Privacy Architecture & Telemetry Rules
This document outlines the privacy-aware data handling practices governing the Lukul Atelier ecosystem operated by Lukul Atelier LLC. By accessing our public terminals, submitting applications, or initializing a client protocol, you agree to these rules. We process limited information needed to operate the Platform, respond to requests, manage access interest, support authorized users, and maintain careful operational records.
1. Service infrastructure and access boundaries
Lukul Atelier uses hosted infrastructure and managed services to operate public pages, account authentication, and supported product features. Access to account and training data is governed through authenticated application and database controls. Technical handling varies by service and environment; this policy does not make a universal encryption-at-rest or user-held database-encryption-key claim.
2. Limited Analytics (Cookieless)
We use Umami Analytics for privacy-conscious site measurement. This helps us understand aggregate usage patterns, site performance, content engagement, and limited technical signals such as page resolution, device type, and referrer context without building advertising profiles.
Because analytics cookies are not used for this measurement, we do not require—nor utilize—legacy cookie consent modals.
3. Form Submissions and Access Interest
When you submit a public contact form, waitlist request, business inquiry, or support message, you may provide personal information such as name, email address, message content, stated interest, and related delivery details. Public form submissions may be handled through trusted form-processing infrastructure and are used to respond to the request, manage access interest, and maintain operational records.
4. Application, Training, and Coaching Data
If you are an initiated client utilizing the LuKul Application (`/app`), the Platform may process account and profile details, training plans, workout logs, progress metrics, workout notes, readiness context, and coach/client relationship records where applicable. Data handling is designed around controlled access, operational safeguards, and careful data-handling boundaries.
Paid access is being prepared separately. Before public paid purchase paths open, payment-related privacy disclosures will be reviewed and updated as needed.
5. Autonomous Rights Execution
Under the GDPR (Article 17 and Article 20), you maintain full control over your data ledger.
- Right to Portability: Authenticated users may export their complete dataset via the `UNIVERSAL CSV EXPORT` system built directly into their terminal dashboard.
- Right to Erasure: To initiate deletion of eligible account, training, contact, support, or access-interest records, you may contact administration terminal at bespoke@lukulatelier.com or use the public Account Deletion route. Retention may apply where legal, security, tax, accounting, dispute, or fraud-prevention obligations require it.