Legal
This Privacy Policy describes how LightCI collects, uses, discloses and protects personal information when you visit lightci.com, communicate with us, or engage our services, and the rights and choices available to you.
LightCI (“LightCI”, “we”, “us”) is an AI consulting firm and product studio headquartered in Toronto, Ontario, Canada, with a distributed team across North America. We design and deploy AI systems for enterprise and private-equity-backed software companies.
This Privacy Policy applies to personal information we collect and use as a controller, meaning when we decide why and how it is processed. That includes:
It does not govern the business data, systems and records we access while delivering an engagement for a client. There, the client is the controller and we act on its instructions. That work is covered by our services agreement with the client and by our AI Data & Privacy Policy, which is the standing commitment for how we handle client data in AI work.
Password-protected pages
Some pages on this site are unlocked with a shared password that we give to a prospective client. The password does not identify you personally. We may see, through analytics, that the page was viewed and from which company.
We do not use personal information collected through this site to make automated decisions that have legal or similarly significant effects on you.
Where the GDPR, the UK GDPR or similar laws apply, we rely on one or more of the following bases for each processing activity:
In Canada, we collect, use and disclose personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial laws, relying on express or implied consent as the circumstances require.
We are based in Canada and our team and service providers operate in Canada and the United States, with some providers operating globally. If you are in the European Economic Area, the United Kingdom or Switzerland, your information may be transferred to countries whose laws differ from yours.
Where we do so, we rely on recognised safeguards: the European Commission’s adequacy decision for Canada (for PIPEDA-governed organisations), Standard Contractual Clauses or the UK International Data Transfer Addendum with providers, and providers’ participation in the EU-U.S. Data Privacy Framework where applicable. You can ask us for a copy of the relevant safeguard.
We keep personal information only as long as we need it for the purposes above, then delete or anonymise it. As a guide:
Backups are overwritten on a rolling schedule, so deleted data may persist in backups for a limited period before it ages out.
We protect personal information with technical and organisational measures appropriate to its sensitivity: encryption in transit and at rest, single sign-on and multi-factor authentication on our systems, named accounts with least-privilege access, managed and encrypted devices, and vendor review before we adopt a tool. Access to client information is limited to the people working on that client.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities as required by law.
Depending on where you live, you may have the right to:
To exercise any right, email privacy@lightci.com. We may need to verify your identity, which we will do with the least information necessary. An authorised agent may make a request on your behalf with evidence of authority. We respond within the timeframe the applicable law requires, and in any case within thirty days.
We do not sell personal information and do not share it for cross-context behavioural advertising as those terms are defined in the California Consumer Privacy Act. We have not sold or shared personal information in the preceding twelve months. The categories of information we collect, our purposes, and the categories of recipients are described above. You have the right to know, correct, delete and opt out, and to be free from retaliation for exercising those rights.
You have the right to lodge a complaint with your local data protection authority, or with the UK Information Commissioner’s Office. We would appreciate the chance to address your concern first.
You have the right to access and correct your personal information and to withdraw consent, subject to legal and contractual restrictions. You may also complain to the Office of the Privacy Commissioner of Canada.
We contact people in business roles about our services, research and events. We do this under Canada’s Anti-Spam Legislation (CASL) and equivalent laws elsewhere, relying on express consent, an existing business relationship, or a conspicuously published business contact address, as the law permits.
Every marketing email includes an unsubscribe link. You can also reply to any message or email us to opt out, and we will action it within ten business days. Opting out of marketing does not stop transactional messages about a live engagement.
Our work puts us inside client systems: CRMs, finance stacks, support queues, product databases, document stores. The personal information in those systems belongs to the client and its customers. In that context we are a processor or service provider acting on documented instructions, and the client’s agreement with us and applicable data processing terms govern.
Read alongside this policy
Our AI Data & Privacy Policy sets out the commitments that apply to every engagement: no training on client data, client data stays in the client’s environment, zero-retention model access, time-boxed access that is revoked at close, and bright lines for regulated data.
If you are a customer or employee of one of our clients and have a question about data we processed on the client’s behalf, please contact the client first. We will help them respond.
Our site and services are for businesses and are not directed to anyone under eighteen. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
We may update this policy from time to time as our practices, tools or the law change. When we do, we will post the revised policy on this page. For material changes, we will post a notice on the site or contact you directly where we have a relationship with you. Continued use of the site after a change means the updated policy applies.
Questions, requests and complaints about privacy can be sent to us at any time.
Privacy questions & requests
privacy@lightci.comWe respond within 30 days, and sooner for anything involving an active engagement.
LightCI
Attn: Privacy
Toronto, Ontario, Canada