Back to LumiGRC
Privacy Notice & Policy
Digital Personal Data Protection (DPDP) Act 2023 & ISO 27701 Compliant

Privacy Notice & Data Protection Policy

This Privacy Notice is issued by Lumiverse Solutions Private Limited (Data Fiduciary) in strict compliance with Section 5 and Section 6 of the Indian Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, and international benchmarks including GDPR and ISO/IEC 27701:2019.

Effective Date: August 24, 2026Entity: Lumiverse Solutions Pvt. Ltd.Grievance Desk: Data Protection & Legal Compliance Cell
Section 1

1. Overview & Data Fiduciary Identity

This Privacy Notice governs the collection, processing, storage, and transfer of digital personal data by Lumiverse Solutions Private Limited (“Lumiverse”, “LumiGRC”, “we”, “our”, or “us”), acting in its capacity as a Data Fiduciary under Section 2(i) of the Digital Personal Data Protection Act, 2023 (DPDP Act).

LumiGRC is an enterprise Governance, Risk, and Compliance (GRC) software platform designed to assist organizations in orchestrating audits, managing evidence, and establishing continuous compliance against 111+ global frameworks including ISO 27001, SOC 2, HIPAA, GDPR, NIST CSF, and the Indian DPDP Act.

Applicability: This Notice applies to all individuals (“Data Principals”) who interact with our public website, request platform demonstrations, register enterprise auditor/client accounts, or upload organizational compliance records to the LumiGRC platform.
Section 2

2. Statutory Rights of the Data Principal (DPDP Act 2023)

Under Chapter III of the DPDP Act 2023, you as a Data Principal hold unambiguous, legally enforceable rights regarding your personal data:

Right to Access & Summary (Sec. 11)

You have the right to obtain a clear summary of all digital personal data being processed by LumiGRC and the identities of all other Data Processors with whom your data has been shared.

Right to Correction & Erasure (Sec. 12)

You can request the correction of inaccurate or misleading data, the completion of incomplete data, and the total erasure of personal data that is no longer required for the specified purpose.

Right of Grievance Redressal (Sec. 13)

You are entitled to file a grievance with our designated Grievance Redressal Officer. If unresolved within 30 days, you have the statutory right to escalate directly to the Data Protection Board of India (DPBI).

Right to Nominate (Sec. 14)

You have the legal right to nominate any individual to exercise your data principal rights in the unfortunate event of death or incapacity.

Section 3

3. Categories of Personal Data Collected

We adhere strictly to the principle of Data Minimization (Section 6(1)). We collect only data strictly necessary to deliver enterprise compliance workflows:

A. Registration & Contact Credentials

First Name, Last Name, Work Email Address, Business Phone Number, Job Title, Organization Name, Industry Sector, and Country.

B. Authentication & Security Identifiers

Bcrypt-hashed passwords, Multi-Factor Authentication (TOTP) seed secrets, one-time recovery hashes, IP addresses, browser user-agents, session tokens, and timestamped login logs.

C. Compliance Evidence & Audit Workpapers

Documents uploaded by auditors and enterprise clients (policy documents, architecture diagrams, access review logs, certificate records). Every uploaded file is stamped with an immutable SHA-256 digital forensic integrity hash to prevent tampering.

D. Availability & Scheduling Telemetry

Calendar synchronization feed tokens, demo meeting slot bookings (Google Meet / Jitsi), and self-declared attendance/absence timeframes used strictly for automated round-robin meeting allocation.

Section 5

5. Technical & Organizational Security Safeguards

In compliance with Section 8(5) of the DPDP Act and ISO/IEC 27001:2022 standards, LumiGRC implements state-of-the-art security controls:

AES-256 & TLS 1.3 Encryption: All database fields and file stores are encrypted at rest with AES-256 and in transit via HTTPS/TLS 1.3.
Mandatory Staff 2FA: Multi-factor authentication is strictly enforced for all internal roles (Super Admin, Sales, Auditors).
Forensic SHA-256 Hashing: Uploaded audit evidence is cryptographically verified to detect unauthorized modifications.
Principle of Least Privilege: Strict Role-Based Access Control (RBAC) with quarterly access review certifications.
Section 6

6. Data Storage & Cross-Border Transfers

In compliance with Section 16 of the DPDP Act 2023, personal data collected from Indian Data Principals is primarily hosted within sovereign data centers located in the Republic of India.

Any international data transfer to cloud infrastructure or enterprise sub-processors conforms strictly to Central Government adequacy notifications, Standard Contractual Clauses (SCCs), and binding Data Processing Addendums (DPAs).

Section 7

7. Retention & Data Eradication Policy

In compliance with Section 8(7) of the DPDP Act, we retain personal data only for as long as necessary to fulfill the specified compliance purposes:

  • Demo Prospects: Retained for 90 days following inquiry or until consent is revoked.
  • Active Enterprise Subscriptions: Retained for the active duration of the SaaS agreement.
  • Post-Termination Eradication: Upon service termination, all customer evidence and personal data is permanently deleted from primary databases within 30 days and purged from secondary backups within 90 days.
Section 8

8. Grievance Redressal & Compliance Officer

In accordance with Section 6(2) and Rule 14 of the DPDP Rules, Lumiverse Solutions maintains a dedicated Grievance Redressal and Compliance Cell:

Data Fiduciary

Lumiverse Solutions Private Limited

Compliance Division

Data Protection & Privacy Cell

Redressal Mechanism

Official LumiGRC Support & DSAR Portal

Resolution Timeline

Within 7 to 14 business days

Escalation to Statutory Authority: If your grievance remains unresolved after 30 days, you are legally entitled to file an appeal with the Data Protection Board of India (DPBI) at https://dpbi.gov.in.

Need an offline copy for your vendor compliance review?

Download the complete DPDP Act & GDPR compliant Privacy Notice in print-ready PDF format.