Our Role Under GDPR
INNERLUXES is committed to complying with the EU General Data Protection Regulation (GDPR) and the UK GDPR. Depending on context, we act as a controller or processor of personal data.
Controller
For personal data collected via our website — contact form enquiries, newsletter signups, and job applications — and for our own employee and vendor records.
Processor
For personal data handled on behalf of clients during engineering engagements — for example, when we build software that processes your end-customers’ data.
Data Processing Agreement (DPA)
For every client engagement involving personal data, we sign a Data Processing Agreement (DPA) setting out scope, sub-processors, security measures, and breach notification obligations.
Lawful Basis for Processing
We rely on the following lawful bases under GDPR Art. 6:
- Contract performance — to deliver services we have agreed to provide.
- Pre-contractual steps — to respond to enquiries, scope an engagement, or evaluate a job application.
- Legitimate interest — to operate our website, secure our systems, and communicate with prospects who have engaged with us.
- Legal obligation — to meet tax, accounting, employment, and regulatory requirements.
- Consent — for non-essential cookies, optional newsletters, and any processing where consent is the appropriate basis.
Your Rights Under GDPR
If you are a data subject in the EU, EEA, or UK, you have the following rights. Each can be exercised by emailing privacy@innerluxes.dev.
Right of Access (Art. 15)
Request a copy of the personal data we hold about you.
Right to Rectification (Art. 16)
Ask us to correct inaccurate or incomplete data.
Right to Erasure (Art. 17)
Ask us to delete your data when we no longer have a lawful basis to retain it.
Right to Restriction (Art. 18)
Ask us to pause certain processing while a dispute is resolved.
Right to Portability (Art. 20)
Receive your data in a structured, machine-readable format and transmit it to another controller.
Right to Object (Art. 21)
Object to processing based on legitimate interest or for direct marketing.
Automated Decision Rights (Art. 22)
We do not subject you to solely automated decisions producing legal or similarly significant effects.
Right to Withdraw Consent
Where consent is the lawful basis, you can withdraw at any time without affecting prior lawful processing.
Right to Lodge a Complaint
With your supervisory authority — the ICO in the UK, or your national DPA in the EU.
How to Exercise a Right
To exercise any right, email privacy@innerluxes.dev with: (1) the right you wish to exercise, (2) your email address as used with us, and (3) any relevant context. We respond within 30 days — extendable once by up to 60 days for complex requests.
International Data Transfers
Where personal data leaves the EU/EEA or UK, we use appropriate transfer mechanisms and perform Transfer Impact Assessments where required. Supplementary measures — including encryption and pseudonymisation — are applied where appropriate.
Standard Contractual Clauses
Used for transfers to countries without an EU adequacy decision.
UK IDTA
UK International Data Transfer Agreement (or addendum to EU SCCs) for UK-origin transfers.
Adequacy Decisions
Used where the destination country has been recognised as providing equivalent protection.
Data Residency
Commitments available for engagements requiring data to remain within a specified region.
Data Security Measures
We implement appropriate technical and organisational measures across every engagement. Security is not bolted on after the fact — it is part of how we build software.
Encryption
AES-256 minimum at rest; TLS 1.2+ in transit. All personal data is encrypted by default.
Access Control
Role-based access with a least-privilege principle. MFA enforced on all internal systems.
Pen Testing
Annual penetration testing with documented remediation of all findings.
Sub-processors
Every sub-processor is bound by a written DPA. Clients are notified 30 days before any change.
Breach Notification Process
In the event of a personal data breach, we follow a documented incident response process with clear timelines for notification and remediation.
01. Detection → 1 hour
Internal incident response activated within 1 hour of detection.
02. Client Alert → 24 hours
Affected clients notified without undue delay — typically within 24 hours where personal data is involved.
03. Authority Notice → 72 hours
Supervisory authority notified within the legally required 72-hour window where applicable.
04. Subject Notification
Data subjects notified where required by Art. 34, without unnecessary delay.
05. Post-Incident Report
Full report covering root cause, impact assessment, and corrective actions delivered to affected clients.
Zain Masood
Compliance Officer & Healthcare IT Compliance Consultant
at INNERLUXES
“GDPR compliance is not a checkbox — it is engineering discipline. We apply encryption, access control, and data minimisation from the first line of code, not the last. Every engagement comes with a DPA and a clear sub-processor register. Our clients can trust that what we build is safe by design.
Privacy Lead & Records
While we are not legally required to appoint a Data Protection Officer under Art. 37, we have a designated Privacy Lead who oversees all data protection matters and serves as your single point of contact for privacy questions.
Contact privacy@innerluxes.dev for any GDPR-related question, subject access request, or concern. We respond within 30 days.
We maintain Records of Processing Activities under Art. 30 for both our controller and processor activities. Available to supervisory authorities and clients on request.
Our services are not directed at children. We do not knowingly process personal data of anyone under 16. Contact us immediately if you believe this has occurred.
GDPR at INNERLUXES – Q&A
INNERLUXES acts as a controller for data collected through its own website (contact forms, job applications) and as a processor for personal data handled on behalf of clients during engineering engagements. A Data Processing Agreement is signed for every client engagement involving personal data.
You have the right of access, rectification, erasure, restriction, data portability, and the right to object. You may also withdraw consent at any time and lodge a complaint with your supervisory authority. INNERLUXES responds to all rights requests within 30 days.
We use Standard Contractual Clauses (SCCs), the UK IDTA, adequacy decisions, and data residency commitments to ensure personal data transferred outside the EU/EEA or UK is protected to an equivalent standard. Transfer Impact Assessments are performed where required.
Internal incident response is activated within 1 hour of detection. Affected clients are notified within 24 hours. Supervisory authority notification is made within the legally required 72-hour window. A full post-incident report follows with root cause analysis and corrective actions.