Data processing
Last updated September 12, 2026.
01Scope
Lumen Tool is a browser-based lighting simulator that runs mainly in the visitor's own browser. The free part requires no account. Lumen Tool Studio uses an email address as the account and a subscription handled by a payment provider. Lumen Tool receives setup data, notes and optional photos when a Studio member explicitly saves or uploads them to the Archive.
This page explains how the limited technical data involved in running the website, the accounts and payment for Studio is handled, and which providers are used.
02Subject matter
The subject matter of the processing is the operation of the Lumen Tool website and lighting simulator, and the limited technical data needed to deliver, secure and improve it.
03Nature and purpose
Lumen Tool processes technical data to serve the website, keep it secure, troubleshoot issues, maintain reliability and - only with consent - understand general usage through analytics.
Lumen Tool does not sell data, does not use data for advertising resale, and does not use data to train AI models.
04Types of data
Technical connection data such as browser type, device information, IP address, timestamps and server logs.
With analytics consent, aggregate usage data such as page visits, engagement, browser and broad device type, operating system and general region.
Lighting setups and projects saved by the user, which are downloaded as files to the user's own computer and are not transmitted to Lumen Tool.
Setups, comparisons, previews, names, notes, collections, favorites, the default opened variant, the explicitly used variant, shoot dates and reference information saved to the Archive. These are linked to the member's account. Optional reference, result and setup photos are processed by the application server and kept privately in OVHcloud Object Storage in the United States as resized images and thumbnails. Original uploads and embedded image metadata are not retained. A complete Archive backup is sent only when the member downloads it; a backup uploaded for restore is checked and processed without being kept as a separate cloud file.
Account data for Studio: the email address, the state of the subscription (running, ending, ended), the plan, the currency, the renewal or end date, and the payment provider's customer number. Sign-in codes and sign-in tokens are short-lived, and a count of recent sign-in attempts per network address is kept briefly to protect against abuse.
Payment data is entered by the customer at the payment provider and held there: name, billing address, card details, VAT number where given, and invoices. Card details never reach Lumen Tool.
05Subprocessors
OVHcloud (OVH US LLC) hosts the Lumen Tool application on infrastructure in the United States.
Coolify is the tool used to put updates live; the tool itself runs on the OVHcloud server.
Stripe handles payment and subscriptions for Lumen Tool Studio. It receives the customer's own payment and billing details on its own payment page, keeps the invoices, and tells Lumen Tool which account has a running subscription. Stripe is also the customer's own place to change or cancel the subscription.
Resend delivers account mail for Lumen Tool, such as the sign-in code and the note that a subscription has ended.
Google Analytics 4 measures basic website use unless the visitor opts out. It must never receive names, private page addresses or anything a visitor types.
The in-browser face-reading feature in Reference Lab analyses the image on the visitor's own device without uploading it. It may send anonymous performance diagnostics (how fast it runs, not what it sees) to Google. A portrait taken into the Lighting Simulator stays in the browser for that tab's visit unless the member explicitly chooses to include it in the Archive. Archive photo uploads are processed by the application server and stored in OVHcloud Object Storage, with account ownership checks and temporary image access links.
Subprocessors may process limited information only where needed to help Lumen Tool operate. They are not allowed to sell data or use it for unrelated advertising.
06Security
Lumen Tool uses reasonable technical and organisational measures, including encrypted connections, secure hosting and strictly limited access to the live servers.
No online service can guarantee complete security, but Lumen Tool is designed around minimal data collection. There are no passwords to steal: signing in to Studio uses a one-time code sent by email.
07International processing
Because the application is hosted in the United States, technical data may be transferred to and processed there. Account and payment data may likewise be processed outside the European Union by OVHcloud, Stripe and Resend. Lumen Tool uses applicable data processing agreements and Standard Contractual Clauses with its providers for these transfers.
08Retention
Technical logs and security records are kept only as long as needed to run and protect the website. Sign-in codes expire within minutes, sign-ins after a limited time, and records of sign-in attempts within hours.
Account records and active Archive items are kept while the account exists. A member can remove individual Archive items. Recovery copies of removed or replaced Archive photos may remain for up to 14 days; deleting the account removes that account's recovery photos directly. Invoices and payment records held by Stripe are kept as long as tax and accounting law requires.
09Changes to this page
Lumen Tool may update this Data processing page as the product, infrastructure or legal requirements develop. The latest version will be published here, and the date above shows when it was last changed.
10Contact
For questions about data processing or security, contact franck@lumentool.com.
Lumen Tool is operated by Tec-Net, registered with the Dutch Chamber of Commerce under number 68341784.