These policies are published as part of our commitment to transparency with institutional clients, partners, and investors. Items marked [in brackets] are pending completion upon incorporation. These documents should be reviewed by a qualified solicitor before formal adoption.
POLICY 01

Information Security Policy

Owner: Data Protection Lead  ·  Last reviewed: July 2026  ·  Next review: July 2027

Purpose

This policy establishes the framework for protecting all information assets held by or processed through Luxury Assets Index, including collector vault data, asset records, documents, and system configurations.

Scope

This policy applies to all systems, services, and data operated by Luxury Assets Index, including third-party services used to deliver the platform.

Information Classification

ClassificationExamplesControls Required
PublicLanding page, marketing content, published policiesStandard web security
InternalProduct roadmap, internal documentationAccess restricted to authorised team
ConfidentialCustomer names, email addresses, account detailsEncryption at rest and in transit, access logging
Highly ConfidentialAsset values, serial numbers, financial documents, storage locationsField-level encryption, strict access controls, audit trail, time-limited access

Key Controls

  • All data transmitted via HTTPS (TLS 1.3 minimum)
  • Passwords hashed using scrypt with a unique random salt per account — never stored in plain text
  • Sensitive database fields encrypted at rest
  • Access to production systems restricted to authorised personnel only
  • API keys and secrets stored in environment variables, never in code repositories
  • Regular review of third-party service permissions
POLICY 02

Data Protection Policy

Owner: Data Protection Lead  ·  Last reviewed: July 2026  ·  Next review: July 2027

Purpose

This policy ensures Luxury Assets Index processes personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Data Protection Principles

We process personal data in accordance with the UK GDPR principles:

  • Lawfulness, fairness, and transparency — We have a documented lawful basis for all processing
  • Purpose limitation — Data is collected for specified, explicit purposes and not processed beyond those
  • Data minimisation — We collect only what is necessary
  • Accuracy — We take reasonable steps to keep data accurate and up to date
  • Storage limitation — Data is retained only as long as necessary
  • Integrity and confidentiality — Appropriate security measures are in place
  • Accountability — We can demonstrate compliance with these principles

Data Retention Schedule

Data TypeRetention PeriodBasis
Account data (active)Duration of accountContract
Account data (closed)30 days post-closureGDPR right to erasure
Asset and vault dataDuration of account + 30 daysContract
Financial transaction records7 yearsLegal obligation (HMRC)
Audit logs2 yearsLegitimate interests (security)
Backup copies90 daysLegitimate interests (continuity)
Support communications2 years post-resolutionLegitimate interests

Subject Rights Process

Requests from individuals exercising their UK GDPR rights must be:

  • Acknowledged within 3 working days
  • Responded to within 30 calendar days
  • Logged in the Subject Access Request register
  • Verified for identity before data is released
POLICY 03

Access Control Policy

Owner: Data Protection Lead  ·  Last reviewed: July 2026  ·  Next review: July 2027

Purpose

This policy ensures that access to platform systems and collector data is granted on a least-privilege basis and is subject to appropriate controls.

User Access Levels

RoleAccess ScopeControls
CollectorOwn vault data onlyAuthenticated session, MFA (planned)
Insurance PartnerExplicitly shared data only, at granted levelCollector permission required, access timestamped
Family OfficeConsolidated view of consenting family membersPer-member permission required
Dealer / VerifierStolen register and value range onlyNo personal data, public lookup
Platform AdministratorSystem managementRestricted data visibility where possible; structured action logging planned, not yet built

Permission Model

  • All third-party access requires explicit, scoped permission from the data owner
  • Permissions are granted at one of three levels (Basic, Full, Claims) as documented in the Security & Trust Framework
  • Permissions are timestamped with grant date, purpose, and expiry
  • All permissions can be revoked by the data owner at any time
  • Time-limited permissions (e.g. Claims Access) expire automatically

Administrative Access

  • Production API access is restricted to authorised personnel only
  • Structured logging of administrative actions is planned but not yet implemented — see Compliance Roadmap
  • API keys are rotated immediately upon any suspected compromise
  • Access to production systems is reviewed quarterly
POLICY 04

Incident Response Plan

Owner: Data Protection Lead  ·  Last reviewed: July 2026  ·  Next review: July 2027

Purpose

This plan establishes the process for detecting, responding to, and recovering from security incidents, including personal data breaches.

Incident Classification

SeverityDefinitionResponse Time
P1 — CriticalConfirmed breach of personal data, system compromise, ransomwareImmediate — within 1 hour
P2 — HighSuspected breach, significant service outage, API key exposureWithin 4 hours
P3 — MediumPartial service degradation, suspicious activity detectedWithin 24 hours
P4 — LowMinor issues, potential vulnerabilities identifiedWithin 72 hours

Response Steps

  1. Detect & Triage — Identify the nature and scope of the incident
  2. Contain — Isolate affected systems, revoke compromised credentials, prevent further damage
  3. Assess — Determine what data was affected and who may be impacted
  4. Notify — If personal data is involved, notify ICO within 72 hours if risk to individuals is likely; notify affected users without undue delay
  5. Recover — Restore systems from clean backups, implement fixes
  6. Review — Document the incident, root cause, and preventive measures

ICO Reporting

Under UK GDPR Article 33, we must notify the ICO within 72 hours of becoming aware of a personal data breach that is likely to result in a risk to individuals' rights and freedoms. Report at: ico.org.uk/for-organisations/report-a-breach/

POLICY 05

AI Governance Policy

Owner: Data Protection Lead  ·  Last reviewed: July 2026  ·  Next review: July 2027

Purpose

This policy governs how Luxury Assets Index uses AI services, ensuring customer data is protected and AI outputs are used responsibly.

AI Services Used

ServiceProviderPurposeData Sent
Asset AnalysisAnthropic (Claude)Rarity, market position, valuation factorsBrand, model, category, year — NO personal identifiers
Market CommentaryAnthropic (Claude)Daily luxury market intelligenceCurrency rates, commodity prices — NO personal data
Image AnalysisAnthropic (Claude)Optional asset photo identificationImage file only — NO account or personal data

AI Data Minimisation Rules

  • Personal identifiers (name, email, account ID, address) are never included in AI prompts
  • Asset financial details (exact purchase price, insurance value) are not sent in initial analysis requests
  • AI prompts are reviewed at each new integration point to ensure minimisation
  • Customer data is never used to train AI models without explicit written consent

AI Output Standards

  • All AI-generated content is clearly labelled as AI-generated and informational only
  • AI outputs do not constitute financial, insurance, legal, or valuation advice
  • AI analysis includes appropriate caveats about accuracy and market conditions
  • Users are encouraged to seek professional advice for significant financial decisions
POLICY 06

Vendor Risk Management Policy

Owner: Data Protection Lead  ·  Last reviewed: July 2026  ·  Next review: July 2027

Purpose

This policy ensures that third-party vendors and service providers who process or store data on our behalf meet appropriate security and compliance standards.

Current Vendor Register

VendorServiceData ProcessedLocationAssessment
Render.comAPI hosting & databaseAsset data, user accountsUSA (AWS infrastructure)SOC 2 compliant. Standard contractual clauses apply.
NamecheapWebsite hosting, domainStatic website files onlyUSANo personal data processed at this layer.
AnthropicAI analysis (Claude API)Anonymised asset details onlyUSAEnterprise API terms. No training on API data by default.
open.er-api.comCurrency ratesNone — public data onlyUSANo personal data. Public API.

Vendor Assessment Process

  • All new vendors processing personal data must be reviewed before onboarding
  • Data Processing Agreements (DPAs) required from all vendors processing personal data
  • Vendor security posture reviewed annually or upon material change
  • International data transfers assessed for adequacy or appropriate safeguards (SCCs)
POLICY 07

Secure Development Policy

Owner: Data Protection Lead  ·  Last reviewed: July 2026  ·  Next review: July 2027

Purpose

This policy establishes secure development practices to minimise security vulnerabilities in the Luxury Assets Index platform.

Current Practices

  • All code stored in private GitHub repositories
  • No secrets, API keys, or credentials committed to version control
  • Environment variables used for all sensitive configuration
  • Dependencies reviewed for known vulnerabilities via npm audit before deployment
  • Input validation on all API endpoints
  • CORS configured to restrict cross-origin requests

Planned Controls (Before Launch)

  • Rate limiting on all API endpoints (express-rate-limit)
  • Authentication middleware on all protected routes
  • SQL injection and XSS protection (upon PostgreSQL migration)
  • Automated dependency scanning (GitHub Dependabot)
  • Professional penetration test before first paying customers

Change Management

  • All changes deployed via GitHub → Render CI/CD pipeline
  • No direct manual edits to production systems
  • Rollback capability maintained via Git history
POLICY 08

Business Continuity & Disaster Recovery

Owner: Data Protection Lead  ·  Last reviewed: July 2026  ·  Next review: July 2027

Purpose

This policy ensures the platform can recover from disruptions and continue to serve users with minimal downtime.

Recovery Objectives

ScenarioRecovery Time Objective (RTO)Recovery Point Objective (RPO)
API server outage30 minutes (Render auto-restarts)Zero — stateless
Database corruption4 hours24 hours (once daily backups implemented)
Full platform outage24 hours24 hours
Key person unavailability72 hours (documentation-dependent)N/A

Current Continuity Measures

  • Frontend website hosted independently from API — partial service available during API outages
  • All code in GitHub — platform can be redeployed from source
  • Render.com provides automatic restarts on process failure

Planned Improvements (Before Launch)

  • Daily automated database backups to separate storage
  • Migration from JSON file storage to PostgreSQL with point-in-time recovery
  • Documented runbooks for all recovery scenarios
  • Secondary deployment region consideration
  • Formal DR test conducted annually