Privacy Policy
Last updated: September 2026
1. Overview
This policy describes what happens to personal data when you use this website or the Monte app. Personal data means any information that can identify you personally.
Responsibilities differ between the website and the app. LuminousApps is the controller for this website (section 2). For the data inside a daycare instance of the app, the respective facility is the controller; LuminousApps acts solely as a processor (section 4).
2. Controller for this website
LuminousApps — Patrick Kass, Wiltbergstrasse 90, Haus 37, 13125 Berlin, Germany, contact@luminousapps.de
3. Data collection on this website
Hosting: This website is hosted on Cloudflare Pages. For technical reasons Cloudflare records data such as IP address, browser type and access time. The legal basis is our legitimate interest in secure operation (Art. 6(1)(f) GDPR).
Contact: If you write to us or use the contact form, we store your details to handle your enquiry and any follow-up questions (Art. 6(1)(b) and (f) GDPR).
Demo instance: If you create a no-obligation demo via the form, we process the data you provide in order to set up the instance. Demo instances are deleted automatically.
4. The Monte app: who is responsible for what?
For processing inside each daycare instance, the respective facility is the controller within the meaning of Art. 4(7) GDPR. It decides on purposes and means and is your first point of contact for access, rectification and erasure.
LuminousApps provides the software and acts as a processor under Art. 28 GDPR — solely on the facility's instructions and never for its own purposes. A data processing agreement is in place with every facility.
5. Data processed in the app
| Area | Data |
|---|---|
| Account | Name, email address, password (stored only as a cryptographic hash), role, language setting, optional profile picture |
| Children | All details required to fulfil the care agreement, in particular name, date of birth, group, care hours, recorded consents, emergency contacts and authorisations |
| Health information | Allergies and intolerances as well as the reason given for an absence. These are special categories under Art. 9 GDPR and are only held in the app on the basis of explicit consent |
| Attendance | Daily attendance, drop-off and pick-up times with timestamps, lunch child status |
| Absences | Period, reason, optional notes, names of authorised collectors |
| Communication | News posts, notice board, parent group chat, team chat, comments and reactions |
| Participation | Entries in bring lists, parent duties and polls |
| Documentation | Uploaded images and files, group journal entries, records of developmental and learning progress |
| Staff scheduling | Where team planning is enabled: agreed working hours, recorded absences, clock-in and clock-out, corrections |
| Technical data | Session data, device push token, logs of security-relevant events (audit log) |
Biometrics: Sign-in via fingerprint or face recognition is verified exclusively by the device's operating system. Biometric characteristics are never transmitted to the app, the facility or LuminousApps, and are not stored there.
6. Purposes and legal bases
| Processing | Legal basis |
|---|---|
| Care and administration: master data, group, care hours, attendance, absences | Art. 6(1)(b) GDPR (care agreement), supplemented by (c) and (e) (statutory tasks) |
| Documentation of developmental and learning progress as a pedagogical duty | Art. 6(1)(c) and (e) GDPR in conjunction with the applicable state law |
| Sending essential notifications by email, platform security, abuse prevention, audit log | Art. 6(1)(f) GDPR (legitimate interest) |
| Parent account, photos in the app, access to developmental documentation, push notifications, content translation | Art. 6(1)(a) GDPR (consent) |
| Health information in the app | Art. 9(2)(a) GDPR (explicit consent) |
Consent is obtained by the facility. You may withdraw any consent at any time with effect for the future, without disadvantage. Processing carried out before withdrawal remains lawful.
7. Service providers
LuminousApps uses the following sub-processors to deliver the service. Indented entries are sub-processors of the provider listed above them.
| Provider | Purpose | Location | Use |
|---|---|---|---|
| Elestio Ltd., Dublin | Operation and administration of the server instance, backups | Ireland (EU) | standard |
| → Hetzner Online GmbH | Data centre for the production environment (database, files) | Falkenstein, Germany | via Elestio |
| → BorgBase | Encrypted backup storage. Encryption happens beforehand on our server; the storage provider cannot read the contents | Helsinki, Finland (EU) | via Elestio |
| → Amazon Web Services | Management layer of the hosting provider only (dashboard, monitoring, logs). No database contents, files or backups | Ireland (EU) | via Elestio |
| Cloudflare | Delivery, DNS, protection against attacks | EU / global | standard |
| Brevo (Sendinblue GmbH, Berlin) | Sending notification emails | EU / France | standard |
| Google Firebase | Delivery of push notifications | USA | only after explicit activation |
| Microsoft Azure | Content translation | EU endpoint | only after explicit activation |
Transfers to third countries: Personal data leaves the EU only where the facility has activated push notifications — a device identifier is then transmitted to Google Firebase in the USA, based on the EU Standard Contractual Clauses and the EU-US Data Privacy Framework. Without that activation, no data flows to providers outside the EU. The translation feature uses an EU endpoint.
8. Retention periods
| Data | Deletion |
|---|---|
| News posts and notice board | 6 months |
| Meal plan | 4 weeks |
| Chat messages | 1 year |
| Absence reports | 3 years |
| Group journal and attendance times | 5 years |
| Audit log | 2 years |
| Account and child data after the end of care | within 30 days; backup copies within 90 days |
Statutory retention obligations remain unaffected. Some providers keep technical residues longer, none of which contain child, parent or staff data: delivery logs at the email provider for up to three months, delivery data at the push provider for up to 180 days.
9. Your rights
- Access to the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interest (Art. 21 GDPR)
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR)
- Complaint to a data protection supervisory authority (Art. 77 GDPR)
For data inside a daycare instance please contact your facility — it is the controller there. For questions about the website or the technology, reach us at contact@luminousapps.de.
No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place.
10. Data security
- Encrypted transmission (TLS) and encrypted storage
- Server-side tenant separation: every database query is filtered by facility and user, so a facility only ever sees its own data
- Role-based access control (parents, team, management)
- Optional two-factor authentication and device binding
- Logging of security-relevant events
- Encrypted backups created daily
Questions about this policy? Write to contact@luminousapps.de.