Privacy Policy
This policy explains how Lutril processes personal data across the Access Governance platform, including access reviews, access requests, catalogue and policy workflows, delegated roles, integrations, and related audit and export capabilities.
1. Scope & Roles
This Privacy Policy applies to the Lutril Access Governance platform operated by Lutril SAS ("Lutril", "we", "our"). It covers the web application, APIs, integrations, and support operations available via Lutril domains. For customer workspace data, Lutril generally acts as a data processor and the customer acts as data controller. Lutril acts as controller for account administration, billing, and service security metadata.
2. Data We Process
- Account and workspace data: administrator and reviewer profile data (name, work email, role, auth settings, tenant identifiers).
- Identity and directory data synchronized from connected systems (for example Google Workspace, Microsoft Entra ID/Azure AD, HRIS, and SaaS connectors): user profiles, org units, manager links, groups, role assignments, and login activity metadata.
- Access governance data produced inside Lutril: access requests, justifications, policy routing, reviewer decisions, reminders, comments, role delegation, and workflow history.
- Catalogue and policy data: application records, owners, approval rules, risk and configuration metadata, and linked controls used in review workflows.
- Operational and security telemetry: logs, API usage events, diagnostic traces, and abuse-prevention signals required to operate and secure the Service.
- Generated outputs: exports and evidence artifacts such as CSV/PDF reports and dashboard snapshots created by authorized users.
3. How We Use Data
Integrations only run with scopes approved by customer administrators. Where relevant, Lutril requests read-only identity scopes first and minimizes write scopes unless explicitly required for a feature enabled by the customer.
- Provide and maintain tenant workspaces, user authentication, authorization, and access governance workflows.
- Ingest and normalize identity and app data so customers can review access, detect mismatches, and enforce least privilege.
- Run platform features including access reviews, access requests, catalogue management, policy enforcement, onboarding and offboarding support, and delegated approval roles.
- Generate customer-requested reports and audit evidence for compliance programs and internal controls.
- Detect, investigate, and prevent security incidents, fraudulent activity, and reliability issues.
- Provide customer support, troubleshooting, and service communications.
4. Legal Bases
- Performance of contract (Art. 6(1)(b) GDPR) to deliver the Service under the applicable Order Form or MSA.
- Legitimate interest (Art. 6(1)(f) GDPR) for platform security, abuse prevention, product reliability, and service improvement.
- Consent (Art. 6(1)(a) GDPR) where legally required (for example optional marketing or optional data-sharing features).
- Legal obligation (Art. 6(1)(c) GDPR) for accounting, regulatory, and lawful disclosure requirements.
5. Sharing & Subprocessors
Lutril does not sell personal data. Customer workspace data is logically isolated and is not shared across tenants. We disclose data only to authorized personnel and approved subprocessors required to deliver the Service. The current list of approved subprocessors is maintained on our Subprocessors page.
6. International Transfers
- Primary production hosting is in the EU whenever available for the deployed stack.
- When transfers outside the EEA occur, Lutril applies appropriate safeguards such as Standard Contractual Clauses and related transfer risk assessments.
- Support access is limited by least privilege and logged; elevated access is granted only when operationally necessary.
7. Security Measures
- Encryption in transit (TLS) and AES-256 encryption at rest for production data stores.
- Role-based access control, least-privilege operations, and audited administrative access.
- MFA requirements for privileged Lutril accounts and controlled deployment procedures.
- Monitoring, logging, and incident response processes designed to detect and remediate threats quickly.
8. Retention
- Customer data is retained for the active subscription term unless deleted earlier by customer action.
- Backups run daily and are encrypted at rest.
- After contract termination, data is deleted according to contractual commitments and operational backup cycles, unless legal obligations require longer retention.
- System and security logs are retained for limited periods necessary for security, forensic review, and reliability operations.
9. Data Subject Rights
- Depending on applicable law, individuals may request access, correction, deletion, restriction, objection, or portability.
- Because Lutril is typically processor for workspace data, requests should usually be submitted through your organization's Lutril administrator.
- Lutril assists customers in responding to valid data subject requests within applicable legal deadlines.
10. Incident Handling
Lutril maintains incident response procedures and notifies affected customers of confirmed security incidents involving customer data in accordance with contractual and legal requirements.
11. Policy Updates
We may update this Privacy Policy to reflect product evolution, legal requirements, or security practices. Material changes are communicated to customer administrators through the Service or by email before they take effect.
12. Browser Extension (Lutril DLP)
The optional Lutril browser extension is force-installed by customer administrators via their MDM (for example Google Workspace or Microsoft Intune) to help discover Shadow IT and prevent sensitive data from being pasted into AI tools. It is governed by this Policy, with Lutril acting as data processor and the customer as data controller.
- Shadow IT discovery: the extension reports the registrable domain of known-SaaS sites visited (matched on-device against a catalogue), together with hit counts and timestamps. It never transmits full URLs, page paths, query strings, or general browsing; only catalogue-matched SaaS domains leave the device.
- AI prompt DLP: on supported AI tools (for example ChatGPT, Claude, Gemini), the extension scans the prompt text entirely on-device to detect high-confidence PII and secrets (such as emails, payment-card numbers, IBANs, API keys, and tokens) and warns the user or redacts the data before it is sent.
- What is transmitted for DLP is metadata only: the AI tool's domain, the type and count of detected items (for example "1 email"), and whether the user was warned or redacted. The prompt text and the matched values themselves are never transmitted to or stored by Lutril.
- Attribution: events are associated with the work email provisioned to the device by the administrator's MDM. The extension requests only minimal permissions (navigation events, storage, and content-script access limited to the supported AI tools and the Lutril API origin).
13. Google API Services & Limited Use Disclosure
Lutril's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We only use data obtained through Google Workspace APIs (such as user profiles, org units, groups, and role assignments) to provide and improve the access governance features that customer administrators have enabled, including access reviews, access requests, and Shadow IT discovery.
- We do not transfer Google user data to third parties except as necessary to provide these features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with prior notice to customers.
- We do not use Google user data for advertising purposes, and we do not sell it.
- We do not use Google Workspace user data to develop, improve, or train generalized artificial intelligence or machine-learning models.
- We do not allow humans to read Google user data unless we have the customer's affirmative agreement, it is necessary for security purposes (such as investigating abuse), it is required to comply with applicable law, or the data has been aggregated and anonymized for internal operations.
14. Website Cookies & Analytics
This section covers visitors to lutril.com, not the Access Governance platform. Analytics run only with consent, requested by a banner on the first visit.
- Analytics provider: PostHog, on its EU cloud (eu.i.posthog.com). Listed on our subprocessors page.
- With consent, PostHog stores an identifier in your browser (a first-party cookie and localStorage entry named ph_<project>_posthog, retained up to 365 days) and records which pages you view and which buttons you click, to measure how the site is used. Legal basis: consent (Art. 6(1)(a) GDPR).
- Without consent, nothing is stored in your browser and no identifier is created. Visits are still counted in aggregate using an identifier derived on PostHog's servers, which needs no device storage. This gives us page counts only, with no profile, no cross-day identity, and no session recording.
- Your choice itself is stored in your browser (a localStorage entry named __ph_opt_in_out_<project>) so we do not ask again. That entry exists only to remember your answer.
- A separate cookie, NEXT_LOCALE, remembers your language. It is strictly necessary to serve the site in the language you picked and is therefore exempt from consent.
- To change or withdraw your choice at any time, use "Manage cookies" in the site footer. Withdrawing deletes the analytics identifier from your browser.
15. Contact
For privacy requests, DPA questions, or security and privacy concerns, contact privacy@lutril.com.