Our Role on Engagements
On most client engagements, INNERLUXES acts as a data processor while you remain the controller. Every engagement opens with a Data Processing Agreement (DPA) that spells out the scope of processing, approved sub-processors, security measures, and breach notification timelines.
Where an engagement calls for joint-controller status — shared CRM access, for example — we address that arrangement explicitly inside the same DPA, so nothing is left ambiguous.
Data Classification
Every piece of data we touch is placed into one of six classification levels, each carrying its own mandatory controls. Nothing falls through the cracks.
Public
Marketing materials, published documentation. No restrictions applied.
Internal
Routine operational data. Access limited to the assigned project team.
Confidential
Client business data, source code, system configs. Strict need-to-know basis.
Restricted
Personal data, financial records, health IDs, credentials. Highest controls — mandatory encryption and full audit logging.
Regulated
Data under GDPR, HIPAA, PCI-DSS, or equivalent. Framework-specific controls on top of Restricted-level defaults.
Ephemeral
Transient data deleted within a defined short window. Logged, never persisted beyond its stated purpose.
Access Controls & Encryption
Getting access wrong is one of the most common ways data ends up in the wrong hands. Our controls are built to prevent that from the start, with no standing production access and no unencrypted data at rest or in transit.
- RBAC with least-privilege enforcement across every system we operate
- MFA required on all internal and client-connected systems
- Just-in-time (JIT) access for production — time-limited, logged elevation only
- SSO with hardware-key MFA for Restricted-class data systems
- Quarterly access reviews with automated de-provisioning on role change
- Session recording on all privileged production sessions
- AES-256 at rest on every storage system holding Restricted or Regulated data
- TLS 1.2+ in transit with HSTS preload on every production endpoint
- Customer-managed encryption keys (CMK) available for regulated workloads
- Field-level encryption for health identifiers, payment card data, and government IDs
- Scheduled key rotation with zero-downtime procedures
- Encrypted backups with separate key management from primary storage
Sub-Processors & Cross-Border Transfers
Every third-party service involved in your engagement and every cross-border data movement is governed by the appropriate legal mechanism — never assumptions.
Sub-processor register
Every cloud, monitoring, and error-tracking service on your engagement is listed, security-assessed, and bound by a written DPA before use.
30-day advance notice
Whenever a new sub-processor is added to your engagement, you receive 30 days’ notice with an objection window before they go active.
EU Standard Contractual Clauses
Used for all transfers originating from the EU or EEA, with transfer impact assessments (TIAs) documented and available on request.
UK IDTA
UK International Data Transfer Agreement — or the UK addendum to EU SCCs — applied for all transfers from the UK.
Adequacy decisions
Relied upon where a valid adequacy decision is in force for the destination country, with ongoing monitoring for decision changes.
Data residency
EU-only, US-only, or other regional constraints configured at the infrastructure level where your requirements demand it.
Adnan Jillani
Principal Architect and Enterprise Solutions Expert
at INNERLUXES
“Data protection is not a checkbox at the end of a project — it is how we start every engagement. Classification, access, encryption, and breach response are all defined before a single line of code is written. That rigour is what lets clients trust us with their most sensitive data.
Incident Response & Breach Notification
A slow response to a security incident costs far more than the incident itself. Our response process is pre-defined, rehearsed, and time-bound.
1-hour activation
Internal incident response is activated within 1 hour of detection — no waiting for approvals.
24-hour client notice
Affected clients notified within 24 hours where personal data is involved — never left waiting.
72-hour regulator notice
Regulator notification within 72 hours where legally required — GDPR Art. 33 and equivalents.
Data subject notice
Affected individuals notified wherever required and wherever notice would help them reduce their own risk.
Full post-incident report
Root cause, scope, timeline, and corrective actions delivered to you in writing after every incident.
Annual tabletop drills
Incident simulations conducted annually to validate response readiness before a real event occurs.
Records Retention & Audit Evidence
Personal data is kept only for as long as the purpose requires, plus any mandatory legal retention period. When your procurement, legal, or compliance team asks for evidence, we have it ready — you should not have to chase us for documentation that should already exist.
- At the close of an engagement your data is either returned in a documented, portable format or securely deleted — your choice, with deletion certificates covering primary data and all backup copies.
- Retention schedules documented per data category and reviewed annually.
- Records of processing activities (RoPA) for our role on your engagement, available on request.
- Sub-processor register with corresponding DPAs provided per engagement.
- Annual penetration test summary from an independent third-party assessor.
- Standard security questionnaire responses in CAIQ and SIG-Lite formats.
- SOC 2 readiness documentation available for enterprise engagements.
- ISO 27001-aligned control mapping provided on request.
Data Subject Requests We Support
Where INNERLUXES processes personal data on your behalf, we support every data subject request your organisation receives — so you can meet your obligations to the people whose data you hold.
Access & Portability
- Locate and return data within 5 business days of your instruction
- Export in structured, machine-readable format for direct handover
Rectification & Erasure
- Update records on written instruction with completion confirmation
- Delete on instruction with deletion certificate covering primary and backup systems
Restriction & Objection
- Processing holds applied on instruction while a dispute or review is in progress
- Automated processing paused on instruction where a data subject objects
Personal Data Management – Q&A
On most client engagements, INNERLUXES acts as a data processor while the client remains the controller. Every engagement opens with a Data Processing Agreement (DPA) covering scope of processing, approved sub-processors, security measures, and breach notification timelines.
Every piece of data we touch is placed into one of six classification levels — Public, Internal, Confidential, Restricted, Regulated, and Ephemeral — each carrying its own mandatory access, encryption, and retention controls.
Internal incident response is activated within 1 hour of detection. Affected clients are notified within 24 hours where personal data is involved. Regulator notification follows within 72 hours where legally required under GDPR Art. 33 and equivalents.
Yes. Email privacy@innerluxes.dev with your request. Completed DPAs are returned within 2 business days and security questionnaires within 5.