Privacy Policy
Version 1.1, in effect from 2026-09-03.
This policy covers the website and the customer portal. It does not cover the SDK, and the reason is the most important sentence on the page: the engine makes no network calls. It does not check a licence server, report usage, or send anything anywhere. Nothing your software does with LumasPDF is visible to us.
What we hold
Only what an account and an order require.
- Account
- Your email address, your name if you give one, a password hash, and the organisation your account belongs to.
- Security
- Sign-in attempts, active sessions and the address they came from. Kept so that "someone else is signing in as me" is an answerable question.
- Orders
- Billing details, VAT identifier, the items bought and the invoices raised.
- Licences
- The keys minted for you and what each one covers. A key carries a customer reference and no personal data beyond the name you chose to put on the licence.
- Downloads
- Which package was downloaded, when, and by which account. This is what makes an entitlement auditable.
- Support
- The tickets and bug reports you file, including anything you attach to them.
- Consent
- Which version of which document you accepted, and when.
Why we hold it
Account, licence, download and order records exist to perform the contract you entered into. Invoices are kept because tax law requires them. Security records exist on the basis of our legitimate interest in keeping accounts from being taken over, which is also your interest.
We do not profile you, we do not sell anything to anyone, and we do not run third-party analytics or advertising scripts on this site.
Cookies
Two, both strictly necessary. One identifies your session so you stay signed in; one carries the token that stops another site from submitting forms as you. If you tick "remember me" there is a third, holding a token that is replaced every time it is used.
There is no analytics cookie and no advertising cookie, so there is no consent banner -- because there is nothing to consent to.
How long we keep it
Account data for as long as the account exists. Invoices and the licence record for the statutory retention period, which is longer than the account may live.
When you ask us to delete your account we erase the personal fields and keep the commercial record with those fields pseudonymised, because we are required to be able to show what was sold. The portal shows you exactly which records are retained, and why, before you confirm.
What you can ask for
Access to what we hold, a machine-readable export of it, correction of anything wrong, deletion subject to the retention above, and a copy of your consent history. All of it is in the portal under Privacy, and none of it requires a support ticket.
Processors
Payment processing is handled by Razorpay (card, UPI, net banking and wallet payments) and by PayPal. Each receives what taking the payment requires -- the amount, the currency, the order reference and whatever you enter on their own page -- and processes it under its own privacy policy. Card and bank details never reach this site.
Outbound email is sent through a transactional email provider on our instructions only. The current list of processors is maintained in the data processing addendum, which is versioned in the same way as this page so a change to it is visible rather than silent.
Staff access
Support staff can open your portal as you when a problem cannot be diagnosed otherwise. That session is time-boxed, recorded in the audit log, and shown to you. There is no silent impersonation.
Who is responsible, and how to reach us
The operating entity named on the Contact page and in the imprint is responsible for the data described here. Questions and requests about it go to support@lumaspdf.com, or to a ticket from the portal. Every request listed under "What you can ask for" can also be made from the portal without writing to anyone.
Operator
Lumas Softech
705, Alif Apartment
Sarkhej-Makraba Road, Sarkhej
Ahmedabad 382210, Gujarat
India
support@lumaspdf.com
· Contact page
Versions
Acceptance is recorded against a version number, so every version stays readable at its own address for as long as the record does.