Cart (0)
Your cart is empty
PRIVACY POLICY
Last updated: 10 May 2026
This Privacy Policy explains how LUMA (Florian BOICHUT, trading as LUMA) collects, uses, stores and protects your personal data when you visit www.lightsbyluma.com or make a purchase from us. It also sets out your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Please read this Policy carefully. By using our Website, you acknowledge that you have read and understood it.
1. WHO WE ARE — DATA CONTROLLER
The data controller responsible for your personal data is:
LUMA – Florian BOICHUT
793 chemin des Mauruches Supérieures
06220 Vallauris, France
Email: contact@lightsbyluma.com
Telephone: +33 6 52 53 12 42
Website: www.lightsbyluma.com
If you have any questions about this Policy or wish to exercise your rights, please contact us using the details above.
2. WHAT PERSONAL DATA WE COLLECT
2.1 Data you provide directly
- Identity data: first name, last name
- Contact data: email address, postal address (billing and delivery), telephone number
- Payment data: payment card details (processed securely by our payment provider — we do not store full card numbers)
- Account data: username and password if you create an account
- Communications data: messages, emails or correspondence you send us, including return and refund requests
2.2 Data collected automatically
- Technical data: IP address, browser type and version, operating system, device type, time zone
- Usage data: pages you visit, time spent, links clicked, referral URLs
- Cookie and tracking data: see Section 9 (Cookies) below
2.3 Data from third parties
- Payment processors may share transaction confirmation data
- Shipping carriers may share delivery status updates
- Analytics providers may share aggregated usage data
3. HOW WE USE YOUR PERSONAL DATA
3.1 To process and fulfil your orders
Processing your order, arranging delivery, sending confirmations and dispatch notifications, handling returns and refunds.
Legal basis: performance of a contract (Article 6(1)(b) UK GDPR).
3.2 To manage your customer account
Creating and maintaining your account, enabling you to view order history and manage preferences.
Legal basis: performance of a contract.
3.3 To provide customer support
Responding to enquiries, handling complaints, processing return and refund requests.
Legal basis: performance of a contract and legitimate interests.
3.4 To send marketing communications
Sending promotional emails, newsletters or offers — only where you have given express consent.
Legal basis: consent (Article 6(1)(a) UK GDPR). Withdrawable at any time (see Section 8).
3.5 To improve our Website and services
Analysing usage patterns to improve content, functionality and performance.
Legal basis: legitimate interests (Article 6(1)(f) UK GDPR).
3.6 To prevent fraud and ensure security
Monitoring transactions and activity to detect and prevent fraudulent or unlawful activity.
Legal basis: legitimate interests and legal obligations.
3.7 To comply with legal obligations
Maintaining records for tax, accounting and regulatory purposes.
Legal basis: compliance with a legal obligation (Article 6(1)(c) UK GDPR).
4. LEGAL BASIS FOR PROCESSING
- Contract (Article 6(1)(b)): to fulfil your order and manage your account
- Legal Obligation (Article 6(1)(c)): compliance with UK law (tax, accounting)
- Legitimate Interests (Article 6(1)(f)): fraud prevention, website improvement, security — provided our interests are not overridden by your rights
- Consent (Article 6(1)(a)): marketing emails. Withdrawable at any time without affecting prior lawful processing.
5. SHARING YOUR PERSONAL DATA
5.1 Shopify Inc.
Our e-commerce platform provider, which hosts our Website and processes payments. Shopify acts as a data processor on our behalf.
5.2 Payment processors
Payment service providers process transactions securely. We do not store full payment card details.
5.3 Shipping and logistics partners
Our shipping partners receive your name and delivery address to fulfil your order.
5.4 Analytics providers
Providers such as Google Analytics receive anonymised usage data to help us understand Website performance. IP addresses are anonymised where possible.
5.5 Professional advisers
Lawyers, accountants and other advisers, under strict obligations of confidentiality.
5.6 Legal and regulatory authorities
Where required by law or court order.
We do not sell, rent, trade or otherwise transfer your personal data to third parties for their own marketing purposes.
6. INTERNATIONAL TRANSFERS
Some service providers (including Shopify Inc. and Google LLC) may process your data outside the UK. Where such transfers occur, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the UK ICO.
Contact us at contact@lightsbyluma.com for more information on specific safeguards.
7. DATA RETENTION
- Order and transaction records: up to 7 years (UK tax and accounting obligations)
- Customer account data: duration of account plus up to 2 years after last activity
- Marketing data: until you withdraw consent or request deletion
- Support and correspondence data: up to 3 years from last communication
- Technical and usage data: up to 2 years in aggregated or anonymised form
When we no longer need your data, we will securely delete or anonymise it.
8. YOUR RIGHTS UNDER UK GDPR
8.1 Right of Access
Request a copy of the personal data we hold about you ("Subject Access Request"). We will respond within one calendar month.
8.2 Right to Rectification
Request correction of inaccurate or incomplete personal data.
8.3 Right to Erasure ("Right to be Forgotten")
Request deletion of your personal data where it is no longer necessary, or where you withdraw consent.
8.4 Right to Restriction of Processing
Request restriction of processing in certain circumstances (e.g. while we verify disputed accuracy).
8.5 Right to Data Portability
Receive your data in a structured, machine-readable format where processing is based on consent or contract and carried out by automated means.
8.6 Right to Object
Object to processing based on legitimate interests, including direct marketing. We will stop processing for direct marketing purposes immediately upon your objection.
8.7 Right to Withdraw Consent
Withdraw consent at any time by clicking "unsubscribe" in any marketing email, or by contacting us at contact@lightsbyluma.com. Withdrawal does not affect prior lawful processing.
8.8 Rights Related to Automated Decision-Making
We do not carry out automated decision-making or profiling that produces legal or significant effects on you.
To exercise any right, contact us at contact@lightsbyluma.com. We will respond within one calendar month. We may ask you to verify your identity. No fee will normally be charged unless requests are manifestly unfounded or excessive.
9. COOKIES
9.1 What are cookies?
Cookies are small text files placed on your device by our Website to recognise your browser and improve your experience.
9.2 Types of cookies we use
- Strictly necessary cookies: essential for the Website to function (shopping cart, checkout). Cannot be disabled.
- Performance and analytics cookies: help us understand how visitors use the Website (e.g. Google Analytics).
- Functionality cookies: remember your preferences (language, currency).
- Marketing cookies: used to deliver relevant advertising and track campaign effectiveness.
9.3 Managing cookies
You can control and delete cookies through your browser settings. Note that disabling certain cookies may affect Website functionality. For more information, visit www.allaboutcookies.org.
10. SECURITY
We implement appropriate technical and organisational measures to protect your data, including:
- SSL/TLS encryption for all data transmitted between your browser and our Website
- Secure, access-controlled servers provided by Shopify
- Restricted internal access on a need-to-know basis
- Regular review of security practices
No method of transmission over the Internet is completely secure. If you believe your data has been compromised, please contact us immediately at contact@lightsbyluma.com.
11. THIRD-PARTY LINKS
Our Website may contain links to third-party websites. We have no control over those sites and encourage you to review their privacy policies. This Policy applies only to our Website.
12. CHILDREN'S PRIVACY
Our Website is not directed at children under 16. We do not knowingly collect data from children under 16. If you believe we have done so inadvertently, contact us and we will delete it promptly.
13. CHANGES TO THIS POLICY
We may update this Policy from time to time. Changes will be posted here with an updated date. Where changes are material, we will notify you by email or prominent notice on our Website.
14. HOW TO COMPLAIN
If you believe we have not handled your personal data correctly, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):
ICO – Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Website: www.ico.org.uk
Telephone: 0303 123 1113
We would appreciate the opportunity to address your concerns before you contact the ICO. Please contact us first at contact@lightsbyluma.com.
15. CONTACT US
LUMA – Florian BOICHUT
Email: contact@lightsbyluma.com
Telephone: +33 6 52 53 12 42
Address: 793 chemin des Mauruches Supérieures, 06220 Vallauris, France