LegalPRIVACY POLICY
Effective date: 20 September 2026
This policy explains how Awuya Digital Limited, operating as Luma, handles personal data across our website, dashboard, and API. It’s written for three audiences at once: the business that runs a Luma account, the people on that business’s team, and the Recipients that business messages through Luma. Use the contents on the left to jump to what matters to you.
01Who we are and who this policy covers
Luma is a business communication platform operated by Awuya Digital Limited (RC 1663836), a company registered in Nigeria with its registered office at Ikeja Town Square, Obafemi Awolowo Way, Ikeja, Lagos, Nigeria (“Luma”, “we”, “us”, “our”). Luma lets businesses (“Customers”, “you”, when you hold a Luma account) send SMS, WhatsApp, and Email messages to their own customers (“Recipients”) from one wallet, one contact database, and one dashboard, with an AI writing assistant (the “AI Message Studio”) that helps draft campaign content.
This Privacy Policy explains how we collect, use, disclose, and protect personal data when you visit uselumaapp.com, create a Luma account, use the Luma dashboard or API, or are a Recipient who receives a message sent through Luma by one of our Customers. It applies wherever Luma operates, starting with Nigeria and extending as we expand across West and East Africa.
If you are a Recipient and want to know more about why you received a message, see “Recipients of messages sent through Luma” in Section 4 and “Your rights” in Section 10 — or contact the business that messaged you directly, since they control what they send and to whom.
02Definitions
- Personal Data — any information relating to an identified or identifiable natural person.
- Account Data — information you provide us directly as a Customer: signup details, billing and KYC information, team member details, and your business context profile.
- Recipient Data — the contact information (phone numbers, email addresses, names, and other attributes) that a Customer uploads to their phonebooks in order to message their own audience.
- Message Content — the text, media, and personalisation data contained in messages sent or drafted through Luma, including AI Message Studio briefs, generated variants, and delivery metadata.
- Processing — anything done to Personal Data: collecting, storing, using, disclosing, or deleting it.
- Data Controller — the party that decides why and how Personal Data is processed. Data Processor — the party that processes Personal Data on a Controller’s instructions.
03Our role: when Luma is a controller, and when we are a processor
We wear two different hats depending on whose data is involved, and it matters for how you should read the rest of this policy:
- Luma as Data Controller — for Account Data: your business’s own registration, billing, KYC, team, and usage information. We decide why and how this data is used, and this policy describes that use directly.
- Luma as Data Processor — for Recipient Data and the content of messages a Customer sends. When a Customer uploads a phonebook or sends a campaign, we process that data only on the Customer’s instructions, to deliver the service they’ve asked for (sending, tracking delivery, screening for compliance). The Customer is the Controller of their own Recipients’ data and is responsible for having a lawful basis — including consent, where required — to hold and message those contacts. See Section 4 for what this means if you are a Recipient.
Enterprise Customers who need a standalone Data Processing Agreement reflecting this split can request one from hello@uselumaapp.com.
04Information we collect
a) Account and signup data
First name, last name, work email, phone number, password (stored as a salted hash, never in plain text), company name, industry, role, and your explicit acceptance of this policy and our Terms of Service.
b) KYC and verification data
To verify your business and unlock higher sending and wallet limits, we collect CAC registration documents, Tax Identification Number (TIN), a director's government-issued ID (NIN, passport, or driver's licence), proof of address, and, where required for anti-money-laundering checks, bank statements.
c) Billing and wallet data
Wallet balance, funding and transaction history, and payment details processed on our behalf by a licensed Nigerian payment service provider. We do not store your full card number — that is handled by our payment processor under its own PCI-DSS obligations.
d) Recipient Data you upload
Phonebook contact records you import or add manually: names, phone numbers, email addresses, state, address, title, customer type, opt-out and DND status, and any custom fields you define. This is Recipient Data — see Section 3.
e) Message Content and delivery metadata
Campaign and single-message content, AI Message Studio briefs and generated variants, sender IDs, scheduling data, and delivery/read/click status per message and per carrier.
f) Developer and API data
API keys, webhook URLs and delivery logs, request logs (method, endpoint, status code, latency), and calling IP addresses.
g) Usage, device, and cookie data
Pages visited on our marketing site and dashboard, browser and device type, IP address, and analytics events, collected via cookies and similar technologies — see Section 11.
05How we use information
- To create and administer your account, authenticate you, and provide customer support.
- To send, route, and track the delivery of messages you compose or generate through the AI Message Studio, over SMS, WhatsApp, or Email.
- To calculate cost, debit and credit your wallet, process payments, and maintain transaction records.
- To verify your identity and business (KYC) and to meet our anti-money-laundering, counter-terrorism-financing, and know-your-customer obligations.
- To screen message content against NCC rules, DND obligations, and our own Acceptable Use Policy before send.
- To generate campaign copy through the AI Message Studio from the business context and campaign brief you provide, and to improve that feature — see Section 9 for AI-specific detail and your ability to opt out of contributing to model improvement.
- To detect, investigate, and prevent fraud, abuse, and security incidents.
- To comply with legal, regulatory, and law-enforcement obligations, including under the Nigeria Data Protection Act 2023, NCC regulations, and the Money Laundering (Prohibition) Act.
- To send you service communications (delivery reports, KYC status, wallet alerts, security notices) and, only with your consent, marketing communications about Luma.
- To analyse aggregated, de-identified usage trends to improve the product.
06Legal bases for processing
Where the Nigeria Data Protection Act 2023 and its subsidiary regulations (including the Nigeria Data Protection Regulation 2019, as continued in force) require a lawful basis, we rely on one or more of the following:
- Contract — processing needed to provide the Luma service you signed up for.
- Consent — for marketing communications, optional cookies, and any AI-training use of your data beyond what is needed to run the service.
- Legal obligation — KYC/AML checks, tax records, and responding to lawful requests from the Nigeria Data Protection Commission (NDPC), the NCC, or law enforcement.
- Legitimate interest — fraud prevention, service security, and product analytics, balanced against your rights and always subject to your right to object below.
07If you are a Recipient of a message sent through Luma
If a business used Luma to send you an SMS, WhatsApp message, or email, your contact details were uploaded to Luma by that business, not by you directly. That business is the Controller of your data and is responsible for having your consent (or another lawful basis) to hold your details and message you, and for honouring your opt-out request.
Every promotional message sent through Luma must include a way to opt out. Once you opt out, Luma excludes you from all future campaigns sent by that business across every one of their phonebooks, platform-wide, within 24 hours, and this exclusion cannot be reversed without your fresh consent.
To exercise a data-subject right (access, correction, deletion) over data a business holds about you in Luma, contact that business first, since they control the content and purpose of the data. If they are unresponsive, you may contact us at hello@uselumaapp.com and we will assist as the platform's processor, or you may lodge a complaint with the Nigeria Data Protection Commission.
08How we share information
We do not sell personal data. We share it only as follows:
- Delivery partners — mobile network operators, SMS aggregators, and WhatsApp Business Solution Providers, to route and deliver the messages you send.
- Payment processors — licensed Nigerian payment service providers, to fund your wallet and process transactions.
- KYC and identity-verification providers — to confirm the documents you submit.
- AI service providers — a third-party AI service provider processes AI Message Studio briefs and business-context inputs to generate campaign copy, under contractual confidentiality and data-protection terms. We have not finalised which provider we use as of the effective date of this policy; this section will be updated with the specific provider's name once selected, without changing the nature of this disclosure.
- Infrastructure and analytics providers — cloud hosting, error monitoring, and website analytics (including Google Analytics) that support running the platform.
- Regulators and law enforcement — the NDPC, the NCC, tax authorities, and law enforcement, where legally required.
- Successors — a party that acquires Luma or Awuya Digital Limited's business, subject to this policy continuing to apply to your data.
Every third party we share data with is bound by a written agreement requiring them to protect it and use it only for the purpose we specify.
09How long we keep information
We keep personal data only as long as necessary for the purposes above, or as required by law, on the following schedule:
| Data type | Retention period |
|---|
| Account data (profile, KYC, billing) | Duration of your account, plus 7 years after closure, to meet financial and tax record-keeping obligations. |
| Message content | 90 days after send, then deleted. Delivery status metadata (sent/delivered/failed/read counts) is retained for reporting purposes for the life of the account. |
| Recipient Data (phonebooks/contacts) | Duration of your account, plus 30 days after account deletion, to allow you to recover it, unless you request earlier deletion. |
| AI Message Studio briefs and outputs | Duration of your account, for audit and quality purposes, unless you opt out of retention for model-improvement use. |
| Security and access logs | 12 months. |
| API request logs | 30 days. |
| Webhook delivery logs | 7 days. |
| Cookies and analytics data | Per Section 11 and the retention settings of the underlying analytics provider. |
When we no longer need personal data, we delete it or irreversibly de-identify it.
10Your rights
Subject to the Nigeria Data Protection Act 2023, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request erasure of your data, subject to our legal retention obligations.
- Restrict or object to certain processing, including direct marketing.
- Receive a copy of your data in a portable format.
- Withdraw consent at any time, where processing is based on consent, without affecting processing already carried out.
- Request an explanation of any automated decision or AI-driven output that produces legal or similarly significant effects on you.
- Lodge a complaint with the Nigeria Data Protection Commission (NDPC), or your local data protection authority if you are outside Nigeria.
To exercise any of these rights, email hello@uselumaapp.com. We will respond within 30 days. We may need to verify your identity before acting on a request.
11AI Message Studio — how it uses your data
- The AI Message Studio generates campaign copy from the business context you provide (what you sell, who you sell to, your brand tone) and the specific brief you enter for a campaign. It never sends a message on its own — you or your team must select and send every message.
- Your business-context profile and campaign briefs are sent to our AI service provider to generate variants, and are stored with your account for audit purposes.
- By default, your account's AI inputs and outputs may be used in de-identified form to improve Luma's AI features. You can opt out of this use at any time from Settings without losing access to the AI Message Studio itself.
- Generated copy is screened against NCC content rules and our Acceptable Use Policy before it can be selected, but the final message — and responsibility for what is sent — remains yours.
12International data transfers
As of the effective date of this policy, Luma hosts and processes Customer, Account, and Recipient Data in Nigeria. As we expand across West and East Africa, or if we engage a service provider (such as an AI or infrastructure provider) that processes data outside Nigeria, we will only transfer personal data internationally where the Nigeria Data Protection Act 2023 permits it — for example, to a country with an adequate level of data protection, or under contractual safeguards equivalent to it — and we will update this policy to reflect any such arrangement.
13Cookies and tracking technologies
Our marketing website and dashboard use cookies and similar technologies to keep you signed in, remember preferences, and understand how the site is used. We use Google Analytics to measure website traffic and behaviour. You can control cookies through your browser settings; disabling them may affect parts of the site that rely on them, such as staying signed in.
14Children's data
Luma is a business tool and is not directed at children. You must be at least 18 years old to create a Luma account. If we learn that we have collected personal data from someone under 18 without appropriate authorisation, we will delete it.
15Security
- Data is encrypted in transit (TLS 1.3) and at rest (AES-256).
- Access to personal data is role-restricted and logged.
- API secret keys are hashed and cannot be retrieved in plain text after generation.
- We support two-factor authentication and maintain an audit log of security-sensitive account events.
- We conduct regular security reviews and aim for independent penetration testing on a recurring basis.
No system is completely secure. If a breach occurs that affects your personal data, we will notify you and, where required, the Nigeria Data Protection Commission, without undue delay.
16Changes to this policy
We may update this policy as our product, legal obligations, or vendors change. For material changes, we will give at least 30 days' notice by email or an in-app notice before they take effect. The "Effective date" at the top of this page always reflects the current version.