Committed to responsible data handling for clients and visitors.

General Privacy Statement

Lumoria operates the website fyvora.pro and provides legal advisory services to IT companies from our office at 169 Stirling Road, Singapore, 140169. This policy explains what personal data we collect, why we collect it, how it is used, and the practical scenarios where data is processed. The approach is example-led: we explain typical cases such as onboarding a new SaaS client, conducting a vendor due diligence, or responding to a data incident, and what data handling steps apply in those scenarios.

Effective date 16-03-2026
Data controller Lumoria (Business ID S2086052A), 169 Stirling Road, Singapore, 140169
Contact email [email protected]
Postal address 169 Stirling Road, Singapore, 140169
01

Key definitions

This section explains terms used in the policy through short examples and practical context to clarify how each term appears in routine engagements.

Personal data means information that identifies or can reasonably identify an individual. Example: the contact details of a company representative (name, email, phone) we use to communicate about a contract review.
Processing covers any operation performed on personal data, such as collection, storage, analysis or sharing. Example: redacting personal identifiers in a contract during due diligence is processing.
User refers to visitors of fyvora.pro and individuals we interact with as part of client engagements, such as company representatives, contractors and potential candidates.
Service means the legal advisory and related resources we provide, including contract drafting, compliance assessments and incident response planning for IT companies.
Cookies are small files placed on a device to hold basic information used to improve site functionality and gather usage metrics. We use them for analytics and session management.
02

What data we collect

We collect personal data in scenarios common to legal advisory work. Below are the categories of information typically obtained and examples illustrating when each category is used.

03

Data you provide

Data you provide directly typically arises from client intake, meetings, onboarding forms and document submission. Examples show how each data type is used in practice.

  • Contact details: names, corporate email addresses and telephone numbers used to schedule consultations and send legal deliverables. Example: scheduling a contract negotiation session with a product manager.
  • Company information: corporate registration numbers (we store Business ID S2086052A for Lumoria), legal entity names and addresses for engagement letters and invoices.
  • Contract documents and attachments: agreements, SOWs, IP assignment records and technical specifications provided during reviews or drafting work.
  • Onboarding and billing details: invoicing address and payment contact for arranging professional fees in the scope of a retained advisory plan.
  • Incident reports and case materials: summaries of security events, relevant logs or notifications necessary for incident response and legal assessment.
  • Communication records: meeting notes, emails and chat transcripts arising from advisory engagements to maintain an accurate project history.
04

Data collected automatically

Some information is collected automatically when you use our website or services; examples below show when and why these data points are recorded.

  • Usage data: pages visited, session duration and navigation paths on fyvora.pro collected to analyze content relevance and improve guidance examples.
  • Device and browser information: device type, browser version and IP address used for site security monitoring and to troubleshoot access issues.
  • Performance metrics: error logs and upload/download times that help us refine document submission workflows and client portal reliability.
  • Analytics identifiers: anonymous identifiers used by analytics tools to understand aggregate behavior for case study development.
  • Session cookies: used to keep you logged in to secure client resources during an advisory engagement.
  • Access logs: timestamped records of file access for auditing in response to client inquiries or billing reviews.
05

Data from third parties

We sometimes receive data about individuals from third parties as part of practical engagements such as due diligence or procurement. Examples clarify the typical sources and uses.

  • Partner referrals: contact information shared by trusted partners when introducing prospective clients for contract advisory services.
  • Vendor-supplied documents: technical or compliance reports provided by a vendor during a contract negotiation or assessment.
  • Public sources: information from public registries and corporate filings used to verify entity details during onboarding.
06

Why we use personal data

We process personal data for clearly defined purposes tied to delivering legal advisory services. Each purpose is illustrated with a scenario so you can see when and why we act.

  • To provide legal advice and drafting services: using contact and contract data to prepare and deliver redlines, memos and templates in client engagements.
  • To communicate with clients and prospects: scheduling, follow-ups and clarifications related to ongoing matters and proposal discussions.
  • To perform due diligence and risk assessments: analyzing documents and metadata during vendor or commitment checks to identify key contractual risks.
  • To manage billing and administrative needs: invoicing and payment processing aligned with delivered services and retained advisory plans.
  • To improve our services: aggregating anonymized usage data and feedback to refine templates, checklists and real-case resources.
  • To fulfill legal or regulatory obligations: responding to lawful requests from authorities or complying with recordkeeping requirements relevant to legal practice.
  • To conduct incident response and remediation: using incident reports and communication logs to coordinate legal and technical response in practice exercises or real events.
  • To protect our rights and those of third parties: processing necessary information in dispute scenarios or to enforce contractual terms.
07

Legal bases for processing

We rely on appropriate legal grounds to process personal data depending on the scenario: contract performance, legitimate interests, compliance with law, or consent where requested. Below are practical examples mapping each basis to common activities.

  • Contract performance: processing contact and contract details is necessary to perform the engagement (for example, drafting agreements and delivering advisory deliverables).
  • Legitimate interests: processing analytics data and maintaining access logs to improve service reliability and prevent fraud, balanced against individual privacy interests.
  • Legal obligation: retaining certain records to comply with applicable professional conduct rules or tax obligations during billing and recordkeeping.
  • Consent: where specific marketing communications or optional surveys are conducted, we ask for consent and provide an easy way to opt out.
08

Cookies and similar technologies

We use cookies to operate the website, protect sessions and gather analytics. Examples show how cookies support client portal sessions and content personalization.

Types include essential session cookies for authentication, analytics cookies for aggregated site performance, and optional preference cookies for saved settings.

Categories: essential (required for site operation), analytics (used to understand aggregate behavior), and preferences (remember layout or language choices).

You can manage cookies via your browser settings and opt out of analytics cookies through the cookie banner where applicable. Turning off essential cookies may affect access to client resources.

Full cookie policy and management options

09

How we share data

We share personal data only as required for a specific purpose and typically under confidentiality terms. Sharing scenarios and safeguards are described below.

  • With service providers: sharing contact and document metadata with secure cloud storage providers and accounting services under data-processing agreements.
  • With clients and counterparties: sharing redacted or necessary contract materials with counterparties during negotiation when instructed by the client.
  • With legal or regulatory authorities: disclosing information when required by law or in response to valid legal process.
  • With external advisors: sharing limited information with forensic experts, translators or technical consultants under confidentiality to support a specific engagement.
  • During a corporate transaction: sharing required data with potential buyers or advisers under controlled due diligence arrangements and confidentiality protections.
  • With marketing processors: sending newsletter recipients' emails to a third-party mailing platform only with consent and in accordance with opt-out choices.
10

Cross-border transfers

Some processing involves transferring data to service providers outside Singapore to perform hosting, analytics or specialist advisory work. For instance, encrypted documents may be stored by a cloud provider with an international footprint during a contract review.

We apply contractual safeguards, access controls and encryption. Where required, we evaluate adequacy of protections and include contractual terms to limit onward sharing. Transfers are only made after assessing the practical necessity and risk.

11

How long we keep data

Retention policies are tied to practical needs and regulatory requirements. We retain different categories of data for specific periods informed by case scenarios and administrative needs.

Client account records and engagement letters are retained for a minimum of seven years after the end of the engagement, to support billing records and potential professional obligations arising from past matters.

Communications and advisory deliverables are kept for the duration of the engagement plus three years to enable continuity in follow-up matters and to reference prior advice in similar case scenarios.

Access logs, system logs and security records are retained for two years to support incident contribute and to provide evidence in case management reviews.

When retention periods expire, personal data is securely deleted or anonymized unless legal obligations require longer retention. For example, documents involved in active disputes may be retained until resolution.

12

Security measures

We apply industry-standard administrative, technical and physical measures to protect personal data relevant to legal advisory work. This includes access controls, encrypted storage, secure transmission, regular vulnerability assessments and documented incident response practices informed by tabletop exercises and prior cases.

  • Access control and role-based permissions: limiting who may view client documents based on the engagement scenario.
  • Encryption in transit and at rest: protecting documents and communications when platform with clients and third-party processors.
  • Regular backups, monitoring and periodic security reviews demonstrated through practical audits and incident simulations.
13

Your rights

You have rights regarding your personal data. Below are the typical remedies and how they apply in real scenarios such as correcting an invoice contact or requesting copies of your submitted documents.

  • Access: you can request a copy of personal data we hold about you, subject to verification and any legal limitations relating to third-party confidentiality.
  • Rectification: you may ask us to correct inaccurate or incomplete personal data, for example when a contact email changes during an ongoing matter.
  • Erasure: in specific cases you may request deletion where data is no longer necessary and there is no overriding legal reason to retain it.
  • Restriction: you may request restriction of processing for certain purposes while a dispute over accuracy is resolved.
  • Objection: you may object to certain processing based on legitimate interests, and we will evaluate the request in the context of the engagement and legal obligations.
  • Data portability: where technically feasible, we can provide your personal data in a commonly used structured format to support transfer to another provider, for example when closing an advisory relationship.
  • Right to restriction of processing — request temporary limitation of processing where accuracy is contested or processing is unlawful but you object to erasure.
  • Right to withdraw consent at any time for specific processing activities where consent is the legal basis; withdrawal does not affect processing prior to withdrawal.
14

Applicable legal framework

Although Singapore is not subject to EU GDPR, Lumoria applies GDPR-aligned principles to clients in cross-border IT engagements. This section explains how Lumoria approaches data subject rights, lawful bases for processing, and cross-border transfers when handling personal data related to EU residents as part of IT projects or advisory services.

GDPR-aligned practices are applied by Lumoria when we process personal data originating from EU residents in the context of IT services, product compliance reviews, or contractual obligations. Applicability is assessed case-by-case and documented in engagement letters or data processing addenda where relevant.

  • Lawful basis assessment — Lumoria documents the legal basis for each processing activity relevant to cross-border IT projects, such as contract performance or legitimate interest assessments supported by balancing tests.
  • Data minimisation — in contracts and project design we advise IT companies on collecting only necessary data for the stated purpose and on anonymisation where feasible.
  • Transfer safeguards — where transfers from the EEA are involved we recommend appropriate safeguards such as standard contractual clauses, and document risk assessments for cross-border transfers.
  • Data subject rights procedures — Lumoria maintains procedures to respond to access, deletion, and portability requests arising from GDPR-aligned engagements, coordinating with client obligations and local law.

If you believe Lumoria has not handled a GDPR-related request appropriately in the context of services we provide, contact our data protection officer for an internal review. For unresolved issues involving EU residents, supervisory authorities in the relevant EEA member state may be contacted in accordance with GDPR procedures.

15

How to exercise your privacy rights

To exercise rights such as access, rectification, erasure, restriction, objection or portability in relation to data processed by Lumoria, submit a written request describing the request and identifying relevant data or project references. Include a copy of government-issued photo ID where necessary to verify identity and protect other clients' confidentiality.

[email protected]

Lumoria aims to respond to verified rights requests within 30 days of receipt. Complex requests or those requiring coordination with third parties may take longer; when this occurs we will notify you of an expected extension and reasons for the delay.

16

Marketing communications

Lumoria may send communications about legal updates, events, or services relevant to IT companies. We tailor marketing content to demonstrate practical scenarios, case studies, and compliance pathways that IT leaders can apply to their operations.

You can opt out of marketing at any time by following the unsubscribe link in our emails or by sending a request to [email protected]. Unsubscribing from marketing will not affect transactional communications about your active engagements.

17

Children's data

Lumoria does not knowingly offer advisory services directly to children or intentionally collect personal data of minors for our IT legal services. If we learn that we have collected personal data of a child without appropriate parental consent in a way that violates applicable law, we will take steps to remove that data where practicable.

18

Third-party links

Our website and client resources may link to third-party sites and tools used in IT governance or compliance workflows. Lumoria is not responsible for external content or the privacy practices of those third parties; review their privacy policies before sharing personal data.

19

Changes to this privacy policy

Lumoria may update privacy practices to reflect regulatory changes, client needs, or operational practices. Material changes affecting client data handling will be documented and communicated via email or client portals; non-material updates will be posted on fyvora.pro.

Hello — welcome to Lumoria. If you have a contract or IP scenario, tell us briefly and we will outline practical next steps.