Home About Privacy Policy Personal Data Management

Personal Data Management

When INNERLUXES engineers work with personal data on your engagement — whether you are the controller and we are the processor, or the other way around — here is exactly how we handle it. Every classification level, access control, encryption standard, and breach notification timeline is documented and followed without exception.

Personal Data Management INNERLUXES

Our Role on Engagements

On most client engagements, INNERLUXES acts as a data processor while you remain the controller. Every engagement opens with a Data Processing Agreement (DPA) that spells out the scope of processing, approved sub-processors, security measures, and breach notification timelines.

Where an engagement calls for joint-controller status — shared CRM access, for example — we address that arrangement explicitly inside the same DPA, so nothing is left ambiguous.

Data Classification

Every piece of data we touch is placed into one of six classification levels, each carrying its own mandatory controls. Nothing falls through the cracks.

Public

Marketing materials, published documentation. No restrictions applied.

Internal

Routine operational data. Access limited to the assigned project team.

Confidential

Client business data, source code, system configs. Strict need-to-know basis.

Restricted

Personal data, financial records, health IDs, credentials. Highest controls — mandatory encryption and full audit logging.

Regulated

Data under GDPR, HIPAA, PCI-DSS, or equivalent. Framework-specific controls on top of Restricted-level defaults.

Ephemeral

Transient data deleted within a defined short window. Logged, never persisted beyond its stated purpose.

Need Our DPA or Security Questionnaire?

Email privacy@innerluxes.dev with your request. Completed DPAs returned within 2 business days, security questionnaires within 5.

Access Controls & Encryption

Getting access wrong is one of the most common ways data ends up in the wrong hands. Our controls are built to prevent that from the start, with no standing production access and no unencrypted data at rest or in transit.

Access Controls
  • RBAC with least-privilege enforcement across every system we operate
  • MFA required on all internal and client-connected systems
  • Just-in-time (JIT) access for production — time-limited, logged elevation only
  • SSO with hardware-key MFA for Restricted-class data systems
  • Quarterly access reviews with automated de-provisioning on role change
  • Session recording on all privileged production sessions
Encryption
  • AES-256 at rest on every storage system holding Restricted or Regulated data
  • TLS 1.2+ in transit with HSTS preload on every production endpoint
  • Customer-managed encryption keys (CMK) available for regulated workloads
  • Field-level encryption for health identifiers, payment card data, and government IDs
  • Scheduled key rotation with zero-downtime procedures
  • Encrypted backups with separate key management from primary storage

Sub-Processors & Cross-Border Transfers

Every third-party service involved in your engagement and every cross-border data movement is governed by the appropriate legal mechanism — never assumptions.

Sub-processor register

Every cloud, monitoring, and error-tracking service on your engagement is listed, security-assessed, and bound by a written DPA before use.

30-day advance notice

Whenever a new sub-processor is added to your engagement, you receive 30 days’ notice with an objection window before they go active.

EU Standard Contractual Clauses

Used for all transfers originating from the EU or EEA, with transfer impact assessments (TIAs) documented and available on request.

UK IDTA

UK International Data Transfer Agreement — or the UK addendum to EU SCCs — applied for all transfers from the UK.

Adequacy decisions

Relied upon where a valid adequacy decision is in force for the destination country, with ongoing monitoring for decision changes.

Data residency

EU-only, US-only, or other regional constraints configured at the infrastructure level where your requirements demand it.

Adnan Jillani — Principal Architect and Enterprise Solutions Expert at INNERLUXES

Adnan Jillani

Principal Architect and Enterprise Solutions Expert
at INNERLUXES

Data protection is not a checkbox at the end of a project — it is how we start every engagement. Classification, access, encryption, and breach response are all defined before a single line of code is written. That rigour is what lets clients trust us with their most sensitive data.

Incident Response & Breach Notification

A slow response to a security incident costs far more than the incident itself. Our response process is pre-defined, rehearsed, and time-bound.

1-hour activation

Internal incident response is activated within 1 hour of detection — no waiting for approvals.

24-hour client notice

Affected clients notified within 24 hours where personal data is involved — never left waiting.

72-hour regulator notice

Regulator notification within 72 hours where legally required — GDPR Art. 33 and equivalents.

Data subject notice

Affected individuals notified wherever required and wherever notice would help them reduce their own risk.

Full post-incident report

Root cause, scope, timeline, and corrective actions delivered to you in writing after every incident.

Annual tabletop drills

Incident simulations conducted annually to validate response readiness before a real event occurs.

Records Retention & Audit Evidence

Personal data is kept only for as long as the purpose requires, plus any mandatory legal retention period. When your procurement, legal, or compliance team asks for evidence, we have it ready — you should not have to chase us for documentation that should already exist.

  • At the close of an engagement your data is either returned in a documented, portable format or securely deleted — your choice, with deletion certificates covering primary data and all backup copies.
  • Retention schedules documented per data category and reviewed annually.
  • Records of processing activities (RoPA) for our role on your engagement, available on request.
  • Sub-processor register with corresponding DPAs provided per engagement.
  • Annual penetration test summary from an independent third-party assessor.
  • Standard security questionnaire responses in CAIQ and SIG-Lite formats.
  • SOC 2 readiness documentation available for enterprise engagements.
  • ISO 27001-aligned control mapping provided on request.

Data Subject Requests We Support

Where INNERLUXES processes personal data on your behalf, we support every data subject request your organisation receives — so you can meet your obligations to the people whose data you hold.

Access & Portability

  • Locate and return data within 5 business days of your instruction
  • Export in structured, machine-readable format for direct handover

Rectification & Erasure

  • Update records on written instruction with completion confirmation
  • Delete on instruction with deletion certificate covering primary and backup systems

Restriction & Objection

  • Processing holds applied on instruction while a dispute or review is in progress
  • Automated processing paused on instruction where a data subject objects

Personal Data Management – Q&A

What role does INNERLUXES play in processing client personal data?

On most client engagements, INNERLUXES acts as a data processor while the client remains the controller. Every engagement opens with a Data Processing Agreement (DPA) covering scope of processing, approved sub-processors, security measures, and breach notification timelines.

How does INNERLUXES classify personal data?

Every piece of data we touch is placed into one of six classification levels — Public, Internal, Confidential, Restricted, Regulated, and Ephemeral — each carrying its own mandatory access, encryption, and retention controls.

How quickly does INNERLUXES notify clients of a data breach?

Internal incident response is activated within 1 hour of detection. Affected clients are notified within 24 hours where personal data is involved. Regulator notification follows within 72 hours where legally required under GDPR Art. 33 and equivalents.

Can I get a DPA template or security questionnaire from INNERLUXES?

Yes. Email privacy@innerluxes.dev with your request. Completed DPAs are returned within 2 business days and security questionnaires within 5.

Let’s discuss your needs

The more detail you share, the more accurate the scope and cost we send back. Free estimate, no sales calls.

Drag and drop or to upload your file(s)

? Max 10MB per file, up to 5 files (20MB total). Supported: doc, docx, xls, xlsx, ppt, pptx, pdf, jpg, png, txt, csv, zip
Preferred way of communication: