Luminary Leads ("we," "our," or "us") is committed to protecting your privacy in accordance with the European Union General Data Protection Regulation (GDPR), Nepal Personal Data Protection Act, and other applicable data protection laws. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services for international recruitment across Poland, Romania, Croatia, Japan, Korea, Dubai, and Malaysia.
Our services involve processing personal data of job seekers and employers across multiple jurisdictions. We are registered in Nepal and operate as a data controller for the personal information we process.
We implement appropriate technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction. These include:
β’ Encryption of sensitive data
β’ Secure servers and databases
β’ Regular security audits
β’ Limited access to personal information
β’ Employee training on data protection
Under GDPR and Nepal Personal Data Protection Act, you have the following rights:
β’ Right to Access: Obtain a copy of your personal data and information about how we process it
β’ Right to Rectification: Correct inaccurate or incomplete personal information
β’ Right to Erasure ('Right to be Forgotten'): Request deletion of your data in certain circumstances
β’ Right to Restrict Processing: Limit how we use your information
β’ Right to Data Portability: Receive your data in a structured, machine-readable format
β’ Right to Object: Object to processing based on legitimate interests or direct marketing
β’ Right to Withdraw Consent: Withdraw consent at any time without affecting prior processing
β’ Right Not to be Subject to Automated Decision-Making: Including profiling
To exercise these rights, contact our Data Protection Officer at
[email protected]
Response Time: We will respond to your request within 30 days (GDPR requirement)
Complaints: You may lodge a complaint with:
β’ Nepal: Office of the Privacy Commissioner
β’ EU: Your local Data Protection Authority
β’ Other regions: Relevant privacy authorities
7. International Data Transfers
As we operate across multiple countries, your data may be transferred internationally:
β’ From Nepal to EU countries (Poland, Romania, Croatia): We use Standard Contractual Clauses (SCCs)
β’ From EU to Nepal: Adequate safeguards per GDPR Article 46
β’ To Japan: Recognized as having adequate data protection by the EU
β’ To Korea: Corporate Binding Rules and explicit consent
β’ To Dubai/UAE: Enhanced security measures and explicit consent
β’ To Malaysia: Contractual safeguards and consent
We ensure all transfers comply with:
β’ GDPR Chapter V requirements
β’ Nepal Personal Data Protection Act cross-border provisions
β’ Local data protection laws in each country
Your data is encrypted during transfer and stored in secure, compliant data centers.
We retain your personal data only as long as necessary:
β’ Active Job Seekers: Duration of job search + 2 years
β’ Placed Candidates: 7 years (employment law requirements)
β’ Unsuccessful Applications: 6 months (with consent for future opportunities)
β’ Marketing Data: Until consent withdrawn
β’ Legal/Tax Records: As required by law (typically 5-7 years)
Deletion Process:
β’ Automatic deletion after retention period
β’ Secure erasure from all systems and backups
β’ Notification of deletion upon request
β’ Certificate of deletion available
We use cookies and similar tracking technologies in compliance with GDPR and ePrivacy Directive:
Types of Cookies:
β’ Essential Cookies: Required for site functionality (no consent needed)
β’ Performance Cookies: Analytics and site improvement (consent required)
β’ Functional Cookies: Remember your preferences (consent required)
β’ Marketing Cookies: Personalized ads and tracking (explicit consent required)
Cookie Management:
β’ Cookie banner for granular consent
β’ Withdraw consent anytime via cookie settings
β’ Browser controls to block/delete cookies
β’ Do Not Track signal respected
Third-Party Services:
β’ Google Analytics (anonymized IP)
β’ LinkedIn Insight Tag (job matching)
β’ Facebook Pixel (with consent only)
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date.
Material Changes:
β’ 30 days advance notice via email
β’ Prominent website notification
β’ Explicit consent for significant changes
β’ Version history maintained
Continued use of our services after changes constitutes acceptance, except where explicit consent is required by law.
11. Country-Specific Provisions
Special provisions apply based on your location:
Poland:
β’ GDPR applies in full
β’ Polish Personal Data Protection Act supplements
β’ UODO (Polish DPA) oversight
Romania:
β’ GDPR and Romanian Law 190/2018
β’ ANSPDCP oversight
Croatia:
β’ GDPR and Croatian Implementation Act
β’ AZOP oversight
Japan:
β’ Act on Protection of Personal Information (APPI)
β’ PPC oversight
β’ EU-Japan adequacy decision applies
Korea:
β’ Personal Information Protection Act (PIPA)
β’ KISA oversight
β’ Enhanced consent requirements
Dubai/UAE:
β’ UAE Federal Law No. 45/2021
β’ DIFC Data Protection Law
β’ Enhanced security measures
Malaysia:
β’ Personal Data Protection Act 2010
β’ Commissioner oversight
Nepal:
β’ Personal Data Protection Act 2024
β’ Right to Information Act
β’ Privacy Commissioner oversight