GDPR Compliance Statement
Last updated: 16 May 2026
Our Commitment to Data Protection
Luminous Shine Limited is committed to full compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page outlines our approach to data protection and your rights under current data protection legislation.
Data Controller Information
Luminous Shine Limited is the data controller responsible for your personal data. Our contact details are:
Luminous Shine Limited
42 Chapel Street
Salford, Greater Manchester
M3 7EB
United Kingdom
Email: [email protected]
Lawful Basis for Processing
We only process your personal data when we have a lawful basis to do so. Depending on the purpose of processing, we rely on one or more of the following legal bases:
Consent
Where you have given clear, informed consent for us to process your personal data for specific purposes. You have the right to withdraw consent at any time by contacting us.
Contract Performance
Where processing is necessary to perform our contract with you or to take steps at your request before entering into a contract. This includes processing your data to provide the benefits support services you have requested.
Legal Obligation
Where we must process your data to comply with legal obligations, such as responding to lawful requests from government departments or regulatory authorities.
Legitimate Interests
Where processing is necessary for our legitimate interests or those of a third party, provided your rights and interests do not override those interests. We have conducted legitimate interests assessments to ensure our processing activities are justified and proportionate.
Special Category Data
In the course of providing benefits support services, we necessarily process special category data including:
- Health data (medical conditions, disability information, assessments)
- Genetic and biometric data (where relevant to benefit claims)
- Data concerning your sex life or sexual orientation (where relevant to specific benefit criteria)
We process this sensitive data only where we have your explicit consent or where processing is necessary for:
- Compliance with employment, social security, and social protection law
- Purposes of preventive or occupational medicine, medical diagnosis, or health or social care
- Reasons of substantial public interest on the basis of UK law
- Establishment, exercise, or defense of legal claims (including tribunal proceedings)
Data Minimization
We adhere to the principle of data minimization, collecting only the personal data that is necessary for the specific purposes we have identified. We do not collect excessive data or retain data longer than necessary.
Data Accuracy
We take reasonable steps to ensure the personal data we hold about you is accurate and up to date. You have the right to request correction of inaccurate or incomplete data. Please contact us if you believe any information we hold about you is incorrect.
Storage Limitation
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or as required by law. Our standard retention periods are:
- Active client files: Duration of service provision plus 7 years
- Closed cases: 7 years from case closure
- Marketing consent records: Until consent is withdrawn plus 1 year
- Website analytics: 26 months
After the retention period expires, we securely delete or anonymize your personal data.
Data Security Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit and at rest
- Pseudonymization where appropriate
- Regular security assessments and penetration testing
- Access controls and authentication systems
- Staff training on data protection and confidentiality
- Secure backup and disaster recovery procedures
- Incident response and breach notification procedures
Your Rights Under GDPR
Right of Access
You have the right to obtain confirmation of whether we process your personal data and, if so, to access that data and receive information about how it is processed.
Right to Rectification
You have the right to request correction of inaccurate personal data and completion of incomplete data.
Right to Erasure
In certain circumstances, you have the right to request deletion of your personal data. This right is not absolute and may be limited by legal obligations requiring us to retain certain data.
Right to Restriction of Processing
You have the right to request restriction of processing in certain circumstances, such as when you contest the accuracy of data or object to processing.
Right to Data Portability
Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
Right to Object
You have the right to object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect you. We do not currently engage in automated decision-making of this nature.
Exercising Your Rights
To exercise any of your data protection rights, please submit a request to:
Email: [email protected]
Post: Data Protection Officer, Luminous Shine Limited, 42 Chapel Street, Salford, Greater Manchester, M3 7EB
We will respond to your request within one month. In complex cases, we may extend this period by two further months, in which case we will inform you and explain the reason for the extension.
We will not charge a fee for processing your request unless it is manifestly unfounded or excessive, particularly if it is repetitive.
Data Breach Notification
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify you without undue delay. We will also notify the Information Commissioner's Office within 72 hours of becoming aware of the breach, where required by law.
Third-Party Data Processors
Where we engage third-party processors to process personal data on our behalf, we ensure they provide sufficient guarantees regarding data protection. We maintain written contracts with all processors that set out their obligations and our rights.
International Data Transfers
We primarily process data within the United Kingdom. If we transfer personal data outside the UK, we ensure appropriate safeguards are in place, such as:
- Adequacy decisions by the UK Secretary of State
- Standard contractual clauses approved by the ICO
- Binding corporate rules
Data Protection by Design and Default
We implement data protection by design and by default, integrating data protection into all our processing activities and business practices from the outset.
Contact the Supervisory Authority
You have the right to lodge a complaint with the Information Commissioner's Office if you believe we have not complied with data protection law:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk
Updates to This Statement
We review and update this GDPR compliance statement regularly to ensure it remains current with legal requirements and our processing activities. The "Last updated" date at the top of this page indicates when changes were last made.