Product record
Actual surfaces, not borrowed credibility
Inspect the dashboard, monitor detail, incident record, demo workspace, and deliberate failure drill before trusting the product.
Privacy
Data matrix
Current controls only. No customer logos, certification claims, or hidden enterprise promises are implied by this matrix.
Control
Account and workspace
Current posture
Email, workspace name, membership, plan, billing state, and support context needed to run the account.
Proof surface
Settings, billing, workspace controls, DPA request path.
Owner
Luota controller
Control
Workflow evidence
Current posture
Monitor definitions, schedules, heartbeats, runs, payload JSON, snippets, incidents, and timeline events.
Proof surface
Monitor detail, incident detail, export, retention policy.
Owner
Customer controller
Control
Alert routing
Current posture
Channel names, delivery preferences, target membership, encrypted sensitive destination fields, and delivery attempts.
Proof surface
Alert routing, incident alert attempts, audit/export surfaces.
Owner
Customer controller
Control
Billing records
Current posture
Stripe customer/subscription state, invoices, plan limits, renewal or cancellation state, and legal accounting records.
Proof surface
Billing page, Stripe customer portal, invoice records.
Owner
Luota/Stripe
Control
Operational logs
Current posture
Request metadata, rate-limit counters, error telemetry, privacy-constrained page views, and Core Web Vitals samples.
Proof surface
Security posture, subprocessors, service diagnostics.
Owner
Luota ops
Control
Exit and deletion
Current posture
Workspace export is available; live data deletion is handled first, while encrypted backup expiry follows the backup retention window.
Proof surface
Export page, privacy request, DPA, backup retention note.
Owner
Luota + customer
Buyer record
Luota is pre-customer, so the commercial site shows product behavior, public controls, and buying mechanics directly. No invented testimonials, logo walls, or compliance claims.
Product record
Inspect the dashboard, monitor detail, incident record, demo workspace, and deliberate failure drill before trusting the product.
Public controls
Review the current security posture, privacy terms, DPA, subprocessor list, disclosure path, and live service status.
Billing state
Confirm workflow limits, retention, Stripe responsibility, cancellation behavior, and what changes after checkout.
Luota is a founder-operated workflow monitoring service. For account, billing, and service operations data, Luota acts as controller. For workflow payloads, run output, monitor events, alert routing, and incident evidence sent by a customer workspace, Luota acts as processor for that customer.
Privacy, deletion, export, DPA, and security requests go to support@luota.dev. Customers that need formal legal-entity details for procurement receive them through the signed DPA and invoice process.
Account and workspace data: email address, workspace name, workspace membership, active plan, billing state, and support messages.
Product data: monitor definitions, schedules, owner labels, runbook URLs, alert-channel configuration, heartbeats, runs, incident state, timeline events, deploy SHA, host/environment metadata, payload JSON, and output snippets.
Operational data: request metadata, rate-limit counters, application logs, error telemetry, Core Web Vitals samples, and privacy-constrained public page-view analytics used to operate and improve the service.
Service delivery: to detect missed, failed, late, stuck, slow, or stale workflow events and show the related incident evidence.
Billing and account administration: to keep Stripe subscription state, invoices, plan limits, account access, password reset, and customer support working.
Security and reliability: to prevent abuse, rate-limit ingest endpoints, investigate errors, verify backups, and maintain service integrity.
Contract: account access, monitor storage, alerts, billing, support, retention, and export/delete handling needed to provide the service.
Legitimate interests: abuse prevention, rate limiting, security logging, service diagnostics, and privacy-friendly performance measurement.
Legal obligation: invoice, tax, accounting, and compliance records that Luota or its processors must keep.
Monitor evidence follows the active plan: 7 days on Free and 30 days on Operator unless a written agreement says otherwise. Downgrades apply the shorter retention window on the next retention sweep.
Daily encrypted Postgres backups follow the documented backup cadence. Deletion requests remove live workspace data first; encrypted backup expiry follows the normal backup retention window.
Stripe billing records and legally required accounting records may be retained for the period required by payment, tax, and accounting obligations.
Primary application and database hosting is in the EU. Some processors operate outside the EU; those transfers rely on the processor's published safeguards such as SCCs, the EU-US Data Privacy Framework, or equivalent contractual measures.
The canonical subprocessor list is published at /subprocessors. A signed DPA is available at /dpa for customers that need Article 28 processor terms.
Depending on your role and jurisdiction, you may request access, correction, deletion, restriction, portability, or objection. Workspace customers can also request export of the workspace evidence Luota controls.
If your employer or customer controls the workspace data, Luota may route the request through that customer as controller. You can also contact your local supervisory authority.
For security posture and operational controls, read the public security page.
Open security posture