How the platform is built and run.
The controls behind the data-protection page — hosting, access, backup, recovery — stated as they are today, with what is not yet in place listed alongside.
How your data is protected
Encrypted in transit
All traffic to lumi is served over HTTPS/TLS. Your data is encrypted between your browser and our servers.
Hosted in the United Kingdom
lumi runs on Amazon Web Services in the United Kingdom (London). Data residency and hosting are set out in our Data Processing Agreement (DPA).
One organisation never sees another
Every organisation’s data is logically separated. Members only ever see anonymised aggregates — never another organisation’s raw answers.
Hardened accounts
Passwords are stored with bcrypt (never in plain text). Sessions are HttpOnly and SameSite; sign-in and password-reset are rate-limited against brute force, with tokenised, expiring reset and invite links.
Every action logged
Key actions are logged, so access and changes are traceable — the basis for accountability in any data-protection review.
Anonymity floor (n≥3)
When fewer than three employers answered a question, the whole card is hidden: on screen and in an export. No individual organisation’s data can be reverse-engineered from the benchmark.
Handled under UK GDPR
Your data, your rights
- Used for one thing — the shared benchmark. Never sold, never passed to third parties for their own purposes.
- Data minimisation — lumi collects reward practice and policy answers, not individual employee records.
- Export any time, and request deletion — we delete your data within 30 days of a verified request.
- A Data Processing Agreement is available on request for members who need one.
Less to review, by design
- No HRIS integration and no data pulled from your systems — lumi is a guided questionnaire, so there’s far less for IT and InfoSec to review.
- No individual employee data ever enters lumi — nothing personal to breach.
- Full sub-processor list published and kept current (below).
- Happy to complete your security questionnaire or DPIA — just ask.
Who touches your data
A short, current list — nothing more than we need to run the service.
The definitive list lives in our sub-processors page.
Certifications
We don’t yet hold SOC 2 or ISO 27001, and we won’t claim a certification we don’t have. Where we are, and where we are going. If you need something below sooner for a procurement process, tell us on the call — it helps us prioritise.
Cyber Essentials — certified 7 September 2026 by Periculo, under IASME (certificate 000b5bc2-a54c-4f22-94ca-2d6188f58ddb, profile 3.3, scope: whole organisation). Recertification due 7 September 2027. The included cyber cover (AIG UK, £25,000 in the aggregate) runs to the same date.The paperwork, and the detail behind it.
Every document a due-diligence review asks for — the Data Sharing Agreement, privacy notice, sub-processor list and a completed security questionnaire — with an account of exactly what we collect and why a DPIA is unlikely to be needed.
Bring your questionnaire.
Bring them to the demo, or email our data-protection contact directly.