Data Protection & Security
Effective Date: July 24, 2026
Last Updated: July 24, 2026
Confidentiality is foundational to trusted executive advisory relationships. Clients and prospective clients may share sensitive information involving finances, operations, ownership, employees, growth plans, transactions, succession, technology, and competitive strategy. LumaKa Advisors, a trade name of LumaKa Ventures LLC, is committed to handling that information responsibly and maintaining safeguards proportionate to its sensitivity and our role.
1. Our Security Principles
· Data Minimization. We seek to collect and retain only information reasonably necessary for a defined business or engagement purpose.
· Purpose Limitation. We use information for legitimate business, advisory, contractual, security, and legal purposes.
· Need-to-Know Access. Access should be limited to authorized individuals who require information to perform their responsibilities.
· Defense in Depth. We use a combination of administrative, technical, contractual, and physical safeguards rather than relying on a single control.
· Responsible Retention. Information should not be retained indefinitely without a legitimate reason.
· Vendor Accountability. Providers with access to sensitive information should be selected and managed with due consideration of security, confidentiality, and reliability.
· Incident Preparedness. We seek to maintain procedures for identifying, escalating, responding to, and learning from security incidents.
2. Administrative Safeguards
· Confidentiality obligations for personnel and contractors, as appropriate.
· Role-based access decisions and periodic review of access.
· Security awareness practices covering phishing, password hygiene, sensitive-data handling, and incident reporting.
· Written or documented operating procedures proportionate to the size and nature of the firm.
· Evaluation of material security risks when adopting new systems or vendors.
· Business-continuity and recovery considerations for critical information and services.
3. Technical Safeguards
Depending on the system, sensitivity, and provider capabilities, safeguards may include:
· Multi-factor authentication for important business systems.
· Strong, unique credentials and password-management practices.
· Encryption in transit and, where provided by the platform, encryption at rest.
· Endpoint protection, system updates, malware protection, and device-security controls.
· Secure configuration of cloud storage, email, document sharing, scheduling, and customer-relationship systems.
· Logging, alerting, backup, recovery, or monitoring features appropriate to the system.
· Restrictions on public sharing and external access to sensitive files.
4. Client Information and Secure Exchange
Clients should use approved secure channels for sensitive materials and avoid sending highly sensitive information through general website forms or unsecured email. Engagement-specific instructions may identify approved document portals, storage locations, authorized recipients, naming conventions, or access procedures. Client personnel remain responsible for protecting their own credentials and promptly reporting suspected unauthorized access.
5. Service Providers
LumaKa Advisors may rely on reputable cloud, communications, scheduling, productivity, analytics, accounting, cybersecurity, and professional-service providers. We seek to use providers appropriate to the nature of the information and may consider their security representations, contractual terms, access model, reputation, and business necessity. No third-party environment is risk-free, and use of a provider does not constitute a guarantee of security.
6. Retention and Disposal
Information is retained based on business need, engagement terms, legal and tax requirements, dispute considerations, insurance requirements, and professional judgment. When information is no longer reasonably required, we seek to delete, destroy, anonymize, or securely dispose of it using methods appropriate to the format and system.
7. Security Incidents
If LumaKa Advisors becomes aware of a suspected security incident, we will evaluate the circumstances, take reasonable containment and remediation steps, preserve appropriate records, coordinate with relevant providers or advisors, and provide legally required notifications. Timing and content of any notification will depend on applicable law, the nature of the information, the likelihood of harm, and investigative needs.
8. Shared Responsibility
Security is a shared responsibility. Clients and website users should use secure devices and networks, protect credentials, verify unusual requests, limit unnecessary distribution of sensitive information, and promptly report suspected fraud, phishing, or unauthorized access involving LumaKa Advisors communications.
9. No Absolute Guarantee
No organization can eliminate all cybersecurity or privacy risk. This statement describes guiding practices and is not a warranty, certification, service-level agreement, or representation that every listed control applies identically to every system at all times.
10. Contact
Security concerns relating to LumaKa Advisors may be reported to Lou@LumaKaAdvisors.com. Do not include sensitive information in the initial report unless requested through a secure channel.

