Privacy Policy
As of: 7 September 2026
1. Controller
The controller for data processing within the meaning of the GDPR is:
Jan Kiefer, Eitelbrodstraße 22, 38108 Braunschweig, Germany, legal@luciphy.com. Further details in the legal notice.
No data protection officer has been appointed; neither Art. 37 GDPR nor § 38 BDSG requires one here.
2. Roles: processing on behalf
Where customer organisations use the service and have their own content (e.g. the source code of their repositories) processed, we act in that respect as a processor on behalf of the respective organisation. The basis is a data-processing agreement (DPA) pursuant to Art. 28 GDPR. The subprocessors used are listed in the subprocessor register.
3. What data we process
When using the platform, the following data in particular is processed:
- Account and identity data: email address, name, role, organisation/tenant assignment, login identifier (via Keycloak).
- Code and scan data: names and metadata of connected repositories, commit identifiers, analysed code snippets as finding evidence, scan results, risk assessments and generated documents.
- Details of purchased AI systems: The name of the system plus the name, contact address and website of its provider. Customers enter these themselves; they may be personal data, for instance where a named contact person is given. They are processed so that the duties under Art. 26 of Regulation (EU) 2024/1689 towards that provider can be documented. Customers are the controller for these details; we process them on their instructions.
- Connection credentials: access tokens for connected code hosts (stored encrypted).
- Billing data: plan, usage quotas and a customer identifier of the payment service provider. Payment card data is processed exclusively at the payment service provider, not by us.
- Communication and preference data: Per-person notification settings, email language and - only where someone subscribes to the newsletter - subscription status, timestamps and the IP addresses of the request and the confirmation.
- Support data: Subject and content of support requests, the message thread, and input to the AI assistant.
- Log/audit data: security-relevant actions with timestamps (stored tamper-evident as a signature chain), technical server logs.
4. Purposes and legal bases
- Provision, operation and performance of the contract for the service – Art. 6(1)(b) GDPR (contract) or processing on behalf under Art. 28 for customer content.
- Security, abuse prevention and a tamper-evident audit trail – Art. 6(1)(f) GDPR (legitimate interest in secure, verifiable operation).
- Compliance with legal obligations (e.g. commercial/tax retention of invoice data) – Art. 6(1)(c) GDPR.
- Consent (for instance to receive the newsletter) – Art. 6(1)(a) GDPR in conjunction with § 7(2) no. 2 UWG.
5. AI-assisted processing (subprocessors)
For risk classification and document generation, code snippets are transmitted to the AI services Anthropic (Claude) and – for semantic search – to Voyage AI. This processing only takes place if it is not disabled for the organisation. Owners can turn off AI processing in the settings; then no code content leaves the platform for these purposes and the relevant features are blocked.
6. Registration, abuse prevention and payment verification
At registration we check the email address given, so that the free allowance cannot be claimed repeatedly through throwaway mailboxes: the address is normalised (lower case, plus-tags and provider-specific dots removed) and checked against a list of known disposable providers; the normalised form is what we store. Where enabled, a bot protection (Cloudflare Turnstile) is used in addition, which transmits the device's IP address to Cloudflare. Anyone wishing to raise their free allowance may voluntarily add a payment method; it is verified through the payment provider with an amount of EUR 0 and is not charged. Where Turnstile accesses information on the device or reads temporary characteristics, it does so on the basis of § 25(2) no. 2 TDDDG, to ensure system security and prevent abuse; no consent is required for that. The legal bases are Art. 6(1)(f) GDPR (legitimate interest in preventing abuse) and Art. 6(1)(b) GDPR for pre-contractual steps.
7. Notifications, compliance digest and newsletter
Recurring system messages - a scan result, quota warnings or the monthly compliance digest - are transactional messages performing the contract (Art. 6(1)(b) GDPR). The digest carries aggregate figures only (such as the number of open obligations) and no specific findings; details are visible only after signing in. Everyone can turn these messages off in their settings.
The regulatory newsletter is marketing and is sent only after express, separately given consent in a double opt-in procedure (Art. 6(1)(a) GDPR, § 7(2) UWG). That consent is not bundled with acceptance of the terms. To evidence it (Art. 7(1) GDPR) we record the time and the wording of the consent text as well as the IP address of the request and of the confirmation.
Consent can be withdrawn at any time with effect for the future: through the unsubscribe link in every marketing email, through the List-Unsubscribe header that mail clients act on, or in the settings. The unsubscribe record is kept so that the withdrawal can be evidenced and no further mail is sent. Our emails contain no tracking pixels and no open or click tracking.
8. Support requests and AI assistant
Support requests are stored with their subject, thread and requesting person so that they can be handled and the handling evidenced (Art. 6(1)(b) GDPR). The AI assistant answers questions from our product documentation; the input is transmitted to Anthropic for that purpose and is processed only where AI processing has not been disabled for the organisation. Draft replies from our support are always reviewed and approved by a person before they are sent; nothing is sent automatically.
9. Transfers you trigger
Where an organisation sets up an outbound integration (Slack, Microsoft Teams or its own webhook), we transmit a notice that an event occurred - not its content - to the destination configured there. Where an organisation publishes a transparency statement, that page is afterwards reachable without signing in; the organisation alone decides on timing, content and withdrawal. Both happen only on express setup or release.
10. No automated decision-making in individual cases
The service's risk classification assesses a software system, not a person. There is no automated decision in an individual case producing legal effects concerning a data subject or similarly significantly affecting them (Art. 22 GDPR). All classifications and generated documents are AI-generated drafts for professional review and do not replace a legal assessment of the individual case.
11. Cookies and local storage
This application uses no tracking or analytics cookies. For sign-in, technically necessary browser storage (localStorage) is used to maintain the session. In addition we set exactly one cookie: NEXT_LOCALE stores the language you chose, so that requests without a language prefix are served in it. It is written only when you switch language, lasts one year, is limited to SameSite=Lax and holds nothing but the language code - no identifier that makes you recognisable. Both are strictly necessary to provide the service you explicitly requested (§ 25(2) no. 2 TDDDG); no consent is required for them, which is why no cookie banner is shown.
12. Recipients and third-country transfer
Recipients are the service providers named in the subprocessor register. The application, the database and the backups are hosted with netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, in data centres in Germany; at rest the data does not leave the EU. Where data is transferred to service providers in the USA, this rests on EU standard contractual clauses (Art. 46(2)(c) GDPR) and, where the provider is certified under the EU-U.S. Data Privacy Framework, additionally on the Commission's adequacy decision of 10 July 2023 (Art. 45 GDPR). Which service rests on which basis is stated per entry in the subprocessor register.
13. Retention period
Personal data is deleted as soon as it is no longer required for the stated purposes. Scan data is additionally deleted automatically after a period each organisation can set (365 days by default). Account and content data is removed when the organisation is deleted (see point 14). The audit trail is not deleted with it while the organisation exists, because a signature chain with gaps loses its purpose - evidencing that nothing was altered. Audit and invoice data is retained within the statutory retention periods: accounting records and invoices for ten years (§ 147(3) AO, § 257(4) HGB), incoming and outgoing commercial and business letters for six years; each period starts at the end of the calendar year in which the record arose. The audit trail is kept for the duration of the business relationship and thereafter within those periods; it records operations and field names, not the content itself.
Technical server and container logs (in particular IP address, time of access, URL requested and user agent) serve to fend off attacks and keep the system stable. They are not archived: they rotate continuously, with at most three files of 10 MB each kept per service; when the newest overflows, the oldest is overwritten. No evaluation beyond that purpose takes place.
14. Your rights
Under the GDPR you have in particular the following rights:
- access (Art. 15), rectification (Art. 16), erasure (Art. 17),
- restriction of processing (Art. 18), data portability (Art. 20),
- objection to processing based on legitimate interests (Art. 21),
- withdrawal of consent given, with effect for the future (Art. 7(3) GDPR); the lawfulness of processing carried out until then is unaffected.
Owners can export their organisation's data directly in the settings as a file (access/portability) and irreversibly delete the organisation with all its data (erasure). For other requests, contact legal@luciphy.com.
You have the right to lodge a complaint with a data-protection supervisory authority, e.g. Die Landesbeauftragte für den Datenschutz Niedersachsen (LfD Niedersachsen), Prinzenstraße 5, 30159 Hannover, Germany.