Privacy Policy

Privacy information for Lumio-Tek customers and visitors.

Last structured update: 10 April 2026. This page explains how Lumio-Tek handles personal data across the public website, commercial conversations, platform access, and client-delivered services. Any remaining unknown legal details are left as clear placeholders rather than guessed.

Scope

Depending on the interaction, Lumio-Tek may process contact details, organisation details, account identifiers, operational audit records, technical usage information, and service data needed to provide access, maintain tenancy boundaries, and support governed workflow execution.

Lawful Bases for Processing

Website analytics and service improvement

We use limited website usage data to understand traffic, improve site performance, maintain security, and develop our services.

Lawful basis: Legitimate interests, where analytics are strictly necessary, proportionate, and balanced against individual rights. Where non-essential cookies or tracking technologies are used, we rely on consent where required.

Contact forms, enquiries, and demo requests

When you contact us, request information, or ask for a demo, we process the information you submit to respond to your enquiry and manage pre-contract discussions.

Lawful basis: Taking steps at your request prior to entering into a contract, and our legitimate interests in responding to business enquiries.

Account creation, onboarding, and customer administration

If you become a customer, we process account, identity, organisation, and service-use data to provide the platform, administer access, and manage the customer relationship.

Lawful basis: Performance of a contract, and legitimate interests in operating, securing, and improving our services.

Product operations, platform security, and audit logging

We process technical, account, and activity data to authenticate users, enforce permissions, monitor misuse, investigate incidents, maintain audit trails, and protect service integrity.

Lawful basis: Legitimate interests in securing our systems, customers, users, and services; and, where applicable, compliance with legal obligations.

Transactional service communications

We send service-related emails or messages such as account notices, security alerts, approval requests, and operational updates.

Lawful basis: Performance of a contract, and legitimate interests in operating a secure and reliable service.

Marketing communications

Where you opt in to receive product updates, newsletters, or promotional communications, we process your contact details to send them.

Lawful basis: Consent, where required by law, or legitimate interests where permitted for existing business contacts under applicable rules.

Client-delivered platform services

Where Lumio-Tek processes personal data within customer environments, workflows, or managed service features, we may act as a processor on the client’s behalf, with the client acting as controller for that data.

Lawful basis: Determined by the relevant client as controller; our processing is carried out under their documented instructions.

Subprocessors and Service Providers

We use carefully selected third-party providers to support website hosting, infrastructure, database services, analytics, communications, payment processing, error monitoring, and other operational functions. These providers process personal data only as necessary to deliver services to us and subject to appropriate contractual and security safeguards.

Categories of providers may include:

  • hosting and cloud infrastructure providers
  • database and authentication providers
  • email and communications providers
  • analytics and diagnostics providers
  • payment and billing providers
  • customer support and document storage providers

A current list of significant subprocessors can be requested by contacting us at sales@lumiotek.com and will be provided on request.

International Transfers

Some of our service providers may process or make personal data accessible outside the United Kingdom. Where we make a restricted transfer, we take steps required by UK data protection law to ensure that personal data remains protected. This may include transferring data to countries recognised as adequate under UK law, or using approved transfer mechanisms and supplementary safeguards where needed.

Retention Schedule

We keep personal data only for as long as necessary for the purposes for which it was collected, including legal, regulatory, tax, security, dispute-resolution, and audit requirements.

  • Website enquiry data: up to 12 months after the last substantive contact.
  • Sales and demo communications: up to 24 months unless a longer relationship develops.
  • Customer account and contract records: for the duration of the relationship and up to 6 years afterwards where needed for legal, tax, or contractual reasons.
  • Security logs and audit records: typically 6 to 24 months depending on risk, incident history, and operational need.
  • Marketing preferences and suppression records: retained as needed to honour opt-out requests and demonstrate compliance.
  • Support tickets and operational communications: typically up to 24 months after closure unless longer retention is required for security, legal, or contractual reasons.

We may retain information for longer where necessary to establish, exercise, or defend legal claims, comply with legal obligations, or investigate security matters.

Your Privacy Rights

Depending on the circumstances, you may have the right to:

  • request access to your personal data
  • request correction of inaccurate data
  • request deletion
  • object to certain processing
  • request restriction of processing
  • request portability of data where applicable

How to exercise your rights

To make a privacy request, please contact us at:

Email: sales@lumiotek.com
Postal address: Lumio-Tek Limited, 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE

Please include enough information for us to identify you and understand your request. We may ask for reasonable proof of identity before responding. We aim to respond within the time required by applicable data protection law.

Complaints and escalation

If you have concerns about how we handle your personal data, we encourage you to contact us first so we can try to resolve the issue. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) in the United Kingdom if you believe your data protection rights have been breached.

Items still requiring legal completion

  • • Publish a dedicated privacy mailbox later if you want privacy enquiries separated from commercial contact.
  • • Add a public subprocessor register page later if you want this available without request.
  • • Confirm whether you want the company registration number surfaced directly in this policy as well as the footer.

Current public business contact for commercial follow-up: sales@lumiotek.com

Registered office used for public legal notices: 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE. Company number: 16929905.

Privacy Policy | Lumio-Tek | Lumio-Tek