BACKGROUND
We respect the privacy of our clients and of everyone who visits our website, www.weareluma.co (“Our Site”). Luma Consulting (we / us / our) will only collect and use personal data in ways that are described in this Privacy Notice, and that are consistent with our obligations and your rights under the Data Protection Legislation.
In this Privacy Notice, the following terms shall have the following meanings:
Client: means a client who engages our services or who purchases products from us; and
Data Protection Legislation: means all applicable data protection and privacy legislation in force from time to time in the UK including the UK GDPR; the Data Protection Act 2018 (DPA 2018) (and regulations made thereunder); the Privacy and Electronic Communications Regulations 2003 (SI 2003/2426) as amended and all other legislation and regulatory requirements in force from time to time which apply to a party relating to the use of personal data (including the privacy of electronic communications).
Luma Consulting, is a limited company incorporated in England & Wales with company number 1590086, whose registered office address is 6 Portland Business Centre, Manor House Lane, SL3 9EG. We are the controller and responsible for your personal data.
If you have any questions relating to your personal data or this Privacy Notice, you may contact us at lucy@weareluma.co.
Our Site may include links to third-party websites. Clicking on those links may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for the way in which they handle personal data. We encourage you to read the privacy policy or privacy notice of every website you visit.
Personal data is any information about you that enables you to be identified. Personal data covers your name and contact details, but also information such as electronic location data and other online identifiers. It does not include data where your identity has been removed (anonymous data).
It is important that your personal data is kept accurate and up-to-date. If any of the personal data we hold about you changes, please let us know.
Where we need to collect personal data by law, or under the terms of a contract we have with you, and you do not provide that data when requested, we may not be able to perform that contract. In this case, we may have to cancel a product or service contract you have with us. We will notify you if this is the case.
Under the Data Protection Legislation, you have the following rights. More information on how to exercise these rights follows later in this Privacy Notice.
We would always appreciate an opportunity to work with you to resolve any issues or complaints you may have before you approach the ICO.
For more information about our use of your personal data or exercising your rights set out above, please contact us at lucy@weareluma.co.
Depending upon whether you are simply browsing Our Site or are a Client, we may collect and hold some or all of the personal data set out below, using the methods also set out below.
Please also see our Cookie Policy on Our Site regarding our use of cookies and similar technologies.
We collect the following types of personal data:
Contact Information: This may include your name, email address, postal address, phone number, and other similar contact details that you provide when contacting us through Our Site, by email or telephone.
Account Information: If you create an account on Our Site, we may collect information associated with your account, such as your username, password, and profile details.
Payment Information: If you purchase goods or services from us, we may collect payment information, including credit card details, billing address, and transaction history. However, please note that we do not store full credit card numbers on our servers.
Communication Data: This includes any correspondence or communication between you and us.
Usage Information: We automatically collect information about your usage of Our Site, including pages visited, time spent on the site, clickstream data, and referring URL, using our analytics software. This data helps us analyse website performance and user preferences.
Technical Information: We may collect technical information about your device and browser, using our analytics software, including your IP address, browser type and version, device type, operating system, and platform.
Social Media Data: If you interact with our social media pages or use social media features integrated into Our Site, we may collect information from your social media profiles, such as your social media handles and activities.
Cookies and Tracking Technologies: We may use cookies and similar tracking technologies to collect information about your browsing behavior and preferences. For more details, please see our Cookie Policy.
Other Information: We may collect additional information not specifically mentioned here with your consent or as required by applicable laws and regulations.
Please note that the exact information collected may vary depending on your interactions with Our Site and the services we offer. We only collect information that is necessary for the purposes outlined in this Privacy Notice and as permitted by Data Protection Law.
Under the Data Protection Legislation, we must always have a lawful basis for using personal data.
We will use your personal data in the following circumstances:
Note that we will only rely on our legitimate interests to use your personal data if your interests and rights do not override those legitimate interests.
We do not carry out automated decision making or any type of automated profiling.
We will only use your personal data for the purposes for which it was originally collected unless we reasonably believe that another purpose is compatible with those original purposes and we need to use your personal data for that purpose.
If we need to use your personal data for an unrelated or incompatible purpose to that for which it was originally collected, we will inform you and explain the legal basis which allows us to do so.
In some circumstances, where permitted or required by law, we may process your personal data without your knowledge or consent. This will only be done within the bounds of the Data Protection Legislation and your legal rights.
We will only process and store our personal data for as long as is necessary taking into account the reasons for which it was first collected.
When deciding what the correct time is to keep the data for, we look at its amount, nature and sensitivity, potential risk of harm from unauthorised use or disclosure, the processing purposes, if these can be achieved by other means, and any legal and regulatory requirements.
We may keep your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation arising out of our relationship.
The law requires us to keep basic information about our clients (including identity, contact and payment information as well as information on the contracts we enter into with our clients) for tax purposes, for six years after they stop being clients.
In some circumstances, we may anonymise your personal data for research or statistical purposes. In this case, we may use this information indefinitely without further notice to you.
The security of your personal data is essential to us.
To protect your personal data, we have put in place appropriate technical and organisational measures, including the following:
We may use external third parties to provide systems, technology or support which involves them processing your personal data on our behalf. For example, we use:
Project Planning Platform
We use Monday.com for project planning and management. This tool helps us organise and track project tasks and timelines. You can review Monday.com’s Privacy Policy, which explains its data protection practices, on their website.
Email and Scheduling Service
Our email communication and meeting scheduling are handled through Gmail, part of Google Workspace. Gmail’s Privacy Policy, detailing how it processes and protects personal data, is available on Google’s website.
Some of these external third parties use physical or cloud storage which is based outside the United Kingdom. By providing any information, including personal data to us, you consent to such transfer, storage and processing. Third countries outside the EEA may not have data protection laws that are as strong as those in the UK. We use our best endeavours to select only external third parties that require the same levels of personal data protection that would apply under the Data Protection Legislation, and ensure these levels of protection are contained in the external third parties’ privacy policies.
In addition, we may:
If any of your personal data is shared with a third party, as described above, we will take steps to ensure that your personal data is handled safely, securely, and in accordance with your rights, our obligations, and the third party’s obligations under the law.
In addition to your rights under the Data Protection Legislation, set out in Section 5 above, when you submit personal data via Our Site, you may be given options to restrict our use of your personal data. We aim to give you control over our use of your data for direct marketing purposes (including the ability to opt out of receiving marketing emails from us), which you may do by unsubscribing using the links provided.
You may access certain areas of Our Site without providing any personal data. However, to use all features and functions available on Our Site you may be required to submit or allow for the collection of certain data.
You may restrict our use of Cookies. For more information, see Our Cookie Policy which is available on Our Site.
If you want to know what personal data we have about you, you can ask us for details of that personal data and for a copy of it. This is known as a Subject Access Request.
All subject access requests should be made in writing and sent to the following email address: lucy@weareluma.co. Please include “Subject Access Request” in the email subject field.
There is not normally any charge for a subject access request, unless your request is ‘manifestly unfounded or excessive’, in which case we may charge an administrative cost.
We will aim to respond to your subject access request within one month of receiving it. If your request is more complex, more time may be required, up to a maximum of three months. We will keep you informed of our progress.
To contact us about anything to do with your personal data and data protection, please email us at lucy@weareluma.co.
We may amend or update this Privacy Notice from time to time. A revised Privacy Notice will be uploaded on Our Site and you will be deemed to have accepted its terms on your first use of Our Site following the revisions. We recommend that you check this page regularly.
This Privacy Notice was last updated on 18th July 2025.