This policy outlines Dragonfish’s commitment to ensuring the security and safety of data within the Lumin platform. It applies to all Dragonfish employees, contractors, and third-party developers who access, use, or manage the Lumin platform and its data. This policy specifically addresses the unique characteristics of Lumin, where the primary data comprises anonymised survey response data. All personal data, if ever collected, is anonymised at source. This means that no personally identifiable data is captured at any point in the process.
● Anonymised Data: Data that does not relate to an identified or identifiable natural person and cannot be re-identified by any means reasonably likely to be used.
● Authorised Personnel: Individuals granted access to Lumin based on business need and role.
● Third-Party Developers: External developers contracted to build or maintain aspects of the Lumin platform under data protection and confidentiality agreements.
● Data Subject Rights: Rights under GDPR such as access, rectification, and erasure, which do not apply to fully anonymised data.
Due to the anonymised nature of data processed by Lumin, data subject rights do not apply to survey responses, as Dragonfish does not retain any personally identifiable information. Nonetheless, Dragonfish still ensures it continues to uphold best practices as required by the UK GDPR and the Data Protection Act 2018. Where applicable, this may include consent or legitimate interests. Important note on reporting thresholds: While the Lumin platform is designed to collect and report anonymised data, Dragonfish actively reviews reporting levels to ensure that aggregated results do not risk indirect identification. Suppression thresholds and segmentation filters are managed to prevent any possibility of re-identification. Dragonfish regularly consults legal guidance, including best practice from the ICO, the EU Data Protection Board, and the GDPR, to ensure that its handling of small-group reporting remains compliant with the principle of data minimisation and does not constitute personal data processing. For any questions or concerns regarding data protection, please contact our Data Protection Officer, at dpo@dragonfishuk.com
Dragonfish is unequivocally committed to maintaining the anonymity of survey respondents. Key anonymity safeguards include:
Data Hosting and Infrastructure The Lumin platform and its database are hosted on Amazon Web Services (AWS), utilising:
AWS is a widely trusted cloud provider used by major enterprises and governments worldwide. The data is currently hosted in the “Europe (London) – eu-west-2” region. This region was selected to balance performance, data residency, and compliance.
Server-Level Protections
Application-Level Protections
Data in Transit
Data at Rest
Access Control
Secure Development Practices
Vulnerability Management
Logging and Monitoring
Dragonfish ensures that all data is stored and processed in compliance with applicable data protection regulations. The Lumin platform’s data is hosted in the “Europe (London) – eu-west-2” AWS region, aligning with the UK GDPR and other relevant data residency requirements. AWS provides a range of compliance certifi cations and adheres to international standards, ensuring that our infrastructure meets stringent security and privacy obligations.
Downloaded data is safely stored on Egnyte’s cloud platform in secure, ISO-certifi ed data centers spread across multiple locations. Built-in redundancy ensures reliability, while strong encryption protects data both at rest and in transit. Access is tightly controlled, so only authorised personnel can retrieve or make changes.
All third-party developers are contractually bound by strict data security and confi dentiality clauses. Controls include:
Unless otherwise agreed with the client, data is retained for six (6) years to support:
After this period:
All data is disposed of in line with Dragonfish’s secure disposal practices to prevent recovery.
Dragonfish is committed to ensuring data security and promptly addressing any security incidents that may arise. We continually monitor and manage security risks to protect the privacy of our users and their data.
All client engagements involving the Lumin platform are governed by contractual Terms & Conditions that refl ect the security and privacy commitments in this policy. These include liability provisions, limitations on data access, and data protection measures. Dragonfish maintains appropriate professional and cyber liability insurance to cover risks associated with data handling, anonymisation breaches, and service disruption.
This data security and safety policy will be reviewed and updated periodically to refl ect any changes in our practices, technologies, or legal requirements. The date of the last review is 25th April 2025. Dragonfish will communicate any signifi cant changes to this policy through appropriate channels.