This policy explains how we process personal data under the EU General Data Protection Regulation (GDPR). The data controller is UpMix Music Group ApS, CVR 45179990, Trøjeløkkevej 6, 4400 Kalundborg, Denmark — privacy@luminaplot.com.
| Category | Examples | Why | Legal basis |
|---|---|---|---|
| Account | Name, email, hashed password | Create and secure your account | Contract |
| Content | Plots, inventories, layouts you create | Provide the Service | Contract |
| Profile | Use case, role, organisation type, country and the gear/consoles you work with | Tailor the product and understand our user base | Legitimate interest |
| Billing | Stripe customer ID, plan, invoices (we do not store card numbers) | Process subscriptions | Contract / legal obligation |
| Technical | IP address, user-agent, session and audit logs | Security, fraud and abuse prevention | Legitimate interest |
We do not sell your personal data. We may create aggregated, anonymised industry insights from user-provided profile information and usage data — such as the most commonly used fixture types, consoles, or equipment categories. These insights do not identify individual users, organisations, or accounts. We may provide them to industry partners for market research, product development, or advertising purposes.
no-reply@luminaplot.com.Processors act under data-processing agreements and only on our instructions.
Where a processor transfers data outside the EU/EEA, the transfer is covered by an adequacy decision or EU Standard Contractual Clauses.
We keep account and content data while your account is active. Billing and invoice records are kept as required by Danish accounting law (generally 5 years). Security logs are kept for a limited period. When you delete your account, we delete or anonymise your data except where retention is legally required.
Under GDPR you have the right to access, rectify, erase, restrict, port, and object to processing of your personal data, and to withdraw consent. You can:
You may also lodge a complaint with the Danish Data Protection Agency (Datatilsynet).
Passwords are hashed with bcrypt; sessions use opaque tokens; admin accounts require email two-factor authentication; access is logged. No system is perfectly secure, but we take appropriate technical and organisational measures.
We use two strictly-necessary cookies to keep you signed in (a session token and a PHP session fallback), plus your browser's local storage for functional preferences such as units, theme and unsent drafts. None of these track you across sites. We use no advertising, analytics, or third-party tracking cookies — which is why you don't see a cookie banner.
We will post changes here and update the date above; material changes will be notified by email.