This Privacy Policy explains how Ligna collects, uses, shares, and protects personal information, and the rights and choices you have.
This Privacy Policy applies to personal information that Ligna, Inc. processes about visitors to our websites, people who sign up for and use the Services, and individuals who interact with us.
Controller vs. processor — the key distinction. When you visit our sites or create an Account, Ligna is the controller of your personal information and this Policy applies. When a Ligna customer (or Agency) uploads or collects information about their own contacts and End Users through the Services, that customer is the controller and Ligna is a processor acting on their behalf under our Data Processing Addendum. If you are an End User of a Ligna customer, please direct your privacy requests to that customer; we will assist them as required.
Account and profile details (name, email, phone, company), billing and payment information (processed by our payment providers), content you submit, and communications with us (such as support requests).
Device and log data, IP address, browser and operating system, approximate location, and usage and analytics data collected through cookies and similar technologies (see Section 7).
Information from integrations and connected apps you authorize, from partners and resellers, from data-enrichment providers, and from publicly available sources.
Customer Data that customers process through the Services (such as their contacts and message recipients) is handled as a processor and governed by the customer's instructions and our Data Processing Addendum, not by this Policy.
We use personal information to:
Where we use AI features, we do not use identifiable Customer Data to train shared models without your opt-in; we may use aggregated, de-identified data to operate and improve the Services.
Where the GDPR or similar laws apply, we rely on one or more of the following legal bases, depending on the purpose: performance of a contract (to provide the Services you request), legitimate interests (such as securing and improving the Services, and direct marketing), consent (which you may withdraw at any time), and compliance with a legal obligation.
We use vetted sub-processors to provide the Services. We maintain a list of sub-processors and provide a mechanism to receive notice of changes, as described in our Data Processing Addendum. Sub-processors are bound by obligations consistent with this Policy and applicable law.
We keep personal information for as long as needed to provide the Services and for the purposes described in this Policy, and then delete or de-identify it, unless a longer period is required by law. Customer Data is retained according to the customer's settings and our Data Processing Addendum. Residual copies may persist in routine backups for a limited time.
We maintain administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, access controls, and monitoring. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. If you have a security concern, contact security@ligna.io.
We are based in the United States and may process information in the U.S. and other countries. Where we transfer personal information from the EEA, UK, or Switzerland, we use appropriate safeguards, such as the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable) and, where available, certification under the EU-U.S., UK, and Swiss Data Privacy Frameworks, together with supplementary measures.
Depending on where you live, you may have the right to access, correct, delete, port, restrict, or object to the processing of your personal information, and to withdraw consent. You can update your information in your Account, unsubscribe from marketing using the link in our emails, and manage cookies as described above. To make a request, email privacy@ligna.io.
If you are an End User of a Ligna customer, please contact that customer to exercise your rights with respect to data they control; we will assist them as required.
If you are in the EEA, UK, or Switzerland, you have the rights described in Section 11 and the right to lodge a complaint with your local supervisory authority. Our legal bases are described in Section 4, and our role as controller or processor is described in Section 1. You can contact our Data Protection Officer and EU/UK representative at dpo@ligna.io.
If you are a California resident, you have the right to know, access, correct, and delete your personal information; to opt out of the "sale" or "sharing" of personal information; to limit the use of sensitive personal information; and to be free from discrimination for exercising your rights.
In the past 12 months we may have collected the following categories of personal information:
| Category | Examples | Disclosed for a business purpose? |
|---|---|---|
| Identifiers | Name, email, phone, IP address, account ID | Yes — to service providers |
| Customer records | Billing details, company information | Yes — to payment and service providers |
| Commercial information | Plans purchased, usage history | Yes — to service providers |
| Internet/network activity | Usage, log, and analytics data | Yes — to analytics providers |
| Geolocation | Approximate location from IP | Yes — to service providers |
| Inferences | Preferences derived from usage | Yes — to service providers |
You can exercise your rights, including opting out of sale/sharing, by emailing privacy@ligna.io or using the "Do Not Sell or Share My Personal Information" link where available. We honor Global Privacy Control browser signals as opt-out requests. You may use an authorized agent, and we will not discriminate against you for exercising your rights.
Where we use automated decision-making technology to make decisions that produce significant effects, we will provide notice and offer the rights required by applicable law, including the ability to opt out or request review.
Residents of other U.S. states with comprehensive privacy laws (such as Virginia, Colorado, Connecticut, Utah, Texas, and others) have similar rights to access, correct, delete, and obtain a copy of their personal information, and to opt out of targeted advertising and certain profiling. To exercise these rights, email privacy@ligna.io; you may appeal a decision by replying to our response.
If you provide your mobile number to receive texts from us, we use it to send the messages you request. We do not share your SMS opt-in or consent with third parties for their marketing. Message and data rates may apply, and message frequency varies. Reply STOP to opt out or HELP for help. Where you send messages to your own contacts through the Services, you are responsible for obtaining consent and providing your own notices, as described in our Terms.
The Services are not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact privacy@ligna.io and we will delete it. Customers who process data about minors through the Services are responsible for doing so lawfully as the controller of that data.
We may update this Policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes, provide additional notice. Your continued use of the Services after the changes take effect means you accept the updated Policy.
For privacy questions or requests, contact us at privacy@ligna.io. For data-protection matters under GDPR, contact our Data Protection Officer and EU/UK representative at dpo@ligna.io.