1. Parties and scope
This Data Processing Addendum (“DPA”) is between the customer that uses Lumen DocAI (“Customer”) and Lumenus LLC, doing business as “Lumen DocAI” (“Lumen DocAI”, “we” or “us”). It forms part of our Terms of Service (the “Agreement”) and applies whenever we process Customer Personal Data in providing the service.
“Customer Personal Data” means personal data contained in documents Customer submits to the service, and in the data extracted from those documents, corrected or approved by Customer, or drafted from them (such as requests to Customer's counterparties).
For Customer Personal Data, Customer is the controller (or business) and Lumen DocAI is the processor (or service provider). This DPA does not cover account, billing or website data, for which Lumen DocAI is the controller; that data is covered by our Privacy Policy.
“Data Protection Laws” means all privacy and data protection laws that apply to the processing of Customer Personal Data under the Agreement, which may include the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), Canada's PIPEDA and Quebec's Law 25. If this DPA conflicts with the Agreement on the processing of Customer Personal Data, this DPA controls.
2. Details of the processing
| Subject matter | Providing the Lumen DocAI document extraction service to Customer under the Agreement. |
|---|---|
| Duration | For the term of the Agreement, and afterwards until the Customer Personal Data is deleted or returned as described in section 11. |
| Nature of processing | Receiving documents (PDF, JPG, PNG) by upload, email to a private document address, or API; reading text from them; sending that text to an AI model provider to extract fields and to verify them in a second, independent pass; storing the documents and results; making them available for review, correction and approval; exporting them (CSV or Excel); sending them to QuickBooks Online where Customer connects it; delivering them through the API and webhooks; and drafting requests to Customer's counterparties, which are sent only when a person at Customer approves that specific email. |
| Purpose | To provide, secure and support the service for Customer, as instructed by Customer. |
| Categories of data subjects | People named in Customer's documents, which may include Customer's employees and teammates; suppliers, vendors, carriers and other counterparties and their contacts; insureds, applicants and other people named in insurance submissions; taxpayers named in tax forms; and workers, candidates and contractors named in staffing paperwork. |
| Categories of personal data | Whatever appears in the documents Customer submits, which may include names; contact details such as email addresses, phone numbers and postal addresses; taxpayer identification numbers, including Social Security numbers; bank account details; and employment, insurance, invoice and shipment details relating to individuals. |
| Sensitive data | Taxpayer IDs, Social Security numbers and bank account details may be included. Customer decides what documents to submit and is responsible for ensuring it may lawfully submit any sensitive or special category data. |
3. Customer responsibilities
Customer is responsible for having a lawful basis to collect and submit Customer Personal Data, for giving any notices and obtaining any consents Data Protection Laws require, for the lawfulness of its instructions, and for reviewing extracted data and approving any outbound email before it is sent.
4. Processing on documented instructions
We will process Customer Personal Data only on Customer's documented instructions, unless the law requires otherwise, in which case we will tell Customer before processing unless the law prohibits that. The Agreement, this DPA, and Customer's use and configuration of the service (for example, uploading documents, approving data, connecting integrations and approving emails) are Customer's complete instructions. We will tell Customer if we believe an instruction breaks Data Protection Laws.
We do not use Customer Personal Data or Customer documents to train AI models.
5. US state law service provider terms
Where the CCPA/CPRA or similar US state laws apply, Lumen DocAI will not:
- sell or share Customer Personal Data;
- retain, use or disclose Customer Personal Data for any purpose other than providing the service under the Agreement, or outside our direct business relationship with Customer, except as those laws permit;
- combine Customer Personal Data with personal data we receive from or on behalf of anyone else, except as those laws permit.
We will comply with the obligations that apply to service providers under those laws and will tell Customer if we can no longer meet them.
6. Confidentiality of personnel
We will make sure that anyone we authorize to process Customer Personal Data is bound by appropriate confidentiality obligations and has access only as needed to provide, secure and support the service.
7. Security measures
We maintain technical and organizational measures designed to protect Customer Personal Data, including:
- HTTPS/TLS encryption in transit for the website, app, API and webhooks;
- isolation of each company's data, enforced on every request;
- role-based access within each account (admins and operators);
- encryption in the database of integration tokens and webhook signing secrets;
- API keys stored only as hashes and shown only once, when created;
- HMAC-signed webhooks;
- an audit log recording exports, approvals, API key and integration changes, and staff changes to account access.
We may update these measures over time, provided the overall level of protection is not reduced.
8. Subprocessors
Customer authorizes us to use the subprocessors below. We will require each subprocessor to protect Customer Personal Data under written terms that provide substantially the same protections as this DPA, as appropriate to the service it provides, and we remain responsible for our subprocessors' performance of those obligations.
| Subprocessor | Purpose |
|---|---|
| DigitalOcean | Hosting and database |
| Anthropic | AI processing of document text through its commercial API (Anthropic does not use data sent through its commercial API to train its models by default) |
| Amazon Web Services SES, or an SMTP email provider | Sending outbound email, including approved requests to counterparties |
| Resend | Receiving email sent to document addresses |
| Stripe | Payments for Customer's subscription |
| Intuit QuickBooks | Receiving data Customer chooses to send, only when Customer connects QuickBooks Online |
We will announce changes to our subprocessors by updating this page and its “last updated” date. If Customer has a reasonable data protection objection to a new subprocessor, it can tell us at hello@lumenglobalsourcing.com, and we will discuss the objection in good faith. If we cannot resolve it, Customer may cancel the affected service as described in the Agreement.
9. Assistance
- Data subject requests. Taking into account the nature of the processing, we will help Customer, by appropriate technical and organizational measures where possible, to respond to requests from individuals exercising their rights under Data Protection Laws. If we receive such a request directly about Customer Personal Data, we will pass it to Customer and will not respond ourselves except to direct the individual to Customer, unless the law requires otherwise.
- Security and compliance. Taking into account the nature of the processing and the information available to us, we will provide reasonable help to Customer in meeting its obligations on security of processing, breach notification, data protection impact assessments and consultations with supervisory authorities.
10. Personal data breaches
We will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. We will provide the information reasonably available to us to help Customer understand the breach and meet any obligations it has to notify authorities or affected individuals, and we will take reasonable steps to contain and address it. Notifying Customer is not an admission of fault or liability.
11. Deletion or return
At the end of the service, or earlier on request, we will delete or return Customer Personal Data at Customer's choice. Customer can export its data (CSV or Excel) while the account is available and can request deletion by emailing hello@lumenglobalsourcing.com. We may keep Customer Personal Data where the law requires it, in which case this DPA continues to protect it for as long as we keep it.
12. Audits and information
We will make available the information reasonably necessary to demonstrate our compliance with this DPA in response to Customer's reasonable written information requests sent to hello@lumenglobalsourcing.com. Customer will keep the information we provide confidential. Where Data Protection Laws require more than written information, the parties will agree in good faith on the scope, timing and conditions of any further audit, so that it does not compromise the security or confidentiality of other customers' data.
13. International transfers
We and our subprocessors may process Customer Personal Data outside the country where it was collected, including in the United States. Where required by Data Protection Laws, the parties will rely on appropriate safeguards such as the EU Standard Contractual Clauses (and, for the UK, the UK addendum to them) for transfers of Customer Personal Data.
14. Liability and term
Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement, to the extent Data Protection Laws allow. This DPA stays in effect for as long as we process Customer Personal Data.
15. Getting a signed copy
This DPA applies automatically when Customer uses the service. If Customer would like a countersigned copy for its records, email hello@lumenglobalsourcing.com with the Customer's legal name, address and the name and title of the person signing.
16. Contact
- Lumenus LLC, doing business as Lumen DocAI
- [Registered address to be added]
- hello@lumenglobalsourcing.com