Privacy Policy
Last updated: November 2024
1. Introduction
LuxaMax Lighting Automation ("we", "our", or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you visit our website or use our services.
We are registered in England and Wales under company number 12345678, with our registered office at 142 Kensington High Street, London, W8 7RG, United Kingdom.
2. Information We Collect
2.1 Information You Provide
We collect information you voluntarily provide to us, including:
- Contact information (name, email address, phone number, postal address)
- Business information (company name, role, industry)
- Project details and requirements when requesting quotes
- Communication preferences and newsletter subscriptions
- Feedback, reviews, and correspondence
2.2 Information Automatically Collected
When you visit our website, we automatically collect certain information:
- IP address and geographic location
- Browser type and version
- Operating system and device information
- Pages visited, time spent, and navigation patterns
- Referring website and search terms used
- Date and time of visits
2.3 Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your experience. For detailed information about our cookie usage, please see our Cookie Policy.
3. How We Use Your Information
We use your personal information for the following purposes:
- Service Provision: To provide lighting automation services, consultations, and customer support
- Communication: To respond to enquiries, send newsletters, and provide updates about our services
- Business Operations: To process quotes, manage projects, and maintain customer relationships
- Marketing: To send relevant offers and information about new services (with your consent)
- Website Improvement: To analyse usage patterns and improve our website functionality
- Legal Compliance: To comply with legal obligations and protect our business interests
4. Legal Basis for Processing
Under UK GDPR, we process your personal data based on the following legal grounds:
- Consent: For marketing communications and non-essential cookies
- Contract: To fulfil service agreements and provide requested consultations
- Legitimate Interest: To improve our services, website functionality, and business operations
- Legal Obligation: To comply with applicable laws and regulations
5. Data Sharing and Disclosure
We do not sell your personal data. We may share your information with:
- Service Providers: Trusted third parties who assist in website hosting, email services, and business operations
- Professional Advisors: Lawyers, accountants, and other professional service providers
- Business Partners: Suppliers and subcontractors involved in delivering our services (with your consent)
- Legal Authorities: When required by law or to protect our legal rights
All third parties are contractually bound to protect your data and use it only for specified purposes.
6. Data Retention
We retain your personal data only as long as necessary for the purposes outlined in this policy:
- Customer Data: For the duration of our business relationship plus 7 years for tax and legal compliance
- Marketing Data: Until you unsubscribe or withdraw consent
- Website Analytics: Typically 26 months for Google Analytics data
- Correspondence: Generally 3 years unless ongoing business relationship exists
7. Your Rights
Under UK data protection law, you have the following rights:
- Right of Access: Request copies of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data
- Right to Restrict Processing: Limit how we use your data
- Right to Data Portability: Receive your data in a structured format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent for marketing or cookies
To exercise these rights, contact us at [email protected].
8. Data Security
We implement appropriate technical and organisational measures to protect your personal data:
- SSL encryption for data transmission
- Secure server infrastructure with regular security updates
- Access controls and authentication procedures
- Regular security assessments and monitoring
- Staff training on data protection principles
- Incident response procedures for potential breaches
9. International Transfers
Your personal data may be transferred to and processed in countries outside the UK/EEA for service provision. We ensure adequate protection through:
- Adequacy decisions by the UK Information Commissioner's Office
- Standard contractual clauses approved by the ICO
- Certification schemes and codes of conduct
10. Children's Privacy
Our services are not intended for children under 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.
11. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or applicable law. We will notify you of significant changes by:
- Posting the updated policy on our website
- Sending email notifications for material changes
- Updating the "last updated" date at the top of this policy
12. Contact Information
For questions about this Privacy Policy or our data practices, contact us:
13. Complaints
If you have concerns about how we handle your personal data, you can lodge a complaint with the UK Information Commissioner's Office (ICO):