Lutron privacy policy
Applies to: Multi-Country
Revised: July 25, 2024

Athena Privacy Notice

Lutron respects your privacy and provides you with control of your personal Data. This Privacy Notice is intended to assist you in making informed decisions when using Athena software (the “Software”) – including but not limited to the Lutron App (“App”) – which lets you control the personal data provided by you or collected by Lutron when you use the software. Please take a moment to read and understand it.

This Privacy Notice explains the Data we collect from you and how we use that Data when you use the services available from the App.


Please note that within the App you may be redirected to a Lutron website, in which case you should also review the privacy notices specific to that website.

Lutron is committed to the security and privacy of our customers’ information.

We design with security and privacy in mind.

The information we gather is used to enhance the Lutron brand experience for the customer.

We are transparent about the information we collect and how we use it.


The primary purpose of collecting Data is to provide you with enhanced functionality in the control your lighting control system. To control your lighting system via the App you must also:

  1. Connect the Athena system to the internet via a wired Ethernet connection.
  2. Have a Wi-Fi or cellular internet connection to the device on which you installed the App (usually a smartphone or tablet computer).

 

What Data categories do we collect, for what purpose, and who do we share it with?

Category:Purpose:Disclosed to:
Personal Data/identifiers (such as email address, facility manager’s name, street address location, etc.) that you provide.
  1. To allow you to access your account
  2. To allow Lutron to send you emails
  3. To identify your location (country)
  4. Connected system functionality.
  5. Remote troubleshooting based on request

Third-party providers, including:

  1. Cloud service providers
  2. Service providers that facilitate email communications from Lutron
Third party integrator functionality (optional)Third-party integrators – information disclosed for services that you requested.
Time-clocking functionality (optional) 

If enabled, we obtain only the general location (within a .6 mile/1 km area) of the Athena lighting control system, such as your city. The exact location is not recorded by us as it is not required to provide time-clocking/scheduling functionality.
 
Technical lighting system information including electronic network and internet activityTo enable connected lighting control system functionality

Third-party providers, including:

  1. Cloud service providers
  2. Third-party integrators – information only disclosed for services that you requested
  3. We may share your system log files to assist with troubleshooting issues or provide technical assistance that you request
  4. Service providers that monitor for up-time reliability and system security
Commercial information for Lutron marketing programs targeted to industry professionals such as: professional installers, designers, facility managers, building operators, building owners.For professionally installed systems, Lutron shares commercial information with the installing contractor (such as number of devices installed). Additionally, we provide the installing contractor’s name (as provided by the installer) to the system operator of the installed lighting control system.

 

  1. Personal Data/Identifiers you provide and configuration Data:

    The primary use of the Athena system is in commercial facilities. Primary users of the Athena software are likely to be:

    1. the installing electrical contractor,
    2. the lighting designer(s), and
    3. the facility manager(s).

    When an Athena system is designed and commissioned, multiple operational details are entered into the system configuration in order to ensure that the system operates according to your specifications. These configuration parameters are entered using the Athena design software (Lutron Designer) and transferred into the Athena lighting control system that is installed at your facility. The system configuration files may also be stored to cloud storage, if you have enabled that functionality.

    Lutron uses this System setup and configuration Data for the following purposes:

    1. To provide you with the ability to control your System with the App (combined with the lighting and technical information from the Processor – see below).

      We share your Data with third-party providers, primarily cloud service providers, to assist us in providing App functionality. If you have requested to integrate your Lutron system with a third party, we share your Data with that third party. See the section—"Your request to share Data with third-party systems” for more information.

      The following is required to be provided to European Union (“EU”) and United Kingdom (“UK”) users: The legal basis for use of your personal information is to perform our obligations in accordance with any contract that we may have with you. In this case, it is to ensure the system operates according to your specifications.

    2. To email you important service updates, such as account password reset requests, information on security updates, technical support information, etc.

      We may contact you by email for service and security-related notifications. An example of a security-related notification is an email confirming your account initiation, password changes, and similar changes that allow you to monitor any unauthorized access to your account. Additionally, we may send you a product support email approximately 1 week after your account is initiated to provide you with customer support contact information. Because this information is provided for App functionality, you cannot opt out of receiving these service and security related emails.

      We share your Data with third-party providers that assist us in delivering these emails to you.

      The following is required to be provided to EU and UK users: The service providers we use are located within the United States (or for select technical issues in India and Costa Rica), the transfer and use of your personal data is governed by transfer mechanisms deemed adequate (e.g., The EU-US Data Privacy Framework, UK-US Data Bridge, and/or appropriate transfer agreements based on EU/UK approved standard contractual clauses). The legal basis for our use of your Data for the purposes in this section is to perform our obligations in accordance with the contract that we have with you, in this case to provide security and service-related updates from us.

    3. To assess system up-time performance, to monitor for security threats and data quality, and to enable us to make informed business decisions.
       
    4. For Vive Systems, to maintain a backup copy of your System’s configuration in order to provide you with service in the event that your System becomes corrupted or is otherwise compromised and cannot be recovered through your own efforts. This feature is a user-enabled optional feature.

      The following is required to be provided to EU and UK users: The legal basis for use of your personal information is to perform our obligations in accordance with any contract that we may have with you and/or to respond to your request for assistance.

    5. To provide insights into the use of your space, including but not limited to energy and occupancy reporting (optional)
       
    6. If you have opted into marketing communications, we will use data to contact you about Lutron and third-party products or to ask you to provide feedback about your experience. You may unsubscribe from marketing communications at any time by clicking “unsubscribe” in the email.

      The following is required to be provided to EU and UK users: The legal basis for our use of your Data for the purposes described in this section is your consent.

    7. To respond to your inquiries regarding purchasing additional Lutron products or services.

      The following is required to be provided to EU and UK users: The legal basis for use of your personal information is to perform our obligations in accordance with any contract that we may have with you.

    8. We collect the name of the country where your system will be used to assist us in complying with country-specific laws such as data-privacy and email marketing rules.
       
  2. Technical lighting system information collected from the Athena lighting control system including electronic network and internet activity.

    We collect technical information from the System to enable system functionality. Examples of this information include: devices you have linked to your Lutron system such as dimmers, switches, remote controls, sensors, room names, scene details, timeclock event details, integration details (such as identifiers for third-party products that are part of any Third-party interoperability you have enabled), Lutron window shades, network configuration information and the MAC ID of the System.  

    If you have selected to use the Dashboard, we will also collect technical information such as energy reports, area occupancy history, and system alert to provide the reporting functionality of that dashboard.

    In addition to collecting technical information from the System, we also regularly push firmware updates to the system processor(s) for both functionality and security updates. Contact Lutron technical support for guidance on how to disable automatic firmware updates.

    We share your Data with third-party providers, primarily cloud service providers, to assist us in providing the App, Dashboard and System functionality. If you have requested to integrate your Lutron system with a third party we share your Data with that third party. See the section—"Your request to share data with third-party systems” for more information.

    The following is required to be provided to EU and UK users: The service providers we use are located within the United States and the transfer and use of your personal data is governed by transfer mechanisms deemed adequate (e.g., The EU-US Data Privacy Framework, UK-US Data Bridge, and/or appropriate transfer agreements based on EU/UK approved standard contractual clauses)). The legal basis for our use of your Data for the purposes described in this section is to perform our obligations in accordance with the contract that we have with you, in this case to provide the functionality for your App to control your lighting system and connected system functionality.

  3. For users in the United States, we use commercial information and electronic network/internet activity (obtained from the System and the App) internally within Lutron for product research and development, marketing, and analytical purposes. The processes we have in place allow us to look at users generally while not identifying any specific person.

Your request to share data with third-party systems

Your lighting control system can inter-operate with many third-party systems. By requesting such third-party interoperability, you are requesting an ongoing transfer of your Data to the third-party system. Each third-party has varying requirements of the quantity of your Data needed for their interoperability to function. Please be aware that some third parties require a complete set of your Data be continuously transferred for their interoperability to function. Any Data we provide to the third party at your request is not covered by this Privacy Notice as that data is no longer under our control. Any Data that you request us to provide to a third party is controlled by that third party’s privacy policy.

Your choices:

The App provides you with many options to customize the functionality of the lighting control system. Additionally, the App provides you with the choice to Share App usage and diagnostic information with us. You may toggle this feature in the “Send Usage Data”.

The following is required to be provided to EU and UK users: If you enable this functionality, we use your Data for understanding how the App is used (including number of devices connected to control), to diagnose problems with the App, and in product development/enhancement. 

We share this information with third-party providers who log and provide App usage and diagnostic information to us.

The following is required to be provided to EU and UK users: The legal basis for our use of your Data for the purposes described in this section is your consent.

Getting help from us:

Within the App, you may request assistance from us by sending system log files from the App to us. These log files contain a full copy of your lighting control system Data, including scene and button names to enable full troubleshooting. If you provide system log files to us, we use this Data for the purpose of diagnosing and responding to your inquiry requesting assistance. We retain log files you send to us for up to 1 year after we have addressed your request for assistance.

The following is required to be provided to EU and UK users:

We may share your system log files with Lutron United States operations and Lutron India operations (Lutron GL Sales and Services Pvt. Ltd.). Additionally, for select technical issues, we may share your log files with a contractor located in India or Costa Rica.

The legal basis for our use of your Data for the purposes described in this section is to perform our obligations in accordance with the contract that we have with you, in this case to respond to your request for assistance.

How to contact us to: request a copy of your data, request to have your personal data erased, or for other privacy inquiries.

  1. www.lutron.com/DataPrivacyRequest

  2. DataPrivacy@Lutron.com

  3. +1 (844) LUTRON1

For security reasons, we will need to verify that the person initiating a data request is authorized. As you must have an account for this App to function, upon our receipt of a Data request we will advise you to send certain information from within the App while you are logged into your account. We must receive the requested information within the provided time period in order for us to initiate your Data request. Should you use an authorized agent to initiate a data request on your behalf, you will need to coordinate the sending of the required account verification information to us with your authorized agent.

If you are contacting us via email or telephones, please be sure to include the nature of your request (e.g. request a copy of your data, request data erasure, etc.). Initiating a request will not impact your service level of the operation of your lighting controls system.

If you request erasure of required operational data, certain functionality provided by the App will be lost such as: the ability to use the App to remotely control your lighting control system, time-clocking, and third-party integrations.

We are required to advise residents of California that they may request the following

  • A copy of your personal information collected by Lutron
  • Deletion of your personal information;
  • Opt-out of the sale of personal information;
  • Correction of inaccurate personal information;
  • Limit the use and disclosure of sensitive personal information. 

The following is required to be provided to EU users regarding Data access and rights:

You have the following rights in relation to the Data we hold about you:

  1. Your right of access. If you ask us, we’ll confirm whether we’re processing your Data and, if so, provide you with a copy of that Data (along with certain other details).

  2. Your right to rectification. If the Data we hold about you is inaccurate or incomplete, you’re entitled to have it rectified. If we’ve shared your Data with others, we’ll let them know about the rectification where possible. If you ask us, where possible and lawful to do so, we’ll also tell you who we’ve shared your Data with so that you can contact them directly.

  3. Your right to erasure. You can ask us to delete or remove your Data in some circumstances such as where we no longer need it or if you withdraw your consent (where applicable). If we’ve shared your Data with others, we’ll let them know about the erasure where possible. If you ask us, where it is possible and lawful for us to do so, we’ll also tell you who we’ve shared your Data with so that you can contact them directly. Upon deleting your Data, backups of personal information may remain for a reasonable time with us before they are deleted. We may need to retain certain Data if required to do so for legal reasons. To remove the possibility of further Data being sent to us, you should remove the ethernet cable from your processor and uninstall the App from your device.

  4. Your right to restrict processing. You can ask us to “block” or suppress the processing of your Data in certain circumstances such as where you contest the accuracy of that Data or you object to us processing it. It won’t stop us from storing your Data though. We’ll tell you before we lift any restriction. If we’ve shared your Data with others, we’ll let them know about the restriction where it is possible for us to do so. If you ask us, where it is possible and lawful for us to do so, we’ll also tell you who we have shared your Data with so that you can contact them directly.

  5. Your right to data portability. You have the right, in certain circumstances, to obtain Data you’ve provided to us (in a structured, commonly used and machine-readable format) and to reuse it elsewhere or to ask us to transfer this to a third party of your choice. We will provide the Data in a comma separated value (CSV) format to you via email upon your request.

  6. Your right to object. You can ask us to stop processing your Data, and we will do so, if we are relying on our own or someone else’s legitimate interests to process your Data, except if we can demonstrate compelling legal grounds for the processing, or processing your Data for direct marketing.

  7. Your rights in relation to automated decision-making and profiling. You have the right not to be subject to a decision when it’s based on automatic processing, including profiling, if it produces a legal effect or similarly significantly affects you, unless such profiling is necessary for entering into, or the performance of, a contract between you and us.

  8. Your right to withdraw consent. If we rely on your consent as our legal basis for processing your Data, you have the right to withdraw that consent at any time.

  9. Your right to lodge a complaint with the supervisory authority. If you have a concern about any aspect of our privacy practices, including the way we’ve handled your personal information, EU users can report it to the data protection authority within your country.

International transfers of personal data

Some of our group entities and service providers are in the United States, Costa Rica or India. We may share information with such parties, and with a contractor located in India, for select technical issues.

The following is required to be provided to EU and UK users: When we transfer personal Data from the EU or UK to the United States and India, such transfers are governed by mechanisms deemed adequate (e.g., The EU-US Data Privacy Framework, UK-US Data Bridge, and/or appropriate transfer agreements based on EU/UK approved standard contractual clauses). Such a transfer may also be necessary in order to perform a contract with you/fulfill your request and/or through obtaining your explicit consent.

How long do we keep your Data & how do we protect it?

Provided you continue to use the lighting control system, we will retain your Data to provide the functionality you have requested. If your App or Dashboard is not used for the applicable period stated below, we will start the process to remove your account from our systems. You will receive at least 2 emails advising you to log into your account and/or use your system in order to keep your account active. Note that if your Data is only needed for a shorter period, we may delete it.

App Inactivity Periods:

  • Athena Systems: 5 years

  • Vive Systems: 10 years

  • myRoom XC Systems: 3 years

Dashboard Inactivity Period: 3 years with a current subscription.  60 days from subscription expiration.

We take security seriously and we follow industry best practices in securing Data, monitoring for potential abuse, and updating systems. We collect only the Data we need to fulfill the purposes stated in this Privacy Policy, and we will not retain Data for longer than necessary.

About us

Lutron Electronics Co., Inc. is headquartered in Coopersburg, Pennsylvania, in the United States. We are approximately 60 miles north of Philadelphia. We are an industry leading manufacturer of lighting control systems and have been in business for more than 50 years.

Contact us at: DataPrivacy@Lutron.com

The following is required to be provided to EU and UK users:

When we transfer personal data from the EU and/or the UK, the transfer and use of your personal data is governed by transfer mechanisms deemed adequate (e.g., The EU-US Data Privacy Framework, UK-US Data Bridge, and/or appropriate transfer agreements based on EU/UK approved standard contractual clauses).

For EU regulatory purposes, the data controller is:

Lutron Electronics, Co., Inc.
Attn: Data Privacy
7200 Suter Road
Coopersburg, PA 18036 USA

and our EU representative is: 

Lutron LTC
34 avenue des Champs-Elysées 
75008 Paris France 

Changes to this Privacy Notice

To ensure that you are always aware of how we use your personal information we will update this Privacy Notice from time to time to reflect any changes to our use of your personal information. We may also make changes as required to comply with changes in applicable law or regulatory requirements. We will notify you by e-mail of any significant changes. However, we encourage you to review this Privacy Notice periodically to be informed of how we use your personal information.

It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.

Lutron, Athena, myRoom XC and Vive are trademarks or registered trademarks of Lutron Electronics Co., Inc., in the US and/or other countries.

Lutron makes no claim to copyright protections for text provided by the European Commission.