Privacy Policy
Last updated: March 1, 2026
1. Introduction
Lukian CORP SRL ("Lukian", "we") respects the confidentiality of your personal data. This Privacy Policy describes how we collect, use, store, and protect your information when you use the Lukian platform ("Service").
Please read this policy carefully. By using our Service, you confirm that you have read and understood the practices described herein.
2. Data We Collect
2.1. Data provided directly:
• Account information: name, email, phone, agency name.
• Property data: address, features, prices, photographs.
• Generated content: descriptions, social media posts, valuations.
• WhatsApp conversations: messages sent and received through AI bots.
• Payment information: processed by Stripe — we do not store card data.
2.2. Data collected automatically:
• IP address, browser type, operating system.
• Pages visited, actions taken on the platform.
• Cookies and similar technologies (see Cookie Policy).
• Performance data and technical errors.
3. How We Use Data
• Service provision — account management, properties, AI content generation, WhatsApp message processing.
• Service improvement — usage analysis, performance optimization, new feature development.
• Communication — account notifications, invoices, important updates, newsletter (with consent).
• Security — fraud detection, abuse prevention, protection against unauthorized access.
• Legal obligations — compliance with applicable legislation, response to legal requests.
4. AI Processing and Third-Party Providers
For AI features, your data (photos, texts, property data) is processed by third-party AI providers:
• Anthropic (Claude) — description generation, conversational assistant, analysis.
• OpenAI (GPT-4) — content generation, text processing.
• fal.ai — AI image editing and generation.
• Meta (WhatsApp Business API) — WhatsApp message sending and receiving.
These providers process data in accordance with their own privacy policies and do not use it for training their models. Data is transmitted encrypted (HTTPS/TLS).
5. Data Storage
Your data is stored on secure servers located in Romania and the European Union. We use encryption at rest and in transit, automatic daily backups, and restricted access based on the need-to-know principle.
Data is retained as long as your account is active. Upon account deletion, all personal data is removed within 30 days, except for data we are legally required to retain (e.g., invoices — 10 years).
6. Data Sharing
We do not sell your personal data. We share data only in the following situations:
• Service providers — payment processors, AI providers, hosting services (under data processing agreements).
• Legal obligations — when the law requires it or in the context of legal proceedings.
• With your consent — in all other situations, only with your explicit consent.
7. Your Rights
Under GDPR, you have the following rights:
• Right of access — you can request a copy of the personal data we hold about you.
• Right to rectification — you can correct inaccurate data.
• Right to erasure — you can request data deletion ("right to be forgotten").
• Right to portability — you can request your data in a structured format (JSON/CSV).
• Right to restriction — you can limit data processing in certain situations.
• Right to object — you can object to data processing for marketing purposes.
To exercise these rights, contact us at [email protected]. We will respond within 30 days.
8. Security
We implement appropriate technical and organizational measures to protect data:
• TLS/SSL encryption for all connections.
• Secure password hashing (bcrypt).
• JWT authentication with refresh tokens.
• Encrypted daily backups.
• 24/7 monitoring and alerting.
• Role and permission-based access restriction.
9. Changes
We reserve the right to update this Policy. Significant changes will be communicated by email at least 30 days before taking effect. The date of the last update is displayed at the top of this page.
10. Google User Data
Lukian offers two optional Google integrations: importing your Google Contacts into your Lukian CRM address book, and syncing your scheduled CRM activities with your Google Calendar. Each is used only if you explicitly connect your Google account from inside the CRM (Contacts → Connect Google, or Activities → Connect calendar), and each can be enabled independently.
What we access: two Google scopes, requested separately and only for the feature you enable.
• https://www.googleapis.com/auth/contacts.readonly — read-only access to your Google Contacts. We never request write access to your contacts and cannot modify or delete anything in your Google address book.
• https://www.googleapis.com/auth/calendar.events — access to the events in your primary Google Calendar, needed both to create the events that correspond to your CRM activities and to read your existing events as busy time.
What we read from Contacts: only the fields needed to create a CRM contact — first name, last name, email address, up to two phone numbers, company name and notes.
What we read from Calendar: the start and end time of events in your primary calendar, plus the event title for events we created ourselves. Your personal events are used only as busy intervals; their titles are shown only to you and are never visible to your colleagues in the shared team calendar. We do not read Gmail messages, Drive files, or any other Google data.
What we write to Calendar: only events that correspond to your own scheduled CRM activities (viewings, meetings, calls). Each event we create carries a private marker identifying it as ours, and we only ever update or delete events carrying that marker. We never modify or delete events you created yourself. We do not add guests and we do not send invitations or notifications to anyone — clients appear in the event description as text, never as invited attendees.
How we use it: imported contacts are stored in your own Lukian workspace so you can call, email and follow up from the CRM. Calendar events keep your phone's calendar in sync with your CRM schedule, and your existing appointments prevent you from being double-booked. Those are the only purposes.
How we store it: Google OAuth access and refresh tokens are encrypted at rest. Imported contacts and calendar data are visible only inside your own workspace.
AI processing: Lukian includes an AI assistant you can ask about your own CRM records. If you use it, contact details (such as a name, phone number or email) may be sent to our AI sub-processors, Anthropic and OpenAI, solely to produce the answer you asked for. They process the data under contract, on our behalf, and do not use it to train their models. Google Calendar data is not sent to them.
What we never do: we do not sell Google user data, we do not use it for advertising or ad personalization, and we do not transfer it to any third party other than the sub-processors that operate the service on our behalf, except where required by law or with your consent. We do not use it to train, develop or improve generalized AI or machine learning models. No human at Lukian reads this data, except where required for security, to comply with the law, or with your explicit consent.
How to revoke and delete: you can disconnect at any time from inside the CRM — Contacts → Disconnect for contacts, or Activities → Disconnect for the calendar. Disconnecting immediately deletes the stored tokens and the sync record; it does not delete events already created in your Google Calendar, which you can remove yourself. You can also revoke access at any time at https://myaccount.google.com/permissions. Imported contacts can be deleted from the CRM like any other contact.
Lukian's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
11. Contact
For any questions regarding data privacy:
Email: [email protected]
DPO: [email protected]
Lukian CORP SRL
CUI 45484296 | J2022000113139
Aleea Murelor nr.10A, Sp. Com.1, Constanța, România
If you are not satisfied with how we handle your data, you have the right to file a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP) — www.dataprotection.ro.