Legal
Privacy Policy
Last updated: August 29, 2026
1. Who We Are and Scope
Luceryn is a product of AQ Professional Services Inc. (“AQ”, “Luceryn”, “we”, “us”), a corporation incorporated in Ontario, Canada. This policy explains how we handle personal information when you visit our website or use our product (the “Service”), and forms part of our Terms of Service. For content your organization puts into Luceryn, your organization is the controller of that data and AQ acts as a processor on its behalf, handling it under your organization's instructions and the Terms. Requests concerning data controlled by your organization should be directed to its workspace administrators.
2. Information We Collect
- Account information - name, work email, role, and organization, used to authenticate you and operate the workspace.
- Workspace content - the projects, plans, RAID items, documents, tickets, contacts, messages, and files your organization creates in the Service.
- Usage and log information - security-oriented logs (sign-ins, administrative actions), technical logs, and information about how the Service is used, collected to operate, secure, and improve the Service.
- Support and communications - messages you send us, support tickets, and related correspondence.
- Optional integrations - if your organization connects Microsoft 365 or similar services, data such as calendar and mail items is read within the scope your organization grants, to power the features that use it.
We do not sell personal information, and we do not set advertising or cross-site tracking cookies. See our Cookie Policy.
3. How We Use Information
We process information to provide, secure, and support the Service; to deliver the features you use (including AI assistance); to administer accounts and billing; to communicate about your account and the Service; to enforce our Terms and protect against fraud, abuse, and security threats; and to comply with legal obligations. We rely on your organization's instructions, the performance of our agreement with you, our legitimate interest in operating a secure and improving product, and consent where required.
We may also create and use aggregated, de-identified information (which no longer identifies any person or organization) for our lawful business purposes, including improving the Service and publishing aggregate trends.
4. AI Processing
AI features use Anthropic's Claude models via its commercial API. Only the specific content needed for a given task is sent. Under Anthropic's commercial terms, your data is not used to train models. Workspaces that require it can disable AI features. See our Security & Trust page and Trust Center.
6. Security, Storage and Retention
Data is encrypted in transit (TLS) and at rest, and is isolated per organization using database row-level security. Access to production systems is restricted and logged. No method of transmission or storage is completely secure, and while we employ commercially reasonable safeguards, we cannot guarantee absolute security. If a personal-data breach affecting you occurs, we will notify the affected organization (and, where legally required, regulators and individuals) without undue delay.
We retain information for as long as your organization's account is active and as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Administrators can configure retention for certain items. Following account closure we delete or de-identify information within a reasonable period, except where retention is required by law or for legitimate business records (such as invoices).
7. Your Rights
Depending on your location, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. Because most data in the Service is controlled by your organization, please direct requests to your workspace administrator first; we will assist them. You can also contact us at [email protected]. We may need to verify your identity before acting on a request, and we aim to respond to verified requests within 30 days. Organizations can request a Data Processing Agreement (DPA) for their use of Luceryn.
8. Marketing Communications
We may send you service and account communications (which are part of operating the Service and cannot be opted out of while you hold an account) and, separately, marketing communications about Luceryn. Marketing messages include an unsubscribe mechanism, and we honour opt-outs in accordance with applicable anti-spam law, including Canada's Anti-Spam Legislation (CASL).
9. International Transfers
The Service is hosted in the United States, and our sub-processors may process data in the United States and other regions. Where required, cross-border transfers are protected by appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms. By using the Service you acknowledge that your information will be processed in these locations.
10. Children
The Service is intended for business use by individuals 18 years of age or older, and is not directed at children. We do not knowingly collect personal information from anyone under 18; if you believe we have, contact us and we will delete it.
11. Third-Party Sites
The Service and our website may link to third-party sites and services. Their privacy practices are governed by their own policies, and we are not responsible for them.
12. Changes and Contact
We may update this policy from time to time; material changes will be notified by email, in-app notice, or by updating the date above, and your continued use of the Service after a change takes effect constitutes acceptance. Questions or concerns? Email [email protected] and we will work with you to resolve them. See also our Terms of Service and Cookie Policy.