top of page

Privacy Policy

LUMISKINGLOW
LED SKIN TECH

PRIVACY POLICY


Effective Date: June 4, 2026

Welcome to LumiSkinGlow. We design and sell innovative LED-based skin technology products, including our Smart LED Skin Jewelry and companion smartphone application. Protecting your privacy is fundamental to how we operate. This detailed Privacy Policy explains in clear terms what personal data we collect, why we collect it, how we use and protect it, who we share it with, and what rights you have under UK GDPR, the Data Protection Act 2018, and applicable EU data protection laws.

Scope: This Policy applies to all personal data processed in connection with our website (including the online store), the LumiSkinGlow Smartphone Application, customer support, marketing communications, and your use of our physical Products (the Smart LED Skin Jewelry / Device).
 

TABLE OF CONTENTS

• 1. What Personal Information Do We Collect?
• 2. How and Why We Use Your Personal Information
• 3. Consent and How to Withdraw It
• 4. Disclosure and Sharing of Your Information
• 5. Third-Party Services, Payment Gateways & Shipping
• 6. The LumiSkinGlow App and Smart LED Skin Jewelry — Privacy by Design
• 7. Cookies, Analytics and Tracking Technologies
• 8. Data Retention Periods
• 9. Data Security Measures
• 10. Your Privacy Rights (Access, Deletion, Objection, etc.)
• 11. International Data Transfers
• 12. Children's Privacy
• 13. Links to Third-Party Websites and Services
• 14. Do Not Track and Global Privacy Controls
• 15. Automated Decision-Making and Profiling
• 16. Changes to This Privacy Policy
• 17. Contact Us, Complaints and Supervisory Authorities

This Policy is written in plain English to help you understand your rights. If you have questions, please contact us — we are happy to explain any part in more detail.

1. WHAT PERSONAL INFORMATION DO WE COLLECT?

We collect personal data only when it is necessary for the purposes described in this Policy. We aim to collect the minimum amount of data required and to be transparent about it. Below we describe the categories of personal data we may collect from or about you.

a. Information You Provide Directly

• Identity & Contact Data: Full name, billing address, shipping address, email address, telephone number. This is collected when you place an order, create an account (if available), or contact us for support.
• Account & Authentication Data: If you register for an account, we collect a username or email, and a securely hashed password. We do not store passwords in plain text.
• Transaction & Order Data: Products selected, quantities, prices, order date and number, payment confirmation status, and any notes or special instructions you provide at checkout or in correspondence.
• Payment Information: We do not store your full credit or debit card number, CVV, or expiry date on our servers. This sensitive data is collected and processed directly by PCI-DSS compliant payment gateways (see Section 5). We may receive a payment token, last four digits of the card, and authorization status for record-keeping and receipts.
• Communications & Support Data: Content of emails, live chat messages (if offered), support tickets, feedback forms, product reviews, warranty claims, and any attachments or photos you voluntarily send us (e.g., for troubleshooting your Device).
• Marketing Preferences: Your choices regarding receiving newsletters, promotional offers, product updates, skin-care tips, or event invitations. We record when and how you opted in.

b. Information Collected Automatically (Technical & Usage Data)

When you browse our Site or use our App, we automatically collect certain technical information:

• Device & Connection Data: IP address (we apply IP anonymization / masking where technically feasible for analytics), browser type and version, operating system and version, device type and model, screen resolution, language preference, time zone.
• Usage & Interaction Data: Pages and products viewed, time spent on pages, referring and exit URLs, search queries on the Site, items added to cart or wishlist, checkout funnel progression, and other clickstream or behavioral data. This helps us understand how our Site and Products are used and where we can improve.
• App-Specific Technical Data: App version, operating system version, device model, and temporary local Bluetooth identifiers required to pair and communicate with your Smart LED Skin Jewelry. These local identifiers are not linked to your identity on our servers and are not transmitted externally.

c. Information from Third Parties

We may receive limited personal data from trusted third parties:

• Payment processors confirming successful transactions or providing fraud signals.
• Shipping carriers providing delivery status updates linked to your order number and address.
• Analytics and advertising platforms providing aggregated, anonymized, or pseudonymized insights (we configure these services to minimize the personal data they process on our behalf).

d. Sensitive / Special Category Data

Our Smart LED Skin Jewelry and App are designed for cosmetic, aesthetic, and wellness use. We do not intentionally collect or process sensitive personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person’s sex life or sexual orientation.

If, in the future, we introduce features that would involve processing such data (for example, optional skin analysis photos or health-related preferences), we will obtain your explicit consent, provide a clear lawful basis, and update this Policy before any such processing begins. Any such data would be processed locally on your device where possible.

Important: We do not knowingly collect personal data from children under the age of 16. See Section 12 for details.

---

2. HOW AND WHY WE USE YOUR PERSONAL INFORMATION

We process your personal data only for specified, explicit, and legitimate purposes and only where we have a valid legal basis under data protection law. We do not use your data for purposes that are incompatible with those disclosed here.

Legal Bases We Rely On

Under the UK GDPR and EU GDPR, we rely on one or more of the following lawful bases:

• Performance of a Contract (Art. 6(1)(b)): Processing necessary to fulfill our contract with you — e.g., processing and delivering your order, providing App functionality that you requested, handling returns, or providing customer support for a purchased Device.
• Consent (Art. 6(1)(a)): Where you have given clear, informed, and freely given consent — e.g., opting in to marketing emails, accepting non-essential cookies, or voluntarily providing additional data for a support request. You can withdraw consent at any time (see Section 3).
• Legitimate Interests (Art. 6(1)(f)): Where processing is necessary for our legitimate business interests or those of a third party, provided those interests are not overridden by your fundamental rights and freedoms. Examples: improving our Site and Products, preventing fraud, ensuring network and information security, and conducting aggregated analytics. We conduct Legitimate Interest Assessments (LIAs) and balance tests for these activities.
• Legal Obligation (Art. 6(1)(c)): Processing necessary to comply with a legal obligation to which we are subject — e.g., retaining transaction records for tax and accounting purposes, responding to lawful requests from public authorities, or fulfilling consumer protection obligations.

Specific Purposes for Which We Process Data

• Order Processing & Fulfillment: To accept and process your purchase, verify payment, arrange shipping and delivery, send order confirmations, invoices, shipping notifications, and handle returns, exchanges, or warranty claims. Legal basis: Contract + Legal Obligation.
• Customer Support & Service: To respond to your inquiries, troubleshoot technical issues with the Device or App, provide guidance on LED skin therapy usage, and resolve complaints. Legal basis: Contract + Legitimate Interest.
• Transactional Communications: To send emails or notifications that are strictly necessary for the service you requested (order updates, delivery tracking, password resets, security alerts). These are not marketing; you generally cannot opt out without losing functionality. Legal basis: Contract + Legitimate Interest.
• Marketing & Promotional Communications: With your consent, to send emails, newsletters, or other messages about new Products, special offers, LED skin care education, events, or personalized recommendations. We use double opt-in where required by law and make it easy to unsubscribe. Legal basis: Consent.
• Website & App Improvement & Personalization: To analyze how our Site and App are used, identify bugs or friction points, test new features, personalize product recommendations and content based on your browsing or purchase history, and optimize the shopping experience. Legal basis: Legitimate Interest (with cookie consent where required).
• Analytics & Business Insights: To generate aggregated, anonymized reports on sales trends, customer demographics (at group level), campaign performance, and product popularity. We configure analytics tools to use the minimum data necessary. Legal basis: Legitimate Interest.
• Security, Fraud Prevention & Legal Compliance: To detect and prevent fraudulent transactions, unauthorized access, spam, or other malicious activity; to enforce our Terms of Service; to comply with tax, accounting, consumer protection, and data protection laws; and to respond to valid legal requests from courts, regulators, or law enforcement. Legal basis: Legitimate Interest + Legal Obligation.
• App & Device Functionality (Local Processing): To enable Bluetooth pairing and local control of your Smart LED Skin Jewelry (LED patterns, brightness, modes, timers). All core processing happens locally on your phone or Device. No personal data is transmitted to our servers for this purpose. Legal basis: Contract (you choose to use the feature) + Legitimate Interest.

We do not use your personal data for any form of solely automated decision-making that produces legal or similarly significant effects on you (see Section 15). We do not sell or rent your personal data to third parties for their independent marketing or other purposes.

---

3. CONSENT AND HOW TO WITHDRAW IT

Where we rely on your consent, we ensure it is freely given, specific, informed, and unambiguous. You have the right to withdraw your consent at any time, and we make it as easy to withdraw as it was to give.

How We Obtain Consent

• At checkout or account creation: clear checkboxes or toggles for marketing communications and non-essential cookies/analytics.
• Cookie banner / preference center on first visit (and accessible via footer): granular choices for analytics and advertising cookies.
• When you voluntarily sign up for our newsletter via a dedicated form (double opt-in confirmation email sent where legally required).
• Implied consent for strictly necessary processing to complete a transaction you initiated (e.g., providing your address to ship the Product you ordered).

How to Withdraw Consent or Change Your Preferences

• Marketing emails: Click the “Unsubscribe” or “Manage Preferences” link at the bottom of any promotional email. This takes effect immediately for future sends. You can also email legal@lumiskinglow.co.uk with “Unsubscribe” in the subject.
• Cookies & Tracking: Use the “Cookie Settings” link in the footer to update your choices at any time. Alternatively, adjust your browser settings to block or delete cookies (note: this may affect Site functionality). See Section 7 for more details and third-party opt-out links.
• App permissions: You can revoke Bluetooth permission or uninstall the App at any time via your phone’s settings. This stops all local communication with the Device.
• Full account deletion / data erasure request: Email legal@lumiskinglow.co.uk — see Section 10 for details on your rights.

Please note: Withdrawing consent for optional processing (marketing, analytics) will not affect our ability to provide the core services you have purchased or requested under contract. However, withdrawing consent for essential cookies or necessary data for order fulfillment may prevent you from completing a purchase or using certain features.

---

4. DISCLOSURE AND SHARING OF YOUR INFORMATION

We do not sell, rent, or trade your personal data. We only disclose it in the limited circumstances described below, and always with appropriate safeguards.

a. Service Providers and Data Processors (Our Trusted Partners)

We engage carefully selected third-party service providers (“processors”) to help us operate our business. They act only on our documented instructions, are bound by Data Processing Agreements (DPAs) that require them to implement appropriate technical and organizational security measures, to process data only for the purposes we specify, and not to use it for their own purposes or sell it. We share only the minimum data necessary for them to perform their contracted services.

Categories of processors we currently use or may use include:

• Payment Processing & Fraud Prevention: PCI-DSS compliant gateways and related services. They receive the payment details you enter directly on their secure pages. We receive only confirmation and limited tokenized data.
• Shipping, Logistics & Couriers: Name, shipping address, phone number, email (for delivery notifications), and order summary. Used solely to pick, pack, ship, and deliver your order and manage returns. See Section 5 for more.
• Website, App Hosting, Cloud Infrastructure & Backend Services: To store, process, and serve the Site, App backend, and databases. We prioritize providers with strong privacy commitments and EU/UK data residency options where available.
• Analytics & Performance Measurement: Google Analytics (configured with IP anonymization and data sharing controls), and similar tools. Data is primarily aggregated and pseudonymized.
• Advertising & Retargeting Platforms: Meta (Facebook/Instagram) Pixel or Conversions API — used to measure ad campaign performance and, with consent, show you relevant ads on other platforms. Configured to respect your choices.
• Email & Customer Communication Platforms: To send transactional and (with consent) marketing emails, manage subscriber lists, and analyze engagement. Includes suppression list management to honor opt-outs.
• Customer Support & CRM Tools: To log, track, and respond to your inquiries and support requests efficiently.
• IT Security, Backup & Business Continuity Services: To protect our systems and data.

b. Legal, Regulatory and Safety Disclosures

We may disclose personal data without your prior consent where required or permitted by law:

• To comply with a legal obligation, court order, or valid request from a public authority (tax authorities, police, data protection supervisory authorities, etc.).
• To enforce or defend our legal rights, including our Terms of Service, or to investigate potential violations.
• To detect, prevent, or address fraud, security threats, or other illegal or harmful activity.
• To protect the vital interests of you or another person (rare).

c. Business Transfers

In the unlikely event of a merger, acquisition, corporate reorganization, or sale of all or substantially all of our assets, personal data may be transferred to the successor entity. We will notify you of any such change and ensure that the new entity is bound by a privacy policy that is at least as protective as this one, or we will obtain your consent where required.

d. With Your Consent or at Your Direction

We may share specific data when you explicitly ask us to (e.g., “please send my order details to my accountant” or when you authorize integration with another service you use).

---

5. THIRD-PARTY SERVICES, PAYMENT GATEWAYS & SHIPPING

Payment Gateways

All direct payment gateways used on our Site adhere to the Payment Card Industry Data Security Standard (PCI-DSS) as managed by the PCI Security Standards Council. This is the highest industry standard for secure handling of credit card information. When you enter your card details, the data is transmitted directly and securely to the payment gateway’s encrypted environment. We never see or store your full card number, CVV, or expiry date. We receive only a confirmation of payment success/failure, a transaction reference, and (in some cases) the last four digits of the card for your receipt and our records.

Shipping Couriers and Logistics Partners

To deliver your order, we share the following information with our logistics partners and couriers (which may include international carriers such as DHL, UPS, FedEx, Royal Mail, or local/regional partners in the UK, EU, and Hungary):

• Full name of the recipient
• Complete shipping address
• Telephone number (for delivery notifications, customs clearance if applicable, and to resolve delivery issues)
• Email address (for tracking links and delivery updates)
• Order contents summary and any special delivery instructions you provided

These partners use the data solely for the purpose of picking, packing, shipping, customs clearance (where relevant), and delivering your package, and for managing any returns or failed delivery attempts. They are contractually prohibited from using it for any other purpose, including their own marketing.

Other Third-Party Integrations

We may integrate with other reputable services to enhance functionality (e.g., review platforms, live chat providers, or social login options if offered). Any such integration is disclosed at the point of use, and data sharing is limited and governed by our contracts with those providers and this Policy.

---

6. THE LUMISKINGLOW APP AND SMART LED SKIN JEWELRY — PRIVACY BY DESIGN

Our Smart LED Skin Jewelry and companion Smartphone Application have been designed from the ground up with privacy and data minimization as core principles. This section provides specific details beyond the general rules in this Policy.

Key Privacy Features of the App + Device

• Local Bluetooth Communication Only: The App communicates with your Smart LED Skin Jewelry exclusively via Bluetooth Low Energy (BLE). No internet connection is required for any core functionality — controlling LED colors, patterns, brightness, animation modes, timers, or skin therapy/wellness programs.
• No Cloud Account Required: You can use the full features of the Device and App without creating an account or logging in. There is no mandatory cloud sync or remote storage of your preferences or usage history.
• No Transmission of Personal Data to Our Servers: The App does not collect, store on our servers, or transmit to LumiSkinGlow or any third party:
  - Your precise or approximate geolocation (GPS, Wi-Fi, or cell tower data)
  - Device usage statistics, session history, or LED mode usage patterns
  - Any sensor or biometric readings from the Device (the Device is an LED emitter/jewelry, not a medical diagnostic tool with health sensors)
  - Photos, voice, or other media unless you voluntarily attach them to a support request
• Local Storage Only: Any settings, favorite modes, or last-used configurations are stored locally on your smartphone (in the App’s private storage) and/or in the Device’s internal memory. Uninstalling the App or performing a factory reset on the Device permanently deletes this local data.
• Optional Account Features (Future): If we introduce optional cloud backup of preferences, multi-device sync, or firmware update management in the future, these will be clearly marked as optional, will require separate explicit consent, and will be covered by an update to this Policy. You will always be able to use the Device without these features.
• Support & Troubleshooting: If you contact us for help with the Device or App, we may ask you to voluntarily share error logs, screenshots, or a description of the issue. Any data you choose to share for this purpose is handled under this Policy and is deleted or anonymized once the issue is resolved (unless we have another legal basis to retain it).

This local-first, privacy-by-design architecture significantly reduces the amount of personal data processed and gives you maximum control. We believe your LED skin therapy and jewelry experience should remain private between you and your Device.

---

7. COOKIES, ANALYTICS AND TRACKING TECHNOLOGIES

We use cookies and similar technologies (web beacons/pixels, local storage, and in-App SDKs where applicable) to provide essential functionality, understand usage, and (with your consent) deliver and measure relevant advertising.

What Are Cookies?

Cookies are small text files that are placed on your device when you visit a website. They allow the website (or third parties) to recognize your device and store certain information about your visit or preferences. We also use similar technologies such as pixels (small invisible images that track whether you have viewed a page or email) and local storage.

Types of Cookies and Tracking Technologies We Use

  |   Type                    |   Purpose                                                                   |   Examples / Providers                            |   Legal Basis                                        |  
  |  -----------------------  |  -------------------------------------------------------------------------  |  -----------------------------------------------  |  --------------------------------------------------  |  
  |   Strictly Necessary      |   Enable core Site functions such as shopping cart, checkout process, session security, and load balancing. Without these the Site cannot function properly.   |   Session cookies, cart ID, CSRF tokens, load balancer cookies   |   Legitimate Interest / Contract performance (no consent required in most cases)   |  
  |   Performance / Analytics   |   Help us understand how visitors use the Site (number of visitors, pages viewed, time on site, traffic sources, conversion rates). Used to improve performance and user experience. Data is largely aggregated.   |   Google Analytics (with IP anonymization enabled, data retention minimized)   |   Legitimate Interest (with cookie consent banner where required)   |  
  |   Functionality / Preferences   |   Remember choices you make (e.g., language, currency, display preferences, dismissed banners) so you do not have to re-enter them on future visits.   |   Preference cookies, UI state cookies           |   Legitimate Interest / Consent                      |  
  |   Targeting / Advertising   |   Used by us and our advertising partners to deliver more relevant ads to you on other websites and to measure the effectiveness of our advertising campaigns (remarketing, conversion tracking).   |   Meta (Facebook) Pixel / Conversions API, Google Ads remarketing (if used)   |   Consent (you can refuse via cookie banner or ad settings)   |  

Managing Your Cookie Preferences

• Cookie Banner / Preference Center: On your first visit (and via a persistent link in the footer), we present a cookie consent banner that allows you to accept all, reject non-essential categories, or customize your choices at a granular level where technically feasible.
• Browser Settings: You can configure your browser to block or delete cookies. Instructions are available in the help sections of Chrome, Firefox, Safari, Edge, etc. Note that blocking strictly necessary cookies will prevent core Site features (e.g., adding items to cart or completing checkout) from working.
• Third-Party Opt-Out Tools:
  - Google Analytics Opt-out: https://tools.google.com/dlpage/gaoptout
  - Meta (Facebook) Ad Preferences and opt-out tools within your Facebook/Instagram settings or via https://www.youronlinechoices.com/
  - Industry-wide opt-out platforms such as the Digital Advertising Alliance (DAA) or Network Advertising Initiative (NAI) tools.
• App Tracking: The LumiSkinGlow App does not use third-party tracking SDKs or analytics that send personal data to external servers. Any future analytics would be clearly disclosed and optional.

We review our use of cookies and tracking technologies regularly and update the information in this section and in our cookie banner as needed.

---

8. DATA RETENTION PERIODS

We retain personal data only for as long as is necessary to fulfill the purposes for which it was collected, or to comply with legal, accounting, tax, or reporting requirements. When data is no longer needed, we securely delete it or anonymize it so that it can no longer be associated with you.

Typical Retention Periods

• Order, Transaction & Accounting Records: 7 years from the date of the transaction (or longer if required by UK tax law, HMRC rules, or applicable EU/Hungarian accounting and tax legislation). This covers invoices, payment records, and related correspondence for audit and legal claim limitation periods.
• Customer Account Data: Retained while your account is active. If you have not placed an order or logged in for 3 years, we may delete or anonymize the account data (except where we have a legal obligation to retain certain records). You can request deletion earlier (see Section 10).
• Marketing Contact Data: Retained until you unsubscribe, withdraw consent, or request deletion. We maintain a minimal suppression list (email address + date of opt-out) indefinitely to ensure we never contact you again for marketing after you have opted out.
• Support, Warranty & Complaint Records: 3–7 years after the last interaction or resolution of the matter, depending on the nature of the issue and applicable limitation periods for legal claims.
• Technical Logs & Analytics Data: Raw server logs and detailed analytics data are typically retained for 14–90 days (or as configured in Google Analytics — we set user data retention to the minimum available, currently 14 months). Aggregated and anonymized statistical data may be retained indefinitely for business intelligence purposes.
• App & Device Local Data: Stored only on your device. Deleted when you uninstall the App, clear App data, or reset the Device. We have no server-side copy.
• Cookie Data: Session cookies are deleted when you close your browser. Persistent cookies have defined expiry dates (typically 1 day to 2 years) or are deleted when you clear them via browser settings or our preference center.

If you exercise your right to erasure (see Section 10), we will delete or anonymize your personal data without undue delay, unless we have a legal obligation or legitimate interest to retain it (e.g., tax records, suppression lists, or ongoing legal claims). In such cases we will inform you of the limited data we must keep and why.

---

9. DATA SECURITY MEASURES

We implement appropriate technical and organizational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Our security program is designed to be commensurate with the sensitivity of the data and the risks involved.

Key Security Measures Include:

• Encryption in Transit: All communication between your browser or App and our servers is protected by TLS/SSL (HTTPS). Payment-related pages use additional secure protocols and are hosted on PCI-DSS compliant infrastructure.
• Encryption at Rest: Where we store sensitive personal data, it is protected using strong encryption (e.g., AES-256 or equivalent) at the database or storage layer.
• Access Controls & Least Privilege: Access to personal data is restricted to authorized personnel who need it to perform their job functions. We use role-based access control (RBAC), multi-factor authentication (MFA) where available, and regular access reviews.
• Secure Software Development: We follow secure coding practices, perform code reviews, static and dynamic security testing, and vulnerability scanning as part of our development lifecycle.
• Regular Security Testing: We conduct or commission penetration testing and security audits on a periodic basis (at least annually or after significant changes).
• PCI-DSS Compliance: Any handling of cardholder data (even if limited) complies with the Payment Card Industry Data Security Standard. We undergo regular compliance assessments.
• Third-Party Security: We perform due diligence on all processors and require them, via contract, to maintain security standards no less protective than our own (including ISO 27001, SOC 2, or equivalent certifications where appropriate).
• Incident Response & Breach Notification: We maintain a documented Personal Data Breach Response Plan. In the event of a breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with GDPR/UK GDPR requirements.
• Staff Awareness: All personnel with access to personal data receive regular training on data protection, information security, and their obligations under this Policy and applicable law.
• Physical & Environmental Security: Our cloud infrastructure providers maintain industry-leading physical security controls at their data centers (badge access, CCTV, environmental controls, etc.).

While we take reasonable and appropriate measures to protect your data, no system can be guaranteed to be 100% secure. If you have reason to believe that your interaction with us is no longer secure (e.g., you suspect your account has been compromised), please contact us immediately at legal@lumiskinglow.co.uk.

---

10. YOUR PRIVACY RIGHTS (ACCESS, DELETION, OBJECTION, ETC.)

Under the UK GDPR, EU GDPR, and other applicable data protection laws, you have a number of important rights in relation to your personal data. These rights are not absolute and may be subject to conditions or exemptions (for example, we may be unable to delete data that we are legally required to retain).

Your Rights Include:

• Right to be Informed — This Privacy Policy (together with any specific notices we provide at the point of collection) informs you about how we process your data.
• Right of Access — You can request confirmation of whether we process your personal data and, if so, obtain a copy of that data together with information about the processing (a “Subject Access Request”). We will usually provide this free of charge within one month.
• Right to Rectification — You can request that we correct any inaccurate or incomplete personal data we hold about you.
• Right to Erasure (“Right to be Forgotten”) — You can request that we delete your personal data without undue delay where there is no overriding legal basis for us to continue processing it (e.g., after you withdraw consent, the contract ends, or the data is no longer necessary). We will inform you if any data must be retained for legal reasons.
• Right to Restrict Processing — You can ask us to temporarily suspend processing of your data in certain circumstances (e.g., while you contest its accuracy or object to processing).
• Right to Data Portability — Where processing is based on consent or contract and carried out by automated means, you can request to receive your data in a structured, commonly used, machine-readable format and, where technically feasible, have it transferred directly to another controller.
• Right to Object — You can object to processing of your data that is based on our legitimate interests or for direct marketing purposes. For direct marketing, we will always honor your objection immediately and without requiring any reason.
• Rights Related to Automated Decision-Making and Profiling — You have the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal or similarly significant effects concerning you. We currently do not engage in such fully automated decision-making with significant effects (see Section 15).
• Right to Withdraw Consent — Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing that occurred before the withdrawal. See Section 3 for easy ways to do this.
• Right to Lodge a Complaint — If you believe we have infringed your data protection rights, you have the right to lodge a complaint with a supervisory authority. We strongly encourage you to contact us first so we can try to resolve the matter quickly and to your satisfaction.

How to Exercise Your Rights

Please send your request to legal@lumiskinglow.co.uk with the subject line “Privacy Rights Request – [Your Name]”. To help us process your request efficiently, please:

• Clearly state which right(s) you wish to exercise
• Provide sufficient information to allow us to identify you and locate your data (e.g., the email address used for orders, order number, approximate date of last interaction)
• Verify your identity if requested (we may ask for a copy of a government-issued ID or send a confirmation link to your registered email — this is to protect your data from unauthorized requests)

We aim to respond to all valid requests within one calendar month of receipt. For complex or numerous requests we may extend this by up to two additional months and will inform you of the extension and the reasons. There is no fee for exercising your rights unless your request is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or refuse to comply.

Supervisory Authorities

• United Kingdom: Information Commissioner’s Office (ICO) — www.ico.org.uk
• Hungary / European Union: Hungarian National Authority for Data Protection and Freedom of Information (NAIH) or the supervisory authority in your country of residence. A full list is available at the European Data Protection Board website.

---

11. INTERNATIONAL DATA TRANSFERS

Some of the third-party service providers we use are located outside the United Kingdom and the European Economic Area (EEA), most notably in the United States (for example, Google LLC for Analytics services and Meta Platforms, Inc. for advertising measurement tools).

When we transfer your personal data to countries that do not have an adequacy decision from the UK Government or European Commission, we ensure that appropriate safeguards are in place to protect your data to a standard essentially equivalent to that in the UK/EU. The main safeguards we use are:

• Standard Contractual Clauses (SCCs) — We enter into the European Commission’s approved Standard Contractual Clauses (and the UK Addendum to the SCCs where required) with the relevant service providers. These are legally binding contracts that require the recipient to protect personal data to EU/UK standards.
• Transfer Impact Assessments (TIAs) — Before relying on SCCs, we assess the laws and practices of the destination country (particularly access by public authorities) and implement supplementary technical and organizational measures (such as strong encryption, strict access controls, and data minimization) where necessary to address any identified risks.
• Consent — In limited cases where other safeguards are not available or appropriate, we may rely on your explicit, informed consent for a specific transfer (we will clearly inform you at the time).

You can request a copy of the relevant safeguards (for example, redacted copies of our SCCs with service providers) by emailing legal@lumiskinglow.co.uk. We are committed to transparency about our international data transfers.

Where possible, we prioritize service providers that offer data processing within the UK or EEA, or that provide strong contractual and technical protections for data transferred elsewhere.

---

12. CHILDREN'S PRIVACY

Our Site, App, Products, and marketing are not directed to children, and we do not knowingly collect or solicit personal information from children under the age of 16 (or the applicable age of digital consent in your jurisdiction, which may be 13 in some cases).

If you are under 16, please do not use our Site or App, make purchases, or provide any personal data to us. If we become aware that we have collected personal data from a child under 16 without verifiable parental or guardian consent, we will take prompt steps to delete that information from our systems.

Parents or legal guardians who believe that their child has provided us with personal data, or who wish to review, delete, or restrict the processing of such data, should contact us immediately at legal@lumiskinglow.co.uk. We will respond promptly and take appropriate action in accordance with applicable law (including COPPA in the US and GDPR in the EU/UK).

If we ever introduce features or Products specifically intended for younger users, we will implement additional age-verification and parental consent mechanisms and update this Policy accordingly before any such processing begins.

---

13. LINKS TO THIRD-PARTY WEBSITES AND SERVICES

Our Site may contain links to third-party websites, applications, or services (for example, social media platforms via “Share” buttons, embedded videos, partner sites, or external review platforms). We do not control these third parties and are not responsible for their privacy practices, content, security, or data handling.

This Privacy Policy applies only to personal data collected by or on behalf of LumiSkinGlow. When you leave our Site or click on a third-party link, you should read the privacy policy and terms of the third-party site or service you are visiting. Your interactions with them are governed solely by their own policies.

Social media plugins and widgets: When you interact with a “Like”, “Share”, or similar button from a third-party platform (e.g., Instagram, Pinterest), that platform may collect information about your visit to our Site, including your IP address and browser information, even if you are not logged into the platform. Their use of such data is governed by their privacy policy.

---

14. DO NOT TRACK AND GLOBAL PRIVACY CONTROLS

Some browsers, browser extensions, or mobile operating systems send “Do Not Track” (DNT) signals or implement Global Privacy Control (GPC) / “Do Not Sell or Share My Personal Information” signals.

There is currently no uniform, industry-wide standard for how websites should interpret or respond to DNT signals. Therefore, our Site and App do not automatically change their behavior or disable non-essential cookies, pixels, or analytics in response to a DNT header.

However, we are committed to giving you meaningful control over your data:

• Our cookie consent banner and preference center allow you to make granular choices about analytics and advertising cookies.
• You can use the browser-level cookie controls and the third-party opt-out tools listed in Section 7.
• We honor easy unsubscribe mechanisms for marketing communications.

We will continue to monitor developments in privacy signals, browser standards, and regulatory guidance (including GPC) and will update our practices and this Policy as appropriate to respect user choices.

---

15. AUTOMATED DECISION-MAKING AND PROFILING

We do not currently engage in any solely automated decision-making (including profiling) that produces legal effects concerning you or similarly significantly affects you.

We may use basic segmentation and profiling techniques for legitimate business purposes, such as:

• Showing you product recommendations based on items you have viewed or purchased (using cookie-based or account-based history).
• Analyzing aggregated customer groups to improve our product range and marketing (group-level insights only).
• Measuring the performance of our advertising campaigns.

These activities are based on our legitimate interests or your consent (via cookies) and do not result in legal or similarly significant effects on individuals. You always have the right to object to such processing and to request human review or intervention where applicable.

If we introduce more advanced AI-powered features in the future (for example, personalized skin routine suggestions based on self-reported preferences or Device usage patterns), we will:

• Clearly inform you at the point of collection or use
• Provide a lawful basis (usually consent or legitimate interest with easy opt-out)
• Update this Privacy Policy before implementation
• Offer you the ability to opt out or request human review where required by law

---

16. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect changes in our data processing practices, the introduction of new features or Products, changes in applicable laws or regulatory guidance, or for other legitimate business reasons.

The “Last Updated” date at the top of this Policy indicates the current version. We encourage you to review this Policy periodically.

How We Notify You of Changes

• Material Changes: If we make significant changes that affect your rights or how we process your data in a substantial way (new categories of data collected, new purposes, new categories of recipients, or material changes to your rights), we will notify you by:
  - Email to the address associated with your account or recent orders (where we have a valid email and the change is significant)
  - A prominent notice, banner, or pop-up on our Site for a reasonable period (at least 30 days)
  - An in-App notification or updated Policy link if the change affects App users
• Non-Material / Clarifying Changes: Minor updates, clarifications, or corrections may be made without individual notification. The updated Policy will be posted on our Site with a new “Last Updated” date.

Your continued use of our Site, App, or Products after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. If you do not agree with the changes, you should stop using our services and may exercise your rights under Section 10 (including requesting deletion of your data).

Previous versions of this Policy are available upon request by emailing legal@lumiskinglow.co.uk. We maintain a record of material changes.

---

17. CONTACT US, COMPLAINTS AND SUPERVISORY AUTHORITIES

If you have any questions, concerns, requests, or complaints about this Privacy Policy or our handling of your personal data, please do not hesitate to contact us. We take privacy seriously and will respond promptly and helpfully.

Privacy Compliance Officer / Contact

LumiSkinGlow  
Privacy Compliance Officer  
Email: info@lumiskinglow.co.uk

We aim to acknowledge receipt of privacy-related emails within 48 business hours and to provide a substantive response within one month (or sooner for simple requests).

Complaints

If you are not satisfied with our response, or if you believe we have not handled your personal data in accordance with applicable law, you have the right to lodge a formal complaint with the relevant supervisory authority:

• United Kingdom: Information Commissioner’s Office (ICO) — Make a complaint online at www.ico.org.uk/make-a-complaint or call their helpline.
• Hungary: Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH) — www.naih.hu
• Other EU/EEA countries: The data protection authority in your country of habitual residence, place of work, or where the alleged infringement occurred. A list of all EU supervisory authorities is available at the European Data Protection Board website.

We encourage you to contact us first at legal@lumiskinglow.co.uk before lodging a complaint with a supervisory authority. We are committed to resolving any concerns you may have in a fair, transparent, and timely manner.

---

Thank you for trusting LumiSkinGlow with your personal data. We are committed to earning and maintaining that trust through responsible, transparent, and secure data practices. This Privacy Policy is effective as of June 4, 2026 and applies to all personal data processed by LumiSkinGlow on or after that date.

© 2026 LumiSkinGlow®. All rights reserved.  
LumiSkinGlow® and LED Skin Tech are registered trademarks or trademarks of LumiSkinGlow.

This document is provided for informational purposes and does not constitute legal advice. For specific legal questions, please consult a qualified attorney in your jurisdiction.

---

Generated on June 4, 2026
 

bottom of page