LUMIFAI
Products
What we build
LUMIFAI Edge Platform
Brand strategy work + KPIs in one platform — continuous, not one-off. →
Reports 3 modules
Persona · Communication · Tracking — as standalone studies. →
Consulting
Who we work with
Direct clients B2B · B2C
Consulting-grade insights at a fraction of the cost — direct, no detours. →
Agencies & Consultancies Partner
State-of-the-art analyses in hours, not weeks — more time for strategy and creative. →
View full service spectrum →
Blog About Contact
Login →
LUMIFAI / Privacy

Privacy.

Last updated · April 2026
Note: The legally binding version of this privacy notice is in German, in line with the requirements of the German Federal Data Protection Act (BDSG) and the EU GDPR. The text below is therefore presented in its original German form. For an English summary, please contact marius@lumifai.com.

1 · Introduction and controller contact details

1.1 We are pleased that you are visiting our website and thank you for your interest. The following sections inform you about how we handle your personal data when you use our website. "Personal data" means any data that can be used to identify you personally.

1.2 Verantwortlicher für die Datenverarbeitung auf dieser Website im Sinne der Datenschutz-Grundverordnung (DSGVO) ist Lumifai GmbH, Käthe-Kollwitz-Ring 7, 63486 Bruchköbel, Deutschland, Tel.: +49 (0) 69 272 426 56, E-Mail: marius@lumifai.com. Der für die Verarbeitung von personenbezogenen Daten Verantwortliche ist diejenige natürliche oder juristische Person, die allein oder gemeinsam mit anderen über die Zwecke und Mittel der Verarbeitung von personenbezogenen Daten entscheidet.

2 · Data collection when visiting our website

2.1 If you merely access our website for information purposes — i.e. if you do not register or otherwise submit information to us — we only collect the data that your browser transmits to the site server (so-called "server log files"). When you access our website, we collect the following data, which are technically necessary for us to display the website to you:

  • The page on our website you visited
  • Date and time of access
  • Amount of data sent in bytes
  • Source / referrer from which you reached the page
  • Verwendeter Browser
  • Verwendetes Betriebssystem
  • Verwendete IP-Adresse (ggf.: in anonymisierter Form)

Processing takes place pursuant to Art. 6 (1)(f) GDPR on the basis of our legitimate interest in improving the stability and functionality of our website. The data are not passed on or otherwise used. We do reserve the right, however, to review server log files retrospectively if there are concrete indications of unlawful use.

2.2 For security reasons and to protect the transmission of personal data and other confidential content (e.g. orders or requests to the controller), this website uses SSL or TLS encryption. You can recognise an encrypted connection by the "https://" prefix and the lock icon in your browser bar.

3 · Hosting & Content-Delivery-Network

3.1 Amazon Web Services

For hosting our website and serving the page content, we use the system of the following provider: Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109, USA.

All data collected on our website are processed on the provider's servers.

We have concluded a data-processing agreement with the provider that ensures the protection of our visitors' data and prohibits unauthorised disclosure to third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which — based on an adequacy decision by the European Commission — ensures compliance with the European data-protection level.

3.2 AWS-CloudFront

We use a content delivery network from the following provider: Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109, USA.

This service allows us to deliver large media files such as graphics, page content or scripts faster via a network of regionally distributed servers. Processing takes place to safeguard our legitimate interest in improving the stability and functionality of our website pursuant to Art. 6 (1)(f) GDPR. We have concluded a data-processing agreement with the provider that ensures the protection of our visitors' data and prohibits unauthorised disclosure to third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which — based on an adequacy decision by the European Commission — ensures compliance with the European data-protection level.

4 · Cookies

To make visiting our website attractive and to enable the use of certain functions, we use cookies — small text files that are stored on your device. Some of these cookies are automatically deleted when you close your browser (so-called "session cookies"), while others remain on your device for longer and enable the storage of page settings (so-called "persistent cookies"). In the latter case, you can find the storage duration in your web browser's cookie settings overview.

Where individual cookies we use also process personal data, processing takes place pursuant to Art. 6 (1)(b) GDPR either to perform the contract, pursuant to Art. 6 (1)(a) GDPR on the basis of consent, or pursuant to Art. 6 (1)(f) GDPR to safeguard our legitimate interests in the best possible website functionality and a user-friendly and effective design of the site visit.

You can configure your browser so that you are informed when cookies are set and decide individually whether to accept them, or rule out the acceptance of cookies for specific cases or in general.

Please note that if you do not accept cookies, the functionality of our website may be restricted.

5 · Kontaktaufnahme

When you contact us (e.g. via contact form or email), personal data is collected. The data collected when using a contact form can be seen from the respective form. These data are stored and used exclusively for the purpose of replying to your enquiry or contacting you and the technical administration connected with this.

The legal basis for processing these data is our legitimate interest in responding to your enquiry pursuant to Art. 6 (1)(f) GDPR. If your contact is aimed at concluding a contract, the additional legal basis for processing is Art. 6 (1)(b) GDPR. Your data will be deleted once your enquiry has been finally processed. This is the case if it can be inferred from the circumstances that the matter in question has been conclusively clarified and provided that no statutory retention obligations conflict.

6 · Registration on the website

You can register on our website by providing personal data. The personal data processed for registration are shown in the input form used for registration. We use the so-called double-opt-in procedure for registration — i.e. your registration is only complete once you have confirmed your sign-up by clicking the link in a confirmation email sent for that purpose. If your confirmation does not take place within 24 hours, your sign-up is automatically deleted from our database. Provision of the data named above is mandatory. You can voluntarily provide all further information by using our portal.

When you use our portal, we store the data required to perform the contract — including any payment information — until you finally delete your account. We also store the voluntary data provided by you for the duration of your use of the portal, unless you delete them first. All entries can be managed and amended in the protected customer area. The legal basis is Art. 6 (1)(f) GDPR.

In addition, we store all content you have published (such as public posts, wall entries, guestbook entries, etc.) in order to operate the website. We have a legitimate interest in providing the website with full user-generated content. The legal basis is Art. 6 (1)(f) GDPR. If you delete your account, your public statements — especially in the forum — remain visible to all readers, but your account is no longer accessible. All other data are deleted in this case.

7 · Use of customer data for direct marketing

Anmeldung zu unserem E-Mail-Newsletter

If you subscribe to our email newsletter, we will regularly send you information about our offerings. The only mandatory entry for sending the newsletter is your email address. Providing further data is voluntary and is used to address you personally. We use the so-called double-opt-in procedure for sending the newsletter. This means that we will only send you an email newsletter once you have expressly confirmed that you consent to receiving the newsletter. We then send you a confirmation email asking you to confirm — by clicking a corresponding link — that you wish to receive the newsletter in future.

By activating the confirmation link, you give us your consent to the use of your personal data pursuant to Art. 6 (1)(a) GDPR. When you sign up for the newsletter, we store the IP address assigned by your internet service provider (ISP) as well as the date and time of sign-up so that we can trace any later misuse of your email address. The data we collect at sign-up are used exclusively for newsletter advertising. You can unsubscribe from the newsletter at any time using the link provided in the newsletter or by sending a corresponding message to the controller named at the beginning. After unsubscribing, your email address is immediately removed from our newsletter distribution list, unless you have expressly consented to further use of your data or we reserve a further use of data that is legally permitted and about which we inform you in this declaration.

8 · Webanalysedienste

Google Analytics 4

This website uses Google Analytics 4, a web analysis service of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), which enables an analysis of your use of our website.

By default, when you visit the website Google Analytics 4 sets cookies which are stored as small text snippets on your device and collect certain information. This information includes your IP address, although Google truncates the last digits to rule out direct attribution to a person.

The information is transmitted to Google servers and further processed there. Transfers to Google LLC, based in the USA, are also possible.

Google uses the information collected on our behalf to evaluate your use of the website, to compile reports on website activities for us, and to provide further services related to website and internet use. The truncated IP address transmitted by your browser as part of Google Analytics is not combined with other Google data. The data collected as part of using Google Analytics 4 are stored for a period of two months and then deleted.

All processing operations described above — in particular the setting of cookies on the device used — only take place if you have given us your express consent pursuant to Art. 6 (1)(a) GDPR.

Without your consent, Google Analytics 4 is not used during your site visit. You can revoke your consent at any time with effect for the future. To exercise your right of revocation, please deactivate this service via the "cookie consent tool" provided on the website.

We have concluded a data-processing agreement with Google that ensures the protection of our visitors' data and prohibits unauthorised disclosure to third parties.

Weitere rechtliche Hinweise zu Google Analytics 4 finden Sie unter business.safety.google, policies.google.com/privacy und unter policies.google.com/technologies/partner-sites.

Demografische Merkmale

Google Analytics 4 uses the special "demographic characteristics" feature and can use this to compile statistics that make statements about the age, gender and interests of site visitors. This is done by analysing advertising and information from third-party providers. This makes it possible to identify target groups for marketing activities. The collected data cannot be attributed to a specific person and are deleted after being stored for a period of two months.

Google Signals

Als Erweiterung zu Google Analytics 4 kann auf dieser Website Google Signals verwendet werden, um geräteübergreifende Berichte erstellen zu lassen. Wenn Sie personalisierte Anzeigen aktiviert haben und Ihre Geräte mit Ihrem Google-Konto verknüpft haben, kann Google vorbehaltlich Ihrer Einwilligung zur Nutzung von Google Analytics gem. Art. 6 Abs. 1 lit. a DSGVO Ihr Nutzungsverhalten geräteübergreifend analysieren und Datenbankmodelle, unter anderem zu geräteübergreifenden Conversions, erstellen. Wir erhalten keine personenbezogenen Daten von Google, sondern nur Statistiken. Wenn Sie die geräteübergreifende Analyse stoppen möchten, können Sie die Funktion „Personalisierte Werbung" in den Einstellungen Ihres Google-Kontos deaktivieren. Folgen Sie dazu den Anweisungen auf dieser Seite: support.google.com.

Weitere Informationen zu Google Signals finden Sie unter folgendem Link: support.google.com/analytics.

UserIDs

As an extension to Google Analytics 4, the "UserIDs" feature can be used on this website. If you have consented to the use of Google Analytics 4 pursuant to Art. 6 (1)(a) GDPR, set up an account on this website and log in to that account on different devices, your activities — including conversions — can be analysed across devices.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which — based on an adequacy decision by the European Commission — ensures compliance with the European data-protection level.

9 · Retargeting / remarketing and conversion tracking

Meta Pixel with advanced matching

Within our online offering, we use the "Meta Pixel" service in advanced-matching mode from the following provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland ("Meta").

If a user clicks on an ad we have run on Facebook or Instagram, the URL of our linked page is extended with a parameter using "Meta Pixel". After the redirect, this URL parameter is then written into the user's browser by a cookie that our linked page itself sets. In addition, this cookie captures specific customer data such as the email address that we collect on our linked website during processes such as purchases, account logins or registrations (advanced matching). The cookie is then read out and enables the data, including the specific customer data, to be transmitted to Meta.

We use "Meta Pixel" with advanced matching to make our ads on Facebook and/or Instagram more effective and to ensure they correspond to the interests of users or have specific characteristics (e.g. interests in particular topics or products, derived from the websites visited) that we transmit to Meta ("Custom Audiences").

In addition, we analyse the effectiveness of our ads by tracking whether users were directed to our website after clicking on an ad (conversion). Compared with the standard "Meta Pixel" variant, the advanced-matching feature helps us measure the effectiveness of our ad campaigns more accurately by capturing more attributed conversions.

Alle übermittelten Daten werden von Meta gespeichert und verarbeitet, so dass eine Zuordnung zum jeweiligen Nutzerprofil möglich ist und Meta die Daten für eigene Werbezwecke gemäß den Datenverwendungsrichtlinien von Meta (facebook.com/about/privacy) verwenden kann. Die Daten können es Meta sowie seinen Partnern ermöglichen, Anzeigen auf und außerhalb von Facebook zu schalten.

All processing operations described above — in particular the setting of cookies to read out information on the device used — only take place if you have given us your express consent pursuant to Art. 6 (1)(a) GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the "cookie consent tool" provided on the website.

We have concluded a data-processing agreement with the provider that ensures the protection of our visitors' data and prohibits unauthorised disclosure to third parties.

The information generated by Meta is generally transmitted to a Meta server and stored there; in this context, transmission to servers of Meta Platforms Inc. in the USA may also occur.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which — based on an adequacy decision by the European Commission — ensures compliance with the European data-protection level.

10 · Site functionalities

Supabase

On our website we use the following provider's service to verify sign-up and login attempts for protected areas of the site: Supabase, Inc., 548 Market St, San Francisco, CA 94104, USA.

Exclusively on the basis of our legitimate interest in maintaining the structural and data security of our website, your sign-in data (email, username and password) are transmitted to the provider for authentication pursuant to Art. 6 (1)(f) GDPR in order to decide on the release of the sign-in attempt.

We have concluded a data-processing agreement with the provider that protects the data of our visitors and prohibits disclosure to third parties.

For data transfers to the USA, the provider relies on the European Commission's standard contractual clauses, which are intended to ensure compliance with the European data-protection level.

11 · Tools and other

Cookie-Consent-Tool

This website uses a so-called "cookie consent tool" to obtain effective user consent for cookies and cookie-based applications that require consent. The "cookie consent tool" is shown to users when they access the site, as an interactive interface in which consent for specific cookies and/or cookie-based applications can be granted by ticking checkboxes. With the help of the tool, all cookies/services requiring consent are only loaded if the respective user grants the appropriate consent by ticking. This ensures that such cookies are only set on the user's device if consent has been granted.

The tool sets technically necessary cookies to store your cookie preferences. Personal user data are generally not processed in this context.

If, in individual cases, personal data (such as the IP address) are processed for the purposes of storing, attributing or logging cookie settings, this takes place pursuant to Art. 6 (1)(f) GDPR on the basis of our legitimate interest in legally compliant, user-specific and user-friendly consent management for cookies and thus in a legally compliant design of our online presence.

A further legal basis for the processing is Art. 6 (1)(c) GDPR. As a controller, we are subject to the legal obligation to make the use of technically non-essential cookies dependent on the respective user's consent.

Where necessary, we have concluded a data-processing agreement with the provider that ensures the protection of our visitors' data and prohibits unauthorised disclosure to third parties.

Further information on the operator and the configuration options of the cookie consent tool can be found directly in the corresponding interface on our website.

12 · Rechte des Betroffenen

12.1 Applicable data-protection law grants you the following data-subject rights (rights of information and intervention) vis-à-vis the controller regarding the processing of your personal data; for the respective conditions for exercising these rights, please refer to the legal basis specified:

  • Right of access pursuant to Art. 15 GDPR;
  • Right to rectification pursuant to Art. 16 GDPR;
  • Right to erasure pursuant to Art. 17 GDPR;
  • Right to restriction of processing pursuant to Art. 18 GDPR;
  • Right to notification pursuant to Art. 19 GDPR;
  • Right to data portability pursuant to Art. 20 GDPR;
  • Right to withdraw consent given pursuant to Art. 7 (3) GDPR;
  • Right to lodge a complaint pursuant to Art. 77 GDPR.

12.2 Widerspruchsrecht

Wenn wir im Rahmen einer Interessenabwägung Ihre personenbezogenen Daten aufgrund unseres überwiegenden berechtigten Interesses verarbeiten, haben Sie das jederzeitige Recht, aus Gründen, die sich aus Ihrer besonderen Situation ergeben, gegen diese Verarbeitung Widerspruch mit Wirkung für die Zukunft einzulegen.

If you exercise your right to object, we will end the processing of the affected data. However, further processing remains reserved if we can demonstrate compelling legitimate grounds for processing that override your interests, fundamental rights and freedoms, or if the processing serves the establishment, exercise or defence of legal claims.

If your personal data are processed by us for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such advertising purposes. You can exercise the objection as described above.

If you exercise your right to object, we will end the processing of the affected data for direct-marketing purposes.

13 · Duration of storage of personal data

The duration of storage of personal data is determined by the respective legal basis, the purpose of processing and — where applicable — by the respective statutory retention period (e.g. commercial and tax-law retention periods).

When personal data are processed on the basis of express consent pursuant to Art. 6 (1)(a) GDPR, the affected data are stored until you revoke your consent.

If statutory retention periods exist for data that are processed within the context of contractual or quasi-contractual obligations on the basis of Art. 6 (1)(b) GDPR, these data are routinely deleted after the retention periods expire, provided they are no longer required for contract performance or initiation and/or there is no longer a legitimate interest on our part in continued storage.

When personal data are processed on the basis of Art. 6 (1)(f) GDPR, these data are stored until you exercise your right to object pursuant to Art. 21 (1) GDPR, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

When personal data are processed for direct-marketing purposes on the basis of Art. 6 (1)(f) GDPR, these data are stored until you exercise your right to object pursuant to Art. 21 (2) GDPR.

Unless otherwise specified in the other information in this declaration about specific processing situations, stored personal data are otherwise deleted when they are no longer necessary for the purposes for which they were collected or otherwise processed.


Copyright-Hinweis: Diese Datenschutzerklärung wurde von den Fachanwälten der IT-Recht Kanzlei erstellt und ist urheberrechtlich geschützt (it-recht-kanzlei.de).

LUMIFAI

Spotlight on your brand. Built in Frankfurt am Main.

Product
LUMIFAI Edge Reports Consulting
Company
About us Blog Contact
Legal
Imprint Privacy Cookie settings
© LUMIFAI GmbH 2026 — All rights reserved.