Information Security Policy

The technical and organisational measures we use to protect personal data and the integrity of the Luxi platform.

Last updated: 24 May 2026

1. Scope

This policy describes the security measures Luxi applies to all systems that process personal data, payment data, or operational data underpinning the booking service. It is reviewed at least annually and after any material incident.

2. Data classification

3. Encryption

4. Access control

5. Vulnerability management

6. Network & perimeter

7. Application security

8. Backups & recovery

9. Incident response

We maintain a documented incident response plan covering detection, containment, eradication, recovery and post-incident review. In the event of a personal-data breach reaching the GDPR notification threshold (Art. 33):

10. Staff training & conduct

11. Reporting a vulnerability

Found something? Email [email protected] with a description, reproduction steps and your contact details. Use this security.txt for PGP key and disclosure terms.


See also: GDPR Policy, Data Retention Policy, Privacy Policy.