Last updated: May 10, 2026
lumina-fusion is committed to protecting the privacy and security of personal data in accordance with the General Data Protection Regulation (GDPR). This statement outlines our compliance approach and your rights under GDPR.
We process personal data based on one or more of the following legal grounds:
Under the GDPR, you have the following rights:
You have the right to be informed about the collection and use of your personal data. This information is provided in our Privacy Policy.
You have the right to request copies of your personal data. We may charge a reasonable fee if your request is clearly unfounded or excessive.
You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
You have the right to request that we erase your personal data under certain conditions, including when:
You have the right to request that we restrict the processing of your personal data under certain conditions.
You have the right to request that we transfer the data we have collected to another organization, or directly to you, in a structured, commonly used, and machine-readable format.
You have the right to object to our processing of your personal data under certain conditions, particularly for direct marketing purposes.
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
To exercise any of these rights, please contact us:
We will respond to your request within one month. If your request is particularly complex or you have made multiple requests, we may extend this period by two further months, in which case we will inform you.
For any questions regarding our GDPR compliance or data protection practices, you may contact our Data Protection Officer at [email protected]
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
When we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as:
We ensure that any third parties processing data on our behalf comply with GDPR requirements through:
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Tel: 0303 123 1113
Website: www.ico.org.uk
We may update this GDPR compliance statement from time to time to reflect changes in our practices or legal requirements. We will post any updates on this page.
For any questions about this GDPR statement or our data protection practices:
Email: [email protected]
Address: 42 Kingsway, London WC2B 6EX, United Kingdom