Skip to content

Privacy Policy

Effective 21 September 2026. Imperium Advisors, LLC, a California limited liability company, operates Luna Compliance. This policy explains what we do with personal information.

Two different relationships, and they are not the same. If you are reading this website, we hold almost nothing about you. If your firm uses the product, the data inside it belongs to your firm and we handle it on your firm's instructions, not our own. Section 2 covers the first. Section 3 covers the second, and it is the one that matters if you are an adviser or one of their employees.

1. Who we are

Imperium Advisors, LLC, a California limited liability company.

490 Post St, Ste 500 PMB 2216 San Francisco, CA 94102 United States

privacy@lunacompliance.io

We are a software company. We are not an investment adviser, a broker-dealer, or a law firm.

2. This website

2.1 What we collect

We collect very little, on purpose.

WhatWhyKept
Request logs: IP address, user agent, page requested, timestampSecurity, abuse prevention, and knowing which pages are read30 days
Your theme choiceSo the site does not flip between light and dark on youIn your browser only, never sent to us
An email address, if you give us oneTo reply, or to send what you asked forUntil you ask us to delete it

We run no third-party analytics, no advertising pixels, and no session recording on this website. Fonts are served from our own domain rather than from Google, so loading a page here does not tell anyone else that you did.

2.2 Cookies

We set no cookies for advertising or analytics. What we store in your browser is described in the cookie notice, and it is a very short list.

We honour the Global Privacy Control signal. Since we neither sell nor share personal information, there is nothing for it to switch off, but we honour it anyway rather than asking you to trust that claim.

2.3 Marketing email

If you subscribe, every message includes a working unsubscribe link and we process the request immediately. We do not buy lists and we do not send you anything you did not ask for.

3. Data inside the product

3.1 It is your firm's data, not ours

When your firm uses Luna, your firm decides what goes in and why. Under California law your firm is the business and we are a service provider; under other privacy laws your firm is the controller and we are a processor. The practical meaning is the same: we process what is in there on your firm's instructions and for no purpose of our own.

The terms that bind us are in the Data Processing Addendum. It is worth reading if you are the person at your firm responsible for vendor oversight, because it is written to the obligations that actually apply to you.

3.2 What the product holds

  • Account details for your firm's users: name, work email, role
  • Personal securities holdings and transactions for access persons and their household members, where your firm enables that module
  • Gifts, entertainment, political contributions, outside business activities, conflicts and violations your firm records
  • Your firm's policies, procedures, Form ADV, and the advertisements it submits for review, including any individual named in them
  • Communications content, where your firm enables archiving
  • Risk indicators we calculate from the above and present to your firm

3.3 What we never do with it

We do not sell it. We do not share it for cross-context behavioural advertising. We do not use it for any purpose of our own.

We do not use it to train machine learning models. Not ours, and not a third party's. Our model provider's commercial terms commit that it may not train on content submitted through its API, and we submit under those terms.

3.4 Who we pass it to

Only the subprocessors on this page, each for a specific purpose, each under obligations no weaker than ours. That page lists what each one receives, and we give your firm 30 days' notice before adding one.

3.5 Employees and household members

If you are an access person at a firm that uses Luna, or the household member of one, your data is in there because your firm's code of ethics requires it, not because you chose to give it to us.

Your rights run through your firm, which decides what it collects and keeps. If you ask us to access, correct or delete something, we will tell your firm within five business days and help them respond. We will not act on it ourselves, because the record may be one your firm is legally required to keep.

3.6 Automated calculations about individuals

Luna computes a risk indicator for each access person from trading activity, gift and entertainment filings, outside business activities, violation history, attestation timeliness, conflicts and preclearance outcomes.

It is a recommendation to a human being. It surfaces to a person at your firm with the contributing factors shown, and nothing happens automatically as a result of it. What your firm then does with it is your firm's decision and your firm's responsibility.

If you want to know how a particular score was arrived at, ask your firm. We will provide the calculation and the contributing factors to them on request.

4. Security

Data is encrypted in transit and at rest. Access within Luna is limited to personnel who need it to operate or support the Services, and is logged.

On isolation between customers, the security page describes exactly how Luna is deployed today rather than making a general claim. We would rather you read the architecture than take a word like "isolated" on trust.

We maintain a written incident response program, and the Data Processing Addendum commits us to notifying your firm within 72 hours of becoming aware of unauthorized access to a system holding your data. That trigger is deliberately earlier than the industry norm, because 17 C.F.R. § 248.30(a)(5) sets it there.

More detail is on the security page.

5. Financial data and the GLBA

Much of what Luna processes for a customer firm is nonpublic personal information subject to the Gramm-Leach-Bliley Act and, for SEC-registered advisers, Regulation S-P. State-registered advisers and exempt reporting advisers are subject instead to the FTC Safeguards Rule at 16 C.F.R. Part 314.

California's privacy statute exempts some of that information from parts of the CCPA. We want to be precise about what that exemption does and does not do: it is information-level rather than entity-level, and by its own terms it does not apply to the private right of action for data breaches at Cal. Civ. Code § 1798.150. We therefore treat that data as sensitive regardless of the exemption, rather than relying on it.

6. Your rights

Depending on where you live, you may have the right to know what personal information we hold, to correct it, to delete it, to receive a copy, and not to be discriminated against for exercising any of these.

For website data, write to privacy@lunacompliance.io and we will respond within 45 days. We will ask you to verify your identity in proportion to the sensitivity of what you are asking for, and no more.

For data inside the product, see Section 3.5. Those requests go to your firm.

You may use an authorized agent. We will ask for proof of authorization.

7. Children

Luna is a business tool. We do not knowingly collect personal information from anyone under 18, and there is no circumstance in which a child should be a user of this product.

8. Retention

Website logs: 30 days. Email you send us: until you ask us to delete it. Product data: as set out in the Data Processing Addendum, which includes an important exception where the data is a record your firm is required to keep.

9. Changes

We will post a new effective date here when this policy changes, and where a change materially affects how we handle product data we will tell your firm's administrators directly rather than relying on you noticing this page.

10. Contact

privacy@lunacompliance.io for anything in this policy. legal@lunacompliance.io for the Data Processing Addendum or the Terms.