Lumen Career

Privacy Policy

Effective Date: January 21, 2026

This Privacy Policy describes how Lumen Career ("Lumen", "we", "us", "our") collects, uses, and shares personal information through our website at https://lumencareer.com and our AI-powered recruitment platform (collectively, the "Service").

This Privacy Policy applies to:

  • Customers and users who register for and use our Service
  • Candidates whose professional information appears in our database

By using our Service, you agree to the collection, use, and sharing of your information as described in this Privacy Policy.

1. Information We Collect

Information About Customers and Users

We collect personal information from individuals and companies who register for and use our Service:

Account and Contact Information:

  • Name, email address, phone number
  • Company name and professional title
  • Account credentials (username and password)
  • Billing and payment information

Service Usage Information:

  • Email campaigns and sequences created through the Service
  • Gmail integration data (as described in our Terms & Conditions)
  • Search queries and candidate lists
  • Feature usage and interactions with the Service

Communications:

  • Messages, questions, and feedback you send us
  • Customer support interactions
  • Responses to surveys or research requests

Automatically Collected Information:

  • IP address, browser type, and device information
  • Pages viewed, access times, and navigation paths
  • Cookies and similar tracking technologies (see Section 2 below)

Information About Candidates

We collect and maintain professional contact information about candidates to provide recruitment services to our customers:

Professional Information:

  • Full name
  • Professional email address and phone number
  • Current and previous job titles
  • Current and previous employers
  • Professional experience and work history
  • Education background
  • Professional skills and qualifications
  • Location (city, region, country)

Sources of Candidate Information:

We obtain candidate information from:

  • Publicly available sources, including professional networking sites, company websites, public directories, and other publicly accessible online sources
  • Third-party data providers who aggregate publicly available professional information
  • Third-party data enrichment providers who provide contact information from publicly available sources

We do not collect sensitive personal data about candidates (such as health information, political affiliations, or protected characteristics under data protection laws).

2. Cookies and Tracking Technologies

We use cookies and similar technologies to operate and improve our Service:

Essential Cookies:

  • Required for the Service to function
  • Remember your login status and preferences
  • Enable core features like email campaigns

Analytics Cookies:

  • Google Analytics to understand how visitors use our website
  • Help us improve the Service and user experience
  • Collect information about pages viewed, time spent, and navigation patterns

Cookie Management:

You can control cookies through your browser settings. Note that disabling cookies may limit your ability to use certain features of the Service.

For more information about Google Analytics and how to opt out, visit: https://tools.google.com/dlpage/gaoptout

3. How We Use Your Information

Use of Customer Information

We use customer information to:

Provide the Service:

  • Create and manage your account
  • Process payments and billing
  • Deliver the features and functionality you requested
  • Send transactional emails and service notifications
  • Provide customer support

Improve and Develop the Service:

  • Analyze usage patterns and improve features
  • Develop new products and services
  • Conduct research and testing
  • Create aggregated, anonymized analytics

Communicate with You:

  • Send product updates and feature announcements
  • Respond to your inquiries and requests
  • Send marketing communications (you can opt out at any time)
  • Request feedback and conduct surveys

Protect and Secure:

  • Prevent fraud and abuse
  • Ensure security of the Service
  • Comply with legal obligations
  • Enforce our Terms & Conditions

Use of Candidate Information

We use candidate information to:

  • Provide recruitment services to our customers
  • Enable customers to search for and identify potential candidates
  • Provide candidate contact information to customers for legitimate recruitment purposes
  • Maintain and improve the accuracy and completeness of our candidate database
  • Analyze trends in recruitment and talent markets (using aggregated, anonymized data)

Legal Basis for Processing (GDPR):

  • Customer data: Processing is necessary for the performance of our contract with you, and for our legitimate interests in operating and improving our Service
  • Candidate data: Processing is based on our legitimate interests in providing recruitment services to our customers, balanced against candidates' rights and interests
  • Marketing communications: Based on our legitimate interests in promoting our Service, with the ability to opt out at any time

4. How We Share Your Information

We do not sell your personal information. We share personal information only in the following circumstances:

Service Providers:

We share information with third-party service providers who perform services on our behalf:

  • Cloud hosting providers (for data storage and Service infrastructure)
  • Payment processors (Stripe Inc. for payment processing)
  • Email service providers (for transactional and marketing emails)
  • Analytics providers (Google Analytics for website analytics)
  • Customer support tools

AI Service Providers:

We use AI technology to power features of our Service. We share data with:

  • OpenAI (for AI-powered content generation)
  • Anthropic Claude (for AI-powered assistance and analysis)
  • Google Gemini (for AI-powered features)

We require all AI service providers to:

  • Use your data only to provide the Service
  • Not use your data to train their AI models
  • Implement appropriate security measures
  • Comply with applicable data protection laws

Data Enrichment Providers:

We use third-party data enrichment providers to obtain candidate contact information from publicly available sources. These providers operate as independent data controllers and are responsible for their own compliance with applicable data protection laws.

Customers (for Candidate Data):

We share candidate professional information and contact details with our customers for legitimate recruitment and hiring purposes. Our customers are independent data controllers and are responsible for their own compliance with data protection laws when using candidate information.

Professional Advisors:

We may share information with lawyers, accountants, auditors, and other professional advisors as necessary in the course of their services to us.

Legal Obligations:

We may disclose information to:

  • Comply with applicable laws, regulations, or legal processes
  • Respond to lawful requests from government authorities
  • Protect our rights, property, and safety, or that of our users or the public
  • Enforce our Terms & Conditions

Business Transfers:

If we are involved in a merger, acquisition, sale of assets, or bankruptcy, your information may be transferred as part of that transaction. We will provide notice before your information is transferred and becomes subject to a different privacy policy.

With Your Consent:

We may share information for other purposes with your consent.

5. Your Data Protection Rights

If you are located in the European Economic Area (EEA), United Kingdom, or other jurisdictions with applicable data protection laws, you have the following rights:

Right to Access:

You can request access to the personal information we hold about you.

Right to Rectification:

You can request that we correct inaccurate or incomplete personal information.

Right to Erasure (Right to be Forgotten):

You can request that we delete your personal information in certain circumstances, such as:

  • The information is no longer necessary for the purposes for which it was collected
  • You withdraw your consent (where processing was based on consent)
  • You object to processing based on legitimate interests and there are no overriding legitimate grounds
  • The information has been unlawfully processed

Right to Restrict Processing:

You can request that we restrict processing of your personal information in certain circumstances.

Right to Data Portability:

You can request a copy of your personal information in a structured, commonly used, and machine-readable format.

Right to Object:

You can object to processing of your personal information based on legitimate interests, including for direct marketing purposes.

Right to Withdraw Consent:

Where we process your information based on consent, you can withdraw that consent at any time.

Right to Lodge a Complaint:

You have the right to lodge a complaint with a supervisory authority, in particular in the EU member state or country where you live, work, or where an alleged infringement of data protection law occurred.

For users in Portugal, the supervisory authority is:

Comissão Nacional de Proteção de Dados (CNPD)
Website: https://www.cnpd.pt/
Email: [email protected]

Exercising Your Rights

For Customers:

To exercise any of these rights, please contact us at [email protected]. You may also update certain account information by logging into your account.

For Candidates:

If you are a candidate and wish to:

  • Request access to your information in our database
  • Request correction of inaccurate information
  • Request deletion of your information from our database
  • Exercise any other data protection rights

Please contact us at [email protected] with the subject line "Candidate Privacy Request." Please include your name and email address so we can locate your information.

We will remove your data from our database and provide guidance on removal from third-party data sources. Please note that we cannot control third-party data providers, but we will assist you in exercising your rights with them.

We will respond to your request within 30 days (or as otherwise required by applicable law). We may ask for additional information to verify your identity before processing your request.

Opt-Out of Marketing Communications:

You can opt out of marketing emails by:

  • Clicking the "unsubscribe" link in any marketing email
  • Emailing us at [email protected] with "UNSUBSCRIBE" in the subject line
  • Updating your communication preferences in your account settings

You will continue to receive transactional and service-related emails even if you opt out of marketing communications.

6. Data Retention

Customer Information:

We retain customer account information for as long as your account is active. After you delete your account, we will retain your information for 30 days to allow for account recovery, and then permanently delete it, except:

  • Financial and payment records, which we retain for 7 years to comply with tax and accounting requirements
  • Information we are required to retain by law

Candidate Information:

We retain candidate information for as long as necessary to provide our recruitment services to customers. Candidates may request deletion of their information at any time by contacting us at [email protected], and we will remove their data from our systems.

Aggregated Data:

We may retain anonymized, aggregated data indefinitely for analytics and business purposes. This data cannot be used to identify individuals.

7. International Data Transfers

Lumen is based in Portugal. We process and store data primarily within the European Economic Area (EEA). However, some of our service providers may process data outside the EEA, including in the United States.

When we transfer personal data outside the EEA, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions by the European Commission
  • Other legally approved transfer mechanisms

8. Data Security

We implement appropriate technical and organizational security measures to protect personal information against unauthorized access, alteration, disclosure, or destruction, including:

  • Encryption of data in transit and at rest
  • Regular security assessments and testing
  • Access controls and authentication requirements
  • Employee training on data protection and security
  • Secure software development practices

However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security.

If we become aware of a data breach that affects your personal information, we will notify you and relevant authorities as required by applicable law.

9. Children's Privacy

Our Service is not directed to children under the age of 16, and we do not knowingly collect personal information from children under 16. If we learn that we have collected personal information from a child under 16, we will take steps to delete that information as soon as possible.

If you believe we have collected information from a child under 16, please contact us at [email protected].

10. Third-Party Services and Links

Our Service may contain links to third-party websites, applications, or services that are not operated by us. This Privacy Policy does not apply to third-party services. We are not responsible for the privacy practices of third parties. We encourage you to read the privacy policies of any third-party services you use.

When you connect third-party services to our Service (such as Gmail), those services may collect information according to their own privacy policies.

11. Google API Services

Our Service uses Google APIs, including Gmail APIs, to provide certain features. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

This means:

  • We use Google user data only to provide or improve user-facing features of our Service
  • We do not use Google user data for serving advertisements
  • We do not allow humans to read Google user data unless we have your affirmative agreement for specific messages, it is necessary for security purposes, or it is required by law
  • We do not use Google user data to develop, improve, or train generalized AI or machine learning models

For more information about how we handle Gmail data, please see Section 6 of our Terms & Conditions.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by:

  • Posting the updated Privacy Policy on our website
  • Updating the "Effective Date" at the top of this Privacy Policy
  • Sending you an email notification (if we have your email address)

We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes are posted constitutes your acceptance of the updated Privacy Policy.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: [email protected]

Last Updated: January 21, 2026