Privacy policy
When you visit, use, or navigate our Services, we may process personal information depending on how you interact with LCS and the Services, the choices you make, and the products and features you use.
1. Who we are and what this policy covers
This Privacy Policy explains how LCS ("we", "us", "our"), registered in Keren Kayemet Le-Israel 19, Kiryat bialik, Israel, collects, uses, shares and protects personal information when you visit lcs-cyber.com (the "Site"), contact us, or use our services.
We are the controller (or "data fiduciary" / "database owner", depending on your jurisdiction) of the personal information described here. Where we process data on behalf of our business customers under a separate agreement, that agreement governs and we act as a processor.
This policy is written to meet the requirements of the Israeli Privacy Protection Law, 5741-1981 (including Amendment 13), the EU and UK General Data Protection Regulation (GDPR), US federal and state privacy laws (including the California Consumer Privacy Act as amended by the CPRA), Canadian and Latin American privacy laws, and India's Digital Personal Data Protection Act, 2023 (DPDP Act). Region-specific details are in Section 7.
2. Information we collect
Information you give us
- Contact details: name, email, phone number, company and job title, when you fill in a form, request a demo, subscribe to updates or email us.
- Account information: login credentials and profile details, if you create an account.
- Communications: the content of messages, support requests and meeting notes.
- Billing information: billing name and address. Payment card data is handled directly by our payment provider and is not stored by us.
Information collected automatically
- Device and usage data: IP address, browser type, operating system, pages viewed, referring URL, dates and times of access.
- Approximate location derived from your IP address.
- Cookies and similar technologies (see Section 4).
Information from others
- Business contact details from partners, event organisers or public professional sources, where permitted by law.
We do not intentionally collect sensitive data (such as health, biometric, religious or political information) through the Site. Please do not send it to us.
3. How we use your information and our legal basis
We use personal information only for the purposes below. The legal basis column applies to GDPR/UK GDPR; under the DPDP Act and Israeli law, we rely on your consent or on the legitimate uses those laws permit.
- Aliquam lacinia fringilla eleifend. Nulla at turpis vulputate, viverra elit et, interdum erat. Duis vitae tincidunt dui.
- Aenean ex magna, tristique nec est in, ultricies tincidunt diam.
- Praesent sed augue sed ex consectetur laoreet. Fusce ultrices condimentum dui, eu dignissim lorem tincidunt eget. Cras interdum vehicula sem nec aliquet.
We do not use your information for automated decision-making that produces legal or similarly significant effects on you.
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under California law. [If you use ad pixels or retargeting, change this sentence and add a "Do Not Sell or Share My Personal Information" link.]
4. Cookies and similar technologies
We use strictly necessary cookies to run the Site. With your consent (where required by law, including in the EU, UK and India), we also use analytics cookies [e.g., Google Analytics] and [marketing cookies, if any].
- You can accept, reject or change your choices at any time through our cookie banner or the site cookie settings.
- We honour Global Privacy Control (GPC) signals as an opt-out where required by US state law.
- Our Site does not currently respond to browser "Do Not Track" signals, as there is no common standard for them.
A list of the cookies we use, their purpose and duration is available in our cookie settings panel.
5. Sharing and international transfers
We share personal information only as needed, and only with:
- Service providers (processors) who host, operate or support the Site and our services, such as cloud hosting [e.g., AWS], email and CRM tools, analytics and payment processors. They act on our instructions under written contracts that require them to protect your data.
- Professional advisers, such as lawyers, auditors and insurers, under confidentiality obligations.
- Authorities, when required by law, court order or to protect rights, safety and security.
- A successor business, in a merger, acquisition or sale of assets, subject to this policy.
A current list of our main sub-processors is available on request.
International transfers. We are based in Israel and our providers may process data in Israel, the EU, the US and other countries. Israel is recognised by the European Commission and the UK as providing an adequate level of protection. For other transfers out of the EU/UK we use Standard Contractual Clauses (or the UK Addendum) or another lawful mechanism. Transfers from India are made in line with the DPDP Act and any restrictions notified by the Indian government. Transfers from Israel comply with the Privacy Protection (Transfer of Data to Databases Abroad) Regulations.
6. How long we keep data and how we protect it
We keep personal information only as long as needed for the purposes in Section 3, then delete or anonymise it:
Security. We apply technical and organisational measures appropriate to the risk, in line with the Israeli Privacy Protection (Data Security) Regulations, 2017 and recognised industry practice. These include encryption in transit and at rest, access control and multi-factor authentication, logging and monitoring, vendor security reviews and staff training. No system is completely secure. If a breach affects your personal information, we will notify you and the relevant authorities as required by law.
7. Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you and get a copy.
- Correct inaccurate or incomplete information.
- Delete your information.
- Object to or restrict certain processing, including direct marketing (you can always unsubscribe using the link in our emails).
- Port your data to another provider in a structured, machine-readable format.
- Withdraw consent at any time, without affecting processing already carried out.
- Complain to a data protection authority.
To exercise a right, email [privacy@lcs-cyber.com]. We may need to verify your identity before acting. We respond within the time required by law (for example, one month under GDPR and 45 days under the CCPA, extendable where the law allows). We will not discriminate against you for exercising your rights.
Israel
Under the Privacy Protection Law, you may inspect personal information about you held in our database and ask us to correct or delete information that is inaccurate, incomplete, unclear or out of date. You are not under a legal obligation to provide personal information, but without it we may not be able to respond to you or provide our services. You may complain to the Privacy Protection Authority.
European Economic Area and United Kingdom
You have all the rights listed above. You may complain to the supervisory authority in your country of residence or work, or to the UK Information Commissioner's Office.
United States
If you are a resident of California or another US state with a comprehensive privacy law (such as Virginia, Colorado, Connecticut, Texas or Oregon), you may have the right to know what we collect and how we use it, and to access, correct and delete it, and to opt out of sale, sharing, targeted advertising and profiling. In the last 12 months we collected the categories in Section 2 (identifiers, commercial information, internet activity, approximate geolocation and professional information) for the purposes in Section 3, and disclosed them only to the recipients in Section 5. You may use an authorised agent to submit a request. If we decline your request, you may appeal by replying to our decision; if you remain unsatisfied, you may contact your state Attorney General.
Canada and Latin America
Residents of Canada (PIPEDA and Quebec Law 25), Brazil (LGPD), Argentina, Mexico, Colombia, Chile and other countries in the region have rights of access, correction, deletion and objection, and may withdraw consent. You may also complain to your local authority, such as the Office of the Privacy Commissioner of Canada, the Commission d'accès à l'information du Québec, or Brazil's ANPD. Our privacy contact for these purposes (including as "encarregado" under the LGPD) is listed in Section 8.
India
Under the DPDP Act, you have the right to obtain a summary of the personal data we process and the processing activities, to have your data corrected, completed, updated or erased, to withdraw consent as easily as you gave it, to nominate another person to exercise your rights in the event of death or incapacity, and to have your grievances addressed. Please contact our Grievance Officer (Section 8) first. If you are not satisfied with our response, you may complain to the Data Protection Board of India. You can also manage consent through a registered Consent Manager where available.We are the controller (or "data fiduciary" / "database owner", depending on your jurisdiction) of the personal information described here. Where we process data on behalf of our business customers under a separate agreement, that agreement governs and we act as a processor.
This policy is written to meet the requirements of the Israeli Privacy Protection Law, 5741-1981 (including Amendment 13), the EU and UK General Data Protection Regulation (GDPR), US federal and state privacy laws (including the California Consumer Privacy Act as amended by the CPRA), Canadian and Latin American privacy laws, and India's Digital Personal Data Protection Act, 2023 (DPDP Act). Region-specific details are in Section 7.
8. Children, changes and contact
Children. The Site is intended for businesses and professionals. It is not directed at children, and we do not knowingly collect personal information from anyone under 18 (or the age of digital consent in your country, such as 13 in the US under COPPA). If you believe a child has given us personal information, contact us and we will delete it.
Changes to this policy. We may update this policy from time to time. We will post the new version here with a new "Last updated" date and, for material changes, notify you by email or a notice on the Site.
Contact Us
- Company: Pablo Libedinsky, Keren Kayemet Le-Israel 19, Kiryat bialik, Israel.
- Privacy contact / Data Protection Officer: Kobi Libedinsky, kobi@lcs-cyber.com.
- Grievance Officer (India): Pablo Libedinsky, pablo@lcs-cyber.com. We acknowledge grievances promptly and resolve them within the period set by the DPDP Rules.
.png)
