Lux
Draft — not yet in effect. 7 items still to be completed (highlighted below).

Privacy Policy

Lux Edge, a Cozens Corp Company, an Indiana corporation (“Lux,” “we,” “us”)

Effective date: [DATE] Last updated: [DATE]

1. Introduction

This Privacy Policy explains how Lux Edge (“Lux”) collects, uses, discloses, and safeguards personal information in connection with the Lux platform and our websites (including monetizelux.com, luxedge.io and their subdomains) and related services (collectively, the “Services”). Lux operates a real-time offer-decisioning marketplace. When a consumer visiting a website operated by one of our seller customers (each a “Seller,” also called a “Publisher”) does not meet that Seller’s internal marketing-qualification criteria — for example, a declined or non-converting applicant on a debt-settlement or personal-loan page — the Seller’s page calls the Lux decisioning service, and Lux’s machine-learning engine selects and ranks, from offers submitted by our buyer customers (each a “Buyer,” also called an “Advertiser”), a short slate of offers to display to that consumer. If the consumer clicks an offer, they are taken to the Buyer’s own website; any regulated downstream activity — consent collection, credit inquiries, telephone contact — occurs there under the Buyer’s own policies, not on Lux.

Lux operates primarily as a business-to-business service. In most of our processing activities we act as a service provider / processor on behalf of our business customers — the Sellers and Buyers described above (the “Controllers”) — who determine the purposes and means of processing. Consumers do not create Lux accounts, and the direct consumer relationship (and the consumer’s directly identifying information) remains with the Seller or the Buyer. Where we determine those purposes ourselves — for example, our own website, marketing, and account administration — we act as a business / controller, and this Policy applies directly.

2. Our data-minimization design

Lux is engineered to limit its exposure to raw personal information. In particular:

Lux does not collect or store consumer telephone numbers, raw credit reports, or consumer consent records as part of the decisioning flow. Those data elements are handled by the applicable Controller (e.g., a seller or buyer) under their own compliance obligations.

3. Information we collect

3.1 Information about business users

3.2 Consumer data processed on behalf of Controllers

The specific categories for each customer are governed by the applicable Data Processing Agreement (DPA) and its processing schedule.

3.2.1 Prefill relay

Where a buyer accepts them and a seller sends them, Lux relays a limited set of fields into the buyer's application form so a consumer does not retype what they have already provided. This is stated here for the first time; it was previously described in no customer-facing document.

3.2.2 Attributes Lux will not accept at all

Following counsel's direction of 2026-08-11, the decisioning API refuses any attribute constituting a prohibited basis under ECOA, Regulation B, or the Fair Housing Act: age (and any banding or derivation of it), race, ethnicity, color, religion, national origin, sex, gender, sexual orientation, marital or familial status, household size, receipt of public assistance, disability, and veteran or military status.

This refusal is absolute. It applies in every environment, in both strict and permissive validation modes, and regardless of any customer's configured allowlist — a customer cannot re-enable a prohibited basis by configuration. It binds at two independent layers: the request is rejected on arrival, and any campaign targeting rule referencing a denied attribute is dropped before it can influence a decision. The second layer is the load-bearing one, because campaign rules are read directly from the database rather than through an administrative interface.

A distinction that matters, and which this Policy states rather than leaves to inference. Three of the fields on the prefill allowlist in §3.2.1 — marital status, veteran status, and household size — also appear in the list above. That is deliberate and is not a contradiction:

The prohibition attaches to using a characteristic to evaluate or rank a credit offer, which Lux does not do. Relaying a value the consumer already supplied, to a form the consumer is choosing to complete, is not an evaluation. Lux additionally refuses veteran status as a decisioning input outright, which is stricter than the law requires.

3.3 Information collected automatically

Referrer control. The Lux offer page is served with Referrer-Policy: no-referrer, so no query parameter on that page — including any relayed prefill value — is disclosed to a Buyer's third parties through the referrer header when a consumer clicks through. This is a property of the offer page itself. An earlier draft attributed it to the outgoing redirect; that was inaccurate.

4. How we use information

5. How we disclose information

6. “Sale” and “sharing” of personal information

Certain U.S. state laws (including the California Consumer Privacy Act as amended by the CPRA) define “sale” and “sharing” broadly. Lux does not sell or share personal information as those terms are defined by the CCPA/CPRA. Contextual tuples used for learning are stripped of identifiers, and all processing for a customer is performed under a service-provider agreement that restricts use to that customer's business purpose.

Where Lux acts as a service provider under a written contract that prohibits retaining, using, or disclosing personal information except as necessary to perform the Services, such transfers are not a “sale.”

7. Your privacy rights

Depending on where you live, you may have some or all of the following rights, subject to legal exceptions:

To exercise these rights, contact us at pcozens.inc@gmail.com or [WEBFORM URL / TOLL-FREE NUMBER]. We will verify your request as required by law. You may use an authorized agent. Because much of the consumer data we hold is pseudonymized and processed on behalf of a Controller, we may need to route your request to the relevant Controller or require additional information to locate your data. Deletion requests are executed against the pseudonymized identifiers (the salted hash or the impression identifier); Lux cannot look up consumer records by name, email address, or telephone number because it does not store them.

European/UK residents: where GDPR/UK GDPR applies, you also have rights to restriction, objection, portability, and to lodge a complaint with a supervisory authority. Our lawful bases are [legitimate interests / contract / consent / legal obligation — CONFIRM].

8. Financial-data notice (GLBA)

Lux is an ad-decisioning technology service, not a financial institution, and is not directly subject to the Gramm-Leach-Bliley Act. Where Lux's customers are financial institutions with GLBA obligations of their own, Lux maintains administrative, technical and physical safeguards designed to support those downstream requirements, and any GLBA privacy notice is delivered by the financial institution rather than by Lux.

9. Data retention

We retain personal information only for as long as necessary for the purposes described in this Policy, to comply with legal, tax, and regulatory obligations, and to resolve disputes, in accordance with our Data Retention & Deletion Policy and the applicable DPA.

The principal periods confirmed by counsel are configured in the purge process and listed below. The purge process is configured and has been manually exercised; evidence of its first unattended scheduled execution is pending.

What Retained for
Pseudonymized consumer identifiers, decision, impression, click and conversion records 180 days from collection
Demo, simulator and marketing contact data 90 days from submission
Live security and audit log records 90 days from the event, and only once durably exported
Exported audit-log archives 365 days from generation
De-identified financial ledger records 7 years from settlement, for tax and accounting purposes

Point-in-time backup recovery covers a rolling 7-day window. A consumer deletion request is keyed to the pseudonymized identifier or the impression identifier, because Lux cannot search for a consumer by name, email address or telephone number — it holds none of them. Security and audit records are keyed by event rather than by consumer and are therefore not reachable by such a request; they age out on the schedule above instead.

10. De-identification, re-identification, and cohort reporting

Lux makes the following commitments publicly, because a technical control and a public undertaking are separate requirements under California law and Lux relies on both.

11. Security

We maintain administrative, technical, and organizational measures designed to protect personal information, including encryption of data in transit and at rest, access controls, salt/secret custody controls, and monitoring. No method of transmission or storage is completely secure. See our Incident Response & Breach Notification Policy for how we handle security incidents.

12. International transfers

Lux is based in the United States. If you access the Services from outside the United States, your information may be transferred to, stored, and processed in the United States. Where required, we rely on appropriate safeguards such as the Standard Contractual Clauses. [CONFIRM whether Lux processes EU/UK data.]

13. Children’s privacy

The Services are not directed to children under 16, and we do not knowingly collect personal information from children.

14. Changes to this Policy

We may update this Policy from time to time. Material changes will be posted with a new effective date.

15. Contact us

Lux Edge, a Cozens Corp Company, an Indiana corporation

[REGISTERED ADDRESS]

Email: pcozens.inc@gmail.com Data protection contact: [NAME], pcozens.inc@gmail.com