Data security: where your data lives and what rights you have

Data security at Lucanto rests on transparency rather than claims you cannot verify. We build and host the application in the EU, the controller is Stark Codes, s. r. o., and personal data is processed under the GDPR. Below you will find what we process, who we do not send it to, and how to exercise your rights.

Contents

How we think about data security at Lucanto

Data security is not a list of fashionable acronyms to us. It is a simple bargain: you know who we are, where your data lives, what we do with it and what stays in your hands. So this page carries no marketing slogans we could not evidence — it carries facts and links to documents you can read yourself.

Lucanto is operated by Stark Codes, s. r. o. We build and host the application in the European Union. Personal data is processed under Regulation (EU) 2016/679 (GDPR), which applies identically across every member state.

Who controls your data

The controller — under Article 4(7) GDPR, whoever determines the purposes and means of processing — is Stark Codes, s. r. o., Holíčska 3043/13, 851 05 Bratislava, company ID 51 414 546. Write to us at hello@lucanto.eu; data requests go to the same address.

That a named company with a registered office and a company registration stands behind the service matters: you have a real counterparty, not an anonymous app with no address.

Data security in practice: where it lives and who processes it

Lucanto is built and hosted in the EU. To run the service we also use processors — for sending e-mail, for support, for web analytics. Each processes data only on our instructions and is bound by a data processing agreement under Article 28 GDPR. The list and the purpose of each is in the Data Processing Agreement (DPA) and in the Privacy Notice.

Where a processor operates outside the European Economic Area (EEA), the transfer is covered by standard contractual clauses approved by the European Commission under Article 46 GDPR. Specific retention and deletion periods are described in the Privacy Notice.

We process the data we need so that you can invoice: your login e-mail, details of your business and clients, the content of documents, and basic information about how the service is used. We do not collect data "just in case" — the data-minimisation principle is set out in Article 5(1)(c) GDPR.

Every processing operation has a legal basis under Article 6 GDPR. Most often that is performance of the contract (we provide you the service), legitimate interest (account security, for instance) or consent (web analytics). Some data we are required to keep for tax and accounting purposes.

Documents can also sit in a 10-year digital archive — part of the PRO and Business plans (see pricing).

Who we do not send your data to

We do not sell your personal data. We do not pass it to third parties for their own marketing. Access is limited to our staff who need it for their work and to processors, to the extent required to run the service (per the DPA).

We disclose data to public authorities only where the law or a court decision requires it. Web analytics, moreover, loads only after you consent — before that it does not run at all. How we handle this is described in the cookie policy.

Your rights over your data under GDPR

GDPR gives you specific rights over your personal data. You do not have to give a reason, and exercising them is free. Here is the overview, with the article each right rests on.

Rights over personal data under GDPR and the articles they rest on
RightWhat it means for you
Right of accessFind out whether and what data of yours we process, and get a copy.Article 15 GDPR
Right to rectificationHave inaccurate data corrected or incomplete data completed.Article 16 GDPR
Right to erasureAsk for your data to be deleted, on the conditions GDPR sets out.Article 17 GDPR (“right to be forgotten”)
Right to restrictionTemporarily limit how we handle your data.Article 18 GDPR
Right to portabilityReceive your data in a structured, machine-readable format.Article 20 GDPR
Right to objectObject to processing based on legitimate interest or direct marketing.Article 21 GDPR
Withdrawing consentWithdraw a consent you gave earlier — for analytics, for instance — at any time.Article 7(3) GDPR
Complaint to a supervisory authorityTurn to the supervisory authority in your own country.Article 77 GDPR

How to exercise your rights and raise a complaint

The process is straightforward:

  • Write to hello@lucanto.eu and say what you want — access, rectification, erasure, portability and so on.
  • We check the request really comes from you, so that we do not hand your data to someone else.
  • We handle it without undue delay and within one month at the latest. For complex requests we can extend that by two months, and we tell you if we do (Article 12(3) GDPR).

If you disagree with how we handled it, you have the right to lodge a complaint with a supervisory authority under Article 77 GDPR. The competent one is the authority in the country of your habitual residence, your place of work, or the place of the alleged infringement. You can also reach us through the contact page.

What we deliberately do not claim about data security

We would rather say less and mean it. So this page deliberately does not list security certifications, specific encryption technologies, uptime figures or guarantees we could not currently back with a document or an audit. A claim like that belongs on a website only when there is verifiable evidence behind it.

What we can tell you is above: who we are, where your data lives, on what basis we process it, who we do not send it to, and what rights you have. If something is missing, write to hello@lucanto.eu — we will add whatever we can evidence.

Frequently asked questions about data security

Where is my data stored?

Lucanto is built and hosted in the European Union. To run the service we use processors — for e-mail or web analytics, for example — each bound by a data processing agreement under Article 28 GDPR; the list is in the DPA. Where a processor operates outside the EEA, that transfer is covered by standard contractual clauses under Article 46 GDPR.

Do you sell my data or use it for advertising?

No. We do not sell your personal data and we do not pass it to third parties for their own marketing. Web analytics loads on the site only after you consent, and you can withdraw that consent at any time (Article 7(3) GDPR). The details are in our cookie policy.

How do I download or delete my data?

Write to hello@lucanto.eu. You have the right of access and to a copy of your data (Article 15 GDPR), to portability in a machine-readable format (Article 20 GDPR) and to erasure (Article 17 GDPR). We handle requests without undue delay and within one month at the latest, under Article 12(3) GDPR.

Who has access to my data?

The controller is Stark Codes, s. r. o. Access is limited to our staff who need it for their work and to processors, to the extent required to run the service — each bound by a data processing agreement under Article 28 GDPR. We disclose data to public authorities only where the law or a court decision requires it.

Why do you not list security certifications or specific encryption?

Because we only make security claims we can back up. We would rather tell you what actually holds: who we are, where your data lives, on what legal basis we process it, who we do not send it to, and what rights you have under GDPR. If something specific is missing for you, write to us and we will add whatever we can evidence.

Where do I complain if I suspect a breach?

Come to us first at hello@lucanto.eu — most things get resolved directly. If you are not satisfied, you have the right to lodge a complaint with a supervisory authority under Article 77 GDPR. The competent one is the authority in the country of your habitual residence, your place of work, or the place of the alleged infringement.

Zdieľať článok

Unlock your financial superpowers

Start for free