1. Overview & Data Fiduciary Identity
This Privacy Notice governs the collection, processing, storage, and transfer of digital personal data by Lumiverse Solutions Private Limited (“Lumiverse”, “LumiGRC”, “we”, “our”, or “us”), acting in its capacity as a Data Fiduciary under Section 2(i) of the Digital Personal Data Protection Act, 2023 (DPDP Act).
LumiGRC is an enterprise Governance, Risk, and Compliance (GRC) software platform designed to assist organizations in orchestrating audits, managing evidence, and establishing continuous compliance against 111+ global frameworks including ISO 27001, SOC 2, HIPAA, GDPR, NIST CSF, and the Indian DPDP Act.
2. Statutory Rights of the Data Principal (DPDP Act 2023)
Under Chapter III of the DPDP Act 2023, you as a Data Principal hold unambiguous, legally enforceable rights regarding your personal data:
You have the right to obtain a clear summary of all digital personal data being processed by LumiGRC and the identities of all other Data Processors with whom your data has been shared.
You can request the correction of inaccurate or misleading data, the completion of incomplete data, and the total erasure of personal data that is no longer required for the specified purpose.
You are entitled to file a grievance with our designated Grievance Redressal Officer. If unresolved within 30 days, you have the statutory right to escalate directly to the Data Protection Board of India (DPBI).
You have the legal right to nominate any individual to exercise your data principal rights in the unfortunate event of death or incapacity.
3. Categories of Personal Data Collected
We adhere strictly to the principle of Data Minimization (Section 6(1)). We collect only data strictly necessary to deliver enterprise compliance workflows:
A. Registration & Contact Credentials
First Name, Last Name, Work Email Address, Business Phone Number, Job Title, Organization Name, Industry Sector, and Country.
B. Authentication & Security Identifiers
Bcrypt-hashed passwords, Multi-Factor Authentication (TOTP) seed secrets, one-time recovery hashes, IP addresses, browser user-agents, session tokens, and timestamped login logs.
C. Compliance Evidence & Audit Workpapers
Documents uploaded by auditors and enterprise clients (policy documents, architecture diagrams, access review logs, certificate records). Every uploaded file is stamped with an immutable SHA-256 digital forensic integrity hash to prevent tampering.
D. Availability & Scheduling Telemetry
Calendar synchronization feed tokens, demo meeting slot bookings (Google Meet / Jitsi), and self-declared attendance/absence timeframes used strictly for automated round-robin meeting allocation.
4. Specified Purpose & Legal Grounds for Processing
Under Section 4 and Section 6 of the DPDP Act, personal data is processed solely under the following lawful grounds:
- Explicit Consent (Section 6(1)): Given freely, specifically, and unambiguously when submitting a demo request or enrolling in platform services.
- Contractual Performance: Processing required to establish role-based access control, assign human auditors, generate audit reports, and enforce mandatory security measures.
- Legitimate Uses (Section 7): Generating audit logs required under ISO 27001 / SOC 2 certification rules and detecting unauthorized cyber-security intrusions.
5. Technical & Organizational Security Safeguards
In compliance with Section 8(5) of the DPDP Act and ISO/IEC 27001:2022 standards, LumiGRC implements state-of-the-art security controls:
6. Data Storage & Cross-Border Transfers
In compliance with Section 16 of the DPDP Act 2023, personal data collected from Indian Data Principals is primarily hosted within sovereign data centers located in the Republic of India.
Any international data transfer to cloud infrastructure or enterprise sub-processors conforms strictly to Central Government adequacy notifications, Standard Contractual Clauses (SCCs), and binding Data Processing Addendums (DPAs).
7. Retention & Data Eradication Policy
In compliance with Section 8(7) of the DPDP Act, we retain personal data only for as long as necessary to fulfill the specified compliance purposes:
- Demo Prospects: Retained for 90 days following inquiry or until consent is revoked.
- Active Enterprise Subscriptions: Retained for the active duration of the SaaS agreement.
- Post-Termination Eradication: Upon service termination, all customer evidence and personal data is permanently deleted from primary databases within 30 days and purged from secondary backups within 90 days.
8. Grievance Redressal & Compliance Officer
In accordance with Section 6(2) and Rule 14 of the DPDP Rules, Lumiverse Solutions maintains a dedicated Grievance Redressal and Compliance Cell:
Lumiverse Solutions Private Limited
Data Protection & Privacy Cell
Official LumiGRC Support & DSAR Portal
Within 7 to 14 business days
Escalation to Statutory Authority: If your grievance remains unresolved after 30 days, you are legally entitled to file an appeal with the Data Protection Board of India (DPBI) at https://dpbi.gov.in.
Need an offline copy for your vendor compliance review?
Download the complete DPDP Act & GDPR compliant Privacy Notice in print-ready PDF format.