Home › Security and data

Security and data: hosted in the EU, encrypted, GDPR-ready

A shield with a lock in front of servers in an EU data centre

Your invoices say who your clients are and what they pay you. This page explains where that data is stored, who can reach it and how to take it with you.

Where it is stored

Everything you put into Lumio is hosted in data centres in the EU: clients, invoices, payments and files. Nothing leaves the EU to be stored.

Encryption

It is encrypted in transit, between your browser and Lumio, and at rest, on our disks and in our backups. Staff access is limited to the people who need it to answer a support request.

GDPR and the data processing agreement

A signed data processing agreement is available on every paid plan; ask and we return it signed within 5 business days. To see, correct or delete personal information, write to privacy@lumio.example and we answer within 21 days.

Who else handles it

We never sell customer data. It is shared only with three kinds of sub-processor: the hosting provider, the card payment processor and the e-mail delivery service. A new sub-processor is announced 30 days before it is used.

Export and deletion

Export invoices, clients and payments as CSV and PDF at any time, on every plan. When an account is closed, everything in it is deleted after 60 days, except the invoice records that tax law makes us keep for 8 years.

Availability

We aim for 99.5 % availability each month. The commitments behind this page are in sections 6 and 8 of the terms of service, and you can reach the team through the contact page.