Website Privacy Policy
Published: 2024-10-17
Who is the Data Controller?
The Data Controller is Luminatens, the developer of the Luminatens app. For any information regarding this Website Privacy Policy, you can contact us via our official email address: [Luminatens@mail.com]. The Data Protection Officer (DPO) is the data controller and can be contacted at the same email address.
What Data is Collected and How?
We limit data collection to what is strictly necessary and collect the following personal data from website users:
- Contact data: Name, surname, email, and any other information voluntarily provided through the contact form.
- Navigation and performance data: IP address (anonymized by Vercel), approximate geolocation data (country derived from IP), information about the device used to access the website, browser type, operating system, pages visited, time of visit, and web performance metrics (like Core Web Vitals). This data is collected through Google Analytics, Microsoft Clarity, Vercel Analytics, and Vercel Speed Insights.
- Behavioral data (collected only with explicit consent): Interactions with the website, such as clicks, time spent on pages, mouse movements, and other interactions. This data is collected through Microsoft Clarity.
This data is collected through:
- Contact forms completed by users.
- Analytics and performance monitoring tools (Google Analytics, Microsoft Clarity, Vercel Analytics, Vercel Speed Insights) to improve user experience and optimize our website (collected only with explicit consent for the 'Statistics' category via the cookie banner).
- Cookies and similar tracking technologies (see our Cookie Policy for more details).
What is the Legal Basis for Collection?
The collection of personal data is based on the following legal bases:
- User consent: Explicitly requested for certain processing activities, such as behavioral data analysis through Microsoft Clarity, statistical analysis via Google Analytics and Vercel Analytics/Speed Insights, and the use of non-technical cookies. Consent for cookies is obtained through the cookie banner upon first access to the website for the appropriate categories (e.g., 'Statistics'). By submitting a comment on our blog, after being informed by this policy and a notice near the comment form, you acknowledge and agree that the name you provide and the content of your comment will be publicly displayed.
- Legitimate Interest of the Controller: To respond to inquiries submitted through the contact form; to ensure the security and integrity of our website; for comment moderation, spam prevention, and abuse detection (which includes processing IP addresses and utilizing Google reCAPTCHA on contact and comment forms); and for aggregated and anonymous analysis of website performance and usage (via Vercel Analytics/Speed Insights and Google Analytics) and the blog. We have performed a balancing test and believe that these processing activities are necessary for our legitimate interests and that these interests are not overridden by your data protection rights. Specifically, the use of reCAPTCHA and IP address processing for comments and contact forms is essential to protect our services from automated abuse and spam, ensuring a safe and functional environment for all users.
For What Specific Purposes is Data Collected?
The collected data is used for the following purposes:
- To provide and manage the website and its content.
- To improve the user experience on the website.
- To analyze user behavior and website performance (via Google Analytics, Microsoft Clarity, Vercel Analytics, and Vercel Speed Insights) to optimize our services, understand how users interact with the website, and identify technical issues.
- To respond to support requests, information inquiries, or other communications submitted through the contact form.
- To monitor and ensure the security of our systems.
- To collect aggregated and anonymous statistics on website usage and performance.
From Which Categories of Sources Do We Collect Personal Information?
Personal information is collected:
- Directly from users through the website (e.g., contact forms, blog comment forms).
- Automatically through analytics and performance monitoring tools (Google Analytics, Microsoft Clarity, Vercel Analytics, Vercel Speed Insights) and tracking technologies (cookies).
Which Third Parties Will Have Access to the Information?
We share personal data (or anonymized/aggregated data) with the following third parties, only when necessary for the described purposes and based on the consent obtained:
- Google (for Google Analytics and Google reCAPTCHA): Used for website usage data analysis and for spam/bot protection on our forms (contact and comments).
- Microsoft Clarity: Used for behavioral analysis of users on the website and blog.
- Vercel Inc.: Provider of Vercel Analytics and Speed Insights for website traffic analysis and performance monitoring.
We ensure that all third-party data processors, including Google (for Analytics and reCAPTCHA), Microsoft, and Vercel, are contractually bound by Data Processing Agreements (DPAs) compliant with GDPR or provide equivalent safeguards. These agreements ensure that data processing is carried out in accordance with GDPR requirements, providing adequate safeguards for your personal data.
Do We Transfer Data Abroad and, if so, What Measures Have Been Taken to Ensure Safe and Compliant Transfers?
What Are the Rights of Users?
Users have the right to:
- Access their personal data.
- Rectify or update their personal data.
- Delete their personal data.
- Limit the processing of their personal data.
- Request data portability.
- Object to processing for legitimate reasons.
- Withdraw consent at any time (e.g., by changing preferences via the cookie banner or cookie icon). Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
- Lodge a complaint with a supervisory authority.
To exercise these rights, users can contact us at the email address [Luminatens@mail.com]. We will respond to requests within one month, as required by the GDPR. Users also have the right to lodge a complaint with a supervisory authority.
How Will We Notify Users and Visitors of Changes or Updates to the Privacy Policy?
Any changes to this Website Privacy Policy will be published on this page with a revised update date. We recommend that you periodically review this page to stay updated on how we handle data.
What is the Effective Date of the Privacy Policy?
This Website Privacy Policy takes effect on 2024-10-17.