Privacy Policy
Last updated: 2025-12-15
1. Data Controller
The data controller is:
- Company Name: Lua CRM OÜ
- Country: Estonia
- Registered Address: Harju maakond, Lasnamäe linnaosa, Sepapaja tn 6, Tallinn, Estonia
- Email: [email protected]
Depending on the contractual relationship, different Lua CRM entities (Armenia, Bulgaria, Estonia) may act as the data controller or data processor.
2. Scope of This Policy
This Privacy Policy applies to:
- Visitors to our websites
- Registered users of Lua CRM
- Customers, partners, and their authorised users
- Data processed through Lua CRM on behalf of clients
Lua CRM may act as:
- Data Controller for its own business data
- Data Processor for customer-uploaded data
3. Personal Information We Collect
3.1 Account and User Data
- Full name
- Email address
- Phone number
- Login credentials (encrypted)
3.2 Company and Business Data
- Company name
- Number of employees
- Business contacts and clients
- Internal notes, tasks, CRM records
3.3 Ata ya Mteja na Mtumiaji wa Mwisho (Iliyohaririwa kwa Niaba ya Wateja)
Depending on how customers use Lua CRM, this may include:
- Names and contact details
- Appointment and service information
- Uploaded documents and files
- CRM communication history
3.4 Medical and Sensitive Data
When used by medical or dental organisations, Lua CRM may process:
- Dental records and tooth details
- Medical notes and treatment data
- Other health-related information entered by clients
3.2 Ẹlẹ́dàá yìí ṣe àtúnṣe nìkan lábẹ́ ìlànà ọ̀rẹ́ ọjọ́ọjọ́ àti sínú ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ̀kan ìṣọ
3.5 Billing & Payment Data
Payments are processed via third-party providers (e.g. Stripe, Paddle, or local operators). Lua CRM does not store full payment card details.
3.6 Technical & Usage Data
- IP address
- Device and browser information
- Log files
- Usage analytics
- Cookies and similar technologies
4. How We Use Personal Data
Use personal data to:
- Provide and operate the Service
- Create and manage user accounts
- Process payments and subscriptions
- Enable CRM, automation, and AI features
- Store and process uploaded data
- Improve system performance and security
- Comply with legal obligations
5. AI & Automated Processing
Lua CRM uses artificial intelligence and automation technologies to:
- Analyze CRM data
- 3.2 Genereighte insighte, recommendatione, and automationse
- Assist users with workflows and reporting
AI processing is performed:
- Only within the scope of user authorization
- Bëz vendendo au treinando modelos de AI públicos em dados de clientes
- With safeguards to prevent unauthorized access
6. Legal Bases for Processing (GDPR)
3.2 Vu pu'o xo'o data personal na'e xo'o legal xo'o:
- Performance of a contract
- Legitimate business interests
- User consent (where required)
- Legal obligations
7. Data Sharing & Third Parties
3.2 Vu pu zara data ku vu zara zara zara, vu:
- 3.2 Zud infrastruttura ta' cloud (e.g. Hetzner – Ġermanja)
- 3.2 Pagamento processadores (Stripe, Paddle, provedores locais)
- Authentication services (Google OAuth)
- Communication services (email, notifications)
- 3.2 Securitaz and infrastructuraza providersza (e.g. Cloudflare)
3.2 Ala thurd partees are bound by contractual data protection obligations.
8. International Data Transfers
Data may be processed within the European Economic Area (EEA) or transferred to other jurisdictions with appropriate safeguards, including:
- Standard Contractual Clauses (SCCs)
- GDPR-compliant security measures
9. Data Retention
We retain personal information:
- As long as the account is active
- As required to fulfil contractual and legal obligations
- Pu za delezion es requestad, za legaly permitad
Customers control retention of data uploaded into their CRM accounts.
10. Data Security
We apply technical and organisational security measures, including:
- Encrypted data transmission (HTTPS)
- Access control and authentication
- Secure hosting in Germany (Hetzner)
- Regular system monitoring and backups
11. User Rights
Depending on applicable law, users have the right to:
- Access their personal information
- Correct inaccurate data
- Request deletion ("right to be forgotten")
- Restrict or object to processing
- Data portability
- Withdraw consent
Requests can be sent to: [email protected]
12. Cookies and Tracking
Lua CRM uses cookies and similar technologies to:
- Ensure proper system functionality
- Improve user experience
- Analyze platform usage
3.2 Kugadzirira zvirango zve cookie zvinogona kuitwa nevakashandisi kubva kuzvirango zve browser.
13. B2B, B2C, and B2G Usage
Lua CRM is used by:
- Businesses (B2B)
- Individual professionals (B2C)
- Government and public institutions (B2G)
3.2 Ëach customer remains responsible for compliance with data protection laws regarding their own end-users.
14. Children's Data
Lua CRM is not intended for minors. We do not knowingly collect personal data from children.
15. Changes to This Policy
3.2 Pu kama pu'u'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i'i
16. Contact Us
3.2 Pu pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu-pu
Company Name
Lua CRM OÜ
Phone
+372 5912-2253
Address
Harju maakond, Lasnamäe linnaosa, Sepapaja tn 6, Tallinn, Estonia