LightEDR
Product
PricingCompanyBlogDocs
Sign inGet started

Legal

Privacy Policy

Last updated: 25 May 2026  ·  Version 1.0

LightEDR Ltd ("LightEDR", "we", "us") operates the LightEDR endpoint detection & response platform at lightedr.com. This policy describes what data we collect, how we use it, and your rights over it.

Contents

  1. Data we collect
  2. How we use it
  3. Who we share it with
  4. Retention
  5. Security
  6. Your rights
  7. Cookies & analytics
  8. Children
  9. Changes to this policy
  10. Contact

1. Data we collect

1.1 Account & organisation data

When you sign up we collect your work email address, organisation name, and a hashed password. We also record the plan tier you selected, your chosen region, and the timestamp at which you accepted these policies.

1.2 Endpoint telemetry

The LightEDR agent running on your endpoints transmits security-relevant events to our platform over an encrypted, mutually-authenticated (mTLS) connection. This telemetry may include:

  • Process creation and termination events (process name, path, command-line arguments, PID, parent PID)
  • Network connection events (source/destination IP, port, protocol)
  • File system events (paths, operations) where relevant to detection rules
  • User authentication events (login/logout, user identifiers)
  • Syslog entries forwarded from the monitored host

This data belongs to you (your organisation). We process it only to operate the detection service on your behalf. See §4 (Retention) for how long we keep it.

1.3 Usage & operational data

We log authentication events (logins, token issuances), API requests, and platform health metrics. This data is used to operate, secure, and improve the service.

1.4 Payment data

Paid plans are billed through Stripe. We never store or transmit your card number; Stripe provides us with a tokenised payment reference, your billing email, and invoice history. Stripe's own privacy policy governs data collected during payment.

1.5 Communications

If you contact us by email we retain that correspondence to resolve your query and improve support quality.

2. How we use it

We use the data we collect to:

  • Provision and operate your LightEDR tenant
  • Evaluate detection rules against your endpoint telemetry and generate alerts
  • Send transactional emails (verification links, alert digests, billing receipts)
  • Investigate and respond to security incidents
  • Improve detection accuracy and platform performance
  • Comply with legal obligations

We do not use your endpoint telemetry to train machine-learning models or for any purpose outside operating your account.

3. Who we share it with

We do not sell your data. We share it only with the sub-processors listed at lightedr.com/legal/sub-processors/. A summary follows:

  • Stripe, Inc. - payment processing. Stripe may transfer data internationally in accordance with their own SCCs.
  • Hostinger - transactional email delivery. Used to send verification links, alert digests, and billing receipts. Only your email address and the relevant message content are transmitted.
  • Hostinger - hosting infrastructure. Your data is stored on servers we control in the United Kingdom / European Union.
  • Legal or regulatory bodies - where we are compelled to disclose by a valid court order or applicable law. We will notify you where legally permitted.

4. Retention

Endpoint telemetry is retained for the period configured in your plan (7 days on Free, 30 days on Starter, 90 days on Business) and then automatically purged. You may configure shorter retention from your dashboard.

Account data is retained for the lifetime of your account plus 30 days following deletion to allow accidental-deletion recovery, then permanently deleted.

Billing records are retained for 6 years as required by UK accounting regulations (Companies Act 2006 / HMRC requirements).

5. Security

We apply the following controls to protect your data:

  • Tenant isolation: each customer's data is stored in a dedicated PostgreSQL schema, logically isolated from all other tenants.
  • Transport encryption: all data in transit is encrypted with TLS 1.2+. Agent connections use mutual TLS (mTLS) with per-agent certificates.
  • Encryption at rest: sensitive configuration values (e.g. OIDC client secrets) are encrypted at rest using AES-256.
  • Access controls: role-based access (admin, analyst, read-only) with JWT authentication and token revocation.
  • Passwords: stored as bcrypt hashes; we never store or log plaintext passwords.

Despite these measures, no system is perfectly secure. If you discover a vulnerability, please disclose it responsibly to security@lightedr.com.

6. Your rights

Depending on your jurisdiction you may have the right to:

  • Access a copy of the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Erase your personal data (subject to retention obligations)
  • Restrict or object to certain processing
  • Portability - receive your data in a machine-readable format
  • Withdraw consent at any time where processing is consent-based

To exercise any of these rights, email privacy@lightedr.com from the address associated with your account. We will respond within 30 days.

If you are in the UK or EU and believe we have not handled your data lawfully, you have the right to lodge a complaint with your supervisory authority (in the UK: the ICO; in the EU: your national DPA).

7. Cookies & analytics

The marketing website uses Microsoft Clarity for anonymised session analytics. Clarity may set cookies to understand user navigation. No personal data from Clarity is linked to your LightEDR account. The platform dashboard does not use third-party analytics cookies.

As a UK-based business we are subject to the UK PECR (Privacy and Electronic Communications Regulations). If you are visiting from the UK or EU, analytics cookies are only set after you have been informed of their use. You may opt out of Clarity tracking at any time by enabling "Do Not Track" in your browser.

8. Children

The service is intended for business use and is not directed at individuals under 18. We do not knowingly collect data from minors.

9. Changes to this policy

We will notify registered users of material changes to this policy by email at least 14 days before they take effect. The current version is always available at lightedr.com/privacy/. Continued use of the service after the effective date constitutes acceptance.

10. Contact

LightEDR Ltd
United Kingdom
Email: privacy@lightedr.com

For enterprise customers requiring a Data Processing Agreement (DPA), please contact legal@lightedr.com.

LightEDR

Lightweight endpoint detection & response, built for SOC teams and security partners.

Product

  • Overview
  • AI & Agents
  • Aggregators
  • Zero Trust EDR
  • For SOC Teams
  • For MSSPs
  • Pricing

Compare

  • vs CrowdStrike
  • vs SentinelOne
  • vs Huntress
  • vs Defender

Blog

  • All posts

Company

  • About
  • Security
  • Contact
  • Partner enquiries
© 2026 LightEDR Ltd
Terms of ServicePrivacy PolicySub-processorslegal@lightedr.com

We use analytics cookies (Microsoft Clarity) to understand how visitors use this site. The platform itself sets no third-party cookies.

We use analytics cookies to understand site usage.