Luminex Brands ("Luminex," "we," "us," "our") provides business strategy, brand architecture, personal branding, lead generation, marketing technology, advertising management, and creative/software design services. This Privacy Policy applies to www.luminexbrands.com, our enquiry and lead forms (including Meta/Facebook/Instagram Lead Ads), WhatsApp business communication, and our client and team login portals, unless a separate policy is shown for a specific product.
By using this website or submitting your information to us, you acknowledge this Privacy Policy. If you do not agree with it, please do not submit personal data to us or use our Services.
Who we are — Data Fiduciary details
Under the DPDP Act, Luminex Brands acts as the Data Fiduciary for personal data collected through this website and our client-facing services.
- Trade name: Luminex Brands CONFIRM: legal entity name / registration no. if incorporated
- Registered office: Attoorkonam, Karingannor P.O., Kollam, Kerala – 691516, India
- Email: info@luminexbrands.com
- WhatsApp: +91 73065 81214 CONFIRM: single official WhatsApp business number
Personal data we collect
- Data you give us directly — name, email, phone/WhatsApp number, company name, business details, and message content submitted through our Contact page, enquiry forms, WhatsApp, email, or calls.
- Data from Meta advertising (Lead Ads) — if you respond to a lead form on a Luminex- or client-run Meta/Facebook/Instagram ad, we receive the fields you submit — typically name, phone, email, and any custom questions on that form.
- Client & portal data — for clients, business, billing, campaign, and account data needed to deliver Services, held in our CRM (Zoho CRM) and, where applicable, your client login portal.
- Team data — for Luminex team members/contractors, access data for the internal team login portal.
- Automatically collected data — standard technical data such as IP address, browser/device type, pages visited, and referral source, collected via cookies and similar technologies (see §4).
Why we process your data
Consistent with the DPDP Act's requirement that data only be used for the purpose disclosed at collection, we process personal data to:
- respond to enquiries and provide quotations or consultations;
- deliver contracted Services — business strategy, brand architecture, campaign management, lead generation, and software/website builds;
- manage our client relationships in Zoho CRM;
- create, run, and optimize advertising campaigns on Meta platforms on behalf of our clients, and for Luminex's own marketing;
- route leads captured through a client's ad campaign to that client's CRM only;
- communicate via WhatsApp Business for enquiries, updates, and support;
- operate the client and team login portals;
- meet our legal, accounting, and compliance obligations.
Cookies, Meta Pixel & similar technologies
We and our advertising partners may use cookies, the Meta Pixel, and Meta's Conversions API to measure website activity and ad performance, and to build custom or lookalike audiences for advertising. These technologies may record data such as pages viewed, actions taken (e.g., a form submission), and device identifiers. You can control or disable cookies through your browser settings; doing so may limit some site functionality.
CONFIRM: list any analytics tool in use (e.g., Google Analytics, GA4) so it can be named here
Advertising run on behalf of clients
Luminex operates a centralized Meta Ads Manager on behalf of multiple clients. When you submit a Lead Ad form or interact with an ad for a specific client's Page, your data is:
- captured through Meta's platform under that client's advertising account;
- routed by Luminex's systems to that specific client's CRM only; and
- never shared with, or visible to, any other Luminex client.
Each client remains responsible for how they use leads once received into their own CRM, in accordance with their own privacy practices.
Who we share data with
We share personal data only where necessary, with:
- Meta Platforms, Inc. (Facebook/Instagram) — for ad delivery, lead capture, and Conversions API events, governed by Meta's own data policy;
- Zoho Corporation (Zoho CRM) — as our CRM processor for storing and managing client and lead records;
- WhatsApp Business Solution Providers — where used, for business messaging CONFIRM: name the BSP once selected;
- Hosting, email, and IT service providers — to operate this website and our internal systems;
- Professional advisors and authorities — where required by law, audit, or to establish or defend legal claims.
We do not sell personal data.
Data retention
We retain personal data only as long as necessary for the purposes described above, or as required by applicable law (including record-keeping obligations under Indian tax, company, and contract law). Enquiry or lead data that does not convert into a client relationship is retained for a limited period and then deleted or anonymized.
CONFIRM: specific retention periods (e.g., unconverted leads deleted after 12 months)
Cross-border data transfers
Some of our service providers — including Meta and Zoho — may process data on servers located outside India. We rely on these providers' own compliance frameworks and, where applicable, the mechanisms permitted under the DPDP Act for personal data transfers outside India.
Your rights as a Data Principal
Under the DPDP Act, you have the right to:
- obtain a summary of the personal data we hold about you and how it is processed;
- request correction, completion, or updating of your personal data;
- request erasure of personal data no longer necessary for the purpose it was collected, subject to our legal retention obligations;
- withdraw consent at any time, without affecting processing carried out before withdrawal;
- nominate another individual to exercise these rights on your behalf in the event of death or incapacity;
- lodge a grievance with us and, if unresolved, with the Data Protection Board of India.
To exercise any of these rights, contact us at info@luminexbrands.com. We aim to respond within a reasonable time as required under applicable law.
Children's data
Our Services are intended for businesses and adults. We do not knowingly collect personal data from children without verifiable parental or guardian consent, as required under the DPDP Act. If you believe a child's data has been submitted to us, contact us and we will remove it.
Security
We apply reasonable technical and organizational safeguards — including access controls, restricted CRM/portal access, and secure credential handling — to protect personal data against unauthorized access, alteration, disclosure, or loss. No online system is completely secure, and we cannot guarantee absolute security.
Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The "Last updated" date at the top of this page reflects the most recent revision. Material changes will be reflected on this page.
Contact & grievance redressal
For privacy questions, data requests, or grievances, reach us at:
