Products Solutions Resources Company Request Demo
Resources Documentation

Data & Security

Understand how customer information moves through your system.

Scope. This page explains how information moves through a Lumver workflow so you can assess it for your own business. It describes practice, not certification. Lumver does not currently hold a formal security certification, and we will say so plainly rather than imply otherwise.

What information may be collected

The exact fields depend on how your workflow is configured. In a typical Capture setup, this includes:

  • The content of the message a customer sent.
  • The channel it arrived through, and the timestamp.
  • Whatever identifier that channel provides — a name, a handle, a phone number or an email address.
  • Structured details extracted from the message, such as what is being asked about or a requested date.
  • The classification applied during qualification, and the resulting status.

You decide which of these your workflow captures. If a field is not needed, it does not have to be collected.

How information moves through a workflow

Information follows the same path as the inquiry itself:

An inquiry is received from the connected channel, processed to extract and classify its contents, written to the configured destination, and then summarized in a notification to the person responsible. Each stage is defined when the workflow is built, so you can see exactly where a given piece of information travels.

How AI may process information

The understanding and qualification stages use AI models to read the message and determine what is being asked. This means the content of an inquiry is processed by a language model as part of that step.

Two things are worth stating clearly. First, this processing happens to serve your workflow — it is not used to build a general dataset about your business. Second, AI classification is not infallible; it can misread an unusual message, which is why we recommend keeping a person in the path for anything consequential. The reasoning behind that is covered in Automation should know when to stop.

Where information may be stored

Storage depends on the destinations your workflow is configured to use. If records are written to a spreadsheet in your Google account, that data lives in your Google account, under your control and subject to Google's terms. If notifications go to email or a messaging platform, a copy of that summary exists there too.

This is worth mapping explicitly during setup. A workflow with four destinations means customer information exists in four places, each with its own access rules and retention behaviour. We will walk through this with you rather than leaving it implicit.

Who receives notifications

Only the destinations you configure. If a notification is sent to a shared inbox or a group channel, everyone with access to that destination can see the customer information it contains — including people who may not need it.

Where the information is sensitive, route it narrowly. Notifying a named person is almost always better than notifying a channel that happens to be convenient.

Every destination you add is another place customer information exists. Add them deliberately.

Collect only what you need

The strongest protection available to a small business is not a security product. It is not holding information it has no use for.

Before adding a field to a workflow, ask what decision it enables. If the answer is "it might be useful eventually," leave it out. Data you did not collect cannot be exposed, cannot be misrouted, and does not need a retention policy.

Questions

If you need specifics about how a proposed workflow would handle your data — including where it would be stored and who would be able to see it — ask before signing anything. We would rather answer a detailed question than have you assume. Write to hello@lumver.co.

Our general handling of data is described in the privacy policy.