Policies
Data Privacy Policy
Last Updated: 2026-01-01
Enactment Date: 2026-02-01
Your privacy is important to us. At Illuminum, we want You to feel secure regarding how Your Personal Data is processed. This policy outlines our commitment to transparency and the protection of Your information.
1. Acceptance & Scope
By using our Service, You agree to the collection and use of Your information in accordance with this Privacy Policy.
Integration: This policy is an integral part of our Terms of Service.
Definitions: Capitalized terms used herein have the same meaning as defined in the Terms of Service for Gaia by Illuminum.
Exclusions: This policy does not apply to non-personal data processed on behalf of business clients (e.g., consultancy or API services), which are regulated by separate service agreements.
2. Definitions of Data Processing
Personal Data: Any information that can be directly or indirectly attributed to a living natural person. This includes names, email addresses, usernames, and images.
Processing: Any action taken with Personal Data in IT systems—such as collection, registration, structuring, storage, transfer, and deletion.
3. Collection of Personal Data
We collect data when You sign up for software solutions, newsletters, webinars, or contact us through support channels.
3.1 Data We Process
Identity: Name, surname, job title, and employer information (if business-affiliated).
Contact: Email address, phone number, and country.
Billing: Billing address and necessary payment information (processed securely via our third-party payment processors).
Usage Data: Content viewed, features used, access times, browser version, device type, and internet connection details.
4. Use of Personal Data
Information obtained during registration is used solely for Illuminum's business purposes:
Service Delivery: Managing accounts and providing requested products.
Security: Preventing illegal activities and safeguarding our systems.
Events: Coordinating logistics for physical events (e.g., food intolerances).
Communications: * Service-Related: Mandatory updates regarding downtime or account security.
Commercial: Information about new courses or events (Users may opt-out via Support).
5. Your Rights (GDPR Compliance)
If You are an EU/EEA resident, You have specific rights under the General Data Protection Regulation (GDPR):
Access & Portability: You have the right to request a copy of Your stored data in a portable format.
Correction & Deletion: You may correct inaccurate info or request deletion. While we respect deletion requests, some data may be retained if required for legal documentation.
Withdrawal of Consent: You can withdraw prior consent at any time by contacting us.
Note: Deleting Your Illuminum Account permanently removes associated data, except where retention is legally mandated.
6. Data Storage & Security
6.1 Duration
We retain Your data only as long as necessary to fulfill the purpose of processing or for the duration of the customer relationship, unless legal obligations require a longer period.
6.2 Security Measures
We treat Personal Data as confidential and use industry-standard measures, including encryption and protected cloud services. While we strive for maximum security, no system is entirely risk-free; our liability for unauthorized access is limited to the extent permitted by law.
7. Disclosure to Third Parties
We do not sell Your Personal Data. Disclosure occurs only in the following contexts:
Data Processors: We use IT suppliers (Data Processors) under strict data processing agreements. Illuminum remains the Data Controller and is responsible for your data.
Independent Controllers: For marketing or analytics, we may use partners whose own privacy policies apply. You will be notified via email if Your data is transferred to a new third-party controller.
Legal Requirements: Data may be shared with police or authorities if required by law.
Business Transfer: In the event of a merger or sale, the recipient will be bound by the same restrictions regarding Your data.
8. International Data Transfers
We strive to process data primarily within the EU/EEA. If data is transferred outside this zone (e.g., for global IT support), we implement safeguards such as Standard Contractual Clauses (SCC) or Binding Corporate Rules (BCR) to ensure a high level of protection.
9. Administration & Disputes
9.1 Data Controller
Illuminum AB Västra Ågatan 22, 753 09 Uppsala
Organization Number: 559359-4343
9.2 Supervisory Authority
The Swedish Data Protection Authority (IMY) monitors the application of data protection law. If You believe we are acting improperly, You may contact them at https://www.imy.se/.
9.3 Governing Law
Disagreements shall be resolved according to the governing law and venue specified in the Illuminum Terms of Service.


