Legal
Privacy Policy
Effective Date: January 31, 2026
1. Introduction
Welcome to DLux ("we," "us," or "our"). We are committed to protecting your privacy and being transparent about how we handle your personal information.
This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data when you visit our website or use our services. By using our website, you agree to the practices described in this policy.
DLux provides AI pipeline engineering and content production services, including custom automation systems, data processing workflows, API integrations, and end-to-end content creation using production-grade pipelines. This policy applies to all information collected through our website and business communications.
Data Controller: DLux is the data controller responsible for your personal information. Contact details are provided in Section 14.
2. Information We Collect
Information You Provide Directly
When you interact with us, you may provide the following information:
- Contact Information: Name, email address, and company name when you email us directly or book a consultation via Google Calendar Appointment Scheduling
- Scheduling Information: Meeting preferences and availability when you use our Google Calendar booking link
- Project Materials: Documents, transcripts, briefs, and other materials you share for project work
- Communication Content: Messages and correspondence you send to us via email
- Payment Information: Billing details for wire transfers or Wise payments (we do not store complete bank account details after transactions are processed)
Required vs. Optional Information (GDPR Disclosure)
For users in the EEA, UK, or Switzerland, the following clarifies which data is required and consequences of not providing it:
- Email inquiries: Providing your email address is required to receive a response. Without it, we cannot reply to your inquiry.
- Scheduling consultations: Name and email are required by Google Calendar Appointment Scheduling to book an appointment. Without this information, you cannot schedule a call.
- Service contracts: Contact information and project materials are required to deliver contracted services. Without them, we cannot perform the contract.
- Payments: Billing information is required to process payment. Without it, we cannot complete the transaction.
- Analytics: Website analytics data is optional and collected only with your consent. Declining does not affect your ability to use our website or services.
Information Collected Automatically
When you visit our website, we collect certain information automatically through Google Analytics:
- Device Information: Browser type, operating system, and device type
- Usage Data: Pages visited, time spent on site, and navigation patterns
- IP Address: Google Analytics 4 does not log or store IP addresses by default
- Referral Data: How you arrived at our website
- Geographic Region: Country and city-level location (derived, not precise)
This data is collected only after you provide consent via our cookie consent banner.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To respond to your inquiries, schedule consultations, provide quotes, deliver contracted services, and communicate about projects
- Site Analytics: To understand how visitors use our website and improve user experience (only with your consent)
- Business Operations: To process payments, maintain records, and manage client relationships
- Legal Compliance: To comply with applicable laws, regulations, and legal processes
We do NOT:
- Sell your personal information to third parties
- Share your personal information with data brokers
- Use your data for third-party advertising or retargeting
- Send marketing emails or newsletters (we do not operate a mailing list)
- Make automated decisions that significantly affect you
4. Legal Bases for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data under the following legal bases:
| Processing Activity | Legal Basis |
|---|---|
| Responding to inquiries | Legitimate Interest — Necessary to respond to your request and evaluate potential business relationships |
| Scheduling consultations | Contract — Necessary to take steps at your request prior to entering into a contract |
| Delivering services | Contract — Necessary for the performance of a contract with you |
| Processing payments | Contract — Necessary for the performance of a contract with you |
| Website analytics | Consent — We only collect analytics data after you consent via our cookie banner |
| Retaining financial records | Legal Obligation — Required for tax and accounting compliance |
You may withdraw consent at any time for processing activities based on consent (such as analytics). Withdrawal does not affect the lawfulness of processing before withdrawal.
5. How We Share Your Information
We share your information only with the following categories of recipients, and only to the extent necessary:
Service Providers
| Provider | Purpose | Data Shared |
|---|---|---|
| Hostinger | Website hosting | Server logs (IP, access times) |
| Google Analytics | Website analytics | Usage data, device info (with consent) |
| Google Calendar Appointment Scheduling | Appointment scheduling | Name, email, meeting preferences |
| Google Drive | Project file storage and delivery | Project materials you provide |
| Wise / Banking Provider | Payment processing | Billing information for transfers |
| Google Fonts | Typography / font delivery | IP address, browser info (automatic on page load) |
These providers process data on our behalf and are contractually obligated to protect your information.
Legal Requirements
We may disclose your information if required by law, court order, or government request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
Business Transfers
If DLux is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
6. Data Retention
We retain your information based on the following guidelines:
| Data Type | Retention Period | Reason |
|---|---|---|
| Email correspondence | Duration of business relationship | Business communication, reference |
| Project files (Google Drive) | 90 days after project completion | Project delivery, revisions |
| Analytics data | 14 months (GA4 default) | Site improvement analysis |
| Payment/invoice records | 7 years | Tax and legal compliance |
| Google Calendar booking data | Per Google's retention policy | Scheduling service |
You may request earlier deletion of your data, subject to our legal retention obligations. See Section 7 for how to make a request.
7. Your Privacy Rights
Rights for All Users
Regardless of your location, you may:
- Request information about what data we hold about you
- Request correction of inaccurate information
- Request deletion of your data (subject to legal retention requirements)
- Withdraw consent for analytics cookies at any time
Additional Rights for EEA/UK Residents (GDPR)
If you are located in the European Economic Area or United Kingdom, you have additional rights:
- Right to Access: Obtain a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion ("right to be forgotten")
- Right to Restriction: Limit how we process your data
- Right to Portability: Receive your data in a portable format
- Right to Object: Object to processing based on legitimate interest
- Right to Withdraw Consent: Withdraw consent at any time
- Right to Complain: Lodge a complaint with your local data protection authority
Rights for California Residents (CCPA/CPRA)
If you are a California resident, you have rights under the California Consumer Privacy Act and California Privacy Rights Act:
- Right to Know: Request disclosure of what personal information we collect, use, and disclose
- Right to Delete: Request deletion of your personal information
- Right to Correct: Request correction of inaccurate information
- Right to Opt-Out: We do not sell or share your personal information for cross-context behavioral advertising
- Right to Non-Discrimination: We will not discriminate against you for exercising your rights
Categories of Personal Information Collected: Identifiers (name, email), commercial information (services purchased), internet activity (analytics with consent), professional information (company name).
Categories Sold or Shared: None. We do not sell or share personal information.
How to Exercise Your Rights
To exercise any of these rights, please email us at mdalexandredlux@gmail.com with the subject line "Privacy Rights Request."
We will respond within:
- GDPR requests: 30 days (extendable by 60 days for complex requests)
- CCPA requests: 45 days (extendable by 45 days)
We may need to verify your identity before processing your request.
9. Data Security
We implement reasonable security measures to protect your personal information:
- Encryption in Transit: All data transmitted via our website uses HTTPS/TLS encryption
- Secure Hosting: Our website is hosted on Hostinger with standard security protections
- Access Controls: Only authorized personnel access client data on a need-to-know basis
- Secure File Sharing: Project files are shared via Google Drive with appropriate access permissions
- Secure Payments: Payments are processed through Wise or direct bank transfer; we do not store complete banking details
However, no method of transmission over the internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
In the event of a data breach affecting your personal information, we will notify you and relevant supervisory authorities as required by applicable law (within 72 hours for GDPR-covered breaches).
10. Third-Party Links and Services
Our website and services involve the following third-party services:
- Google Calendar Appointment Scheduling: For scheduling consultations — governed by Google's Privacy Policy
- Google Drive: For file sharing — governed by Google's Privacy Policy
- Google Analytics: For website analytics — governed by Google's Privacy Policy
- Google Fonts: For typography — governed by Google's Privacy Policy. Font files are loaded from Google servers when you visit our website.
We are not responsible for the privacy practices of these external services. We encourage you to review their respective privacy policies.
11. Children's Privacy
Our services are designed for businesses and professionals. We do not knowingly collect personal information from children under 13 years of age (or under 16 in the EEA).
If we become aware that we have collected information from a child, we will take steps to delete that information promptly. If you believe we may have collected information from a child, please contact us immediately.
12. International Data Transfers
DLux is based in the United States. If you are accessing our services from outside the United States, your information will be transferred to and processed in the United States.
For EEA/UK Users
When we transfer your data outside the EEA/UK, we rely on:
- Adequacy Decisions: Where applicable, transfers to countries deemed adequate by the European Commission
- Standard Contractual Clauses: For our service providers (Google) that have implemented EU Standard Contractual Clauses
You may request a copy of the safeguards we use by contacting us.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes:
- We will update the "Effective Date" at the top of this page
- For material changes, we will provide notice via email to existing clients or a prominent notice on our website
We encourage you to review this policy periodically. Your continued use of our website or services after changes constitutes acceptance of the updated policy.
14. Contact Us
If you have any questions about this Privacy Policy, our data practices, or wish to exercise your privacy rights, please contact us:
DLux
Data Controller
12202 Club Dr, APT 397
Tampa, FL 33612
United States
Email: mdalexandredlux@gmail.com
Privacy Rights Requests: Please use subject line "Privacy Rights Request"
We aim to respond to all inquiries within 30 days.
Supervisory Authority
If you are located in the EEA and believe we have not addressed your concerns adequately, you have the right to lodge a complaint with your local data protection supervisory authority.