The short version
Your data stays yours
You own your business data and your customers' data. We hold it to run your automations, and we delete it when you ask.
We never train models on it
Your conversations are never used to train third-party AI models. They are sent to our AI providers only to generate a reply inside your own automation.
We sell nothing
We do not sell, rent, or trade personal data. We share it only with the named sub-processors that make the service work.
Ask and we act
Access, correction, export, deletion, or withdrawal of consent - write to our Grievance Officer and we respond within 30 days.
This summary is for readability only. The full terms below are what legally apply.
Lumoscale is a UDYAM-registered MSME building AI automation systems that talk to your customers on your behalf. That means we handle conversations, contact details, and business records that matter - and we treat that responsibility seriously.
This Policy sets out exactly what we collect, why, who else touches it, how long we keep it, and what you can demand of us. No hidden clauses, no data sales, no model training on your conversations.
Lumoscale ("Lumoscale", "we", "us", or "our") is a UDYAM-registered Micro, Small and Medium Enterprise (MSME) operating under the Micro, Small and Medium Enterprises Development Act, 2006, based in Bengaluru, Karnataka, India.
We design, build, and operate done-for-you AI automation systems - AI voice agents and call handling, messaging and DM automation, and back-office workflow automation - for businesses across industries and geographies.
This Privacy Policy explains what information we collect, why we collect it, who we share it with, how long we keep it, and the rights you can exercise over it. It applies to www.lumoscale.com and to every automation, dashboard, and support channel we operate for our clients.
Depending on whose data is involved, Lumoscale acts in one of two distinct capacities. This distinction determines who is accountable for what.
Where we act as a Processor, you remain the Data Fiduciary. You are responsible for having a lawful basis and valid notice or consent for the data you route through our systems, and your end-customers should refer to your privacy policy. Our handling of that data is governed by the service agreement or Data Processing Addendum between us.
We collect only what is necessary to build, run, and support your automations.
We do not intentionally collect special or sensitive categories of personal data (such as health, financial account, biometric, or government-ID information) unless your automation is expressly configured to capture it, in which case you must ensure you have the legal right to do so and must tell us in advance so we can apply appropriate safeguards.
We use the information described above to:
We do not use your data, or your end-customers' data, to train third-party AI models. Content sent to our AI providers is used solely to generate a response within your automation in that moment. We do not sell, rent, or trade personal data to anyone, for any purpose.
We process personal data on the following grounds:
Where we act as a Processor for your end-customers' data, the legal basis is established and maintained by you as the Data Fiduciary.
Transparency about AI is central to how we build. Where an automation communicates directly with your customers:
To deliver the service we rely on a small set of trusted providers who process data on our instructions as sub-processors. We share only the minimum data each one needs.
Each provider operates under its own privacy policy and security programme, and we require contractual commitments to confidentiality and appropriate safeguards. We may update this list as our stack evolves; material changes are notified under Section 14. A current list of sub-processors is available on request.
No system is perfectly secure. We maintain reasonable, industry-standard safeguards appropriate to our size and the sensitivity of the data, and we continue to strengthen them as we grow. If a personal data breach affects you, we will notify you and the relevant authority without undue delay, in accordance with the Digital Personal Data Protection Act, 2023 and CERT-In directions.
We keep personal data only as long as it serves a purpose:
Under the Digital Personal Data Protection Act, 2023 and other applicable data protection laws, you have the right to:
To exercise any right, email contact@lumoscale.com. We verify identity before acting and respond within 30 days. If you are an end-customer of one of our clients, please direct your request to that business - we will forward it to them and assist them in responding.
Our automations are built to handle communication, qualification, and booking in a compliant manner across the industries we serve.
Our services are built for businesses and are not directed at individuals under 18. We do not knowingly collect personal data from children. If you believe a child's data has reached us through one of our systems, contact us and we will delete it promptly. Where your automation may interact with minors, you are responsible for obtaining verifiable parental consent as required by law.
We may update this Privacy Policy as our services, providers, or legal obligations change. The "Last updated" date at the top always reflects the current version. For material changes we will give you reasonable advance notice by email or through your dashboard before they take effect. Continued use of our services after the effective date means you accept the updated Policy.
For questions about this Policy, to exercise your rights, or to raise a grievance under the Digital Personal Data Protection Act, 2023, contact our Grievance Officer:
If your grievance is not resolved to your satisfaction, you may escalate it to the Data Protection Board of India.