, email [email protected] with:

  • The right you want to exercise.
  • Enough information for us to identify you and find your data (typically the email address you use to log in or correspond with us).
  • For requests on behalf of another person, evidence of your authority to act for them.

We will respond within one calendar month of receiving a complete request, as required by the UK GDPR. If your request is complex or you make several requests, we may extend this by a further two months and will tell you within the first month if we need to do so. We will not charge a fee for a request unless it is manifestly unfounded, excessive, or repetitive; if we do, we will explain why before we proceed.

We may need to ask you to verify your identity before responding. This is to protect your data from being disclosed to someone else.


10. Your right to lodge a complaint

You have the right to complain to a data protection supervisory authority about how Lua handles your personal data.

  • United Kingdom — Information Commissioner's Office (ICO) Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF ico.org.uk | 0303 123 1113

  • European Economic Area — you may complain to the supervisory authority in the EU member state where you live, where you work, or where the alleged infringement took place. A list of national supervisory authorities is at edpb.europa.eu.

We would always appreciate the chance to address your concerns before you go to a regulator. Email [email protected] and we will respond on the same one-month clock as a rights request.


11. Cookies and similar tracking

On our marketing website (heylua.ai and its subdomains) and the Lua product console we use a small number of cookies and similar technologies. Strictly-necessary cookies (session, security, load-balancing) are set without a consent prompt because UK PECR and the EU ePrivacy Directive permit them. All other cookies — including analytics and any marketing cookies — are set only after you give consent through the cookie banner.

The cookie banner on heylua.ai is the operational front door for cookie consent. Alongside strictly-necessary cookies, the website uses PostHog product analytics, which records page views, click interactions, and device/browser information and stores identifiers in cookies and browser local storage to distinguish visitors. Consent-gated advertising and analytics tags delivered via Google Tag Manager likewise run only after opt-in. Analytics runs only with your opt-in, and you can change your preferences at any time via the "Cookie preferences" link on the site. You can also contact [email protected] with any request regarding analytics data.

Inside the authenticated Lua console we do not use cookies for analytics — product analytics inside the console use a hashed user identifier issued at sign-in (see section 4.4).


12. Google User Data and API Services

When you connect a Google account to a Lua agent, the agent accesses your Google data only through the Google services and permission scopes you authorize on Google's consent screen. Access is limited to the scopes you grant and is used solely to provide the features you have configured your agent to perform on your behalf.

Lua's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We do not use data obtained through Google Workspace APIs to develop, improve, or train generalized or non-personalized artificial intelligence and/or machine learning models. Google user data is not sold, and is not transferred to third parties except as necessary to provide or improve the user-facing features you have enabled, to comply with applicable law, or as part of a merger or acquisition.

You can revoke Lua's access to your Google data at any time by disconnecting the integration within the app or through your Google Account permissions.


13. Children

Lua's products are B2B. We do not knowingly market to or collect personal data from children under 13. If you believe we have inadvertently collected such data, please email [email protected] and we will delete it.

If one of our customers operates an agent aimed at children, the customer is the controller and is responsible for any age-appropriate-design obligations (UK ICO Age Appropriate Design Code, COPPA in the US, equivalents elsewhere). The DPA we sign with each customer requires the customer to comply with the law applicable to their data subjects.


14. Security

We take the security of personal data seriously. A public summary of our security practices is available on request. Headline points:

  • Encryption in transit and at rest for personal data across our systems.
  • Least-privilege access — role-based access controls, with MFA required for staff.
  • Centralized security monitoring across our production estate.
  • Independent assurance — independent security assurance documentation is available to customers under NDA.
  • Incident response — a documented incident-response policy and runbook with a 72-hour GDPR Art. 33 notification commitment to the ICO and a 24-hour customer-notification commitment in our DPAs.

If we discover a personal data breach that is likely to result in a risk to your rights and freedoms we will notify the relevant regulator within 72 hours of becoming aware of it, and we will notify you directly without undue delay if the breach is likely to result in a high risk to you.


15. Changes to this notice

We will update this notice when our processing changes, when new subprocessors are added, when retention windows shift, or when the law moves. Every change is version-tracked.

  • Material changes (new categories of data, new lawful basis, new sub-processors that handle your personal data, retention changes that extend the window) will be notified to you in advance by email where we hold your email, by a banner on the website, or in the product. Customers also receive notification via the channel set out in their contract.
  • Non-material changes (typos, clarifications, formatting) are made without notification but are version-tracked.

When we change this notice, the version and last-reviewed fields at the top of this document are updated and the change is recorded in the revision history below.


16. Effective date and revision history

Effective date of this version: 2026-07-22

VersionDateSummary
1.02026-05-18Initial version.
1.12026-07-22Cookie and analytics disclosure updated; UK and EU representative status updated.
1.22026-07-22Added section 12, "Google User Data and API Services"; later sections renumbered.
1.32026-07-22Single effective date; DPO contact updated to [email protected]; vendor and region detail consolidated into the Subprocessor List; cookie section updated for the live consent banner; transfer-safeguards availability and B2B data-source statements added; security section generalised.
1.42026-07-22Contact clarifications.
1.52026-08-11Article 27 UK & EU representatives appointed (GDPRLocal Ltd; Instant EU GDPR Representative Ltd) and named at section 2.