Legal
Privacy policy
Effective date: 21 September 2026
This policy describes what actually happens on lucentworks.online. The short version: the site sets no cookies, runs no analytics and has no forms, so the only personal information that exists is a server log held by the hosting provider and any email you choose to send.
1. Who is responsible
The controller of personal information described in this policy is:
- Ivan Kukulnyk s.r.o.
- Primátorská 296/38, Libeñ, 180 00 Praha 8, Czech Republic
- Company number: 19375280
- VAT number: CZ19375280
- Email: info@lucentworks.online
The company publishes this website under the name Lucent Works. Privacy enquiries reach a person at the address above; there is no separate privacy officer, and no third party handles these requests on the company's behalf.
2. What is collected
Two categories exist, and there is no third.
- Server logs, kept by the hosting provider
- When a browser requests a page, the web server records the request. The record contains the IP address the request came from, the browser's user agent string, the URL requested, the response status, the referring page where the browser sends one, and the date and time. This happens automatically on the hosting infrastructure and is not something the site's pages do.
- Emails you send
- If you write to the address above, the message reaches a mailbox: your email address, your name if you give it, and whatever you put in the message. Nothing is collected here that you do not choose to send.
To be specific about what is not collected: there are no cookies of any kind, no analytics, no advertising or conversion pixels, no tracking scripts, no local storage or session storage, no browser fingerprinting, no forms, no newsletter, no accounts, no chat widget and no third-party fonts, images or scripts loaded from anywhere else. The site makes no external requests. Affiliate links are ordinary links that lead to another website; this site places no tracker on your browser when you use one, and receives no personal information back from the advertising programme, only aggregate records of whether registrations occurred.
3. Why, and on what basis
Server logs are kept for security and diagnostics: identifying attacks, investigating errors and confirming the site is reachable. The company relies on its legitimate interests in keeping the site secure and working; this is not something you are asked to consent to, and because no cookies are set, no consent is required for anything.
Emails are processed for the single purpose of answering what you wrote about. Where the correspondence concerns a legal request, the basis is compliance with a legal obligation.
4. How long it is kept
- Server logs: retained by the hosting provider for up to 30 days in the ordinary course, then deleted or overwritten. A log preserved as evidence of a specific security incident is kept for as long as that incident is being dealt with and no longer than 12 months.
- Email correspondence: kept for up to 24 months after the exchange ends, then deleted. Correspondence that needs to be kept longer for a legal reason is kept only for as long as that reason lasts.
5. Who else sees it
The hosting provider, which operates the server and its logs, and the provider of the email service used for the address above. Both act as service providers to the company, not for their own purposes. Nothing is sold, rented or shared for advertising, and there is no analytics company, advertising network or data broker in this picture, because the site uses none.
Cross-border disclosure (Australian Privacy Principle 8). The publisher is established in the Czech Republic, and its hosting and email providers operate infrastructure outside Australia, including in the European Union. If you are in Australia, your IP address and the other log details listed above are therefore handled by recipients outside Australia, as is any email you send. By using the site and by writing to the address above, information about you is handled overseas in the way described here.
6. Security
The site is served over HTTPS, so traffic between your browser and the server is encrypted. Access to the server and to the mailbox is limited to the publisher, protected by unique credentials and multi-factor authentication where the provider supports it. The site holds no database of readers, no accounts and no payment information, which removes most of what could be lost. No system is perfectly secure, and this policy does not claim otherwise.
7. Your rights under the Australian Privacy Principles
If you are in Australia, the Australian Privacy Principles under the Privacy Act 1988 (Cth) describe rights of access to and correction of personal information; they are published by the Office of the Australian Information Commissioner at oaic.gov.au.
To exercise them, write to info@lucentworks.online, ideally from the address you originally used, since that is how a request can be matched to anything held. Requests are answered within 30 days. In practice, the only information likely to be held about you is an email exchange; server logs are not indexed by person and generally cannot be linked to an individual without additional information.
If you are not satisfied with the response, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au, which accepts privacy complaints and explains its process there.
8. Data breaches
If a breach of personal information occurs that is likely to result in serious harm, the publisher will assess it promptly and, where the Notifiable Data Breaches scheme applies, notify the affected individuals and the Office of the Australian Information Commissioner in accordance with that scheme, which the Commissioner describes at oaic.gov.au.
9. European and United Kingdom rights
The publisher is established in the Czech Republic, so the General Data Protection Regulation applies to its processing, and equivalent rights apply under the United Kingdom GDPR for readers there.
The legal basis for keeping server logs is legitimate interests (Article 6(1)(f)) — specifically, keeping the site secure and diagnosing faults. The basis for handling email is legitimate interests in responding to correspondence, or compliance with a legal obligation where that applies. There is no consent basis anywhere on this site because nothing here requires consent: no cookies are set and no tracking takes place.
Subject to the conditions in the legislation, you have rights of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests. Requests go to the email address above. You may also complain to a supervisory authority — in the Czech Republic, the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), and in the United Kingdom, the Information Commissioner's Office.
10. Children
This site is written for adults and is not directed at people under 16. It collects nothing from anyone, including children, and it has no account, no form and no mechanism through which a child could provide personal information. If a parent or guardian believes a child has sent an email containing personal information, write to the address above and the correspondence will be deleted.
11. Changes to this policy
If the site ever adds anything that collects or processes personal information — an analytics tag, a form, a third-party script — this policy and the cookie policy will be updated in the same change, before the addition goes live, and any consent mechanism required will be in place first. The effective date at the top of this page shows when the current version took effect. Material changes will be summarised on this page.