Privacy Policy
Last updated: 30 July 2026
Effective from: 30 August 2026
Controller and contact
1. Controller and contact
The controller described in this Notice is Stark Codes, s. r. o., Holíčska 3043/13, 851 05 Bratislava – mestská časť Petržalka, Slovak Republic, Company ID 51 414 546, Tax ID 2120683730, VAT ID SK2120683730, registered in the Commercial Register of Municipal Court Bratislava III, section Sro, file 126116/B (“Stark Codes”, “Lucanto”, “we”). Privacy contact: hello@lucanto.eu.
This Notice explains processing when you visit
lucanto.eu, create an account, useapp.lucanto.euprivately or for business, pay, communicate with us, or receive marketing.2. When we are controller and processor
2.1 We are controller when we determine the purposes and means, especially for:
registration and management of accounts, users and workspaces;
billing, payment, fraud prevention and legal obligations;
security, operation, support and improvement of the Service;
communications, marketing and optional analytics; and
content and documents of a person using Lucanto for private purposes.
2.2 We are processor when a business customer determines the purposes for personal data in documents, records and other workspace content. The customer is then controller and the DPA applies. This Notice still applies to account, contract, payment, security and communication data we process for our own purposes.
2.3 If you use Lucanto for another organisation, that organisation should explain its processing of workspace content. We forward relevant requests or help it respond.
3. Data we process
Depending on use, we may process:
identity and contact data: name, email, telephone, job title and login identifier;
account and workspace data: role, permission, membership, settings, language, and history of consent and accepted terms;
external sign-in data: provider, provider user identifier, email, name, profile photo and an Apple relay email where selected, within the scope you authorise;
business and billing data: business name, company/tax/VAT identifiers, registered and billing address, country and data needed to determine VAT;
document content: invoices, receipts, attachments, photographs and data within them, such as names, addresses, signatures, identifiers, items, amounts, dates, IBAN and other financial data about counterparties, staff or customers;
AI extraction data: a document or relevant part submitted for extraction, prompt/instruction, extracted fields, corrections, status and technical request identifiers;
payment metadata: Stripe customer and payment identifiers, status, amount, currency, date, method type and final digits; Stripe processes full card details;
bank data: for an activated Tatra banka PSD2 connection, account identifier/IBAN, currency, balance, transactions, counterparties, amounts, dates, messages and bank-authorisation state;
communication, email and support data: messages, attachments, addressee, delivery, unsubscribe, requests, feedback and resolution records;
bug-report and observability data: reporter name/email, legal workspace name, company ID, failed-AI-extraction metadata, internal user/workspace IDs, stack trace, request path, time and technical error data; for optional session replay, visited screens, clicks and interface changes; sensitive fields and documents are to be masked or excluded, and a document is sent to a ticket only on the User's separate instruction;
technical, device and security data: IP, TLS fingerprint, user-agent, browser, operating system, access time and URL, request headers, referrer, Turnstile sitekey/origin and token, audit events, error and security logs;
logo data: counterparty name or domain, IP and technical Logo.dev request data;
cookie and analytics data: identifiers, sessions, language, pseudonymised user/workspace identifier and product events only where you consent to optional analytics; and
integration and external-resource data: identifiers/content needed for a connection and IP, user-agent, referrer and requested URL when Google Fonts, jsDelivr or unpkg loads directly.
We do not intentionally request special-category data. A document may nevertheless contain it. Do not upload such data unless necessary and supported by an appropriate legal basis and safeguards.
4. Data sources
We obtain data from you, your workspace administrator, documents and integrations uploaded or activated by a user, automatically from devices and Service use, from Google or Apple when selected for sign-in, from Tatra banka for an activated PSD2 connection, from Stripe during payment, and from public or commercial sources for lawful B2B outreach and business verification. Where we are processor, the business customer determines the original source and lawful collection.
5. Purposes, legal bases and retention
We do not ask for blanket consent. Necessary processing relies on contract, legal obligation or legitimate interest. Marketing and optional cookie analytics rely on separate consent unless law permits a specific communication on another basis.
Purpose
Data
Legal basis when we are controller
Typical period
Registration, authentication, account, workspace and features
identity, contact, account, business, technical, private-user content
contract; pre-contract steps
account duration; Customer Content erased within 45 days after deletion
Google or Apple sign-in
| external ID, email, name, photo/relay address, authentication token
contract at your request; legitimate security interest
while linked; tokens revoked or erased when no longer needed
OpenAI automated document extraction
document, AI input/output, technical identifiers
contract for private user; business-customer instructions under DPA
in Lucanto for the content lifecycle; under standard settings, OpenAI abuse-monitoring logs for up to 30 days, and longer only where required by law or reasonably necessary to protect OpenAI's services or third parties from harm
Tatra banka PSD2 connection
IBAN/account, balance, transactions, counterparties, authorisation and technical identifiers
contract; legal obligation
contract term and limitation period; accounting and tax records generally 10 years or another statutory period
| Subscription, payments, VAT, invoices and accounting
account, business, billing, payment metadata
contract; legal obligation
contract term and limitation period; accounting and tax records generally 10 years or another statutory period
Cloudflare proxy/CDN and Turnstile security, fraud prevention and audit
account, IP, TLS fingerprint, user-agent, URL/headers, origin/sitekey, token, logs, payment status
legitimate interest in secure/available Service; necessary technology; law
our routine security logs for up to 12 months; longer only while handling an incident, legal claim or legal duty; Turnstile tokens expire after 5 minutes
Hosting, production database, storage and operation
application records and PostgreSQL databases at Render, including application data, cache, job queues and realtime messages; attachments in Hetzner Object Storage
contract; legitimate interest in availability and security
Customer Content is erased within 45 days after account or Service deletion; technical backups follow the same cycle unless law requires a specific record
Server-side logging, monitoring and backend error reporting through Render and Better Stack
IP address, request ID, internal user/workspace IDs, path without query string, status, time, stack trace, error and security events; excluding passwords, tokens, cookies, full payment details and document content
legitimate interest in security, stability, diagnosis and legal claims
routine logs and error records for up to 12 months; longer only for a specific incident, claim or legal duty
Optional Better Stack browser monitoring and session replay
cookie/local session identifier, pseudonymised internal user/workspace IDs, frontend errors, visited screens, clicks, interface changes and device; sensitive inputs and documents are masked or excluded
consent
session replays for up to 90 days; new collection stops on withdrawal
Support, bug reports and Service communication
contact/account, workspace name/company ID, messages, attachments, extraction metadata
contract; legitimate interest in response, bug correction and evidence
account duration and generally 3 years after ticket/account closure; technical metadata shorter where possible, longer for dispute
Transactional/service email through Resend
name, email, language, account/plan state, security/contract message, delivery state
contract; legal obligation; legitimate delivery interest
message content and delivery records for up to 3 years after sending; longer only for a legal claim or legal duty
Necessary service, legal and subprocessor notices
name, email, account, role
contract; law; legitimate interest
account/contract duration and time needed to evidence delivery
Marketing email through Loops
name, email, business, preference and sequences
consent; only where law permits a specific existing-customer message with easy opt-out
until withdrawal, objection or generally 24 months inactivity; suppression record reasonably longer
Counterparty logo through Logo.dev
counterparty name/domain, IP and technical data
technical data | contract; legitimate interest in clear interface
Logo.dev DPA/log period; in Lucanto with relevant record
Optional site/product analytics through Google Tag Manager-managed tags
cookie IDs, IP/derived location, device, pseudonymised user/workspace ID, language and product events
consent
up to 24 months or a shorter period stated for the particular analytics tool; new collection stops on withdrawal
Technical libraries and fonts
IP, user-agent, referrer, requested URL
legitimate interest only where a direct external request is necessary and proportionate
Lucanto keeps no separate copy of the CDN request; the provider keeps technical logs under its published retention policy
Legal claims and compliance
relevant data above
legitimate interest; law
applicable limitation or statutory period
AI processing and human review
6.1 Lucanto sends uploaded documents or relevant parts to the OpenAI API for automated recognition and structuring. The User can correct the result before saving. AI may make mistakes; do not use output without checking it for accounting, tax, payment or legal decisions.
6.2 For EEA customers, OpenAI Ireland Ltd. provides the API Services. OpenAI acts as processor or subprocessor for API data and, under its business terms, does not train or improve its models on these inputs and outputs by default.
6.3 We use the standard OpenAI API retention setting. OpenAI may retain input and output content and related technical data in abuse-monitoring logs for up to 30 days, and longer only where law requires or where reasonably necessary to protect OpenAI's services or third parties from harm. OpenAI processing is not restricted exclusively to the EEA. Transfers outside the EEA rely on an adequacy decision or EU Standard Contractual Clauses.
6.4 We do not make decisions based solely on automated processing that have legal or similarly significant effects on a person. AI extraction is human-reviewed input, not a decision about a person.
7. Recipients and providers
We disclose data only as necessary. A provider can be our processor for one activity and an independent controller for another. The current recipient and provider list appears directly below. A provider that processes Customer Personal Data on Stark Codes' behalf for the business Service is additionally listed as a Subprocessor in DPA Annex 3.
This Article also serves as Lucanto's public provider register. We do not operate a separate register page.
Provider
Typical role and purpose
**OpenAI Ireland Ltd. and approved subprocessors
processor/subprocessor for AI document extraction
**Plus Five Five, Inc. (Resend)
processor for transactional/service email and delivery information |
Astrodon Corporation (Loops)
processor for consented or otherwise permitted marketing email and sequences
Stripe Payments Europe, Limited and relevant Stripe companies
processor for technical payment handling; independent controller for regulated payments, KYC, fraud and compliance
Cloudflare, Inc. a príslušné spoločnosti Cloudflare
application hosting and managed PostgreSQL databases; stores application records and technical databases used for cache, job queues and realtime communication and provides operational database backups
Render Services, Inc.
application hosting and managed PostgreSQL databases; stores application records and technical databases used for cache, job queues and realtime communication and provides operational database backups
Hetzner Online GmbH
S3-compatible Object Storage in the EU (Germany or Finland) for attachments including invoices, receipts and contracts
Better Stack, Inc.
server-side operating logs including IP and internal identifiers, backend errors and diagnostics on legitimate interests; its browser tag, frontend monitoring and session replay start only after analytics consent, with sensitive fields and documents masked or excluded
Linear Orbit, Inc.
bug reports/tasks: reporter name/email, workspace legal name/company ID and failed-AI-extraction metadata
Google Ireland Limited / Google LLC
Google OAuth (email/profile/name/photo); Google Tag Manager for tag management and, only after consent, tags that transmit analytics; Google Fonts on pages where fonts load directly from Google
Apple Distribution International Ltd. and relevant Apple group companies
Sign in with Apple: unique ID, email/relay and optional name; Apple follows its own privacy terms
Tatra banka, a.s.
PSD2 bank connection: IBAN/account, balance and transactions; typically independent controller for banking/regulatory purposes
Simple Casual, LLC (Logo.dev)
counterparty name/domain, IP and technical data to retrieve a logo; processor under its DPA
Volentio JSD Limited (jsDelivr) and CDN suppliers
direct library loading; IP, browser, referrer and requested URL
UNPKG delivered through Cloudflare's global edge network
direct library loading; IP, browser, referrer and requested URL
We may also disclose data to professional advisers under confidentiality, public authorities where law requires, or an acquirer in a reorganisation or business sale with appropriate safeguards.
8. International transfers
Some providers or their suppliers are based or process outside the EEA, particularly in the United States. We use a GDPR Chapter V mechanism: an European Commission adequacy decision, including the EU–U.S. Data Privacy Framework where applicable to the recipient and transfer, or EU Standard Contractual Clauses with supplementary measures where needed. On request we provide information about the specific mechanism or relevant safeguards, subject to protection of trade secrets.
Product development occurs in the EU, and attachments in Hetzner Object Storage are stored in the EU. Lucanto is not an EU-only processing service. OpenAI, Resend, Loops, Stripe, Cloudflare, Render, Better Stack, Linear, Google, Apple, Logo.dev, jsDelivr and UNPKG or their published suppliers may process data outside the EEA under those safeguards.
9. Cookies and similar technologies
We use necessary cookies and local storage for authentication, Cloudflare/Turnstile security, settings and recording consent choice without consent where essential. Google Tag Manager is a tag-management tool: values in the local
dataLayerare not sent to Google unless a configured tag transmits them. The external GTM container, tags that transmit optional analytics or marketing, and the entire Better Stack browser tag load only after analytics consent. Without consent,user_id,workspace_id, language and product events must not be transmitted for analytics or marketing, and Better Stack must not create its_bscookie or local identifier in the browser. Server-side logs and backend technical error reporting may remain active on legitimate interests with minimised data. Withdraw through Cookie Settings as easily as you consented. See the Cookie Policy.10. Retention and erasure
10.1 We keep data only for the section 5 period or as necessary for the purpose, considering its nature, risk, contract duration, statutory periods and the need to evidence claims.
10.2 After account deletion or Service termination, we erase Customer Content from active systems and backups within 45 days, unless law requires a specific record. Backups are isolated during the rotation cycle and not used in ordinary operations. If a backup is restored, applicable deletion requests are re-applied.
10.3 We do not erase records we must retain as controller, such as tax and accounting documents, evidence of consent or Terms acceptance, payment, claim or incident records. We limit them to what is necessary, separate them from active Customer Content, and erase or anonymise when the need ends.
11. Security
We use risk-appropriate measures including access and role controls, multi-factor access to privileged systems, encryption in transit, appropriate encryption at rest, backup and recovery, logging, vulnerability management, incident handling, staff confidentiality and provider review. More detail for B2B customers is in DPA Annex 2.
12. Your rights
Subject to GDPR conditions, you may:
obtain confirmation and access;
correct inaccurate or complete incomplete data;
request erasure;
restrict processing;
receive data you provided in portable form where applicable;
object to legitimate-interest processing;
withdraw consent at any time without affecting earlier lawfulness; and
not be subject to a solely automated decision with legal or similarly significant effects unless a legal exception applies.
Contact hello@lucanto.eu. We may reasonably verify identity. We normally respond within one month and may extend for complexity under GDPR with an explanation. If your employer or another business customer controls the data, contact it first; we help at its instruction.
You may complain to the Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava 27, dataprotection.gov.sk, or a supervisory authority in your habitual residence or workplace. We welcome the opportunity to resolve the issue first.
13. Marketing
Marketing consent is separate, voluntary and unticked by default. Withdraw through the message link or settings. Opting out does not stop necessary service messages such as payment confirmations, security alerts, legal changes or trial expiry.
Where law permits B2B outreach without consent based on legitimate interests, each message identifies the source or source category and offers an easy objection. We honour direct-marketing objections without further balancing.
14. Children
The Service is not intended for anyone under 18. If we learn that we obtained such data without a valid basis, we erase it.
15. Changes to this Notice
We notify existing Users of a material change by email or persistent in-Service notice at least 14 days in advance unless law or urgent security requires sooner. We show the updated date above. Where new consent is needed, we ask for it; silence or continued use is not consent.