PRIVACY POLICYEffective Date: September 09, 2026
This Website Privacy Policy explains how LUMINARA TECH LIMITED, a company registered in Hong Kong (“LUMINARA”, “Company”, “we”, “us” or “our”), processes personal data collected through our website
luminaratech.org.
We provide services on web application development, mobile app development, custom software development, API integration and process automation, Q&A and software testing, DevOps and cloud infrastructure.
The Company is a ‘data user’ for the purposes of the Hong Kong PDPO and, where the GDPR applies, a ‘controller’ for the purposes of the GDPR. This Privacy Policy applies only to personal data processed by us as a controller in connection with this website. Where we process personal data on behalf of our clients as a processor in the course of providing services, that processing is governed by the relevant client agreement and data processing agreement.
1. Controller and contact detailsThe controller of your personal data is:
LUMINARA TECH LIMITED (Hong Kong)
Reg. Number: 80925927
Address: Unit 2904-05, 29/F, Universal Trade Centre, 3 Arbuthnot Road, Central, Hong Kong
Email:
collaboration@luminaratech.org 2. Applicable legal framework and geographic scopeHONG KONG – PDPOThe Company is established in Hong Kong. The Personal Data (Privacy) Ordinance (Cap. 486) of the Laws of Hong Kong (“PDPO”), including the six Data Protection Principles (“DPPs”) in Schedule 1, applies where the Company controls the collection, holding, processing or use of personal data in or from Hong Kong.European Union and European Economic Area - GDPR
The EU General Data Protection Regulation, Regulation (EU) 2016/679 ("GDPR"), applies where the relevant processing falls within its territorial scope. This may include processing carried out in the context of an establishment in the EU/EEA, or processing by a non-EU controller that is related to intentionally offering goods or services to individuals in the EU/EEA or monitoring their behavior there. Mere accessibility of the Website in the EU/EEA does not, by itself, determine that the GDPR applies.
We do not use Website analytics, behavioral advertising, profiling or other tools intended to monitor visitors' behavior. Where the GDPR does not legally apply to a particular Website interaction, we nevertheless aim to apply substantially equivalent transparency, security and rights-handling standards to individuals in the EU/EEA.
The operational parts of this Policy apply generally. Where a legal basis or right must be identified under a specific law, the relevant GDPR and PDPO provisions are stated separately.
3. Personal Data We Collect2.1 Data You Provide Directly
When you interact with our website or contact us, we may collect the following categories of personal data:
• Contact information: full name, company name, email address
• Communication data: we may also collect the content of any message, enquiry or request that you submit to us through the form, if the form contains a message field or similar free-text field.
Providing the information requested in the contact form is voluntary; however, if you do not provide the information necessary to identify and respond to your enquiry, we may be unable to respond.
2.2 Data Collected Automatically
When you visit our website, we may automatically collect:
• Technical data: IP address, browser type and version, operating system, device information
2.3 Sensitive Personal Data
We do not intentionally collect sensitive personal data (e.g. Identity Card numbers, passport numbers, health information, racial or ethnic origin, religious beliefs) through our website.
4. Purposes of Collection and how this is permitted under the PDPO and GDPRWe process personal data collected through the website for the following purposes:
Purpose | Personal data | How this is permitted under the PDPO | GDPR legal basis |
Responding to enquiries | Inquiry form data: full name, company name, contact email and message content | Personal data is collected lawfully and fairly for purposes directly related to our functions and activities and only to the extent adequate and not excessive for those purposes, in accordance with DPP1. Personal data submitted in connection with an enquiry is used for responding to and managing that enquiry and directly related purposes in accordance with DPP3. | Art. 6(1)(f): legitimate interests in responding to professional and business inquiries. |
Legal and regulatory compliance | Relevant inquiry, technical and communication records. | We may collect personal data for legal and regulatory compliance where such collection is for a lawful purpose directly related to our functions or activities and is necessary, adequate but not excessive for that purpose, in accordance with DPP1. | Art. 6(1)(c): processing when it is necessary to comply with a legal obligation. |
Operating, troubleshooting and securing the Website; preventing spam, fraud, misuse and cyber incidents. | Strictly necessary cookie data and basic technical data required for website operation | We may collect and use limited technical and security-related personal data where this is necessary for the lawful purposes of operating, maintaining, troubleshooting and securing the Website and our systems, and preventing spam, fraud, misuse and cyber incidents. | Art. 6(1)(f): legitimate interests in a secure, reliable Website. |
|
|
|
|
5. Disclosure of Personal Data5.1 Third-Party Service Providers
We may disclose personal data to third-party service providers, including data processors, that process personal data on our behalf and for our purposes, such as IT and hosting providers, business systems providers, professional advisers and other operational support providers.
Where we engage a data processor to process personal data on our behalf, we adopt contractual or other appropriate means to ensure that the processor does not retain the personal data longer than necessary and protects it against unauthorized or accidental access, processing, erasure, loss or use, in accordance with DPP2(3) and DPP4(2) of the PDPO.
5.2 Regulatory and Legal Authorities
We may disclose personal data to government agencies, regulators, law enforcement bodies, or courts where required by law, including under the PDPO and/or GDPR and other applicable Hong Kong laws or applicable anti-money laundering legislation. Such disclosures are made only to the extent required and permitted by law.
5.3 Business Transfers
In the event of a merger, acquisition, or sale of all or part of our business assets, personal data held by us may be transferred to the successor entity, subject to equivalent data protection obligations.
5.4 No Sale of Personal Data
We do not sell, rent, or trade your personal data to third parties for their own marketing purposes.
6. International and Cross-border Transfers of Personal Data The Company is established in Hong Kong. Personal data submitted through the Website may therefore be received, stored or otherwise processed in Hong Kong. Hong Kong is outside the EEA and, as of the last update of this Policy, is not a country covered by an adequacy decision of the European Commission. Where the GDPR's international-transfer rules apply to a transfer of personal data to Singapore or another country outside the EEA, we rely on an available lawful transfer mechanism, such as an applicable adequacy decision, the European Commission's Standard Contractual Clauses, together with supplementary measures where required, or another mechanism permitted under Chapter V GDPR. Derogations under Article 49 GDPR are used only where the applicable legal conditions are met.
Under the PDPO, section 33 relating specifically to cross-border transfers has not been brought into operation. Nevertheless, other requirements of the PDPO continue to apply to personal data transferred outside Hong Kong, including DPP3 in relation to the permitted purposes of use and, where a data processor is engaged, DPP2(3) and DPP4(2) in relation to retention and security. We may use contractual safeguards and other appropriate measures for cross-border transfers, having regard to guidance issued by the PCPD, including its Recommended Model Contractual Clauses for Cross-border Transfer of Personal Data.
7. Retention of Personal DataWe retain personal data only for as long as necessary for the relevant purpose, taking into account applicable legal obligations, statutory limitation periods, security needs and the principle of data minimization.
Inquiry-form submissions and related correspondence are retained for up to six months after the inquiry is closed or after the last substantive communication. If an inquiry leads to pre-contractual negotiations or a contractual relationship, the relevant records may be transferred to separate business or client files and retained in accordance with the applicable contract, a separate privacy notice, applicable legal retention requirements and statutory limitation periods.
Routine server, security and error logs are normally retained for up to 90 days. Such logs may be retained for a longer period where necessary to investigate a security incident, prevent or address abuse, comply with applicable law, or establish, exercise or defend legal claims.
Data contained in strictly necessary technical cookies are retained only for the duration of the relevant session or for the limited technical period required for the relevant Website function. Such data may be retained for a longer period only where this is necessary for security, troubleshooting or the establishment, exercise or defense of legal claims.
8. Your Rights Under the PDPO and/or GDPRHong Kong – rights and complaints under the PDPO
Where the Personal Data (Privacy) Ordinance (Cap. 486) of the Laws of Hong Kong (“PDPO”) applies, you have rights in relation to your personal data in accordance with Data Protection Principle 6 (“DPP6”) and the relevant provisions of the PDPO.
Subject to the conditions, procedures and exemptions under the PDPO, you may:
- request confirmation as to whether we hold personal data relating to you and request access to such personal data by making a data access request in accordance with section 18 of the PDPO;
- request a copy of personal data relating to you that we hold, subject to the applicable requirements and exemptions under the PDPO;
- where personal data supplied to you in response to a data access request is inaccurate, request correction of that personal data in accordance with sections 22 to 25 of the PDPO; and
- where applicable, require us to cease using your personal data for direct marketing in accordance with Part 6A of the PDPO. Any such opt-out request will be complied with without charge.
To exercise your rights under the PDPO, please submit your request to us at:
Email:
collaboration@luminaratech.org We may require reasonable information to verify your identity and to identify the personal data to which your request relates before processing the request.
If you consider that our processing of your personal data may contravene the PDPO, you may lodge a complaint with the Office of the Privacy Commissioner for Personal Data, Hong Kong (“PCPD”), subject to the applicable complaint procedures of the PCPD.
European Union and European Economic Area – rights and complaints under the GDPR
To exercise any of the above rights, please submit a written request to our DPO at
Email:
collaboration@luminaratech.org We may require reasonable information to verify your identity before processing your request.
Where the GDPR applies, you may lodge a complaint with a supervisory authority in the EU/EEA Member State of your habitual residence, place of work or the place of the alleged infringement. A list of EU/EEA supervisory authorities is available from the European Data Protection Board.
9. Cookies and technical informationOur website uses only strictly necessary technical cookies and similar technologies that are required for the website to function properly, maintain security, remember essential settings, and support basic website operations.
We do not use analytics cookies, advertising cookies, marketing cookies, tracking pixels or behavioral profiling technologies on this website.
Strictly necessary cookies may collect limited technical information, such as:
- session identifiers;
- cookie preference or security-related information;
- technical logs necessary for website operation and security;
- browser and device information required to display the website correctly.
These cookies cannot be switched off through our website because they are necessary for the website to operate. You may be able to block or delete cookies through your browser settings, but doing so may affect the functionality or security of the website.
10. Security of Personal DataLUMINARA implements appropriate technical and organizational security measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Our security measures include:
• Access controls and role-based permissions limiting access to personal data to authorized personnel only;
• Regular security assessments and vulnerability scanning of our website and systems;
• Staff training on data protection and security awareness;
• Contractual security obligations imposed on all third-party data processors;
• Incident response procedures, including our Data Breach Response Plan.
In the event of a personal data breach, we will comply with applicable notification requirements under the PDPO and, where applicable, the GDPR. Where required by applicable law, this may include notifying the PCPD, the competent EU/EEA data protection supervisory authority or authorities, and affected individuals within the applicable statutory timeframes and subject to the relevant legal thresholds and exceptions.
11. Children’s PrivacyOur Website is not intended for individuals under the age of 16, and we do not knowingly collect, use, or disclose personal data from minors.
We request that individuals under the age of 16 do not submit any personal data through the Website or contact forms. If we become aware that personal data has been provided by a minor without verifiable parental or guardian consent, we will take reasonable steps to erase such personal data as soon as practicable where it is no longer required for the purpose for which it was collected, in accordance with PDPO, and will protect such data while it is retained.
If you believe that a minor has provided personal data to us, please contact so that appropriate action may be taken.
12. Changes to This PolicyWe reserve the right to update or amend this Privacy Policy at any time. Material changes will be notified to you via our website or, where we hold your email address, by email. The "Effective Date" at the top of this Policy indicates when the current version was last updated. We encourage you to review this Policy periodically.
14. Contact Us & ComplaintsFor any questions, concerns, or requests relating to this Privacy Policy or our data protection practices, please contact our Data Protection Officer:
Name / Title | Data Protection Officer |
Organization | LUMINARA TECH LIMITED |
Email | collaboration@luminaratech.org |
Postal Address | Unit 2904-05, 29/F, Universal Trade Centre, 3 Arbuthnot Road, Central, Hong Kong |