1. Introduction
Lizentia ("we," "our" or "us") is committed to protecting privacy. This Privacy Policy explains how we collect, use, share and safeguard information when you visit our Website or use our Services. For clients operating a Platform built or managed by Lizentia, this Policy is supplemented by the data-processing terms in the signed engagement agreement.
2. Scope of This Policy
This Policy covers two related but distinct contexts: (a) data we collect directly through the Lizentia Website, and (b) Client and Platform data we process on behalf of clients under signed engagement agreements. The two are governed differently and are addressed in separate sections below.
3. Definitions
- Personal Data
- Information relating to an identified or identifiable individual, as defined by applicable data-protection law.
- Website Visitor
- Any individual who accesses the Lizentia Website, including prospective clients and members of the public.
- Client
- An organization that has signed an engagement agreement with Lizentia for Services.
- Platform User
- An authorized user of a Platform Lizentia operates for a Client, whose data is controlled by the Client.
- Processing
- Any operation performed on Personal Data, such as collection, storage, use, sharing or deletion.
- Controller
- The party that determines the purposes and means of processing Personal Data.
- Processor
- A party that processes Personal Data on behalf of a Controller.
4. Data Protection Roles
For Website data, Lizentia acts as the Controller. For Client and Platform data, Lizentia generally acts as a Processor on behalf of the Client, who is the Controller. The exact role allocation is confirmed in each signed engagement agreement and any applicable data-processing addendum.
5. Website Data We Collect
When you use the Lizentia Website we may collect:
- Name and contact details you submit
- Email address and phone number
- Company and role
- Procurement identifiers (RFP/RFP link)
- Message, project details and inquiry type
- Uploaded files and attachments
- Usage analytics (pages visited, session duration)
- Cookies and similar technologies
6. Client and Platform Data
Client and Platform data includes:
- Data within Platforms Lizentia builds or operates for Clients
- User records managed by Clients in those Platforms
- Records created through forms deployed on Client-controlled sites
- Data Clients direct Lizentia to process during implementation
Lizentia does not control Client or Platform data; the Client does.
7. How We Use Data
Website data is used to:
- Respond to inquiries and procurement requests
- Provide requested Services and support
- Send relevant communications where permitted
- Improve the Website and Service quality
- Protect against fraud and misuse
- Maintain records for legal and contractual obligations
- Comply with applicable laws
8. Legal Basis for Processing
- Consent — where you explicitly agree to processing, such as submitting an inquiry
- Contract — processing necessary to respond to a request or perform a signed agreement
- Legitimate interests — for Website security, improvement and fraud prevention, balanced against your rights
- Legal obligation — to meet recordkeeping or regulatory requirements
11. International Transfers
Data may be processed in jurisdictions where Lizentia or its service providers operate. Where data crosses borders, Lizentia uses appropriate transfer mechanisms as required by applicable data-protection law. For Client data, international transfer terms are specified in the signed engagement agreement.
12. Data Retention
- Website inquiries are retained only as long as needed to respond and for any applicable recordkeeping period.
- Client data retention is governed by the signed engagement agreement.
- Platform User data is controlled by the Client, not by Lizentia.
- Deprecated data is deleted or anonymized according to the applicable retention schedule.
13. Data Security
We implement reasonable technical and organizational measures, including:
- Encryption in transit
- Access controls and least privilege
- Administrative-access logging
- Vendor due diligence
- Environment separation
- Secure development practices
- Incident-response planning
- Personnel confidentiality
14. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access — request a copy of your Personal Data
- Rectification — correct inaccurate or incomplete data
- Erasure — request deletion where legally permitted
- Restriction — limit processing in defined circumstances
- Portability — receive your data in a structured format where applicable
- Objection — object to processing based on legitimate interests
- Withdraw consent — at any time, without affecting prior processing
- Complain — to a supervisory authority
To exercise a right, contact Lizentia through the Contact page.
15. Children's Privacy
The Lizentia Website is not directed to children and we do not knowingly collect data from children. If you believe a child has provided us with data, contact us and we will take appropriate steps to delete it.
16. AI and Search Data
Where AI or search features are deployed, Client governance configuration determines whether Client data is used for model training or indexing. Lizentia does not make blanket commitments on the Website about training use — those commitments are defined by the actual deployment and contractual configuration.
17. Client Responsibilities
Clients are responsible for the lawful collection and processing of data within Platforms Lizentia builds or operates for them, for providing required notices to Platform Users, and for obtaining any necessary consents. Lizentia supports lawful processing as a Processor but does not assume the Client's Controller obligations.
18. Subprocessors
Lizentia uses authorized subprocessors to deliver Services. A list of subprocessors relevant to a Client engagement is available under the engagement agreement's disclosure terms. Clients receive notice of material subprocessor changes as provided in the signed agreement.
19. Breach Notification
Lizentia maintains incident-response planning. Any breach-notification timelines affecting Client data are defined in the signed engagement agreement. Lizentia does not publish unsupported notification deadlines on the Website.
20. Data Processing Addenda
Clients may request a data-processing addendum consistent with applicable law. The executed addendum governs the specific processing relationship and supersedes this Policy for Client data where the two conflict.
21. Marketing Communications
You may receive communications in response to an inquiry or where you have opted in. You can unsubscribe from marketing communications at any time using the unsubscribe link or by contacting us. Transactional or service-related communications are not marketing and are sent as needed.
22. Accessibility of This Policy
This Policy is published in an accessible format. If you need this Policy in an alternative format to exercise your rights, contact Lizentia through the Contact page.
23. Changes to This Policy
We may update this Policy from time to time. The "Last updated" date indicates the most recent revision. Material changes affecting Client data are governed by the change-control terms of the relevant signed engagement agreement.
24. Governing Law
This Policy is governed by the laws of the jurisdiction defined in the signed engagement agreement, or where no signed agreement exists, by the laws of the jurisdiction in which Lizentia's contracting entity is organized.
25. Contact
For privacy questions or to exercise your rights, contact Lizentia through the Contact page.
Last updated: July 2026
26. Data Protection Contact
Lizentia maintains a privacy contact responsible for handling data-protection inquiries. For Client engagements, the privacy contact and any applicable data-protection officer are identified in the engagement agreement.