LumaPack
Privacy Policy
How we collect, use, and protect personal data when you engage with Lumapack.
Introduction
Lumapack ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect personal data when you visit our website or do business with us. For data protection purposes, Lumapack is the data controller.
Information We Collect
We may collect and process the following personal data:
- Name, job title, and business name
- Email address and phone number
- Billing and delivery addresses
- Payment and transaction information
- Artwork files or branding materials you submit
- Website usage data (IP address, browser type, pages visited)
- Communications with us (emails, enquiries, support messages)
How We Collect Your Data
We collect data when you:
- Place an order or request a quote
- Submit an enquiry via our website
- Upload artwork for custom-branded packaging
- Subscribe to marketing communications
- Browse our website (via cookies and analytics tools)
How We Use Your Data
We use your personal data to:
- Process orders and manage customer accounts
- Produce and deliver custom-branded packaging
- Communicate about orders, quotes, or enquiries
- Improve our website and services
- Send marketing communications (where permitted)
- Comply with legal and regulatory obligations
Legal Basis for Processing
Under UK GDPR, we process personal data based on:
- Contractual necessity - to fulfill orders and services
- Legitimate interests - operating and improving our business
- Legal obligations - tax, accounting, and compliance
- Consent - where required for marketing communications
Sharing Your Data
We may share your data with:
- Payment processors
- Delivery and logistics providers
- Printing and manufacturing partners (for custom branding)
- IT, hosting, and website analytics providers
- Professional advisers or authorities where legally required
We only share data necessary for the service provided and require third parties to protect your information.
International Transfers
If personal data is transferred outside the UK, we ensure appropriate safeguards are in place, such as approved contractual clauses.
Data Retention
We retain personal data only for as long as necessary:
- Order and invoice data: up to 6 years for legal and tax purposes
- Marketing data: until you withdraw consent or unsubscribe
- Enquiry data: as long as reasonably required to respond
Your Data Protection Rights
Under UK GDPR, you have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict processing
- Withdraw consent at any time
- Lodge a complaint with the Information Commissioner's Office (ICO)
To exercise your rights, contact us using the details in the Contact Us section below.
Data Security
We take appropriate technical and organisational measures to protect personal data from loss, misuse, unauthorised access, or disclosure.
Third-Party Links
Our website may contain links to third-party websites. We are not responsible for their privacy practices or content.
Changes to This Policy
We may update this Privacy Policy from time to time. The latest version will always be published on our website.
Contact Us
If you have any questions about this Privacy Policy or how we handle your data, please contact us.
