Legal Documentation
Privacy Policy
Last updated: January 2026
1. Data Controller
LumistraSystems, located at Calle Trapería, 9, 30001 Murcia, España, is the data controller responsible for the processing of personal data collected through this website.
2. Data We Collect
We collect the following categories of personal data when you interact with our services: identification data (name, email address), communication data (messages, inquiries), technical data (IP address, browser type, device information), and usage data (pages visited, interaction patterns).
3. Purpose of Processing
Your personal data is processed for the following purposes: responding to inquiries and providing requested services, performing cybersecurity audits and assessments, maintaining communication regarding active engagements, complying with legal obligations, and improving our service delivery.
4. Legal Basis
Processing is based on: (a) consent given for specific purposes; (b) performance of a contract or pre-contractual measures; (c) compliance with legal obligations; (d) legitimate interests pursued by LumistraSystems in maintaining service quality and security.
5. Data Retention
Personal data is retained for the duration necessary to fulfill the purposes for which it was collected, or as required by applicable law. Financial records are retained for a minimum of 6 years in accordance with Spanish tax regulations.
6. Data Security
LumistraSystems implements appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. This includes encryption, access controls, and regular security assessments.
7. Your Rights
Under GDPR, you have the right to: access your personal data, rectify inaccurate data, request erasure (right to be forgotten), restrict processing, data portability, object to processing, and lodge a complaint with the Spanish Data Protection Authority (AEPD).
8. Contact
For any privacy-related inquiries, contact us at [email protected] or write to: LumistraSystems, Calle Trapería, 9, 30001 Murcia, España.
Refund Policy
Last updated: January 2026
1. Service Delivery
LumistraSystems delivers cybersecurity services as specified in the agreed scope of work. All services are performed with due professional diligence in accordance with industry standards.
2. Refund Eligibility
Refunds are evaluated on a case-by-case basis. Partial refunds may be granted if: (a) the service was not delivered as specified in the contract; (b) the scope of work was materially different from what was agreed upon; (c) the engagement was terminated before service delivery for reasons attributable to LumistraSystems.
3. Non-Refundable Items
The following are not eligible for refunds: services already rendered and accepted, deliverables that have been delivered and approved, third-party licensing fees, and consultancy hours that have been utilized.
4. Requesting a Refund
To request a refund, contact us at [email protected] with your contract reference and reason for the request. Refund requests must be submitted within 30 days of the invoice date.
5. Processing Time
Approved refunds will be processed within 14 business days to the original payment method. LumistraSystems reserves the right to deduct administrative fees where applicable.
Terms of Service
Last updated: January 2026
1. Acceptance of Terms
By accessing or using the services provided by LumistraSystems, you agree to be bound by these Terms of Service. If you do not agree to these terms, do not use our services.
2. Scope of Services
LumistraSystems provides cybersecurity services including but not limited to penetration testing, vulnerability assessments, SOC monitoring, incident response, compliance consulting, and security architecture design. Service specifications are defined in individual statements of work.
3. Client Obligations
The client shall: provide accurate and complete information required for service delivery, ensure timely access to relevant systems and personnel, obtain necessary authorizations for testing activities, and maintain confidentiality of all reports and findings.
4. Intellectual Property
All reports, methodologies, and deliverables produced by LumistraSystems remain the intellectual property of LumistraSystems. The client receives a non-exclusive license to use the deliverables for their internal purposes. Custom tooling and scripts developed during engagements remain property of LumistraSystems unless otherwise agreed in writing.
5. Confidentiality
Both parties agree to maintain the confidentiality of all information exchanged during the engagement. LumistraSystems shall not disclose client data to third parties without prior written consent, except as required by law.
6. Limitation of Liability
LumistraSystems' total liability under any engagement shall not exceed the total fees paid by the client for the specific service giving rise to the claim. LumistraSystems shall not be liable for indirect, consequential, or incidental damages.
7. Governing Law
These terms are governed by the laws of Spain. Any disputes arising from these terms or the services provided shall be subject to the exclusive jurisdiction of the courts of Murcia, España.
8. Modifications
LumistraSystems reserves the right to modify these Terms of Service at any time. Changes will be effective upon posting on this website. Continued use of our services constitutes acceptance of the modified terms.