This policy explains how Lulu AI handles personal data. It is intended to be transparent and practical. If a signed order form, data processing agreement or company notice identifies a specific contracting entity, address or controller, that document controls for that customer relationship.
1. Who we are
Lulu AI provides business operating software, AI-assisted workflows, provider integrations, analytics, communications and growth automation. For the personal data processed through the service, the responsible controller or processor depends on how the service is used. In many workspace contexts, the customer is the controller of its own business, employee, prospect and customer data, and Lulu processes that data on the customer's instructions.
2. Data we process
We may process the following categories of data:
- Account data, such as name, email address, login identifiers, roles, workspace membership and authentication events.
- Business profile data, such as company descriptions, products, services, legal profile fields, operational records and connected business assets.
- Customer-supplied content, including uploaded files, notes, prompts, messages, knowledge-base entries, media, campaign material and generated drafts.
- Connected-provider data from services such as advertising, analytics, social platforms, email, calendars, payments, communications, commerce, storage or CRM systems, depending on what a workspace connects.
- Usage, security and diagnostic data, including logs, device and browser information, IP-derived metadata, API calls, error reports, audit events and abuse-prevention signals.
- Billing and transaction references, such as invoices, subscription records, wallet balances, provider payment references and tax-relevant records. Card details are handled by payment providers and are not stored by Lulu.
3. Why we process data
We process data to provide, secure, maintain and improve the service; authenticate users; operate workspaces; run requested AI and automation workflows; connect third-party providers; prepare drafts and recommendations; process payments; provide support; detect abuse; comply with legal duties; and keep records needed to resolve disputes or verify provider actions.
4. Legal bases
Where data protection law requires a legal basis, processing may rely on performance of a contract, steps requested before entering into a contract, legitimate interests in operating and securing the service, consent, compliance with legal obligations, or the customer's documented instructions where Lulu acts as a processor.
5. AI processing and automation
Lulu AI may send customer-provided content, business records and workflow context to configured AI providers or internal AI systems to analyze information, generate drafts, classify records, summarize content, recommend actions or execute approved workflows. AI output can be incomplete, inaccurate, biased, duplicated or unsuitable for a particular use. Customers remain responsible for reviewing outputs and deciding whether to use them.
6. Third-party providers
The service can connect to external providers selected or authorized by the customer, including Meta, Google, Microsoft, CRM, email, payment, communications, hosting, analytics, advertising, storage and AI providers. When a workspace connects a provider, data may be exchanged with that provider according to the customer's configuration, the provider's own terms and the provider's privacy practices. Lulu cannot guarantee the availability, accuracy, security, approval, pricing or policy behavior of third-party providers.
7. Sharing and processors
We share data only as needed to operate the service, comply with law, protect rights and security, or follow customer instructions. Recipients may include infrastructure providers, AI providers, payment processors, communication providers, analytics and monitoring providers, professional advisers, authorities when legally required, and connected services authorized by a workspace.
8. International transfers
Data may be processed in countries other than the country where the user or customer is located. Where required, Lulu uses legally recognized transfer mechanisms, contractual safeguards or customer-approved provider configurations. Customers should not submit data to Lulu or connected providers unless they are authorized to do so.
9. Retention and deletion
We keep data while an account or workspace is active and afterwards only for the periods needed for backup, security, audit, legal, billing, dispute-resolution and provider-verification purposes. Retention periods vary by record type. Some records, such as invoices, security logs, payment records and provider action evidence, may need to be retained even after an account is closed. Backup copies expire on their normal protected rotation.
10. Your choices and rights
Depending on applicable law, individuals may request access, correction, deletion, restriction, portability or objection, and may withdraw consent where processing is based on consent. Requests can be sent to privacy@lulu-ai.cn. We may need to verify identity and may route workspace data requests to the relevant customer controller.
11. Security
Lulu uses technical and organizational safeguards such as encryption in transit, access controls, workspace isolation, audit logging, provider credential protection and operational monitoring. No system is risk-free. We do not guarantee that the service, third-party providers, AI systems, networks or stored data will be uninterrupted, error-free, fully secure or immune from unauthorized access.
12. Children
Lulu AI is intended for business use and is not directed to children. Users must not submit children's personal data unless they have a lawful basis and all required authority to do so.
13. Changes
We may update this policy as the service, providers or law changes. Material changes will be posted on this page or communicated through the service where required. Continued use of the service after an update means the updated policy applies, to the extent permitted by law.
14. Contact
Privacy requests and security reports can be sent to privacy@lulu-ai.cn. Security reports may also follow security.txt.