← Luminid
Luminid · Legal Entity ID: 3102-950-241 · Costa Rica · hello@luminid.org

Data Processing Addendum

Last updated: 2026-07-12

Contents

1. What this document is2. Roles3. Scope of processing4. Luminid's obligations as processor5. Subprocessors6. Security measures7. International transfers8. Deletion on termination9. Liability, precedence, and contact

1. What this document is

This is a readable reference copy of Luminid's Data Processing Addendum (DPA) for employer customers. It describes how Luminid processes job seeker personal data on your behalf when your organization uses Luminid to hire.

A signature-ready execution copy of this DPA, including the EU Standard Contractual Clauses annexes where applicable, is available on request at hello@luminid.org with the subject line "DPA execution copy". Executing the DPA is a condition of accessing job seeker personal data through the platform where applicable data protection law requires a controller-processor agreement.

This DPA supplements the Terms of Service. If this DPA and the Terms conflict on a data protection matter, this DPA prevails.

2. Roles

For job seeker personal data processed inside your hiring pipelines (applications to your job listings, job seeker materials you review, your notes and stage decisions), your organization is the data controller and Luminid is your data processor. Luminid processes that data only on your documented instructions, as expressed through your use of the platform and this DPA.

For personal data Luminid processes to run the platform itself (accounts, authentication, job seeker profiles and verifications that job seekers own and carry, security, billing, platform improvement), Luminid is an independent controller. That processing is described in the Privacy Policy at luminid.org/privacy, not governed by this DPA.

A job seeker's verifications belong to the job seeker. When a job seeker withdraws an application or your subscription ends, the job seeker keeps their own profile and verification records.

3. Scope of processing

Subject matter: job seeker personal data made available to your organization through your hiring pipelines on Luminid.

Duration: the term of your subscription, plus the deletion period in Section 8.

Nature and purpose: hosting, storage, display, transmission, and organization of job seeker application data so your team can evaluate job seekers for the specific positions they applied to; scoring of simulation responses against documented criteria where a simulation is attached to your role; and related support and security operations.

Categories of data subjects: job seekers who apply to your job listings or whom you source through the platform, and your own authorized users.

Categories of personal data: identity and contact data, professional and profile data, application materials, simulation responses and results (including transcripts of voice simulations and, where the job seeker consented, audio recordings), pipeline records and notes, and communications between your team and job seekers.

Special categories: not intentionally processed. Employers must not solicit special-category data from job seekers through the platform.

4. Luminid's obligations as processor

Luminid will:

  • Process job seeker personal data only on your documented instructions, unless required otherwise by law, in which case Luminid informs you before processing unless the law prohibits that notice
  • Ensure that every person authorized to process the data is bound by confidentiality
  • Implement and maintain the technical and organizational security measures in Section 6
  • Assist you, with appropriate technical and organizational measures, in responding to data subject requests (access, correction, deletion, portability, objection, restriction, and human review of automated scoring)
  • Assist you with your obligations regarding security, breach notification, and data protection impact assessments, taking into account the nature of the processing
  • Notify you without undue delay after becoming aware of a personal data breach affecting job seeker data processed on your behalf, with enough information for you to meet your own notification duties
  • Make available the information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, on reasonable notice and no more than once per year unless a breach or supervisory authority requires otherwise
  • Delete or return the data at the end of the engagement as described in Section 8

5. Subprocessors

You give general authorization for Luminid to engage the subprocessors below. Luminid remains fully liable to you for each subprocessor's performance and binds each one to data protection obligations no less protective than this DPA.

  • Supabase — database, authentication, and file storage (infrastructure on Amazon Web Services)
  • Vercel — web hosting and application infrastructure
  • Anthropic — automated scoring of simulation responses against documented criteria
  • OpenAI — real-time voice transcription for voice simulations
  • Resend — transactional email delivery
  • ONVO Pay — payment processing (your billing data, not job seeker data)
  • FacturaTica — electronic invoicing under Costa Rican law (your billing data, not job seeker data)

Luminid will notify you at least thirty (30) days before any new subprocessor begins processing job seeker personal data, by updating the list published at luminid.org/privacy and by email to your account owner. You may object on reasonable data protection grounds within that period; if the objection cannot be resolved, you may terminate the affected services without penalty.

6. Security measures

Luminid maintains, at minimum:

  • Encryption in transit (TLS 1.2 or higher, HSTS) and at rest (AES-256 at the storage layer, including backups)
  • Row-Level Security at the database layer, so each account can only query the rows it is entitled to, as a defense-in-depth control beneath the application layer
  • Role-based access control for production systems, restricted to personnel who need it for their function, with multi-factor authentication on administrative access and individual credentials (no shared accounts)
  • Password hashing with bcrypt and per-user salts; no plaintext password storage
  • Logging of access to production systems, with regular review
  • Dependency scanning, security review of changes, and a responsible disclosure process (see the Terms of Service)
  • A documented incident response procedure with the notification commitments in Section 4
  • Vendor security assessment for subprocessors, bound by written data processing agreements

Luminid does not create or store voiceprints or any biometric identifier. Voice simulations are scored on transcripts.

7. International transfers

Job Seeker personal data may be processed in the United States and other jurisdictions where the subprocessors in Section 5 operate. For transfers of personal data from the EEA, the UK, or Switzerland to countries without an adequacy decision, the parties rely on the EU Standard Contractual Clauses (module two, controller to processor) and the UK Addendum or IDTA as applicable, which are incorporated into the execution copy of this DPA. Transfer impact assessments are available on request.

8. Deletion on termination

When your subscription ends or this DPA terminates:

  • Your account enters a read-only export window of thirty (30) days, during which you can export your pipeline data
  • At your written choice, Luminid deletes or returns the job seeker personal data processed on your behalf; absent an instruction, Luminid deletes it
  • Deletion completes within ninety (90) days of the end of the export window, including removal from active systems and purge from backups through normal rotation
  • Luminid may retain data only where and for as long as law requires (for example, financial records under Costa Rican tax law), and job seekers retain their own profiles and verifications, which they control independently
  • On request, Luminid confirms completion of deletion in writing

9. Liability, precedence, and contact

Liability under this DPA is subject to the limitations of liability in the Terms of Service, except where applicable data protection law does not permit such limits.

Order of precedence for data protection matters: (1) the Standard Contractual Clauses where they apply, (2) the executed DPA, (3) this reference copy, (4) the Terms of Service.

For DPA questions, execution copies, audits, or data protection notices: hello@luminid.org, subject line "DPA". Luminid, Legal Entity ID (Cédula Jurídica) 3102-950-241, San José, Costa Rica.

Privacy PolicyBack to Luminid© 2026 Luminid · 3102-950-241