Policies & agreements
Below are the documents that govern your relationship with Lumaa — whether you visit lumaa.ai, sign up as a Client, or are a call recipient. All are in force as of 8 May 2026.
Terms of Service
Plans, payment, SLA, liability, governing law (DIFC). The contract you accept when you sign up.
PrivacyPrivacy Policy
What personal data we collect, why, how long we keep it, and your rights under UAE PDPL.
CookiesCookie Policy
Which cookies we set, why each is necessary, and how to control them.
RulesAcceptable Use Policy
What you may and may not do with the Service. UAE TDRA-aligned. Incorporated into the Terms.
DisclosureRecording & AI Disclosure
How call recipients are informed of automated calling and recording, and how opt-outs work.
B2BData Processing Agreement
Controller / processor obligations for the personal data Clients process via the Service. Includes sub-processor list.
Sub-processors
The current sub-processor list is published as Annex A of the DPA. We commit to 30 days' written notice before adding or replacing a sub-processor that handles personal data.
Responsible disclosure
If you believe you've found a security vulnerability in Lumaa, please email security@lumaa.ai with reproduction steps. We will acknowledge within 5 business days and ask for a 90-day disclosure window before any public discussion. Please do not run automated scanners against tenants you do not own; CTF-style testing against your own tenant is welcome. A machine-readable contact is also at /security.txt per RFC 9116.
Contacting us
- Privacy / data subject rights: privacy@lumaa.ai
- Legal / contracts: legal@lumaa.ai
- Security / responsible disclosure: security@lumaa.ai
- Abuse reports: abuse@lumaa.ai
- General: hello@lumaa.ai
Postal: Lumaa AI FZ-LLC, Dubai, United Arab Emirates.
Regulatory references
- UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL).
- UAE Federal Decree-Law No. 34 of 2021 on Combating Rumours and Cybercrime.
- TDRA Consumer Protection Regulations.
- UAE Federal Tax Authority record-keeping rules (5-year invoice retention).