Privacy Policy

What we collect, why we collect it, how long we keep it and what you can make us do about it — written out in full rather than summarised.

Effective: 1 September 2026 Last reviewed: 8 September 2026 Version: 3.1 Applies to: ubritelight.com and uBRITE-branded products

1. Who we are

uBRITE Lighting is a trading brand of Sumar International, Inc., a corporation registered in the State of Delaware, United States, with its principal place of business at 1420 Brightway Drive, Suite 210, Dover, DE 19901, USA. In this policy, “we”, “us” and “uBRITE” mean Sumar International, Inc.

For the purposes of the EU and UK General Data Protection Regulation we act as the data controller for personal data collected through this website and through our sales, warranty and service operations. For data we process on behalf of a business customer — for example a tenant list supplied to us for a commercial retrofit — we act as a processor under the terms of the relevant services agreement.

This policy covers ubritelight.com and every subdomain, our warranty registration system, our order and support systems, and any uBRITE-branded form or portal that links to this page. It does not cover third-party websites we link to; those have their own policies and we do not control them.

2. What personal data we collect

We collect only what a specific purpose requires. The categories are:

2.1 Data you give us directly

Personal data collected directly
WhereWhatRequired?
Contact formFirst and last name, email, phone (optional), company (optional), topic, approximate number of fittings (optional), ZIP code (optional), message text, consent flagsName, email, topic, message required
Warranty registrationName, email, product SKU, lamp serial number, quantity, purchase date, retailer, ZIP code, free-text notesAll except notes
NewsletterEmail addressYes
Trade accountBusiness name, registered address, tax identification number, named contacts, trade references, delivery addressesYes, for credit terms
Site surveySite address, access arrangements, contact on site, photographs of fittings and spacesYes, to deliver the service
RecruitmentCV, cover letter, right-to-work confirmation, referencesAs stated in the advert

2.2 Data collected automatically

When you visit the site, our servers and our own first-party analytics record: IP address (truncated to the first three octets before storage), user-agent string, referring URL, pages requested, timestamps, approximate region derived from the truncated IP, and whether the request came from a returning browser. We do not use third-party advertising trackers, social media pixels, session recording, cross-site fingerprinting or data brokers.

2.3 Data from third parties

For trade accounts we may receive credit-reference information from commercial credit agencies, and confirmation of company status from public registries. For rebate administration we may receive confirmation of eligibility from a utility programme administrator, where you have asked us to apply on your behalf.

2.4 Data we do not collect

We do not collect special-category data (health, biometrics, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sexual orientation), and we ask that you do not include it in free-text fields. We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.

We do not store full payment card numbers. Card payments are processed by a PCI-DSS Level 1 certified payment provider; we receive only a token, the last four digits and the card brand.

Purposes and legal bases for processing
PurposeData usedLegal basis (GDPR Art. 6)
Replying to an enquiryContact form dataConsent, and legitimate interests in answering the people who write to us
Fulfilling an orderName, delivery and billing address, payment tokenPerformance of a contract
Administering a warrantyRegistration data, serial number, claim historyPerformance of a contract
Delivering a serviceSite data, survey notes, photographs, metering dataPerformance of a contract
NewsletterEmail addressConsent, withdrawable at any time
Fraud prevention and site securityTruncated IP, request logs, honeypot field resultsLegitimate interests in protecting the service
Aggregate analyticsTruncated IP, page views, referrerLegitimate interests in understanding which pages are useful
Accounting and tax recordsTransaction recordsLegal obligation
Product safety and recallRegistration and batch dataLegal obligation, and vital interests where a safety issue arises

Where we rely on legitimate interests we have carried out a balancing assessment and concluded that the processing is necessary, proportionate and not overridden by your rights. You may object to any such processing — see section 8.

4. Who we share it with

We do not sell personal data, and we do not share it for cross-context behavioural advertising. Under the California Consumer Privacy Act as amended by the CPRA, we have not sold or shared personal information in the preceding twelve months.

We do disclose personal data to the following categories of recipient, each under a written contract limiting them to our instructions:

  • Hosting and infrastructure. Our website and application servers are operated in United States data centres.
  • Email delivery. Transactional and newsletter email is delivered through a specialist provider.
  • Payment processing. A PCI-DSS Level 1 certified processor, which receives card data directly from your browser.
  • Logistics. Carriers receive the name, delivery address and phone number needed to deliver a parcel.
  • Installation partners. Where a retrofit is delivered by an approved partner, they receive the site address and on-site contact only.
  • Recycling processors. R2-certified processors receive return volumes and the shipping label data; no customer identity beyond that.
  • Professional advisers. Auditors, insurers and lawyers, under professional confidentiality obligations.
  • Authorities. Where we are legally compelled, or where disclosure is necessary to establish, exercise or defend legal claims. We notify you of any such request unless legally prohibited.

In the event of a merger, acquisition or asset sale, personal data may transfer to the acquiring entity. We would notify affected individuals before the transfer and the acquiring entity would remain bound by this policy until it was lawfully replaced.

5. International transfers

We are based in the United States and our infrastructure is located there. If you are in the European Economic Area, the United Kingdom or Switzerland, your personal data is transferred outside your jurisdiction when you contact us.

We rely on the European Commission’s Standard Contractual Clauses (Decision 2021/914), together with the UK International Data Transfer Addendum where the UK GDPR applies, as the transfer mechanism. We have carried out a transfer impact assessment and apply the following supplementary measures: encryption in transit (TLS 1.3) and at rest (AES-256), strict access controls with multi-factor authentication, data minimisation at the point of collection, IP truncation before storage, and a published policy of challenging any government access request that is not lawfully binding on us.

A copy of the relevant clauses is available on request from the address in the final section.

6. How long we keep it

We keep personal data only as long as the purpose requires, then delete or irreversibly anonymise it. Our schedule:

Data retention schedule
RecordRetained forWhy
General enquiry24 months from last contactContinuity if you write again
Quotation not proceeded with24 monthsRe-quoting and price history
Warranty registrationWarranty term plus 24 monthsClaim administration and dispute window
Order and transaction records7 years from end of tax yearTax and accounting obligation
Survey notes and photographs6 years from completionProfessional liability period
Metering and audit data6 years, then anonymised for benchmarksContractual and statistical
Newsletter subscriptionUntil you unsubscribe, plus 30 daysHonouring the unsubscribe
Server and security logs90 daysSecurity investigation
Aggregate analytics26 months, no identifiersYear-on-year comparison
Unsuccessful job applications12 months, with consentFuture vacancies

Where a legal claim is live or reasonably anticipated, relevant records are placed on hold and retained until the matter is finally resolved.

7. How we protect it

Our technical and organisational measures include:

  • TLS 1.3 for all data in transit, with HTTP Strict Transport Security enforced site-wide.
  • AES-256 encryption at rest for databases and backups.
  • Role-based access control on the principle of least privilege, reviewed quarterly, with multi-factor authentication mandatory for all staff accounts.
  • Separation of production and non-production environments; no production personal data in test systems.
  • Encrypted, access-controlled backups with restoration tested twice yearly.
  • Annual penetration testing by an independent third party, with findings remediated on a risk-rated schedule.
  • Mandatory annual data protection training for every member of staff with access to personal data.
  • A documented incident response plan, rehearsed annually.

No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and notify affected individuals without undue delay where the risk is high.

8. Your rights

8.1 If you are in the EEA, UK or Switzerland

  • Access — a copy of the personal data we hold about you, with information about how it is processed.
  • Rectification — correction of inaccurate data and completion of incomplete data.
  • Erasure — deletion where the data is no longer necessary, consent is withdrawn, or processing is unlawful.
  • Restriction — a pause on processing while accuracy or a legitimate-interests objection is being resolved.
  • Portability — data you gave us, in a structured, commonly used, machine-readable format.
  • Objection — to processing based on legitimate interests, and absolutely to direct marketing.
  • Withdrawal of consent — at any time, without affecting processing already carried out.
  • Complaint — to your local supervisory authority. We would appreciate the chance to resolve it first.

8.2 If you are in California

Under the CCPA as amended by the CPRA you may request disclosure of the categories and specific pieces of personal information collected, the sources, the business purposes and the categories of recipient; request deletion; request correction; and limit the use of sensitive personal information (we do not use sensitive personal information for any purpose requiring a limitation right). You may exercise these rights through an authorised agent with written authorisation. We will not discriminate against you for exercising any right.

8.3 Other US states

Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and other states with comprehensive privacy statutes have broadly equivalent rights of access, correction, deletion, portability and opt-out. We apply the same process to all such requests regardless of residency.

8.4 How to exercise a right

Email [email protected] with “Data rights request” in the subject line, or write to the address in the final section. We will verify your identity proportionately to the sensitivity of the request — usually by confirming control of the email address on file, and for warranty or order records by matching two details from the record.

We respond within 30 days for GDPR requests and 45 days for US state requests, extendable once by a further 60 days for complex requests, with notice. There is no charge unless a request is manifestly unfounded or excessive, in which case we will tell you the fee before proceeding.

9. Cookies and similar technologies

This site uses a small number of strictly necessary first-party cookies and equivalent browser storage. It uses no advertising cookies, no third-party trackers and no cross-site identifiers. The full inventory, with purposes and durations, is set out in the cookie policy.

10. Automated decision-making

We do not carry out automated decision-making producing legal or similarly significant effects, as defined in Article 22 GDPR. Trade credit applications include an automated credit-reference check, but the decision to grant or refuse terms is always taken by a person who can be asked to explain it and who will reconsider on request.

11. Changes to this policy

We review this policy at least annually and whenever our processing changes materially. The version number and review date at the top of the page always reflect the current text.

For material changes — a new purpose, a new category of recipient, a materially longer retention period — we will give at least 30 days’ notice by email to subscribers and account holders and by a prominent notice on this site before the change takes effect. Superseded versions are retained and available on request.

How to contact us about this policy

Write to [email protected] with the policy name in the subject line, call +1 (888) 555-2783 between 8:00 and 18:00 ET on working days, or post to:

uBRITE Lighting — Legal & Compliance
Sumar International, Inc.
1420 Brightway Drive
Suite 210
Dover
DE 19901
USA

We acknowledge written enquiries within five working days and aim to resolve them within thirty.