Privacy Policy Overview
myluxiora takes a practical, risk-focused approach to handling personal data collected through our website and client engagements. This policy explains what information we collect, why we use it, and how we protect it. We collect only data necessary to provide legal services to IT companies, manage engagements, and operate the website. Personal data practices include secure storage, role-based access for authorized staff, and retention only for as long as needed for legitimate business and legal purposes. We describe user rights, mechanisms to exercise those rights, and the steps available if you have concerns about how your data is handled. This policy applies to contacts, clients, visitors to myluxiora.pro and any affiliated services delivered from our office in Nonthaburi, Thailand.
Definitions
This section defines key terms used in the policy to ensure clarity about what we collect and process.
- Personal data means any information that identifies or can be used to identify a natural person, such as name, email address, phone number, business registration identifiers and technical identifiers linked to an individual.
- Processing refers to any operation or set of operations performed on personal data, including collection, recording, organization, storage, modification, retrieval, consultation, use, disclosure, or erasure.
- User means any visitor to the website, prospective client, current client, or third party whose personal data we process in connection with providing legal services.
- Service refers to legal advice, document drafting, compliance reviews, workshops and other professional services provided by myluxiora to clients in the IT sector.
- Cookies are small data files placed on a device to remember preferences, support session functionality and collect analytics to improve site performance and user experience.
Data Collection
We collect data directly from users, automatically via website technologies, and from third parties where necessary to deliver services and comply with legal obligations.
Data You Provide
Information supplied when you register, request services, communicate with us, or otherwise engage with myluxiora.
- Identification and contact details: name, job title, company name, business ID and email address.
- Communications and engagement records: messages, contract instructions, and quoted materials.
- Billing and transaction details necessary to process payments and maintain client accounts.
- Technical and project information you provide for legal work, such as code descriptions, system architecture summaries and service-level terms.
- Consents and preferences regarding marketing and communications.
- Any other information you choose to submit when using our services.
Automatically Collected Data
We use standard website technologies and analytics to collect technical information that helps secure and improve our services.
- Device and browser details such as IP address, user agent and screen resolution.
- Usage data including pages visited, session duration and referral sources.
- Cookies and similar identifiers used to support authentication, preferences and analytics.
- Performance and error logs to diagnose issues and improve platform reliability.
- Geolocation inferred from IP for basic regional routing and compliance filtering.
- Security-related telemetry to detect abuse and protect client data.
Data from Third Parties
We may receive information from partners, service providers and public sources to verify identity, enrich records and perform services.
- Identity verification providers and business registries for client onboarding.
- Payment processors for invoicing and transaction records.
- Analytics and hosting providers that process aggregated technical data.
Purposes of Processing
We use personal data only for specified, legitimate purposes necessary to operate the business and provide legal services to IT clients.
- Delivering legal services, drafting documents and managing client relationships.
- Managing billing, payments and accounting obligations.
- Communicating service updates, appointments and case progress.
- Ensuring compliance with legal and regulatory obligations in Thailand and applicable jurisdictions.
- Protecting our systems and client data from misuse, fraud and security incidents.
- Improving website performance, content and user experience through analytics.
- Defending or asserting legal rights in disputes and contribute.
- Maintaining records necessary for corporate governance and regulatory reporting.
Legal Bases for Processing
When applicable, we rely on appropriate legal bases for processing personal data, including contractual necessity and legitimate interests.
- Performance of a contract: processing required to provide legal services and manage engagements.
- Legal compliance: processing necessary to meet statutory or regulatory obligations.
- Legitimate interests: processing for security, fraud prevention, and business administration when balanced with data subject rights.
- Consent: where required for marketing communications or non-essential processing, we seek clear consent which can be withdrawn.
Rights of Data Subjects
Depending on local law and your jurisdiction, you may have rights concerning your personal data. We outline common rights and how to exercise them.
- Access: request confirmation of whether we process your data and obtain a copy of the data we hold about you.
- Rectification: request correction of inaccurate or incomplete personal data.
- Erasure: request deletion of personal data where there is no lawful reason to retain it.
- Restriction: request restriction of processing in specific circumstances.
- Portability: request transfer of your data to another service provider where feasible.
- Objection: object to processing based on legitimate interests where applicable.
Cookies and Similar Technologies
We use cookies to power site functionality, maintain sessions and collect analytics to improve user experience.
Types include essential cookies for site operation, performance cookies for analytics, and preference cookies for saved settings.
Essential: required for navigation and security. Analytics: aggregate usage insights. Preferences: remember language and display choices.
You can manage cookie preferences via your browser settings or the cookie banner on our site. Disabling analytics cookies may affect site improvement efforts.
Read our full cookie policy on the website.
Data Sharing
We share personal data only when necessary to deliver services, comply with law, or with trusted service providers under confidentiality terms.
- Service providers who host data, run analytics, or support payment processing under contractual security obligations.
- Professional advisers such as auditors or external counsel when required for legal matters.
- Authorities or courts when compelled by law or to respond to lawful requests.
- Potential acquirers or partners during any business transaction, subject to confidentiality protections.
- Third parties with your explicit consent to share specified information.
- Aggregated or anonymized data that cannot reasonably identify an individual may be shared for research or product improvement.
International Data Transfers
When personal data is transferred outside Thailand, we apply appropriate safeguards such as contractual clauses, due diligence of recipients and security controls to maintain protection consistent with applicable law.
Safeguards may include standard contractual clauses, encryption in transit and at rest, access controls and supplier audits to ensure adequate protection.
Data Retention
We retain personal data only as long as necessary for the purposes described, or to satisfy legal, tax or audit obligations.
Client account information is retained for the duration of the engagement and for a period of up to seven years thereafter for recordkeeping and compliance with applicable Thai regulations, unless a different retention period is required by law.
Communications and case files are kept for the duration of the matter and for a reasonable period thereafter to protect legal interests and comply with professional standards, typically up to seven years.
Technical logs and backup copies are retained for operational and security purposes for up to two years, with aggregated logs retained longer only in anonymized form.
We retain personal data only as long as necessary to provide legal services to IT clients, comply with regulatory obligations, or resolve disputes. Retention periods vary by data type: client engagement files and contracts — up to 7 years for tax and regulatory requirements; billing and payment records — up to 7 years; communication records — up to 3 years after case closure unless needed longer for legal purposes. When data is no longer required, we will securely delete or anonymize it in a manner appropriate to the data sensitivity.
Data security and protection
myluxiora applies industry-standard technical and organizational safeguards to protect personal information against unauthorized access, disclosure, alteration, or destruction. Our security approach is tailored to legal practice needs for the IT sector, balancing access for legal work with strict controls to limit exposure. We regularly review security measures and update them in line with evolving threats and best practices.
- Encrypted storage for client files and backups using proven encryption standards.
- Access controls and role-based permissions to ensure only authorized personnel can view sensitive records.
- Regular security assessments, software patching, and secure communication channels for client correspondence.
Your data rights
As a data subject, you have rights over your personal information. You can exercise these rights to inspect, correct, restrict, port, or request deletion of personal data held by myluxiora where applicable under Thai law and relevant regulations.
- Right to access: request a copy of personal data we hold about you.
- Right to rectification: ask us to correct inaccurate or incomplete information.
- Right to deletion: request removal of data when no longer necessary for legal obligations.
- Right to restriction: request limits on how we process your data in specific circumstances.
- Right to data portability: request a structured, machine-readable copy of data we process for you.
- Right to object: object to certain processing activities, such as direct marketing.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.
- Right to lodge a complaint: contact local authorities if you believe your rights have been violated.
How to make a rights request
To exercise any data subject right, send a request to our privacy contact with details of the requested action and proof of identity. We may need additional information to verify your identity and to locate relevant records. Reasonable fees may apply only where permitted by law.
We aim to respond to verified requests within 30 calendar days. If your request is complex or we require more time, we will inform you and provide an expected response timeframe, not exceeding an additional 30 days unless otherwise permitted by law.
Marketing communications
myluxiora may send service updates, legal bulletins, and IT sector advisories to clients and contacts who opt in. Communications are designed to provide practical value to IT businesses, including regulatory updates, contract templates, and risk management tips.
You can opt out from marketing emails at any time using the unsubscribe link included in each message or by contacting our privacy team. Opting out will not affect transactional messages about active matters.
Children's privacy
Our services are directed at businesses and professionals. We do not knowingly collect personal information from children under the age of 13. If we discover that we have collected such information inadvertently, we will take steps to delete it promptly upon verification.
External links and third parties
Service-related content may include links to third-party resources. myluxiora is not responsible for third-party privacy practices or content. Before sharing personal information with external sites or providers, please review their privacy policies.
Changes to this privacy policy
We may update this policy to reflect legal, operational, or service changes. Material changes will be posted on myluxiora.pro with an updated effective date. Continued use of our services after changes indicates acceptance of the revised policy.
Contact for privacy matters
For privacy inquiries, requests, or concerns, contact myluxiora at: 70/5, Soi Nonthaburi 46, Tha Sai Sub District, Amphoe Mueang Nonthaburi District, Nonthaburi Province 11000, Thailand; Phone: +66925558493; Business ID: 4970119256937; Email: [email protected].
- +66925558493
- [email protected]
- 70/5, Soi Nonthaburi 46, Tha Sai Sub District, Amphoe Mueang Nonthaburi District, Nonthaburi Province 11000, Thailand