Privacy Policy

Last updated: 30 July 2026
Effective from: 30 August 2026

  • Controller and contact


    1. Controller and contact

    The controller described in this Notice is Stark Codes, s. r. o., Holíčska 3043/13, 851 05 Bratislava – mestská časť Petržalka, Slovak Republic, Company ID 51 414 546, Tax ID 2120683730, VAT ID SK2120683730, registered in the Commercial Register of Municipal Court Bratislava III, section Sro, file 126116/B (“Stark Codes”, “Lucanto”, “we”). Privacy contact: hello@lucanto.eu.

    This Notice explains processing when you visit lucanto.eu, create an account, use app.lucanto.eu privately or for business, pay, communicate with us, or receive marketing.

    2. When we are controller and processor

    2.1 We are controller when we determine the purposes and means, especially for:

    • registration and management of accounts, users and workspaces;

    • billing, payment, fraud prevention and legal obligations;

    • security, operation, support and improvement of the Service;

    • communications, marketing and optional analytics; and

    • content and documents of a person using Lucanto for private purposes.

    2.2 We are processor when a business customer determines the purposes for personal data in documents, records and other workspace content. The customer is then controller and the DPA applies. This Notice still applies to account, contract, payment, security and communication data we process for our own purposes.

    2.3 If you use Lucanto for another organisation, that organisation should explain its processing of workspace content. We forward relevant requests or help it respond.

    3. Data we process

    Depending on use, we may process:

    • identity and contact data: name, email, telephone, job title and login identifier;

    • account and workspace data: role, permission, membership, settings, language, and history of consent and accepted terms;

    • external sign-in data: provider, provider user identifier, email, name, profile photo and an Apple relay email where selected, within the scope you authorise;

    • business and billing data: business name, company/tax/VAT identifiers, registered and billing address, country and data needed to determine VAT;

    • document content: invoices, receipts, attachments, photographs and data within them, such as names, addresses, signatures, identifiers, items, amounts, dates, IBAN and other financial data about counterparties, staff or customers;

    • AI extraction data: a document or relevant part submitted for extraction, prompt/instruction, extracted fields, corrections, status and technical request identifiers;

    • payment metadata: Stripe customer and payment identifiers, status, amount, currency, date, method type and final digits; Stripe processes full card details;

    • bank data: for an activated Tatra banka PSD2 connection, account identifier/IBAN, currency, balance, transactions, counterparties, amounts, dates, messages and bank-authorisation state;

    • communication, email and support data: messages, attachments, addressee, delivery, unsubscribe, requests, feedback and resolution records;

    • bug-report and observability data: reporter name/email, legal workspace name, company ID, failed-AI-extraction metadata, internal user/workspace IDs, stack trace, request path, time and technical error data; for optional session replay, visited screens, clicks and interface changes; sensitive fields and documents are to be masked or excluded, and a document is sent to a ticket only on the User's separate instruction;

    • technical, device and security data: IP, TLS fingerprint, user-agent, browser, operating system, access time and URL, request headers, referrer, Turnstile sitekey/origin and token, audit events, error and security logs;

    • logo data: counterparty name or domain, IP and technical Logo.dev request data;

    • cookie and analytics data: identifiers, sessions, language, pseudonymised user/workspace identifier and product events only where you consent to optional analytics; and

    • integration and external-resource data: identifiers/content needed for a connection and IP, user-agent, referrer and requested URL when Google Fonts, jsDelivr or unpkg loads directly.

    We do not intentionally request special-category data. A document may nevertheless contain it. Do not upload such data unless necessary and supported by an appropriate legal basis and safeguards.

    4. Data sources

    We obtain data from you, your workspace administrator, documents and integrations uploaded or activated by a user, automatically from devices and Service use, from Google or Apple when selected for sign-in, from Tatra banka for an activated PSD2 connection, from Stripe during payment, and from public or commercial sources for lawful B2B outreach and business verification. Where we are processor, the business customer determines the original source and lawful collection.

    5. Purposes, legal bases and retention

    We do not ask for blanket consent. Necessary processing relies on contract, legal obligation or legitimate interest. Marketing and optional cookie analytics rely on separate consent unless law permits a specific communication on another basis.

Purpose

Data

Legal basis when we are controller

Typical period

Registration, authentication, account, workspace and features

identity, contact, account, business, technical, private-user content

contract; pre-contract steps

account duration; Customer Content erased within 45 days after deletion

Google or Apple sign-in

| external ID, email, name, photo/relay address, authentication token

contract at your request; legitimate security interest

while linked; tokens revoked or erased when no longer needed

OpenAI automated document extraction

document, AI input/output, technical identifiers

contract for private user; business-customer instructions under DPA

in Lucanto for the content lifecycle; under standard settings, OpenAI abuse-monitoring logs for up to 30 days, and longer only where required by law or reasonably necessary to protect OpenAI's services or third parties from harm

Tatra banka PSD2 connection

IBAN/account, balance, transactions, counterparties, authorisation and technical identifiers

contract; legal obligation

contract term and limitation period; accounting and tax records generally 10 years or another statutory period

| Subscription, payments, VAT, invoices and accounting

account, business, billing, payment metadata

contract; legal obligation

contract term and limitation period; accounting and tax records generally 10 years or another statutory period

Cloudflare proxy/CDN and Turnstile security, fraud prevention and audit

account, IP, TLS fingerprint, user-agent, URL/headers, origin/sitekey, token, logs, payment status

legitimate interest in secure/available Service; necessary technology; law

our routine security logs for up to 12 months; longer only while handling an incident, legal claim or legal duty; Turnstile tokens expire after 5 minutes

Hosting, production database, storage and operation

application records and PostgreSQL databases at Render, including application data, cache, job queues and realtime messages; attachments in Hetzner Object Storage

contract; legitimate interest in availability and security

Customer Content is erased within 45 days after account or Service deletion; technical backups follow the same cycle unless law requires a specific record

Server-side logging, monitoring and backend error reporting through Render and Better Stack

IP address, request ID, internal user/workspace IDs, path without query string, status, time, stack trace, error and security events; excluding passwords, tokens, cookies, full payment details and document content

legitimate interest in security, stability, diagnosis and legal claims

routine logs and error records for up to 12 months; longer only for a specific incident, claim or legal duty

Optional Better Stack browser monitoring and session replay

cookie/local session identifier, pseudonymised internal user/workspace IDs, frontend errors, visited screens, clicks, interface changes and device; sensitive inputs and documents are masked or excluded

consent

session replays for up to 90 days; new collection stops on withdrawal

Support, bug reports and Service communication

contact/account, workspace name/company ID, messages, attachments, extraction metadata

contract; legitimate interest in response, bug correction and evidence

account duration and generally 3 years after ticket/account closure; technical metadata shorter where possible, longer for dispute

Transactional/service email through Resend

name, email, language, account/plan state, security/contract message, delivery state

contract; legal obligation; legitimate delivery interest

message content and delivery records for up to 3 years after sending; longer only for a legal claim or legal duty

Necessary service, legal and subprocessor notices

name, email, account, role

contract; law; legitimate interest

account/contract duration and time needed to evidence delivery

Marketing email through Loops

name, email, business, preference and sequences

consent; only where law permits a specific existing-customer message with easy opt-out

until withdrawal, objection or generally 24 months inactivity; suppression record reasonably longer

Counterparty logo through Logo.dev

counterparty name/domain, IP and technical data

technical data | contract; legitimate interest in clear interface

Logo.dev DPA/log period; in Lucanto with relevant record

Optional site/product analytics through Google Tag Manager-managed tags

cookie IDs, IP/derived location, device, pseudonymised user/workspace ID, language and product events

consent

up to 24 months or a shorter period stated for the particular analytics tool; new collection stops on withdrawal

Technical libraries and fonts

IP, user-agent, referrer, requested URL

legitimate interest only where a direct external request is necessary and proportionate

Lucanto keeps no separate copy of the CDN request; the provider keeps technical logs under its published retention policy

Legal claims and compliance

relevant data above

legitimate interest; law

applicable limitation or statutory period

    1. AI processing and human review

    6.1 Lucanto sends uploaded documents or relevant parts to the OpenAI API for automated recognition and structuring. The User can correct the result before saving. AI may make mistakes; do not use output without checking it for accounting, tax, payment or legal decisions.

    6.2 For EEA customers, OpenAI Ireland Ltd. provides the API Services. OpenAI acts as processor or subprocessor for API data and, under its business terms, does not train or improve its models on these inputs and outputs by default.

    6.3 We use the standard OpenAI API retention setting. OpenAI may retain input and output content and related technical data in abuse-monitoring logs for up to 30 days, and longer only where law requires or where reasonably necessary to protect OpenAI's services or third parties from harm. OpenAI processing is not restricted exclusively to the EEA. Transfers outside the EEA rely on an adequacy decision or EU Standard Contractual Clauses.

    6.4 We do not make decisions based solely on automated processing that have legal or similarly significant effects on a person. AI extraction is human-reviewed input, not a decision about a person.

    7. Recipients and providers

    We disclose data only as necessary. A provider can be our processor for one activity and an independent controller for another. The current recipient and provider list appears directly below. A provider that processes Customer Personal Data on Stark Codes' behalf for the business Service is additionally listed as a Subprocessor in DPA Annex 3.

    This Article also serves as Lucanto's public provider register. We do not operate a separate register page.

Provider

Typical role and purpose

**OpenAI Ireland Ltd. and approved subprocessors

processor/subprocessor for AI document extraction

**Plus Five Five, Inc. (Resend)

processor for transactional/service email and delivery information |

Astrodon Corporation (Loops)

processor for consented or otherwise permitted marketing email and sequences

Stripe Payments Europe, Limited and relevant Stripe companies

processor for technical payment handling; independent controller for regulated payments, KYC, fraud and compliance

Cloudflare, Inc. a príslušné spoločnosti Cloudflare

application hosting and managed PostgreSQL databases; stores application records and technical databases used for cache, job queues and realtime communication and provides operational database backups

Render Services, Inc.

application hosting and managed PostgreSQL databases; stores application records and technical databases used for cache, job queues and realtime communication and provides operational database backups

Hetzner Online GmbH

S3-compatible Object Storage in the EU (Germany or Finland) for attachments including invoices, receipts and contracts

Better Stack, Inc.

server-side operating logs including IP and internal identifiers, backend errors and diagnostics on legitimate interests; its browser tag, frontend monitoring and session replay start only after analytics consent, with sensitive fields and documents masked or excluded

Linear Orbit, Inc.

bug reports/tasks: reporter name/email, workspace legal name/company ID and failed-AI-extraction metadata

Google Ireland Limited / Google LLC

Google OAuth (email/profile/name/photo); Google Tag Manager for tag management and, only after consent, tags that transmit analytics; Google Fonts on pages where fonts load directly from Google

Apple Distribution International Ltd. and relevant Apple group companies

Sign in with Apple: unique ID, email/relay and optional name; Apple follows its own privacy terms

Tatra banka, a.s.

PSD2 bank connection: IBAN/account, balance and transactions; typically independent controller for banking/regulatory purposes

Simple Casual, LLC (Logo.dev)

counterparty name/domain, IP and technical data to retrieve a logo; processor under its DPA

Volentio JSD Limited (jsDelivr) and CDN suppliers

direct library loading; IP, browser, referrer and requested URL

UNPKG delivered through Cloudflare's global edge network

direct library loading; IP, browser, referrer and requested URL

  • We may also disclose data to professional advisers under confidentiality, public authorities where law requires, or an acquirer in a reorganisation or business sale with appropriate safeguards.

    8. International transfers

    Some providers or their suppliers are based or process outside the EEA, particularly in the United States. We use a GDPR Chapter V mechanism: an European Commission adequacy decision, including the EU–U.S. Data Privacy Framework where applicable to the recipient and transfer, or EU Standard Contractual Clauses with supplementary measures where needed. On request we provide information about the specific mechanism or relevant safeguards, subject to protection of trade secrets.

    Product development occurs in the EU, and attachments in Hetzner Object Storage are stored in the EU. Lucanto is not an EU-only processing service. OpenAI, Resend, Loops, Stripe, Cloudflare, Render, Better Stack, Linear, Google, Apple, Logo.dev, jsDelivr and UNPKG or their published suppliers may process data outside the EEA under those safeguards.

    9. Cookies and similar technologies

    We use necessary cookies and local storage for authentication, Cloudflare/Turnstile security, settings and recording consent choice without consent where essential. Google Tag Manager is a tag-management tool: values in the local dataLayer are not sent to Google unless a configured tag transmits them. The external GTM container, tags that transmit optional analytics or marketing, and the entire Better Stack browser tag load only after analytics consent. Without consent, user_id, workspace_id, language and product events must not be transmitted for analytics or marketing, and Better Stack must not create its _bs cookie or local identifier in the browser. Server-side logs and backend technical error reporting may remain active on legitimate interests with minimised data. Withdraw through Cookie Settings as easily as you consented. See the Cookie Policy.

    10. Retention and erasure

    10.1 We keep data only for the section 5 period or as necessary for the purpose, considering its nature, risk, contract duration, statutory periods and the need to evidence claims.

    10.2 After account deletion or Service termination, we erase Customer Content from active systems and backups within 45 days, unless law requires a specific record. Backups are isolated during the rotation cycle and not used in ordinary operations. If a backup is restored, applicable deletion requests are re-applied.

    10.3 We do not erase records we must retain as controller, such as tax and accounting documents, evidence of consent or Terms acceptance, payment, claim or incident records. We limit them to what is necessary, separate them from active Customer Content, and erase or anonymise when the need ends.

    11. Security

    We use risk-appropriate measures including access and role controls, multi-factor access to privileged systems, encryption in transit, appropriate encryption at rest, backup and recovery, logging, vulnerability management, incident handling, staff confidentiality and provider review. More detail for B2B customers is in DPA Annex 2.

    12. Your rights

    Subject to GDPR conditions, you may:

    • obtain confirmation and access;

    • correct inaccurate or complete incomplete data;

    • request erasure;

    • restrict processing;

    • receive data you provided in portable form where applicable;

    • object to legitimate-interest processing;

    • withdraw consent at any time without affecting earlier lawfulness; and

    • not be subject to a solely automated decision with legal or similarly significant effects unless a legal exception applies.

    Contact hello@lucanto.eu. We may reasonably verify identity. We normally respond within one month and may extend for complexity under GDPR with an explanation. If your employer or another business customer controls the data, contact it first; we help at its instruction.

    You may complain to the Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava 27, dataprotection.gov.sk, or a supervisory authority in your habitual residence or workplace. We welcome the opportunity to resolve the issue first.

    13. Marketing

    Marketing consent is separate, voluntary and unticked by default. Withdraw through the message link or settings. Opting out does not stop necessary service messages such as payment confirmations, security alerts, legal changes or trial expiry.

    Where law permits B2B outreach without consent based on legitimate interests, each message identifies the source or source category and offers an easy objection. We honour direct-marketing objections without further balancing.

    14. Children

    The Service is not intended for anyone under 18. If we learn that we obtained such data without a valid basis, we erase it.

    15. Changes to this Notice

    We notify existing Users of a material change by email or persistent in-Service notice at least 14 days in advance unless law or urgent security requires sooner. We show the updated date above. Where new consent is needed, we ask for it; silence or continued use is not consent.