Privacy Policy

LIGHTHOUSE PRIVACY POLICY

Version 1.0

Effective Date: 15 July 2026

Last Updated: 15 July 2026

INTRODUCTION

At Lighthouse, we recognize that privacy, transparency, and responsible data handling are fundamental to building trust.

This Privacy Policy explains how LH InfraMesh Pvt Ltd and its affiliates, subsidiaries, service providers, successors, and authorized representatives (collectively referred to as “Lighthouse”, “Company”, “we”, “our”, or “us”) collect, use, process, store, share, transfer, retain, and protect information relating to users of the Lighthouse Platform.

This Privacy Policy applies to all users of Lighthouse’s products and services, including professionals, architects, interior designers, consultants, contractors, manufacturers, brands, distributors, resellers, vendors, developers, enterprise customers, procurement teams, advertisers, and other participants.

We encourage you to read this Privacy Policy carefully.

By accessing or using the Platform, you acknowledge that your information may be processed in accordance with this Privacy Policy.

ARTICLE 1

INTRODUCTION

1.1 Our Commitment to Privacy

Lighthouse is committed to:

  • Respecting user privacy
  • Processing information responsibly
  • Maintaining appropriate security measures
  • Providing transparency regarding data processing
  • Complying with applicable privacy and data protection laws
  • Giving users meaningful control over their information

We believe users should understand:

  • What information is collected
  • Why information is collected
  • How information is used
  • Who information is shared with
  • How long information is retained
  • What rights users possess

1.2 Purpose of this Privacy Policy

This Privacy Policy explains:

a. Information Collection

The categories of information Lighthouse collects directly and indirectly.

b. Information Usage

How Lighthouse uses information to operate and improve its services.

c. Information Sharing

When and why information may be disclosed to other users, partners, service providers, enterprise customers, regulators, or other parties.

d. User Rights

The privacy rights available to users.

e. Security Measures

How Lighthouse seeks to protect information.

f. International Transfers

How information may be transferred across jurisdictions.

g. AI Processing

How information may be processed through Lighthouse AI Services.

1.3 Privacy Principles

Lighthouse seeks to operate according to the following principles:

Transparency

Users should understand how information is processed.

Purpose Limitation

Information should be used for legitimate business purposes.

Data Minimization

Only information reasonably necessary should be collected.

Security

Reasonable safeguards should be implemented.

Accountability

Lighthouse remains accountable for information under its control.

User Control

Users should have meaningful privacy choices whenever possible.

1.4 Global Operations

Lighthouse operates as a global platform.

Information may be processed in multiple countries where Lighthouse, its affiliates, service providers, infrastructure providers, or partners operate.

Additional privacy rights may apply depending upon the user’s location.

1.5 Relationship to Other Documents

This Privacy Policy should be read together with:

  • Terms of Service
  • Cookie Policy
  • AI Policy
  • User Uploaded Content & AI Processing Notice
  • Security Policy
  • Data Processing Addendum (where applicable)
  • Other applicable Lighthouse policies

Where a conflict exists between this Privacy Policy and a signed enterprise agreement, the signed enterprise agreement shall control solely with respect to the covered services.

ARTICLE 2

SCOPE OF THIS PRIVACY POLICY

2.1 Services Covered

This Privacy Policy applies to information collected through:

Lighthouse Websites

All Lighthouse-owned websites and web applications.

Mobile Applications

iOS, Android, tablet, and future mobile applications.

Enterprise Platforms

Enterprise procurement, collaboration, and workflow solutions.

Partner Portals

Brand, manufacturer, reseller, vendor, contractor, consultant, and partner portals.

Marketplace Services

Product discovery, product listing, RFQs, procurement workflows, and related services.

AI Services

AI-powered planning, recommendations, search, analysis, procurement support, design visualization, and related AI functionality.

Advertising Services

Sponsored listings, promotional services, campaigns, and advertising functionality.

APIs & Integrations

Developer services, APIs, and integrated systems.

2.2 Individuals Covered

This Privacy Policy applies to:

Visitors

Individuals browsing Lighthouse without creating an account.

Registered Users

Individuals with Platform accounts.

Professionals

Architects, designers, consultants, engineers, contractors, and related professionals.

Commercial Participants

Manufacturers, brands, distributors, resellers, dealers, and vendors.

Enterprise Users

Enterprise customers and authorized users.

Advertisers

Participants using advertising and promotional services.

Procurement Participants

Users participating in procurement and RFQ workflows.

2.3 Information Not Covered

This Privacy Policy generally does not apply to:

Third-Party Services

Information collected by third-party websites, applications, or services not controlled by Lighthouse.

Independent Professional Relationships

Information exchanged directly between users outside the Platform.

Third-Party Transactions

Information processed independently by third-party payment providers, logistics providers, contractors, suppliers, or professionals.

Such parties may maintain their own privacy policies.

2.4 Regional Privacy Requirements

Certain regions may provide additional privacy rights and protections.

Where required by applicable law, Lighthouse shall provide additional disclosures relating to:

  • Data subject rights
  • International transfers
  • Consent requirements
  • Data access requests
  • Data deletion requests
  • Regulatory complaint procedures

2.5 Future Services

This Privacy Policy applies to future Lighthouse services unless superseded by a separate privacy notice.

ARTICLE 3

DEFINITIONS

For purposes of this Privacy Policy, the following definitions apply.

3.1 Account

A registered profile created on the Lighthouse Platform.

3.2 AI Services

Any artificial intelligence, machine learning, recommendation, automation, predictive, analytical, generative, or related functionality offered by Lighthouse.

3.3 AI Output

Any recommendation, estimate, report, visualization, generated image, generated text, classification, prediction, ranking, procurement recommendation, or similar output produced by AI Services.

3.4 Personal Information

Any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an individual.

Examples may include:

  • Name
  • Email address
  • Phone number
  • Address
  • Profile information
  • Identification information
  • Device identifiers
  • Online identifiers

3.5 Sensitive Personal Information

Information subject to heightened protection under applicable laws.

Examples may include:

  • Government identification information
  • Financial information
  • Verification information
  • Biometric information (where collected)
  • Other categories defined by law

3.6 User

Any individual or legal entity accessing or using the Platform.

3.7 User Content

Any content uploaded, submitted, posted, stored, transmitted, or otherwise provided by a user.

Examples include:

  • Projects
  • Product listings
  • Images
  • Drawings
  • Floor plans
  • BIM files
  • CAD files
  • Reviews
  • Messages
  • RFQs

3.8 Processing

Any operation performed on information including:

  • Collection
  • Storage
  • Use
  • Analysis
  • Sharing
  • Transfer
  • Disclosure
  • Deletion

3.9 Service Provider

Any third party engaged by Lighthouse to support Platform operations.

3.10 Platform

All Lighthouse websites, mobile applications, systems, marketplaces, procurement services, AI services, APIs, enterprise services, and related offerings.

ARTICLE 4

INFORMATION YOU PROVIDE TO US

4.1 General

Lighthouse collects information that Users voluntarily provide when interacting with the Platform.

The categories of information collected may vary depending upon:

  • Account type
  • Services used
  • Features accessed
  • User role
  • Subscription level
  • Jurisdiction

4.2 Account Registration Information

When creating an Account, Users may provide:

Individual Information

  • Full name
  • Display name
  • Username
  • Email address
  • Mobile number
  • Password credentials
  • Date of birth (where applicable)
  • Country
  • State
  • City

Business Information

  • Company name
  • Business type
  • Registration number
  • Tax registration details
  • Website address
  • Business email
  • Business phone number

4.3 Profile Information

Users may provide profile information including:

Professional Information

  • Profession
  • Specialization
  • Experience
  • Education
  • Certifications
  • Licenses
  • Memberships
  • Awards
  • Skills

Business Information

  • Business description
  • Team information
  • Services offered
  • Geographic coverage
  • Operating locations

Social Information

  • Biography
  • Profile photographs
  • Cover photographs
  • Portfolio information
  • Social media links

4.4 Verification Information

To verify identity or business legitimacy, Lighthouse may collect:

Individual Verification

  • Government-issued identification
  • Professional licenses
  • Certification documents
  • Address proof

Business Verification

  • Company registration certificates
  • GST/VAT registrations
  • Trademark registrations
  • Manufacturer authorizations
  • Distributor authorizations
  • Reseller authorizations

4.5 Communications Information

When Users communicate through the Platform, Lighthouse may collect:

  • Messages
  • Attachments
  • RFQ communications
  • Procurement communications
  • Support requests
  • Feedback submissions
  • Survey responses
  • Complaint submissions

4.6 Project Information

Users may upload:

  • Project photographs
  • Renderings
  • Drawings
  • Floor plans
  • Specifications
  • BIM files
  • CAD files
  • Project descriptions
  • Project budgets
  • Project timelines

4.7 Product Information

Commercial participants may provide:

  • Product information
  • Product specifications
  • Product dimensions
  • Product images
  • Product videos
  • Product certifications
  • Product warranty information
  • Product catalogues

4.8 Enterprise Information

Enterprise customers may provide:

  • Employee information
  • Procurement information
  • Vendor information
  • Business process information
  • Workflow information
  • Project information

4.9 Payment Information

Depending upon services used, Users may provide:

  • Billing information
  • Invoicing information
  • Tax information
  • Subscription information

Payment card information is generally processed by third-party payment processors and may not be stored by Lighthouse.

ARTICLE 5

INFORMATION WE COLLECT AUTOMATICALLY

5.1 General

When Users access the Platform, certain information may be collected automatically.

5.2 Device Information

We may collect:

  • Device type
  • Device model
  • Operating system
  • Browser type
  • Browser version
  • Application version
  • Device identifiers

5.3 Log Information

We may collect:

  • Login activity
  • Logout activity
  • Access times
  • Access dates
  • Session information
  • Error logs
  • Diagnostic information

5.4 Network Information

We may collect:

  • IP address
  • Approximate geographic location
  • Internet service provider information
  • Network information

5.5 Usage Information

We may collect information regarding:

  • Pages viewed
  • Features accessed
  • Searches performed
  • Projects viewed
  • Products viewed
  • RFQs submitted
  • Leads generated
  • Advertisements viewed
  • AI tools accessed

5.6 Interaction Information

We may collect information regarding:

  • Clicks
  • Scrolling behavior
  • Navigation patterns
  • Session duration
  • User preferences

5.7 Cookies & Similar Technologies

We may collect information through:

  • Cookies
  • Pixels
  • SDKs
  • Tags
  • Local storage technologies
  • Similar technologies

Additional details are provided in the Cookie Policy.

ARTICLE 6

INFORMATION WE RECEIVE FROM THIRD PARTIES

6.1 Third-Party Sources

We may receive information from third parties including:

  • Authentication providers
  • Enterprise customers
  • Business partners
  • Advertising partners
  • Analytics providers
  • Verification providers
  • Public sources

6.2 Social Login Providers

Where Users register through third-party authentication services, Lighthouse may receive:

  • Name
  • Email address
  • Profile information
  • Account identifiers

subject to permissions granted by the User.

6.3 Enterprise Customers

Enterprise customers may provide information relating to authorized users.

6.4 Verification Providers

Verification partners may provide information relating to:

  • Identity validation
  • Business validation
  • Credential validation

6.5 Public Sources

Information may be obtained from publicly available sources including:

  • Government registries
  • Professional directories
  • Public websites
  • Public databases

where permitted by applicable law.

ARTICLE 7

INFORMATION COLLECTED THROUGH AI SERVICES

7.1 AI Interactions

When Users interact with AI Services, Lighthouse may collect:

  • Prompts
  • Instructions
  • Questions
  • Requests
  • Uploaded files
  • Uploaded images
  • Uploaded plans
  • Uploaded drawings
  • AI feedback

7.2 AI Material Planner Data

Users may provide:

  • Project type
  • Budget information
  • Material preferences
  • Location information
  • Procurement requirements

7.3 AI Space Revamp Data

Users may upload:

  • Existing space images
  • Reference images
  • Design preferences
  • Product preferences
  • Budget preferences

7.4 AI Procurement Planner Data

Users may provide:

  • Product requirements
  • Procurement requirements
  • RFQs
  • Vendor preferences
  • Project timelines

7.5 AI Usage Analytics

We may collect information regarding:

  • AI feature usage
  • Prompt categories
  • Output categories
  • AI interaction patterns

for improving Platform functionality.

ARTICLE 8

INFORMATION COLLECTED THROUGH MARKETPLACE & PROCUREMENT SERVICES

8.1 Marketplace Activities

Lighthouse may collect information regarding:

  • Products viewed
  • Brands viewed
  • Suppliers viewed
  • Search activity
  • Product comparisons
  • Product preferences

8.2 RFQ Information

We may collect:

  • RFQ details
  • Product requirements
  • Project requirements
  • Quantity requirements
  • Budget information
  • Delivery requirements

8.3 Procurement Information

We may collect:

  • Procurement workflows
  • Supplier selections
  • Procurement decisions
  • Procurement preferences
  • Procurement analytics

8.4 Lead Information

We may collect information relating to:

  • Lead requests
  • Lead responses
  • Lead interactions
  • Lead performance

8.5 Advertising Information

We may collect information relating to:

  • Advertisement impressions
  • Advertisement clicks
  • Campaign interactions
  • Promotional interactions

8.6 Business Intelligence Information

We may generate aggregated and de-identified information relating to Platform usage, procurement trends, product trends, project trends, and marketplace activity.

Such information does not identify individual users.

ARTICLE 9

HOW WE USE INFORMATION

9.1 General Purpose of Processing

Lighthouse processes information to:

  1. Operate the Platform;
  2. Provide requested services;
  3. Authenticate Users;
  4. Facilitate marketplace interactions;
  5. Enable procurement workflows;
  6. Provide AI-powered functionality;
  7. Improve user experience;
  8. Maintain security;
  9. Detect fraud;
  10. Comply with legal obligations;
  11. Support enterprise services;
  12. Conduct business operations.

9.2 Service Delivery

Information may be processed to:

  1. Create accounts;
  2. Authenticate users;
  3. Maintain profiles;
  4. Display portfolios;
  5. Display products;
  6. Facilitate RFQs;
  7. Deliver procurement workflows;
  8. Provide enterprise functionality.

9.3 Personalization

Information may be used to personalize:

  1. Search results;
  2. Product recommendations;
  3. Supplier recommendations;
  4. Professional recommendations;
  5. Project recommendations;
  6. AI outputs;
  7. Marketplace experiences.

9.4 Communication

Information may be used to:

  1. Send service notifications;
  2. Respond to support requests;
  3. Send security alerts;
  4. Provide transactional communications;
  5. Deliver account-related notices.

9.5 Analytics & Improvement

Information may be processed to:

  1. Improve Platform functionality;
  2. Improve AI models;
  3. Improve procurement workflows;
  4. Improve user experience;
  5. Improve search systems;
  6. Improve recommendation systems.

9.6 Compliance Purposes

Information may be processed to:

  1. Comply with laws;
  2. Comply with court orders;
  3. Respond to regulatory requests;
  4. Enforce Platform policies;
  5. Protect rights and interests.

ARTICLE 10

ACCOUNT MANAGEMENT

10.1 Account Creation

Information is processed to:

  1. Create accounts;
  2. Maintain accounts;
  3. Verify identities;
  4. Manage subscriptions;
  5. Manage permissions.

10.2 Authentication

Information may be used to:

  1. Verify identity;
  2. Authenticate users;
  3. Detect unauthorized access;
  4. Protect accounts.

10.3 Verification Services

Information may be processed for:

  1. Professional verification;
  2. Business verification;
  3. Product verification;
  4. Credential verification;
  5. Identity verification.

10.4 Profile Management

Information may be used to:

  1. Display profiles;
  2. Display portfolios;
  3. Display qualifications;
  4. Display professional information;
  5. Facilitate discovery.

10.5 Subscription Administration

Information may be processed to:

  1. Manage subscriptions;
  2. Process payments;
  3. Issue invoices;
  4. Manage renewals;
  5. Provide premium services.

ARTICLE 11

AI SERVICES

11.1 AI Operations

Information may be processed to operate AI Services including:

  1. AI Material Planner;
  2. AI Budget Planner;
  3. AI Procurement Planner;
  4. AI Space Revamp;
  5. AI Product Discovery;
  6. AI Search;
  7. AI Analytics;
  8. Future AI Services.

11.2 AI Input Processing

Information submitted to AI Services may be processed to:

  1. Interpret requests;
  2. Generate outputs;
  3. Produce recommendations;
  4. Generate visualizations;
  5. Create reports.

11.3 AI Improvement

Subject to applicable laws, user preferences, contractual obligations, and Platform policies, Lighthouse may use information to:

  1. Improve AI accuracy;
  2. Improve AI safety;
  3. Improve AI performance;
  4. Improve recommendation systems;
  5. Improve user experience.

11.4 Human Review

Certain AI interactions may be reviewed by authorized personnel for:

  1. Quality assurance;
  2. Safety;
  3. Security;
  4. Abuse prevention;
  5. Service improvement.

11.5 AI Governance

Information may be processed to:

  1. Detect AI misuse;
  2. Detect abuse;
  3. Detect prohibited activity;
  4. Ensure responsible AI operation.

ARTICLE 12

MARKETPLACE SERVICES

12.1 Product Discovery

Information may be processed to:

  1. Display products;
  2. Recommend products;
  3. Categorize products;
  4. Improve product search.

12.2 Supplier Discovery

Information may be processed to:

  1. Match suppliers;
  2. Recommend suppliers;
  3. Display suppliers;
  4. Improve supplier discovery.

12.3 Professional Discovery

Information may be processed to:

  1. Recommend professionals;
  2. Display professionals;
  3. Match users with professionals;
  4. Improve professional discovery.

12.4 Lead Generation

Information may be processed to:

  1. Generate leads;
  2. Distribute leads;
  3. Track lead performance;
  4. Improve lead quality.

12.5 Advertising Services

Information may be processed to:

  1. Deliver advertisements;
  2. Measure campaign performance;
  3. Improve advertising relevance;
  4. Prevent advertising fraud.

ARTICLE 13

PROCUREMENT SERVICES

13.1 Procurement Workflows

Information may be processed to:

  1. Create RFQs;
  2. Route RFQs;
  3. Match suppliers;
  4. Compare quotations;
  5. Support procurement workflows.

13.2 Procurement Planning

Information may be processed to:

  1. Generate procurement recommendations;
  2. Generate procurement insights;
  3. Support sourcing activities;
  4. Support procurement analytics.

13.3 Supplier Matching

Information may be used to identify suppliers potentially relevant to a procurement requirement.

Lighthouse does not guarantee suitability of matched suppliers.

13.4 Procurement Analytics

Information may be processed to:

  1. Improve procurement systems;
  2. Improve supplier discovery;
  3. Improve recommendation quality;
  4. Improve workflow efficiency.

13.5 Fraud Prevention

Information may be processed to detect:

  1. Fake RFQs;
  2. Procurement fraud;
  3. Supplier fraud;
  4. Identity fraud;
  5. Commercial abuse.

13.6 Business Operations

Information may be processed for:

  1. Reporting;
  2. Auditing;
  3. Compliance;
  4. Recordkeeping;
  5. Internal administration.

ARTICLE 14

LEAD GENERATION

14.1 Lead Services

Lighthouse may process information to facilitate lead generation activities between users, professionals, suppliers, brands, manufacturers, contractors, consultants, developers, and enterprise customers.

14.2 Lead Matching

Information may be processed to:

  1. Match users with professionals;
  2. Match users with suppliers;
  3. Match RFQs with vendors;
  4. Recommend service providers;
  5. Recommend procurement participants.

14.3 Lead Distribution

Information may be shared with relevant participants for purposes of:

  1. Responding to inquiries;
  2. Responding to RFQs;
  3. Providing quotations;
  4. Providing consultations;
  5. Facilitating commercial interactions.

14.4 Lead Analytics

Information may be processed to:

  1. Measure lead quality;
  2. Measure lead performance;
  3. Improve lead matching;
  4. Improve conversion rates;
  5. Improve Platform functionality.

14.5 Lead Protection

Lighthouse may implement measures to prevent:

  1. Fake leads;
  2. Lead abuse;
  3. Unauthorized lead harvesting;
  4. Lead reselling;
  5. Lead manipulation.

ARTICLE 15

SECURITY & FRAUD PREVENTION

15.1 Security Purposes

Information may be processed to:

  1. Protect users;
  2. Protect accounts;
  3. Protect Platform systems;
  4. Detect unauthorized access;
  5. Detect misuse.

15.2 Fraud Prevention

Information may be processed to detect:

  1. Identity fraud;
  2. Procurement fraud;
  3. Payment fraud;
  4. Listing fraud;
  5. Counterfeit product activity;
  6. Fake project activity;
  7. Fake review activity;
  8. Account abuse.

15.3 Security Monitoring

Lighthouse may monitor Platform activity to:

  1. Detect security incidents;
  2. Detect suspicious activity;
  3. Protect Platform integrity;
  4. Prevent abuse.

15.4 Verification Activities

Information may be processed to:

  1. Verify identities;
  2. Verify businesses;
  3. Verify credentials;
  4. Verify product ownership;
  5. Verify project ownership.

15.5 Incident Investigation

Information may be processed to investigate:

  1. Security incidents;
  2. Fraud incidents;
  3. Policy violations;
  4. Regulatory matters;
  5. Legal disputes.

15.6 Security Logs

Lighthouse may maintain logs and records relating to:

  1. Authentication events;
  2. Access events;
  3. Security events;
  4. Administrative actions;
  5. Platform activities.

ARTICLE 16

MARKETING & ADVERTISING

16.1 Marketing Communications

Lighthouse may use information to provide:

  1. Product updates;
  2. Service announcements;
  3. Newsletters;
  4. Event invitations;
  5. Promotional communications;
  6. Industry updates.

16.2 Marketing Preferences

Users may manage marketing preferences through available Platform settings or by following unsubscribe instructions.

16.3 Advertising Services

Information may be used to:

  1. Deliver advertising;
  2. Deliver sponsored content;
  3. Measure advertising performance;
  4. Improve advertising relevance.

16.4 Promotional Campaigns

Information may be used to administer:

  1. Referral programs;
  2. Loyalty programs;
  3. Rewards programs;
  4. Promotional campaigns;
  5. Contests and events.

16.5 Advertising Measurement

Lighthouse may process information relating to:

  1. Advertisement impressions;
  2. Advertisement clicks;
  3. Campaign interactions;
  4. Conversion activities.

16.6 No Sale of Personal Information

Except where expressly disclosed, contractually authorized, legally required, or permitted under applicable law, Lighthouse does not sell personal information in exchange for monetary consideration.

ARTICLE 17

ANALYTICS & PRODUCT IMPROVEMENT

17.1 Platform Improvement

Information may be processed to:

  1. Improve Platform performance;
  2. Improve user experience;
  3. Improve reliability;
  4. Improve functionality.

17.2 Marketplace Improvement

Information may be processed to improve:

  1. Product discovery;
  2. Supplier discovery;
  3. Professional discovery;
  4. Procurement workflows;
  5. Lead generation systems.

17.3 AI Improvement

Subject to applicable laws and Platform policies, information may be processed to improve:

  1. AI recommendations;
  2. AI search;
  3. AI procurement assistance;
  4. AI visualizations;
  5. AI planning tools.

17.4 Research & Development

Information may be used for:

  1. Product research;
  2. Service development;
  3. Platform testing;
  4. Innovation initiatives.

17.5 Aggregated Information

Lighthouse may generate aggregated, statistical, anonymized, or de-identified information for:

  1. Analytics;
  2. Research;
  3. Reporting;
  4. Industry insights;
  5. Platform improvement.

Such information is not intended to identify individuals.

ARTICLE 18

LEGAL BASIS FOR PROCESSING

18.1 General

Where required by applicable law, Lighthouse processes information only when a valid legal basis exists.

18.2 Contractual Necessity

Processing may be necessary to:

  1. Create accounts;
  2. Provide services;
  3. Deliver subscriptions;
  4. Operate procurement workflows;
  5. Operate marketplace services.

18.3 Consent

Processing may be based on consent where required by law.

Examples may include:

  1. Marketing communications;
  2. Optional cookies;
  3. Certain AI features;
  4. Optional integrations.

18.4 Legitimate Interests

Processing may be based upon legitimate business interests including:

  1. Security;
  2. Fraud prevention;
  3. Service improvement;
  4. Analytics;
  5. Platform administration.

Provided such interests are balanced against user rights.

18.5 Legal Obligations

Processing may be necessary to:

  1. Comply with laws;
  2. Comply with court orders;
  3. Comply with regulatory requirements;
  4. Respond to lawful requests.

18.6 Protection of Rights

Processing may be necessary to:

  1. Protect users;
  2. Protect Lighthouse;
  3. Protect public interests;
  4. Prevent harm.

ARTICLE 19

CONSENT & WITHDRAWAL OF CONSENT

19.1 Obtaining Consent

Where required by applicable law, Lighthouse shall obtain consent before processing information.

19.2 Scope of Consent

Consent may apply to:

  1. Marketing communications;
  2. Optional cookies;
  3. Optional data sharing;
  4. Certain AI features;
  5. Other optional processing activities.

19.3 Withdrawal of Consent

Users may withdraw consent at any time, subject to legal, contractual, and operational limitations.

19.4 Effect of Withdrawal

Withdrawal of consent shall not affect processing conducted before withdrawal.

19.5 Service Impact

Withdrawal of consent may limit access to certain features where processing is necessary for operation of those features.

19.6 Recordkeeping

Lighthouse may maintain records of consent and consent withdrawals for compliance purposes.

ARTICLE 20

SHARING WITH OTHER USERS

20.1 Public Profile Information

Certain information may be visible to other users depending on account settings and platform functionality.

Examples may include:

  • Name
  • Display name
  • Company name
  • Profile photograph
  • Cover image
  • Biography
  • Professional information
  • Services offered
  • Portfolio information
  • Verification status
  • Awards
  • Certifications
  • Reviews and ratings

20.2 Project Information

Information associated with published projects may be visible to other users including:

  • Project title
  • Project description
  • Project images
  • Product tags
  • Brand tags
  • Professional tags
  • Location information (where provided)
  • Project categories

20.3 Product Information

Commercial participants may make product information available to users including:

  • Product descriptions
  • Specifications
  • Images
  • Catalogues
  • Certifications
  • Warranty information
  • Availability information

20.4 Reviews & Ratings

Reviews, ratings, testimonials, comments, and related content submitted by users may be visible to other users.

20.5 Communications

Where users voluntarily communicate with other users, information may be shared directly with the intended recipients.

20.6 User-Controlled Sharing

Users remain responsible for information they choose to make publicly visible or share with other users.

ARTICLE 21

SHARING WITH PROFESSIONALS, SUPPLIERS & COMMERCIAL PARTICIPANTS

21.1 Procurement & RFQ Sharing

When users submit RFQs, inquiries, consultation requests, or procurement requests, relevant information may be shared with:

  • Architects
  • Interior Designers
  • Consultants
  • Contractors
  • Manufacturers
  • Brands
  • Suppliers
  • Distributors
  • Resellers
  • Vendors
  • Other relevant participants

for purposes of responding to the request.

21.2 Lead Distribution

Information associated with lead requests may be shared with relevant participants for purposes of:

  • Responding to inquiries
  • Providing quotations
  • Providing consultations
  • Facilitating procurement activities
  • Facilitating commercial engagements

21.3 Professional Matching

Information may be shared when users request assistance identifying:

  • Professionals
  • Suppliers
  • Products
  • Services
  • Procurement participants

21.4 Product & Procurement Workflows

Information may be shared to facilitate:

  • Product discovery
  • Supplier discovery
  • Quotation requests
  • Procurement planning
  • Material planning
  • Project sourcing

21.5 User Responsibility

Users should carefully evaluate information before sharing sensitive project, procurement, commercial, or business information with third parties.

ARTICLE 22

SHARING WITH SERVICE PROVIDERS

22.1 Service Providers

Lighthouse may share information with service providers that support Platform operations.

22.2 Categories of Service Providers

Examples include:

Infrastructure Providers

  • Cloud hosting providers
  • Data storage providers
  • Content delivery providers

Security Providers

  • Security monitoring providers
  • Fraud prevention providers
  • Threat detection providers

Payment Providers

  • Payment processors
  • Subscription processors
  • Billing providers

Communication Providers

  • Email providers
  • Messaging providers
  • Notification providers

Analytics Providers

  • Analytics platforms
  • Performance monitoring providers
  • Reporting providers

Verification Providers

  • Identity verification providers
  • Business verification providers
  • Credential verification providers

AI Providers

  • AI infrastructure providers
  • AI model providers
  • AI processing providers

22.3 Limited Purpose Sharing

Service providers may only process information for authorized purposes and subject to contractual obligations.

22.4 Confidentiality Requirements

Service providers are expected to maintain reasonable confidentiality, privacy, and security measures.

ARTICLE 23

SHARING WITH ENTERPRISE CUSTOMERS

23.1 Enterprise Services

Where enterprise services are used, information may be shared with enterprise customers and their authorized administrators.

23.2 Enterprise Administration

Enterprise administrators may access information relating to:

  • Authorized users
  • Account activity
  • Procurement activity
  • Workflow activity
  • Enterprise-managed content

subject to applicable agreements.

23.3 Employer-Controlled Accounts

Where an account is provided by an employer, organization, institution, or enterprise customer, certain information may be accessible to authorized administrators.

23.4 Enterprise Agreements

Additional information-sharing obligations may be governed by:

  • Enterprise Terms
  • SaaS Agreements
  • Data Processing Addenda
  • Enterprise Security Addenda

ARTICLE 24

LEGAL DISCLOSURES

24.1 Compliance With Laws

Lighthouse may disclose information where reasonably necessary to:

  • Comply with laws
  • Comply with court orders
  • Comply with regulatory requirements
  • Comply with lawful requests

24.2 Protection of Rights

Information may be disclosed to:

  • Protect users
  • Protect Lighthouse
  • Protect service providers
  • Protect the public

24.3 Fraud Prevention

Information may be disclosed where reasonably necessary to:

  • Investigate fraud
  • Investigate security incidents
  • Investigate policy violations
  • Prevent unlawful activity

24.4 Regulatory Requests

Information may be disclosed to:

  • Regulatory authorities
  • Government agencies
  • Law enforcement agencies
  • Courts
  • Administrative authorities

where legally required or permitted.

24.5 Emergency Situations

Information may be disclosed where reasonably necessary to:

  • Prevent serious harm
  • Protect safety
  • Respond to emergencies
  • Protect public interests

ARTICLE 25

CORPORATE TRANSACTIONS

25.1 Business Changes

Information may be transferred in connection with:

  • Mergers
  • Acquisitions
  • Investments
  • Corporate restructurings
  • Asset sales
  • Insolvency proceedings
  • Financing transactions

25.2 Due Diligence

Information may be disclosed to potential investors, acquirers, lenders, advisors, auditors, consultants, or transaction participants subject to appropriate confidentiality obligations.

25.3 Successor Organizations

Where Lighthouse undergoes a corporate transaction, information may be transferred to successor entities.

25.4 Continued Protection

Any successor entity receiving information shall be expected to honor applicable privacy obligations and legal requirements.

ARTICLE 26

INTERNATIONAL DATA TRANSFERS

26.1 Global Operations

Lighthouse operates globally and information may be processed, stored, accessed, transferred, or hosted in multiple jurisdictions.

26.2 Cross-Border Transfers

Information may be transferred between countries where:

  • Lighthouse operates
  • Service providers operate
  • Enterprise customers operate
  • Infrastructure providers operate

26.3 Transfer Safeguards

Where required by applicable law, Lighthouse may implement safeguards including:

  • Contractual protections
  • Data transfer agreements
  • Security measures
  • Regulatory mechanisms

26.4 User Acknowledgement

Users acknowledge that information may be transferred internationally in accordance with this Privacy Policy.

ARTICLE 27

AI DATA PROCESSING

27.1 AI Services

Lighthouse may utilize artificial intelligence, machine learning, generative AI, predictive analytics, automation technologies, recommendation systems, and related technologies (“AI Services”) to provide Platform functionality.

27.2 AI Processing Activities

Information may be processed through AI Services for purposes including:

  1. Product discovery;
  2. Supplier discovery;
  3. Professional discovery;
  4. Procurement planning;
  5. Material planning;
  6. Quantity estimation;
  7. Budget estimation;
  8. Project planning;
  9. Space redesign;
  10. Design visualization;
  11. Search enhancement;
  12. Analytics;
  13. Workflow automation.

27.3 AI Processing Scope

AI Services may analyze:

  • User Inputs
  • User Content
  • Project Information
  • Product Information
  • RFQs
  • Procurement Data
  • Platform Interactions
  • Search Activity
  • Usage Patterns

for purposes described in this Privacy Policy.

27.4 AI Infrastructure

AI Services may be operated through:

  • Lighthouse-owned systems
  • Third-party AI providers
  • Cloud-based AI infrastructure
  • Enterprise AI integrations
  • Future AI technologies

subject to applicable contractual and legal requirements.

27.5 AI Processing Notice

Users acknowledge that information submitted to AI-powered features may be processed by AI systems in order to generate requested functionality.

ARTICLE 28

AI INPUTS

28.1 User Inputs

Users may voluntarily submit information to AI Services.

Examples include:

Text Inputs

  • Prompts
  • Questions
  • Instructions
  • Requests

Image Inputs

  • Space photographs
  • Product images
  • Site photographs
  • Design references

Technical Inputs

  • Floor plans
  • Drawings
  • BIM files
  • CAD files
  • Specifications

Commercial Inputs

  • Budgets
  • RFQs
  • Procurement requirements
  • Vendor requirements
  • Material requirements

28.2 Ownership of Inputs

Users retain ownership of information they lawfully own and submit to AI Services.

28.3 Authorization

Users represent and warrant that they possess necessary rights and permissions to submit AI Inputs.

28.4 Sensitive Information

Users should avoid submitting information that:

  • Is unnecessary for requested services
  • Is confidential and unauthorized for disclosure
  • Violates contractual obligations
  • Violates applicable laws

unless specifically required for a Platform service.

28.5 Input Storage

AI Inputs may be stored, retained, logged, analyzed, or processed in accordance with:

  • This Privacy Policy
  • AI Policy
  • Data Retention Schedule
  • Applicable laws

ARTICLE 29

AI OUTPUTS

29.1 Generated Outputs

AI Services may generate:

  • Recommendations
  • Estimates
  • Visualizations
  • Product suggestions
  • Procurement suggestions
  • Design concepts
  • Reports
  • Analytics
  • Insights

29.2 Relationship Between Inputs & Outputs

AI Outputs are generated based upon patterns, models, datasets, algorithms, user inputs, and other factors.

Outputs may not always accurately reflect real-world conditions.

29.3 Similar Outputs

Users acknowledge that similar or identical outputs may be generated for different users.

29.4 Output Storage

Lighthouse may retain AI Outputs for:

  • Service delivery
  • Platform operations
  • User access
  • Quality assurance
  • Compliance obligations

29.5 Output Analytics

Information relating to AI Outputs may be analyzed to:

  • Improve recommendations
  • Improve accuracy
  • Improve reliability
  • Improve user experience

ARTICLE 30

HUMAN REVIEW OF AI CONTENT

30.1 Human Review

Certain AI interactions may be reviewed by authorized personnel.

30.2 Review Purposes

Human review may occur for:

  1. Quality assurance;
  2. Service improvement;
  3. Security;
  4. Fraud prevention;
  5. Safety reviews;
  6. Compliance obligations;
  7. Technical troubleshooting.

30.3 Restricted Access

Human review access shall be limited to authorized personnel with legitimate business needs.

30.4 Confidentiality

Personnel involved in review activities are expected to comply with confidentiality, privacy, security, and internal governance requirements.

30.5 Review Minimization

Lighthouse seeks to minimize human access to AI interactions wherever reasonably possible.

ARTICLE 31

AI TRAINING & PLATFORM IMPROVEMENT

31.1 Service Improvement

Information may be used to improve:

  • AI functionality
  • Recommendation systems
  • Search systems
  • Marketplace functionality
  • Procurement workflows
  • Platform performance

31.2 Model Improvement

Subject to applicable laws, contractual commitments, user preferences, and internal policies, Lighthouse may use information to:

  1. Improve model performance;
  2. Improve safety;
  3. Improve relevance;
  4. Improve accuracy;
  5. Reduce harmful outputs.

31.3 Aggregated Information

Lighthouse may generate aggregated, anonymized, statistical, or de-identified information for:

  • AI improvement
  • Product development
  • Research
  • Analytics
  • Reporting

31.4 Enterprise Restrictions

Where enterprise agreements restrict AI training or model improvement activities, Lighthouse shall comply with such contractual commitments.

31.5 Future AI Technologies

Lighthouse may introduce future AI technologies that process information in accordance with this Privacy Policy and applicable laws.

ARTICLE 32

AI RISK CONTROLS & GOVERNANCE

32.1 Responsible AI Principles

Lighthouse seeks to operate AI Services according to principles including:

  • Fairness
  • Transparency
  • Accountability
  • Security
  • Reliability
  • Human oversight

32.2 Risk Management

Lighthouse may implement controls designed to identify and mitigate risks relating to:

  • Bias
  • Inaccuracy
  • Security threats
  • Fraud
  • Misuse
  • Unauthorized access

32.3 AI Governance Program

Lighthouse may maintain governance frameworks addressing:

  • AI development
  • AI deployment
  • AI monitoring
  • AI security
  • AI compliance

32.4 High-Risk Activities

Certain AI activities may be subject to enhanced controls, review procedures, validation requirements, monitoring activities, or human oversight.

Examples include:

  • Procurement planning
  • Quantity estimation
  • Budget estimation
  • Supplier scoring
  • Construction-related recommendations

32.5 User Responsibilities

Users remain responsible for independently evaluating AI-generated recommendations before making business, procurement, design, construction, financial, or operational decisions.

32.6 Regulatory Compliance

Lighthouse may modify AI Services to comply with:

  • Emerging AI regulations
  • Data protection laws
  • Industry standards
  • Government requirements
  • Enterprise obligations

ARTICLE 33

DATA RETENTION

33.1 Retention Principles

Lighthouse retains information only for as long as reasonably necessary to:

  1. Provide Platform services;
  2. Operate the Platform;
  3. Comply with legal obligations;
  4. Resolve disputes;
  5. Prevent fraud;
  6. Protect security;
  7. Enforce agreements;
  8. Maintain business records.

33.2 Retention Factors

Retention periods may depend upon:

  1. Type of information;
  2. Purpose of processing;
  3. User relationship;
  4. Legal requirements;
  5. Regulatory obligations;
  6. Security requirements;
  7. Contractual commitments.

33.3 Account Information

Account-related information may be retained during the life of an account and for a reasonable period thereafter.

33.4 Procurement Records

RFQs, procurement workflows, procurement communications, procurement decisions, quotations, and related records may be retained for compliance, audit, legal, and operational purposes.

33.5 Project Information

Projects, portfolios, drawings, BIM files, CAD files, images, specifications, and related content may be retained while associated accounts remain active and for additional periods as required.

33.6 Verification Records

Identity verification records, business verification records, and supporting documents may be retained for fraud prevention, compliance, audit, and legal purposes.

33.7 Financial Records

Invoices, billing records, subscription records, advertising records, and payment-related records may be retained as required by applicable tax, accounting, and legal obligations.

33.8 Security Records

Security logs, audit logs, authentication records, incident records, and related information may be retained for security and compliance purposes.

33.9 AI Records

AI Inputs, AI Outputs, AI interaction logs, AI usage information, and AI-related records may be retained in accordance with:

  • AI Policy
  • Data Retention Schedule
  • Enterprise Agreements
  • Applicable laws

33.10 Deletion Requests

Where permitted by law, Users may request deletion of certain information.

Deletion requests may be subject to:

  1. Legal obligations;
  2. Contractual obligations;
  3. Security requirements;
  4. Fraud prevention requirements;
  5. Ongoing disputes;
  6. Regulatory obligations.

33.11 Anonymization

Where appropriate, Lighthouse may anonymize, aggregate, or de-identify information rather than delete it.

ARTICLE 34

INFORMATION SECURITY

34.1 Security Commitment

Lighthouse seeks to implement reasonable administrative, technical, organizational, and physical safeguards designed to protect information.

34.2 Security Objectives

Security measures are intended to protect against:

  1. Unauthorized access;
  2. Unauthorized disclosure;
  3. Unauthorized modification;
  4. Unauthorized destruction;
  5. Data loss;
  6. Security incidents.

34.3 Security Program

Lighthouse may maintain security programs addressing:

  1. Governance;
  2. Risk management;
  3. Access controls;
  4. Monitoring;
  5. Incident response;
  6. Vendor management;
  7. Security awareness.

34.4 Encryption

Where appropriate, Lighthouse may utilize encryption technologies for:

  1. Data in transit;
  2. Data at rest;
  3. Authentication processes;
  4. Sensitive information.

34.5 Infrastructure Security

Lighthouse may utilize:

  1. Firewalls;
  2. Network protections;
  3. Threat detection systems;
  4. Monitoring systems;
  5. Security tooling.

34.6 Security Testing

Security measures may include:

  1. Vulnerability assessments;
  2. Penetration testing;
  3. Security reviews;
  4. Code reviews;
  5. Infrastructure assessments.

34.7 No Absolute Security Guarantee

No system can be guaranteed to be completely secure.

Users acknowledge that security risks may exist despite reasonable safeguards.

ARTICLE 35

ACCESS CONTROLS

35.1 Need-to-Know Access

Access to information is generally limited to authorized personnel with legitimate business needs.

35.2 Role-Based Access

Lighthouse may utilize role-based access controls to restrict access to information.

35.3 Authentication Controls

Access controls may include:

  1. Password protection;
  2. Multi-factor authentication;
  3. Device controls;
  4. Session controls;
  5. Access reviews.

35.4 Personnel Access Management

Lighthouse may implement procedures relating to:

  1. User provisioning;
  2. User de-provisioning;
  3. Access reviews;
  4. Access restrictions.

35.5 Enterprise Access Controls

Enterprise customers may be provided administrative tools to manage authorized users.

35.6 Monitoring

Access activities may be logged, monitored, reviewed, and audited for security purposes.

ARTICLE 36

INCIDENT RESPONSE

36.1 Incident Management

Lighthouse may maintain incident response procedures designed to identify, investigate, contain, remediate, and document security incidents.

36.2 Security Events

Security events may include:

  1. Unauthorized access;
  2. Unauthorized disclosure;
  3. Malware incidents;
  4. Data compromise;
  5. Service disruptions;
  6. Infrastructure attacks.

36.3 Investigation Activities

Incident investigations may involve:

  1. Log analysis;
  2. System reviews;
  3. Security reviews;
  4. Forensic activities;
  5. Vendor coordination.

36.4 Notifications

Where required by applicable law, contractual commitments, or regulatory obligations, Lighthouse may provide notifications relating to certain security incidents.

36.5 Remediation

Lighthouse may take corrective actions including:

  1. Security updates;
  2. Access restrictions;
  3. Service modifications;
  4. Infrastructure improvements.

36.6 Documentation

Incident records may be maintained for audit, compliance, legal, and operational purposes.

ARTICLE 37

INTERNATIONAL DATA TRANSFERS

37.1 Global Operations

Lighthouse operates internationally and information may be processed in multiple jurisdictions.

37.2 Transfer Scenarios

Information may be transferred:

  1. Between Lighthouse entities;
  2. To service providers;
  3. To enterprise customers;
  4. To infrastructure providers;
  5. To support Platform operations.

37.3 Legal Mechanisms

Where required, Lighthouse may implement safeguards including:

  1. Contractual commitments;
  2. Data transfer agreements;
  3. Regulatory mechanisms;
  4. Security measures.

37.4 User Acknowledgement

Users acknowledge that information may be processed in countries with data protection laws different from those in their home jurisdiction.

37.5 Adequacy Measures

Where required by law, Lighthouse may assess transfer risks and implement additional protections.

ARTICLE 38

DATA LOCALIZATION & CROSS-BORDER PROCESSING

38.1 Regional Requirements

Certain jurisdictions may impose data localization, residency, or cross-border transfer restrictions.

Lighthouse may implement region-specific controls where required.

38.2 Local Storage

Where commercially, technically, legally, or contractually required, Lighthouse may maintain information within specific geographic regions.

38.3 Distributed Infrastructure

Lighthouse may utilize distributed cloud infrastructure, backup systems, content delivery systems, and service providers located in multiple jurisdictions.

38.4 Cross-Border Support

Authorized personnel, service providers, and enterprise support teams may access information across borders where necessary to provide services.

38.5 Future Localization Requirements

Lighthouse reserves the right to modify infrastructure, storage locations, transfer mechanisms, and processing arrangements to comply with evolving legal requirements.

ARTICLE 39

USER PRIVACY RIGHTS

39.1 General Rights

Subject to applicable laws, contractual obligations, technical limitations, and legal requirements, Users may possess privacy rights relating to their information.

Such rights may vary depending upon:

  1. User location;
  2. Applicable law;
  3. Type of information;
  4. Nature of processing;
  5. Contractual relationships.

39.2 Available Rights

Users may have rights including:

  1. Access rights;
  2. Correction rights;
  3. Deletion rights;
  4. Data portability rights;
  5. Restriction rights;
  6. Objection rights;
  7. Consent withdrawal rights;
  8. Marketing preference rights;
  9. Complaint rights.

39.3 Verification of Requests

Before fulfilling certain requests, Lighthouse may require reasonable verification of identity to:

  1. Protect user information;
  2. Prevent fraud;
  3. Prevent unauthorized disclosure;
  4. Comply with legal obligations.

39.4 Limitations

Certain rights may be limited where:

  1. Laws require retention;
  2. Contractual obligations exist;
  3. Fraud prevention requirements exist;
  4. Security requirements exist;
  5. Rights of others may be affected.

ARTICLE 40

ACCESS REQUESTS

40.1 Right to Access

Subject to applicable law, Users may request information regarding:

  1. Information collected;
  2. Information used;
  3. Categories of information;
  4. Processing activities;
  5. Sharing activities;
  6. Retention practices.

40.2 Information Provided

Where required by law, Lighthouse may provide information regarding:

  1. Personal information maintained;
  2. Categories of recipients;
  3. Processing purposes;
  4. Retention information;
  5. Rights available to Users.

40.3 Request Submission

Access requests may be submitted through:

  1. Account settings;
  2. Privacy request forms;
  3. Support channels;
  4. Designated privacy contacts.

40.4 Response Periods

Lighthouse shall respond within timeframes required by applicable laws.

40.5 Exceptions

Certain information may be withheld where permitted by law, including:

  1. Information affecting other individuals;
  2. Security-related information;
  3. Confidential business information;
  4. Legally protected information.

ARTICLE 41

CORRECTION REQUESTS

41.1 Right to Correct

Users may request correction of inaccurate or incomplete information.

41.2 Self-Service Updates

Where available, Users may update information through account settings.

41.3 Verification

Lighthouse may request supporting evidence where reasonably necessary.

41.4 Professional Information

Users remain responsible for maintaining accurate:

  1. Qualifications;
  2. Certifications;
  3. Licenses;
  4. Business information;
  5. Product information;
  6. Portfolio information.

41.5 Correction Limitations

Certain historical records, transaction records, audit logs, and compliance records may not be modified.

ARTICLE 42

DELETION REQUESTS

42.1 Right to Request Deletion

Subject to applicable law, Users may request deletion of certain information.

42.2 Scope of Deletion

Deletion may include:

  1. Account information;
  2. Profile information;
  3. User-generated content;
  4. Communication records;
  5. Platform information.

42.3 Exceptions

Lighthouse may retain information where reasonably necessary to:

  1. Comply with laws;
  2. Comply with tax obligations;
  3. Resolve disputes;
  4. Prevent fraud;
  5. Protect rights;
  6. Maintain security;
  7. Fulfill contractual obligations.

42.4 Account Closure

Closure of an Account does not automatically result in immediate deletion of all information.

42.5 Anonymization Alternative

Where appropriate, Lighthouse may anonymize or de-identify information instead of deleting it.

ARTICLE 43

DATA PORTABILITY

43.1 Right to Portability

Where required by law, Users may request a copy of certain information in a structured, commonly used, and machine-readable format.

43.2 Eligible Information

Portability requests may apply to:

  1. Profile information;
  2. Account information;
  3. User-submitted information;
  4. Certain usage information.

43.3 Technical Limitations

Portability may be subject to technical feasibility and legal restrictions.

43.4 Security Controls

Lighthouse may implement verification procedures before releasing portable information.

ARTICLE 44

OBJECTION & RESTRICTION RIGHTS

44.1 Objection Rights

Where applicable, Users may object to certain processing activities.

44.2 Restriction Rights

Users may request restrictions on processing in circumstances permitted by law.

44.3 Evaluation

Lighthouse may evaluate:

  1. Legal requirements;
  2. Contractual obligations;
  3. Legitimate interests;
  4. Technical feasibility;

before acting upon such requests.

44.4 Continuing Processing

Certain processing activities may continue where permitted by applicable law.

ARTICLE 45

MARKETING PREFERENCES

45.1 Marketing Choices

Users may control marketing communications through available settings and communication preferences.

45.2 Unsubscribe Rights

Marketing emails may generally include unsubscribe mechanisms.

45.3 Service Communications

Users may continue receiving:

  1. Security notices;
  2. Transactional notices;
  3. Account notices;
  4. Compliance notices;
  5. Service-related communications.

even where marketing communications are disabled.

45.4 Advertising Preferences

Users may be provided options to manage advertising-related preferences where available.

45.5 Consent-Based Marketing

Where required by law, marketing communications shall be based on valid consent or another lawful basis.

ARTICLE 46

REGIONAL PRIVACY RIGHTS

46.1 General

Certain jurisdictions provide additional privacy rights.

Where applicable, Lighthouse shall honor such rights in accordance with relevant laws.

46.2 European Economic Area, United Kingdom & Switzerland

Users located in these regions may possess rights including:

  1. Access;
  2. Rectification;
  3. Erasure;
  4. Restriction;
  5. Portability;
  6. Objection;
  7. Complaint rights.

46.3 India

Users in India may possess rights under applicable Indian data protection laws, including rights relating to:

  1. Information access;
  2. Correction;
  3. Erasure;
  4. Grievance redressal;
  5. Consent management.

46.4 United States

Users in certain U.S. states may possess rights relating to:

  1. Access;
  2. Correction;
  3. Deletion;
  4. Opt-out rights;
  5. Appeal rights.

46.5 Canada

Canadian users may possess privacy rights under applicable federal and provincial privacy laws.

46.6 Australia

Australian users may possess privacy rights under applicable privacy legislation.

46.7 Singapore

Singapore users may possess privacy rights under applicable personal data protection laws.

46.8 Other Jurisdictions

Lighthouse may provide additional rights where required by applicable law.

46.9 Regulatory Complaints

Users may lodge complaints with applicable data protection authorities, privacy regulators, grievance officers, or other competent authorities where permitted by law.

ARTICLE 47

CHILDREN’S PRIVACY

47.1 General Policy

The Lighthouse Platform is primarily intended for business, professional, procurement, marketplace, and enterprise users.

The Platform is generally not directed toward children.

47.2 Minimum Age

Users must meet the minimum age requirements applicable within their jurisdiction to create and operate an Account.

Where applicable law requires parental or guardian consent, such consent must be obtained before use.

47.3 Information Collection

Lighthouse does not knowingly collect personal information from children in violation of applicable laws.

47.4 Parental Requests

Parents, guardians, or authorized representatives who believe information relating to a child has been improperly collected may contact Lighthouse for review.

47.5 Removal of Information

Where Lighthouse becomes aware that information has been collected in violation of applicable law, Lighthouse may:

  1. Delete information;
  2. Restrict access;
  3. Terminate accounts;
  4. Take other appropriate actions.

ARTICLE 48

COOKIES & TRACKING TECHNOLOGIES

48.1 Use of Cookies

Lighthouse may utilize cookies and similar technologies to support Platform functionality.

48.2 Categories of Cookies

Cookies may include:

Essential Cookies

Required for Platform operation.

Examples:

  • Authentication
  • Security
  • Session management

Functional Cookies

Used to remember:

  • Preferences
  • Settings
  • Language choices
  • User experience selections

Analytics Cookies

Used to understand:

  • Platform usage
  • User behavior
  • Performance metrics
  • Service quality

Advertising Cookies

Used to:

  • Measure advertising performance
  • Improve campaign effectiveness
  • Deliver relevant promotions

48.3 Cookie Management

Users may manage cookie preferences through:

  • Browser settings
  • Consent management tools
  • Cookie preference centers

where available.

48.4 Impact of Disabling Cookies

Disabling certain cookies may affect Platform functionality.

48.5 Additional Information

Further details are available in the Cookie Policy.

ARTICLE 49

ADVERTISING TECHNOLOGIES

49.1 Advertising Services

Lighthouse may utilize technologies supporting:

  1. Sponsored listings;
  2. Featured content;
  3. Advertising campaigns;
  4. Promotional activities;
  5. Marketing analytics.

49.2 Advertising Information

Information processed may include:

  • Advertisement views
  • Advertisement clicks
  • Campaign interactions
  • Conversion metrics

49.3 Advertising Measurement

Information may be processed to:

  1. Measure performance;
  2. Improve campaigns;
  3. Prevent advertising fraud;
  4. Improve relevance.

49.4 Sponsored Content

Certain content appearing on the Platform may be sponsored or promoted.

49.5 Advertising Partners

Advertising-related information may be shared with authorized service providers supporting advertising operations.

ARTICLE 50

THIRD-PARTY SERVICES

50.1 Third-Party Providers

The Platform may integrate with third-party services including:

  1. Payment processors;
  2. Cloud providers;
  3. Communication providers;
  4. Verification providers;
  5. AI providers;
  6. Analytics providers;
  7. Enterprise software providers;
  8. Mapping providers;
  9. Infrastructure providers.

50.2 Independent Policies

Third-party providers may maintain independent privacy notices, terms, and practices.

50.3 Third-Party Responsibility

Lighthouse is not responsible for privacy practices of third-party services not controlled by Lighthouse.

50.4 User Responsibility

Users should review applicable privacy notices before interacting with third-party services.

50.5 Future Integrations

Lighthouse may add, modify, or remove third-party integrations over time.

ARTICLE 51

CHANGES TO THIS PRIVACY POLICY

51.1 Updates

Lighthouse may update this Privacy Policy periodically.

51.2 Reasons for Updates

Updates may occur due to:

  1. Regulatory changes;
  2. Product changes;
  3. Service changes;
  4. Security requirements;
  5. Operational changes;
  6. AI developments.

51.3 Notification Methods

Updates may be communicated through:

  1. Website notices;
  2. Mobile app notifications;
  3. Email communications;
  4. Platform announcements.

51.4 Effective Date

Updated versions become effective on the date specified within the revised Privacy Policy.

51.5 Continued Use

Continued use of the Platform following an effective update constitutes acknowledgment of the revised Privacy Policy.

ARTICLE 52

CONTACT INFORMATION

52.1 Privacy Questions

Questions relating to this Privacy Policy may be submitted through Lighthouse’s designated privacy contact channels.

52.2 Privacy Requests

Privacy rights requests may be submitted through:

  1. Account settings;
  2. Privacy request forms;
  3. Support channels;
  4. Designated privacy contacts.

52.3 Official Communications

Official privacy-related communications may be delivered electronically where permitted by law.

ARTICLE 53

DATA PROTECTION OFFICER

53.1 Appointment

Where required by applicable law, Lighthouse may appoint a Data Protection Officer (“DPO”) or equivalent privacy representative.

53.2 Responsibilities

The DPO may oversee:

  1. Privacy compliance;
  2. Data protection governance;
  3. Privacy requests;
  4. Regulatory interactions;
  5. Privacy incident management.

53.3 Contact Information

DPO contact details shall be published on the Platform where applicable.

ARTICLE 54

GRIEVANCE OFFICER

54.1 Appointment

Where required by applicable law, Lighthouse may appoint a Grievance Officer.

54.2 Responsibilities

The Grievance Officer may address:

  1. Privacy complaints;
  2. User concerns;
  3. Data requests;
  4. Regulatory matters;
  5. Escalations.

54.3 Contact Information

Grievance Officer details shall be made available through the Platform.

54.4 Resolution Process

Complaints shall be reviewed and addressed in accordance with applicable laws and internal procedures.

ARTICLE 55

EFFECTIVE DATE

55.1 Effective Date

This Privacy Policy becomes effective on the date specified at the beginning of this document.

55.2 Applicability

This Privacy Policy applies to information processed from the effective date onward and, where permitted by law, to information previously collected and maintained by Lighthouse.

55.3 Acceptance

By using the Platform, Users acknowledge the practices described in this Privacy Policy.

PRIVACY POLICY SCHEDULES

SCHEDULE A

CATEGORIES OF PERSONAL INFORMATION

Identity Information

  • Name
  • Username
  • Date of birth
  • Identification details

Contact Information

  • Email address
  • Phone number
  • Address

Professional Information

  • Experience
  • Certifications
  • Licenses
  • Qualifications

Business Information

  • Company details
  • Registration information
  • Tax information

Project Information

  • Project uploads
  • Drawings
  • BIM files
  • CAD files

Procurement Information

  • RFQs
  • Supplier preferences
  • Procurement workflows

AI Information

  • Prompts
  • AI Inputs
  • AI Outputs

Usage Information

  • Search activity
  • Platform interactions
  • Analytics information

SCHEDULE B

DATA RETENTION SCHEDULE

Information Category

Typical Retention

Account Records

Up to 7 Years

Verification Records

Up to 7 Years

RFQ Records

Up to 10 Years

Procurement Records

Up to 10 Years

Financial Records

As Required By Law

Security Logs

Up to 5 Years

AI Records

Per AI Policy

Enterprise Records

Per Contract

SCHEDULE C

INTERNATIONAL DATA TRANSFER SCHEDULE

Cross-border transfers may occur for:

  • Platform operations
  • Enterprise services
  • Cloud hosting
  • AI processing
  • Security operations
  • Customer support

Appropriate safeguards may be implemented where required.

SCHEDULE D

AI PROCESSING SCHEDULE

AI Inputs

  • Prompts
  • Images
  • Drawings
  • Plans
  • RFQs

AI Outputs

  • Recommendations
  • Reports
  • Visualizations
  • Estimates

AI Processing Purposes

  • Service delivery
  • Search
  • Recommendations
  • Platform improvement
  • Security

SCHEDULE E

COOKIE CATEGORIES SCHEDULE

Essential Cookies

Required for Platform operation.

Functional Cookies

Preference and settings management.

Analytics Cookies

Performance and usage analytics.

Advertising Cookies

Advertising measurement and optimization.