Complimentary worldwide shipping on orders over $75

Legal & Compliance

Data Protection Policy

Last Updated: August 31, 2026

Effective Date: August 31, 2026

1. Scope & Core Principles

At Luxxine, protecting personal data and maintaining strict technical governance is paramount to our operations. This Data Protection Policy defines the corporate standards, organizational controls, processing guidelines, and security mechanisms implemented across Luxxine to safeguard personal data and ensure compliance.

All processing activities adhere to six fundamental data protection principles:

  • Lawfulness, Fairness & Transparency: Personal data is collected and processed lawfully, ethically, and with complete user visibility.
  • Purpose Limitation: Data is strictly processed for declared operational purposes and not reused for incompatible activities.
  • Data Minimization: Only the minimal necessary data required to complete a specific action or transaction is collected.
  • Accuracy & Recency: Luxxine takes every reasonable step to ensure personal data is accurate, complete, and kept up to date.
  • Storage Limitation: Information is retained only for the duration required to serve its purpose or meet legal obligations.
  • Integrity & Confidentiality: Data is secured using robust technical, cryptographic, and administrative controls.

2. Data Governance & Security Controls

To mitigate risk, prevent unauthorized access, and ensure business continuity, Luxxine deploys multi-layered technical controls:

  • Encryption Standard: All sensitive data in transit is encrypted using TLS 1.3, while stored data relies on AES-256 encryption at rest.
  • Access Control & Least Privilege: System access is strictly restricted through role-based access controls (RBAC) and mandatory multi-factor authentication (MFA).
  • Network Security: Web traffic is filtered via firewalls, intrusion detection systems (IDS), and routine perimeter vulnerability assessments.
  • Security Audits: Third-party security audits and automated code vulnerability scans are performed routinely across all infrastructure.

3. Data Subject Rights & Fulfillment Workflows

Data subjects hold statutory rights under applicable privacy frameworks (including GDPR, CCPA, and Ghana Data Protection Act 2012). Users may submit requests for data access, rectification, porting, or deletion ('Right to be Forgotten'). All requests received through official channels undergo identity verification and are fulfilled within 30 days without cost to the requester.

4. Incident Management & Breach Notification

Luxxine maintains an active Incident Response Plan. In the event of a confirmed or suspected personal data breach, our Security Team conducts immediate containment and forensic isolation. If a breach presents a risk to user rights, relevant regulatory authorities and affected individuals will be notified within 72 hours of verification.

5. Third-Party Vendor & Subprocessor Compliance

All third-party subprocessors, payment gateways, and cloud service providers undergo formal privacy impact assessments. Vendors are legally required to execute Data Processing Agreements (DPAs) containing standard contractual clauses, ensuring equivalent standards of technical protection and strict non-disclosure obligations.

6. International Data Transfers & Contact

When transferring personal data across international borders, Luxxine relies on legally recognized transfer mechanisms, including adequacy decisions, Standard Contractual Clauses (SCCs), and localized data processing options where mandated by law.

For data protection inquiries or to exercise your privacy rights, contact our Compliance Team at support@luxxine.com | +233206520051