PRIVACY POLICY & TERMS OF USE

Effective Date: September 1, 2026 | Version: 1.0

1. Who We Are

LuxAura RegTech Advisory ("LRT", "we", "us") is a technology advisory firm providing compliance-by-design consulting and advisory on middleware solutions.

2. Data We Collect

We only collect and process data you voluntarily provide or that is necessary for service delivery:

  • Contact Information (name, email, organization, phone): To respond to inquiries and deliver requested materials (e.g., whitepapers).

  • Engagement Data: During advisory projects, we may temporarily process client-provided data (e.g., compliance frameworks, audit logs) solely for service delivery.

  • Technical Data (IP address, session cookies): For security monitoring, fraud prevention, and essential website functionality only.

We do NOT collect:

  • Financial data (e.g., transaction records, account numbers).

  • Payment information (we do not process payments).

  • Sensitive personal data (e.g., biometric, racial, or ethnic information).

3. How We Use Your Data

  • Reply to your inquiries (e.g., Enquiry@luxauraregtech.com).

  • Deliver only what you request (e.g., whitepapers, reports, advisory services).

  • Improve our services (anonymized, aggregated insights only).

4. GDPR Compliance & International Transfers

For EU/EEA Clients & Data Subjects:

  • Legal Basis: GDPR Article 6(1)(b) (contract performance) and 6(1)(f) (legitimate interests for security).

  • International Transfers: For data transferred outside the EU/EEA (e.g., to Hong Kong), we rely on:

    • Standard Contractual Clauses (2021/914) (European Commission-approved).

    • Supplementary measures (encryption, access controls).

  • EU Representation: We are establishing an EU-based representative to comply with GDPR Article 27. For GDPR inquiries, contact: privacy@luxauraregtech.com.

  • Your Rights: As an EU/EEA resident, you have the right to:

    • Access, correct, or delete your personal data.

    • Restrict or object to processing.

    • Data portability (where applicable).

    • Lodge a complaint with a supervisory authority.

    • We respond to all requests within 30 days (free of charge, unless excessive).

For Non-EU Clients:

  • Data is processed in accordance with applicable local laws (e.g., Hong Kong PDPO).

5. Data Retention

  • Contact Form Submissions & Email Correspondence: Retained for up to 2 years, or until a deletion request is submitted.

  • Engagement Data: Returned or securely deleted within 14 days of engagement completion.

  • Session Cookies: Retained only for the duration of your session.

6. Security

  • Encryption: TLS 1.3 (data in transit), AES-256 (data at rest).

  • Access Controls: Restricted to authorized personnel only (role-based access).

  • Backups: Automated daily encrypted backups with secure offsite storage.

  • Breach Notification: We will notify affected clients of any data breach within 72 hours of discovery (GDPR-compliant).

7. Cookies

  • We use only essential cookies (for forms and security).

  • No tracking, analytics, or advertising cookies.

8. Contact

Institutional-Grade RegTech