Lumina Privacy Notice
About this notice
Last updated: 29/05/24
Amba is committed to your privacy. This privacy policy (“Privacy Policy”) is meant to help you understand what personal data we collect about you, how we use that personal data, including how to access and update your information.
We respect and value the privacy of everyone who visits this website and its subdomains, subdomain.lumina-uk.com (“Our Site”), and will only collect and use personal data in ways that are described here, and in a manner that is consistent with Our obligations and your rights under the law.
Please read this Privacy Policy carefully and ensure that you understand it. Your acceptance of our Privacy Policy is deemed to occur upon your first use of Our Site. If you do not accept and agree with this Privacy Policy, you must stop using our site immediately.
About us
In this policy ‘Amba’, ‘We’, ‘Us’, ‘Our’ means Amba People Limited, company number 4316451, registered office85 Great Portland Street, First Floor, London, W1W 7LT . Our Site is owned and operated by Amba.
We are contracted by your employer to administer some or all of your employee benefits scheme on their behalf. For the purposes of applicable data protection laws Amba are a “Data Processor” under contract by your employer the “Data Controller”.
If you have any questions about our site or this Privacy Policy, please contact us by email at privacy@amba-uk.com ; by telephone on 01454 808658, or by post at 85 Great Portland Street, First Floor, London, W1W 7LT
What does this policy cover?
This Privacy Policy applies only to your use of Our Site and email communications sent to you about your access to the Lumina platform. It relates to personal data which means any and all data that relates to an identifiable person who can be directly or indirectly identified from that data. In this case, it means personal data provided to us by your employers and that you give to Us via Our Site. This definition shall, where applicable, incorporate the definitions provided in the Data Protection Act 2018 incorporating the UK-GDPR.
Our Site may contain links to other websites. Please note that We have no control over how your data is collected, stored, or used by other websites and We advise you to check the privacy policies of any such websites before providing any data to them.
Your rights
You have the following rights under the Data Protection Act 2018/UK-GDPR, which this Policy and Our use of personal data have been designed to uphold:
- The right to be informed about Our collection and use of personal data;
- The right of access to the personal data We hold about you (see How can you access your data?);
- The right to rectification if any personal data We hold about you is inaccurate or incomplete (please contact Us using the details below);
- The right to erasure – i.e. the right to ask Us to delete any personal data We hold about you (We only hold your personal data for a limited time, as explained in section but if you would like Us to delete it sooner, please contact Us using the details below);
- The right to restrict (i.e. prevent) the processing of your personal data;
- The right to data portability (obtaining a copy of your personal data to re-use with another service or organisation);
- The right to object to Us using your personal data for particular purposes; and
- Rights with respect to automated decision making and profiling.
If you have any cause for complaint about Our use of your personal data, please contact Us using the details provided in the section below and We will do Our best to solve the problem for you. We may need to refer you to your HR department or relevant data protection contacts within your organisation if it relates to something outside of our control.
If We are unable to help, you also have the right to lodge a complaint with the UK’s supervisory authority, the Information Commissioner’s Office.
For further information about your rights, please contact the Information Commissioner’s Office or your local Citizens Advice Bureau.
What data do we collect?
This site contains personal data provided to us by your employer so that we can operate your lumina platform. This data may include some or all of the following personal data dependent on the service your employer has chosen:
First name
Last name
Email address
We may also collect the following personal data to monitor performance of our site
IP address
Web browser type and version
Operating system
How do we use your data?
All personal data is processed and stored securely, for no longer than is necessary in light of the reason(s) for which it was first collected. We will comply with Our obligations and safeguard your rights under the UK-GDPR at all times. More details on security are provided below.
Our use of your personal data will always have a lawful basis, which is performance of a contract (e.g. provision of employee benefits to you). Specifically, We may use your data for the following purposes:
Analysing your use of Our Site and gathering anonymous feedback to enable Us to continually improve Our Site and your user experience.
You have the right to object to Us using your personal data at any time, and to request that We delete it. This request should be made to your employers HR department or relevant data protection contact as they are the Data Controller for your personal data and we can only act on instruction from them. Please be aware that by objecting you will not be able to access your employer’s employee benefit scheme online and take advantage of the benefits available to you.
You may unsubscribe or opt-out of employee communications from Us at any time by using the unsubscribe link in our emails. Please note opt out will not affect informational emails sent out by the Lumina platform which provide information about actions you take in the system, transactions you enter into, and your account information.
How long and where do we store your data?
We only keep your personal data for as long as We need to in order to use it as described above, and/or for as long as We have your permission to keep it.
Your Data will therefore be retained for the following periods:
- Your personal details and benefit selections will be retained until 2 years after you leave the employment of your company. This is to allow us to service benefit scheme year end and financial year end reporting requests from your employer. Please note processing of your personal data will stop one month after your leave date.
- We utilise cloud services, such as Microsoft to process and store your data, which is located in data centres in the UK and Europe.
- Where We do store data outside the UK, We will take all reasonable steps to ensure that your data is treated as safely and securely as it would be within the UK and under the UK GDPR e.g. by ensuring our data processors have adequate data protection mechanisms in place such as Binding Corporate Rules, Standard Contractual Clauses or Adequacy Regulations.
- You are deemed to accept and agree to this by using Our Site and submitting information to Us.
Data Security
Data security is very important to Us, and to protect your data We have taken suitable measures to safeguard and secure data collected through Our Site.
Steps We take to secure and protect your data include:
- Your personal data is only accessible to Amba employees, contractors, agency staff that need to access it to do their jobs. All Amba staff are bound by a confidentiality agreement.
- We comply with and certify to relevant security standards, including Cyber Essentials and IASME Cyber Assurance. Further details regarding these standards can be found at https://www.iasme.co.uk.
- The Lumina platform uses an SSL certificate to ensure a secure connection when users login and data is uploaded.
- Initial access to the Lumina for Employees is by invitation in the welcome email. The Employee must set a strong password. The link in the welcome email is only active for 30 days and can only be used once.
- All user passwords must be strong and must be a minimum of 8 characters, include at least 1 , lower case, number and special character.
- All user sessions (both employee or administrators) timeout after 10 minutes of inactivity. Amba employ development methods that seek to minimise the threat from cross site scripting and SQL injection.
- There is a robust permissions model to prevent unauthorised access to personal data from different clients.
- Penetration tests of the Lumina platform are conducted by external company each year.
- Data is backed up daily and a copy stored off site. All backup data is stored in the UK. Please see “How long and Where Do We Store Your Data?” for more information.
- We carrying out security vetting of our benefit providers and sub processors to ensure that your personal data is handled in line with UK-GDPR.
Do we share your data?
We may share your data with other companies in Our group to provide you with your employee benefits and answer your queries. This includes Amba Health & Wellbeing Limited and Amba Money Limited.
We will share your data with the third parties that provide the benefits that you have selected / your employer provides you with.
We do not share your data with any other third parties.
In certain circumstances, We may be legally required to share certain data held by Us, which may include your personal data, for example, where We are involved in legal proceedings, where We are complying with legal obligations, a court order, or a governmental authority.
We may compile statistics about the use of Our Site including data on traffic, usage patterns, user numbers, and other information. All such data will be anonymised and will not include any personally identifying data, or any anonymised data that can be combined with other data and used to identify you. We may from time to time share such data with third parties such as prospective investors, affiliates, partners. Data will only be shared and used within the bounds of the law.
What happens if our business changes hands?
We may, from time to time, expand or reduce Our business and this may involve the sale and/or the transfer of control of all or part of Our business. Any personal data that you have provided will, where it is relevant to any part of Our business that is being transferred, be transferred along with that part and the new owner or newly controlling party will, under the terms of this Privacy Policy, be permitted to use that data only for the same purposes for which it was originally collected by Us.
In the event that any of your data is to be transferred in such a manner, you will be contacted in advance and informed of the changes.
How can you control your data?
In addition to your rights under the GDPR, set out above, when you submit personal data via Our Site, you may be given options to restrict Our use of your data. In particular, We aim to give you strong controls on Our use of your data for communications purposes (including the ability to opt-out of receiving emails from Us which you may do by unsubscribing using the links provided in Our emails.
Your right to withhold information
You may restrict Our use of Cookies. For more information, see the section our cookie policy below.
How can you access your data?
You have the right to ask for a copy of any of your personal data held by Us. We will forward your request to your HR department to request permission to provide the information to you (We need to do this as your employer is the data controller and we can only act on their instruction). We will provide any and all information in response to your request free of charge and within 30 days. You can contact us using the contact details below.
How can you correct your data?
You have a right to request that your personal data is updated if it is incorrect. All of the personal data we hold about you is provided by your employer and sent to us on a regular basis. If information we hold about you is incorrect, please contact your HR department to get the data corrected. This will mean that we are provided with your updated data on the next data load.
Contact details
If you have any questions about Our Site or this Privacy Policy, or wish to access your data please contact Us
by email at privacy@amba-uk.com
by telephone on 01454 808658, or
by post at85 Great Portland Street, First Floor, London, W1W 7LT .
Please ensure that your query is clear, particularly if it is a request for information about the data We hold about you.
Changes to our privacy policy
We may change this Privacy Policy from time to time (for example, if the law changes). Any changes will be immediately posted on Our Site and you will be notified to review and accept these changes. In the event you have a query regarding these changes please raise this to us using the Contact details above or speak to your employers HR Department / Data Protection contact. If you do not accept the changes to our privacy policy you will not be able to continue using Our Site.
Our Cookie Policy
What is a cookie?
A cookie is a small file placed onto your device that enables happypeople.co.uk features and functionality. For example, cookies enable us to identify your device, secure your access to the Employee Benefits portal. Any browser visiting our website will receive cookies from us.
If you want to find out more about cookies, including how to see what cookies have been set and how to manage and delete them, visit www.allaboutcookies.org , or www.aboutcookies.org .
Does the Lumina platform use cookies?
Yes. we use cookies to ensure everyone who uses the lumina portal has the best possible experience. Cookies help us keep your account safe. By continuing to visit or use our website you are agreeing to the use of cookies for the purposes we describe below.
Types of Cookie
We use two types of cookie: persistent cookies and session cookies. A persistent cookie helps us recognize you as an existing user, so it’s easier to return to the employee benefit portal. Session cookies only last for as long as the session (usually the current visit to a website or a browser session).
Strictly Necessary Cookies
These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as logging in or filling in forms
These cookies do not store any personally identifiable information. Below is a list of strictly necessary cookies.
Categories of Use |
Cookie Name |
Description / Purpose |
Cookie Type |
Expiration |
User Session |
.Amba.Aith |
Secured login token for active user session within the Dashboard. |
Necessary |
14 days |
User Session |
.AspNetCore.AntiForgery.xxxxxxxxxx |
Current user session authentication for validating the origin of data posted web pages. |
Necessary |
Immediate |
User Session |
saml-session |
Unique user token for SAML 2.0 sessions. |
Necessary |
Immediate |
Performance Cookies
These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. The information we get through the use of these cookies is anonymised and we make no attempt to identify you, or influence your experience of the site while you are visiting it. If you do not allow these cookies we will not be able to include your visit in our statistics.
How to control cookies
Most browsers allow you to control cookies through their settings preferences. By default, most internet browsers accept Cookies but this can be changed. For further details, please consult the help menu in your internet browser or the documentation that came with your device.
However, if opt out of the strictly necessary cookies listed above you will be unable to use our website as they are critical to the functioning of the site.
You can choose to delete Cookies on your computer or device at any time, however you may lose any information that enables you to access Our Site more quickly and efficiently including, but not limited to, login and personalisation settings.
It is recommended that you keep your internet browser and operating system up-to-date and that you consult the help and guidance provided by the developer of your internet browser and manufacturer of your computer or device if you are unsure about adjusting your privacy settings.
Congratulation on reading our Cookie Policy, now get back out there and save the planet!