Privacy & Cookies Policy
PRIVACY & COOKIES POLICY - LYTHORE
1. Introduction and Scope
This Privacy & Cookies Policy (the "Policy") explains how Personal Data is collected, used, stored, and protected when users browse or interact with the website www.lythore.com (the "Website"), as well as how cookies and similar technologies are used.It applies to all users of the Website, including clients, partners, professionals, and creators.
1.2.
Lythore attaches the utmost importance to the protection of Personal Data and undertakes to act in compliance with:
- Internationally recognized data protection standards, including those inspired by the EU General Data Protection Regulation (GDPR), where applicable.
- UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and its implementing regulations, as well as the specific rules applicable to free zones in the United Arab Emirates, including the Meydan Free Zone;
1.3. This Policy applies to all Personal Data processing carried out by Lythore, including:
- data collected when browsing the Website (cookies, IP addresses, connection data);
- data voluntarily provided by Users (account creation, contact forms, newsletter subscription, orders);
- data generated by transactions (billing, delivery, order tracking, customer service);
- data processed in the context of relationships with creators, partners, and technical or logistics service providers.
1.4.
This Policy has an international scope and applies to all processing activities implemented by Lythore, including those involving cross-border transfers of Personal Data outside the United Arab Emirates. In such cases, Lythore implements appropriate safeguards to ensure a level of protection consistent with international standards.
1.5.
By accessing the Website, creating an account, or using Lythore’s services, the User acknowledges having read and understood this Policy.
2. Personal Data Collected
2.1. In connection with the use of the Website and the services offered, Lythore may collect various categories of Personal Data, collected directly from Users, automatically generated through browsing, or obtained via partners and service providers.
2.2. Personal Data provided directly by Users includes:
- identification data: last name, first name, title, postal address, email address, telephone number (where applicable);
- account-related data: login credentials, encrypted passwords, preferences;
- payment data: information necessary to process payments, handled exclusively by certified payment service providers; Lythore does not store full payment card details;
- any information voluntarily communicated by the User via forms or customer service interactions.
2.3. Personal Data collected automatically includes:
- technical data: IP address, device type, operating system, browser;
- browsing data: pages viewed, time spent, actions taken, approximate location;
- cookies and similar technologies.
2.4. Personal Data obtained from third parties or generated through operations includes:
- order and transaction data (history, delivery, invoicing);
- information provided by creators, carriers, and payment partners;
- data from public or lawful sources where collection is permitted.
2.5. Lythore strictly applies the principle of data minimization, collecting only data that is strictly necessary for the purposes described in this Policy.
3. Purposes of Processing
3.1.
Personal Data is processed solely for specific, explicit, and legitimate purposes.
3.2. Main purposes include:
- management of user accounts;
- order processing, delivery, and returns;
- invoicing, accounting, and legal compliance;
- customer service and complaint handling;
- coordination with creators and partners;
- improvement of the Website and services (analytics and performance);
- sending communications and newsletters, subject to required consent;
- fraud prevention and security;
- compliance with applicable legal and regulatory obligations.
3.3. Any material change to processing purposes will be communicated to Users and, where required, subject to prior consent
4. Legal Basis for Processing
4.1.
Processing activities are based on one or more of the following legal grounds:
- Performance of a contract;
- Compliance with a legal obligation;
- User consent;
- Lythore’s legitimate interests (security, service improvement, fraud prevention).
4.2.
Where processing is based on consent, Users may withdraw consent at any time without affecting the lawfulness of prior processing.
5. Data Sharing and Recipients
5.1.
Lythore does not sell or rent Personal Data.
5.2. Personal Data may be shared with:
- creators and partners (for order execution);
- logistics and transport providers;
- payment service providers;
- technical and hosting providers;
- competent authorities where legally required.
5.3. Lythore ensures that all recipients provide appropriate guarantees of security and confidentiality and are contractually bound to comply with applicable data protection laws.
6. International Data Transfers
6.1.
Personal Data may be transferred outside the User’s country of residence, including between the UAE, the European Union, and other jurisdictions.
6.2.
Such transfers are governed by appropriate safeguards, including contractual, technical, and organizational measures inspired by internationally recognized standards (such as Standard Contractual Clauses where required).
6.3. Additional information regarding these safeguards may be provided upon request.
7. Data Retention
7.1.
Personal Data is retained only for as long as necessary to fulfill the purposes for which it was collected and in accordance with applicable legal requirements.
7.2. Indicative retention periods include:
- account data: for the duration of the account’s activity and up to three (3) years after deletion;
- order, invoicing, and accounting data: for the period required by applicable legal and accounting obligations, which may extend up to ten (10) years;
- marketing data: three (3) years from the last contact;
- cookies and technical data: a maximum of thirteen (13) months.
7.3. After expiration of retention periods, data is securely deleted or archived.
8. Users’ Rights
8.1.
Users may exercise the following rights, subject to applicable law: access, rectification, erasure, restriction, objection, portability, and withdrawal of consent.
8.2.
Requests may be sent to contact@lythore.com. Lythore will respond within a maximum of thirty (30) days, unless a lawful extension applies.
8.3. Users may lodge a complaint with the competent data protection authority in their country of residence (e.g., CNIL in France for EU Users).
9. Data Security
9.1. Lythore implements appropriate technical and organizational measures, including encryption, access controls, audits, and secure hosting.
9.2.
In the event of a Personal Data breach likely to result in a high risk to Users’ rights and freedoms, Lythore will notify the competent authority and affected Users within the timeframes required by applicable law (including 72 hours where GDPR applies).
10. Cookies Policy
10.1. Cookies and similar technologies may be used to ensure Website functionality, measure audience, and personalize the user experience.
10.2. Cookies are categorized as necessary, analytics, personalization, and advertising cookies.
10.3. Depending on the applicable jurisdiction, certain cookies require prior explicit consent. Where required, Lythore applies a clear opt-in mechanism and allows Users to manage their preferences at any time.
10.4. Refusing non-essential cookies may limit certain features but does not prevent access to the Website.
11. Changes to this Policy
11.1.
Lythore may update this Policy at any time.
11.2.
Any material changes will be communicated appropriately.
11.3.
The updated Policy applies as of its publication on the Website.
12. Contact
For any questions or to exercise data protection rights:
Email: contact@lythore.com
Address: Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.