Privacy Policy
What we collect, why we collect it, and the rights you have over it — under both the GDPR and POPIA.
Last updated: 6 August 2026
Who we are
Dev Luma ("we", "us") is a software development company. This policy explains what personal information we collect through this website, why we collect it, and what rights you have over it.
For the purposes of the EU/UK General Data Protection Regulation (GDPR) we are the data controller. For the purposes of South Africa's Protection of Personal Information Act (POPIA) we are the responsible party. Our Information Officer is [Information Officer name], contactable at info@devluma.io.
Registered entity: [Registered company name], [Registered address].
What we collect
Information you give us. When you submit our contact form we collect your name, email address, and — if you choose to provide them — your company name, budget range, and the details of your enquiry.
Information collected automatically. We use Plausible Analytics, a privacy-focused service that does not use cookies and does not collect or store personal data. It records aggregate page views, referrer, approximate country, and device type. It cannot identify you individually and does not track you across other websites.
What we do not do. We do not use advertising cookies, we do not build visitor profiles, we do not sell personal information, and we do not use your enquiry to add you to a marketing list without asking you first.
Why we use it, and our legal basis
To respond to your enquiry. Legal basis: taking steps at your request prior to entering into a contract (GDPR Art. 6(1)(b)). Under POPIA, processing is necessary to conclude or perform under a contract to which you are a party.
To operate and improve the website. Legal basis: our legitimate interest in understanding aggregate usage (GDPR Art. 6(1)(f)). Because our analytics collects no personal data, this has minimal privacy impact.
To meet legal obligations. Where we are required to retain records, for example for tax or accounting purposes.
International transfers
We work with clients in the EU, United States, Australia, and South Africa, and some of our providers process data outside your country of residence.
Where personal information is transferred out of the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses or an adequacy decision. Where it is transferred out of South Africa, we rely on section 72 of POPIA, which requires the recipient to be subject to comparable protection.
How long we keep it
Contact enquiries are kept for 24 months from our last correspondence with you, so that we have context if you come back to us, and then deleted.
If the enquiry becomes a client engagement, the associated records are retained for the duration of the engagement and for as long afterwards as tax and contractual record-keeping requires.
Aggregate analytics contains no personal data and is retained indefinitely.
Your rights
You can ask us to give you a copy of the personal information we hold about you, correct it if it is wrong, delete it, restrict how we use it, or object to our using it. Where processing is based on consent, you can withdraw that consent at any time. Under the GDPR you also have the right to receive your data in a portable format.
To exercise any of these rights, email info@devluma.io. We will respond within one month (GDPR) or a reasonable period (POPIA). We will not charge you, and we will not treat you differently for asking.
If you are unhappy with how we have handled your information, you have the right to complain. In the EU or UK, complain to your national data protection authority. In South Africa, complain to the Information Regulator at enquiries@inforegulator.org.za.
How we protect it
The website is served over HTTPS. Contact form submissions are transmitted over an encrypted connection and delivered to a mailbox protected by multi-factor authentication. Access to enquiry data is limited to the people who need it to reply to you.
No system is perfectly secure. If a breach occurs that is likely to put your rights at risk, we will notify you and the relevant regulator as the GDPR and POPIA require.
Changes to this policy
We may update this policy as our services or the law change. The date at the top of this page shows when it was last revised. Material changes will be highlighted on this page.
Questions about this policy: info@devluma.io.