GDPR Compliance

Your Rights Under the General Data Protection Regulation

Full Compliance Since May 25, 2018

Back to Home

GDPR Compliance Status: Fully Compliant

Luminary Leads is fully compliant with the General Data Protection Regulation (EU) 2016/679.

DPO Appointed

Certified Data Protection Officer

Regular Audits

Annual third-party assessments

Staff Training

Ongoing privacy education

1. GDPR Compliance Overview

The General Data Protection Regulation (GDPR) is a comprehensive data protection law that applies to all organizations processing personal data of EU residents. As Luminary Leads operates in Poland, Romania, and Croatia, we fully comply with GDPR requirements. Our Commitment: β€’ Full GDPR compliance since May 25, 2018 β€’ Regular audits and assessments β€’ Continuous improvement of data protection measures β€’ Transparent data processing practices β€’ Respect for individual rights GDPR Principles We Follow: β€’ Lawfulness, fairness, and transparency β€’ Purpose limitation β€’ Data minimization β€’ Accuracy β€’ Storage limitation β€’ Integrity and confidentiality β€’ Accountability

3. Your GDPR Rights

Under GDPR, you have the following rights: Right to Access (Article 15): β€’ Request a copy of your personal data β€’ Understand how we process it β€’ Receive information about transfers Right to Rectification (Article 16): β€’ Correct inaccurate data β€’ Complete incomplete data β€’ Update outdated information Right to Erasure (Article 17): β€’ Request deletion of your data β€’ "Right to be forgotten" β€’ Applies in specific circumstances Right to Restrict Processing (Article 18): β€’ Limit how we use your data β€’ During dispute resolution β€’ When accuracy is contested Right to Data Portability (Article 20): β€’ Receive your data in machine-readable format β€’ Transfer to another service β€’ Applies to consent/contract based processing Right to Object (Article 21): β€’ Object to direct marketing β€’ Object to legitimate interests processing β€’ Object to profiling Right to Withdraw Consent: β€’ Withdraw consent anytime β€’ Does not affect prior processing β€’ Easy withdrawal mechanism

4. Data Protection Measures

Technical Measures: β€’ AES-256 encryption at rest β€’ TLS 1.3 for data in transit β€’ Multi-factor authentication β€’ Regular security audits β€’ Intrusion detection systems β€’ Secure backup procedures β€’ Access logging and monitoring Organizational Measures: β€’ Data Protection Officer appointed β€’ Staff training programs β€’ Privacy by Design implementation β€’ Data Protection Impact Assessments (DPIA) β€’ Vendor due diligence β€’ Incident response procedures β€’ Regular policy reviews Physical Security: β€’ Secure data center facilities β€’ Access control systems β€’ Environmental monitoring β€’ Disaster recovery plans

5. International Data Transfers

Transfer Mechanisms: To Nepal (Non-EU): β€’ Standard Contractual Clauses (SCCs) - Module 2 β€’ Additional safeguards implemented β€’ Transfer Impact Assessment conducted Within EU: β€’ Free movement of data β€’ Same protection standards To Other Countries: β€’ Japan: Adequacy decision β€’ Korea: SCCs + supplementary measures β€’ Dubai: SCCs + enhanced security β€’ Malaysia: SCCs + consent Safeguards: β€’ Encryption during transfer β€’ Access controls β€’ Contractual obligations β€’ Regular audits β€’ Data localization where required Your Rights: β€’ Information about transfers β€’ Copy of safeguards β€’ Object to certain transfers

6. Data Breach Procedures

Breach Response Timeline: Detection: β€’ 24/7 monitoring systems β€’ Immediate escalation procedures β€’ Incident response team activation Assessment (0-24 hours): β€’ Determine scope and impact β€’ Identify affected individuals β€’ Assess risk level β€’ Implement containment measures Notification: β€’ Supervisory Authority: Within 72 hours β€’ Affected Individuals: Without undue delay (for high-risk breaches) β€’ Detailed breach report β€’ Mitigation advice Our Commitments: β€’ Transparent communication β€’ Support for affected individuals β€’ Free credit monitoring (where applicable) β€’ Regular updates on investigation β€’ Lessons learned implementation Prevention: β€’ Regular security assessments β€’ Employee training β€’ Technical controls β€’ Vendor management

7. Cookie Policy

Our Comprehensive Cookie Policy: What Are Cookies? Cookies are small text files placed on your device when you visit our website. They help us provide you with a better experience by remembering your preferences and understanding how you use our site. Types of Cookies We Use: πŸ”’ Essential Cookies (Always Active) β€’ Session management and security β€’ Load balancing and site functionality β€’ Authentication and access control β€’ Form submission handling β€’ No consent required as they are necessary for operation πŸ“Š Analytics Cookies (Consent Required) β€’ Google Analytics for traffic analysis β€’ Custom analytics for user journey mapping β€’ Performance monitoring β€’ Error tracking and debugging β€’ Heatmap and scroll depth analysis β€’ A/B testing and optimization βš™οΈ Functional Cookies (Consent Required) β€’ Language preferences β€’ User interface customization β€’ Recently viewed jobs β€’ Form autofill preferences β€’ Accessibility settings β€’ Time zone detection 🎯 Marketing Cookies (Explicit Consent Required) β€’ Facebook Pixel for retargeting β€’ Google Ads remarketing β€’ LinkedIn Insight Tag β€’ Social media integration β€’ Conversion tracking β€’ Interest-based advertising Third-Party Cookies: β€’ Google Analytics: _ga, _gid, _gat β€’ Facebook: fr, _fbp β€’ LinkedIn: li_gc, bcookie β€’ YouTube: YSC, VISITOR_INFO1_LIVE Cookie Duration: β€’ Session cookies: Deleted when browser closes β€’ Persistent cookies: 1 day to 2 years β€’ Analytics cookies: 2 years β€’ Marketing cookies: 90 days Your Cookie Rights: β€’ Accept or reject non-essential cookies β€’ Change preferences anytime β€’ Delete cookies through browser settings β€’ Opt-out of specific services β€’ Request information about cookies used Managing Cookies: β€’ Use our cookie consent tool β€’ Browser settings control β€’ Google Ads Settings β€’ Facebook Ad Preferences β€’ LinkedIn Ad Preferences Consequences of Blocking Cookies: β€’ Essential features may not work β€’ Preferences won't be saved β€’ You may see generic content β€’ Some forms may not function β€’ Analytics won't track improvements Cookie-Free Alternatives: β€’ Local storage for preferences β€’ Server-side sessions β€’ URL parameters for tracking β€’ Browser fingerprinting (not used) Updates to Cookie Policy: β€’ Regular reviews every 6 months β€’ Notification of significant changes β€’ Consent renewal annually β€’ Version history maintained

8. Data Protection Impact Assessment

When We Conduct DPIAs: Mandatory Cases: β€’ Biometric data processing β€’ Large-scale special category data β€’ Systematic monitoring β€’ Automated decision-making β€’ New technologies DPIA Process: 1. Describe processing operations 2. Assess necessity and proportionality 3. Identify and assess risks 4. Determine mitigation measures 5. Consult stakeholders 6. Review and approve 7. Monitor and review Transparency: β€’ DPIA summaries available on request β€’ Stakeholder consultation β€’ Regular reviews and updates Risk Mitigation: β€’ Technical measures β€’ Organizational controls β€’ Policy updates β€’ Training programs

9. Children's Data Protection

Age Restrictions: β€’ Minimum age: 18 years for our services β€’ No intentional collection from minors β€’ Age verification procedures If Child Data is Discovered: β€’ Immediate deletion β€’ Parent/guardian notification β€’ No further processing β€’ Incident documentation Special Protections: β€’ Enhanced consent requirements β€’ Parental control options β€’ No profiling of children β€’ No direct marketing β€’ Educational materials only Compliance: β€’ Regular age verification audits β€’ Staff training on child protection β€’ Clear age requirements β€’ Prompt response to concerns

10. Automated Decision Making

Our Approach: Limited Automation: β€’ Initial candidate screening β€’ Job matching algorithms β€’ Risk assessment Human Oversight: β€’ All significant decisions reviewed β€’ Human intervention available β€’ Explainable algorithms β€’ Regular audits Your Rights: β€’ Request human review β€’ Express your viewpoint β€’ Contest decisions β€’ Understand logic involved Safeguards: β€’ No decisions based solely on automation β€’ Regular algorithm testing β€’ Bias prevention measures β€’ Transparency reports β€’ Fair processing guarantees

11. Supervisory Authorities

You can contact supervisory authorities: Poland: UODO (UrzΔ…d Ochrony Danych Osobowych) Address: Stawki 2, 00-193 Warsaw Website: uodo.gov.pl Email: [email protected] Romania: ANSPDCP Address: B-dul G-ral. Gheorghe Magheru 28-30, Bucharest Website: dataprotection.ro Email: [email protected] Croatia: AZOP (Agencija za zaΕ‘titu osobnih podataka) Address: Selska cesta 136, 10000 Zagreb Website: azop.hr Email: [email protected] European Data Protection Board: Website: edpb.europa.eu For cross-border complaints How to File a Complaint: 1. Contact us first for resolution 2. If unsatisfied, contact your local authority 3. Provide detailed information 4. We cooperate fully with investigations

12. Contact Our DPO

Data Protection Officer: Name: [DPO Name] Certification: IAPP CIPP/E, CIPM Email: [email protected] Phone: +977 9808888489 Secure Contact: dpo.luminaryleads.com.np/secure Office Hours: β€’ Sunday-Friday: 9:00-18:00 NPT β€’ Emergency: 24/7 for breaches Response Times: β€’ General inquiries: 48 hours β€’ Rights requests: 72 hours β€’ Urgent matters: 24 hours How We Can Help: β€’ Exercise your rights β€’ Privacy concerns β€’ Data protection advice β€’ Complaint handling β€’ Training requests β€’ DPIA consultation Anonymous Reporting: privacy.luminaryleads.com.np/anonymous

GDPR Resources

Access our comprehensive GDPR resources to better understand your rights and our compliance measures.

Have questions about GDPR or your data rights?

Contact Our Data Protection Officer