Trust Center
Security and compliance frameworks we hold, published only when they are in place.
Compliance status
| Framework | Status | Notes |
|---|---|---|
| ISO 27001 | Certified Information security management system certified to ISO/IEC 27001. Certificate available under NDA on request. | Information security management system certified to ISO/IEC 27001. Certificate available under NDA on request. |
| GDPR | Compliant We process personal data in line with the EU General Data Protection Regulation, including purpose limitation, access controls, and retention practices. | We process personal data in line with the EU General Data Protection Regulation, including purpose limitation, access controls, and retention practices. |
Data protection & residency
GDPR: Personal data is processed under lawful bases appropriate to the relationship (for example legitimate interest or contract), with purpose limitation, access controls, and deletion on request where applicable.
DPDP Act, 2023 (India): We design product and website practices with India's Digital Personal Data Protection Act in mind: purpose limitation, retention on request deletion, and clear disclosure of processors.
Customer production data: For product deployments, data residency and network topology (including private / customer VPC options) are agreed per engagement.
Documents
Security questions?
Reach us for questionnaires or architecture reviews at info@techlumino.com.