Privacy notice
Controller
LumeSec Technologies GmbH Rissach 10, 6092 Birgitz, Austria Commercial register FN 679364s, Landesgericht Innsbruck Email: hello@lumesec.ai
What happens when you simply read
Nothing that identifies you. AI Compass embeds no external fonts, no ad networks, no tag managers and no third-party analytics. The Geist typeface is served from the same server as the page.
Cookies
Only strictly necessary cookies are set:
| Cookie | Purpose | Lifetime |
|---|---|---|
NEXT_LOCALE | Remembers the chosen language | 1 year |
kompass-theme | Remembers light or dark appearance | 1 year |
kompass-level | Remembers the chosen level of detail | 1 year |
kompass-anon | Prevents repeat voting on the same page | 90 days |
kompass.session_token | Sign-in, only after registration | 30 days |
These are required for the service to work, so no consent is needed. No cookies are set for advertising or profiling.
Usage measurement
We measure usage entirely ourselves, in our own database in the EU. We record the event type, the path visited, the language, the chosen level of detail and — where present — the host of the referring page.
We do not record: IP address, user agent, device characteristics, or any cross-site identifier. Without an account, attribution to a person is not technically possible.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in improving the service. Retention: 400 days, after which only aggregated monthly figures remain.
Account and sign-in
An account is optional and only needed to open tools — templates, worksheets, datasheets and exports. Every explanation on this site is, and remains, accessible without one.
- Only your email address is required.
- There is no password. Sign-in uses a single-use link.
- Your name is collected only if you generate a certificate.
- A session lasts 30 days.
We also store your preferences, your saved articles, your learning progress and which tools you have opened. The last of these is what lets us improve content where it is actually used.
Legal basis: Art. 6(1)(b) GDPR — performance of the service you requested.
Newsletter
The newsletter is separate from registration. An account subscribes you to nothing.
Subscription uses double opt-in: after entering your address you receive a confirmation email, and only clicking it adds you to the list.
Legal basis: Art. 6(1)(a) GDPR. You can withdraw consent at any time with one click; every message contains a link.
Certificates
On completing a learning path you can generate a certificate of participation. It carries your name, the path, the date and a verification code, and is publicly retrievable at its verification address — that is its purpose.
If you delete your account the certificate remains valid but is anonymised: the name is removed and the verification code keeps working.
Recipients
| Recipient | Purpose | Location |
|---|---|---|
| Hosting provider | Running the application | EU |
| Database operator | Storing account data | EU |
| Resend | Sending sign-in and confirmation email | EU region |
Art. 28 GDPR processing agreements are in place with all processors. No transfer to a third country takes place.
External links
The "Partners and courses" section points to third-party offerings. Clicks pass through our own redirect so that we can count which recommendations are used — this creates the same event record described above, without an IP address. The linked offerings are governed by their own privacy notices.
Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20) and objection (Art. 21).
Access and erasure are self-service: your account page offers a complete JSON data export and a delete function. Deletion takes effect immediately and covers all associated records.
You may lodge a complaint with the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at.