For data protection and legal teams

What lumi collects.

Everything your reviewer needs, on one page: what we hold, what personal data exists, where it goes, what we do not yet have, and the documents a review asks for as downloads.

lumi does not collect data about your employees. It collects your organisation's reward policies.

What your pension match is, how many days of leave you offer, whether you enhance sick pay — answered by one of your own people through a structured questionnaire.

This is not a promise about how we behave. All 317 benchmark questions are multiple-choice, yes/no, or a number. None is free text. A member could not submit a payroll record, a name or a salary if they wanted to, because the form does not accept typing.

Every question we ask is published in full, without an account, in the metric register. You do not have to take this page's word for it — read the whole question set yourself.

01

What is collected

The questionnaire has 317 active questions. This is every answer format that exists in it — measured against the live question set, not described from memory.

Answer formatQuestionsCould it hold personal data?
Single choice from a fixed list246No — the options are ours
Multiple choice from a fixed list24No — the options are ours
A number by seniority level24No — numeric, by grade not by person
Yes / no16No
A single number12No
Free text0Does not exist

Where a question mentions an individual — “the typical value of an individual recognition award”, "can employees request an explanation of how their pay was determined" — it is asking about the policy, and the answer is chosen from a list. No instance of a person is ever described.

02

The personal data that does exist

Some is unavoidable, because people log in. It concerns the two or three colleagues who use the platform — not your workforce — and it is held in a separate database from the benchmark data, so the analytical store carries no identities at all.

DataWhyKept
Work email addressSign-in, and delivery of the one-time codeWhile the account exists
Display nameSo colleagues can see who did whatWhile the account exists
Password, hashedAuthentication. A bcrypt hash, never readableWhile the account exists
Session and invite tokensKeeping a session open; inviting a colleagueExpire automatically
Action logWho changed an answer or shared a view, and whenWith the organisation's record

One exception: if one of your users voluntarily suggests a new metric, their work email is stored with the suggestion so we can reply. It is removed when that person leaves your organisation.

03

Where the data goes

WhoWhat they processWhereSafeguard
Amazon Web ServicesHosting and encrypted backupsUnited Kingdom (London)AWS data processing agreement
Anthropic PBCNarrative in board packs, from figures onlyUnited StatesSCCs / UK Addendum · no training on inputs
PostmarkSign-in codes, invitations, resetsUnited StatesSCCs / UK Addendum

That is the complete list, maintained at the sub-processor list. Members who have accepted the Data Sharing Agreement are notified before it changes.

What reaches the AI sub-processor: aggregated and derived figures only — percentiles, medians, counts of organisations, the text of a policy option. No individual salary and no employee record is sent, because neither is collected. A signed data-minimisation attestation confirming this was appended to our Article 30 record and Legitimate Interests Assessment on 3 September 2026. If you would rather nothing left the platform, you can switch AI features off — either for yourself, or, if you are an Admin, for your whole organisation, in Settings and without asking us. An organisation-wide switch overrides every individual setting including new joiners, deletes AI text already generated for you, and costs you no benchmark function: the pages that carry AI commentary fall back to text lumi composes on its own servers. It can be switched back on by an Admin at any time.

04

What comes back out

Members see anonymised aggregates only — medians, percentiles and distributions. When fewer than five organisations answered a question, the whole card is hidden: on screen, in an export and in a board pack. Your raw answers are never visible to another member, and no aggregate can be resolved back to your organisation.

This is enforced in the calculation engine rather than in the interface, so it holds for exports and shared links as well as for the screen.

05

DPIA screening

Our assessment against the criteria that ordinarily trigger a Data Protection Impact Assessment. Offered as material for your DPO to review and reach their own conclusion — not as a substitute for it.

TriggerVerdictWhy
Special category dataNot presentNone is collected, and none can be entered
Large-scale processing of personal dataNot presentA handful of named users per member
Systematic monitoring of individualsNot presentOrganisational policies are compared, never people
Profiling or automated decisionsNot presentNo output concerns an individual; Article 22 does not arise
Matching or combining datasets about peopleNot presentAggregation is across organisations, not individuals
Data concerning vulnerable peopleNot presentBusiness users in a professional capacity
Innovative technologyPartlyA language model writes narrative from aggregate figures. It receives no personal data and makes no decision
International transferYesTwo US sub-processors under SCCs with the UK Addendum. Benchmark data is hosted in the UK

Our position: the processing that concerns your workforce is not personal-data processing at all, and the personal data that does exist is a small number of business contact records for your own colleagues. On that basis we would not expect a full DPIA to be required. Your DPO may reach a different view, and we will support whatever assessment you need.

06

Security, and what we do not yet have

In place today: multi-factor authentication enforced for every user, with an optional trusted browser that skips the emailed code for up to 30 days on a single-use rotating token; passwords stored as bcrypt hashes with brute-force throttling; encryption in transit and at rest; tenant isolation enforced at the server rather than in the interface; least-privilege administrative access; nightly encrypted off-site backups with a restore tested and evidenced rather than assumed; audit logging of sharing actions. lumi is Cyber Essentials certified — Periculo under IASME, certificate 000b5bc2-a54c-4f22-94ca-2d6188f58ddb, 7 September 2026; recertification due 7 September 2027.

Being equally clear about the gaps, because you will ask:

  • ISO 27001 and SOC 2 — not held. On the roadmap, not claimed.
  • Independent penetration test — not yet commissioned.

lumi is an early-stage company and says so. Our published principles commit us to not claiming certifications we do not hold, and this page is written to the same standard.

This page is written for a data-protection or legal reviewer. If you are assessing us on the technical controls themselves — hosting, patching, access control, backup and recovery — those are set out in full on the security page.

07

Exit

  • Export at any time, without asking us — every benchmark, register and document downloads as CSV, Excel or PDF.
  • Deletion on request — contributed data is removed from live systems within 30 days and excluded from later snapshots.
  • What cannot be recalled — aggregates already distributed, which do not identify you. Stated in the agreement rather than left to be discovered.
  • Never sold — not sold, rented or disclosed to any third party for their own purposes, and never used to train externally available models.
For your legal and data-protection teams

Download the paperwork.

The documents a due-diligence review usually asks for, as PDFs you can attach to your record. Each is generated from the text this site serves, so the download and the page can never disagree.

Need something else — the data-minimisation attestation, or a document not listed here? Email dpo@lumihr.co.uk.

What we commit to, in writing

  • Your own template, back within two working days. Send us your security or data-protection questionnaire in whatever format your process uses. We complete it and return it in your format.
  • The Data Sharing Agreement counter-signed on request. If your process needs a signed instrument rather than accepted online terms, say so and we will sign and return it. Reasonable amendments are considered rather than refused on principle.
  • A call with your DPO, not a sales call. Whoever is reviewing us can speak to the person who built the platform and wrote these answers. Ask for it and we will find a time that week.

These commitments describe how we work today, as a small UK company where one person answers these questions. If we ever cannot meet one of them, you will be told when we can, rather than left waiting.