Legal

Privacy Statement

Effective date: September 2026

Data privacy is important to us at Lumara Health. This Privacy Statement explains what personal data we collect, how we use it, and the rights and choices available to you.

Lumara Health builds software for health plans and other healthcare organisations. Our products are deployed for and operated on behalf of those customers, who determine the purposes and means of processing. In that context Lumara Health acts as a service provider to the customer and, for protected health information, as a HIPAA business associate under a Business Associate Agreement. If you are a member or patient of one of our customers, that organisation’s own privacy notice governs your health information, and requests about it are made to that organisation.

Lumara Health acts as the responsible party (data controller) only for the limited personal data it collects directly: from visitors to lumara.health, from people who contact us, and from users of Lumara-hosted demonstration environments, which run synthetic data.

How we use personal data

Your data is collected to help us:

Our AI-assisted features have been subject to risk assessment under our Risk Management Framework and General AI Usage Policy to consider and mitigate adverse implications of automated processing.

Personal data we may collect

Lumara Health may collect one or more of the following types of data as a requirement for using our services:

  1. Name
  2. Contact information
  3. IP address
  4. Session identifiers (cookies) in demonstration environments; the lumara.health website sets no analytics or advertising cookies
  5. Usage data

Special categories of data

Data concerning health: processed only as a business associate on behalf of our customers, within customer-controlled environments and under a Business Associate Agreement. Lumara Health does not collect health information directly from individuals through its website or demonstration environments.

If you send us information we did not ask for (for example, in an email to us), we protect it to the same standard as the data listed above, but we do not review it for additional privacy risks before storing it. Please do not send protected health information to Lumara Health by email.

When we share your personal data

Your personal data may be shared with third parties under one or more of the following scenarios:

We do not sell your personal data, and we do not share it for cross-context behavioural advertising.

Your rights

Your rights depend on the capacity in which we hold your data.

Health information held on behalf of a health plan or healthcare provider

Your rights over that information are set by HIPAA and are exercised through the health plan or provider (the covered entity) whose member or patient you are:

Lumara Health supports the covered entity in fulfilling these requests as our Business Associate Agreement requires. HIPAA does not provide a general right to erasure, and Lumara Health cannot delete data held within a customer’s environment on its own initiative; such requests are directed to the covered entity.

Personal data Lumara Health collects directly

(Website visitors, people who contact us, and users of demonstration environments.) You may:

We respond to verified requests within 30 days and will explain if a request cannot be fulfilled in full.

Minors. Our website and services are intended for adults and for use by healthcare organisations. We do not knowingly collect personal data directly from children under 13. Health information about minors, such as a dependent covered by a health plan, may be processed on behalf of our customers as a business associate, under the customer’s authority and applicable law.

Sensitive data. We process health information only on behalf of our customers under HIPAA and their Business Associate Agreements; we do not ask individuals to consent to that processing directly, because it occurs under the customer’s authority and applicable law. We do not collect other special categories of personal data.

Automated decisions. Lumara Health’s products use AI models for language understanding and phrasing. Decisions with legal or similarly significant effects are not made by an AI model: care-pathway selection and escalation are made by deterministic, rule-based logic that is configured and reviewable, clinical questions are escalated to human clinicians, and eligibility and benefit determinations are not made by our products at all but remain with the health plan. No individual is subject to a decision based solely on automated processing that produces legal or similarly significant effects.

These rights are subject to applicable law and to our legal obligations. For any privacy concerns or to exercise your rights, please use the contact details below.

Sub-processors and locations

The following service providers process personal data on Lumara Health’s behalf. Protected health information processed for our customers stays within customer-controlled environments and is not sent to these providers unless the customer’s agreement and a Business Associate Agreement with the provider permit it. We update this list when a sub-processor is added or replaced, and notify customers of such changes as their agreements require.

Sub-processorPurposePersonal dataLocation
Google WorkspaceEmail, documents, calendar and identityBusiness contact details, correspondenceUnited States and other Google data centre locations
VercelHosting for lumara.health and demonstration applicationsIP address, browser and request logsUnited States
NeonDemonstration databasesSynthetic data only; demonstration account detailsUnited States
SupabaseDemonstration databases and authenticationSynthetic data only; demonstration account detailsUnited States
AnthropicAI model API for Lumara productsContent of product interactions (synthetic today); not used for model trainingUnited States
OpenAIAI model API for demonstration productsContent of demonstration interactions (synthetic today); not used for model trainingUnited States
GitHubSource code hostingNone by policy (no personal data in repositories)United States
SlackInternal communicationsEmployee and business-contact names; no protected health information by policyUnited States
1PasswordCredential managementEmployee account detailsUnited States
JumpCloudDevice management for company laptopsEmployee and device detailsUnited States
DrataCompliance monitoringEmployee records and system configuration evidenceUnited States
GranolaMeeting notes for business callsBusiness-contact names and meeting content; no protected health information by policyUnited States

Privacy requests and contacts

For further information about our privacy practices, or to raise any privacy requests or complaints in relation to your data, please contact us using the following methods:

Changes to this statement

We review this Privacy Statement at least annually and whenever our services or the law change. The current version is published on this page with its effective date.