Skip to content

LEGAL

Data protection and international transfers

The framework we apply to personal data across jurisdictions, the safeguards behind cross-border transfers, and the rights available to you wherever you are.

Effective 16 August 2026

Scope of this notice

Lunava Digital Solutions FZCO ("Lunava") delivers digital platforms, software engineering and procurement advisory to clients in multiple regions. This notice explains the data protection framework we apply, in addition to the privacy policy that covers this website.

Where we determine why and how personal data is processed, for example enquiries submitted to us, we act as a controller. Where we build or operate a platform on a client's instructions, we act as a processor for the personal data inside that platform, and the client's own privacy notice governs the individuals concerned.

Laws we design against

We design our handling of personal data to satisfy the common core of the following regimes, and to meet the additional requirements of whichever regime applies to a given engagement:

  • EU General Data Protection Regulation (GDPR) and the UK GDPR with the Data Protection Act 2018
  • UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and applicable free zone data protection regulations
  • California Consumer Privacy Act as amended by the CPRA, and comparable US state privacy laws
  • Canada's Personal Information Protection and Electronic Documents Act (PIPEDA)
  • Brazil's Lei Geral de Proteção de Dados (LGPD)
  • South Africa's Protection of Personal Information Act, No. 4 of 2013 (POPIA), addressed in detail in our POPIA statement at /legal/popia
  • Singapore's Personal Data Protection Act (PDPA) and comparable Asia-Pacific regimes
  • Sector rules that a client engagement brings with it, for example public sector procurement or donor reporting requirements

Principles we apply

Across every engagement we work to the same operating principles: collect only the personal data a purpose genuinely requires, state the purpose before collection, keep data accurate, restrict access to those who need it, retain it only as long as the purpose or the law requires, and be able to evidence each of those decisions.

We do not sell or share personal data for cross-context behavioural advertising, and we do not use personal data collected through this site for automated decision-making or profiling that produces legal effects.

Lawful basis and consent

For business enquiries we rely on legitimate interest in responding to a request about our services, or on steps taken at your request prior to entering a contract. For analytics and campaign measurement we rely on consent, collected through the cookie banner and switched off by default.

Where an engagement involves special category or sensitive data, we agree the lawful basis, additional safeguards and access restrictions with the client in writing before that data is processed.

International transfers

Because we operate globally, personal data may be processed outside the country in which it was collected, including in the United Arab Emirates, the European Economic Area, the United Kingdom and the United States, depending on the service provider involved.

Where personal data leaves the EEA or the UK, transfers are made under an adequacy decision where one exists, or otherwise under the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, supported by a transfer risk assessment. For transfers from the UAE we rely on the mechanisms permitted under the PDPL, including adequate jurisdiction status or contractual safeguards.

Where a client requires processing to remain within a specific country or region, we can scope hosting and support accordingly as part of contracting. Tell us the requirement before design begins so it can be built in rather than retrofitted.

Processor commitments

When we act as a processor we commit, in contract, to process personal data only on documented instructions, to impose confidentiality obligations on personnel, to apply appropriate technical and organisational security measures, to engage subprocessors only under equivalent written terms and with notice of changes, to assist with data subject requests and impact assessments, to support breach notification, and to delete or return personal data at the end of the engagement.

A data processing agreement incorporating these commitments, with Standard Contractual Clauses where relevant, can be executed alongside the services agreement.

Subprocessors

We use a small set of established service providers to deliver email, analytics and hosting. Each is bound by written terms and processes data only on our instructions. The current list is published on our subprocessors page, and clients receive notice before a new subprocessor is introduced into their engagement.

Your rights, by region

The rights available to you depend on the law that applies to you. In practice we honour the broadest reasonable interpretation for anyone who contacts us:

  • Access to the personal data we hold about you and information about how it is used
  • Correction of inaccurate or incomplete data
  • Deletion, subject to legal, accounting and contractual retention obligations
  • Restriction of, or objection to, processing based on legitimate interest, including direct marketing
  • A portable copy in a structured, commonly used, machine-readable format
  • Withdrawal of consent at any time, without affecting processing carried out before withdrawal
  • Non-discrimination for exercising a right, and the right to lodge a complaint with your supervisory authority

How to make a request

Send your request to support@lunavadigital.com with enough detail for us to identify the data concerned. We acknowledge within five working days and respond within 30 days, or within the shorter period your local law requires. If we need an extension we will tell you why before the deadline passes.

If your data sits inside a platform we operate for a client, we will forward the request to that client as controller and support them in responding.

Breach response

We maintain an incident response process covering detection, containment, assessment and notification. Where a personal data breach is likely to result in a risk to individuals, we notify the relevant controller without undue delay and, where we are the controller, notify the competent supervisory authority within 72 hours of becoming aware, together with affected individuals where the risk is high.

Changes

We review this notice at least annually and whenever our processing, service providers or the applicable legal framework change materially. The effective date above reflects the current version.

All Lunava policies are listed in our legal centre.