INTERNAL DATA PROTECTION COMPLIANCE MANUAL

Confidential – Internal Company Document

Version: 1.0

Effective Date: July 20, 2026

1. Purpose

This Manual establishes Luxeromo.com’s internal policies and procedures for protecting personal data and complying with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and, where applicable, other international privacy laws.

The objectives of this Manual are to:

  • protect customer, supplier and employee information;
  • promote responsible handling of personal data;
  • reduce privacy and cybersecurity risks;
  • support compliance with legal obligations;
  • demonstrate accountability through documented procedures.

This Manual applies to all directors, officers, employees, contractors and consultants who process personal data on behalf of Luxeromo.com.

2. Scope

This Manual applies to personal data processed by Luxeromo.com in connection with:

  • customer accounts;
  • bookings and reservations;
  • supplier registrations;
  • commission management;
  • marketing activities;
  • customer support;
  • website operations;
  • mobile applications;
  • payment administration;
  • business operations.

3. Data Protection Principles

All personnel must ensure that personal data is processed:

  • lawfully, fairly and transparently;
  • only for specified and legitimate purposes;
  • only where necessary;
  • accurately and kept up to date;
  • securely;
  • only for as long as necessary;
  • in accordance with this Manual.

4. Roles and Responsibilities

Directors

Directors are responsible for:

  • approving privacy policies;
  • ensuring adequate resources for compliance;
  • overseeing data protection governance;
  • monitoring compliance.

Management

Managers are responsible for:

  • implementing this Manual;
  • ensuring staff follow procedures;
  • reporting risks;
  • supporting audits and reviews.

Employees and Contractors

All personnel must:

  • protect confidential information;
  • use personal data only for authorised purposes;
  • maintain strong passwords and access controls;
  • report suspected security incidents immediately;
  • complete required privacy and security training.

5. Data Classification

Personal information should be classified according to sensitivity, for example:

Public Information – approved for public release.

Internal Information – routine business information.

Confidential Information – customer, supplier and commercial information.

Restricted Information – highly sensitive information requiring enhanced controls.

Access should be limited according to business need.

6. Collection of Personal Data

Staff should collect only the personal data reasonably necessary for the intended purpose.

Where required by law:

  • provide privacy information;
  • obtain valid consent where applicable;
  • avoid collecting unnecessary information.

7. Access Controls

Personal data should only be accessible to authorised personnel.

Access should be:

  • role-based;
  • regularly reviewed;
  • removed promptly when no longer required.

Accounts should never be shared between users.

8. Password and Authentication Policy

Personnel must:

  • use strong passwords;
  • enable multi-factor authentication where available;
  • never share passwords;
  • report suspected account compromise immediately.

9. Data Security

Luxeromo.com should implement appropriate safeguards, including:

  • encrypted communications where appropriate;
  • secure cloud hosting;
  • firewalls;
  • malware protection;
  • system monitoring;
  • regular backups;
  • vulnerability management.

10. Responding to Data Subject Requests

Individuals may request to:

  • access their personal data;
  • correct inaccurate information;
  • request deletion where applicable;
  • restrict processing;
  • object to certain processing;
  • receive a copy of their data where legally required.

Internal Procedure

  1. Record the request.
  2. Verify the identity of the requester.
  3. Identify the data involved.
  4. Assess legal requirements and any exemptions.
  5. Respond within the applicable legal timeframe.
  6. Keep a record of the request and response.

11. Personal Data Breach Response

A personal data breach may include:

  • unauthorised access;
  • accidental disclosure;
  • loss of devices containing personal data;
  • ransomware;
  • hacking;
  • incorrect disclosure to third parties.

Immediate Response

  1. Contain the incident.
  2. Notify management immediately.
  3. Preserve evidence.
  4. Assess affected data.
  5. Determine whether regulatory notification is required.
  6. Notify affected individuals where legally required.
  7. Document the incident and corrective actions.

12. Supplier Due Diligence

Before sharing personal data with suppliers, Luxeromo.com should verify, where appropriate:

  • business identity;
  • legal authority to operate;
  • security measures;
  • privacy compliance;
  • contractual commitments;
  • ability to protect customer information.

Suppliers handling personal data should be subject to written contractual obligations.

13. Data Retention

Personal data should only be retained for as long as necessary for:

  • legal obligations;
  • customer support;
  • accounting;
  • fraud prevention;
  • dispute resolution;
  • legitimate business purposes.

When retention is no longer necessary, information should be securely deleted or anonymised.

14. Records of Processing Activities

Luxeromo.com should maintain internal records describing:

  • categories of personal data processed;
  • purposes of processing;
  • recipients of personal data;
  • international transfers;
  • retention periods;
  • security measures.

These records should be reviewed regularly and updated when business practices change.

15. Staff Training

All personnel who handle personal data should receive training on:

  • privacy principles;
  • cybersecurity awareness;
  • phishing prevention;
  • password security;
  • reporting incidents;
  • confidentiality obligations.

Training should be refreshed periodically.

16. Monitoring and Audits

Luxeromo.com should periodically review:

  • compliance with this Manual;
  • access permissions;
  • supplier compliance;
  • security controls;
  • incident records;
  • privacy policies.

Recommendations should be documented and followed up.

17. Disciplinary Action

Failure to comply with this Manual may result in disciplinary action, termination of employment or contract, and where appropriate, legal action.

18. Policy Review

This Manual should be reviewed at least annually or sooner if there are significant changes in law, technology or business operations.

19. Confidentiality

This Manual contains confidential internal procedures and is intended solely for authorised personnel of Luxeromo.com.

It must not be disclosed externally without the prior approval of the Company’s management.

 

Approved by: ___________________________

Position: ______________________________

Date: _________________________________

© Luxeromo.com. All Rights Reserved.