Privacy Notice
Last updated: · Last reviewed:
Last updated: 22 September 2026
1. Who we are and how to contact us
Lydmera Limited is a company incorporated in Guernsey with company number 78292. Our registered office is published on the Company information page.
For privacy questions or to exercise a data-protection right, email privacy@lydmera.com. You may also write to the registered office, marked “Privacy.”
Lydmera maintains its annual registration with the Office of the Data Protection Authority (ODPA) in Guernsey.
Lydmera is established in Guernsey and has no establishment in the United Kingdom or European Economic Area. Its direct privacy contact for all territories is privacy@lydmera.com. The Service is initially marketed to professional and business users in Guernsey and the United Kingdom rather than intentionally marketed in the EEA. This Notice and the applicable representative information will be updated before Lydmera intentionally expands its offer or targeted marketing into an EEA country.
2. Our roles
Lydmera acts as a controller when it decides why and how personal data is used for Account creation, authentication, Subscription administration, security, support, legal compliance and operation of its business.
Customers may include personal data about their own clients, site contacts, personnel or other third parties in project files. Where a Customer determines why that personal data is used and Lydmera processes it only to provide the Service on the Customer’s instructions, the Customer is normally the controller and Lydmera is the processor. Where the Customer itself acts for its client as processor, Lydmera may be a subprocessor. That processing is governed by our Data Processing Addendum. A person whose data appears only in Customer Content should normally contact the relevant Customer first; we will assist that Customer as required.
Paddle acts as an independent controller for transaction information it processes as authorised reseller and Merchant of Record. Paddle is not Lydmera’s payment processor or subprocessor for that transaction activity.
3. Personal data we process
The data actually processed depends on how you use the Service.
Account and authentication data
- name, email address and password-authentication records;
- organisation, role and profile information you provide;
- Account and user identifiers;
- login, session, verification and security events; and
- settings and preferences associated with the Account.
We do not receive your plaintext password from the authentication provider.
Subscription and transaction data
- selected plan, Subscription status and billing period;
- Paddle customer, subscription, transaction, receipt and invoice references;
- transaction status, timestamps, currency, price, discount and tax metadata; and
- limited contact and billing information Paddle shares for fulfilment, reconciliation, support, fraud prevention and legal compliance.
Full payment-card details are submitted to Paddle and are not stored by Lydmera.
Customer Content and project data
- pool geometry, construction and operating conditions;
- site or project location used for climate and design conditions;
- project briefs, plans, sketches, drawings, specifications and equipment data;
- calculation inputs, assumptions, selections and Outputs; and
- names, business contact details or other personal data that a Customer chooses to include in those materials.
Please do not include personal data that is not needed for the project. Do not upload special-category data, criminal-offence data, payment-card data, credentials or other highly regulated data unless Lydmera has agreed an appropriate workflow in writing.
AI-feature data
- the parts of documents, images, instructions or project information submitted to an AI-assisted feature;
- prompts and configuration sent to the commercial AI service; and
- the extracted values or draft text returned by that service.
Technical and security data
- IP address, request time, browser/device and operating-system information contained in ordinary request logs;
- pages or API routes requested, response status, errors and performance information;
- authentication, abuse-prevention and security events; and
- cookie and local-storage information described in the Cookie Policy.
Optional website analytics
Google Analytics 4 is optional and disabled by default. A fresh choice under our current analytics notice is required for public-page visits and the confirmed outcomes below; a previous choice covering public-page visits only does not authorise this expanded purpose. The Google browser tag loads only after acceptance and only on our home, features, pricing and product-tour pages. It does not record page views inside the application, sign-in, checkout, contact or legal pages.
With your consent, we keep a fixed acquisition context for up to 30 days to understand whether a visit leads to a sales enquiry accepted by our email provider, an activated trial, or a first subscription payment actually captured by Paddle. These outcomes are confirmed by our servers, not by a button click or a browser success screen. Trial and first-payment measurement is limited to eligible new Accounts after rollout. The first eligible context is linked to the authenticated Account internally for delayed confirmation; it is not replaced by later visits.
The context contains a random token reference, consent and expiry information, Google browser and session identifiers, an approved public landing page and fixed campaign codes. Google receives approved public page and visit information, browser/session identifiers, browser/device information and approximate location derived from your IP address. Our server outcome reports send the browser identifier, outcome and actual time, selected plan where relevant and fixed acquisition codes. They do not assign a later payment to an earlier browser session. Only approved organic LinkedIn/YouTube codes and Google Search pilot codes are used, as listed in the Cookie Policy; direct or unknown campaigns remain unattributed.
We do not send names, email addresses or their hashes, Account or project identifiers, Paddle identifiers, Customer Content, form text, payment amounts or card details through this integration. Search terms, advertising click identifiers, arbitrary URL parameters, fragments and private-page addresses are excluded. Google receives your IP address and browser/device information when your browser connects to its service; these identifiers and the consented Account linkage are personal data, not anonymous information.
Advertising data sharing, Google signals and advertising personalisation remain disabled. We do not use behavioural advertising, cross-site tracking, device fingerprinting or session replay. You can reject analytics or withdraw through Analytics preferences without affecting contact delivery, checkout or access to the Service. Withdrawal stops browser measurement, requests deletion of the acquisition cookie and removal of Google identifiers from our context, and cancels unsent outcome exports. If our server cannot confirm withdrawal, a warning asks you to retry while local measurement remains off. An export already dispatched cannot be recalled; withdrawal does not undo earlier lawful processing.
Communications
- contact-form fields and messages;
- support, sales, billing, legal, privacy and security correspondence; and
- records of choices about optional communications, if such communications are later offered.
For reliable contact delivery and to prevent duplicate messages, we may keep a minimal operational receipt for 30 days: a random submission reference, a keyed digest used to recognise an unchanged retry, the email provider’s message reference and delivery timestamps. This receipt contains no second copy of your message. It is separate from optional analytics and is used on our legitimate interest in delivering requested enquiries reliably.
Legal and compliance records
- the version of legal documents accepted, acceptance time and related Account identifier;
- requests, complaints, disputes and rights-verification records; and
- records needed for accounting, fraud prevention, sanctions or legal claims.
4. Where the data comes from
We receive personal data:
- directly from you or an authorised user;
- from the Customer organisation that provides your Account or includes you in Customer Content;
- automatically when you use the Service;
- from Paddle in connection with a transaction;
- from service providers acting for us; and
- from public or licensed climate, location, standards or manufacturer sources where a feature requires them.
5. Why we use data and our legal bases
The precise labels differ slightly between the Data Protection (Bailiwick of Guernsey) Law, 2017, the UK GDPR and the EU GDPR. The table states the corresponding basis in plain language.
| Purpose | Typical data | Basis |
|---|---|---|
| Create, authenticate and administer an Account | Account, authentication, preferences | Contract or steps requested before a contract; legitimate interests for organisational-user administration |
| Provide calculations, storage, AI-assisted features, reports and support | Customer Content, project data, Account data, communications | Contract; for Customer-controlled third-party data, Customer’s documented instructions under the DPA |
| Administer a trial, Subscription and entitlements | Account, Paddle transaction metadata, plan status | Contract; legitimate interests in reconciling and protecting the service |
| Secure the Service, prevent abuse and investigate incidents | Technical, security, Account and relevant Customer Content | Legitimate interests and legal obligations |
| Diagnose faults and improve reliability | Error, performance and limited usage data | Legitimate interests, balanced against user rights; data minimisation and aggregation where possible |
| Measure selected public visits and confirmed sales-enquiry, trial and first-payment outcomes, if analytics is enabled | Consented browser identifiers, fixed acquisition codes, internal Account linkage and limited outcome data described above | Your optional analytics consent; a fresh analytics choice is required and may be withdrawn through Analytics preferences |
| Deliver requested enquiries reliably and prevent duplicate email delivery | Submission reference, keyed retry digest, provider message reference and timestamps | Legitimate interests in reliable delivery and preventing duplicate messages; independent of analytics consent |
| Respond to contact, sales and support enquiries | Contact details and communications | Steps requested before a contract, contract or legitimate interests in responding |
| Keep accounting, tax, corporate and legal records | Transaction metadata, correspondence, acceptance and dispute records | Legal obligation and legitimate interests in establishing or defending legal claims |
| Send essential service messages | Account, email, Subscription and security data | Contract, legal obligation or legitimate interests; these are not optional marketing |
| Send optional product marketing, if introduced | Email and preference | Consent where required, or a documented business-marketing basis with an easy opt-out where law permits |
We do not rely on consent merely because a person submits the Contact form. The form provides a privacy notice; responding is based on the requested steps or our legitimate interests. Any marketing consent must be separate, optional and unticked.
Where we rely on legitimate interests, those interests include operating and securing a professional SaaS service, preventing fraud, supporting users, improving reliability and protecting legal rights. You may object as explained in section 10.
6. AI-assisted processing
Lydmera uses a commercial service supplied by Anthropic, PBC in the United States for specified document/image extraction and draft-text functions.
When you choose an AI-assisted feature, relevant Customer Content and instructions are sent to Anthropic and the result is returned to Lydmera. Lydmera remains responsible for defining the feature and for its processor relationship with Anthropic; the user remains responsible for checking the returned value or text before use.
Under Anthropic’s published commercial terms and privacy information:
- Anthropic acts as a processor for commercial API data;
- commercial inputs and outputs are not used to train Anthropic models unless the customer elects to participate in a separate programme; and
- under standard API retention, inputs and outputs are ordinarily deleted from Anthropic’s backend within 30 days, subject to stated exceptions such as longer-retention features, safety/usage-policy enforcement, law or a separate zero-data-retention agreement.
Lydmera does not authorise Anthropic to use Customer Content to train its general models. Unless a shorter retention arrangement applies to the production feature, Anthropic’s published standard API retention applies: inputs and outputs are ordinarily deleted from its backend within 30 days, subject to its stated exceptions for particular features, usage-policy enforcement, legal requirements and separately agreed arrangements.
AI is not used to make a decision about a person’s legal rights, employment, credit or access to the Service. It assists with project inputs and narrative. Deterministic engineering calculations are not Article 22 decisions about a person, but incorrect extracted data can still affect an Output.
7. Who receives personal data
Processors and subprocessors
We use service providers for hosting/edge delivery, database/authentication/file storage, commercial AI, transactional and contact email, and climate/location functions. They may process only the data required for their service and must be governed by appropriate contractual terms.
The current named list, purposes, regions and transfer mechanisms is maintained on the Subprocessors page. Customer-facing processing under the DPA uses the general authorisation and change process stated there and in the DPA.
Paddle — independent controller
Paddle receives and determines how to use buyer and transaction data as reseller/Merchant of Record. Paddle and Lydmera may share names, addresses, email addresses, purchase history, transaction status and transaction analytics for fulfilment, support, compliance, fraud prevention and reconciliation. Each party is responsible for its own controller obligations. Paddle’s Privacy Policy and Buyer Terms apply to Paddle’s processing.
Google Analytics — optional website measurement
If you accept analytics when it is enabled, Google Ireland Limited receives the limited website-measurement data described in section 3 to provide reports for Lydmera. Lydmera is the controller and Google provides analytics as a processor under the accepted Google Analytics Terms of Service and Google Ads Data Processing Terms. Google’s information about data collected from sites using its services explains its processing.
Google may process data internationally, including in the United States. Its transfer information describes reliance on the Data Privacy Frameworks for applicable EEA, UK and Swiss transfers to the US, and contractual-clause fallback under the accepted processing terms. Section 10 and Appendix 3A of those terms describe the applicable arrangements. You may request further information as explained in section 8.
Other disclosures
We may disclose data:
- to professional advisers under confidentiality duties;
- to a regulator, court, law-enforcement body or other authority where lawfully required;
- to protect rights, security and users where a lawful basis exists; or
- as part of a genuine financing, reorganisation, merger or sale, subject to confidentiality and data-protection requirements.
We do not sell personal data or share it for third-party behavioural advertising.
8. International transfers
Lydmera is established in Guernsey. Guernsey has an EU adequacy decision and is recognised under the UK’s inherited/adequacy framework for relevant transfers. Adequacy supports transfers into Guernsey within its scope; it does not remove Lydmera’s other duties or any UK/EEA representative requirement.
Some providers process data in the United States or other countries. Depending on the data flow and applicable law, we use an authorised or adequate jurisdiction, approved standard contractual clauses (and a UK Addendum where required), contractual clauses permitted by Guernsey law, or another lawful mechanism. We assess providers and apply supplementary measures where appropriate.
SOC 2, ISO 27001 and similar certifications may be evidence considered in security diligence. They are not, by themselves, a lawful international-transfer mechanism.
Contact privacy@lydmera.com for information about the safeguard relevant to a particular transfer and, where legally available, a copy or summary with confidential information removed.
9. Retention
We keep personal data only for as long as needed for the purposes above, taking account of the Account lifecycle, legal duties, dispute periods, security and backup cycles.
| Data | Retention criteria |
|---|---|
| Active Account/profile and current project content | While the Account is active and needed to provide the Service |
| Project content after Account closure | Until deletion through the normal active-system deletion cycle, unless Customer requests earlier deletion where available or a legal reason requires restriction or retention |
| Residual disaster-recovery backups | Until overwritten through the applicable provider backup cycle; restored only for disaster recovery and then returned to the deletion cycle |
| Ordinary operational/security logs | For the limited operational or security period configured for the relevant service, or longer where needed for an incident, fraud investigation or legal claim |
| Contact and routine support records | Until the enquiry and reasonable follow-up are complete, or longer where linked to an Account, dispute or legal duty |
| Transaction, accounting and tax metadata | For the period required by applicable accounting, tax and corporate-record law |
| Legal acceptance and material contract records | For the relationship and the period reasonably needed to establish, exercise or defend legal claims |
| Marketing preference and suppression record | Until consent is withdrawn; a minimal suppression record may be retained to honour an opt-out |
| Optional analytics choice and cookies | The choice is saved for up to 365 days after your action; analytics cookies last up to 90 days without extending their expiry on each visit, and are cleared on rejection or withdrawal |
| Acquisition context and Google identifiers held by Lydmera | Fixed, nonrolling window of up to 30 days, shortened by withdrawal, Account closure or consent expiry; the acquisition cookie is cleared and Google browser/session identifiers are removed. Minimal consent, withdrawal and business deduplication evidence may remain only as needed to honour choices and reconcile outcomes, without reusable Google identifiers |
| Minimal contact-delivery receipt | 30 days from the first attempt; ordinary enquiry correspondence follows the separate retention criterion above |
| Google Analytics user and event data, if enabled | The property’s user-data and event-data retention periods are set to 2 months, without resetting the period on new activity. Standard aggregate reports are not subject to these periods. Browser-cookie expiry is a separate limit |
Deletion may be delayed where data is needed to comply with law, investigate abuse, establish or defend a claim, or protect another person. Where possible, we restrict use during that period.
10. Your rights
Depending on the law that applies and our role, you may have rights to:
- receive information about processing;
- access personal data and receive a copy;
- correct inaccurate or incomplete data;
- request erasure;
- restrict processing;
- object to processing based on legitimate interests or to direct marketing;
- receive qualifying data in a portable format;
- withdraw consent without affecting earlier lawful processing; and
- complain to a supervisory authority.
Rights are not absolute. We may need to verify identity, clarify a request or retain information where law permits. We normally respond within one month; applicable law may allow an extension for a complex or numerous request, in which case we will explain.
If Lydmera holds the data only as a processor for a Customer, we may refer the request to that Customer and assist it.
Email privacy@lydmera.com to exercise a right.
11. Complaints
You may complain to the Office of the Data Protection Authority, Guernsey at odpa.gg.
Where the UK GDPR or EU GDPR applies, you may also have the right to complain to the UK Information Commissioner’s Office or an EEA supervisory authority. You do not have to contact us first, although we would welcome the opportunity to resolve the issue.
Where the UK data-protection complaints procedure applies, we will acknowledge a complaint within 30 days and respond without undue delay. This does not extend any deadline for exercising a right or contacting a regulator.
12. Security
We use technical and organisational measures intended to provide security appropriate to the nature and risk of the data. The current public summary is in the Security Overview. No internet service can guarantee absolute security.
Email security@lydmera.com promptly if you believe personal data or an Account has been compromised.
If Lydmera is a processor for affected Customer Content, we notify the relevant Customer without undue delay after becoming aware of a reportable personal-data breach, as required by the DPA. Where Lydmera is controller, we notify the ODPA and affected people when and within the periods the applicable law requires. A 72-hour regulator deadline is not a blanket promise that every affected person will receive notice within 72 hours.
13. Storage on your device
The Cookie Policy lists cookies and other device storage, including the optional 30-day acquisition cookie and the consent cookie that remembers your choice for up to 365 days. Its opaque withdrawal reference is cleared after confirmed withdrawal, or retained if a retry is needed. A fresh analytics choice is required; this integration does not contact Google before acceptance. Use Analytics preferences to reject or withdraw. Browser measurement stops immediately; server confirmation cancels unsent exports and removes Google identifiers from the acquisition context. If confirmation fails, follow the displayed retry warning. Already-dispatched requests and earlier lawful processing cannot be undone.
14. Children
The Service is designed for adults carrying out professional or related project work. Account creation is not permitted for a person under 18. If you believe a child has created an Account or that we hold a child’s personal data without an appropriate basis, email privacy@lydmera.com.
15. Changes to this Notice
We may update this Notice when processing, providers or law changes. We will post the current version and update the date above. If a change materially affects registered users, we will provide an appropriate notice before it takes effect where practicable or legally required. A new purpose requiring consent will not be authorised merely by continued use.
16. Contact
Privacy enquiries and rights requests: privacy@lydmera.com
Registered office: published on the Company information page.