1. Controller and contact
Privacy requests may be sent to privacy@iterluma.com. Authenticated participants may also use the Support area. Radiant is intended for adults aged 18 or older.
2. Data and purposes
Depending on how you use Radiant, we process account and application details, readiness answers, learning progress, attempts, evidence, support messages, first-party product events, public repository information, pinned revisions, automated verification results, and connection or security records.
We use this information to evaluate applications, manage invitations and accounts, deliver learning and support, verify project evidence, protect the service, meet legal duties, improve the beta, and defend rights. Optional product updates are sent only when separately requested.
Radiant does not sell personal data and does not request payment-card information during the free founding beta.
3. Legal bases and decisions
Processing may rely on steps requested before joining the beta, performance of the participant relationship, compliance with legal duties, legitimate interests balanced against your rights, regular exercise of rights, or consent when the law requires it.
Admission is not decided solely by the readiness score. The learning roadmap uses explainable rules to recommend activities, but those recommendations do not create legal or similarly significant effects and may change as new evidence is recorded.
4. Sharing and international processing
Radiant uses Hetzner Online GmbH to host the staging application and database in Nuremberg, Germany; Cloudflare, Inc. for authoritative DNS and encrypted R2 backups restricted to the European Union jurisdiction; Titan Solution Ltd SEZC for transactional and support email; UptimeRobot s. r. o. for public availability and API-health monitoring; and GitHub, Inc. for private source control, Actions orchestration, technical logs, and bounded artifacts.
Founding Beta participant personal data must not be placed in GitHub repositories, CI logs, or artifacts. Providers receive only the access needed for their function and must follow applicable contractual confidentiality, security, purpose, and incident-response requirements.
Some providers and disclosed subprocessors operate outside Brazil, including in the European Union, the United States, the Cayman Islands, Canada, Spain, Estonia, and other documented locations. International processing is limited to what is necessary and uses the contractual and transfer safeguards described in the applicable provider terms and data-processing agreements.
5. Retention and deletion
- Application access and security logs are normally kept for six months, unless a specific lawful need requires longer.
- Waitlist and unsuccessful application records are normally deleted or anonymized within twelve months after the last meaningful interaction.
- Participant account, learning, evidence, consent, project, and support records are kept during the relationship and normally for up to twelve months after closure.
- Repository archives and isolated workspaces are discarded after verification; bounded hashes, manifests, decisions, and results follow the account or evidence period.
- Optional marketing data is kept until withdrawal, with a minimal suppression record when needed to respect the opt-out.
- Encrypted off-host backups use a bounded rotation of 14 daily, 4 weekly, and 1 monthly snapshot in Cloudflare R2’s European Union jurisdiction. Incident records are retained when required by applicable rules.
Information may be kept longer when necessary to comply with law, respond to an authority, preserve evidence, or exercise or defend rights.
6. Security and incidents
Radiant uses access controls, password hashing, protected sessions, rate limits, private data networks, bounded backups, and isolated code execution. No system is risk-free. Relevant incidents are assessed and communicated to authorities and affected people when required by applicable law.
7. Your LGPD rights
Subject to legal conditions, you may request confirmation, access, correction, information about sharing, anonymization, blocking or deletion of unnecessary or unlawful data, portability when applicable, deletion of consent-based data, information about consent, withdrawal of consent, opposition, and review of relevant automated decisions.
Instructions are available on the Data rights page. Identity verification may be required before disclosing or changing account data.
8. Cookies and changes
Radiant currently uses only necessary authentication and security cookies and limited browser storage needed for assessment handoff and drafts. See the Cookie Notice.
Material changes receive a new version and effective date. Renewed acknowledgement or consent will be requested when required.