This policy explains what personal data LiftCycle collects, how we use it, and the rights you have over it. Plain-language version below; the legal canonical text is available on request at info@liftcyclemanagement.com.
1. Who we are
Data controller: LiftCycle Management LLC, 1750 Pennsylvania Ave NW, Suite 300, Washington, DC 20006, USA. Reachable at info@liftcyclemanagement.com. For EU/UK matters, our designated contact is the same address.
2. What data we collect
- Marketing form data — name, work email, company, message, and submission metadata (IP, user-agent, timestamp) when you contact us or book a demo.
- Account data once you sign up — email, name, hashed password, TOTP secret (if you enrol 2FA), session tokens.
- Workspace data inside LiftCycle — lift assets, job records, technician notes, photos, signatures. You own this data outright.
- Operational logs — error stack traces, audit log entries (who did what, when), webhook flight ledger.
- We do not collect credit-card data on our infrastructure. All payment information is handled directly by Stripe under PCI-DSS Level 1. We see only the last 4 digits and the brand.
3. Why we hold it (lawful basis)
- Contract performance — to deliver the LiftCycle service you've subscribed to.
- Legitimate interest — to respond to a contact-form submission, to detect abuse, to maintain audit logs for security investigations.
- Consent — for the optional marketing newsletter (separate opt-in, opt-out one click).
- Legal obligation — when retention is required by tax law, statutory recordkeeping, or a lawful order.
4. Where it lives
All customer data is stored on AWS infrastructure in the region you choose at signup (eu-west-2, us-east-1, ap-south-1, or me-south-1). We do not move workspace data across regions without your written instruction. Daily encrypted backups; point-in-time recovery for the last 30 days.
5. How long we keep it
- Contact-form submissions: 24 months, then anonymised.
- Active workspace data: indefinitely, while your subscription is active.
- After cancellation: 90 days to allow export, then full deletion (subject to legal retention obligations on financial records — typically 7 years for invoicing data).
- Audit logs: 24 months on Solo Field Framework, 7 years on Business Enterprise.
7. Your rights
Under GDPR / UK GDPR you have the right to access, rectify, erase, restrict, port, and object to processing of your personal data. To exercise any of these, email info@liftcyclemanagement.com with the subject "Data request". We respond within 30 days.
9. Security
TLS in transit, AES-256 at rest, role-based access control, mandatory 2FA on all admin accounts, audit logs of every change. SOC 2 Type II audit pending Q3 2026. Disclosures and bug bounty: info@liftcyclemanagement.com.
10. Changes to this policy
Material changes are emailed to every active workspace owner 30 days in advance. Historical versions are available on request.