0%
Legal

Privacy Policy

Effective Date: May 16, 2026 | Last Updated: May 16, 2026

LumiFin SAS — 50 rue Anatole France, 92290 Châtenay-Malabry, France

https://lumifin.io

1. Data Controller

LumiFin SAS ("Lumi", "we", "us") is the data controller for processing described in this Privacy Policy. Address: 50 rue Anatole France, 92290 Châtenay-Malabry, France. Email: privacy@lumifin.io.

Our Payment Partner, Trans-Fi Inc. ("Transfi"), is an independent data controller for personal data it processes to provide Payment Services (custody, FX, settlement, compliance). Transfi's privacy policy is available at https://www.transfi.com/privacy-policy.

2. Data We Collect

2.1 Data you provide

  • Account registration: full name, email address, phone number, date of birth, nationality, residential address.
  • Identity verification (KYC): government-issued identity document (passport, national ID, or driving license), selfie or liveness check image.
  • Financial information: IBAN of your SEPA bank account.

2.2 Data generated through use

  • Transaction data: amounts, dates, currencies, merchant identifiers, exchange rates, wallet balance history.
  • Technical data: device model, operating system version, app version, IP address, device identifiers, push notification tokens.
  • Usage data: screens viewed, features used, session duration (collected via Firebase Analytics).

2.3 Data from third parties

Identity verification results from our KYC provider; payment confirmation data from Transfi; Open Banking account information from our payment initiation provider (limited to IBAN verification).

3. Purposes and Legal Bases

We process your personal data for the following purposes and legal bases under Article 6 GDPR:

  • Contract performance (Art. 6(1)(b)): creating and managing your Account; processing transactions; displaying balance and history; communicating about your Account and transactions; providing customer support.
  • Legal obligations (Art. 6(1)(c)): identity verification and KYC/AML compliance (French Monetary and Financial Code, Art. L561-12); responding to lawful requests from authorities; maintaining records as required by law.
  • Legitimate interests (Art. 6(1)(f)): preventing fraud and securing the App; improving our services and user experience; analytics and crash reporting (via Firebase Analytics and Firebase Crashlytics); enforcing our Terms and Conditions.
  • Consent (Art. 6(1)(a)): marketing communications (you can withdraw consent at any time); optional co-marketing communications from Lumi and Transfi (opt-in only).

4. Data Sharing

We share personal data only when necessary and with appropriate safeguards:

  • Payment Partner (Transfi): We share your identity, financial, and transaction data with Transfi so they can provide Payment Services. Transfi processes this data as an independent controller under its own privacy policy and legal bases.
  • Service providers: We use third-party processors for identity verification, analytics (Firebase), crash reporting (Firebase Crashlytics), cloud hosting, Open Banking payment initiation, and customer support tools. These processors act on our instructions under Data Processing Agreements (DPAs) that include GDPR-compliant safeguards.
  • Legal requirements: We may disclose data to authorities when required by law, regulation, or court order.

We do not sell your personal data. We do not use your data for automated decision-making or profiling that produces legal effects.

5. International Transfers

Some of our service providers and Transfi operate outside the EU/EEA. When personal data is transferred internationally, we ensure adequate protection through: EU adequacy decisions (where applicable); Standard Contractual Clauses (SCCs) approved by the European Commission; the EU-US Data Privacy Framework (for US-based processors certified under the DPF).

You may request a copy of the relevant transfer safeguards by contacting privacy@lumifin.io.

6. Data Retention

We retain your data only as long as necessary for the purposes described:

  • Account data: retained while your Account is active plus 30 days after closure to handle disputes.
  • Identity documents (KYC): 5 years from end of relationship, as required by French AML law (Art. L561-12 CMF).
  • Transaction records: 5 to 10 years depending on applicable legal retention requirements (tax, AML, accounting).
  • Security logs: up to 24 months for fraud prevention and incident investigation.
  • Analytics data: 14 months (Firebase Analytics default retention).
  • Marketing suppression list: retained indefinitely to honour your opt-out.

After the applicable retention period, data is securely deleted or anonymized.

7. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

Right of access (Art. 15): obtain a copy of your data. Right to rectification (Art. 16): correct inaccurate data. Right to erasure (Art. 17): request deletion (subject to legal retention obligations). Right to restriction (Art. 18): limit processing in certain circumstances. Right to data portability (Art. 20): receive your data in a machine-readable format. Right to object (Art. 21): object to processing based on legitimate interests. Right to withdraw consent (Art. 7(3)): withdraw consent at any time without affecting prior processing.

To exercise your rights, email privacy@lumifin.io with your full name and the right you wish to exercise. We will respond within 30 days (extendable by 60 days for complex requests, with notice). We may ask for identity verification before fulfilling your request.

For data held by Transfi as independent controller, please also contact Transfi directly at privacy@transfi.com.

If you are unsatisfied with our response, you may lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés) at https://www.cnil.fr or with your local supervisory authority.

8. Security

We implement appropriate technical and organizational measures to protect your data, including: encryption in transit (TLS 1.2+) and at rest; access controls and least-privilege principles; secure authentication (mPIN, biometrics); regular security assessments; incident response procedures.

No system is perfectly secure. If a data breach occurs that poses a high risk to your rights, we will notify you and the relevant supervisory authority as required by Articles 33-34 GDPR.

9. Children

The App is not intended for individuals under 18. We do not knowingly collect data from minors. If we discover that a minor has created an Account, we will close it and delete the data promptly.

10. Cookies and Tracking

The Lumi App does not use cookies (it is a mobile application). We use Firebase Analytics and Firebase Crashlytics SDKs for usage analytics and crash reporting. You can opt out of analytics collection in the App settings. Our website (lumifin.io) uses only strictly necessary cookies that do not require consent.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified via the App or email at least 30 days before they take effect. The "Last Updated" date at the top indicates the current version. Continued use of the App after the effective date constitutes acceptance of the updated policy.

12. Contact

For any privacy-related questions or to exercise your rights:

LumiFin SAS — 50 rue Anatole France, 92290 Châtenay-Malabry, France

Email: privacy@lumifin.io | Website: https://lumifin.io

— End of Privacy Policy —