Legal
Privacy Policy
Last updated: 18 September 2026
1. Data Controller
The data controller responsible for data processing under the General Data Protection Regulation (GDPR) is: Regulumos GmbH Ravensberger Str. 20 33415 Verl Germany Email: privacy@compliancemadeineurope.eu
2. Purposes and Legal Bases for Data Processing
We process personal data in strict compliance with the principles of data minimization and purpose limitation.
2.1 Website Provision and Log Files
When you use our website, our hosting provider automatically collects information (IP address, browser type/version, operating system, referrer URL, time of request).
- Purpose: Ensuring proper operation and protection against cyberattacks.
- Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation).
2.2 Cookies and Local Storage
We use exclusively technically necessary mechanisms for local storage. We do not use non-essential analytics or tracking cookies.
- Google reCAPTCHA: Protection of our forms against automated misuse by setting the necessary _GRECAPTCHA cookie for risk analysis.
- Local Storage: Storage of cookie preferences (cmie_cookie_consent) and session language (i18nextLng).
- Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in IT security) and § 25(2) TDDDG (technical necessity).
2.3 LumosGPT – Sovereign Large Language Model (LLM)
We provide our B2B customers with LumosGPT, an EU-hosted large language model (LLM) solution. When using LumosGPT, we process the following categories of personal data:
- Processed Data: Your inputs (prompts) and outputs generated by the model (responses); session and interaction data (timestamps, session IDs, user IDs); usage metrics usage metrics (number of requests, input and output token consumption, models used, latency); communication protocols and error logs for operation and security; optional: content of uploaded documents (if you submit these for processing).
- Purposes: Provision of LLM services and answering your queries; ensuring system stability, performance monitoring, and troubleshooting; compliance with security and compliance requirements, in particular under the EU AI Act; audit and internal compliance controls; calculation of costs and billing based on actual usage; display of usage data (token consumption, model usage, request volume) on the customer-facing usage dashboard.
- Legal Basis: Art. 6(1)(b) GDPR (contract performance and provision of the LumosGPT service).
- Automated Decision-Making: Regulumos does not make automated decisions with legal effect based on LumosGPT usage. Should you use LumosGPT outputs for automated decision-making within your organization, you are responsible for such decisions as the data controller.
- No Use for AI Model Training: Your prompts, responses, and uploaded documents are processed exclusively via AWS Bedrock within private EU cloud environments. Anthropic and other model providers receive no access to your inputs or outputs at any time. Your data is not used or made accessible for the training, fine-tuning, or improvement of AI models — by Regulumos, AWS, Anthropic, or any other model provider. This is contractually guaranteed by the AWS Bedrock terms of service.
- Important Notice – AI-Generated Content: The responses generated by LumosGPT are the result of a statistical model and may contain inaccuracies, hallucinations, or incorrect information. Regulumos provides no warranties regarding the accuracy, completeness, or fitness of LumosGPT outputs for your purposes. You are responsible for verifying and validating all outputs before use.
- Storage Configuration by Customer Choice: The duration of storage of prompts and responses is determined by your contractual terms and configuration settings. By default, your active session context (conversation history, prompts, and responses) is stored in encrypted form for 12 months to enable a continuous user experience, and is then automatically deleted. You may agree with us on a shorter retention period or immediate deletion upon session termination.
- Audit and Compliance (EU AI Act): To comply with the requirements of the EU AI Act (2024/1689), we maintain audit logs (pseudonymized or aggregated) for 6 months to demonstrate safe and correct use of LumosGPT and to conduct internal compliance controls. These logs contain no sensitive prompt content, only metadata such as user ID, timestamp, and process class.
- Data Processing for B2B Customers: In providing LumosGPT, Regulumos acts as a data processor pursuant to Art. 28 GDPR on behalf of its B2B customers, who act as data controllers for the data entered by their employees. A Data Processing Agreement (DPA) in accordance with Art. 28 GDPR will be concluded with each B2B customer prior to the commencement of processing.
2.4 Newsletter and Marketing Communications
After explicit consent via double opt-in procedure, we use your email address to send you tailored updates. These include information on AI compliance, technological developments, and products and services of Regulumos GmbH.
- Legal Basis: Art. 6(1)(a) GDPR (consent). You may withdraw consent at any time with future effect.
2.5 B2B Customer and Contract Data
For our services, we collect name, business contact information, company details, and payment information.
- Purpose: Contract processing, invoicing, and service delivery.
- Legal Basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(c) GDPR (compliance with legal retention obligations).
2.6 Customer Preferences and Interaction Data
When you use our services, we process data regarding your business preferences, communication settings, and interactions with our services. This is to optimize our ongoing services for your specific business context.
- Legal Basis: Art. 6(1)(b) GDPR (contract performance).
3. Recipients and Data Processors
We engage specialized service providers (data processors) with whom we have concluded data processing agreements in accordance with Art. 28 GDPR:
- Amazon Web Services EMEA SARL: Hosting and infrastructure (including LumosGPT infrastructure).
- Google Ireland Limited: Provision of reCAPTCHA.
- Mollie B.V.: Payment processing for B2B services.
- Finom B.V.: Invoicing and banking.
4. Data Transfer to Third Countries
The entire LumosGPT infrastructure — including compute, database services, and model inference — is operated exclusively within the European Union by Amazon Web Services EMEA SARL (Luxembourg). No LumosGPT data is transferred to third countries. For other services used on this website (Google reCAPTCHA, operated by Google Ireland Limited), data may be transferred to the USA. This takes place on the basis of the European Commission's adequacy decision on the EU-US Data Privacy Framework and through the conclusion of Standard Contractual Clauses (SCCs) pursuant to Art. 46 GDPR.
5. Storage Duration and Data Deletion
We store personal data only as long as necessary for the stated purposes or to fulfill legal obligations:
- Server Logs: Automatic deletion typically after 7 to 14 days.
- LumosGPT – Audit and Compliance Logs: Pseudonymized or aggregated audit logs are retained for at least 6 months to comply with EU AI Act (2024/1689) requirements and conduct internal compliance controls, then automatically deleted.
- Newsletter and Marketing Data: Storage until withdrawal of consent. Records of consent are retained for a further 3 years to defend against legal claims.
- Paid Services and Consultations: Storage of result data and interaction data for the duration of the business relationship plus 3 years from the end of the calendar year (§ 195 BGB).
- Contract and Billing Data: Retention for 10 years in accordance with commercial and tax law requirements (§ 257 HGB, § 147 AO).
- Business Correspondence: Retention for 6 years (§ 257 HGB).
6. Your Rights
Under the GDPR, you have the following rights regarding your personal data: right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and withdrawal of consent (Art. 7(3)).
- Right to Object (Art. 21 GDPR): You have the right to object at any time, on grounds relating to your particular situation, to processing based on legitimate interests (Art. 6(1)(f) GDPR). You also have the absolute right to object at any time to processing for direct marketing purposes.
To exercise your rights, please send an email to: privacy@compliancemadeineurope.eu.
- Right to Lodge a Complaint: You also have the right to lodge a complaint with a data protection supervisory authority, for example with the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW).
7. Contact
For data protection-related inquiries, please send an email to: privacy@compliancemadeineurope.eu