1. Who we are
uBRITE Lighting is a trading brand of Sumar International, Inc., a corporation registered in the State of Delaware, United States, with its principal place of business at 1420 Brightway Drive, Suite 210, Dover, DE 19901, USA. In this policy, “we”, “us” and “uBRITE” mean Sumar International, Inc.
For the purposes of the EU and UK General Data Protection Regulation we act as the data controller for personal data collected through this website and through our sales, warranty and service operations. For data we process on behalf of a business customer — for example a tenant list supplied to us for a commercial retrofit — we act as a processor under the terms of the relevant services agreement.
This policy covers ubritelight.com and every subdomain, our warranty registration system, our order and support systems, and any uBRITE-branded form or portal that links to this page. It does not cover third-party websites we link to; those have their own policies and we do not control them.
2. What personal data we collect
We collect only what a specific purpose requires. The categories are:
2.1 Data you give us directly
| Where | What | Required? |
|---|---|---|
| Contact form | First and last name, email, phone (optional), company (optional), topic, approximate number of fittings (optional), ZIP code (optional), message text, consent flags | Name, email, topic, message required |
| Warranty registration | Name, email, product SKU, lamp serial number, quantity, purchase date, retailer, ZIP code, free-text notes | All except notes |
| Newsletter | Email address | Yes |
| Trade account | Business name, registered address, tax identification number, named contacts, trade references, delivery addresses | Yes, for credit terms |
| Site survey | Site address, access arrangements, contact on site, photographs of fittings and spaces | Yes, to deliver the service |
| Recruitment | CV, cover letter, right-to-work confirmation, references | As stated in the advert |
2.2 Data collected automatically
When you visit the site, our servers and our own first-party analytics record: IP address (truncated to the first three octets before storage), user-agent string, referring URL, pages requested, timestamps, approximate region derived from the truncated IP, and whether the request came from a returning browser. We do not use third-party advertising trackers, social media pixels, session recording, cross-site fingerprinting or data brokers.
2.3 Data from third parties
For trade accounts we may receive credit-reference information from commercial credit agencies, and confirmation of company status from public registries. For rebate administration we may receive confirmation of eligibility from a utility programme administrator, where you have asked us to apply on your behalf.
2.4 Data we do not collect
We do not collect special-category data (health, biometrics, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sexual orientation), and we ask that you do not include it in free-text fields. We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
We do not store full payment card numbers. Card payments are processed by a PCI-DSS Level 1 certified payment provider; we receive only a token, the last four digits and the card brand.
3. Why we process it, and our legal basis
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Replying to an enquiry | Contact form data | Consent, and legitimate interests in answering the people who write to us |
| Fulfilling an order | Name, delivery and billing address, payment token | Performance of a contract |
| Administering a warranty | Registration data, serial number, claim history | Performance of a contract |
| Delivering a service | Site data, survey notes, photographs, metering data | Performance of a contract |
| Newsletter | Email address | Consent, withdrawable at any time |
| Fraud prevention and site security | Truncated IP, request logs, honeypot field results | Legitimate interests in protecting the service |
| Aggregate analytics | Truncated IP, page views, referrer | Legitimate interests in understanding which pages are useful |
| Accounting and tax records | Transaction records | Legal obligation |
| Product safety and recall | Registration and batch data | Legal obligation, and vital interests where a safety issue arises |
Where we rely on legitimate interests we have carried out a balancing assessment and concluded that the processing is necessary, proportionate and not overridden by your rights. You may object to any such processing — see section 8.
4. Who we share it with
We do not sell personal data, and we do not share it for cross-context behavioural advertising. Under the California Consumer Privacy Act as amended by the CPRA, we have not sold or shared personal information in the preceding twelve months.
We do disclose personal data to the following categories of recipient, each under a written contract limiting them to our instructions:
- Hosting and infrastructure. Our website and application servers are operated in United States data centres.
- Email delivery. Transactional and newsletter email is delivered through a specialist provider.
- Payment processing. A PCI-DSS Level 1 certified processor, which receives card data directly from your browser.
- Logistics. Carriers receive the name, delivery address and phone number needed to deliver a parcel.
- Installation partners. Where a retrofit is delivered by an approved partner, they receive the site address and on-site contact only.
- Recycling processors. R2-certified processors receive return volumes and the shipping label data; no customer identity beyond that.
- Professional advisers. Auditors, insurers and lawyers, under professional confidentiality obligations.
- Authorities. Where we are legally compelled, or where disclosure is necessary to establish, exercise or defend legal claims. We notify you of any such request unless legally prohibited.
In the event of a merger, acquisition or asset sale, personal data may transfer to the acquiring entity. We would notify affected individuals before the transfer and the acquiring entity would remain bound by this policy until it was lawfully replaced.
5. International transfers
We are based in the United States and our infrastructure is located there. If you are in the European Economic Area, the United Kingdom or Switzerland, your personal data is transferred outside your jurisdiction when you contact us.
We rely on the European Commission’s Standard Contractual Clauses (Decision 2021/914), together with the UK International Data Transfer Addendum where the UK GDPR applies, as the transfer mechanism. We have carried out a transfer impact assessment and apply the following supplementary measures: encryption in transit (TLS 1.3) and at rest (AES-256), strict access controls with multi-factor authentication, data minimisation at the point of collection, IP truncation before storage, and a published policy of challenging any government access request that is not lawfully binding on us.
A copy of the relevant clauses is available on request from the address in the final section.
6. How long we keep it
We keep personal data only as long as the purpose requires, then delete or irreversibly anonymise it. Our schedule:
| Record | Retained for | Why |
|---|---|---|
| General enquiry | 24 months from last contact | Continuity if you write again |
| Quotation not proceeded with | 24 months | Re-quoting and price history |
| Warranty registration | Warranty term plus 24 months | Claim administration and dispute window |
| Order and transaction records | 7 years from end of tax year | Tax and accounting obligation |
| Survey notes and photographs | 6 years from completion | Professional liability period |
| Metering and audit data | 6 years, then anonymised for benchmarks | Contractual and statistical |
| Newsletter subscription | Until you unsubscribe, plus 30 days | Honouring the unsubscribe |
| Server and security logs | 90 days | Security investigation |
| Aggregate analytics | 26 months, no identifiers | Year-on-year comparison |
| Unsuccessful job applications | 12 months, with consent | Future vacancies |
Where a legal claim is live or reasonably anticipated, relevant records are placed on hold and retained until the matter is finally resolved.
7. How we protect it
Our technical and organisational measures include:
- TLS 1.3 for all data in transit, with HTTP Strict Transport Security enforced site-wide.
- AES-256 encryption at rest for databases and backups.
- Role-based access control on the principle of least privilege, reviewed quarterly, with multi-factor authentication mandatory for all staff accounts.
- Separation of production and non-production environments; no production personal data in test systems.
- Encrypted, access-controlled backups with restoration tested twice yearly.
- Annual penetration testing by an independent third party, with findings remediated on a risk-rated schedule.
- Mandatory annual data protection training for every member of staff with access to personal data.
- A documented incident response plan, rehearsed annually.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and notify affected individuals without undue delay where the risk is high.
8. Your rights
8.1 If you are in the EEA, UK or Switzerland
- Access — a copy of the personal data we hold about you, with information about how it is processed.
- Rectification — correction of inaccurate data and completion of incomplete data.
- Erasure — deletion where the data is no longer necessary, consent is withdrawn, or processing is unlawful.
- Restriction — a pause on processing while accuracy or a legitimate-interests objection is being resolved.
- Portability — data you gave us, in a structured, commonly used, machine-readable format.
- Objection — to processing based on legitimate interests, and absolutely to direct marketing.
- Withdrawal of consent — at any time, without affecting processing already carried out.
- Complaint — to your local supervisory authority. We would appreciate the chance to resolve it first.
8.2 If you are in California
Under the CCPA as amended by the CPRA you may request disclosure of the categories and specific pieces of personal information collected, the sources, the business purposes and the categories of recipient; request deletion; request correction; and limit the use of sensitive personal information (we do not use sensitive personal information for any purpose requiring a limitation right). You may exercise these rights through an authorised agent with written authorisation. We will not discriminate against you for exercising any right.
8.3 Other US states
Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and other states with comprehensive privacy statutes have broadly equivalent rights of access, correction, deletion, portability and opt-out. We apply the same process to all such requests regardless of residency.
8.4 How to exercise a right
Email [email protected] with “Data rights request” in the subject line, or write to the address in the final section. We will verify your identity proportionately to the sensitivity of the request — usually by confirming control of the email address on file, and for warranty or order records by matching two details from the record.
We respond within 30 days for GDPR requests and 45 days for US state requests, extendable once by a further 60 days for complex requests, with notice. There is no charge unless a request is manifestly unfounded or excessive, in which case we will tell you the fee before proceeding.
9. Cookies and similar technologies
This site uses a small number of strictly necessary first-party cookies and equivalent browser storage. It uses no advertising cookies, no third-party trackers and no cross-site identifiers. The full inventory, with purposes and durations, is set out in the cookie policy.
10. Automated decision-making
We do not carry out automated decision-making producing legal or similarly significant effects, as defined in Article 22 GDPR. Trade credit applications include an automated credit-reference check, but the decision to grant or refuse terms is always taken by a person who can be asked to explain it and who will reconsider on request.
11. Changes to this policy
We review this policy at least annually and whenever our processing changes materially. The version number and review date at the top of the page always reflect the current text.
For material changes — a new purpose, a new category of recipient, a materially longer retention period — we will give at least 30 days’ notice by email to subscribers and account holders and by a prominent notice on this site before the change takes effect. Superseded versions are retained and available on request.
How to contact us about this policy
Write to [email protected] with the policy name in the subject line, call +1 (888) 555-2783 between 8:00 and 18:00 ET on working days, or post to:
uBRITE Lighting — Legal & Compliance
Sumar International, Inc.
1420 Brightway Drive
Suite 210
Dover
DE 19901
USA
We acknowledge written enquiries within five working days and aim to resolve them within thirty.