Privacy Policy

Last updated: March 1, 2026

1. Introduction

Lukian CORP SRL ("Lukian", "we") respects the confidentiality of your personal data. This Privacy Policy describes how we collect, use, store, and protect your information when you use the Lukian platform ("Service").

Please read this policy carefully. By using our Service, you confirm that you have read and understood the practices described herein.

2. Data We Collect

2.1. Data provided directly:

• Account information: name, email, phone, agency name.

• Property data: address, features, prices, photographs.

• Generated content: descriptions, social media posts, valuations.

• WhatsApp conversations: messages sent and received through AI bots.

• Payment information: processed by Stripe — we do not store card data.

2.2. Data collected automatically:

• IP address, browser type, operating system.

• Pages visited, actions taken on the platform.

• Cookies and similar technologies (see Cookie Policy).

• Performance data and technical errors.

3. How We Use Data

• Service provision — account management, properties, AI content generation, WhatsApp message processing.

• Service improvement — usage analysis, performance optimization, new feature development.

• Communication — account notifications, invoices, important updates, newsletter (with consent).

• Security — fraud detection, abuse prevention, protection against unauthorized access.

• Legal obligations — compliance with applicable legislation, response to legal requests.

4. AI Processing and Third-Party Providers

For AI features, your data (photos, texts, property data) is processed by third-party AI providers:

• Anthropic (Claude) — description generation, conversational assistant, analysis.

• OpenAI (GPT-4) — content generation, text processing.

• fal.ai — AI image editing and generation.

• Meta (WhatsApp Business API) — WhatsApp message sending and receiving.

These providers process data in accordance with their own privacy policies and do not use it for training their models. Data is transmitted encrypted (HTTPS/TLS).

5. Data Storage

Your data is stored on secure servers located in Romania and the European Union. We use encryption at rest and in transit, automatic daily backups, and restricted access based on the need-to-know principle.

Data is retained as long as your account is active. Upon account deletion, all personal data is removed within 30 days, except for data we are legally required to retain (e.g., invoices — 10 years).

6. Data Sharing

We do not sell your personal data. We share data only in the following situations:

• Service providers — payment processors, AI providers, hosting services (under data processing agreements).

• Legal obligations — when the law requires it or in the context of legal proceedings.

• With your consent — in all other situations, only with your explicit consent.

7. Your Rights

Under GDPR, you have the following rights:

• Right of access — you can request a copy of the personal data we hold about you.

• Right to rectification — you can correct inaccurate data.

• Right to erasure — you can request data deletion ("right to be forgotten").

• Right to portability — you can request your data in a structured format (JSON/CSV).

• Right to restriction — you can limit data processing in certain situations.

• Right to object — you can object to data processing for marketing purposes.

To exercise these rights, contact us at privacy@lukian.ai. We will respond within 30 days.

8. Security

We implement appropriate technical and organizational measures to protect data:

• TLS/SSL encryption for all connections.

• Secure password hashing (bcrypt).

• JWT authentication with refresh tokens.

• Encrypted daily backups.

• 24/7 monitoring and alerting.

• Role and permission-based access restriction.

9. Changes

We reserve the right to update this Policy. Significant changes will be communicated by email at least 30 days before taking effect. The date of the last update is displayed at the top of this page.

10. Contact

For any questions regarding data privacy:

Email: privacy@lukian.ai

DPO: dpo@lukian.ai

Lukian CORP SRL

CUI 45484296 | J2022000113139

Aleea Murelor nr.10A, Sp. Com.1, Constanța, România

If you are not satisfied with how we handle your data, you have the right to file a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP) — www.dataprotection.ro.