Privacy notice
Privacy notice
1. Controller and privacy contact
Lugh Innovation UG (haftungsbeschränkt), Waldhornstr. 44, 82110 Germering, represented by managing director Christian Meier. Please address privacy enquiries to kontakt@lugh.dev or call +49 (0)89 89 43 68-0.
2. Scope and roles
This notice covers our website, contact and support channels, LTC product and ordering pages, customer and technician portals, and management of our own customer relationships. For Lugh LTC customer instances, the respective customer is generally the controller for its operational content; Lugh Innovation processes this data as a processor within the agreed scope. Details are set out in a data processing agreement.
3. Data categories, purposes and legal bases
Depending on usage, we process master and contact data, company and tax master data, contract, product, payment and billing data, roles and permissions, user-uploaded content and documents, and technical usage, log, security and communication data. Legal bases include performance of contracts and pre-contractual measures, legal obligations, legitimate interests in secure and economical operations, and consent where expressly obtained.
4. Website, logs and strictly necessary cookies
When pages are accessed, data including IP address, time, destination, referrer, browser and device details is processed to deliver content, analyse errors and defend against attacks. Strictly necessary cookies support sessions, language, time zone, login, forms and abuse prevention. Analytics or marketing technologies are activated only after any required consent. Details are provided in the cookie notice.
5. Contact, support, feedback and roadmap
Contact details and messages are transferred to CRM or helpdesk for processing. Public contact is protected against automated abuse by a local arithmetic question and an invisible empty field; no external captcha provider is called. Support is reserved for signed-in customers. Bug reports and feature requests may be displayed across instances in pseudonymised form; confidential content, contact details and security information remain in protected processing areas.
6. LTC configuration, ordering and provisioning
For orders, we process package selection; the desired instance name, checked for uniqueness; company, owner, contact, address, tax, bank, accounting, language, region, usage, app, email and logo details. These are used to create prospect or customer records, a quotation or order and, following successful payment or approval, a provisioning request. Passwords and comparable secrets are not collected in the public order form but subsequently through protected self-service.
7. PayPal
If PayPal is selected, order and transaction data needed to initiate payment, check status, prevent fraud and allocate payments is transmitted to PayPal. PayPal also processes data as an independent controller; transfers to third countries may take place under safeguards described by PayPal. The PayPal privacy information also applies. A payment expressly labelled as sandbox is a test and does not result in a real charge.
8. LTC operations, monitoring and backups
Customer instances are operated with logical separation. To fulfil contracts, maintain security and manage capacity and usage-based billing, we process technical status, successful logins or active users, actual storage occupied including backups, availability, backup status, errors and security events. Encrypted backups follow the agreed retention schedule. Restoration requires two-stage confirmation and the appropriate permission; actions are logged in a traceable manner.
9. Recipients and processors
Access is limited to authorised employees and contractually engaged service providers where necessary for hosting, data centres, networks, email, backup, maintenance, support, development, payment processing or legal obligations. An up-to-date list of LTC subprocessors is provided to contract customers with the data processing agreement or on request.
10. Retention, export, termination and deletion
Data is retained for its specific purpose only as long as required by the contract, security, evidence or statutory retention requirements. Commercial and tax-relevant documents may generally need to be retained for up to ten years; data with shorter requirements is deleted when its purpose ceases. A customer-specifically encrypted export can be provided before the contract ends. Termination and instance deletion require double confirmation by the authorised owner, are logged and respect existing retention obligations. Documented recovery and re-delete safeguards prevent deleted tenants from being permanently reactivated from old backups.
11. Security
We use technical and organisational measures appropriate to the risk, including transport and backup encryption, separate administration networks, role-based permissions, multiple confirmations for critical actions, logging, monitoring, patching and recovery procedures. Absolute security cannot be guaranteed.
12. Data subject rights
Subject to statutory conditions, data subjects have rights of access, rectification, erasure, restriction, portability and objection. Consent may be withdrawn for the future. For data in a customer instance, please primarily contact the responsible customer organisation; we support it within our processor role.
13. Complaints and automated decisions
You may complain to a data protection supervisory authority. For a private-sector company based in Bavaria, the competent authority is generally the Bayerisches Landesamt für Datenschutzaufsicht, Promenade 18, 91522 Ansbach, www.lda.bayern.de. Through this website, Lugh Innovation does not make decisions based solely on automated processing that produce legal or similarly significant effects.
14. Changes
We update this notice when processes, service providers or the legal situation change. The version currently published applies.
Last updated: 5 August 2026.
Supplement: newsletter, AI chat, maps and privacy choices
English translation of the existing German notice. German original