Skip to main content

Legal

Privacy Policy

How Lumero handles personal information.

Last updated: 25 July 2026

Data encrypted in transit & at rest

TLS in transit, AES at rest

Data stored in Australia

Google Cloud infrastructure

Tenant isolation

Organisation data isolated at app & database level

Confidentiality thresholds

Minimum number of responses required to report on small groups

The short version

Lumero is a reporting platform for employee surveys. Here's what you should know:

  • Lumero is a reporting platform. We also offer a managed service where we run an employee survey for you through a third-party survey tool, under your instruction.
  • Your data is your data. We use it to provide the reporting service you've paid for, and nothing else.
  • We don't sell your information. Ever.
  • We store your data in Australia, on Google Cloud infrastructure.
  • We take confidentiality seriously, including built-in protections to prevent individual survey respondents from being identified in reports.
  • Lumero is a New Zealand-based platform and operates under the New Zealand Privacy Act 2020. If your organisation is based in Australia, the Australian Privacy Act 1988 (Cth) also applies to how we handle your data.

The full policy below explains everything in more detail. If something isn't clear, email us at legal@lumero.works.

Two ways we work

The Lumero platform is a reporting tool only. It does not run surveys. When you use the platform, you bring your own employee survey data – collected through whatever tool you choose – and we provide the reporting on top of it. This is BYO (Bring Your Own) survey data mode, and it's how most clients use Lumero.

Separately, we also offer a managed service in which we run an employee survey for you using a third-party survey tool. The tool collects responses under your instruction, and the data is then imported into the Lumero platform for reporting. We'll tell you in writing which third-party tool we propose to use before the survey runs.

In both modes your organisation is the data controller under the New Zealand Privacy Act 2020 and, where your organisation is based in Australia, under the Australian Privacy Act 1988 (Cth) as well. Lumero Ltd (and, in managed-service mode, the third-party survey tool) acts as a data processor.

The rest of this policy applies in both modes. Where something is specific to one, we say so.

What information we collect and why

Account and contact information

When you set up a Lumero account, we collect your name, email address, organisation name, role, and phone number. This is standard information needed to set up your account, configure access, and manage the billing relationship.

Billing information

Lumero invoices either you directly or, where you've arranged it, your consulting partner.

Survey data

This is the data we hold for your reporting. It typically includes survey responses, demographic data (such as team, role, tenure, or location), and question text as chosen by your organisation.

BYO mode:

  • We receive the data from you, not from your employees. We never contact or communicate with survey respondents.
  • We recommend removing individual identifiers like names and employee ID numbers before providing us with your survey data. We will also remove any extraneous data of this kind before uploading to Lumero.

Managed-service mode:

  • Responses are collected through a third-party survey tool under your instruction. That tool holds the raw responses; Lumero imports the data into the reporting platform for analysis.
  • Any communications to respondents go out through the survey tool, using messaging and disclosures you have approved.
  • The survey tool's privacy terms and data location apply to the collection step in addition to Lumero's.
  • For surveys run on or after 1 May 2026, the disclosures you provide to respondents must comply with IPP 3A of the NZ Privacy Act 2020, which requires that employees be notified when their personal information is collected through a source other than themselves.

Authentication data

Lumero uses Auth0 for secure login. Auth0 handles authentication and provides us with a verified user identity. We don't store your password.

Session and security logs

When you use Lumero, we keep a record of your login session so you stay signed in. We also log security events – things like signing in, signing out, and any requests that are blocked by our access controls. Your session automatically ends after 30 minutes of inactivity, and cannot last longer than 12 hours regardless of activity. These security logs are kept for 90 days. Your IP address is used only for security checks such as rate limiting, and is never stored in a way that could identify you.

Contact form submissions

If you contact us through the Lumero website, we use the information you provide solely to respond to your enquiry.

How we use your information

We use the information we hold to:

  • Provide and run your reporting environment
  • Manage your account, login, and access levels
  • Support and configure your account
  • Send invoices and manage billing
  • Send transactional emails (password resets, account alerts, email verification)
  • Send you product updates (you consent to receive these when creating your account - unsubscribe at any time using the link in any email from us)
  • Monitor and fix technical errors

We do not use your data for advertising, profiling, or any purpose unrelated to providing and improving Lumero.

AI-assisted features (opt-in)

Lumero offers optional AI-powered features to enhance your reporting. These features are opt-in – they only run when you choose to activate them.

When you use an AI feature, relevant survey data (such as comment text) is sent to Anthropic (the maker of Claude) for processing. Only the data necessary for that feature is shared – no additional identifiers or demographic data are included unless required for the feature to function.

By activating an AI feature, you authorise us to send the relevant data to Anthropic for processing. You should ensure this is consistent with your own obligations to your employees. If you prefer not to use AI-assisted features, all standard reporting remains fully available.

Who we share your data with

We don't sell your data or share it with third parties for their own purposes. Where third parties handle your data as part of delivering Lumero:

  • Your reporting data is stored in Australia, on Google Cloud infrastructure.
  • Login is handled by Auth0 – we never see or store your password.
  • AI-assisted features send the necessary data to Anthropic only when you opt in (see the section above).
  • In managed-service mode, a third-party survey tool is also involved as a data processor for the collection step. The specific tool varies by client. Survey-tool providers may store data outside Australia or New Zealand.
  • Where you authorise a consulting partner to access your reporting, we provide that access on your instruction.

For a complete and current list of the third-party providers we use to deliver Lumero, see our sub-processors list. Clients can also review our Data Processing Agreement.

How we protect your data

Security is built into Lumero's architecture. Key protections include:

  • Tenant isolation – every client's data is completely separated from every other client's, enforced at both the application and database level
  • Encryption in transit – all data is encrypted using TLS
  • Encryption at rest – data in the Lumero database is encrypted at rest
  • Layered access controls – multiple independent checks govern who can access what
  • Confidentiality thresholds – no results, including individual comments, are displayed for any group with fewer than the minimum number of respondents (default: 5, configurable). This applies across all report views
  • Tiered report access – users see only the data appropriate to their role, as configured by your organisation
  • Admin access logging – when we access your data for support or configuration, that access is logged

How long we keep your data

Survey reporting and data are available for 18 months from the date your contract begins. Before this period expires, we'll contact you to ask whether you'd like to extend. If we don't hear back, your data will be deleted within 30 days of our final contact attempt.

You can request deletion of your data at any time by emailing legal@lumero.works.

Platform audit logs are retained for 90 days and then automatically and permanently deleted.

Because Lumero is a reporting platform and not a data collector, your original survey data files remain in your own possession at all times.

Your privacy rights

The New Zealand Privacy Act 2020 gives you rights over personal information we hold about you as an account holder. You can ask us what information we hold, and request corrections if anything is wrong. If your organisation is based in Australia, the Australian Privacy Act 1988 (Cth) provides the same rights to access and correct personal information we hold.

For survey respondent data, these rights sit primarily with your organisation as the data controller. If an employee asks to access or correct their information in a survey dataset, that's a request your organisation would need to handle – we can assist where needed.

To exercise your rights, or to raise a privacy concern, contact us at legal@lumero.works. If you're not satisfied with how we've handled it, you can complain to the Office of the Privacy Commissioner at privacy.org.nz (New Zealand) or the Office of the Australian Information Commissioner at oaic.gov.au (Australia).

Cookies and browser storage

Lumero does not use any analytics, advertising, or tracking cookies.

Changes to this policy

If we make significant changes to this policy, we'll let you know by email before the changes take effect. The "last updated" date at the top of this page always reflects the current version.

Data breaches

If we become aware of a privacy breach likely to cause serious harm, we will notify affected clients directly by email and report to the relevant privacy regulator as required by law. For New Zealand clients, that's the Office of the Privacy Commissioner; for Australian clients, the Office of the Australian Information Commissioner (OAIC). We aim to notify affected clients as soon as practicable, and where reasonably possible within 72 hours.

Contact us

Get in touch

Email: legal@lumero.works

Website: https://lumero.works