Privacy Policy
Alonia Culture Media Ltd · Nicosia, Cyprus · Effective 15 February 2026
Alonia Culture Media Ltd (Triptolaimou 17, Flat 104, 1087 Nicosia, Cyprus) is the data controller for Lumio. This policy explains what we collect, why, and the rights you have. Privacy questions: [email protected].
1. Data we collect & why
| Category | Purpose | Legal basis |
|---|---|---|
| Account data (email, password hash) | Create and secure your account | Contract |
| Subscription & billing data | Manage trial, renewal, refunds (handled by our payment provider once connected) | Contract / legal obligation |
| Usage data (picks viewed, device, browser) | Operate and improve the Service | Legitimate interest |
| Analytics & advertising data | Measure and, where applicable, promote the Service | Consent (see Cookies) |
| Support correspondence | Respond to your requests | Legitimate interest |
We only deploy analytics or advertising processing after you consent through our cookie banner. Essential processing needed to run the Service does not require consent.
2. Processors
We use service providers strictly to operate Lumio — for example hosting and, once connected, a payment processor. Processors act on our instructions under data-processing agreements. We do not list a specific payment processor here until checkout is genuinely connected, and we do not sell your personal data.
3. Retention
Account and subscription data are kept while your account is active and for the period required to meet legal and accounting obligations, then deleted or anonymised. Analytics data is retained only for the limited period needed for its purpose.
4. Your rights
You have the right to access, rectify, erase, restrict, and port your personal data, to object to processing based on legitimate interest, and to withdraw consent at any time. To exercise these rights, email [email protected]. You may also lodge a complaint with the Office of the Commissioner for Personal Data Protection in Nicosia.
5. International transfers & security
Where data is processed outside the EEA, we rely on appropriate safeguards such as standard contractual clauses. We protect data with encryption in transit (SSL) and access controls, and we never store full card numbers on our own servers.
6. Changes
We will post material changes here with a revised effective date.