Deerlight
Deerlight Privacy Policy
Privacy Policy for Deerlight.
1. Scope and controller
This policy explains how 南京灵澜智能科技有限公司, as personal-information controller, collects, uses, stores, shares, and protects information when providing Deerlight. It applies to the product’s website, app, online services, and directly related support.
The service is not designed specifically for children. A user who cannot independently consent to information processing under local law should have a guardian review this policy and provide any required consent. Contact privacy@lumenlan.com if you believe a minor submitted information without appropriate consent.
A third party independently controls its website, system, or account under its own privacy rules. This policy does not replace those rules. Current categories and triggers appear in the Third-Party Services notice.
2. Information we process
- Account and project: Lumenlan user identifier, shelf, project, member or integration identity, role, permission, project access credential, and action record.
- Knowledge content: uploaded documents and text, document versions, source ledgers, public repository addresses and imported content, candidate facts, evidence, knowledge entries, skills, and attachments.
- Intelligent services and delegation: knowledge excerpts needed to complete a request, retrieval and usage information, organization candidates and review state, and authorized tasks, related content, status, results, and write-back records sent to or received from Kite.
- Integration records: connected-tool identity, authorization range, action type such as create, read, or change, time, outcome, and security records.
3. Purposes and grounds
- Perform your request: create and authenticate an account, maintain sessions, synchronize state, process content, send notifications, fulfil payments and entitlements, provide remote or knowledge functions, and answer support requests.
- Protect security and reliability: verify devices and actions, prevent fraud and abuse, rate-limit, diagnose faults, restore backups, audit high-risk actions, and respond to security incidents.
- Meet legal obligations and protect legitimate interests: retain necessary transaction and dispute evidence, answer a lawful authority request, enforce agreements, and protect users, Lumenlan, or third parties.
- Where consent is legally required, we obtain it before processing and keep a record of the choice. Withdrawal does not sign you out of the current session, while necessary processing may continue for contract performance, security, disputes, or legal obligations.
- We do not sell personal information or use terminal text, private files, or knowledge-base content to build advertising profiles for other customers. A materially new purpose will be separately disclosed and authorized when required.
4. Device permissions and local processing
A browser, Kite, a connected tool, or the operating system may keep sign-in information, configuration, cache, logs, or a project access credential on your device. Use device lock and disk protection, and sign out, revoke credentials, and clear caches before sharing or disposing of the device.
Necessary cookies or local storage maintain sign-in, security, language, and service state and are not used for cross-site advertising. If nonessential analytics are introduced, we will provide the relevant notice and choice.
5. Sharing, processors, and public disclosure
We share information only as necessary to deliver a function you select, secure and operate the service, fulfil payment, follow your authorization, complete a corporate reorganization, or meet a legal obligation. Permissions, contracts, and audits restrict recipients. The Third-Party Services notice lists the principal current categories.
When you share a machine, project, archive, file, knowledge item, or connected notification service, the recipient can access content under the permission you grant. Check the recipient, term, and permission range. Copies made independently by that recipient may no longer be within our control.
We do not publicly disclose personal information unless you deliberately publish or share it or law requires disclosure. For a law-enforcement or regulatory request, we verify authority, scope, and process and limit disclosure where law permits.
6. International processing
Apple, an AI vendor, local agent, code host, app store, or another third party that you choose may process data outside your country or region. We do not describe dynamically changing service routes as a permanently fixed country or region.
For an international transfer, we use necessary contractual, access-control, encryption, or other safeguards under applicable rules and minimize the transferred content. If separate notice or consent is required, it will be presented before the feature is enabled. You should also review the region settings of the third-party account or model you select.
7. Retention and deletion
We retain information for the shortest period needed for its purpose, considering account state, archive or project settings, security, disputes, and legal duties. Periods differ by data and product, so we do not make an inaccurate single fixed promise.
After account or content deletion, we delete or de-identify active data where technically and legally feasible. Payment, refund, anti-fraud, security-audit, dispute, and legally required records may be restricted and retained. Backup copies remain isolated until normal rotation and are not restored to ordinary use.
Deleting this product’s content does not necessarily delete the shared Lumenlan account. Use the Platform or app account-deletion control to delete the shared account, and export material you need beforehand where the product supports export.
8. Security and incidents
We use risk-appropriate transport protection, irreversible protection or encryption for sign-in information, permission isolation, least privilege, security-operation records, protections against excessive requests, backup, and vulnerability remediation. Sensitive identity data such as a full phone number is shown only to authorized administrators; such access avoids public caching and is recorded without unnecessary personal information.
No internet or terminal service can promise absolute security. If an incident is likely to materially affect you, we investigate, contain, and remediate it under applicable rules and provide recommended steps through in-product notice, email, push, or another reachable method.
9. Your rights and choices
- Use supported controls to access, correct, or complete account and content information and manage devices, sessions, notifications, sharing, integrations, and cross-product authorizations.
- Delete content, withdraw a product legal consent, cancel a subscription, or request account deletion. We may re-verify identity to prevent impersonation.
- Ask for an explanation, obtain a copy where law requires, restrict or object to particular processing, and appeal an automation, account restriction, or request outcome.
- Submit a request to privacy@lumenlan.com with the product, account clue, and request type, but no password, verification code, or complete token. We respond after identity verification under applicable requirements.
10. Updates and contact
Material changes to products, data use, or applicable requirements receive reasonable notice. If renewed consent is required, we expressly request it before a later sign-in rather than treating silence as consent.
Privacy: privacy@lumenlan.com. Support and appeals: support@lumenlan.com. Controller: 南京灵澜智能科技有限公司.