Privacy Policy
Last updated: June 9, 2026
Table of Contents
- 1. Scope
- 2. Data Controller
- 3. Information We Collect
- 4. Legal Basis for Processing (GDPR)
- 5. How We Use Your Information
- 6. Self-Hosted Products
- 7. Data Sharing and Sub-Processors
- 8. Data Retention
- 9. Your Rights Under GDPR
- 10. Your Rights Under CCPA/CPRA
- 11. Cookies
- 12. Security Measures
- 13. Data Breach Notification
- 14. International Transfers
- 15. Children’s Privacy
- 16. Changes to This Policy
- 17. Contact
1. Scope
This Privacy Policy covers the LiteSecurity (“LiteSecurity,” “we,” “us”) license portal website at www.litesecurity.net and our account/subscription management services. It does not cover data processed within self-hosted product instances, which remain entirely on your infrastructure (see Section 6).
2. Data Controller
LiteSecurity is the data controller for the personal data processed through the license portal. If you are located in the European Economic Area (EEA) and LiteSecurity does not maintain an establishment there, we will appoint an EU representative as required by GDPR Article 27 and update this section with their contact information. In the interim, please direct inquiries to privacy@litesecurity.net.
3. Information We Collect
Information you provide
- Email address — used for account identification, license delivery, and communications.
- Organization name — used to associate licenses with your business entity.
- Payment information — processed through Stripe. LiteSecurity does not store credit card numbers. We receive only transaction confirmation data (amount, date, status).
Information collected automatically
- License heartbeat data — self-hosted product instances send periodic heartbeat pings containing only: license ID, product version, and timestamp. No user data, configuration, or usage telemetry is included.
- Session data — strictly necessary session cookies for maintaining your authenticated session on the license portal.
4. Legal Basis for Processing (GDPR)
Under the General Data Protection Regulation, we process your personal data on the following legal bases:
- Contract performance (Art. 6(1)(b)) — account management, license key generation and delivery, subscription billing and renewal, and payment processing via Stripe.
- Legitimate interest (Art. 6(1)(f)) — license compliance verification via heartbeat data, product update notifications, fraud prevention, and improving our services. Our legitimate interest does not override your fundamental rights; you may object at any time (see Section 9).
- Legal obligation (Art. 6(1)(c)) — retaining transaction records as required by tax and financial regulations, and responding to lawful data requests from authorities.
5. How We Use Your Information
- Account management and authentication
- License key generation and delivery
- Subscription billing and renewal
- Customer support
- Product update notifications
- License compliance verification (via heartbeat data described above)
6. Self-Hosted Products
LiteGRC and LiteAI are deployed entirely on your infrastructure. All product data — compliance records, audit evidence, AI traffic logs, DLP scan results, and any other data processed by the Products — remains on your servers at all times.
The only data transmitted to LiteSecurity from self-hosted instances is the license heartbeat described in Section 3: license ID, product version, and timestamp. This is used solely to verify license validity.
7. Data Sharing and Sub-Processors
- Stripe (payment processing) — we share your email and transaction details with Stripe for payment processing. See Stripe's Privacy Policy.
- Infrastructure providers — the license portal and license verification service are hosted on cloud infrastructure. These providers process data as sub-processors under our instructions.
- No selling of data — we do not sell, rent, or trade your personal information to third parties.
- Legal requirements — we may disclose information if required by law, subpoena, or court order.
A current list of sub-processors is available upon request by emailing privacy@litesecurity.net.
8. Data Retention
We retain your account information and license records for the duration of your subscription plus 12 months after expiration. After this period, your data will be deleted unless retention is required by law (e.g., tax records). Heartbeat data is retained for 90 days and then automatically purged. You may request earlier deletion by contacting us.
9. Your Rights Under GDPR
If you are located in the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation:
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — request correction of inaccurate data.
- Right to erasure — request deletion of your personal data.
- Right to restriction of processing — request that we limit the processing of your personal data in certain circumstances (e.g., while we verify the accuracy of contested data).
- Right to portability — receive your data in a structured, machine-readable format.
- Right to object — object to processing of your data based on legitimate interest, including for direct marketing purposes.
- Right to withdraw consent — where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
- Right to lodge a complaint — you have the right to lodge a complaint with a supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement.
We will respond to verified data subject requests within 30 days of receipt. In complex cases, we may extend this period by an additional 60 days with notice to you.
A Data Processing Agreement (DPA) is available upon request for customers subject to GDPR requirements. Contact privacy@litesecurity.net to request a copy.
To exercise any of these rights, contact privacy@litesecurity.net.
10. Your Rights Under CCPA/CPRA
If you are a California resident, the California Consumer Privacy Act and the California Privacy Rights Act provide you with the following rights:
- Right to know — request information about the categories and specific pieces of personal data we collect.
- Right to delete — request deletion of your personal data.
- Right to correct — request correction of inaccurate personal information we hold about you.
- Right to opt-out of sale — we do not sell personal data, so this right is automatically satisfied.
- Right to limit use of sensitive personal information — we do not collect sensitive personal information as defined under CCPA/CPRA (e.g., Social Security numbers, financial account details, precise geolocation, biometric data).
- Right to non-discrimination — we will not discriminate against you for exercising your privacy rights.
We will respond to verified consumer requests within 45 days of receipt. We may extend this period by an additional 45 days with notice to you.
Verification
We will verify your identity before processing data requests by confirming your account email address. For requests to delete or access specific pieces of personal information, we may require additional verification.
Authorized Agents
You may designate an authorized agent to submit requests on your behalf. Authorized agents must provide written proof of authorization (e.g., a signed power of attorney or written authorization from you). We may also require you to verify your identity directly with us.
11. Cookies
We use session cookies only for maintaining your authenticated session on the license portal. These are strictly necessary cookies as defined under the ePrivacy Directive and do not require consent. We do not use third-party tracking cookies, analytics cookies, or advertising cookies. You can manage cookies through your browser settings, but disabling session cookies may prevent you from using the license portal.
12. Security Measures
We protect your data with industry-standard security measures including:
- TLS encryption for all data in transit
- Encryption at rest for stored data
- Access controls and authentication for internal systems
- Regular security reviews
13. Data Breach Notification
In the event of a data breach affecting your personal information, we will notify affected individuals in accordance with applicable law. For individuals in the EEA, we will report qualifying breaches to the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay (GDPR Article 34). For U.S. residents, notification will be provided in accordance with applicable state breach notification laws.
14. International Transfers
Your information is processed and stored in the United States. If you are accessing the license portal from outside the United States, your information will be transferred to, processed, and stored in the United States.
For transfers of personal data from the EEA, UK, or Switzerland to the United States, we rely on applicable transfer mechanisms as required by law, which may include: the EU-U.S. Data Privacy Framework (if certified), Standard Contractual Clauses (SCCs) approved by the European Commission, or other lawful transfer mechanisms. To request a copy of the applicable transfer mechanism, contact privacy@litesecurity.net.
15. Children’s Privacy
Our Products are not directed at individuals under the age of 13. We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a child, please contact us immediately and we will promptly delete the information.
16. Changes to This Policy
We may update this Privacy Policy from time to time. We will provide at least 30 days' notice of material changes via email to the address associated with your account. The “Last updated” date at the top of this page indicates when the policy was last revised. Your continued use of the license portal after the effective date of the updated policy constitutes acceptance.
17. Contact
For privacy-related questions, to exercise your data rights, or to request a DPA or sub-processor list, contact us at privacy@litesecurity.net.