Legal Framework
Operational Directives
01. Privacy Policy
LuminaCoreDynamics, registered at Lyrskovgade 4, 1758 Kobenhavn V, Denmark, is committed to protecting the privacy and security of your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable Danish data protection legislation.
1. Data Controller
The data controller responsible for processing your personal data is LuminaCoreDynamics, located at Lyrskovgade 4, 1758 Kobenhavn V, Denmark. For any data protection inquiries, contact our Data Protection Officer at [email protected].
2. Categories of Personal Data
We may collect and process the following categories of personal data:
- Identity data: name, job title, organization
- Contact data: email address, telephone number, postal address
- Technical data: IP address, browser type, operating system, device identifiers
- Usage data: pages visited, time spent, navigation patterns
- Security assessment data: network configurations, vulnerability reports (processed under contractual obligations)
3. Legal Basis for Processing
We process personal data under the following legal bases as defined in Article 6(1) GDPR:
- Consent: Where you have given explicit consent for specific processing purposes
- Contractual necessity: Processing necessary for the performance of a contract or pre-contractual measures
- Legitimate interests: Processing necessary for our legitimate interests in providing cybersecurity services, subject to your fundamental rights
- Legal obligation: Processing required to comply with EU or Danish law
4. Data Retention
Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected. Security assessment data is retained for the duration of the contractual relationship plus 5 years in accordance with Danish accounting regulations. Client contact data is retained for 3 years following the last communication.
5. International Transfers
Where we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission or adequacy decisions under Article 45 GDPR.
6. Your Rights
Under GDPR, you have the following rights regarding your personal data:
- Right of access (Article 15)
- Right to rectification (Article 16)
- Right to erasure (Article 17)
- Right to restriction of processing (Article 18)
- Right to data portability (Article 20)
- Right to object (Article 21)
- Right not to be subject to automated decision-making (Article 22)
To exercise these rights, contact [email protected]. You also have the right to lodge a complaint with the Danish Data Protection Authority (Datatilsynet).
7. Security Measures
LuminaCoreDynamics implements state-of-the-art technical and organizational measures to protect personal data, including but not limited to: encryption at rest and in transit, multi-factor authentication, regular security audits, and access controls aligned with the principle of least privilege.
03. Refund Policy
LuminaCoreDynamics provides specialized cybersecurity services. Due to the nature of our work, refund policies are structured as follows:
1. Service Commencement
Once a security engagement has commenced and resources have been allocated, partial or full refunds may be subject to deductions based on work completed. Initial consultations and scoping assessments are non-refundable.
2. Milestone-Based Payments
For projects structured around milestones, payments made for completed milestones are non-refundable. Work-in-progress milestones may be eligible for partial refunds calculated proportionally based on completion status.
3. Subscription Services
Monthly subscription services (such as Threat Monitoring & SOC) may be cancelled with 30 days written notice. No refunds are provided for partial billing periods.
4. Dispute Resolution
Refund requests should be submitted in writing to [email protected] within 14 days of service delivery. Disputes will be handled in accordance with Danish consumer protection law and EU Directive 2011/83/EU on consumer rights.
5. Force Majeure
LuminaCoreDynamics shall not be liable for refund obligations where service delivery is prevented by circumstances beyond reasonable control, including but not limited to natural disasters, war, government actions, or cyberattacks targeting our infrastructure.
04. Terms of Service
These Terms of Service ("Terms") govern the provision of cybersecurity services by LuminaCoreDynamics, registered at Lyrskovgade 4, 1758 Kobenhavn V, Denmark ("Provider") to the client ("Client"). By engaging our services, the Client agrees to these Terms.
1. Scope of Services
The Provider delivers cybersecurity services including but not limited to penetration testing, security audits, threat monitoring, incident response, and security consulting. Specific deliverables, timelines, and fees are defined in individual Statements of Work (SOW) or Service Agreements.
2. Client Obligations
The Client shall: provide accurate and complete information necessary for service delivery; grant appropriate access to systems and infrastructure as required; designate authorized personnel for coordination; comply with all applicable laws and regulations.
3. Confidentiality
Both parties agree to maintain strict confidentiality regarding all information exchanged during the engagement. This includes vulnerability findings, security configurations, network architectures, and business processes. Confidentiality obligations survive termination for a period of 5 years.
4. Intellectual Property
All reports, methodologies, and proprietary tools developed by LuminaCoreDynamics remain the intellectual property of the Provider. Client-specific configurations and custom implementations are transferred to the Client upon full payment.
5. Limitation of Liability
LuminaCoreDynamics shall not be liable for indirect, consequential, or incidental damages. Total liability shall not exceed the total fees paid for the specific service giving rise to the claim. The Provider does not guarantee the prevention of all security incidents.
6. Governing Law
These Terms are governed by Danish law. Any disputes shall be resolved through the Danish courts, with the Copenhagen City Court as the venue of first instance.
7. Data Processing Agreement
Where the Provider processes personal data on behalf of the Client, a separate Data Processing Agreement (DPA) in compliance with Article 28 GDPR shall be executed prior to service commencement.