Home About GDPR Compliance

GDPR Compliance at INNERLUXES

We take data protection seriously. This page explains how INNERLUXES handles personal data, what your rights are as a data subject under EU and UK GDPR, and exactly how to exercise them — with a response guaranteed within 30 days.

GDPR Compliance

Our Role Under GDPR

INNERLUXES is committed to complying with the EU General Data Protection Regulation (GDPR) and the UK GDPR. Depending on context, we act as a controller or processor of personal data.

Controller

For personal data collected via our website — contact form enquiries, newsletter signups, and job applications — and for our own employee and vendor records.

Processor

For personal data handled on behalf of clients during engineering engagements — for example, when we build software that processes your end-customers’ data.

Data Processing Agreement (DPA)

For every client engagement involving personal data, we sign a Data Processing Agreement (DPA) setting out scope, sub-processors, security measures, and breach notification obligations.

Lawful Basis for Processing

We rely on the following lawful bases under GDPR Art. 6:

  • Contract performance — to deliver services we have agreed to provide.
  • Pre-contractual steps — to respond to enquiries, scope an engagement, or evaluate a job application.
  • Legitimate interest — to operate our website, secure our systems, and communicate with prospects who have engaged with us.
  • Legal obligation — to meet tax, accounting, employment, and regulatory requirements.
  • Consent — for non-essential cookies, optional newsletters, and any processing where consent is the appropriate basis.

Your Rights Under GDPR

If you are a data subject in the EU, EEA, or UK, you have the following rights. Each can be exercised by emailing privacy@innerluxes.dev.

Right of Access (Art. 15)

Request a copy of the personal data we hold about you.

Right to Rectification (Art. 16)

Ask us to correct inaccurate or incomplete data.

Right to Erasure (Art. 17)

Ask us to delete your data when we no longer have a lawful basis to retain it.

Right to Restriction (Art. 18)

Ask us to pause certain processing while a dispute is resolved.

Right to Portability (Art. 20)

Receive your data in a structured, machine-readable format and transmit it to another controller.

Right to Object (Art. 21)

Object to processing based on legitimate interest or for direct marketing.

Automated Decision Rights (Art. 22)

We do not subject you to solely automated decisions producing legal or similarly significant effects.

Right to Withdraw Consent

Where consent is the lawful basis, you can withdraw at any time without affecting prior lawful processing.

Right to Lodge a Complaint

With your supervisory authority — the ICO in the UK, or your national DPA in the EU.

How to Exercise a Right

To exercise any right, email privacy@innerluxes.dev with: (1) the right you wish to exercise, (2) your email address as used with us, and (3) any relevant context. We respond within 30 days — extendable once by up to 60 days for complex requests.

Need to Submit a Data Request?

Our Privacy Lead responds within 30 days. Send us the right you wish to exercise and a way to identify you in our records — we’ll handle the rest.

International Data Transfers

Where personal data leaves the EU/EEA or UK, we use appropriate transfer mechanisms and perform Transfer Impact Assessments where required. Supplementary measures — including encryption and pseudonymisation — are applied where appropriate.

Standard Contractual Clauses

Used for transfers to countries without an EU adequacy decision.

UK IDTA

UK International Data Transfer Agreement (or addendum to EU SCCs) for UK-origin transfers.

Adequacy Decisions

Used where the destination country has been recognised as providing equivalent protection.

Data Residency

Commitments available for engagements requiring data to remain within a specified region.

Data Security Measures

We implement appropriate technical and organisational measures across every engagement. Security is not bolted on after the fact — it is part of how we build software.

Encryption

AES-256 minimum at rest; TLS 1.2+ in transit. All personal data is encrypted by default.

Access Control

Role-based access with a least-privilege principle. MFA enforced on all internal systems.

Pen Testing

Annual penetration testing with documented remediation of all findings.

Sub-processors

Every sub-processor is bound by a written DPA. Clients are notified 30 days before any change.

Breach Notification Process

In the event of a personal data breach, we follow a documented incident response process with clear timelines for notification and remediation.

01. Detection → 1 hour

Internal incident response activated within 1 hour of detection.

02. Client Alert → 24 hours

Affected clients notified without undue delay — typically within 24 hours where personal data is involved.

03. Authority Notice → 72 hours

Supervisory authority notified within the legally required 72-hour window where applicable.

04. Subject Notification

Data subjects notified where required by Art. 34, without unnecessary delay.

05. Post-Incident Report

Full report covering root cause, impact assessment, and corrective actions delivered to affected clients.

Zain Masood — Compliance Officer & Healthcare IT Compliance Consultant at INNERLUXES

Zain Masood

Compliance Officer & Healthcare IT Compliance Consultant
at INNERLUXES

GDPR compliance is not a checkbox — it is engineering discipline. We apply encryption, access control, and data minimisation from the first line of code, not the last. Every engagement comes with a DPA and a clear sub-processor register. Our clients can trust that what we build is safe by design.

Privacy Lead & Records

While we are not legally required to appoint a Data Protection Officer under Art. 37, we have a designated Privacy Lead who oversees all data protection matters and serves as your single point of contact for privacy questions.

Privacy Lead

Contact privacy@innerluxes.dev for any GDPR-related question, subject access request, or concern. We respond within 30 days.

Records (RoPA)

We maintain Records of Processing Activities under Art. 30 for both our controller and processor activities. Available to supervisory authorities and clients on request.

Children’s Data

Our services are not directed at children. We do not knowingly process personal data of anyone under 16. Contact us immediately if you believe this has occurred.

GDPR at INNERLUXES – Q&A

What role does INNERLUXES play under GDPR?

INNERLUXES acts as a controller for data collected through its own website (contact forms, job applications) and as a processor for personal data handled on behalf of clients during engineering engagements. A Data Processing Agreement is signed for every client engagement involving personal data.

What rights do I have under GDPR with INNERLUXES?

You have the right of access, rectification, erasure, restriction, data portability, and the right to object. You may also withdraw consent at any time and lodge a complaint with your supervisory authority. INNERLUXES responds to all rights requests within 30 days.

How does INNERLUXES handle international data transfers?

We use Standard Contractual Clauses (SCCs), the UK IDTA, adequacy decisions, and data residency commitments to ensure personal data transferred outside the EU/EEA or UK is protected to an equivalent standard. Transfer Impact Assessments are performed where required.

How quickly does INNERLUXES notify of a data breach?

Internal incident response is activated within 1 hour of detection. Affected clients are notified within 24 hours. Supervisory authority notification is made within the legally required 72-hour window. A full post-incident report follows with root cause analysis and corrective actions.

Let’s discuss your needs

The more detail you share, the more accurate the scope and cost we send back. Free estimate, no sales calls.

Drag and drop or to upload your file(s)

? Max 10MB per file, up to 5 files (20MB total). Supported: doc, docx, xls, xlsx, ppt, pptx, pdf, jpg, png, txt, csv, zip
Preferred way of communication: