Privacy Policy
Privacy Policy
1. Controller
LiftWize DataStream Limited
[Insert Your Irish Registered Address Here]
Dublin, Ireland
legal@liftwize.com
DPO Contact Details for Data Protection Matters: privacy@liftwize.com
This Privacy Policy informs you how LiftWize DataStream Limited as a data controller processes your personal data. This Privacy Policy concerns the LiftWize marketing websites (liftwize.com) and all platform services (app.liftwize.com) which collect personal data or are linked to this Privacy Policy. We maintain a shared customer, marketing, and stakeholder register, and our corporate Affiliates act as joint controllers for that register. If you are a consumer residing in the State of California, our supplementary privacy notice for California residents applies to you.
2. Name of Register
Customers, Marketing, and Stakeholders Register.
3. What Data Do We Process, and What is the Purpose and Legal Basis of Processing?
Data subjects are the customers, trial users, prospect customers, and other stakeholders of LiftWize DataStream Limited. Among the types of personal data LiftWize collects are:
Basic Information: Such as name, customer account number, username, and/or other direct identifiers.
Contact Information: Such as email address, phone number, and physical billing/business address.
Company Metrics: Information related to the company’s corporate contact persons and business structure.
Marketing Preferences: Explicit direct marketing opt-ins and opt-outs.
Event Information: Data you provide in connection with webinars, events, or product training sessions we host, including registration details and billing parameters.
Customer Relationship & Contractual Data: Information regarding past and current subscription plans, contract orders, formal correspondence, support chat history, payment methods, and other structural data voluntarily submitted to our platform.
Connection & Device Data: Information regarding the terminal device you use, including IP addresses, device IDs, browser configurations, geographic regions, and cookie data.
The Purpose of the Processing:
Delivering, maintaining, and improving our marketing analytics platform and cross-channel pipelines according to user needs.
Conducting user surveys and product feedback analyses.
Fulfilling our contractual promises, dashboard services, and operational obligations.
Purchasing and ordering necessary auxiliary software and services from our cloud suppliers to safely maintain our business.
Invoicing and processing corporate subscription accounts.
Bookkeeping, tax validation, and regulatory accounting.
Marketing our analytics services to relevant enterprise entities.
Honoring customer choices regarding direct marketing opt-outs.
Managing customer support channels, tickets, and user onboarding pipelines.
Targeting relevant business advertising across our online channels.
Analyzing platform telemetry and feature utilization trends to fix software bugs.
Recording optimization or sales strategy calls for internal employee training and process improvement.
The Legal Basis of Processing:
Consent: The data subject has given consent for one or more specific processing purposes (e.g., opting into marketing cookies via Cookiebot).
Contractual Necessity: Processing is necessary for the performance of a contract to which the data subject is a party (e.g., provision of the LiftWize SaaS dashboard).
Legal Obligation: Processing is necessary for compliance with a legal obligation to which LiftWize is subject under Irish or EU law (e.g., corporate financial bookkeeping).
Legitimate Interest: Processing is necessary for the purposes of the legitimate business interests pursued by LiftWize or by a verified third party (e.g., network security monitoring, fraud prevention, and performance analytics).
4. From Where Do We Receive Data?
We receive information primarily from the following sources: directly from you (during signup or form submissions), corporate authorities, credit check registries, professional social media channels (e.g., LinkedIn), contact information verification services, and connected marketing APIs.
We also automatically collect connectivity and conversion tracking telemetry when you interact with our marketing websites, user interfaces, or connected data paths. Detailed information on how we utilize cookies can be found in our standalone [Cookie Policy](Insert Link Here).
For the core purposes described in this Privacy Policy, personal data may also be dynamically collected and updated from publicly available corporate repositories or based on information securely received from administrative authorities within the boundary limits of applicable laws.
5. To Whom Do We Disclose Data, and Do We Transfer Data Outside the EU or EEA?
We may disclose data from this customer and marketing register to our trusted cooperation partners who run co-marketing campaigns or joint business events with us, and who act as independent data controllers (such as social media operators and enterprise advertising networks). Otherwise, we do not disclose personal data from the register to external parties unless legally mandated by a binding court or administrative order.
We utilize specialized infrastructure subcontractors that process personal data strictly on our behalf. We have outsourced our cloud server framework, IT architecture management, and database maintenance to tier-1 service providers (including Google, Amazon Web Services, and Cloudflare) on whose securely protected and encrypted environments your personal data is stored.
We transfer personal data outside the EU/EEA to fulfill the service delivery purposes stated in this Privacy Policy. When personal data is routed or stored outside the EU/EEA, we strictly ensure that the data is transferred in total alignment with applicable law, primarily by enforcing the European Commission’s Standard Contractual Clauses (SCCs) or utilizing other verified legal safeguards as described in Article 46 of the GDPR.
6. How Do We Protect the Data, and How Long Do We Store It?
Access to systems processing personal data is strictly restricted to authorized LiftWize employees on a role-based access control (RBAC) and strict "need-to-know" basis. Every internal system user is required to utilize strong unique passwords and mandatory Multi-Factor Authentication (MFA). Our data is housed in isolated cloud environments protected by secure web application firewalls, internal encryption metrics, and automated network logging perimeters. All regular database storage backups reside within top-tier cloud centers that utilize restricted physical perimeters accessible only to pre-designated system engineering personnel.
We store the data only for as long as it remains legally and operationally necessary for the specific purposes of processing. Personal data held within the Customer, Stakeholder, and Marketing registers is erased after the statutory claim limitation period related to that customer relationship has elapsed. This timeframe is typically five (5) to seven (7) years following active contract termination.
We regularly review the necessity of our data repositories against applicable data minimization principles. We take all reasonable steps to ensure that no incompatible, outdated, or inaccurate personal data is stored, and we act to correct or erase such records without delay upon discovery.
7. How Do We Use Cookies on Our Website?
Our marketing websites and social media interaction channels employ cookies, pixels, and related tracking scripts to optimize platform performance, analyze traffic metrics, record conversion attribution paths, and deliver targeted advertising across third-party networks. Cookies enable us to evaluate referring sites, page navigation flows, device types, browser categories, and connecting IP addresses.
To customize your opt-in selections, manage your cookie permissions, or view the complete audit list of active tracking tags generated by our consent management platform, Cookiebot, please review our comprehensive [Cookie Policy](Insert Link Here).
8. What Are Your Rights as a Data Subject?
You possess the absolute right to access the personal data stored by LiftWize concerning yourself, alongside the right to demand the immediate rectification or erasure of that data. You retain the right to withdraw your processing consent at any time where consent serves as the underlying legal basis. Withdrawing consent does not affect the lawfulness of any data processing executed prior to the withdrawal. Where processing is automated and based on your explicit consent or a binding contract, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, or request that we transmit it directly to another designated organization where technically feasible.
You hold the right to object to processing, to request the restriction of processing, and to lodge a formal complaint with a competent supervisory authority at any time free of charge. You can view the comprehensive list of European data protection authorities via the [European Data Protection Board Website](Link to EU Commission/EDPB website).
As an Irish-incorporated entity, our primary lead supervisory authority is the Data Protection Commission (DPC) of Ireland. Their formal contact information is detailed below:
Data Protection Commission (Ireland)
6 Pembroke Row
Dublin 2, D02 X963
Ireland
Telephone: +353 1 765 0100 / 1800 437 737
Email: info@dataprotection.ie
Website: www.dataprotection.ie
For specific personal reasons, you also possess the right to object to profiling and other data processing activities concerning yourself when our legitimate interest is cited as the legal foundation. In your written objection, you should explicitly clarify the unique circumstances surrounding your dispute. LiftWize can only refuse such requests based on clear statutory exemptions provided by law. No automated decision-making that produces definitive legal effects or similarly significantly impacts you takes place within our systems.
All requests, user rights exercises, and formal privacy inquiries should be submitted in writing to: privacy@liftwize.com.
9. Changes to This Privacy Policy
Should LiftWize introduce amendments to this Privacy Policy, we will publish the updated version directly on our website, clearly indicating the modification date at the top of the page. If the structural adjustments are significant, we will provide you with clear notice via additional communicative channels, such as a localized dashboard banner or a direct electronic email update. We recommend checking this policy periodically to stay informed of our active data security practices.
Supplementary Privacy Notice for California Residents
Last Updated: July 2026
This Supplementary Privacy Notice applies solely to individual residents of the State of California (“consumers” or “you”). We adopt this notice to comply with the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, the “CCPA”). This notice covers both our online interactions via liftwize.com and professional business-to-business (B2B) relationships.
1. Information We Collect and Disclose
In the preceding 12 months, LiftWize DataStream Limited has collected, used, and disclosed the following statutory categories of Personal Information for operational business purposes:
CCPA Category | Specific Pieces Collected | Purpose of Processing | Disclosed to / Shared With |
Identifiers | Real name, business email address, IP address, unique cookie IDs, account usernames. | Providing the SaaS dashboard, user authentication, managing client accounts. | Cloud hosting providers (AWS, Google), edge security networks (Cloudflare). |
Commercial Information | Subscription tiers, purchase histories, billing records, invoice metrics. | Invoicing, corporate accounting, transaction validation. | Payment processors, internal tax and accounting tools. |
Internet & Electronic Network Activity | Browsing history, page clicks, conversion tracking paths, interactions with ads. | Optimizing website layout, tracking marketing ROI, measuring campaign conversion success. | Analytics platforms (Google Analytics) and Advertising Networks (Google Ads, Meta Pixels). |
Geolocation Data | Coarse geographic location (country or city level) derived from IP routing. | Geolocation compliance checks, DDoS threat mitigation, regional routing. | Edge network providers (Cloudflare), consent tools (Cookiebot). |
Sensitive Personal Information | LiftWize account login credentials (username and password combinations). | To grant secure access to | AWS infrastructure (securely encrypted at rest). |
Notice on Sensitive Personal Information: LiftWize only collects account login credentials to fulfill the specific service you requested. We do not use or disclose your sensitive personal information for any other commercial profiling purposes, meaning we are not legally required to offer a "Right to Limit" link.
2. The "Sale" or "Sharing" of Data
LiftWize does not sell your personal information for monetary compensation.
However, because we deploy Google Ads conversion tracking and social media pixels on our marketing site, the CCPA defines these analytics interactions as “sharing” data for cross-context behavioral advertising.
Categories Shared: Identifiers and Internet/Electronic Network Activity.
Recipients: Google Ads, Meta, LinkedIn, and TikTok advertising ecosystems.
Opt-Out Availability: You can block this data exchange at any time by toggling off "Marketing" cookies in our footer Cookie Settings link, or by enabling the Global Privacy Control (GPC) signal in your web browser.
3. Your California Privacy Rights
As a California resident, you hold the following explicit legal rights regarding your data:
Right to Know & Access: You can request that we disclose the specific categories and pieces of personal information we have collected about you over the past 12 months, including the sources and commercial purposes for the collection.
Right to Delete: You can request that we delete personal data collected from you, subject to certain exceptions (such as data required to maintain your active SaaS account or satisfy tax compliance audits).
Right to Correct: If any data we hold about you is inaccurate (such as an incorrect corporate email or name), you have the right to request immediate rectification.
Right to Opt-Out of Sharing: You have the absolute right to direct us to stop sharing your data with third-party advertising networks.
Right to Non-Discrimination: We will never penalize, change subscription rates, or reduce the service quality of the LiftWize platform because you choose to exercise your CCPA privacy rights.
4. How to Exercise Your Rights
To submit an official request to access, correct, or delete your California consumer data, please use one of the following validated pathways:
Email Submission: Send a message directly to privacy@liftwize.com with the subject line "CCPA Consumer Rights Request."
Cookie Management Banner: To instantly exercise your Right to Opt-Out of Sharing, click the Cookie Settings link in our website footer to update your selections, or turn on the Global Privacy Control (GPC) plugin in your browser.
Request Verification Process:
To protect your account security, we are legally required to verify your identity before fulfilling access, deletion, or correction requests. We will typically match the email address from which you submit your request against the active account profile on record within our system database. Authorized agents may also submit requests on your behalf, provided they submit verified written proof of your signature and clear legal authorization.