This Privacy Policy explains how luca.ecosystem ("we", "us", "our") collects, uses, stores, and protects your personal data when you use lucAI and related services (the "Service"). We are committed to protecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Romanian Law No. 363/2018 on the protection of natural persons with regard to the processing of personal data, and other applicable data protection legislation.
By using the Service, you acknowledge that you have read and understood this Privacy Policy.
The data controller responsible for your personal data is:
| Field | Detail |
|---|---|
| Data Controller | Luca, operating under luca.ecosystem |
| Legal Representative | Parent/legal guardian of Luca (available upon request) |
| Contact Form | |
| Country | Romania (EU Member State) |
As Luca is a minor under Romanian law, a parent or legal guardian acts as co-controller and legal representative for data protection purposes. You may contact our legal representative via the contact form (select "Privacy / Data Protection Request").
We collect and process the following categories of personal data:
| Purpose | Legal Basis (GDPR Art. 6) |
|---|---|
| Account creation and authentication | Art. 6(1)(b) — Performance of a contract |
| Processing AI messages and generating responses | Art. 6(1)(b) — Performance of a contract |
| Knowledge base storage and retrieval | Art. 6(1)(b) — Performance of a contract |
| Rate limiting and abuse prevention | Art. 6(1)(f) — Legitimate interest |
| Service improvement and analytics | Art. 6(1)(f) — Legitimate interest |
| Marketplace tool publishing and attribution | Art. 6(1)(b) — Performance of a contract |
| Security monitoring and incident response | Art. 6(1)(f) — Legitimate interest |
| Compliance with legal obligations | Art. 6(1)(c) — Legal obligation |
In accordance with the EU AI Act (Regulation (EU) 2024/1689), we inform you that:
We share your data with the following third-party sub-processors who assist in providing the Service:
| Sub-processor | Purpose | Location | DPA |
|---|---|---|---|
| Cloudflare, Inc. | Hosting (Workers, D1, KV, Pages), CDN, DDoS protection | United States / Global Edge | Cloudflare DPA |
| Groq, Inc. | AI inference (large language model processing) | United States | Groq Terms of Service |
Both Cloudflare and Groq are certified under the EU-US Data Privacy Framework. Cloudflare additionally incorporates Standard Contractual Clauses (SCCs) as a fallback transfer mechanism.
Your data may be transferred to and processed in countries outside the European Economic Area (EEA), specifically the United States, where our sub-processors operate. We ensure adequate protection through:
| Data Type | Retention Period |
|---|---|
| Account data (email, password hash, display name) | While account is active + 30 days after deletion |
| Session tokens | Up to 30 days; rotated on use |
| Knowledge base content | While account is active + 30 days after deletion |
| Rate limit counters | 24 hours (auto-expire) |
| Published marketplace tools | Retained until developer requests removal |
AI conversation messages are processed in real-time and not stored permanently on our servers. Messages may temporarily reside in memory during active sessions only.
Under the GDPR and Romanian data protection law, you have the following rights:
To exercise any of these rights, use our contact form (select "Privacy / Data Protection Request"). We will respond within 30 days (extendable to 60 days for complex requests, with notification).
If you believe your data protection rights have been violated, you have the right to lodge a complaint with:
| Authority | Detail |
|---|---|
| Supervisory Authority | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) |
| Website | www.dataprotection.ro |
| anspdcp@dataprotection.ro |
The Service is intended for users aged 16 and above. We do not knowingly collect personal data from children under 16. If we become aware that a child under 16 has provided us with personal data, we will take steps to delete such information promptly.
Users under the age of 16 must obtain parental or guardian consent before using the Service.
We implement appropriate technical and organizational measures to protect your personal data, including:
The Service uses localStorage for essential functionality (authentication tokens, UI preferences). We do not use tracking cookies, advertising cookies, or third-party analytics services that set cookies.
Cloudflare may set essential security and performance cookies as part of its CDN and DDoS protection services.
We may update this Privacy Policy from time to time. Material changes will be communicated via the Service or by email (if you have provided an email address). Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
For any questions about this Privacy Policy or to exercise your data protection rights:
| Contact Form | |
| Subject line | "Data Protection Request — [your request type]" |
We aim to acknowledge all requests within 3 business days and provide a substantive response within 30 calendar days.