Privacy Policy
How Lytheron OÜ handles personal data when you visit, create an account, use Lytheron Pallet or contact us.
La versión inglesa es la versión contractual de referencia.
1. Who is responsible for your data
Lytheron OÜ, registry code 17311276, registered at Tuukri tn 19-202, Kesklinna linnaosa, 10120 Tallinn, Estonia, is the controller for account, website, support, security and commercial-contact data it determines how to use.
For operational personal data uploaded or entered by a customer organisation into Lytheron Pallet on behalf of that organisation, the customer normally acts as controller and Lytheron OÜ acts as processor under the Data Processing Addendum.
Privacy and legal enquiries: legal@lytheron.com.
2. Data we may process
- Account and identity data such as name, business email, authentication identifiers, organisation membership and role.
- Organisation and business data such as company details, depots, customers, counterparties and operational settings.
- Operational content such as pallet movements, vouchers, recovery cases, stock, jobs, documents and evidence uploaded by authorised users.
- Client Portal membership and access information.
- Support, legal and commercial correspondence.
- Technical and security data such as session information, IP-derived security signals, request logs, timestamps and audit events.
3. Why we process personal data
- To provide, secure and administer the service and user accounts.
- To perform a contract or take steps requested before entering into a contract.
- To protect the service, prevent abuse, investigate incidents and maintain auditability.
- To respond to support, legal, procurement and commercial enquiries.
- To meet accounting, tax, legal and regulatory obligations where applicable.
- For legitimate interests such as improving reliability, capacity planning and service security, provided those interests do not override individual rights.
4. Customer-controlled operational data
Customers decide which operational and personal data they enter into Lytheron Pallet and are responsible for having an appropriate legal basis, transparency notice and internal authorisation for that processing.
Lytheron does not sell customer operational data and does not use it for third-party advertising.
5. Service providers and international processing
The service currently uses Supabase for database, authentication and storage services and Vercel for application hosting and delivery. The production database project is configured in the EU (Paris region) and the application project is configured for Paris.
Providers may process limited support, security, telemetry or account information in other locations under their own contractual and legal safeguards. Where GDPR requires safeguards for transfers outside the EEA, Lytheron relies on the mechanisms made available by the relevant provider and applicable law.
The current subprocessor list is published on the Subprocessors page.
6. Cookies and local storage
Lytheron Pallet currently uses technologies required for authentication, session continuity, language or security functionality. We do not currently deploy advertising cookies or third-party behavioural analytics on the public site.
More detail is available in the Cookie Policy.
7. Retention
We retain account and customer data for as long as needed to provide the service and thereafter only as reasonably necessary for legal, contractual, security, dispute-resolution or backup purposes.
Retention periods may differ by data category. Customers may request deletion or export of their data subject to legal obligations and technical backup cycles.
8. Your rights
Where the GDPR applies, individuals may have rights of access, rectification, erasure, restriction, objection and portability, and the right to complain to a competent supervisory authority.
If your data was provided to Lytheron Pallet by a customer organisation, please contact that organisation first where it is the controller. We will assist the controller as required by our DPA.
9. Security and changes
We use technical and organisational measures designed to protect confidentiality, integrity and availability, as described on the Security page.
We may update this policy when the service, legal requirements or processing activities change. The current effective date is shown on this page.