Legal · For clients
This policy describes how LightCI handles client data when we design, build and operate AI systems on behalf of our clients. It applies to every engagement and supplements the agreements we enter into with each client.
AI systems are only useful when they are connected to real data. That means the companies we work with hand us access to the systems that run their business. We think that trust should be met with a written, public standard rather than a reassurance in a meeting.
This policy applies to every LightCI engagement in which we access, process or build systems that process your data (“client data”). It supplements your master services agreement and any data processing addendum. If a signed agreement says something more specific or more protective, the agreement governs. Our general Privacy Policy covers how we handle personal information on our own website and in our own business.
Every system we build follows the same shape. Data is read, with scoped permissions, from your systems of record (for example your CRM, ERP and finance systems, support platform, document stores, data warehouse and product databases) into a semantic layer and agents that run in your environment: your cloud account, your keys, your logs. Model calls go out to the provider under enterprise terms with no training and zero retention, and outputs are returned to your systems. Inputs stay in your environment, outputs return to your systems, and logs are written to your observability stack.
LightCI engineers access these systems through named accounts issued by your identity provider, with least-privilege, time-boxed access that is revoked at close. No production data is held on our machines. We document this data map for each build before it goes live, and you keep it.
The one thing that does not appear on that map is a LightCI data store. We do not maintain copies of your production data, and we design so that we never need to.
Depending on the engagement, the systems we connect to may contain:
We ask for the minimum needed for the job. Much of a build can be done on synthetic, sampled or masked data, and we default to that until a system is ready for production data.
For client data, you are the controller (or “business” under U.S. state law) and LightCI is a processor (or “service provider”). We process client data only on your documented instructions, for the purposes of the engagement, and not for our own purposes.
You are responsible for having the right to share the data with us, for notices to your own customers and employees, and for telling us about any special handling requirements. We are responsible for following this policy, your instructions and the security measures below, and for helping you respond to data-subject requests, audits and regulators for the systems we built.
Business contact information about your staff, such as the names and emails of the people we work with, is handled under our general Privacy Policy, where we act as controller.
The rule
LightCI does not train, fine-tune or otherwise improve any AI model using client data. We configure and contract with model providers so that they cannot either.
We are model-agnostic in design and Claude-first in practice. Our default provider is Anthropic, accessed either through your own enterprise agreement, through the Claude Developer Platform on enterprise terms, or through your cloud provider’s hosted offering of Claude (such as Amazon Bedrock or Google Cloud Vertex AI) inside your account.
We give you the sub-processor list for your build before production, tell you before adding one, and honour your right to object. You may restrict us to particular providers, regions or deployment models, including cloud-only or on-premises.
Systems we build are deployed into infrastructure you own: your cloud accounts, your tenants, your identity provider, your secrets manager. API keys for model providers are issued under your accounts wherever possible, so usage, billing and logs are visible to you and survive our departure.
Agents act. That makes their data handling a design question, not just an access question. Every agent we deploy follows these defaults, which you can tighten:
Some categories of data get extra rules, agreed before we touch them.
We work with many companies, sometimes in the same sector and sometimes backed by the same investors. Your data, prompts, evaluations and outputs are never shared with, or reused for, another client.
During an engagement, client data lives in your environment under your retention policies. Working material we hold, such as notes, masked samples and meeting recordings, is limited to what the engagement needs.
At the end of an engagement, or earlier on request:
Exceptions are limited to what a law or a signed agreement requires us to keep, and to systems you have asked us to continue operating under a support contract.
If we become aware of a confirmed security incident affecting your data, we notify your designated contact without undue delay and no later than seventy-two hours after confirmation, or sooner if your agreement says so. The notice includes what we know, what we are doing, and what we need from you. We cooperate fully with your investigation and any regulatory notification you must make.
Security researchers and anyone who spots a problem in a system we built can write to us at privacy@lightci.com.
At any point in an engagement you can:
Regulatory posture
We design the systems we build to be explainable and logged, so you can meet transparency, record-keeping and human-oversight obligations under laws such as the EU AI Act and sector rules that apply to you. We will tell you plainly where a proposed use sits against those rules.
We may update this policy from time to time. We notify active clients of material changes before they take effect, and a change never reduces the protections in a signed agreement. Questions about how your data is handled, or a request under this policy, can go to the team below.
Privacy questions & requests
privacy@lightci.comWe respond within 30 days, and sooner for anything involving an active engagement.
LightCI
Attn: Privacy
Toronto, Ontario, Canada