Lumeon and GDPR
CertReports found no public GDPR evidence for Lumeon as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 8 Dec 2025
- Expires or valid through
- 8 Dec 2026
- Scope
- HOW WE USE PERSONAL DATA Lumeon respects an individual’s privacy and is committed to protect their personal data. We will only use personal data when the law allows us to. Most commonly, we will use personal data in the following circumstances: • Where we need to perform the contract we are about to enter into or have entered into with an individual. • Where it is necessary for our legitimate interests (or those of a third party) and an individual’s interests and fundamental rights do not override those interests. • Where we need to comply with a legal obligation. PURPOSES FOR WHICH WE WILL USE PERSONAL DATA Lumeon has reviewed the areas of processing it undertakes and identified the main areas of activity as: • Holding and, to extent necessary for supporting customer contracts (e.g. technical support of live system), interacting with patient data as data processor (customer is data owner); • Facilitating flow of personal data relating to customers’ patients to third parties/partners where necessary/permitted under arrangements in place between customer (data owner) and 3rd party (e.g. information for patient payments); • Employee-related data needed and processed for purposes of employment of individual • Data concerning contacts at (prospective) customers, suppliers and partners processed in relation to those relationships and/or fulfilling contract rights and responsibilities. THE DATA WE COLLECT We may collect, use, store and transfer different kinds of personal data, which we have grouped together as follows: • Identity Data includes first name, last name, username or similar identifier (if a customer is seeking customer portal access). • Contact Data includes personal or business address, email address and telephone numbers. • Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, devices type you use to access this website. • Profile Data includes your username and password. • Personal data, including name, date of birth, address and emergency contact/next of kin details • Additional contact details, including phone numbers and email addresses • Payroll data including tax, National Insurance and bank details • Proof of right to work at the place of employment for the entire period of employment, including copies of passports, visas and birth certificate, where needed • Compliance documents, including criminal record checks where needed and referencing information We may share your personal information with other entities in Lumeon Ltd, Lumeon LLC and their corporate owner Health Catalyst, Inc as part of our regular reporting activities on company performance, in the context of a business reorganization or group restructuring exercise, for system maintenance support and hosting of data. We may share your personal information with other third parties, for example in the context of the possible sale or restructuring of the business. We may also need to share your personal information with a regulator or to otherwise comply with the law. "Third parties" includes third-party service providers (including contractors and designated agents) and other entities within our group. The following are examples of activities carried out by third-party service providers: Office management and equipment, administration, and IT services. All our third-party service providers and other entities in the group are required to take appropriate security measures to protect your personal information in line with our policies. We do not allow our third-party service providers to use your personal data for their own purposes. We only permit them to process your personal data for specified purposes and in accordance with our instructions.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Lumeon LLC: Active: EU-US Certification, SW-US Certification, UK Extension Certification | Live pagesha256 ffc136dc1d |
- Kind
- listing
- Issued or listed
- 8 Feb 2018
- Scope
- HOW WE USE PERSONAL DATA Lumeon respects an individual’s privacy and is committed to protect their personal data. We will only use personal data when the law allows us to. Most commonly, we will use personal data in the following circumstances: • Where we need to perform the contract we are about to enter into or have entered into with an individual. • Where it is necessary for our legitimate interests (or those of a third party) and an individual’s interests and fundamental rights do not override those interests. • Where we need to comply with a legal obligation. PURPOSES FOR WHICH WE WILL USE PERSONAL DATA Lumeon has reviewed the areas of processing it undertakes and identified the main areas of activity as: • Holding and, to extent necessary for supporting customer contracts (e.g. technical support of live system), interacting with patient data as data processor (customer is data owner); • Facilitating flow of personal data relating to customers’ patients to third parties/partners where necessary/permitted under arrangements in place between customer (data owner) and 3rd party (e.g. information for patient payments); • Employee-related data needed and processed for purposes of employment of individual • Data concerning contacts at (prospective) customers, suppliers and partners processed in relation to those relationships and/or fulfilling contract rights and responsibilities. THE DATA WE COLLECT We may collect, use, store and transfer different kinds of personal data, which we have grouped together as follows: • Identity Data includes first name, last name, username or similar identifier (if a customer is seeking customer portal access). • Contact Data includes personal or business address, email address and telephone numbers. • Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, devices type you use to access this website. • Profile Data includes your username and password. • Personal data, including name, date of birth, address and emergency contact/next of kin details • Additional contact details, including phone numbers and email addresses • Payroll data including tax, National Insurance and bank details • Proof of right to work at the place of employment for the entire period of employment, including copies of passports, visas and birth certificate, where needed • Compliance documents, including criminal record checks where needed and referencing information
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Lumeon inc: Inactive | Live pagesha256 5e77796e57 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Lumeon GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.
No same-category vendor has GDPR evidence in the index yet.