Privacy Policy

This Privacy Policy explains how DOBRICEAN IOAN-DORIAN PERSOANA FIZICA AUTORIZATA processes personal data when you visit lunasites.io, create or use a LunaSites account, purchase a plan, manage or visit a Luna-hosted site, submit a form to Luna, contact support, receive marketing, or connect an AI client through Luna MCP.


It also explains the important distinction between data Luna processes as an independent controller and data Luna processes as a processor on behalf of a LunaSites customer.


1. Controller identity and contact

For the controller activities described in this Policy, the controller is DOBRICEAN IOAN-DORIAN PERSOANA FIZICA AUTORIZATA, registered office ORS. NASAUD, STR. TUDOR VLADIMIRESCU, NR.22, Bistrita-Nasaud, ROMANIA, Trade Registry no. F06/336/2022, CUI 46952301.


Privacy contact: contact@lunasites.io


2. Scope and roles

Luna is generally a controller for account registration, authentication, billing, Luna marketing, support, product-security logs, abuse prevention and our own website analytics.


A LunaSites customer is generally the controller for personal data that the customer chooses to collect from its own site visitors—such as contact-form responses, newsletter signups, uploaded files and customer-configured analytics. For that data, Luna acts as processor under the customer’s instructions and the Data Processing Addendum. The customer’s privacy policy should explain its purposes and lawful bases.


Luna may still act as a separate controller for limited technical data needed to deliver, secure and defend the hosting service, comply with law and handle illegal-content notices. The exact role depends on the processing context, not merely on where data is stored.


3. Personal data we process, purposes and legal bases

The table describes the principal processing activities. We process only data reasonably necessary for the stated purpose, but exact fields depend on the features you use.


Account and authentication: name, email, account ID, authentication provider IDs, verification status, login and security events.

Purpose: Create and secure accounts; authenticate users; administer roles and access.

GDPR legal basis: Contract; legitimate interests in security and abuse prevention; legal obligation where applicable.


Sites and collaboration: Customer Content, site settings, templates, assets, domains, collaborators, permissions, drafts, publication state and action logs.

Purpose: Provide the builder, CMS, hosting, collaboration, publication, recovery and support.

GDPR legal basis: Contract; legitimate interests in reliable operation and service improvement.


Billing: billing identity and address, tax details, site ID, plan, renewal status, invoices, transaction IDs, payment status and limited card metadata.

Purpose: Process purchases, renewals, refunds, accounting, tax and fraud prevention.

GDPR legal basis: Contract; legal obligations; legitimate interests in payment security and claims.


Support and communications: messages, form submissions to Luna, screenshots, attachments, call or email metadata and feedback.

Purpose: Respond, troubleshoot, maintain service quality, document requests and resolve disputes.

GDPR legal basis: Contract; legitimate interests; consent where relevant.


Luna MCP and connected AI: client identity, OAuth grants and scopes, prompts or commands sent through Luna, tool calls, selected site, action results, approvals, logs and affected Customer Content.

Purpose: Authenticate connections, execute requested actions, prevent unauthorised writes, audit changes and support users.

GDPR legal basis: Contract; user instructions; legitimate interests in security and accountability.


Usage, analytics and device data: IP address, timestamps, browser/device, referring and requested URLs, page events, approximate location derived from IP, identifiers and error/performance logs, depending on configuration.

Purpose: Operate, secure and measure Luna’s sites and Service; detect abuse; understand feature usage; improve performance.

GDPR legal basis: Legitimate interests; consent for non-essential cookies or similar storage where required.


Marketing: email, subscription status, preferences, engagement and campaign source.

Purpose: Send product updates and measure communications.

GDPR legal basis: Consent, or legitimate interests where a lawful existing-customer exception applies; always subject to opt-out rights.


Legal and moderation data: illegal-content notices, identity/contact details, evidence, decisions, complaints, sanctions checks and legal correspondence.

Purpose: Comply with legal duties; protect rights; enforce Terms; respond to authorities and defend claims.

GDPR legal basis: Legal obligation; legitimate interests; establishment, exercise or defence of legal claims.

Where we rely on legitimate interests, those interests include operating a secure and useful SaaS platform, preventing fraud and abuse, supporting customers, measuring performance, improving features and defending legal claims. We balance those interests against the rights and expectations of affected individuals. You may object as explained below.


4. Data sources

We obtain personal data:

• directly from you when you register, purchase, build, publish, submit a form, configure a domain or SMTP service, contact us, join a mailing list, or exercise a right;

• from an account owner or collaborator who invites you or adds content about you;

• automatically from your device, browser, use of the Service, hosted-site requests and security systems;

• from payment, authentication, hosting, email, domain, analytics and other providers involved in a transaction or integration;

• from a connected AI client when it makes an authenticated Luna MCP request on your behalf;

• from LunaSites customers whose sites you visit or whose forms you submit; and

• from public sources, rights holders, complainants, authorities and fraud or abuse-prevention sources where lawful.


5. Customer sites, visitors, forms and analytics

A LunaSites customer decides what its site publishes, what form fields it asks for, whether consent is required, where notifications are sent, how long responses are kept and which third-party embeds or analytics it enables. The customer must provide its own privacy and cookie notices and a valid method for visitor requests.

When you submit a form, join a newsletter or otherwise interact with a customer site, the customer normally receives the data and controls the purpose. Luna processes the submission to store, display and transmit it as configured. Contact that site owner first for access, correction or deletion; we will assist the customer as required by our DPA and law.

Luna may process request logs and security signals for our own hosting security, fraud prevention, service integrity and legal compliance. A published site is public: information the customer publishes may be indexed, cached or copied by search engines and third parties beyond Luna’s control.


6. Payments

Payments are processed by Stripe. The processor may collect complete payment-card and billing data under its own privacy notice. Luna generally receives transaction identifiers, payment status, plan and renewal information and limited payment-method metadata needed for account and accounting records.


7. Luna MCP, OAuth and third-party AI providers

When you connect an AI client, Luna uses OAuth or another supported authorisation mechanism to identify the client and granted scopes. The client may send prompts, commands or content to Luna and may receive site data or action results within those permissions. Luna records enough information to execute, secure and audit the connection.


The AI provider independently processes information you submit to its client under that provider’s privacy notice and account settings. Do not connect a provider or send Customer Content unless you are authorised and have reviewed its retention, training and transfer terms. Revoking the Luna connection stops future access but does not delete data already retained by the third-party provider.


AI training: Luna does not use personal data, Customer Content, prompts or commands to train AI models.


8. Cookies, local storage and similar technologies

We and our providers may use cookies, browser local storage, IndexedDB, pixels and similar technologies. Strictly necessary technologies support authentication, security, CSRF protection, load balancing, session continuity, account preferences and requested features. Where the law allows, these operate without consent because the requested service cannot function reliably without them.

Analytics, advertising or other non-essential technologies will be used only after the consent required by Romanian and EU law. Rejecting non-essential technologies must be as easy as accepting them. You can change choices through

[COOKIE SETTINGS LINK OR CONSENT MANAGEMENT PLATFORM]

Public implementation review identified Luna’s first-party analytics script on lunasites.io and Firebase Authentication / App Check with Google reCAPTCHA on the dashboard, as well as browser storage for interface preferences. The exact production inventory, provider, purpose, lifetime and first/third-party status must be verified before publication.

Cookie inventory: [INSERT A VERIFIED COOKIE / LOCAL-STORAGE TABLE WITH NAME, PROVIDER, PURPOSE, LEGAL CATEGORY AND EXPIRY FOR THE MARKETING SITE, DASHBOARD AND PUBLISHED CUSTOMER SITES]

Customer sites may add their own embeds, scripts and cookies. Those are controlled by the site owner, who must configure notices and consent. Browser controls may delete stored data but can impair requested functions.


9. How we share personal data

We may disclose personal data only as reasonably necessary to:

• hosting, infrastructure, content-delivery, authentication, security, analytics, payment, email, support and professional-service providers acting under contract;

• a LunaSites customer, site owner or authorised administrator for data collected through that customer’s site;

• a connected AI or third-party service that you instruct us to use;

• professional advisers, auditors, insurers and financing parties subject to confidentiality;

• competent courts, regulators, law-enforcement bodies or other authorities where legally required or necessary to protect rights and safety;

• a buyer, investor or successor in a merger, financing, reorganisation or sale, subject to appropriate safeguards; and

• other parties where you request or validly consent to the disclosure.

We do not sell personal data for money. If a future activity qualifies as a sale, sharing for cross-context behavioural advertising or another regulated disclosure, we will update this Policy and provide required choices before beginning it.

Subprocessor list: [PUBLISH A VERIFIED SUBPROCESSOR LIST WITH LEGAL ENTITY, SERVICE, PROCESSING LOCATION AND TRANSFER MECHANISM]

Technical confirmation needed. Publicly observable services include Vercel for the dashboard, Render-hosted Luna API endpoints, Google/Firebase Authentication and App Check/reCAPTCHA, Google Fonts, and Bunny CDN-hosted media. These observations do not prove the complete processor chain or contractual legal entities; the engineering and privacy owners must confirm the production list.


10. International transfers

Some providers or recipients may process personal data outside Romania or the EEA. Where a destination is not covered by an adequacy decision, we use an appropriate transfer mechanism such as the European Commission’s Standard Contractual Clauses, together with supplementary measures where necessary. You may request information about the relevant safeguards from the privacy contact, subject to protection of confidential and security information.


11. Retention

We retain personal data only for as long as necessary for the purposes described in this Policy, taking account of customer instructions, legal obligations and the need to establish, exercise or defend legal claims. The following retention periods apply:


  • Account profile and authentication data: for the duration of the account and up to 30 days after account closure.


  • Customer Content and site data: retained for a recovery period of up to 30 days after deletion or termination. Residual backup copies are removed within 90 days of the initial deletion or termination, not an additional 90 days after the recovery period. Backup copies are isolated from ordinary use pending expiry.


  • Form responses: 12 months from submission by default, unless the customer specifies a different period justified by the collection purpose and applicable law.


  • MCP authorisation, tool and audit logs: 90 days from the logged event. We minimise logged content and avoid retaining full prompts or Customer Content in these logs. MCP access and tokens are revoked when the connection is disconnected; log retention does not extend access.


  • Technical and request logs: 30 days from collection.


  • Security logs: 90 days from collection. Records needed to investigate a specific incident may be retained longer under the limited exceptions below.


  • Identifiable analytics data: 6 months from collection, followed by deletion or irreversible anonymisation.


  • Support messages and attachments: 12 months after the request is closed.


  • Billing, invoices and tax records: for the mandatory retention period under applicable Romanian accounting and tax law.


  • Newsletter subscriptions and marketing records: until consent is withdrawn or an objection or unsubscribe request is received. We review inactive subscriptions after 24 months without interaction and delete records that are no longer necessary. Marketing messages stop immediately upon unsubscribing. A minimal suppression record may be retained for as long as necessary to honour the opt-out and prevent accidental resubscription.


  • Illegal-content notices and moderation decisions: 12 months after resolution. Records relating to a legal dispute are retained only for as long as necessary to establish, exercise or defend legal claims.


Longer retention is limited to data necessary to comply with a legal obligation or legal hold, investigate a specific fraud or security incident, or establish, exercise or defend a legal claim. Access to these records is restricted, and the continuing need for retention is reviewed periodically. When data is no longer needed, it is deleted or irreversibly anonymised; residual backup copies remain isolated until the applicable backup expiry. Customer-controlled data is also subject to the customer's lawful instructions and applicable erasure obligations.

12. Security and personal-data incidents

We use risk-appropriate measures such as access controls, authentication, encryption in transit, logging, environment separation, vendor due diligence and incident procedures. The exact safeguards evolve and no system is completely secure. Customers must configure their sites, permissions, embeds, SMTP credentials and connected AI clients securely.

If a personal-data breach affects data for which a customer is controller, Luna will notify and assist the customer as required by the DPA. For Luna’s controller data, we will notify the competent authority and affected individuals where GDPR thresholds require it.


13. Your rights

Subject to GDPR conditions and exceptions, you may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time without affecting earlier lawful processing. You have an unconditional right to object to direct marketing.


You also have rights concerning decisions based solely on automated processing that produce legal or similarly significant effects. Luna does not currently intend to make such decisions about account users solely by automated means.


Automated enforcement confirmation: [CONFIRM WHETHER FRAUD, SECURITY OR MODERATION SYSTEMS CAN SUSPEND OR REJECT AN ACCOUNT WITHOUT HUMAN REVIEW; IF YES, DESCRIBE THE LOGIC, SIGNIFICANCE AND REVIEW RIGHTS]


Send a request to contact@lunasites.io. We may verify identity and authority. We normally respond within one month, subject to lawful extension for complexity or volume. There is usually no fee, but manifestly unfounded or excessive requests may be handled as GDPR permits.


For Customer Content controlled by a LunaSites customer, contact that customer first. If you contact us, identify the relevant site URL so we can route the request without disclosing data to an unauthorised person.


You may lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), Bd. G-ral Gheorghe Magheru 28–30, Sector 1, Bucharest, or through its current complaint channels at https://www.dataprotection.ro/. You may also complain to the supervisory authority of your habitual residence, workplace or the alleged infringement.


14. Children

LunaSites accounts are not intended for persons under 18. Customers must not use the Service to collect children’s personal data without a lawful basis, age-appropriate notice, required parental authorisation and appropriate safeguards. If you believe a child has provided account data to Luna contrary to this Policy, contact us.


15. Marketing communications

You may unsubscribe from marketing by using the link in an email or contacting us. Transactional, security, billing and service notices are not marketing and may continue while necessary. Customers using LunaSites newsletters or SMTP must maintain their own lawful subscription records and unsubscribe process.


16. Changes to this Policy

We may update this Policy to reflect product, vendor, legal or operational changes. We will post the new date and notify account users of material changes through email, the dashboard or another appropriate channel. Where a new purpose requires consent, we will seek it before that processing begins.


17. Contact

Controller: DOBRICEAN IOAN-DORIAN PERSOANA FIZICA AUTORIZATA


Address: ORS. NASAUD, STR. TUDOR VLADIMIRESCU, NR.22, Bistrita-Nasaud, ROMANIA


Privacy email: contact@lunasites.io


General contact: contact@lunasites.io


Build extraordinary websites. Keep your ideas in motion.

© 2026 Lunasites · Built for the beautifully ambitious.

Logo final