Privacy Policy

1. Who We Are

Luma Wellness Studios (“Luma”, “we”, “us”, “our”) operates 24/7 unstaffed, members-only wellnessstudios in Ireland offering automated spray tanning, red light therapy and hydro massage services,accessed via our member app and secure door entry system.

For the purposes of the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act2018, Luma Wellness Studios is the data controller of your personal data.

Controller: [Luma Wellness Studios Ltd / legal entity name], [registered address], Ireland. Company registration no. [CRO number].

Privacy contact: privacy@lumaglow.ie · +353 [phone]

2. Scope of This Policy

This policy explains how we collect, use, share and protect personal data when you:

• Visit our website at lumaglow.ie, including when you register interest or sign up for a foundingmembership;

• Create an account or book services through our member app;

• Enter and use our studios, including via our door access system and on-site CCTV;

• Pay for memberships or pay-as-you-go services;

• Communicate with us by email, phone, social media or in-app messaging.

3. Personal Data We Collect

Examples: Name, email address, phone number, date of birth (to verify you are 18+)

Source: You

Examples: Username, membership tier, booking history, founding member status

Source: You / Our Booking Platform

Examples: Bank account (IBAN) for SEPA Direct Debit, card details, billing history. Full payment details are processed by our payment provider; we never store full card or bank credentials ourselves.

Source: You / Payment Provider

Examples: Door entry events (date, time, studio, credential used), booking check-ins, app usage logs

Source: Access Control & App Systems

Examples: Contraindication questionnaire responses (e.g. skin conditions, pregnancy, photosensitising medication) completed before using spray tan or red light services

Source: You

Examples: Video footage of studio common areas (never treatment rooms)

Source: On-site cameras

Examples: IP address, device type, cookie identifiers, pages visited, ad interaction data

Source: Cookies & similar technologies

Examples: Emails, support requests, survey responses, reviews

Source: You

Special category (health) data

Safety questionnaire responses may reveal information about your health. This is “special category data” under Article 9 GDPR. We collect it only with your explicit consent, and only to confirm the services are safe for you to use. You may withdraw consent at any time, though we may then be unable to provide the relevant service.

Children

Our services and website are not directed at anyone under 18. We do not knowingly collect personal data from minors, and membership requires confirmation that you are 18 or over.

4. How We Use Your Data and Our Legal Bases

Creating and managing your membership account, bookings and access credentials

Contract (Art. 6(1)(b))

Processing payments and managing SEPA Direct Debit mandates

Contract (Art. 6(1)(b)); legal obligation (Art.6(1)(c)) for financial records

Screening health contraindications before spray tan / red light use

Explicit consent (Art. 9(2)(a))

Operating door access and verifying that only membersenter unstaffed studios

Contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) in site security

CCTV monitoring of common areas for member safety, security and incident investigation

Legitimate interests (Art. 6(1)(f))

Sending service messages (booking confirmations, access issues, safety notices)

Contract (Art. 6(1)(b))

Marketing emails and founding member offers

Consent (Art. 6(1)(a)); you may opt out at any time

Website analytics and advertising measurement (e.g. Meta advertising)

Consent (Art. 6(1)(a)) via our cookie banner

Improving our services, demand analysis and business planning (aggregated where possible)

Legitimate interests (Art. 6(1)(f))

Establishing, exercising or defending legal claims; complying with law

Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f))

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You can request details of these assessments using the contact details above.

5. CCTV in Unstaffed Studios

Because our studios operate without staff on site, CCTV is an important safety and security measure. Cameras cover entrances and common areas only. Cameras are never installed in treatment rooms, and signage at each studio identifies the areas under surveillance and the data controller.

Footage is retained for [30] days and then automatically overwritten, unless required for the investigation of an incident, a legal claim or a request from An Garda Síochána, in which case the relevant footage is preserved for as long as necessary.

6. Who We Share Your Data With

We do not sell your personal data. We share it only with:

Service providers (processors): our booking and membership platform, door access provider, payment processor, email and hosting providers, and analytics / advertising platforms — each under contracts requiring them to protect your data and act only on our instructions;

Professional advisers: insurers, lawyers, accountants and auditors where necessary;

Authorities: the Revenue Commissioners, the Data Protection Commission, An Garda Síochána orother bodies where we are legally required to do so;

Business transfers: a buyer or investor in the event of a sale, merger or reorganisation of our business, subject to appropriate safeguards.

7. International Transfers

Some of our service providers process data outside the European Economic Area (for example, in the United States). Where this happens, we ensure appropriate safeguards are in place, such as European Commission adequacy decisions (including the EU–US Data Privacy Framework where applicable) or Standard Contractual Clauses, together with additional measures where required. You can request a copy of the relevant safeguards using the contact details above.

8. How Long We Keep Your Data

Duration of membership + [6] years (limitationperiod for contract claims)

[6] years after the relevant tax year (Revenue requirements)

Duration of membership + [2] years, then deleted

[12] months

[30] days (unless preserved for an incident)

Until you unsubscribe or [2] years of inactivity

As set out in our Cookie Policy

When data is no longer needed, we delete or irreversibly anonymise it.

9. How We Protect Your Data

We use appropriate technical and organisational measures including encryption in transit, access controls limiting who at Luma can see your data, reputable third-party platforms with strong security certifications, and secure disposal of data at the end of its retention period. No system is completely secure, but we will notify you and the Data Protection Commission of any breach where legally required.

10. Your Rights

Under the GDPR you have the right to:

• Access the personal data we hold about you, and receive a copy;

• Rectify inaccurate or incomplete data;

• Erase your data in certain circumstances (“right to be forgotten”);

• Restrict processing in certain circumstances;

• Data portability — receive data you provided in a structured, machine-readable format;

• Object to processing based on legitimate interests, and to direct marketing at any time;

• Withdraw consent at any time, without affecting processing carried out before withdrawal;

• Not be subject to solely automated decisions producing legal or similarly significant effects.

To exercise any right, contact privacy@lumaglow.ie. We will respond within one month (extendable by two further months for complex requests). We may ask you to verify your identity first. Exercising these rights is free of charge except in cases of manifestly unfounded or excessive requests.

Complaints

If you are unhappy with how we handle your data, please contact us first so we can try to resolve it. You also have the right to lodge a complaint with the Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28 · www.dataprotection.ie.

11. Cookies and Similar Technologies

Our website uses cookies and similar technologies for essential functionality, analytics and advertising measurement (including the Meta Pixel). Non-essential cookies are set only with your consent, which you can give, refuse or withdraw at any time via our cookie banner. Full details are set out in our separate Cookie Policy at [link].

12. Changes to This Policy

We may update this policy from time to time. Material changes will be notified by email or in-app notice before they take effect, and the “effective date” above will be updated. The current version is always available at lumaglow.ie/privacy.