Legal

Privacy Policy

This Privacy Policy explains how MyLumera Technologies (“we,” “us,” or “our”) collects, uses, stores, protects, and discloses personal information in accordance with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its implementing rules and regulations. By using our platform and products, you consent to the practices described herein.

Data Privacy Act Compliance. We are committed to upholding the rights of data subjects and implementing reasonable and appropriate organizational, physical, and technical security measures to protect personal data against unauthorized access, use, disclosure, alteration, or destruction.

Data controller and contact

MyLumera Technologies acts as the personal information controller (PIC) for data collected through our platform. Our Data Protection Officer (DPO) can be reached at privacy@mylumera.net for any privacy-related inquiries, complaints, or data subject requests.

What we collect and why

We collect personal data necessary to deliver our services: (a) account information (name, email, company, role) for identity and access management; (b) usage data (logs, actions, timestamps) for audit, security, and product improvement; (c) support communications for troubleshooting; and (d) billing information for subscription management. We do not collect more than is necessary for these lawful purposes.

Legal basis for processing

Under the Data Privacy Act, we process personal data based on: (a) consent, where freely given and documented; (b) contractual necessity, to fulfill our service agreements; (c) legal obligation, where required by law or regulatory authority; and (d) legitimate interest, such as fraud prevention and network security, provided it does not override your fundamental rights.

How we protect your data

We implement a combination of organizational, physical, and technical safeguards: encryption in transit (TLS) and at rest; role-based access controls with least-privilege principles; regular security assessments and vulnerability management; staff training on data privacy; and incident response procedures aligned with the National Privacy Commission (NPC) guidelines.

Data sharing and subprocessors

We share personal data only with trusted subprocessors necessary for hosting, email delivery, analytics, and payment processing. All subprocessors are bound by data protection obligations. We do not sell personal data to third parties. Cross-border transfers, if any, comply with Section 19 of the Data Privacy Act and applicable NPC circulars.

Your rights as a data subject

Under the Data Privacy Act, you have the right to: (a) be informed; (b) access your personal data; (c) object to processing; (d) erasure or blocking; (e) damages for violation; (f) file a complaint with the NPC; (g) rectify inaccurate data; and (h) data portability. To exercise these rights, contact our DPO at privacy@mylumera.net with sufficient proof of identity.

Data retention and breach notification

Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. In the event of a personal data breach that poses a risk to your rights, we will notify the NPC within 72 hours and affected data subjects without undue delay, in accordance with NPC Circular No. 2022-04.

Cookies and analytics

We use essential cookies for authentication and session management. Optional analytics cookies help us understand platform usage. You can manage cookie preferences through your browser settings. We do not use tracking cookies for third-party advertising.

Updates to this policy. We may revise this Privacy Policy from time to time to reflect changes in law, technology, or our practices. Material changes will be communicated through the platform or via email. Continued use of our services after updates constitutes acceptance of the revised policy.

Last updated: June 2026. This Privacy Policy is maintained by MyLumera Technologies and may be revised as our practices evolve. For questions, contact privacy@mylumera.net.