Privacy
Privacy Policy
Last updated: July 26, 2026.
1. Controller And Contact
The CGILighthouse legal entity identified in your quote or first invoice is the controller for personal data connected with that order. Before an order is issued, CGILighthouse handles website enquiries as the prospective service provider. For privacy questions or requests, contact sales@cgilighthouse.com.
2. Personal Data We Receive
Depending on how you use our services, we may process:
- identity and business details, including name, email address, company, job title, account memberships, assigned roles and permissions;
- authentication and security data, including a password verifier, session and invitation records, login events, IP address, device or browser information and security audit events;
- project data, including briefs, product or SKU information, messages, participants, tasks, dates, status, time entries, results, source files, GLB assets and other attachments;
- billing data, including billing identity, tax details, currency, quoted and invoiced amounts, discounts, VAT, payment status and payment-provider references; and
- support, enquiry and notification records, including the content and delivery status of relevant emails.
Payment card details are entered with the payment provider and are not intended to be stored in the CGILighthouse portal.
3. How We Use Data
- To respond to enquiries and quote requests.
- To create invite-only company workspaces and manage authorized access.
- To evaluate, price, produce, review and deliver CGI projects.
- To operate project and task messages, files, results, source deliverables and the Client’s 3D catalogue.
- To issue invoices, reconcile payments and maintain accounting records.
- To send invitations, password resets, project notifications, result notices and review reminders.
- To enforce permissions, prevent abuse, investigate incidents and maintain audit records.
4. Legal Bases
When the GDPR applies, we rely on steps requested before entering a contract and performance of a contract for enquiries and project work; legitimate interests for appropriate business communication, service administration, fraud prevention and security; legal obligations for tax, accounting and other required records; and consent where a specific optional use requires it. Where data relates to a Client’s worker or contractor, the Client may separately be responsible for ensuring it has a lawful basis to provide that data.
5. Sessions, Cookies And Browser Storage
The public website does not require advertising cookies. The production portal uses a strictly necessary secure session cookie to keep an authenticated user signed in and to protect workspace access. It may also use short-lived browser state required for request security or accessibility preferences. We do not use browser storage as the database for portal projects, credentials or permissions.
6. Service Providers And Sharing
We do not sell personal data. We disclose only the data reasonably needed for service delivery, security, payment, legal compliance or a business transaction. Providers may include:
- Cloudflare for website and application delivery, Workers processing, D1 database services, R2 object storage and security;
- Stripe for payment processing, payment status, fraud controls and payment reconciliation;
- Zoho for transactional email and related delivery records; and
- professional advisers, production contractors or replacement infrastructure providers where appropriate and subject to access and confidentiality controls.
Providers can change as the platform develops. Where a material change affects this policy, we will update this page. Provider names describe the services we currently use or plan to enable; a feature that has not yet been activated does not collect the associated category of data.
7. Retention
Retention depends on the record and the applicable contract:
- chat attachments are normally deleted 60 days after the related task closes, unless the contract specifies another period;
- results and agreed source files are retained according to the order or contract and may be moved to another storage or archive provider;
- message transcripts, task decisions and audit records may be kept longer where needed to document delivery, permissions, disputes or security;
- invoice, tax and payment records are retained for the period required by applicable law; and
- invitations, reset links and sessions expire according to their security purpose, although limited security events may be retained for abuse prevention.
Deletion from active systems may not immediately remove an item from provider backups. Backup copies are isolated and expire according to the relevant backup cycle.
8. Your Rights
Where the GDPR or similar laws apply, you may request access, correction, deletion, restriction or portability, and may object to certain processing. You may withdraw consent where processing is based on consent. These rights can be limited by another lawful basis or a record-keeping obligation. We may need to verify your identity and authority before acting. You may also complain to the data-protection authority in your country.
9. International Transfers
Some providers may process data outside the European Economic Area or your country. Where required, we use an adequacy decision, approved contractual clauses or another legally recognized transfer safeguard. Provider locations and safeguards may change with the services enabled for a project.
10. Security
We use technical and organizational measures appropriate to the data and service. The production design includes one-way password verification, secure session cookies, tenant and permission checks, private file storage, time-limited authorized downloads, upload validation, rate limiting, payment-webhook verification and append-only audit events. Access is invite-only and company owners control their members’ permissions. No internet service is completely risk-free, so do not upload sensitive personal data unless it is necessary and authorized for the project.
11. Client Responsibilities
A Client company owner decides which workers receive access and permissions. Clients should keep their membership list current, remove access promptly when it is no longer needed, avoid including unnecessary personal data in project files and inform us promptly about suspected unauthorized access.
12. Changes
We may update this Privacy Policy as the website, tools or services change. The latest version will be published on this page with the updated date.