OVERVIEW
THE LYON COMPANY LLC. (THE “COMPANY”) IS COMMITTED TO MAINTAINING ROBUST PRIVACY PROTECTIONS FOR ITS USERS. OUR PRIVACY POLICY (“PRIVACY POLICY”) IS DESIGNED TO HELP YOU UNDERSTAND HOW WE COLLECT, USE AND SAFEGUARD THE INFORMATION YOU PROVIDE TO US AND TO ASSIST YOU IN MAKING INFORMED DECISIONS WHEN USING OUR SERVICE.
FOR PURPOSES OF THIS AGREEMENT, “SITE” REFERS TO THE COMPANY’S WEBSITE, WHICH CAN BE ACCESSED AT HTTPS://THELYONCOMPANY.COM OR HTTPS://WWW.THELYONCOMPANY.COM. “SERVICE” REFERS TO THE COMPANY’S SERVICES ACCESSED VIA THE SITE, IN WHICH USERS CAN CONTACT THE COMPANY. THE TERMS “WE,” “US,” AND “OUR” REFER TO THE COMPANY.“YOU” REFERS TO YOU, AS A USER OF OUR SITE OR OUR SERVICE.
BY ACCESSING OUR SITE OR OUR SERVICE, YOU ACCEPT OUR PRIVACY POLICY AND TERMS OF USE FOUND HERE: HTTPS://THELYONCOMPANY.COM/TERMS-OF-SERVICE, AND YOU CONSENT TO OUR COLLECTION, STORAGE, USE AND DISCLOSURE OF YOUR PERSONAL INFORMATION AS DESCRIBED IN THIS PRIVACY POLICY.
I. INFORMATION WE COLLECT
We collect “NON-PERSONAL INFORMATION” and “PERSONAL INFORMATION.” Non-Personal Information includes information that cannot be used to personally identify you, such as anonymous usage data, general demographic information we may collect, referring/exit pages and URLs, platform types, preferences you submit and preferences that are generated based on the data you submit and number of clicks. Personal Information includes your email, which you submit to us through the registration process at the Site.
INFORMATION COLLECTED VIA TECHNOLOGY :
To activate the Service you do not need to submit any Personal Information other than your email address. To use the Service thereafter, you do not need to submit further Personal Information [,which may include: IP Address, Browser Type, Operating System].
However, in an effort to improve the quality of the Service, we track information provided to us by your browser or by our software application when you view or use the Service, such as the website you came from (known as the “referring URL”), the type of browser you use, the device from which you connected to the Service, the time and date of access, and other information that does not personally identify you.
We track this information using cookies, or small text files which include an anonymous unique identifier. Cookies are sent to a user’s browser from our servers and are stored on the user’s computer hard drive. Sending a cookie to a user’s browser enables us to collect Non-Personal information about that user and keep a record of the user’s preferences when utilizing our services, both on an individual and aggregate basis. For example, the Company may use cookies to collect the following information :
Web Traffic :
- IP Address
- Browser Type
- Operating System
INFORMATION YOU PROVIDE US BY REGISTERING FOR AN ACCOUNT :
In addition to the information provided automatically by your browser when you visit the Site, to become a subscriber to the Service you will need to create a personal profile. You can create a profile by registering with the Service and entering your email address, and creating a user name and a password. By registering, you are authorizing us to collect, store and use your email address in accordance with this Privacy Policy.
Company :
- Company name
- Address (if company is a customer) - billing
- VAT number (if applicable) - billing
Contacts :
- First name
- Last name
- Email address
- Relevant notes, like when we had contact
CHILDREN’S PRIVACY :
The Site and the Service are not directed to anyone under the age of 13. The Site does not knowingly collect or solicit information from anyone under the age of 13, or allow anyone under the age of 13 to sign up for the Service. In the event that we learn that we have gathered personal information from anyone under the age of 13 without the consent of a parent or guardian, we will delete that information as soon as possible. If you believe we have collected such information, please contact us at [email protected].
II. HOW WE USE AND SHARE INFORMATION
PERSONAL INFORMATION :
Except as otherwise stated in this Privacy Policy, we do not sell, trade, rent or otherwise share for marketing purposes your Personal Information with third parties without your consent. We do share Personal Information with vendors who are performing services for the Company, such as the servers for our email communications who are provided access to user’s email address for purposes of sending emails from us. Those vendors use your Personal Information only at our direction and in accordance with our Privacy Policy.
In general, the Personal Information you provide to us is used to help us communicate with you. For example, we use Personal Information to contact users in response to questions, solicit feedback from users, provide technical support, and inform users about promotional offers. We may share Personal Information with outside parties if we have a good-faith belief that access, use, preservation or disclosure of the information is reasonably necessary to meet any applicable legal process or enforceable governmental request; to enforce applicable Terms of Service, including investigation of potential violations; address fraud, security or technical concerns; or to protect against harm to the rights, property, or safety of our users or the public as required or permitted by law.
NON-PERSONAL INFORMATION :
In general, we use Non-Personal Information to help us improve the Service and customize the user experience. We also aggregate Non-Personal Information in order to track trends and analyze use patterns on the Site. This Privacy Policy does not limit in any way our use or disclosure of Non-Personal Information and we reserve the right to use and disclose such Non-Personal Information to our partners, advertisers and other third parties at our discretion.
In the event we undergo a business transaction such as a merger, acquisition by another company, or sale of all or a portion of our assets, your Personal Information may be among the assets transferred. You acknowledge and consent that such transfers may occur and are permitted by this Privacy Policy, and that any acquirer of our assets may continue to process your Personal Information as set forth in this Privacy Policy. If our information practices change at any time in the future, we will post the policy changes to the Site so that you may opt out of the new information practices. We suggest that you check the Site periodically if you are concerned about how your information is used.
III. HOW WE PROTECT INFORMATION
We implement security measures designed to protect your information from unauthorized access. Your account is protected by your account password and we urge you to take steps to keep your personal information safe by not disclosing your password and by logging out of your account after each use.
We further protect your information from potential security breaches by implementing certain technological security measures including encryption, firewalls and secure socket layer technology. However, these measures do not guarantee that your information will not be accessed, disclosed, altered or destroyed by breach of such firewalls and secure server software. By using our Service, you acknowledge that you understand and agree to assume these risks.
WEBSITE SECURITY :
HTTP Protocol :
- Where possible, servers need to be configured to allow HTTP1.1 and HTTP2. Using the latter indirectly forces to use HTTPS, which is the preferred way of deploying any service provided by our company.
HTTPS Only :
- All websites and intranet sites that contain confidential or sensitive data, will be HTTPS-only. The server configuration is allowed to listen to port 80 and redirect visitors to the secured protocol version.
SSL Version :
- Old protocol versions of SSL (SSLv2 and SSLv3) are no longer allowed, as they are considered insecure.
TLS Version :
- When possible, limit clients to the last few versions of the TLS protocol. Currently this is 1.2 and 1.3. Older versions should only be allowed when there is a clear business need.
Content Security Protocol (CSP) :
- Although not required yet, all of our websites and web-based products are expected to be configured with CSP.
Storage :
- Where possible all data should be stored on encrypted drives. This helps against attacks during the “data at rest” phase, like data stored on an USB drive. It also prevents people from rebooting any of our servers without our knowledge.
Backup :
- To counter data loss, backups need to be created for important assets and data. As a backup is another copy of the data, the same rules apply to storage. Where possible, it needs to be encrypted. Backups should not be stored longer than needed.
Retention :
- The rule regarding data retention is simple: as short as possible. We only backup what is really needed and are especially careful not to store customer data too long. For example, audit data is usually easy to be recreated.
IV. YOUR RIGHTS REGARDING THE USE OF YOUR PERSONAL INFORMATION
You have the right at any time to prevent us from contacting you for marketing purposes. When we send a promotional communication to a user, the user can opt out of further promotional communications by following the unsubscribe instructions provided in each promotional e-mail. Please note that notwithstanding the promotional preferences you indicate by either unsubscribing or opting out, we may continue to send you administrative emails including, for example, periodic updates to our Privacy Policy.
CCPA :
In addition, a business subject to California Business and Professions Code Section 22581 must allow California residents under age 18 who are registered users of online sites, services or applications to request and obtain removal of content or information they have publicly posted. Your request should include a detailed description of the specific content or information to be removed. Please be aware that your request does not guarantee complete or comprehensive removal of content or information posted online and that the law may not permit or require removal in certain circumstances.
For purposes of the CCPA, The Lyon Company LLC has not sold Personal Information relating to California residents in the last 12 months. Under California Civil Code section 1798.83, California residents who provide Personal Information in obtaining products or services for personal, family, or household use may request information about the Personal Information shared by The Lyon Company LLC, if any, with other third parties for their own direct marketing purposes. If applicable, this information will include the identity and addresses of those third parties and the type of Personal Information.
GDPR :
The European General Data Protection Regulation (GDPR) is of limited impact for our business. This is mostly because we do business-to-business. The information stored about individuals, EU citizens in particular, is typically limited to their full name (first, last), with sometimes their personal email address. Typically we do not store address details of individuals, as that is not our typical customer.
The GDPR states that IP addresses should be considered personal data. This because it can be seen as an ‘online identifiers’. We do store IP addresses in our logs, mainly for security reasons. This allows us to counter malicious or excessive traffic. We do not use IP addresses for identification of a person. Log files are rotated daily, with at most 60 rotated copies.
V. LINKS TO OTHER WEBSITES
As part of the Service, we may provide links to or compatibility with other websites or applications. However, we are not responsible for the privacy practices employed by those websites or the information or content they contain. This Privacy Policy applies solely to information collected by us through the Site and the Service. Therefore, this Privacy Policy does not apply to your use of a third party website accessed by selecting a link on our Site or via our Service. To the extent that you access or use the Service through or on another website or application, then the privacy policy of that other website or application will apply to your access or use of that site or application. We encourage our users to read the privacy statements of other websites before proceeding to use them.
VI. CHANGES TO OUR PRIVACY POLICY
The Company reserves the right to change this policy and our Terms of Service at any time. We will notify you of significant changes to our Privacy Policy by sending a notice to the primary email address specified in your account or by placing a prominent notice on our site. Significant changes will go into effect 30 days following such notification. Non-material changes or clarifications will take effect immediately. You should periodically check the Site and this privacy page for updates.
VII. CONTACT US
If you have any questions regarding this Privacy Policy or the practices of this Site, please contact us by sending an email to [email protected].
Last Updated: This Privacy Policy was last updated on: 1-10-2021