Global Commitment to Privacy
Lucisun is committed to protecting your personal data. We comply with applicable privacy laws and regulations, with a particular focus on the EU General Data Protection Regulation (GDPR) as our standard for data privacy. We may update this Privacy & Data Protection Policy from time to time to reflect changes in our practices or legal requirements. Any updates will be posted on this page (and we will notify you through appropriate channels when required). This policy is effective from November 12, 2025.
Introduction
Ludata is a web-based software-as-a-service (SaaS) platform provided by Lucisun. This Privacy Policy explains what information we collect through the Ludata application, how we use and protect that information, and what rights you have regarding your personal data. It applies when you access the Ludata web application (and any related interfaces such as APIs or data dashboards associated with Ludata). Protecting your privacy and personal information is one of our top priorities. If you have any questions about this Policy or how Lucisun handles your data, please contact us using the details in the Contact Us section below.
Consent and Scope
By registering for or using the Ludata platform, you agree to this Privacy & Data Protection Policy and consent to the collection, use, and processing of your information as described herein. This Policy applies to all users of the Ludata web application and related services, whether you use the service as an individual or on behalf of an organization. It covers personal data collected through your use of Ludata. This Policy does not cover offline interactions you may have with Lucisun outside of the Ludata platform; such activities may be subject to separate privacy notices.
Types of Data We Collect
When you use Ludata, we collect several types of data to provide and improve our services. We only collect data that is necessary for the purposes described in this Policy:
- Account Information: When you register an account on Ludata, we collect personal identifiers such as your name and email address. If you create an account on behalf of a business or organization, we may also collect your company/organization name and related billing details (e.g., VAT number). You will also create login credentials (such as a password) to secure your account.
- Contact and Profile Details: You may choose to provide additional contact information or profile details (e.g., phone number, job title). Providing this information is optional, but it can help us communicate with you and personalize your experience.
- Site & Geolocation Data: Ludata is designed to work with solar energy site data. You may input geographic information (latitude/longitude or address) of a site, upload measurement datasets, or enter PV system parameters. This site and geolocation data is stored within your account to enable analysis. While this data typically does not identify an individual, we treat it as part of your account data and protect it accordingly.
- Usage Logs and Technical Data: Our systems automatically record certain technical information when you use Ludata (e.g., IP address, browser/OS, device type, referring pages, timestamps, actions taken). We may also collect general location information inferred from your IP (such as city/country). These usage logs help us troubleshoot, secure the platform, and understand how users interact with Ludata.
- Cookies and Session Data: We use cookies and similar technologies to keep you logged in and to remember preferences (see Cookies and Analytics below). Aside from authentication/session cookies, our analytics tooling does not use cookies.
- Communications: If you contact Lucisun for support or feedback regarding Ludata, we collect the information you provide (e.g., name, contact details, and message content) to respond and resolve issues.
We do not collect special categories of personal data via Ludata and the platform is not intended for children (see Children’s Privacy).
Legal Basis for Processing
Under the GDPR (where it applies), Lucisun must have a valid legal basis to process your personal data. Depending on the context, we rely on one or more of the following bases:
- Performance of a Contract: To provide the Ludata services you requested (account creation, authentication, delivering platform functionality).
- Legitimate Interests: For platform security, troubleshooting, usage analytics (privacy-friendly), and product improvement—carefully balanced against your rights.
- Consent: Where required (e.g., for optional marketing unrelated to core service). You may withdraw consent at any time.
- Legal Obligation: To comply with financial/tax or regulatory requirements and lawful requests from authorities.
How We Use Your Data
We use the information collected through Ludata for the following purposes:
- Provide and Operate the Service: Create/manage accounts, authenticate logins, and deliver core Ludata functionality (analyses, simulations, reports).
- Communicate with You: Send essential, transactional emails (account activation, verification, password resets, service notices) via Brevo; respond to support requests.
- Improve and Customize: Analyze de-identified usage to troubleshoot, optimize UX, and develop new features; use anonymized/aggregated insights to enhance algorithms.
- Ensure Security: Monitor logs and technical signals to detect fraud/misuse and protect accounts and systems.
- Legal & Compliance: Enforce terms, comply with laws, retain required records.
- Optional Marketing: Only with your prior consent; you can opt out anytime. Service-critical emails will still be sent.
Third-Party Service Providers (Data Processors)
To operate Ludata efficiently, Lucisun relies on a few trusted service providers. They act as data processors and are bound by strict contractual obligations:
- Hetzner (Hosting & Databases): Ludata’s application servers and primary databases are hosted on Hetzner’s secure EU infrastructure. All Ludata data (account, site, logs) resides in Europe.
- DigitalOcean (Supplementary Storage/Infra): Additional storage/backups run on DigitalOcean with data located in EU regions. We have a DPA and Standard Contractual Clauses (SCCs) in place.
- Brevo (Email): Transactional/operational emails are sent via Brevo (France/EU). We share only what’s necessary (name, email, message content) for delivery; Brevo processes it solely under our instructions.
- Umami (Analytics Software): Self‑hosted by Lucisun in the EU; no external analytics provider receives user data.
We do not share your personal data with third parties for their own marketing. Other disclosures occur only when required by law, to our confidential advisors, or in a business transfer, in which case the commitments of this Policy will continue.
International Data Transfers
Lucisun aims to store and process Ludata data within the EU. Where international aspects arise (e.g., providers with non‑EU headquarters or remote access for support), we implement safeguards such as EU Standard Contractual Clauses, encryption, and data‑minimization to ensure GDPR‑level protection.
Data Retention
- Account Data: Retained while your account is active; deleted or anonymized upon account deletion.
- Site/Measurement Data: Retained for your use; deletions remove data from active systems (with limited backup retention).
- Transaction/Billing Records (if applicable): Retained for legally required periods (e.g., commonly 7 years).
- Support Communications: Kept for a reasonable period to track service history, unless you request deletion and no overriding need exists.
- Analytics Logs: Kept in aggregate/de‑identified form; raw logs with IPs are rotated and purged on short cycles.
- Backups: Encrypted and retained on rolling cycles (e.g., ~30–60 days). Deleted data in backups is isolated until backups expire.
Your Rights Under GDPR
Depending on your jurisdiction, you may have rights including: access, rectification, erasure, restriction, objection, data portability, consent withdrawal, and the right to lodge a complaint with a supervisory authority. We will verify identity where required and respond within statutory timelines.
Children’s Privacy
Ludata is intended for adult professional use and is not directed to children under 16. We do not knowingly collect data from children. If we learn that a minor has provided personal data, we will delete it and terminate the account. Jurisdiction‑specific age thresholds (e.g., 13) are respected.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy & Data Protection Policy or the handling of your personal data, please reach out:
- Data Controller: Lucisun — Rue Saint‑Jean 29, 1495 Villers‑la‑Ville, Belgium.
- Email: info@lucisun.com
- Contact Form: You may also contact us via the Lucisun website or any in‑app support interface, indicating your request relates to “Ludata Privacy”.
Updated on: 12/11/2025