Legal
LightEDR Ltd ("LightEDR", "we", "us") operates the LightEDR endpoint detection & response platform at lightedr.com. This policy describes what data we collect, how we use it, and your rights over it.
When you sign up we collect your work email address, organisation name, and a hashed password. We also record the plan tier you selected, your chosen region, and the timestamp at which you accepted these policies.
The LightEDR agent running on your endpoints transmits security-relevant events to our platform over an encrypted, mutually-authenticated (mTLS) connection. This telemetry may include:
This data belongs to you (your organisation). We process it only to operate the detection service on your behalf. See §4 (Retention) for how long we keep it.
We log authentication events (logins, token issuances), API requests, and platform health metrics. This data is used to operate, secure, and improve the service.
Paid plans are billed through Stripe. We never store or transmit your card number; Stripe provides us with a tokenised payment reference, your billing email, and invoice history. Stripe's own privacy policy governs data collected during payment.
If you contact us by email we retain that correspondence to resolve your query and improve support quality.
We use the data we collect to:
We do not use your endpoint telemetry to train machine-learning models or for any purpose outside operating your account.
We do not sell your data. We share it only with the sub-processors listed at lightedr.com/legal/sub-processors/. A summary follows:
Endpoint telemetry is retained for the period configured in your plan (7 days on Free, 30 days on Starter, 90 days on Business) and then automatically purged. You may configure shorter retention from your dashboard.
Account data is retained for the lifetime of your account plus 30 days following deletion to allow accidental-deletion recovery, then permanently deleted.
Billing records are retained for 6 years as required by UK accounting regulations (Companies Act 2006 / HMRC requirements).
We apply the following controls to protect your data:
Despite these measures, no system is perfectly secure. If you discover a vulnerability, please disclose it responsibly to security@lightedr.com.
Depending on your jurisdiction you may have the right to:
To exercise any of these rights, email privacy@lightedr.com from the address associated with your account. We will respond within 30 days.
If you are in the UK or EU and believe we have not handled your data lawfully, you have the right to lodge a complaint with your supervisory authority (in the UK: the ICO; in the EU: your national DPA).
The marketing website uses Microsoft Clarity for anonymised session analytics. Clarity may set cookies to understand user navigation. No personal data from Clarity is linked to your LightEDR account. The platform dashboard does not use third-party analytics cookies.
As a UK-based business we are subject to the UK PECR (Privacy and Electronic Communications Regulations). If you are visiting from the UK or EU, analytics cookies are only set after you have been informed of their use. You may opt out of Clarity tracking at any time by enabling "Do Not Track" in your browser.
The service is intended for business use and is not directed at individuals under 18. We do not knowingly collect data from minors.
We will notify registered users of material changes to this policy by email at least 14 days before they take effect. The current version is always available at lightedr.com/privacy/. Continued use of the service after the effective date constitutes acceptance.
LightEDR Ltd
United Kingdom
Email: privacy@lightedr.com
For enterprise customers requiring a Data Processing Agreement (DPA), please contact legal@lightedr.com.