Data Processing Agreement
Last updated Jul 20, 2026
When someone fills in a contact form on a website you built with Lumen, that message is yours. You decide what happens to it, and we only handle it on your behalf. This agreement sets out that arrangement. It applies automatically to every account; there is nothing to sign.
Who is who
You are the controller: your website collects the message, and you decide why and what happens next. Maurer Software, operating Lumen, is the processor: we store the message and forward it to you, and we do nothing else with it.
This agreement forms part of our Terms of Service and takes precedence over them for anything concerning your visitors’ personal data.
What we process, and why
- Purpose
- Receiving contact-form submissions from your website, storing them so they are not lost, and notifying you by email.
- Categories of people
- Visitors to the websites you publish who choose to send you a message.
- Categories of data
- Whatever your form asks for, typically a name, an email address, and a message, together with the time it was sent, which form it came from, and whether the consent box was ticked. We do not require or design for special-category data, and you should not build a form that collects it.
- Duration
- Until you delete the message, delete the website it belongs to, or close your account.
Website analytics
- Purpose
- Measuring aggregate traffic to the websites you publish so you can see how they are doing.
- Categories of people
- Visitors to the websites you publish.
- Categories of data
- Aggregate metrics only: page views, approximate country, referrer, and device type. No cookies are set, no IP addresses are stored, and unique visitors are counted with a salted, daily-rotating fingerprint that cannot be reversed or used to track anyone across days or sites. No special-category data is involved.
- Duration
- Retained by our analytics provider for roughly 90 days, then it expires automatically.
Our obligations
We process your visitors’ data only on your instructions. Using the service is the instruction; we do not use these messages for our own purposes, and we do not use them to train any AI model.
Everyone with access is bound by confidentiality. We take the security measures described below, help you respond if a visitor exercises their rights, and help you meet your own obligations around security and breach notification.
If we ever become legally required to process the data in some other way, we will tell you first unless the law forbids it.
Security
Concretely, and not as aspiration:
- Separation is enforced by the database. Every row carries its owner, and access rules live in the database itself rather than in application code, so one customer cannot read another’s messages even if our own code has a bug.
- Your visitors’ IP addresses are never stored. We need to limit how often a form can be submitted, so we keep a salted one-way hash that expires by itself. The address itself is never written down.
- All data is encrypted in transit, and encrypted at rest by our storage providers.
- Forms are protected against automated abuse, and every submission is validated and size-limited before it is stored.
- Messages are stored first and emailed second, so a mail failure never loses a lead.
Sub-processors
We use these companies to process your visitors’ messages. This is deliberately a shorter list than the one in our privacy policy: a contact-form submission is handled by our own edge network, written to our database, and emailed to you. It never reaches an AI provider or our payment provider.
| Company | Role | Where |
|---|---|---|
| Supabase | Database and authentication | Switzerland |
| Cloudflare | Content delivery, SSL certificates, DNS and object storage | Global edge network, with stored images in an EU-jurisdiction bucket |
| Resend | Email delivery | European Union and United States |
You authorise these. If we add or replace one, we will tell you by email at least 30 days beforehand, and you may object by closing your account before the change takes effect.
Deletion and return
You can delete any message from your Forms inbox at any time, and it is removed permanently. Deleting a website removes its messages with it. Closing your account removes everything.
This is how you meet an erasure request from one of your visitors, and you do not need to ask us. If you need help, email [email protected].
International transfers
Messages are stored in Switzerland. Email delivery may involve processing outside Switzerland and the EU; where that happens the transfer is covered by the European Commission’s Standard Contractual Clauses or an equivalent safeguard.
Breaches and audits
If your visitors’ data is ever exposed, we will tell you without undue delay and give you what you need to notify your supervisory authority.
On request we will provide the information you reasonably need to demonstrate that we meet these obligations. Where an on-site audit is legally required, we will agree the scope with you in advance so it does not disrupt other customers.
Your side of it
You are responsible for having a lawful basis to collect what your form asks for, for telling your visitors what you will do with it, and for answering them when they ask. Keep the consent box on your forms, because it is there for your protection, not ours.
Who we are
Lumen is operated by Maurer Software, a sole proprietorship in Switzerland, entered in the Swiss commercial register under CHE-199.123.882.
[email protected]
