⚠ Draft — Pending Lawyer Review — Not Yet Effective
LuxGov

Privacy Policy

Version 1.0· Effective Date: 5 June 2026· Luxemss Resources (202603121194)

Contents
  1. Introduction
  2. Data Controller
  3. Categories of Data Collected
  4. Legal Basis for Processing
  5. How We Use Your Data
  6. Tenant Data Isolation
  7. Data Storage Locations
  8. Data Retention
  9. Data Deletion and Offboarding
  10. Cross-Border Data Transfers
  11. Data Subject Rights
  12. Cookies and Tracking
  13. Children's Data
  14. Security Measures
  15. Data Breach Notification
  16. Do Not Sell (California)
  17. Changes to This Policy
  18. Contact

1. Introduction

This Privacy Policy explains how Luxemss Resources (SSM Registration No. 202603121194 / PG0587419-T) ("LuxGov", "we", "us", or "our") collects, uses, stores, and protects personal data and building compliance data when you use the LuxGov platform ("Platform").

This Privacy Policy is designed to comply with:

Where there is a conflict between the requirements of different jurisdictions, LuxGov will apply the higher standard of protection.

2. Data Controller

Luxemss Resources

SSM Registration No: 202603121194 (PG0587419-T)

No 46, Jalan Bidara 3, Saujana Utama 3, 47000 Sungai Buloh, Selangor, Malaysia

Email: admin@luxgov.net

Where LuxGov processes personal data on behalf of a Tenant (as a data processor), the Tenant is the data controller and LuxGov acts as the data processor. This relationship is governed by the Data Processing Agreement.

3. Categories of Data Collected

3.1. Account Data

Full name, email address, organisation name and role, jurisdiction of operation, and subscription plan selection.

3.2. Authentication Data

Microsoft Entra ID tokens and session identifiers, email/password authentication records (passwords are hashed — plaintext passwords are never stored), login timestamps, IP addresses, device identifiers, session duration and expiry data.

3.3. Usage Data

Audit runs initiated (project IDs, timestamps, jurisdictions), feature usage patterns, API request logs (endpoints accessed, response codes, latency), error logs and diagnostic data.

3.4. Billing Data

Subscription plan, billing cycle, and billing history; Stripe customer identifier and subscription identifier; invoice records and payment status.

Important

LuxGov does not collect, store, or have access to payment card numbers, CVVs, or bank account details. All payment processing is handled exclusively by Stripe Inc. in accordance with PCI DSS Level 1 requirements.

3.5. Building Compliance Data (Tenant-Uploaded)

Architectural drawings, engineering reports and structural calculations, compliance certificates and professional certifications, building permits, inspection reports, and regulatory correspondence. This data may contain personal data of third parties (e.g., names and professional registration numbers of engineers, architects, and building certifiers). The Tenant, as data controller, is responsible for ensuring it has the necessary consents to upload such data.

4. Legal Basis for Processing

JurisdictionLegal Basis
Malaysia (PDPA 2010)Consent (Section 6); performance of contract; legitimate interests; compliance with legal obligation
Singapore (PDPA 2012)Consent; contractual necessity; legitimate interests (Section 17, as amended 2021)
Australia (Privacy Act 1988)Consent; necessary for the performance of a contract; permitted under Australian Privacy Principles (APPs 3, 6)
United Kingdom (UK GDPR)Consent (Art.6(1)(a)); performance of contract (Art.6(1)(b)); legitimate interests (Art.6(1)(f)); legal obligation (Art.6(1)(c))
United States (CCPA/CPRA)Business purpose; contractual necessity; with notice and consent where required by state law

5. How We Use Your Data

5.1. Service Delivery

Providing the automated compliance auditing service; running the seven-stage compliance pipeline against jurisdiction-specific Building Codes; generating Compliance Outputs (audit reports, deficiency lists, compliance scores); managing Tenant accounts, projects, and user permissions.

5.2. AI-Powered Compliance Analysis

Building compliance documents are processed by our AI engine including Anthropic's Claude API for classification, analysis, and compliance scoring.

Disclosure Regarding AI Processing

Document content is transmitted to Anthropic's Claude API for natural language analysis. Anthropic's API Terms of Service explicitly prohibit using API inputs for model training. LuxGov does not use Tenant Data for training, fine-tuning, or improving AI models.

5.3. Billing and Account Management

Processing subscription payments via Stripe, generating invoices, enforcing plan limits, and managing trial periods and subscription renewals.

5.4. Platform Improvement

Analysing aggregated, anonymised usage patterns to improve Platform features. Individual Tenant Data is never used in identifiable form for this purpose.

5.5. Legal and Regulatory Compliance

Complying with applicable laws, regulations, and legal processes; responding to lawful requests from government authorities; enforcing our Terms of Service and protecting our legal rights.

6. Tenant Data Isolation

LuxGov implements strict technical measures to ensure that each Tenant's data is isolated from all other Tenants:

7. Data Storage Locations

LuxGov stores Tenant Data in Azure data centres located in the Jurisdiction of the Tenant's operations:

JurisdictionAzure RegionData Protection Law
Malaysia (MY)Malaysia WestPDPA 2010
Singapore (SG)Southeast AsiaPDPA 2012
Australia (AU)Australia EastPrivacy Act 1988
United Kingdom (UK)UK SouthUK GDPR / DPA 2018
United States (US)East USCCPA / State laws

8. Data Retention

Data CategoryRetention PeriodBasis
Active project dataDuration of subscriptionContractual necessity
Post-termination project data30 days after terminationData export grace period
Active audit logsRetained per jurisdiction and regulatory requirementRegulatory compliance
WORM-protected audit archivesUp to 7 years for AU/US jurisdictionsRegulatory (QBCC Act, State Construction Law)
Billing records7 yearsMalaysian Income Tax Act 1967
Authentication logs90 daysSecurity monitoring

9. Data Deletion and Offboarding

9.1. Upon termination of a subscription, the Tenant has a thirty (30) day grace period to export all Tenant Data.

9.2. After the grace period, LuxGov will permanently delete Tenant Data from active storage systems through a sovereign purge process specific to the Tenant's Jurisdiction.

9.3. UK, SG, MY (SOFT WORM jurisdictions): Audit archives can be deleted after the applicable retention period expires, or upon legal basis (e.g., GDPR Article 17 right to erasure, PDPA withdrawal of consent).

AU, US (HARD WORM jurisdictions): Audit archives under HARD LOCK immutability cannot be deleted before the expiration of the regulatory retention period (up to 7 years). This is a regulatory requirement. The Client acknowledges and consents to this retention upon subscribing.

10. Cross-Border Data Transfers

As a general principle, Tenant Data is stored within the Tenant's chosen Jurisdiction. However, certain processing activities require cross-border data transfers:

AI Processing Transfer: Building compliance document content is transmitted to Anthropic's Claude API infrastructure, based in the United States, for AI-powered compliance analysis. This transfer is governed by Anthropic's Data Processing Addendum and API Terms of Service.

Payment Processing: Billing data is processed by Stripe Inc., headquartered in the United States, governed by Stripe's published Data Processing Agreement.

Transfer Safeguard MechanismApplicability
Standard Contractual Clauses (EU/UK SCCs)UK Tenants — incorporated by reference into the DPA
APEC Cross-Border Privacy Rules (CBPR)SG, AU Tenants
Malaysia PDPA Section 129MY Tenants — transfer only with adequate protection or Client consent
Contractual safeguardsAll Tenants — sub-processor DPAs with Microsoft, Anthropic, and Stripe

11. Data Subject Rights

RightMYSGAUUKUS (CA)
Access✅ S.12✅ S.21✅ APP 12✅ Art.15✅ §1798.100
Correction✅ S.34✅ S.22✅ APP 13✅ Art.16✅ §1798.106
Deletion✅ S.34✅ Art.17✅ §1798.105
Portability✅ S.26H✅ Art.20
Withdraw Consent✅ S.38✅ S.16✅ Art.7
Non-discrimination✅ §1798.125

To exercise any of these rights, please contact us at admin@luxgov.net. We will respond within 21 days (Malaysia), 30 days (Singapore, Australia, UK), or 45 days (United States — California).

12. Cookies and Tracking

12.1. The Platform uses session cookies only to maintain authenticated user sessions. These are essential for Platform operation and cannot be disabled.

12.2. The Platform does not use third-party advertising or marketing cookies, cross-site tracking pixels, behavioural analytics cookies, or social media tracking scripts.

12.3. The Platform uses Microsoft Application Insights for server-side performance monitoring and error diagnostics. This telemetry data is anonymised and does not track individual user behaviour.

13. Children's Data

The Platform is a business-to-business service designed for use by organisations and professionals in the built environment. It is not intended for use by individuals under the age of eighteen (18). LuxGov does not knowingly collect personal data from children.

14. Security Measures

MeasureImplementation
Encryption in transitTLS 1.2+ for all data transmission
Encryption at restAES-256-GCM for state files; Azure Storage Service Encryption for blob storage
Secret managementAzure Key Vault for all credentials, API keys, and encryption keys (no hardcoded secrets)
Tenant isolationPostgreSQL Row Level Security; per-tenant storage containers
Access controlRole-based access control (RBAC) across defined tenant and platform roles, fail-closed enforcement
Audit loggingSHA-256 hash-chained audit trail, WORM-protected archives
AuthenticationMicrosoft Entra ID (Azure AD) with JWT token validation; JWKS key verification

15. Data Breach Notification

In the event of a personal data breach, LuxGov will notify the affected Tenant within seventy-two (72) hours of becoming aware of the breach, and notify the relevant data protection authority within the time required by applicable law:

16. Do Not Sell My Personal Information (California)

LuxGov does not sell, share, or rent personal data to third parties for monetary or other valuable consideration. LuxGov does not share personal data for cross-context behavioural advertising. California residents may contact us at admin@luxgov.net to exercise their rights under the CCPA/CPRA.

17. Changes to This Privacy Policy

LuxGov may update this Privacy Policy from time to time. Material changes will be notified to Tenants via email or dashboard notification at least thirty (30) days before taking effect. The "Effective Date" at the top of this document indicates when it was last updated.

18. Contact

Luxemss Resources — Data Privacy

No 46, Jalan Bidara 3, Saujana Utama 3, 47000 Sungai Buloh, Selangor, Malaysia

Email: admin@luxgov.net

Website: www.luxgov.net

Supervisory Authorities: