Skip to content
Trust

Security and data protection are part of the operation.

Lumenoeva is designed for business workflows where control, confidentiality, auditability and clear data boundaries matter. Technical controls, operating procedures and customer-specific contractual safeguards sit around the same managed workflow.

The practical question

Can Lumenoeva work with CRM, customer or proprietary company data?

Yes — where the information is necessary and authorised for the agreed workflow. A production workflow may require access to customer records, CRM information, documents, supplier data, product information or commercially sensitive internal processes.

Production data is not collected through the public workflow-enquiry form. Before customer processing begins, the systems, data categories, permitted actions, access roles, approved providers, human-review path, retention, transfer arrangements and security responsibilities are defined for the operation.

Purpose-limited

Information is accessed and used only for the contracted workflow, its controls, support and agreed service evidence.

Confidential

Access to client information is restricted to authorised people and systems operating under defined confidentiality and security obligations.

Least privilege

Each person, integration and service receives only the level of access required for the role it performs in the workflow.

Customer-controlled boundaries

The customer agreement defines which systems may be accessed, which actions may be taken and which decisions remain with the client.

No unrelated use

Customer information is not sold, repurposed for unrelated Lumenoeva activity, advertising or resale.

Training boundary

Lumenoeva does not use customer workflow information to train public foundation models.

Retention + deletion

Retention, return and deletion requirements are defined for the workflow and customer relationship rather than left indefinite.

Traceable operation

Workflow activity, automated execution and human interventions can be recorded so important actions do not disappear into an opaque service process.

Control architecture

Client separation

Operational state, submissions and workflow context are logically separated between client environments.

Least-privilege access

People and systems receive only the access required for the defined workflow and review responsibility.

Server-side secrets

Provider credentials and operational secrets remain server-side rather than being exposed to ordinary browser users.

Auditability

Workflow actions, model activity, human interventions and outcomes can be recorded as operating evidence.

Controlled recovery

Retries and recovery are designed to preserve state and avoid uncontrolled duplication after failures.

Provider boundaries

External AI and data services are approved components behind Lumenoeva-owned workflow and control logic.

Human review

Ambiguous, sensitive or high-risk cases can be routed to trained people rather than blindly committed.

Incident response

Customer operations use defined escalation, incident handling and notification responsibilities appropriate to the service.

Before production begins

The control model follows the data and the operation.

Each customer workflow is qualified as an operating boundary, not merely connected to a system and switched on. The production schedule defines the information and access required to complete the agreed outcome.

  • Systems and data categories involved
  • Permitted user, service and integration access
  • Actions Lumenoeva may take and decisions that remain with the customer
  • Approved AI, infrastructure and data providers
  • Human-review requirements and access boundary
  • Retention, return and deletion requirements
  • International-transfer mechanism where required
  • Security, incident and notification responsibilities
European customer data

Processor terms and transfer safeguards are established before processing.

Where Lumenoeva acts as a processor of personal data for a customer subject to the GDPR, the processing relationship is governed by appropriate processor terms defining the subject matter, duration, purpose, data, instructions, security responsibilities and applicable subprocessor arrangements.

Where the agreed operation involves an international transfer that requires safeguards under GDPR Chapter V, an applicable transfer mechanism is established before processing begins. Depending on the processing relationship, this may include the European Commission's Standard Contractual Clauses together with supplementary safeguards where appropriate.

Sri Lanka is not currently covered by a general European Commission adequacy decision. The customer-specific role allocation, data categories, approved subprocessors, retention, security schedule and transfer mechanism therefore form part of the production assessment where EU/EEA personal data is involved.

Sri Lanka framework

Local obligations sit alongside customer-specific international safeguards.

Lumenoeva is established in Sri Lanka and operates within the applicable Sri Lankan legal framework, including the Personal Data Protection Act as its relevant provisions come into force. International customer commitments are additionally defined through the applicable service, confidentiality, processor and transfer documentation.

For customers, the practical point is that location does not replace contractual clarity: the production workflow documents who processes what, for which purpose, under which access and provider boundaries, and with which transfer safeguards where required.

Operational documents
Customer processingProcessor terms / DPA where applicable
International transferApplicable transfer mechanism where required
SecurityWorkflow-specific security schedule
ProvidersApproved subprocessor register
Security questions

Need the control model for a specific workflow?

Security, data and provider requirements are mapped as part of workflow assessment and contracting before production access is established.

Contact Lumenoeva →