Lumi Nova: Your data & privacy 

Your data

BFB Labs attaches great importance to your right to privacy and the protection of your personal data. We want you to feel secure when you deal with BFB Labs and your personal data are in good hands.

BFB Labs  protects your personal data in accordance with applicable laws and our data privacy policies. In addition, BFB Labs maintains the technical and organisational measures to protect your personal data against anyone who should not see it. We also make sure that no one can change it share it, delete it or anything else 

Data privacy and storage statement

We will only keep your personal information we collected online only as long as it is necessary for the purpose for which it was collected. When we no longer need it, we will remove your information from our system.

How to request erasure of data

If you would like your data to be erased from our systems, then all you have to do is ask the person who gave you access to Lumi Nova. This person is likely to be a health, care or education professional.

This app is not a substitute or is meant to be a replacement for professional advice. You should consult your doctor, or other relevant professional before making any decisions that could affect your health or the health of others.

All the information you record using this app will be held and stored on your own personal phone. We would recommend you take all possible steps to keep this information secure.

If you have any questions about this privacy statement or your use of the Lumi Nova app, please contact us via email at support@bfb-labs.com

We reserve the right to anonymously track and report a user's activity inside the app. We do this so we can help create a better experience for our users in future versions of the app.

We may update our privacy policy from time to time when we update this app and/or by posting a new version on our website. You should keep your app updated and check our website to ensure you are happy with any changes.

Privacy policy

Plain English Summary

Lumi Nova is a product of BFB Labs. This privacy notice tells you how your Personal Data is used. This is so you can decide whether or not to give your consent to BFB Labs; which we need in accordance with the General Data Protection Regulation (GDPR)  to use our products and for us to use your personal data. The privacy notice is to be read in conjunction with our standard Terms and Conditions.

Terminology

“You” This means the user (young person) and the person giving their consent(parent/guardian) to see or share their data

“Lumi Nova” is a game that gathers, stores, and shares personal data

“Guardian” is an adult with parental responsibilities 

“Professionals” are school staff members or medical professionals responsible for providing you with access to the Lumi Nova app and tracking user progress 

“Organisations” are customers of BFB Labs that are involved in your care and that you trust to view your records, for example, schools, children and adolescent mental health services, hospitals

“Encryption” secures data in such a way that only those with the correct credentials can access it

Types of BFB Labs Service Users

Lumi Nova is suitable for young people  aged 7-12 years.

Purpose of BFB Labs

Our aim is to help young people access the support and build the resilience they need to improve and sustain good mental health.

Privacy Notice Key Points

Below are some key points about how we use and collect your Personal Information. If you want more information about how we use and collect your Personal Information, please read the rest of this Privacy Policy.

Personal Information we collect - -When your parent, guardian or School (teacher) registers you to use our app, or you self sign up online we collect Personal Information provided by or about you, such as your name and birth date. We may also collect what is referred to as ‘special categories of data’, which is protected in a special way by the law. We also automatically collect information about how you use our app.

Reasons for using and collecting your personal Information - - We need to use your Personal Information so that you can use our app. We also use your Personal Information to improve our products,to understand how people use our app, for our records, for marketing to protect the security of the website and app and to prevent people from misusing our website and app.

How Long We Keep Your Information. - -We keep Personal Information for as long as we need it for the purposes described in this Privacy Notice.

Your data will be used for the following purposes:

  • To ensure your healthcare service provider or school is able to monitor your progress.

  • To provide you with important information about the product, such as important updates and notifications.

  • To anonymise your data and view it as an aggregate to improve our products and services and better inform health sector needs.

Will my information be used for anything else?

We may track and report a user's activity inside the app. This data will be anonymised if we do so. We do this so we can help create a better experience for our users and develop better products for other users like you. We may also use anonymised optional demographic data provided to help ensure that our products can be accessed by people who need it.

In order to support our partners, BFB Labs leverages a number of third-party applications and tools—some of which collect data and personal data, BFB Labs leverages these applications in the context of GDPR and European Data Privacy considerations.

What Are Third-Party Applications?

A third-party vendor is a company that provides an auxiliary product or service which has not been supplied from the original manufacturer to an end user. Twilio, for instance, is used for one-way SMS messages which allows us notify service users. These third-party solutions often serve a very specific purpose and have great value as third-party vendors are often considered innovators or specialists in the particular solution they provide.

Data Collection Among Third-Party Applications

BFB Labs uses third-party vendors and applications to collect company and contact data across our platform, some of which is personally identifiable. This data can be used for reporting purposes, and to enhance the experience of users.

Third-Party Application Usage

BFB Labs leverages several third party tools throughout our platform for purposes including Customer Relationship Management (CRM), platform hosting, product service delivery and analytics. This includes Amazon Web Server (AWS) and Twilio. 

AWS: AWS does provide start-to-end information management, ensuring that as well as secure storage, they also securely dispose of data.  They have the following accreditations: 


Twilio: generates and sends unique game key and BFB Labs mobile game download instructions via SMS using a 3rd party tool (Twilio is a sub-processor which receives personal non-identifiable data in the form of the guardian’s phone number only) to the guardian.

Twilio also allows information management, ensuring secure storage and secure disposal of data and have the following accreditations:

  • ISO 27001; 

  • ISO 27017

  • ISO 27018

  • SOC 2 Compliant

As our sub-processors, AWS stores data in the UK, and Twilio stores data in the EU (Ireland). The information stored in these systems allows us to provide positive experiences for users, as well as to support analytics and content personalisation.

Commitment To Data Protection

We are regularly evaluating our third-party vendor relationships and agreements to identify and mitigate any data processing risks, and to implement safeguards that ensure data is protected for all our users, BFB Labs partners, and employees.

Commitment To The Rights Of Data Subjects

We are also evaluating all BFB Labs-owned domains to ensure that we are protecting the rights of all users by being transparent about the types of third-party vendors we use, and ensuring those vendors are compliant with applicable privacy and security regulations and requirements.

Confidentiality

BFB Labs  requires Organisations to maintain the confidentiality of your personal data and prohibits them from using it for any other purpose. BFB Labs does not share any identifiable personal data with other third parties because we do not have access to such information.

Is Lumi Nova free?

For the users, yes - there is no charge to children, guardians or individual professionals. Lumi Nova is paid for by organisations such as your local health service, school, hospital or council. 

Can I delete or hide my BFB Labs account if I change my mind?

Because professionals may make care decisions based on the data we collect on your usage of our product and progress, it is a care record. Data records are retained in line with retention policies of the health or care organisation that provided you with access to Lumi Nova, which would be in line with guidance as follows here. Professionals have control over the data to ensure the safety of the child’s care.

How is my information protected?

BFB Labs is committed to protecting your privacy.

BFB Labs cannot see your medical record and has no control over your record. We keep your personal data on secure servers. We encrypt the data so no one can see your data except the Organisations that provided you with access to the app or those with a lawful basis. We have registered with the Information Commissioner’s Office (“ICO”), which regulates data protection in the UK, and our registration number is ZA393479.

Tracking and Analytics

BFB Labs tracks software usage to improve software quality. BFB Labs does not track identifying information or personal records. 

This Privacy Notice

This privacy notice applies to Lumi Nova (referred to in this privacy notice as the "product" or the “game”), which you access by entering a unique game key assigned to the user.

This privacy notice does not apply to any other online or offline BFB Labs sites, products, or services.

Agreement and Further Information

A guardian’s continued use of the product constitutes the guardian’s agreement to this privacy notice. If you feel you require further information before you are able to provide consent – please refer to the sections below or contact support@bfb-labs.com

Disclosure and use of personal data 

We do not use or disclose Personal Data except as described in this notice. If we receive a help request to support@bfb-labs.com we may be provided with a name and email address.

Lawful disclosures

BFB Labs may access and/or disclose information if such action is necessary to:

Comply with the law or orders served on BFB Labs;

Protect or defend the rights or property of BFB Labs (including the enforcement of our agreements); or

Act in urgent circumstances to protect the personal safety and welfare of users of BFB Labs products or members of the public.

Data storage 

BFB Labs’ data centres are in the UK and in Ireland. Data for UK NHS customers are stored inside the UK data centres. All BFB Labs data centres are ISO 27001 certified. BFB Labs may add future data centres for customers in Europe, the USA, Australia, New Zealand and Canada, and storage of those customers’ data will be in those jurisdictions.

How we use aggregated information and statistics 

BFB Labs may use aggregated information not identifiable to a specific user from the Product to improve the quality of the Product and for marketing of the Product.

This aggregated information is not associated with any individual Account.

BFB Labs does not use identifiable personal data for marketing purposes. The only information we aggregate is usage data, e.g. how many people are using the Product, what progress they are making, the region they are based in.

Security of personal information

BFB Labs is committed to protecting the security of personal information. We use a variety of security technologies and procedures to help protect personal information from unauthorised access, use, and disclosure. For example, we store your information on computer servers with limited access that are located in controlled facilities. The Product stores all data using encryption so that only Professionals are able to access your data. The Product sends all communications, except e-mail, using HTTPS.

When we replace our servers we erase the old equipment completely as part of ISO 27001 compliance and in line with National Cyber Security Centre (NCSC) guidelines.

Changes to this privacy notice

We may update this privacy notice at any time. When we do, we will change the "last updated" date at the bottom of the privacy notice. If there are material changes to this privacy notice we will notify Users, either by placing a prominent notice on the homepage of the BFB Labs web site or by sending a notification directly to the Product.

We encourage Guardians to review this notice periodically. Users’ continued use of the Product constitutes the Guardian’s' agreement to this privacy notice, as amended.

Contact information 

The name Lumi Nova is a registered trademark of BFB Labs Ltd which is a private company limited by shares and registered in the UK with company number 09700274. You can find our registered office address and contact telephone number in the footer of our website at www.bfb-labs.com.


Would you like to know more? 

Contact: support@bfb-labs.com


Last Reviewed: 19th January 2024