Privacy Policy for Lighthief Cyprus Ltd

Effective Date: October 9, 2025
Last Updated: October 9, 2025

At Lighthief Cyprus Ltd (“Lighthief,” “we,” “us,” or “our”), we are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, share, and protect your personal information in compliance with the General Data Protection Regulation (GDPR) (EU) 2016/679, Cyprus data protection laws, and other applicable regulations. It applies to our website (https://lighthief.cy), Meta Lead Ads, email communications, phone interactions, and other services related to solar installations, net metering, and renewable energy solutions.

1. Data Controller

Lighthief Cyprus Ltd is the data controller responsible for your personal data.
Contact Details:

  • Address: 28 October Ave 249, Lophitis Business Center 1, Office 201, 3035 Limassol, Cyprus

  • Email: office@lighthief.com

  • Phone: +357 77 77 00 50

2. Personal Data We Collect

We collect and process the following types of personal data:

  • Identity and Contact Data: Name, email address, phone number, and address (e.g., provided via our website form for a solar savings report or quote).

  • Financial Data: Current monthly electricity costs or property details (e.g., residential/commercial, provided voluntarily for personalized reports).

  • Marketing and Communication Data: Preferences for receiving updates, responses to campaigns (e.g., Meta Lead Ads), and optional notes.

  • Technical Data: IP address, browser type, device information, and website usage data (e.g., via cookies or analytics tools).

  • Transaction Data: Details related to solar installations, net metering applications, or grant/loan applications (e.g., Solar for All €1,500 grant).

We do not collect sensitive data (e.g., health, political opinions) unless required for specific services (e.g., grant eligibility) and only with your explicit consent. We do not knowingly collect data from individuals under 18.

3. How We Collect Your Data

We collect data through:

  • Direct Interactions: When you fill out forms (e.g., solar savings report, quote request), contact us via email/phone, or engage with our Meta Lead Ads.

  • Automated Technologies: Cookies, pixels, and analytics tools (e.g., Google Analytics, Meta Pixel) track website visits and ad interactions. See our Cookie Policy for details.

  • Third Parties: Partners like the Electricity Authority of Cyprus (EAC) or banks (for Green Energy Loans) may provide data related to applications, with your consent.

4. Lawful Bases for Processing

We process your data based on the following GDPR lawful bases:

  • Consent: For marketing communications, Meta Lead Ads, or optional data (e.g., notes in forms). You can withdraw consent anytime (see Section 8).

  • Contract: To provide quotes, savings reports, or process net metering/grant applications (e.g., fulfilling your request for a solar installation).

  • Legitimate Interests: For improving services, analyzing website usage, or fraud prevention, where your rights are not overridden.

  • Legal Obligation: To comply with Cyprus/EU laws (e.g., tax records, grant audits).

5. How We Use Your Data

We use your personal data to:

  • Provide personalized solar savings reports and quotes.

  • Process net metering applications (deadline: Dec 31, 2025) and Solar for All grant applications (€1,500 max).

  • Facilitate Green Energy Loan applications with banks (no downpayment required).

  • Send marketing communications (e.g., solar tips, deadline reminders) if you opt in.

  • Improve our website and services via analytics (e.g., tracking form submissions).

  • Comply with legal obligations (e.g., GDPR, Cyprus tax laws).

We do not use your data for automated decision-making or profiling that significantly affects you.

6. Sharing Your Data

We may share your data with:

  • Service Providers: CRM platforms, analytics tools (e.g., Google Analytics), or cloud storage providers, all GDPR-compliant.

  • Partners: EAC for net metering, banks for Green Energy Loans, or government bodies for grants, only with your consent.

  • Legal Authorities: If required by law (e.g., tax audits).

  • Third Parties: Only if explicitly consented (e.g., for loan processing) and with strict compliance agreements.

We do not sell your data or share it for unrelated purposes. Any third-party recipients are bound by GDPR and Meta Lead Ad Terms (effective Oct 10, 2025).

7. Data Security

We implement appropriate technical and organizational measures to protect your data, including:

  • Encryption for data transmission (e.g., SSL on our website).

  • Secure storage with access limited to authorized personnel.

  • Regular security audits and staff training.

We protect against unauthorized access, loss, or damage, considering the nature of the data (e.g., low-risk contact details vs. financial data). In case of a data breach, we will notify you and the Cyprus Data Protection Commissioner within 72 hours, as required by GDPR.

8. Your Data Subject Rights

Under GDPR, you have the following rights:

  • Access: Request a copy of your personal data.

  • Rectification: Correct inaccurate data.

  • Erasure: Request deletion of your data (subject to legal obligations, e.g., tax records).

  • Restriction: Limit how we process your data.

  • Portability: Receive your data in a structured, machine-readable format.

  • Objection: Object to processing based on legitimate interests (e.g., marketing).

  • Withdraw Consent: Opt out of marketing or optional processing anytime.

To exercise these rights, contact us at office@lighthief.com or +357 77 77 00 50. We will respond within one month (extendable for complex requests). You may also lodge a complaint with the Cyprus Data Protection Commissioner (www.dataprotection.gov.cy).

9. Data Retention

We retain your data only as long as necessary:

  • Form/Lead Data: 3 years post-submission, unless you request deletion or we need it for contracts (e.g., installations).

  • Marketing Data: Until you unsubscribe or withdraw consent.

  • Legal/Grant Data: 7 years to comply with Cyprus tax/grant audit requirements.

Deleted data is securely erased or anonymized.

10. International Data Transfers

Your data is primarily processed within the EU/EEA. If transferred outside (e.g., to US-based analytics providers), we ensure GDPR-compliant safeguards, such as:

  • EU Standard Contractual Clauses (SCCs).

  • Binding Corporate Rules for processors.

  • Data Protection Agreements per Meta Lead Ad Terms.

11. Cookies and Tracking

Our website and Meta Lead Ads use cookies/pixels for analytics and ad performance (e.g., tracking form submissions at https://lighthief.cy/solar-installation-in-cyprus/). You can manage preferences via our Cookie Consent Tool. See our Cookie Policy for details.

Our website and ads may link to third-party sites (e.g., EAC, banks). We are not responsible for their privacy practices. Review their policies before sharing data.

13. Meta Lead Ads

When you submit data via our Meta Lead Ads (e.g., name, email for a savings report), it is governed by this policy and Meta’s Lead Ad Terms (effective Oct 10, 2025). We ensure:

  • Clear disclosure that your data follows our policy.

  • A link to this policy in all ads.

  • No targeting of minors.

  • Consent for sharing (e.g., with EAC for net metering).

14. Updates to This Policy

We may update this policy to reflect legal or operational changes. Significant updates will be notified via email or our website. Continued use of our services after updates constitutes acceptance.

15. Contact Us

For questions, complaints, or to exercise your rights:

  • Email: office@lighthief.com

  • Phone: +357 77 77 00 50

  • Address: 28 October Ave 249, Lophitis Business Center 1, Office 201, 3035 Limassol, Cyprus

For investor/partner inquiries: a.sybaris@lighthief.com (+357 95 152 788).

Lighthief Cyprus Ltd
HE 477423 | TIN: 60187188Q
© 2025 Lighthief Cyprus Ltd. All rights reserved.