Legal
Privacy Statement
Effective date: September 2026
Data privacy is important to us at Lumara Health. This Privacy Statement explains what personal data we collect, how we use it, and the rights and choices available to you.
Lumara Health builds software for health plans and other healthcare organisations. Our products are deployed for and operated on behalf of those customers, who determine the purposes and means of processing. In that context Lumara Health acts as a service provider to the customer and, for protected health information, as a HIPAA business associate under a Business Associate Agreement. If you are a member or patient of one of our customers, that organisation’s own privacy notice governs your health information, and requests about it are made to that organisation.
Lumara Health acts as the responsible party (data controller) only for the limited personal data it collects directly: from visitors to lumara.health, from people who contact us, and from users of Lumara-hosted demonstration environments, which run synthetic data.
How we use personal data
Your data is collected to help us:
- Personalize your experience.
- Provide support and troubleshooting when using our services.
- Analyse and improve our services.
- Tell business contacts who have engaged with us about our services.
- Meet our legal and compliance obligations.
- Provide AI-assisted features within our products, as described under Automated decisions below.
Our AI-assisted features have been subject to risk assessment under our Risk Management Framework and General AI Usage Policy to consider and mitigate adverse implications of automated processing.
Personal data we may collect
Lumara Health may collect one or more of the following types of data as a requirement for using our services:
- Name
- Contact information
- IP address
- Session identifiers (cookies) in demonstration environments; the lumara.health website sets no analytics or advertising cookies
- Usage data
Special categories of data
Data concerning health: processed only as a business associate on behalf of our customers, within customer-controlled environments and under a Business Associate Agreement. Lumara Health does not collect health information directly from individuals through its website or demonstration environments.
If you send us information we did not ask for (for example, in an email to us), we protect it to the same standard as the data listed above, but we do not review it for additional privacy risks before storing it. Please do not send protected health information to Lumara Health by email.
When we share your personal data
Your personal data may be shared with third parties under one or more of the following scenarios:
- With the sub-processors listed below, subject to the agreed terms of service and with a basis of processing in line with this statement.
- When your explicit consent is given.
- To government agencies, regulators or law enforcement agencies with a lawful purpose.
We do not sell your personal data, and we do not share it for cross-context behavioural advertising.
Your rights
Your rights depend on the capacity in which we hold your data.
Health information held on behalf of a health plan or healthcare provider
Your rights over that information are set by HIPAA and are exercised through the health plan or provider (the covered entity) whose member or patient you are:
- The right to access and obtain a copy of your protected health information (45 CFR §164.524).
- The right to request amendment of information that is inaccurate or incomplete (45 CFR §164.526).
- The right to an accounting of certain disclosures of your information (45 CFR §164.528).
- The right to request restrictions on how your information is used and disclosed (45 CFR §164.522).
Lumara Health supports the covered entity in fulfilling these requests as our Business Associate Agreement requires. HIPAA does not provide a general right to erasure, and Lumara Health cannot delete data held within a customer’s environment on its own initiative; such requests are directed to the covered entity.
Personal data Lumara Health collects directly
(Website visitors, people who contact us, and users of demonstration environments.) You may:
- Ask what we hold and request a copy of your personal data, together with an explanation of how we obtained it, what we use it for and who we share it with.
- Ask us to correct inaccurate or incomplete data.
- Ask us to delete personal data we no longer need for the purposes described here or for our legal obligations. We will tell you if any records must be kept, for example compliance records we are required to retain for six years.
- Object to marketing at any time; we will stop contacting you for that purpose.
We respond to verified requests within 30 days and will explain if a request cannot be fulfilled in full.
Minors. Our website and services are intended for adults and for use by healthcare organisations. We do not knowingly collect personal data directly from children under 13. Health information about minors, such as a dependent covered by a health plan, may be processed on behalf of our customers as a business associate, under the customer’s authority and applicable law.
Sensitive data. We process health information only on behalf of our customers under HIPAA and their Business Associate Agreements; we do not ask individuals to consent to that processing directly, because it occurs under the customer’s authority and applicable law. We do not collect other special categories of personal data.
Automated decisions. Lumara Health’s products use AI models for language understanding and phrasing. Decisions with legal or similarly significant effects are not made by an AI model: care-pathway selection and escalation are made by deterministic, rule-based logic that is configured and reviewable, clinical questions are escalated to human clinicians, and eligibility and benefit determinations are not made by our products at all but remain with the health plan. No individual is subject to a decision based solely on automated processing that produces legal or similarly significant effects.
These rights are subject to applicable law and to our legal obligations. For any privacy concerns or to exercise your rights, please use the contact details below.
Sub-processors and locations
The following service providers process personal data on Lumara Health’s behalf. Protected health information processed for our customers stays within customer-controlled environments and is not sent to these providers unless the customer’s agreement and a Business Associate Agreement with the provider permit it. We update this list when a sub-processor is added or replaced, and notify customers of such changes as their agreements require.
| Sub-processor | Purpose | Personal data | Location |
|---|---|---|---|
| Google Workspace | Email, documents, calendar and identity | Business contact details, correspondence | United States and other Google data centre locations |
| Vercel | Hosting for lumara.health and demonstration applications | IP address, browser and request logs | United States |
| Neon | Demonstration databases | Synthetic data only; demonstration account details | United States |
| Supabase | Demonstration databases and authentication | Synthetic data only; demonstration account details | United States |
| Anthropic | AI model API for Lumara products | Content of product interactions (synthetic today); not used for model training | United States |
| OpenAI | AI model API for demonstration products | Content of demonstration interactions (synthetic today); not used for model training | United States |
| GitHub | Source code hosting | None by policy (no personal data in repositories) | United States |
| Slack | Internal communications | Employee and business-contact names; no protected health information by policy | United States |
| 1Password | Credential management | Employee account details | United States |
| JumpCloud | Device management for company laptops | Employee and device details | United States |
| Drata | Compliance monitoring | Employee records and system configuration evidence | United States |
| Granola | Meeting notes for business calls | Business-contact names and meeting content; no protected health information by policy | United States |
Privacy requests and contacts
For further information about our privacy practices, or to raise any privacy requests or complaints in relation to your data, please contact us using the following methods:
- Privacy Officer: Praneet Mhatre, Chief Technology Officer
- Email: privacy@lumara.health
- Web: this page, https://lumara.health/privacy
Changes to this statement
We review this Privacy Statement at least annually and whenever our services or the law change. The current version is published on this page with its effective date.