LumiBaseDocs

Data Map — Personal Data Inventory

Kiểm kê nơi LumiBase lưu dữ liệu cá nhân, làm cơ sở cho thông báo quyền riêng tư và khai báo trên store (Google Play Data safety, Apple Privacy Nutrition Labels) và để khoanh vùng yêu cầu của chủ thể dữ liệu.

⚠️ Không phải tư vấn pháp lý. Đây là tài liệu kỹ thuật. Triển khai của bạn có thể thêm collection/field tuỳ biến chứa dữ liệu cá nhân khác — hãy mở rộng bản đồ tương ứng. [Inference] Phân loại dưới đây phản ánh schema mặc định, không phải mô hình nội dung của bạn.

1. Định danh & truy cập

BảngDữ liệu cá nhânMục đíchLưu giữ
usersemail, họ tên, avatar, preferences, external_id, password_hash, tfaXác thực, hồ sơĐến khi erasure (ẩn danh tại chỗ)
user_sites, user_roles, user_policiesliên kết user↔site/role/policyPhân quyềnXoá khi erasure
api_keyshash token*, người tạo, IP dùng gần nhấtTruy cập lập trìnhĐến khi thu hồi
login_attemptsemail, IP, kết quảChống brute-forceLUMIBASE_AUDIT_RETENTION_DAYS (mặc định 90n)
login_baselineshistogram quốc gia/thiết bị/giờ per-userPhát hiện bất thườngXoá khi erasure
admin_backup_codesmã khôi phục đã hash*Khôi phục tài khoảnXoá khi erasure

* Bí mật/credential — được mask trong audit log và loại trừ khỏi data export.

2. Đồng ý & liên lạc

BảngDữ liệu cá nhânMục đíchLưu giữ
user_consentsuser id, loại consent, mốc grant/withdrawBản ghi đồng ý (GDPR Điều 7)Trạng thái hiện tại; lịch sử ở audit_log
email_suppressionsemail chuẩn hoáThực thi unsubscribe / opt-outĐến khi đăng ký lại
notificationsid người nhận/gửi, tiêu đề, nội dungThông báo in-appLUMIBASE_NOTIFICATION_RETENTION_DAYS (opt-in)

3. Nội dung & hoạt động

BảngDữ liệu cá nhânMục đíchLưu giữ
itemsnội dung do tác giả nhập; user_created/user_updatedKho nội dungSoft-delete (deleted_at) rồi dọn
revisionsuser_id (tác giả), delta, provenance agentLịch sử thay đổiTheo item
activityuser_id, IP, user-agent, payloadLog thao tácLUMIBASE_ACTIVITY_RETENTION_DAYS (opt-in)
audit_logemail actor/target, IP, quốc gia, metadata (đã mask)Vết audit bảo mậtLUMIBASE_AUDIT_RETENTION_DAYS (mặc định 90n)

4. Data export gồm gì

GET /api/v1/me/data-export trả về của người gọi: hồ sơ (loại trừ secret), consents, hoạt động, revisions tự viết và thông báo. Xem gap-analysis.md.

5. Erasure xoá gì

Account erasure do feature regulated-content-readiness xử lý qua admin POST /api/v1/admin/erasure (và Subject Access Request qua /api/v1/admin/sar), dựa trên erasure_requests (schema/regulated.ts) và apps/cms/src/services/erasure-service.ts. Xem user-rights-catalog.md.

6. Phân loại field

Field nội dung tuỳ biến có thể gắn nhãn qua fields.classification (none / internal / pii / phi). Field phân loại pii/phi bắt buộc mã hoá và bị mask mặc định trừ khi caller có read_decrypted; đọc giải mã được audit (field_access_log). Cung cấp bởi feature regulated-content-readiness.

7. Bên xử lý thứ ba

[Inference] Tuỳ triển khai. Thường gặp: host database (Postgres/Neon/Supabase), host edge/runtime (Cloudflare/Docker), transport SMTP/email, và sink CDC (ClickHouse) hoặc đích Firebase sync nếu cấu hình. Liệt kê sub-processor thực tế trong DPA — xem dpa-template.md.

Last modified: 26/09/2026