Maqaas · Legal
Maqaas Privacy Policy
Effective Date: September 20, 2026
This Privacy Policy describes how Lumara Labs, LLC, a Delaware limited liability company (“Lumara,” “Maqaas,” “we,” “us,” or “our”), processes information in connection with the Maqaas website, application programming interfaces (“APIs”), documentation, pilot programs, and related services (collectively, the “Services”).
Maqaas is designed as a business-to-business service and is not intended for consumer or household use.
1. Information We Process
Depending on how the Services are used, we may process information provided by customers through the Maqaas API, including invoice or document content, supplier and vendor information, purchase-order information, invoice numbers, monetary amounts, currencies, addresses, contact information, tax or company registration identifiers, payment or banking information, document filenames, email metadata or content, and other information contained in business documents submitted to the Services.
Customers may alternatively submit previously extracted facts. When the supported JSON decision endpoint is used in this manner, Maqaas can perform decisioning without submitting the underlying document to our configured third-party model provider. The document-upload endpoint uses model-based extraction and does not provide this bypass.
We also process operational information necessary to provide and protect the Services, including tenant information, API credential information, usage records, request identifiers, routes, response status information, latency information, idempotency information, and technical or error information.
API keys are not stored as plaintext credentials in the application database.
2. Business Documents
Maqaas is designed so that business documents submitted for processing are processed in memory and are not persisted by the Maqaas application as stored business documents.
The current Maqaas application database does not contain fields for storing submitted invoices, raw documents, extracted invoice facts, decision results, or evidence reports as customer-document records.
This does not mean that no information associated with a request can ever appear in operational systems. For example, technical or error logs may contain limited request-related metadata, and third-party infrastructure or model providers may process information as described below.
3. Artificial Intelligence and Automated Processing
Maqaas may use a third-party artificial-intelligence model to extract structured information from unstructured business communications or documents.
Where model-based extraction is used, information provided to our configured third-party model provider may include the sender, subject, message body, filename, and document text.
Certain other customer-provided information—including purchase-order context, vendor context, trusted banking details, Maqaas rules, tenant identifiers and API credentials—is not structurally included in the model extraction request in the current version of the Service.
Customers using the supported JSON decision endpoint can avoid model-based
extraction by supplying extracted_facts. The document-upload
endpoint uses model-based extraction and does not provide this bypass.
The model does not make the final Maqaas invoice decision. Maqaas applies its own deterministic, versioned decision rules to extracted or customer-supplied facts.
Maqaas does not execute payments, transfer funds, alter bank accounts, or independently communicate with suppliers as part of the current Services.
4. How We Use Information
We may process information to provide and operate the Services; authenticate customers and administer API access; extract structured information from submitted business content; generate decisions, evidence and related API responses; enforce usage allowances and rate limits; diagnose failures; maintain security and reliability; prevent misuse; provide customer support; maintain business and operational records; and comply with applicable legal obligations.
Lumara does not use customer-submitted business documents or their extracted content to train Lumara models or for advertising unrelated to providing the Services, unless the customer expressly agrees otherwise.
5. Service Providers
We use third-party providers to operate Maqaas. Depending on the manner in which the Services are used, these providers may process limited information on our behalf.
Current infrastructure and service providers include Railway, which provides application and database infrastructure; our configured third-party model provider, which performs model-based extraction when that functionality is invoked; Netlify, which hosts the Maqaas public website; UptimeRobot, which provides availability monitoring; GoDaddy, which provides domain and email-related services; and Google Fonts, which may receive ordinary browser/network information when website fonts are requested.
We may also use development and administrative services, including GitHub, that do not necessarily receive customer API content as part of ordinary runtime processing.
Third-party providers process information under their own applicable contractual and privacy arrangements.
6. Storage and Retention
The current Maqaas application does not persist submitted business documents as document records.
Maqaas does retain certain operational and account-related records necessary to operate and administer the Services, including tenant records, usage records, API-key records and idempotency-related records.
Maqaas does not currently maintain an automated fixed deletion schedule for these operational records. We retain such information for as long as reasonably necessary for service operation, security, administration, dispute resolution, legal compliance and other legitimate business purposes, subject to applicable law.
References in technical documentation to an idempotency period do not represent a general data-retention or automatic-deletion period.
Information processed by third-party service providers may be subject to those providers' own retention practices.
7. Logs
We maintain operational logs for security, reliability, troubleshooting and service administration.
These logs may contain technical information such as request identifiers, tenant identifiers, routes, status information, latency, decision-related metadata, errors and provider-related information. In certain document-extraction failure scenarios, a submitted filename may also appear in operational logs.
Customers should therefore avoid including unnecessary personal or confidential information in filenames.
We do not intentionally log plaintext API credentials or complete business-document contents as ordinary application telemetry.
8. Security
We use technical and organizational measures designed to protect the Services and information processed through them.
No method of transmission, processing or storage is completely secure, however, and we cannot guarantee absolute security.
Customers are responsible for protecting their API credentials and for promptly contacting us if they believe a credential has been compromised.
Unless expressly agreed in writing, the Services should not be interpreted as carrying a particular certification, regulatory approval or security accreditation merely because security controls are implemented.
9. International Processing
Lumara is a United States company, and the Services use infrastructure and providers that may process information in jurisdictions different from the customer's own.
Our current primary application/database infrastructure is configured in a United States region. Other service providers may process information from additional locations according to their infrastructure and contractual arrangements.
10. Customer Responsibilities
Maqaas customers determine what business information they submit to the Services.
Customers are responsible for ensuring that they have the necessary rights, permissions and lawful basis to provide information to Maqaas and to instruct Lumara and its service providers to process that information.
Customers should not submit information that is unnecessary for the business purpose for which they are using the Services.
11. Privacy Requests
Maqaas does not currently provide a self-service interface for deleting, correcting or exporting information.
Requests concerning access, correction, deletion or other privacy matters may be sent to support@maqaas.com.
We will evaluate requests according to the information available to us, our contractual relationship with the relevant customer, and applicable law. Where Lumara processes information on behalf of a business customer, individuals may need to direct their request to that customer as the organization controlling the relevant information.
12. Children
Maqaas is a business service and is not directed to children. Users of the Services must be at least 18 years old and authorized to act on behalf of the organization for which they use Maqaas.
13. Changes to This Policy
We may update this Privacy Policy as the Services, our practices or applicable requirements change. We will publish the updated policy with a revised effective date.
Where required by applicable law or contract, we will provide additional notice of material changes.
14. Contact
Lumara Labs, LLC131 Continental Dr, Suite 305
Newark, Delaware 19713
United States
Email: support@maqaas.com