Last Updated: 2025-11-04
Controller: LumaDock Ltd (trading as “LumaDock”), company no. 15844051, registered office at DNS House, 382 Kenton Road, Harrow, Greater London, United Kingdom, HA3 8DP, and business address at 13 Hanover Square, Mayfair, London W1S 1HN, United Kingdom.
This Privacy Policy & Data Processing Agreement (“Policy” / “DPA”) governs how LumaDock collects, processes, stores, transfers, and protects personal data when providing VPS, cloud hosting, networking, and related Services. LumaDock fully complies with the UK GDPR, EU GDPR, and the Data Protection Act 2018.
1. Definitions
- LumaDock: A brand operated by LumaDock Ltd.
- Personal Data: Any information identifying or relating to an identifiable natural person.
- Customer Data: Any Personal Data or content hosted, transmitted, or stored using LumaDock Services.
- Controller: The Customer for Customer Data; LumaDock for its own business operations.
- Processor: LumaDock when processing Customer Data for infrastructure delivery.
- Sub-processor: Third parties engaged to provide infrastructure, payments, security, or operational support.
2. Scope & Roles
LumaDock may process Personal Data as:
- Controller — for account management, billing, fraud prevention, security, and website operations.
- Processor — for Customer Data stored or transmitted on LumaDock VPS or hosting infrastructure.
3. Categories of Data Collected
3.1 Information You Provide
- Name, address, phone, email.
- Billing details, VAT information, payment confirmations.
- Support tickets, logs, console outputs you send, communications.
- Verification documentation when required for fraud or abuse mitigation.
3.2 Information Collected Automatically
- IP addresses, device identifiers, browser data, OS signatures.
- Server-side logs, security logs, firewall logs, and networking metadata.
- Access timestamps, authentication logs, API activity.
- Cookie-based session and analytics data (see Cookie Policy).
3.3 Customer Data Hosted via VPS/Cloud
Customer Data may include websites, applications, databases, backups, configuration files, or any content uploaded to a VPS. LumaDock does not access Customer Data except:
- as strictly necessary to deliver support;
- to investigate abuse or security incidents;
- where required by applicable law.
4. Purposes of Processing
- Account creation, provisioning, and delivery of VPS and cloud infrastructure.
- Performance monitoring, optimisation, and security hardening.
- Fraud detection, abuse mitigation, and IP reputation protection.
- Billing, invoicing, taxation, and financial compliance.
- Communications regarding service status, outages, updates, or support.
- Legal compliance and enforcement of Terms of Service & AUP.
5. Legal Bases
- Contractual necessity — operating your VPS, network resources, and account.
- Legitimate interests — network monitoring, anti-abuse systems, marketing to existing customers, fraud prevention.
- Legal obligations — accounting, law enforcement requests, retention duties.
- Consent — where explicitly required (e.g., marketing where no prior relationship exists).
6. Sub-processors
LumaDock uses secure Sub-processors (datacenters in London, Frankfurt, Paris, Amsterdam, Bucharest, Helsinki; payment processors; identity services; analytics systems). All Sub-processors operate under GDPR-compliant agreements. A list is available on request.
7. International Data Transfers
Where data must leave the UK/EU, LumaDock ensures adequate protections via:
- UK Standard Contractual Clauses;
- EU Standard Contractual Clauses;
- Equivalent safeguards as required by the UK GDPR/EU GDPR.
8. Security Measures
- Isolation of customer instances and networks.
- Strict access controls and MFA for sensitive systems.
- 24/7 network monitoring and DDoS mitigation.
- Encrypted storage where applicable and encrypted transport for all control-plane communications.
- Regular patching and vulnerability scanning.
9. Abuse & Security Events
If a Security Incident involving Customer Data occurs, LumaDock will notify affected Customers promptly with details and remediation guidance. LumaDock may temporarily disable or isolate affected systems to protect platform integrity.
10. Data Retention
- Customer Data is deleted after service termination unless legally required to be retained.
- Backups persist only through their normal retention schedule.
- Account and billing records must be stored for statutory periods (typically 6 years).
11. Cookies & Tracking
LumaDock uses essential cookies, analytics cookies (where lawful), and session cookies. Details are provided in the Cookie Policy. Consent banners are displayed where required by law.
12. Marketing Communications
LumaDock may contact customers regarding service updates, relevant products, and promotions. Opt-out is always available.
13. Data Subject Rights
You may exercise all rights under the UK GDPR/EU GDPR, including:
- Access
- Rectification
- Erasure
- Objection (including to marketing)
- Restriction
- Data portability
- Withdrawal of consent
14. Required Disclosures
LumaDock may disclose Personal Data where necessary to:
- Comply with law or court orders;
- Investigate abuse, fraud, or network threats;
- Enforce Terms, AUP, or other agreements.
15. Children
LumaDock does not knowingly allow the use of Services by individuals under 18 and does not knowingly process their data.
16. Policy Updates
This Policy may be modified from time to time. Continued use of the Services after a revision constitutes acceptance of the updated Policy.
17. Contact
Data Protection Inquiries:
LumaDock Ltd (trading as LumaDock)
13 Hanover Square, Mayfair, London W1S 1HN, United Kingdom
Email: [email protected]
Phone: +44 20 4578 1002

