Privacy Policy

Last Updated: November 9, 2025

1. Introduction

Lumina Corp Nigeria ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services.

2. Information We Collect

2.1 Personal Information

We may collect personal information that you voluntarily provide to us, including:

  • Name and contact information (email address, phone number, address)
  • Company or organization information
  • Job title and professional information
  • Communication preferences
  • Any other information you choose to provide through our contact forms

2.2 Software Service Data

When you use our software services (Lumina DPM, Lumina Library), we may process:

  • Institutional Data: Church records, member information, financial data
  • Library Data: Book records, user preferences, borrowing history
  • System Data: Usage patterns, performance metrics, error logs
  • User Account Data: Login credentials, access permissions, activity logs
  • Communication Data: Messages, notifications, support requests

2.3 Automatically Collected Information

We may automatically collect certain information when you visit our website or use our services:

  • IP address and location data
  • Browser type and version
  • Device information and operating system
  • Pages visited and time spent on our website
  • Referring website information
  • System performance and error data
  • Security and access logs

3. How We Use Your Information

We use the collected information for the following purposes:

3.1 Service Provision

  • To provide and maintain our software services (Lumina DPM, Lumina Library)
  • To process and store institutional data as requested by our clients
  • To provide technical support and customer service
  • To manage user accounts and access permissions
  • To process payments and billing information

3.2 Service Improvement

  • To analyze usage patterns and improve our software functionality
  • To develop new features and services
  • To conduct research and analytics (using anonymized data only)
  • To monitor system performance and security
  • To provide personalized user experiences

3.3 Communication and Marketing

  • To respond to your inquiries and provide customer support
  • To send you updates about our products and services (with your consent)
  • To notify you of important service changes or security updates
  • To conduct surveys and gather feedback

3.4 Legal and Security

  • To comply with legal obligations and regulatory requirements
  • To protect our rights, property, and safety
  • To prevent fraud and unauthorized access
  • To investigate security incidents and breaches
  • To enforce our terms of service and agreements

4. Information Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information in the following circumstances:

  • With your explicit consent
  • To comply with legal requirements or court orders
  • To protect our rights, property, or safety
  • With trusted service providers who assist us in operating our website (under strict confidentiality agreements)

5. Data Processing and Client Rights

5.1 Data Controller vs Data Processor

For our software services: You (our clients) are the data controller, and Lumina Corp Nigeria acts as a data processor. This means you determine the purposes and means of processing your institutional data, while we process it according to your instructions and our service agreements.

For our website and marketing: Lumina Corp Nigeria is the data controller for personal information collected through our website, contact forms, and marketing activities.

5.2 Client Data Ownership

You retain full ownership of all data you input into our systems. We do not claim ownership of your data and will not use your institutional data for purposes other than providing our services to you.

5.3 Your Rights

Under applicable data protection laws, you have the right to:

  • Access: Request copies of your personal information
  • Rectification: Correct inaccurate or incomplete information
  • Erasure: Request deletion of your personal information
  • Portability: Receive your data in a structured, machine-readable format
  • Restriction: Limit how we process your information
  • Objection: Object to certain types of processing
  • Withdraw Consent: Withdraw consent for data processing at any time

5.4 Data Export and Portability

Upon request, we will provide you with a complete export of your data in standard formats (CSV, JSON, XML). Data export requests must be made in writing and will be processed within 30 days. Export fees may apply for large datasets or complex requests.

6. Data Security

We implement comprehensive technical and organizational security measures to protect your information against unauthorized access, alteration, disclosure, or destruction.

6.1 Technical Security Measures

  • Encryption: All data is encrypted in transit (TLS/SSL) and at rest (AES-256)
  • Access Controls: Multi-factor authentication and role-based access permissions
  • Network Security: Firewalls, intrusion detection, and regular security monitoring
  • Secure Infrastructure: Hosted on secure, compliant cloud platforms
  • Regular Updates: Software and security patches applied promptly

6.2 Organizational Security Measures

  • Staff Training: Regular security awareness and data protection training
  • Access Management: Principle of least privilege and regular access reviews
  • Incident Response: Documented procedures for security incidents
  • Vendor Management: Security assessments of third-party service providers
  • Audit Trails: Comprehensive logging and monitoring of system access

6.3 Data Breach Response

In the event of a data breach, we will:

  • Notify affected clients within 24 hours of discovery
  • Provide regular updates on our response and remediation efforts
  • Cooperate with relevant authorities and regulatory bodies
  • Implement additional security measures to prevent future incidents
  • Provide support and guidance to affected clients

Note: While we implement industry-standard security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.

7. Data Retention and Deletion

We retain your information only for as long as necessary to fulfill the purposes outlined in this policy:

7.1 Retention Periods

  • Client Data: Retained for the duration of the service agreement plus 7 years for legal compliance
  • Website Analytics: Retained for 26 months (Google Analytics default)
  • Contact Information: Retained until you request deletion or withdraw consent
  • Support Communications: Retained for 3 years for service improvement
  • System Logs: Retained for 1 year for security and troubleshooting

7.2 Data Deletion

When data is no longer needed, we will:

  • Securely delete data from all systems and backups
  • Provide confirmation of deletion upon request
  • Retain only anonymized data for analytics and service improvement
  • Comply with legal requirements for data retention where applicable

7.3 Right to Erasure

You have the right to request deletion of your personal information. We will honor such requests unless we have a legal obligation to retain the data or legitimate business interests that override your request.

8. Third-Party Services

We use third-party services to provide and improve our services. These services may collect and process your information:

8.1 Service Providers

  • Zoho Mail: Email services for contact form submissions and communications
  • Google Analytics: Website analytics and performance monitoring
  • Hosting Providers: Secure cloud infrastructure for our services
  • Payment Processors: Secure payment processing for service fees

8.2 Data Processing Agreements

All third-party service providers are bound by strict data processing agreements that require them to:

  • Process data only for the purposes we specify
  • Implement appropriate security measures
  • Not use your data for their own purposes
  • Return or delete data when services end
  • Comply with applicable data protection laws

8.3 Third-Party Privacy Policies

We encourage you to review the privacy policies of third-party services we use. We are not responsible for the privacy practices of these third parties, but we ensure they meet our security and privacy standards.

9. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to improve your experience on our website. These small text files help us understand how you interact with our site and provide better service.

Types of Cookies We Use

  • Essential Cookies: Required for the website to function properly (e.g., navigation, security)
  • Analytics Cookies: Help us understand website usage through Google Analytics (anonymous data only)
  • Preference Cookies: Remember your choices and settings for a better experience

How We Use Cookies

  • Analyze website traffic and user behavior (anonymized)
  • Improve website performance and user experience
  • Remember your preferences and settings
  • Ensure website security and functionality

Your Cookie Choices

You can control cookies through your browser settings. Most browsers allow you to:

  • View and delete cookies
  • Block cookies from specific websites
  • Block all cookies (may affect website functionality)
  • Set preferences for different types of cookies

Note: Disabling certain cookies may affect the functionality and performance of our website. By continuing to use our website, you consent to our use of cookies as described in this policy.

10. International Data Transfers

Your information may be transferred to and processed in countries other than Nigeria. We ensure that such transfers comply with applicable data protection laws and implement appropriate safeguards, including:

  • Standard contractual clauses approved by relevant authorities
  • Adequacy decisions by competent data protection authorities
  • Certification schemes and codes of conduct
  • Binding corporate rules for intra-group transfers

We primarily process data within Nigeria and use reputable international service providers that maintain high data protection standards.

11. Children's Privacy

Our services are not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If you become aware that a child has provided us with personal information, please contact us immediately so we can take appropriate action.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:

  • Posting the updated Privacy Policy on this page
  • Updating the "Last Updated" date
  • Sending email notifications for significant changes
  • Providing notice through our services when appropriate

Your continued use of our services after such changes constitutes acceptance of the updated Privacy Policy.

13. Contact Us

If you have any questions about this Privacy Policy, our data practices, or wish to exercise your rights, please contact us at:

Email: contact@luminacorp.org
Address: Lagos, Nigeria
Website: https://luminacorp.org

We will respond to your inquiries within 30 days and work with you to address any concerns about your privacy and data protection.