Privacy Policy
1. Who We Are
ANDLAH is a digital infrastructure and business automation company operated by Luminoxa Research Labs. We build websites, automation systems, CRM pipelines, branding, digital marketing solutions, and cloud infrastructure for businesses worldwide.
Data Controller: Luminoxa Research Labs (ANDLAH)
Website: andlah.com
Client Portal: app.andlah.com
Privacy Contact: privacy@andlah.com
2. Scope
This Privacy Policy applies to all personal data collected through:
- The ANDLAH marketing website (andlah.com)
- The ANDLAH client portal (app.andlah.com)
- Contact forms, newsletter subscriptions, and enquiry submissions
- Email communications with ANDLAH
- Services delivered by ANDLAH to clients
It does not apply to third-party websites linked from our pages.
3. Legal Basis for Processing (GDPR Article 6)
Where GDPR applies, we process your personal data under the following legal bases:
Contract Fulfilment (Art. 6(1)(b))
Processing necessary to deliver services you have requested or contracted with us.
Legitimate Interests (Art. 6(1)(f))
Platform security, fraud prevention, service improvement, and business analytics, provided those interests do not override your rights.
Consent (Art. 6(1)(a))
Newsletter subscriptions and marketing communications. You may withdraw consent at any time.
Legal Obligation (Art. 6(1)(c))
Where processing is required to comply with applicable law.
4. Data We Collect
4.1 Contact Form Submissions
- Full name, email address, phone number
- Company name and industry
- Services of interest, budget range, and timeline
- Description of your business challenge
4.2 Newsletter Subscriptions
- Email address
- Subscription source and date
4.3 Client Portal (app.andlah.com)
- Account credentials (email, hashed password)
- Company and billing information
- Project communications and documents
- Activity and access logs
4.4 Automatically Collected Data
- IP address, browser type, operating system
- Pages visited, time on site, referring URL
- Cookie identifiers
- Device and screen information
5. How We Use Your Data
We do not sell your personal data. We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.
6. Data Sharing & Third Parties
We do not sell, rent, or trade your personal data. We share data only in these limited circumstances:
6.1 Service Providers (Sub-processors)
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database hosting & authentication | EU / US (AWS) |
| Vercel | Website hosting & deployment | Global (Edge) |
| OpenAI | AI chatbot responses | US |
| Google Analytics | Website usage analytics | US |
| Microsoft Clarity | User behaviour analytics | US |
6.2 Legal Disclosure
We may disclose your data to law enforcement or regulators where required by applicable law.
6.3 Business Transfer
In the event of a merger or acquisition, your data may be transferred. We will notify affected users before data becomes subject to a different privacy policy.
7. International Data Transfers
ANDLAH operates globally. Your data may be processed in countries outside your own, including the United States and European Union.
For transfers from the EU/UK, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
All sub-processors are contractually bound to maintain equivalent data protection standards.
8. Data Retention
| Data Type | Retention Period |
|---|---|
| Contact form submissions | 3 years from submission date |
| Newsletter subscriber email | Until unsubscribed + 30 days |
| Active client portal accounts | Duration of contract + 2 years |
| Deleted portal accounts | Purged within 90 days of deletion request |
| Website analytics data | 26 months (Google Analytics default) |
| Security & access logs | 12 months |
| Billing & financial records | 7 years (legal requirement) |
9. Security
We implement industry-standard technical and organisational measures to protect your personal data:
- Encryption at rest (AES-256) and in transit (TLS 1.3)
- Row-Level Security (RLS) on all database tables
- Role-based access controls (RBAC)
- Hashed passwords that are never stored in plain text
- Regular security reviews and dependency updates
- Access logging and anomaly monitoring
No method of transmission over the internet is 100% secure. If you believe your data has been compromised, contact privacy@andlah.com immediately.
11. Your Rights
We honour the following rights globally, regardless of jurisdiction:
To Exercise Your Rights
Email privacy@andlah.com. We respond within 30 days. We may verify your identity before processing the request.
12. Children's Data
Our services are intended for businesses and professionals. We do not knowingly collect personal data from individuals under the age of 16 (or 13 in the United States). Contact privacy@andlah.com if you believe we have inadvertently collected data from a minor.
13. Data Breach Notification
In the event of a personal data breach, ANDLAH will:
- Notify the relevant supervisory authority within 72 hours of becoming aware (GDPR requirement)
- Notify affected individuals without undue delay where the breach creates high risk to their rights
- Document the breach, its effects, and remedial actions taken
14. Changes to This Policy
When we make material changes, we will:
- Update the "Last Updated" date at the top of this page
- Notify newsletter subscribers via email at least 30 days before changes take effect
- Post a prominent notice on our website for significant changes
Continued use after the effective date constitutes acceptance of the updated policy.
15. Contact & Complaints
For all privacy-related enquiries, data subject requests, or complaints:
Supervisory Authorities
You have the right to lodge a complaint with your local data protection authority:
European Union
Your national Data Protection Authority (DPA)
United Kingdom
Information Commissioner's Office (ICO), ico.org.uk
United States (California)
California Attorney General, oag.ca.gov
Canada
Office of the Privacy Commissioner, priv.gc.ca
Australia
Office of the Australian Information Commissioner, oaic.gov.au
South Africa
Information Regulator, inforegulator.org.za
Nigeria
Nigeria Data Protection Commission, ndpc.gov.ng
Brazil
Autoridade Nacional de Protecao de Dados, gov.br/anpd