General Data Protection Regulation (GDPR)
Organizations established in the EU and processing personal data of EU-based individuals are, in almost all cases, required to comply with the GDPR as of May 25, 2018. The GDPR updates and harmonizes the framework for processing personal data in the European Union, and brings with it new obligations for organizations and new rights for individuals.
The team at Lusha is fully committed to the requirements of the GDPR. Our legal and policy experts have closely analyzed the requirements of the GDPR and continue to monitor new guidance on best practices for implementing the requirements of the GDPR. We have taken these new requirements to heart and made changes to our products, contracts and policies to ensure that we are fully in compliance with the GDPR. Lusha services comply with the GDPR as of May 25, 2018.
Worldwide Product Compliance
Many of our customers operate in multiple jurisdictions around the world. To ensure a consistent user experience, Lusha has adopted the GDPR requirements to our entire platform and support it worldwide. We believe that use of uniform rules and program logic will greatly enhance our all customers’ ability to comply with the GDPR’s requirements.
Your Rights Regarding Your Personal Information
We respect your privacy rights and therefore you may contact us at any time and we shall work diligently to respect your choices and requests regarding your Personal Information. The purpose of the list stipulated below is to allow Users and Contacts to exercise their rights under applicable privacy and data protection regulations:
- The right of Access: You may request to access your Personal Information and obtain a copy of Personal Information which is being processed by Lusha. In the event that you request to know what Personal Information is being processed by us, we will provide you with the following information free of charge: purposes of processing; categories of Personal Information processed; recipient(s) of Personal Information; length of time during which the Personal Information will be stored; your privacy rights; and information on data transfers. Such requests will be made by sending a request to Support@Lusha.co, please make sure to provide your relevant details.
- The right of Rectification: You may request to change, update or complete any missing data we process about you, by sending an email to Support@Lusha with you relevant details. Please note that we may rectify, replenish or remove incomplete or inaccurate information, at any time and at our own discretion.
- The right of Erasure: You may at any time withdraw your consent to our processing of your Personal Information. In this case, if there is no overriding legitimate interest for continuing the processing of your Personal Information (e.g. to comply with our legal obligations, resolve disputes, enforce our agreements, etc.) and the Personal Information is no longer necessary in relation to the purpose for which it was originally collected, we will erase your data. Such withdrawal of consent will be made by sending an email to Support@Lusha.co with your relevant details.
- The right of Restriction of Processing: You may request us to restrict processing of your Personal Information if one of the following applies: (i) the accuracy of the Personal Information is contested by you; (ii) the processing is unlawful; or (iii) if we no longer need the Personal Information. Such a request will be made by sending an email with the relevant details to Support@lusha.co.
- Right to Data Portability: You have the right to receive the Personal Information in a structured, commonly used and machine-readable format. Such a request will be made by sending an email with your relevant details to Support@Lusha.co
- Right to object to processing Data: You have the right to object to processing your data. Such a request will be made by sending an email with your relevant details to Support@Lusha.co
If you are not satisfied with our response or believe we are collecting or processing your Personal Information not in accordance with the laws, you can complain to the applicable data protection authority.
Personal Information will be retained by Lusha in such a way that you can be identified only as long as is necessary for Lusha’s processing activities (“Processing Date”). Lusha will adopt the same retention policy for all Users and Contacts regardless of their place of residence, which will follow the reasonable mandatory retention period, which is 7 years as from the Processing Date
Please note that we may retain the information we collect for as long as needed to provide the Services and to comply with our legal obligations, resolve disputes and enforce our agreements.
If you wish to remove Business Profiles existing in our servers or if you prefer that we will not disclose your Business Profiles with our Users, vendors or business partners, you may opt-out by filling in your relevant details here. In this case, we shall not continue to use or disclose your Business Profiles.
Please be notified: some of the information that is gathered about you may arrive from the web and is public by other platforms. In some cases, you may encounter your details again after request for removal, in case they were re-collected over the web, contributed by other partners or in other means that are not including access to your device. We recommend you to periodically check your profile or the Services to ensure that your then-existed profile or account include only the Information you chose to have displayed.
Legal Basis for processing
The biggest myth about the GDPR is that consent is the ONLY way to lawfully process personal information concerning EU data subjects. While consent is one basis for lawful processing, it is not the only one.
Lusha’s lawful basis for processing is its legitimate interest in providing its services to its user, empowering the users to fight fraud online and verifying and authenticating online identities.
The categories of recipients of the personal data
In order to provide our service, we may share certain personal data with companies and individuals that subscribe to our service. We may also share personal data with the following recipients: (i) our subsidiaries; (ii) subcontractors and other third-party service providers (e.g. payment processors, advertisers and marketers, hosting services, etc.); (iii) auditors or advisers of our business processes; and (iv) any potential purchasers or investors in Lusha.
Transfer of Data to a Third Country
If we transfer personal data outside of the EU or EEA, we only do so in accordance with the legal mechanisms set out in the GDPR (for example, the Privacy Shield or to territories which have been deemed by the European Commission as providing an adequate level of protection).
Individuals from the EU may contact our EU representative according to Art. 27 GDPR regarding all requests related to data protection and privacy:
Lusha Systems Inc