Legal
Privacy Policy
How Lumero handles personal information.
Last updated: 25 July 2026
Data encrypted in transit & at rest
TLS in transit, AES at rest
Data stored in Australia
Google Cloud infrastructure
Tenant isolation
Organisation data isolated at app & database level
Confidentiality thresholds
Minimum number of responses required to report on small groups
The short version
Lumero is a reporting platform for employee surveys. Here's what you should know:
- Lumero is a reporting platform. We also offer a managed service where we run an employee survey for you through a third-party survey tool, under your instruction.
- Your data is your data. We use it to provide the reporting service you've paid for, and nothing else.
- We don't sell your information. Ever.
- We store your data in Australia, on Google Cloud infrastructure.
- We take confidentiality seriously, including built-in protections to prevent individual survey respondents from being identified in reports.
- Lumero is a New Zealand-based platform and operates under the New Zealand Privacy Act 2020. If your organisation is based in Australia, the Australian Privacy Act 1988 (Cth) also applies to how we handle your data.
The full policy below explains everything in more detail. If something isn't clear, email us at legal@lumero.works.
Two ways we work
The Lumero platform is a reporting tool only. It does not run surveys. When you use the platform, you bring your own employee survey data – collected through whatever tool you choose – and we provide the reporting on top of it. This is BYO (Bring Your Own) survey data mode, and it's how most clients use Lumero.
Separately, we also offer a managed service in which we run an employee survey for you using a third-party survey tool. The tool collects responses under your instruction, and the data is then imported into the Lumero platform for reporting. We'll tell you in writing which third-party tool we propose to use before the survey runs.
In both modes your organisation is the data controller under the New Zealand Privacy Act 2020 and, where your organisation is based in Australia, under the Australian Privacy Act 1988 (Cth) as well. Lumero Ltd (and, in managed-service mode, the third-party survey tool) acts as a data processor.
The rest of this policy applies in both modes. Where something is specific to one, we say so.
What information we collect and why
Account and contact information
When you set up a Lumero account, we collect your name, email address, organisation name, role, and phone number. This is standard information needed to set up your account, configure access, and manage the billing relationship.
Billing information
Lumero invoices either you directly or, where you've arranged it, your consulting partner.
Survey data
This is the data we hold for your reporting. It typically includes survey responses, demographic data (such as team, role, tenure, or location), and question text as chosen by your organisation.
BYO mode:
- We receive the data from you, not from your employees. We never contact or communicate with survey respondents.
- We recommend removing individual identifiers like names and employee ID numbers before providing us with your survey data. We will also remove any extraneous data of this kind before uploading to Lumero.
Managed-service mode:
- Responses are collected through a third-party survey tool under your instruction. That tool holds the raw responses; Lumero imports the data into the reporting platform for analysis.
- Any communications to respondents go out through the survey tool, using messaging and disclosures you have approved.
- The survey tool's privacy terms and data location apply to the collection step in addition to Lumero's.
- For surveys run on or after 1 May 2026, the disclosures you provide to respondents must comply with IPP 3A of the NZ Privacy Act 2020, which requires that employees be notified when their personal information is collected through a source other than themselves.
Authentication data
Lumero uses Auth0 for secure login. Auth0 handles authentication and provides us with a verified user identity. We don't store your password.
Session and security logs
When you use Lumero, we keep a record of your login session so you stay signed in. We also log security events – things like signing in, signing out, and any requests that are blocked by our access controls. Your session automatically ends after 30 minutes of inactivity, and cannot last longer than 12 hours regardless of activity. These security logs are kept for 90 days. Your IP address is used only for security checks such as rate limiting, and is never stored in a way that could identify you.
Contact form submissions
If you contact us through the Lumero website, we use the information you provide solely to respond to your enquiry.
How we use your information
We use the information we hold to:
- Provide and run your reporting environment
- Manage your account, login, and access levels
- Support and configure your account
- Send invoices and manage billing
- Send transactional emails (password resets, account alerts, email verification)
- Send you product updates (you consent to receive these when creating your account - unsubscribe at any time using the link in any email from us)
- Monitor and fix technical errors
We do not use your data for advertising, profiling, or any purpose unrelated to providing and improving Lumero.
AI-assisted features (opt-in)
Lumero offers optional AI-powered features to enhance your reporting. These features are opt-in – they only run when you choose to activate them.
When you use an AI feature, relevant survey data (such as comment text) is sent to Anthropic (the maker of Claude) for processing. Only the data necessary for that feature is shared – no additional identifiers or demographic data are included unless required for the feature to function.
By activating an AI feature, you authorise us to send the relevant data to Anthropic for processing. You should ensure this is consistent with your own obligations to your employees. If you prefer not to use AI-assisted features, all standard reporting remains fully available.
How we protect your data
Security is built into Lumero's architecture. Key protections include:
- Tenant isolation – every client's data is completely separated from every other client's, enforced at both the application and database level
- Encryption in transit – all data is encrypted using TLS
- Encryption at rest – data in the Lumero database is encrypted at rest
- Layered access controls – multiple independent checks govern who can access what
- Confidentiality thresholds – no results, including individual comments, are displayed for any group with fewer than the minimum number of respondents (default: 5, configurable). This applies across all report views
- Tiered report access – users see only the data appropriate to their role, as configured by your organisation
- Admin access logging – when we access your data for support or configuration, that access is logged
How long we keep your data
Survey reporting and data are available for 18 months from the date your contract begins. Before this period expires, we'll contact you to ask whether you'd like to extend. If we don't hear back, your data will be deleted within 30 days of our final contact attempt.
You can request deletion of your data at any time by emailing legal@lumero.works.
Platform audit logs are retained for 90 days and then automatically and permanently deleted.
Because Lumero is a reporting platform and not a data collector, your original survey data files remain in your own possession at all times.
Your privacy rights
The New Zealand Privacy Act 2020 gives you rights over personal information we hold about you as an account holder. You can ask us what information we hold, and request corrections if anything is wrong. If your organisation is based in Australia, the Australian Privacy Act 1988 (Cth) provides the same rights to access and correct personal information we hold.
For survey respondent data, these rights sit primarily with your organisation as the data controller. If an employee asks to access or correct their information in a survey dataset, that's a request your organisation would need to handle – we can assist where needed.
To exercise your rights, or to raise a privacy concern, contact us at legal@lumero.works. If you're not satisfied with how we've handled it, you can complain to the Office of the Privacy Commissioner at privacy.org.nz (New Zealand) or the Office of the Australian Information Commissioner at oaic.gov.au (Australia).
Changes to this policy
If we make significant changes to this policy, we'll let you know by email before the changes take effect. The "last updated" date at the top of this page always reflects the current version.
Data breaches
If we become aware of a privacy breach likely to cause serious harm, we will notify affected clients directly by email and report to the relevant privacy regulator as required by law. For New Zealand clients, that's the Office of the Privacy Commissioner; for Australian clients, the Office of the Australian Information Commissioner (OAIC). We aim to notify affected clients as soon as practicable, and where reasonably possible within 72 hours.