Home/Privacy Policy

Privacy Policy

Last Updated: March 25, 2026Effective: March 25, 2026Version: 1.0Applicable: Worldwide
This Privacy Policy is designed to comply with GDPR (EU), CCPA (California), PIPEDA (Canada), LGPD (Brazil), POPIA (South Africa), PDPA (Singapore/Thailand), NDPR (Nigeria), and the Australian Privacy Act. We use GDPR as our baseline because it sets one of the highest privacy standards globally.

1. Who We Are

ANDLAH is a digital infrastructure and business automation company operated by Luminoxa Research Labs. We build websites, automation systems, CRM pipelines, branding, digital marketing solutions, and cloud infrastructure for businesses worldwide.

Data Controller: Luminoxa Research Labs (ANDLAH)

Website: andlah.com

Client Portal: app.andlah.com

Privacy Contact: privacy@andlah.com

2. Scope

This Privacy Policy applies to all personal data collected through:

  • The ANDLAH marketing website (andlah.com)
  • The ANDLAH client portal (app.andlah.com)
  • Contact forms, newsletter subscriptions, and enquiry submissions
  • Email communications with ANDLAH
  • Services delivered by ANDLAH to clients

It does not apply to third-party websites linked from our pages.

4. Data We Collect

4.1 Contact Form Submissions

  • Full name, email address, phone number
  • Company name and industry
  • Services of interest, budget range, and timeline
  • Description of your business challenge

4.2 Newsletter Subscriptions

  • Email address
  • Subscription source and date

4.3 Client Portal (app.andlah.com)

  • Account credentials (email, hashed password)
  • Company and billing information
  • Project communications and documents
  • Activity and access logs

4.4 Automatically Collected Data

  • IP address, browser type, operating system
  • Pages visited, time on site, referring URL
  • Cookie identifiers
  • Device and screen information

5. How We Use Your Data

Service Delivery: To respond to enquiries, manage projects, and deliver contracted services.
Communication: To send project updates, proposals, invoices, and support responses.
Newsletter: To send business insights on automation, growth, and digital systems (with your consent).
Platform Security: To detect fraud, abuse, and unauthorised access.
Analytics & Improvement: To understand how our website is used and improve user experience.
Legal Compliance: To comply with applicable laws, regulations, and lawful requests.

We do not sell your personal data. We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.

6. Data Sharing & Third Parties

We do not sell, rent, or trade your personal data. We share data only in these limited circumstances:

6.1 Service Providers (Sub-processors)

ProviderPurposeLocation
SupabaseDatabase hosting & authenticationEU / US (AWS)
VercelWebsite hosting & deploymentGlobal (Edge)
OpenAIAI chatbot responsesUS
Google AnalyticsWebsite usage analyticsUS
Microsoft ClarityUser behaviour analyticsUS

6.2 Legal Disclosure

We may disclose your data to law enforcement or regulators where required by applicable law.

6.3 Business Transfer

In the event of a merger or acquisition, your data may be transferred. We will notify affected users before data becomes subject to a different privacy policy.

7. International Data Transfers

ANDLAH operates globally. Your data may be processed in countries outside your own, including the United States and European Union.

For transfers from the EU/UK, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where applicable

All sub-processors are contractually bound to maintain equivalent data protection standards.

8. Data Retention

Data TypeRetention Period
Contact form submissions3 years from submission date
Newsletter subscriber emailUntil unsubscribed + 30 days
Active client portal accountsDuration of contract + 2 years
Deleted portal accountsPurged within 90 days of deletion request
Website analytics data26 months (Google Analytics default)
Security & access logs12 months
Billing & financial records7 years (legal requirement)

9. Security

We implement industry-standard technical and organisational measures to protect your personal data:

  • Encryption at rest (AES-256) and in transit (TLS 1.3)
  • Row-Level Security (RLS) on all database tables
  • Role-based access controls (RBAC)
  • Hashed passwords that are never stored in plain text
  • Regular security reviews and dependency updates
  • Access logging and anomaly monitoring

No method of transmission over the internet is 100% secure. If you believe your data has been compromised, contact privacy@andlah.com immediately.

10. Cookies & Tracking

10.1 Cookies We Use

CookieTypePurpose
Session cookiesEssentialMaintain your login session on the portal
_ga, _gidAnalyticsGoogle Analytics helps us understand site usage
Clarity cookiesAnalyticsMicrosoft Clarity helps us review behaviour patterns and heatmaps
Supabase authEssentialAuthentication token for portal access

10.2 Managing Cookies

You can manage your cookie preferences at any time using our panel. See our full Cookie Policy for details on every cookie we use, duration, and opt-out options.

11. Your Rights

We honour the following rights globally, regardless of jurisdiction:

Right to Access: Request a copy of all personal data we hold about you.
Right to Rectification: Request correction of inaccurate or incomplete data.
Right to Erasure: Request deletion of your personal data ('right to be forgotten'), subject to legal retention requirements.
Right to Data Portability: Receive your data in a structured, machine-readable format.
Right to Restrict Processing: Ask us to pause processing your data in certain circumstances.
Right to Object: Object to processing based on legitimate interests or for direct marketing.
Right to Withdraw Consent: Withdraw consent for newsletter or marketing communications at any time.
Right to Non-Discrimination: (CCPA) We will not discriminate against you for exercising your privacy rights.
Right to Lodge a Complaint: Complain to your local supervisory authority (see Section 15).

To Exercise Your Rights

Email privacy@andlah.com. We respond within 30 days. We may verify your identity before processing the request.

12. Children's Data

Our services are intended for businesses and professionals. We do not knowingly collect personal data from individuals under the age of 16 (or 13 in the United States). Contact privacy@andlah.com if you believe we have inadvertently collected data from a minor.

13. Data Breach Notification

In the event of a personal data breach, ANDLAH will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware (GDPR requirement)
  • Notify affected individuals without undue delay where the breach creates high risk to their rights
  • Document the breach, its effects, and remedial actions taken

14. Changes to This Policy

When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page
  • Notify newsletter subscribers via email at least 30 days before changes take effect
  • Post a prominent notice on our website for significant changes

Continued use after the effective date constitutes acceptance of the updated policy.

15. Contact & Complaints

For all privacy-related enquiries, data subject requests, or complaints:

privacy@andlah.com

Supervisory Authorities

You have the right to lodge a complaint with your local data protection authority:

European Union

Your national Data Protection Authority (DPA)

United Kingdom

Information Commissioner's Office (ICO), ico.org.uk

United States (California)

California Attorney General, oag.ca.gov

Canada

Office of the Privacy Commissioner, priv.gc.ca

Australia

Office of the Australian Information Commissioner, oaic.gov.au

South Africa

Information Regulator, inforegulator.org.za

Nigeria

Nigeria Data Protection Commission, ndpc.gov.ng

Brazil

Autoridade Nacional de Protecao de Dados, gov.br/anpd