Home · Privacy Policy

Privacy Policy

1. Who we are

LUMA Fine Diamond Jewellery Ltd ("LUMA", "we", "us"), Plot 000, Rhodes Park, Lusaka, Zambia, is the data controller of your personal data. Contact: see the Contact page. This policy is written in accordance with the Data Protection Act No. 3 of 2021 of Zambia.

2. What we collect and why

  • Member account: name, email, phone/WhatsApp and a password (stored only as a one-way hash). Used to run your account, points, invite and gift balances.
  • Orders and delivery: address, city, contact time, payment preference and notes. Used to fulfil and insure delivery and to issue certificates and valuations.
  • Communications: WhatsApp and email conversations with the care team, kept for service continuity.
  • Technical data: basic access logs (IP, browser) for security and troubleshooting only.

3. Legal basis

  • Performance of a contract — delivering your order or running your account;
  • Consent — the newsletter or other optional communications you subscribe to;
  • Legitimate interest — security, fraud prevention and service improvement, balanced against your rights;
  • Legal obligation — tax and commercial records required by Zambian law.

4. Who we share with

Only what is necessary, never for sale of data: insured couriers (delivery), banks/payment providers (payments you initiate), the SMS gateway (only if you use SMS one-time sign-in), and professional advisers or authorities where the law requires. Everyone handling your data is under confidentiality and data-protection obligations.

5. Where your data is stored (cross-border transfer)

Records are kept on secured servers operated for us by a professional hosting provider whose data centres are located outside Zambia. We transfer and store personal data outside Zambia only to operate the storefront and member services, under appropriate technical and organisational safeguards, in line with the Data Protection Act, 2021. By using the site you acknowledge this transfer.

6. Storage, security and retention

  • Passwords are stored as salted one-way hashes — no one, including us, can read them.
  • Access is restricted to authorised staff on the care and bench teams.
  • Account data is kept while your account is active; order and invoice records are kept for the retention period required for tax and consumer purposes, then deleted or anonymised.

7. Data breach notification

If a breach occurs that is likely to result in a risk to your rights, we will notify you and the relevant authority without undue delay, as required by the Data Protection Act, 2021, describing what happened and the steps we have taken.

8. Direct marketing and opting out

Marketing messages are sent only where you have subscribed. Every message includes a working unsubscribe; you may also ask our care team to stop at any time. Service messages about orders and care cannot be opted out of while you have open orders.

9. Your rights (Data Protection Act, 2021)

  • Access a copy of the personal data we hold on you;
  • Correction of inaccurate data — or update it yourself in your member panel;
  • Deletion (right to erasure) where we have no lawful basis to keep it;
  • Object to processing and restriction, and withdraw consent at any time;
  • Account deletion: write to our care team and your member account will be removed, subject to records we must retain by law;
  • Lodge a complaint with the authority responsible under the Data Protection Act No. 3 of 2021 if we fail to resolve your concern.

To exercise any right, write to our care team — we respond within statutory time.

10. Children

Our services are not directed to persons under 18, and we do not knowingly collect their data. A parent or guardian may contact us to remove any data collected inadvertently.

11. Third-party links and changes

Links to third-party sites are outside this policy; those sites have their own policies. We update this policy from time to time and post the effective date at the top of the page.