Privacy Policy
Last updated: 27 July 2026
This policy explains what Lumea does with personal information — both the details of the businesses that subscribe to it, and the client records those businesses keep inside it. It describes how the product actually works, not how software of this kind usually works.
Two different roles
Lumea is operated by CSystems Ltd. It plays two distinct roles, and the difference decides who answers a request about data.
For a business's own account — the owner's name, email, phone, chosen plan and billing — Lumea is the controller. Ask us directly.
For everything a business enters about its own clients — names, phone numbers, appointments, invoices, messages, photos — the business is the controller and Lumea only processes that data on its instructions. A client of a salon should therefore contact the salon; we act only on the salon's instruction, and we do not use its client list for our own purposes.
What is collected
Business account: name, email address, phone number, business name, tax identifiers, address, subscription plan and team members' names and roles.
Client records entered by the business: name, phone, email, national ID number where the business chooses to record it, notes, appointment and purchase history, account balance, memberships and gift cards.
Financial documents: invoices, receipts and credit notes, including the amounts, the payer's details and the tax numbers printed on them. Once issued these are frozen and, by law, cannot be edited or deleted.
Messages: WhatsApp and SMS sent and received through Lumea, along with any attached images or files.
Images uploaded by the business: logos, service photos, portfolio pictures and client photos.
Technical data needed to run the service: sign-in sessions, the language, regional date format and theme you chose, and server logs of errors and requests.
What it is used for
Running the product: showing calendars, booking appointments, issuing documents, sending reminders and keeping balances correct.
Sending the messages a business asks to be sent — appointment reminders, confirmations and replies in a conversation the client started.
Keeping accounts secure and supporting them when something goes wrong.
Meeting bookkeeping and tax obligations that apply to issued financial documents.
Lumea does not sell personal data, does not share it with advertisers, and does not use client records to train models.
Why we are allowed to process it
Performance of a contract — providing the service a business subscribed to.
Legal obligation — retaining issued tax documents for the period the law requires.
Legitimate interests — keeping the service secure, preventing abuse and diagnosing faults.
Consent — where a business asks its clients for consent before marketing to them. Obtaining that consent is the business's responsibility.
Who else sees it
Only the processors needed to deliver the product, and only the data each of them needs:
019SMS — the gateway that delivers SMS. It receives the recipient's phone number and the message text.
Meta (WhatsApp Business Cloud API) — used when a business connects WhatsApp. It receives the recipient's phone number, the message and any attachment.
Google — only if a team member connects Google Calendar, and then only the appointment times and titles that sync.
The hosting provider that runs the servers and storage.
We also disclose data where a binding legal order requires it. We do not transfer data to anyone else.
How long it is kept
Client records, appointments and messages are kept while the business's account is active, and are deleted when the business deletes them or closes the account.
Issued invoices and receipts are kept for as long as tax law requires them to be kept, even after an account closes. They cannot be deleted before then — that immutability is enforced by the database itself.
Server logs are kept for a short operational period and then discarded.
How it is protected
Each business gets its own separate database, so one account's queries cannot reach another's data.
Uploaded files — logos, photos, PDFs — live in a private storage bucket per business, with no public URL. Every download is served through the application after checking the session.
Database credentials are encrypted at rest and never sent to the browser.
Sessions are signed cookies, marked HttpOnly and SameSite, and passwords are stored only as salted hashes.
No system is perfectly secure, and we do not claim otherwise. If a breach affects personal data we will notify the affected businesses and the regulator as the law requires.
Your rights
You may ask to see the personal data held about you, to correct it, to delete it, to receive a copy in a portable format, or to object to a particular use.
If you are a business subscribing to Lumea, write to us at the address below.
If you are a client of a business that uses Lumea, contact that business — it holds the record and decides what happens to it. If you cannot reach them, write to us and we will help you make contact.
You may also complain to your data protection authority. In Israel this is the Privacy Protection Authority.
Cookies
Lumea sets only the cookies it needs to work: one that keeps you signed in, and small preferences for your language, regional date format and light or dark theme.
There are no advertising cookies and no third-party tracking, which is why the site does not ask you to accept any.
Children
Lumea is a tool for businesses and is not directed at children. A business may record an appointment for a minor; where it does, the business is responsible for obtaining a parent's or guardian's consent.
Where the data is held
Data is stored on servers in the region chosen for the deployment. Where a processor listed above operates outside that region — Meta and Google in particular — the transfer relies on the safeguards those providers offer under applicable law.
Changes to this policy
If this policy changes, the date at the top changes with it, and significant changes are announced inside the product before they take effect.
Contact
Questions about this policy, or a request about your data, can be sent to the controller:
CSystems Ltd
info@csystems.co.il
Hagai 113a, Har Adar 9083600, Israel
info@csystems.co.il