Privacy Notice
Last updated: 2026-07-29
1. Controller and contact
The controller described in this Notice is Stark Codes, s. r. o., Holíčska 3043/13, 851 05 Bratislava – mestská časť Petržalka, Slovak Republic, Company ID 51 414 546, Tax ID 2120683730, VAT ID SK2120683730, registered in the Commercial Register of Municipal Court Bratislava III, section Sro, file 126116/B ("Stark Codes", "Lucanto", "we"). Privacy contact: hello@lucanto.eu.
This Notice explains processing when you visit lucanto.eu, create an account, use app.lucanto.eu privately or for business, pay, communicate with us, or receive marketing.
2. When we are controller and processor
2.1 We are controller when we determine the purposes and means, especially for:
- registration and management of accounts, users and workspaces;
- billing, payment, fraud prevention and legal obligations;
- security, operation, support and improvement of the Service;
- communications, marketing and optional analytics; and
- content and documents of a person using Lucanto for private purposes.
2.2 We are processor when a business customer determines the purposes for personal data in documents, records and other workspace content. The customer is then controller and the DPA applies. This Notice still applies to account, contract, payment, security and communication data we process for our own purposes.
2.3 If you use Lucanto for another organisation, that organisation should explain its processing of workspace content. We forward relevant requests or help it respond.
3. Data we process
Depending on use, we may process:
- identity and contact data: name, email, telephone, job title and login identifier;
- account and workspace data: role, permission, membership, settings, language, and history of consent and accepted terms;
- external sign-in data: provider, provider user identifier, email, name, profile photo and an Apple relay email where selected, within the scope you authorise;
- business and billing data: business name, company/tax/VAT identifiers, registered and billing address, country and data needed to determine VAT;
- document content: invoices, receipts, attachments, photographs and data within them, such as names, addresses, signatures, identifiers, items, amounts, dates, IBAN and other financial data about counterparties, staff or customers;
- AI extraction data: a document or relevant part submitted for extraction, prompt/instruction, extracted fields, corrections, status and technical request identifiers;
- payment metadata: Stripe customer and payment identifiers, status, amount, currency, date, method type and final digits; Stripe processes full card details;
- bank data: for an activated Tatra banka PSD2 connection, account identifier/IBAN, currency, balance, transactions, counterparties, amounts, dates, messages and bank-authorisation state;
- communication, email and support data: messages, attachments, addressee, delivery, unsubscribe, requests, feedback and resolution records;
- bug-report and observability data: reporter name/email, legal workspace name, company ID, failed-AI-extraction metadata, internal user/workspace IDs, stack trace, request path, time and technical error data; for optional session replay, visited screens, clicks and interface changes; sensitive fields and documents are to be masked or excluded, and a document is sent to a ticket only on the User's separate instruction;
- technical, device and security data: IP, TLS fingerprint, user-agent, browser, operating system, access time and URL, request headers, referrer, Turnstile sitekey/origin and token, audit events, error and security logs;
- logo data: counterparty name or domain, IP and technical Logo.dev request data;
- cookie and analytics data: identifiers, sessions, language, pseudonymised user/workspace identifier and product events only where you consent to optional analytics; and
- integration and external-resource data: identifiers/content needed for a connection and IP, user-agent, referrer and requested URL when Google Fonts, jsDelivr or unpkg loads directly.
We do not intentionally request special-category data. A document may nevertheless contain it. Do not upload such data unless necessary and supported by an appropriate legal basis and safeguards.
4. Data sources
We obtain data from you, your workspace administrator, documents and integrations uploaded or activated by a user, automatically from devices and Service use, from Google or Apple when selected for sign-in, from Tatra banka for an activated PSD2 connection, from Stripe during payment, and from public or commercial sources for lawful B2B outreach and business verification. Where we are processor, the business customer determines the original source and lawful collection.
5. Purposes, legal bases and retention
We do not ask for blanket consent. Necessary processing relies on contract, legal obligation or legitimate interest. Marketing and optional cookie analytics rely on separate consent unless law permits a specific communication on another basis.
| Purpose | Data | Legal basis when we are controller | Typical period |
|---|---|---|---|
| Registration, authentication, account, workspace and features | identity, contact, account, business, technical, private-user content | contract; pre-contract steps | account duration; Customer Content erased within 45 days after deletion |
| Google or Apple sign-in | external ID, email, name, photo/relay address, authentication token | contract at your request; legitimate security interest | while linked; tokens revoked or erased when no longer needed |
| OpenAI automated document extraction | document, AI input/output, technical identifiers | contract for private user; business-customer instructions under DPA | in Lucanto for the content lifecycle; under standard settings, OpenAI abuse-monitoring logs for up to 30 days, and longer only where required by law or reasonably necessary to protect OpenAI's services or third parties from harm |
| Tatra banka PSD2 connection | IBAN/account, balance, transactions, counterparties, authorisation and technical identifiers | contract; legal obligation | contract term and limitation period; accounting and tax records generally 10 years or another statutory period |
| Subscription, payments, VAT, invoices and accounting | account, business, billing, payment metadata | contract; legal obligation | contract term and limitation period; accounting and tax records generally 10 years or another statutory period |
| Cloudflare proxy/CDN and Turnstile security, fraud prevention and audit | account, IP, TLS fingerprint, user-agent, URL/headers, origin/sitekey, token, logs, payment status | legitimate interest in secure/available Service; necessary technology; law | our routine security logs for up to 12 months; longer only while handling an incident, legal claim or legal duty; Turnstile tokens expire after 5 minutes |
| Hosting, production database, storage and operation | application records and PostgreSQL databases at Render, including application data, cache, job queues and realtime messages; attachments in Hetzner Object Storage | contract; legitimate interest in availability and security | Customer Content is erased within 45 days after account or Service deletion; technical backups follow the same cycle unless law requires a specific record |
| Server-side logging, monitoring and backend error reporting through Render and Better Stack | IP address, request ID, internal user/workspace IDs, path without query string, status, time, stack trace, error and security events; excluding passwords, tokens, cookies, full payment details and document content | legitimate interest in security, stability, diagnosis and legal claims | routine logs and error records for up to 12 months; longer only for a specific incident, claim or legal duty |
| Optional Better Stack browser monitoring and session replay | cookie/local session identifier, pseudonymised internal user/workspace IDs, frontend errors, visited screens, clicks, interface changes and device; sensitive inputs and documents are masked or excluded | consent | session replays for up to 90 days; new collection stops on withdrawal |
| Support, bug reports and Service communication | contact/account, workspace name/company ID, messages, attachments, extraction metadata | contract; legitimate interest in response, bug correction and evidence | account duration and generally 3 years after ticket/account closure; technical metadata shorter where possible, longer for dispute |
| Transactional/service email through Resend | name, email, language, account/plan state, security/contract message, delivery state | contract; legal obligation; legitimate delivery interest | message content and delivery records for up to 3 years after sending; longer only for a legal claim or legal duty |
| Necessary service, legal and subprocessor notices | name, email, account, role | contract; law; legitimate interest | account/contract duration and time needed to evidence delivery |
| Marketing email through Loops | name, email, business, preference and sequences | consent; only where law permits a specific existing-customer message with easy opt-out | until withdrawal, objection or generally 24 months inactivity; suppression record reasonably longer |
| Counterparty logo through Logo.dev | counterparty name/domain, IP and technical data | contract; legitimate interest in clear interface | Logo.dev DPA/log period; in Lucanto with relevant record |
| Optional site/product analytics through Google Tag Manager-managed tags | cookie IDs, IP/derived location, device, pseudonymised user/workspace ID, language and product events | consent | up to 24 months or a shorter period stated for the particular analytics tool; new collection stops on withdrawal |
| Technical libraries and fonts | IP, user-agent, referrer, requested URL | legitimate interest only where a direct external request is necessary and proportionate | Lucanto keeps no separate copy of the CDN request; the provider keeps technical logs under its published retention policy |
| Legal claims and compliance | relevant data above | legitimate interest; law | applicable limitation or statutory period |
If we need personal data to conclude or perform a contract or by law and you do not provide it, we may be unable to create an account, accept a payment or provide the affected feature. Marketing and analytics consent is voluntary and declining it does not restrict the core Service.
6. AI processing and human review
6.1 Lucanto sends uploaded documents or relevant parts to the OpenAI API for automated recognition and structuring. The User can correct the result before saving. AI may make mistakes; do not use output without checking it for accounting, tax, payment or legal decisions.
6.2 For EEA customers, OpenAI Ireland Ltd. provides the API Services. OpenAI acts as processor or subprocessor for API data and, under its business terms, does not train or improve its models on these inputs and outputs by default.
6.3 We use the standard OpenAI API retention setting. OpenAI may retain input and output content and related technical data in abuse-monitoring logs for up to 30 days, and longer only where law requires or where reasonably necessary to protect OpenAI's services or third parties from harm. OpenAI processing is not restricted exclusively to the EEA. Transfers outside the EEA rely on an adequacy decision or EU Standard Contractual Clauses.
6.4 We do not make decisions based solely on automated processing that have legal or similarly significant effects on a person. AI extraction is human-reviewed input, not a decision about a person.
7. Recipients and providers
We disclose data only as necessary. A provider can be our processor for one activity and an independent controller for another. The current recipient and provider list appears directly below. A provider that processes Customer Personal Data on Stark Codes' behalf for the business Service is additionally listed as a Subprocessor in DPA Annex 3.
This Article also serves as Lucanto's public provider register. We do not operate a separate register page.
| Provider | Typical role and purpose |
|---|---|
| OpenAI Ireland Ltd. and approved subprocessors | processor/subprocessor for AI document extraction |
| Plus Five Five, Inc. (Resend) | processor for transactional/service email and delivery information |
| Astrodon Corporation (Loops) | processor for consented or otherwise permitted marketing email and sequences |
| Stripe Payments Europe, Limited and relevant Stripe companies | processor for technical payment handling; independent controller for regulated payments, KYC, fraud and compliance |
| Cloudflare, Inc. and relevant Cloudflare companies | reverse proxy/CDN, security, DDoS protection and Turnstile; processor for Turnstile, independent controller when improving bot detection |
| Render Services, Inc. | application hosting and managed PostgreSQL databases; stores application records and technical databases used for cache, job queues and realtime communication and provides operational database backups |
| Hetzner Online GmbH | S3-compatible Object Storage in the EU (Germany or Finland) for attachments including invoices, receipts and contracts |
| Better Stack, Inc. | server-side operating logs including IP and internal identifiers, backend errors and diagnostics on legitimate interests; its browser tag, frontend monitoring and session replay start only after analytics consent, with sensitive fields and documents masked or excluded |
| Linear Orbit, Inc. | bug reports/tasks: reporter name/email, workspace legal name/company ID and failed-AI-extraction metadata |
| Google Ireland Limited / Google LLC | Google OAuth (email/profile/name/photo); Google Tag Manager for tag management and, only after consent, tags that transmit analytics; Google Fonts on pages where fonts load directly from Google |
| Apple Distribution International Ltd. and relevant Apple group companies | Sign in with Apple: unique ID, email/relay and optional name; Apple follows its own privacy terms |
| Tatra banka, a.s. | PSD2 bank connection: IBAN/account, balance and transactions; typically independent controller for banking/regulatory purposes |
| Simple Casual, LLC (Logo.dev) | counterparty name/domain, IP and technical data to retrieve a logo; processor under its DPA |
| Volentio JSD Limited (jsDelivr) and CDN suppliers | direct library loading; IP, browser, referrer and requested URL |
| UNPKG delivered through Cloudflare's global edge network | direct library loading; IP, browser, referrer and requested URL |
We may also disclose data to professional advisers under confidentiality, public authorities where law requires, or an acquirer in a reorganisation or business sale with appropriate safeguards.
8. International transfers
Some providers or their suppliers are based or process outside the EEA, particularly in the United States. We use a GDPR Chapter V mechanism: an European Commission adequacy decision, including the EU–U.S. Data Privacy Framework where applicable to the recipient and transfer, or EU Standard Contractual Clauses with supplementary measures where needed. On request we provide information about the specific mechanism or relevant safeguards, subject to protection of trade secrets.
Product development occurs in the EU, and attachments in Hetzner Object Storage are stored in the EU. Lucanto is not an EU-only processing service. OpenAI, Resend, Loops, Stripe, Cloudflare, Render, Better Stack, Linear, Google, Apple, Logo.dev, jsDelivr and UNPKG or their published suppliers may process data outside the EEA under those safeguards.
9. Cookies and similar technologies
We use necessary cookies and local storage for authentication, Cloudflare/Turnstile security, settings and recording consent choice without consent where essential. Google Tag Manager is a tag-management tool: values in the local dataLayer are not sent to Google unless a configured tag transmits them. The external GTM container, tags that transmit optional analytics or marketing, and the entire Better Stack browser tag load only after analytics consent. Without consent, user_id, workspace_id, language and product events must not be transmitted for analytics or marketing, and Better Stack must not create its _bs cookie or local identifier in the browser. Server-side logs and backend technical error reporting may remain active on legitimate interests with minimised data. Withdraw through Cookie Settings as easily as you consented. See the Cookie Policy.
10. Retention and erasure
10.1 We keep data only for the section 5 period or as necessary for the purpose, considering its nature, risk, contract duration, statutory periods and the need to evidence claims.
10.2 After account deletion or Service termination, we erase Customer Content from active systems and backups within 45 days, unless law requires a specific record. Backups are isolated during the rotation cycle and not used in ordinary operations. If a backup is restored, applicable deletion requests are re-applied.
10.3 We do not erase records we must retain as controller, such as tax and accounting documents, evidence of consent or Terms acceptance, payment, claim or incident records. We limit them to what is necessary, separate them from active Customer Content, and erase or anonymise when the need ends.
11. Security
We use risk-appropriate measures including access and role controls, multi-factor access to privileged systems, encryption in transit, appropriate encryption at rest, backup and recovery, logging, vulnerability management, incident handling, staff confidentiality and provider review. More detail for B2B customers is in DPA Annex 2.
12. Your rights
Subject to GDPR conditions, you may:
- obtain confirmation and access;
- correct inaccurate or complete incomplete data;
- request erasure;
- restrict processing;
- receive data you provided in portable form where applicable;
- object to legitimate-interest processing;
- withdraw consent at any time without affecting earlier lawfulness; and
- not be subject to a solely automated decision with legal or similarly significant effects unless a legal exception applies.
Contact hello@lucanto.eu. We may reasonably verify identity. We normally respond within one month and may extend for complexity under GDPR with an explanation. If your employer or another business customer controls the data, contact it first; we help at its instruction.
You may complain to the Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava 27, dataprotection.gov.sk, or a supervisory authority in your habitual residence or workplace. We welcome the opportunity to resolve the issue first.
13. Marketing
Marketing consent is separate, voluntary and unticked by default. Withdraw through the message link or settings. Opting out does not stop necessary service messages such as payment confirmations, security alerts, legal changes or trial expiry.
Where law permits B2B outreach without consent based on legitimate interests, each message identifies the source or source category and offers an easy objection. We honour direct-marketing objections without further balancing.
14. Children
The Service is not intended for anyone under 18. If we learn that we obtained such data without a valid basis, we erase it.
15. Changes to this Notice
We notify existing Users of a material change by email or persistent in-Service notice at least14 days in advance unless law or urgent security requires sooner. We show the updated date above. Where new consent is needed, we ask for it; silence or continued use is not consent.
Operated by: Stark Codes, s.r.o.