Privacy policy
This policy explains how Luxia Ltd collects and uses personal data, the lawful basis for each use, how long we keep it, and what rights you have.
Last updated — 2 August 2026
Who we are
Luxia Ltd is the data controller for the personal data described in this policy.
Luxia Ltd13 Whites Row
London E1 7NF
United Kingdom
Registered in England & Wales, Company No. 13431915
Data protection enquiries: hello@luxia.uk
ICO registration number: ZB228718
What we collect, and why
Enquiries through our contact form or by email
We collect your name, email address, company name, website, and anything you choose to tell us in your message.
We use this to respond to you and, where a conversation develops, to keep a record of what was discussed.
Lawful basis: legitimate interests — responding to an
enquiry you initiated.
Retention: 24 months from the last contact, unless you become a
client, in which case client retention below applies.
Operational Health Scorecard
Where you complete our scorecard, we collect the answers you provide about your business together with the contact details you supply, and we generate a report from them.
We use this to produce your report, to send it to you, and to follow up where you have indicated you would like us to.
Lawful basis: consent, given when you submit the questionnaire.
You may withdraw it at any time by writing to hello@luxia.uk.
Retention: 24 months from completion, or until you withdraw
consent.
Clients and prospective clients
We hold business contact details, correspondence, proposals, contracts and billing records for the people we work with.
Lawful basis: performance of a contract, and legal obligation
for records we must retain for accounting purposes.
Retention: seven years from the end of the engagement, in line
with UK statutory requirements for business records. Correspondence not required
for those purposes is deleted after 24 months.
Agency partners
We hold business contact details and correspondence relating to partnership arrangements.
Lawful basis: legitimate interests, and performance of a
contract where one exists.
Retention: as for clients.
Client operational data
During an engagement we access systems belonging to our clients — Shopify, warehouse and fulfilment platforms, advertising accounts and communication tools. This data is predominantly commercial rather than personal, but it may include personal data such as customer names and delivery addresses.
Where we access this data, we act as a data processor on the client's instructions, not as a controller. Our responsibilities are set out in the data processing agreement forming part of every engagement, which covers the scope of access, security measures, sub-processors, breach notification and deletion on termination.
We do not use client operational data for any purpose other than delivering the engagement, and we do not retain it after an engagement ends beyond what the client instructs.
Cookies
This site does not use cookies of any kind — no analytics cookies, no advertising cookies, and no third-party tracking. Because nothing is set, no cookie consent banner is required.
Who we share data with
We do not sell personal data, and we do not share it for marketing purposes.
We use the following providers, who process data on our behalf under contract:
| Provider | Purpose | Location |
|---|---|---|
| Bluehost | Website hosting, including the Operational Health Scorecard, which is self-built and runs on the same account | Phoenix, Arizona, USA |
| Formspree | Contact form submissions | Austin, Texas, USA |
| Google Workspace | Email and document storage | EU/US |
| FreeAgent | Invoicing and accounting records | Edinburgh, Scotland, UK |
We may also disclose personal data where we are legally required to do so.
International transfers
Bluehost and Formspree process data in the United States; Google Workspace may process data in the EU or the US. Where a transfer takes place outside the United Kingdom, it is protected by an adequacy decision, the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, as applicable to that provider. FreeAgent holds data in the UK and involves no international transfer.
Security
We hold personal data on access-controlled systems with multi-factor authentication. Access to client systems is limited to the individuals delivering the engagement, uses the narrowest permissions the work requires, and is revoked when the engagement ends.
No system is entirely secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours and inform you where required.
Your rights
Under UK data protection law you have the right to:
- Be informed about how your data is used — the purpose of this policy
- Access the personal data we hold about you
- Rectify data that is inaccurate or incomplete
- Erase your data, where we have no overriding legal basis to keep it
- Restrict how we process it
- Portability — receive your data in a machine-readable format
- Object to processing based on legitimate interests
- Withdraw consent at any time, where consent is the basis
To exercise any of these, write to hello@luxia.uk. We will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.
Complaints
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office.
Information Commissioner's OfficeWycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
ico.org.uk
Changes to this policy
We update this policy when our practices change. The date at the top reflects the most recent revision. Material changes affecting how we use data already collected will be notified directly where we hold contact details for you.