PRIVACY POLICY & TERMS OF USE
Effective Date: September 1, 2026 | Version: 1.0
1. Who We Are
LuxAura RegTech Advisory ("LRT", "we", "us") is a technology advisory firm providing compliance-by-design consulting and advisory on middleware solutions.
2. Data We Collect
We only collect and process data you voluntarily provide or that is necessary for service delivery:
Contact Information (name, email, organization, phone): To respond to inquiries and deliver requested materials (e.g., whitepapers).
Engagement Data: During advisory projects, we may temporarily process client-provided data (e.g., compliance frameworks, audit logs) solely for service delivery.
Technical Data (IP address, session cookies): For security monitoring, fraud prevention, and essential website functionality only.
We do NOT collect:
Financial data (e.g., transaction records, account numbers).
Payment information (we do not process payments).
Sensitive personal data (e.g., biometric, racial, or ethnic information).
3. How We Use Your Data
Reply to your inquiries (e.g., Enquiry@luxauraregtech.com).
Deliver only what you request (e.g., whitepapers, reports, advisory services).
Improve our services (anonymized, aggregated insights only).
4. GDPR Compliance & International Transfers
For EU/EEA Clients & Data Subjects:
Legal Basis: GDPR Article 6(1)(b) (contract performance) and 6(1)(f) (legitimate interests for security).
International Transfers: For data transferred outside the EU/EEA (e.g., to Hong Kong), we rely on:
Standard Contractual Clauses (2021/914) (European Commission-approved).
Supplementary measures (encryption, access controls).
EU Representation: We are establishing an EU-based representative to comply with GDPR Article 27. For GDPR inquiries, contact: privacy@luxauraregtech.com.
Your Rights: As an EU/EEA resident, you have the right to:
Access, correct, or delete your personal data.
Restrict or object to processing.
Data portability (where applicable).
Lodge a complaint with a supervisory authority.
We respond to all requests within 30 days (free of charge, unless excessive).
For Non-EU Clients:
Data is processed in accordance with applicable local laws (e.g., Hong Kong PDPO).
5. Data Retention
Contact Form Submissions & Email Correspondence: Retained for up to 2 years, or until a deletion request is submitted.
Engagement Data: Returned or securely deleted within 14 days of engagement completion.
Session Cookies: Retained only for the duration of your session.
6. Security
Encryption: TLS 1.3 (data in transit), AES-256 (data at rest).
Access Controls: Restricted to authorized personnel only (role-based access).
Backups: Automated daily encrypted backups with secure offsite storage.
Breach Notification: We will notify affected clients of any data breach within 72 hours of discovery (GDPR-compliant).
7. Cookies
We use only essential cookies (for forms and security).
No tracking, analytics, or advertising cookies.
8. Contact
Privacy Inquiries: privacy@luxauraregtech.com