Privacy Policy

Privacy Policy

Privacy Policy for customers, potential customers, members and website visitors

Last updated: 3 September 2026


1. Who we are

LK Technology Frontier Ltd ("LK Technology Frontier", "we", "us" or "our") provides websites, digital content and services under the CTO Larsson and Larsson Line names, including Larsson Line Pro, courses, the Larsson Line indicator and related services.

LK Technology Frontier Ltd is a company registered in Cyprus and is the controller of the personal data described in this Privacy Policy where we determine why and how that data is processed.

LK Technology Frontier Ltd
Makariou III, 34
Hadjiyianni Bldg, Office 203
Limassol 3065
Cyprus
Company registration no.: HE 459024

Privacy contact: info@ctolarsson.com

Telephone: +44 20 39968761

This Privacy Policy applies to our websites, including ctolarsson.com and its subdomains, lkfrontier.com, Larsson Line Pro, our checkout and Admin Panel, our course and related services, and our communications with customers and prospective customers.

Some parts of the Services use third-party platforms, such as Kajabi, TradingView and payment providers. Legacy service providers may also continue to process limited personal data for existing-user access during wind-down. Those providers may process personal data as independent controllers under their own privacy policies when you use their services directly.

Accounts for our paid Services are intended for persons aged 18 or over.


2. Personal data we process

The personal data we process depends on which parts of the Services you use.

Account and identity information

This may include:

  • name;
  • email address and, where provided, alternative email addresses;
  • account and user identifiers;
  • user-selected nickname;
  • account status and service entitlements;
  • purchase, activation, expiry and renewal dates; and
  • subscription or membership status.

Authentication for our course website is provided through Kajabi. Authentication for Larsson Line Pro and the Admin Panel is provided through Firebase/Google Cloud. Passwords used with those authentication systems are handled by the applicable authentication provider and are not stored in our Larsson Line Pro application databases.

Purchase, payment and tax information

We process information needed to administer purchases and determine access to the Services, such as:

  • customer and transaction identifiers;
  • payment-provider customer or subscription identifiers;
  • payment status and payment-method category;
  • amount, currency and purchase date;
  • product and access period;
  • renewal information;
  • country, whether the purchase was made as a consumer or for business purposes, and other information relevant to tax treatment, statutory consumer rights or jurisdiction-based service availability; and
  • limited checkout and payment-attempt information used for troubleshooting.

Complete payment-card details are processed by payment providers and are not stored in our application databases.

Payment providers may process additional information such as billing addresses, tax identifiers, payment credentials, fraud-prevention information, IP addresses and payment transaction information under their own systems.

We may obtain or retain copies of more detailed billing, invoice and transaction records where necessary for accounting, audit, tax, banking, AML/KYC, regulatory or legal purposes. For example, information may be exported from a payment provider and provided to our accounting or audit firm, tax service providers, banks or public authorities where required.

Payment, tax and infrastructure providers may record IP addresses and other location evidence in their own systems. We do not currently maintain a separate Company database of checkout IP addresses for VAT or jurisdiction screening. We may retain transaction-location evidence received from those providers where reasonably necessary for tax, accounting, audit or legal records.

We occasionally accept payment by bank transfer. We do not receive customer crypto-assets directly. Where a customer chooses a digital-asset payment method, payment is made to a payment service provider which handles the payment and settles funds to us in fiat currency.

Cancellation, termination and statutory withdrawal information

If you cancel a renewal, exercise a statutory withdrawal right, submit a contract-termination request or otherwise ask us to end a subscription or contract, we may process:

  • your name and contact information;
  • account, order, invoice, subscription or other contract identifiers;
  • the Service concerned and the requested termination date;
  • the type of cancellation or termination and, where relevant, the reason you provide;
  • the date and time of submission and receipt, acknowledgements, decisions and related correspondence; and
  • resulting subscription, access and refund information.

If information provided in connection with an extraordinary termination request includes special-category or other sensitive personal data, please provide only what is reasonably necessary for us to understand and handle the request. We process such information only where and to the extent permitted by applicable data-protection law.

Larsson Line Pro Portfolio information

The Portfolio feature is private to the relevant user.

Information a user chooses to store may include:

  • assets or instruments;
  • quantities and other position information;
  • user-entered cash or portfolio information;
  • notes and other free-text information;
  • alerts and settings; and
  • other information the user chooses to enter for use with Portfolio functionality and analytics.

Portfolio information can reveal information about a user's financial interests or holdings. We treat this information as private user data and do not make private Portfolio information available to other Larsson Line Pro members.

Legacy user-generated content — existing users only

User-generated sharing functionality is closed to new sign-ups and is being wound down. This section applies only to legacy content created or retained for existing users while that functionality remains available.

Depending on the choices previously made by the user, legacy user-generated data may include:

  • a user-selected nickname;
  • comments;
  • images or charts uploaded with comments;
  • shared asset lists;
  • assets included in those shared lists; and
  • timestamps and other information necessary to display and manage the content.

Comments and images posted through legacy sharing functionality are visible to other Larsson Line Pro members. A shared list is visible to other members only where its creator chose to share it.

Other members normally see the user's chosen nickname rather than the user's account email address or real name, unless the user chooses to disclose identifying information in their own content.

Users with remaining legacy access should not include personal data about themselves or other people in shared content unless they are comfortable sharing that information with other Larsson Line Pro members and have the right to do so.

TradingView information

Where you use TradingView, we may process:

  • your TradingView username to activate or administer access to the Larsson Line indicator.

Legacy external-platform information

For legacy existing users who still have access to an external-platform feature during the wind-down, we may process:

  • the username, platform user ID and membership or role information needed to administer the remaining external-platform access.

Messages exchanged through that legacy external platform remain hosted by the relevant third-party provider. We do not copy or retain the general message history in our own application databases.

Course and Kajabi information

Kajabi hosts our course platform and may process information including:

  • name and email address;
  • Kajabi user ID and authentication information;
  • course access and progress;
  • mailing-list or subscription status; and
  • information about marketing emails, such as whether a message was opened or a link was clicked.

Historical information relating to older purchases may also remain within Kajabi systems in accordance with Kajabi's own retention and processing arrangements.

Usage, administration, security and troubleshooting information

We and our infrastructure providers may process information such as:

  • latest login information;
  • account activity and administrative logs;
  • actions performed within the Services;
  • service activation and entitlement history;
  • checkout attempts and whether the user continued to the payment provider;
  • technical error or troubleshooting information;
  • correspondence and support history; and
  • internal administrative notes where reasonably necessary.

Cloud, authentication, security and other infrastructure providers may also automatically process technical information such as IP addresses, browser or device information and security logs even where those data are not copied into our own application databases.

Cloudflare Turnstile

We use Cloudflare Turnstile on certain public forms to protect against automated abuse and spam. Turnstile processes technical information about the browser, device and network connection to determine whether a request is likely to be made by a human. We use this processing for security and abuse prevention.

Support communications

If you contact us, we process and retain the information contained in your enquiry and related correspondence where reasonably necessary to investigate and answer the enquiry, maintain appropriate support history, administer our relationship with you, and meet applicable legal or evidential requirements.

This may include your name, email address, account information, purchase or entitlement information, correspondence, screenshots and other information you choose to provide.

If you contact us by telephone, we may process your caller number, voicemail recording and an automatically generated transcript to receive, review and respond to your enquiry.

Marketing and email information

We maintain different communication lists, which may include customers, Larsson Line Pro members, prospective customers and people who have separately requested particular communications such as new-video notifications or free educational material.

Depending on the communication, we may process:

  • name;
  • email address;
  • subscriber category;
  • subscription and unsubscribe information;
  • email delivery information; and
  • information about email opens and link clicks where provided by the mailing platform.

Marketing and broadcast emails are currently primarily administered through Kajabi.

We also use email infrastructure including Twilio SendGrid for operational communications such as Larsson Line Pro alerts, service information, renewal or expiry information and other messages necessary to provide or administer the Service.

Website analytics, advertising and similar technologies

Subject to your cookie choices and applicable law, our websites may use analytics and advertising technologies such as Google Analytics, Hotjar, RudderStack, Google advertising technologies and X advertising technologies.

These technologies may process information including:

  • IP address and approximate location;
  • browser and device information;
  • online or cookie identifiers;
  • referring page or advertising campaign;
  • pages visited and interactions with the website;
  • session and usage information;
  • heatmap or interaction information; and
  • advertising-conversion information.

Not every technology is used on every part of our Services.

For more information, including the technologies currently detected on our websites and how to manage your choices, please see our Cookie Policy.

Merchandise

Where we make optional merchandise available, shipping information is generally entered directly with the merchandise supplier, such as Freaker USA.

We may receive or exchange limited order or contact information where reasonably necessary to resolve an order or delivery problem.

Legacy content reports and moderation

If you submit an illegal-content notice or other report concerning legacy user-generated content, or if content you posted is reported, we may process:

  • reporter and author information;
  • the reported content and its location;
  • the reason for the report;
  • information or evidence supplied with the report;
  • communications concerning the report;
  • moderation decisions and reasons; and
  • related records required by applicable law.

Reports may sometimes contain allegations about unlawful conduct or other sensitive matters. We process such information only as reasonably necessary to review the report, operate and protect the remaining legacy functionality, enforce our Terms and comply with applicable law.


3. Why we process personal data and our legal bases

Where the GDPR or UK GDPR applies, our principal purposes and legal bases are:

Purpose Principal legal basis
Create and administer accounts and provide purchased Services Performance of a contract — Article 6(1)(b) GDPR
Maintain Portfolio information and provide personalised account functionality selected by the user Performance of a contract — Article 6(1)(b)
Display legacy user-generated content that an existing user previously chose to share during wind-down Performance of a contract — Article 6(1)(b)
Activate TradingView and administer remaining legacy third-party platform access for existing users Performance of a contract — Article 6(1)(b)
Process purchases, subscriptions, renewals and service entitlements Performance of a contract — Article 6(1)(b)
Handle cancellation, termination and statutory-withdrawal requests, including acknowledgements, access changes and refunds Performance of a contract and/or compliance with legal obligations — Articles 6(1)(b) and 6(1)(c)
Determine and document VAT, tax and customer-location treatment and apply jurisdiction-based service availability Compliance with legal obligations for tax/location records and our legitimate interests in applying jurisdiction-specific service restrictions — Articles 6(1)(c) and 6(1)(f)
Maintain accounting, invoice, tax, audit and statutory records Compliance with legal obligations — Article 6(1)(c)
Respond to support requests and administer the customer relationship Performance of a contract and/or our legitimate interests in providing effective customer support — Articles 6(1)(b) and 6(1)(f)
Send necessary account, security, payment, renewal, expiry, contractual or legal communications Performance of a contract and/or compliance with legal obligations — Articles 6(1)(b) and 6(1)(c)
Prevent fraud, protect accounts, troubleshoot problems and secure the Services Our legitimate interests in operating secure and reliable Services — Article 6(1)(f), and legal obligations where applicable
Handle legacy user-content reports, moderation and illegal-content notices Compliance with legal obligations where applicable and our legitimate interests in operating and protecting remaining legacy functionality — Articles 6(1)(c) and 6(1)(f)
Establish, exercise or defend legal claims and resolve disputes Our legitimate interests in protecting our legal rights — Article 6(1)(f), and other applicable legal grounds
Send direct marketing Consent where required; otherwise our legitimate interests in marketing our own services where applicable law permits this and appropriate opt-out rights have been provided — Articles 6(1)(a) and 6(1)(f)
Use non-essential analytics and advertising cookies or similar technologies Consent where required — Article 6(1)(a)
Comply with lawful requests from courts, tax authorities, regulators, law-enforcement authorities or other competent authorities Compliance with legal obligations — Article 6(1)(c)

A GDPR legal basis does not replace separate rules that may apply to electronic marketing, cookies or similar technologies. Where applicable law requires consent for a marketing communication or technology, we request that consent separately.

Where we rely on legitimate interests, we consider the relevant business purpose, the necessity of the processing and its potential effect on individuals.

Where a cancellation, termination or statutory-withdrawal request contains special-category personal data, we process that information only where an additional condition under Article 9 GDPR applies, including Article 9(2)(f) where processing is necessary for the establishment, exercise or defence of legal claims.


4. Where we obtain personal data

Most personal data comes directly from you when you create an account, purchase a Service, use Larsson Line Pro, use any remaining legacy user-generated functionality available to your existing account, subscribe to communications or contact support.

We may also obtain personal data from:

  • authentication and platform providers such as Kajabi, Firebase and Google;
  • payment processors and financial institutions;
  • TradingView or legacy service providers where needed to administer integrations or remaining existing-user access;
  • analytics and advertising providers, subject to applicable consent requirements;
  • accountants, auditors, tax advisers or professional advisers;
  • public authorities where appropriate; and
  • other service providers involved in operating the Services.

5. Information required to provide the Services

Certain information is necessary to enter into or perform our contract with you.

For example, we need an email address and account information to provide digital access, and the applicable payment provider needs the information required to process a purchase.

Billing, tax and customer-location information may also be required to calculate tax, issue invoices, comply with tax law or apply jurisdiction-based service-availability restrictions.

If required information is not provided, we may be unable to create an account, process a purchase or provide the relevant Service.

Portfolio information, legacy user-generated content or uploads where still available to an existing account, and most marketing subscriptions are optional. You do not have to use those features.


6. Who receives personal data

We use third parties to operate, support and administer our Services. The personal data disclosed or otherwise made available to a recipient depends on the service it provides and the reason for the processing.

Core technology and service providers

Our principal technology and service providers include:

Google, including Google Cloud, Firebase, Google Workspace and Google Drive, for cloud infrastructure, authentication, business email, document storage and related business IT.

Cloudflare, for Turnstile bot detection and abuse prevention on certain public forms.

Kajabi, for website and course hosting, customer accounts, course access and progress, and email communications.

Sonetel, for business telephone, voicemail, transcription and delivery of messages.

Stripe, including Stripe Tax, for payment processing, subscriptions, billing, invoices, tax calculation and related payment administration.

Twilio SendGrid, for delivery of operational and service-related emails.

TradingView, in connection with access to the Larsson Line indicator and related product functionality.

Discord, solely for remaining legacy existing-user access during wind-down. Messages and other content exchanged through Discord remain hosted on Discord’s systems.

These providers may receive account identifiers, contact information, technical information, service-entitlement information or other personal data necessary for the particular service they provide.

Payments, accounting, tax, audit, banking and legal compliance

Some of the most detailed personal data we process arises from purchases and the legal and financial records associated with them.

We may disclose personal data where reasonably necessary for payment processing, accounting, statutory audit, tax reporting, banking, AML/KYC checks, regulatory compliance or other legal obligations.

Recipients may include:

  • payment processors and payment service providers, including Stripe, PayPal, xMoney and CoinGate where applicable;
  • our accounting firm and statutory auditor;
  • tax advisers and tax-filing providers, including Taxually;
  • banks, payment institutions and other regulated financial service providers;
  • lawyers and other professional advisers where information is reasonably necessary for advice, compliance, disputes or legal claims; and
  • competent tax authorities, regulators, courts, law-enforcement authorities and other public bodies.

Depending on the purpose, these disclosures can include detailed transaction records containing information such as a customer's name, billing address, country, tax information, transaction amount, currency, payment information and transaction identifiers.

For example, accounting, audit, tax, banking or regulatory processes may require us to obtain or provide copies of original reports or transaction records generated by payment providers.

We do not publish a list of the individual banks, auditors, authorities or other institutions that may receive data in a particular case. The identity of a specific recipient can depend on the transaction, jurisdiction, legal requirement or financial relationship involved.

Some of these recipients process personal data on our instructions. Others, including banks, statutory auditors, certain professional advisers and public authorities, may determine their own purposes and means of processing and have independent legal responsibilities for the information they receive.

Merchandise fulfilment — Freaker USA

Freaker USA fulfils optional merchandise, such as socks or caps, made available in connection with our Services.

Where you choose to order merchandise, you provide the shipping information required for fulfilment directly to Freaker USA. This can include your name, delivery address and other contact or fulfilment information.

Shipping information is particularly privacy-sensitive because it may identify a customer's home or other physical delivery address. Freaker USA processes this information for order fulfilment and delivery.

We may receive or exchange limited order, contact or delivery information with Freaker USA where reasonably necessary to administer the merchandise programme or resolve an order or delivery problem.

Analytics and advertising providers

Subject to your cookie choices and applicable law, our websites may use analytics and advertising providers including:

Google, including Google Analytics, Google Ads and YouTube;
Hotjar, for website interaction analytics and heatmaps;
RudderStack, for website analytics infrastructure; and
X, and other advertising providers identified in our Cookie Policy, for advertising measurement and related advertising functions where enabled.

These providers may receive online identifiers, IP addresses, browser or device information, website activity, advertising-attribution information and similar usage information.

Not every provider or technology is used on every part of our Services. The Cookie Policy provides more detailed and current information about the technologies operating on our websites.

Customer support and operational assistance

Authorised contractors and service providers may have access to limited customer information where this is reasonably necessary to provide customer support, technical assistance or other operational services on our behalf.

Access is limited to information relevant to the work being performed.

AI-assisted business tools

OpenAI or other approved AI service providers may process limited customer information in the circumstances described in the section AI-assisted support and internal work.

Customer support remains human-operated. AI tools may be used to assist authorised personnel with tasks such as troubleshooting, analysis, summarisation or preparation of draft responses.

Other disclosures

We may also disclose personal data:

  • where you ask or authorise us to do so;
  • where reasonably necessary to protect the security or integrity of our Services or investigate fraud or abuse;
  • in connection with the establishment, exercise or defence of legal claims;
  • where required by applicable law or a legally binding request; or
  • in connection with a merger, acquisition, restructuring or transfer of all or part of the business, subject to applicable data-protection requirements.

Processors and independent controllers

The legal role of a recipient depends on the particular processing involved.

Some providers process personal data on our behalf and subject to our instructions. Other organisations may process information as independent controllers because they determine their own purposes and legal obligations. This may apply, for example, to certain payment providers, banks, statutory auditors, professional advisers, public authorities, TradingView, legacy third-party platforms and advertising platforms.

Where another organisation acts as an independent controller, its own privacy information applies to the processing for which it determines the purposes and means.


7. We do not sell customer lists

We do not sell customer contact details or customer lists to projects or other third parties for their independent marketing.

We do not provide customer contact details to issuers, crypto projects or other businesses so that they can market investments, tokens, financial products or other unrelated products to our customers.

Advertising cookies and similar technologies may nevertheless involve disclosures of online identifiers or usage information to advertising providers. Some privacy laws use specialised definitions of terms such as "sale", "sharing" or "targeted advertising" that can include certain advertising technology even where no customer list is sold and no money is paid for the personal data. Where such laws apply, the applicable rights are described below and in our Cookie Policy.


8. Legacy user-generated content and privacy

This section applies only to legacy user-generated content created by existing users while the feature is being wound down. It is not available to new sign-ups.

When an existing user publishes a comment, image or shared asset list through remaining legacy functionality, other Larsson Line Pro members can view that content together with the user’s chosen nickname.

Do not publish information that you want to remain private.

Private Portfolio data and private text notes are not intentionally displayed to other members.

If legacy user-generated content is subsequently deleted, we will remove it from our Services in accordance with our retention and deletion processes. However, we cannot guarantee deletion of copies that another person may independently have made outside our systems, including copies made in breach of our Terms.


9. Cookies and similar technologies

We use cookies and similar technologies for functions including authentication, security, preferences, website operation, analytics and, where enabled, advertising measurement.

Strictly necessary technologies may operate without optional cookie consent where permitted by law because they are required to provide functionality requested by the user or operate the service.

Where consent is required for analytics, advertising or other non-essential technologies, those technologies should not be activated until the relevant consent has been obtained.

You can manage applicable choices through our cookie-consent controls.

For current details, please see our Cookie Policy.


10. Marketing and service communications

Marketing communications and necessary service communications are treated differently.

You can unsubscribe from marketing emails using the unsubscribe function in the communication or by contacting us.

Where applicable law permits us to send marketing concerning our own similar services to an existing customer without separate prior consent, we provide the opt-out opportunities required by applicable law.

An objection to or unsubscribe from direct marketing does not stop communications that are reasonably necessary to provide or administer a Service you use.

For example, we may still send:

  • account and access information;
  • security notices;
  • payment or invoice information;
  • subscription and renewal information;
  • legally required renewal notices;
  • service-expiry information;
  • important changes to a Service or contract; and
  • other contractual or legal notices.

11. AI-assisted support and internal work

Customer support is handled by people. We do not operate an autonomous AI customer-support system that independently decides how customer enquiries should be resolved.

In limited circumstances, authorised personnel may use approved AI-assisted tools to help analyse information, troubleshoot a problem, summarise material or prepare a draft response.

Where identifiable customer information is processed in such a tool, our operating rule is to use configurations or business services under which the submitted customer content is not used to train the provider's general AI models.

AI-assisted output is used as an aid to human work. A human remains responsible for the relevant customer communication or operational decision.

We may also use AI tools for internal business tasks where this can be done consistently with applicable privacy, confidentiality and security requirements.

Voicemail messages may also be automatically transcribed by our telephone service provider. The transcript assists human handling of the enquiry; it does not independently respond to callers or make decisions.


12. Automated decision-making and profiling

We do not use customer personal data to make solely automated decisions that produce legal effects concerning a customer or similarly significantly affect them.

Larsson Line Pro contains automated market analytics, but those calculations analyse market and historical price data rather than making automated decisions about an individual's eligibility, creditworthiness or personal financial suitability.

Analytics and advertising providers may use online identifiers and activity information for measurement, attribution or advertising-related profiling where permitted by applicable law and your cookie choices.


13. International transfers

We are established in Cyprus, but we use international service providers and have customers around the world.

Personal data may therefore be processed in Cyprus, elsewhere in the EU/EEA, the United Kingdom, the United States and other countries in which relevant service providers or authorised contractors operate.

Where GDPR-protected personal data is transferred outside the EU/EEA, we use an appropriate transfer mechanism where required. Depending on the recipient, this may include:

  • a European Commission adequacy decision;
  • the EU-US Data Privacy Framework for eligible certified US recipients;
  • the European Commission's Standard Contractual Clauses;
  • another legally recognised transfer mechanism; or
  • an applicable statutory derogation in the limited circumstances where one is available.

For UK personal data, applicable mechanisms may include UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework, the UK International Data Transfer Agreement or Addendum, or another lawful transfer mechanism.

For personal data protected by Swiss law, applicable adequacy decisions, the Swiss-US Data Privacy Framework, contractual safeguards or other mechanisms permitted under Swiss law may be used.

Global cloud and technology providers can use multiple data centres and subprocessors. It is therefore not always practicable to identify every country in which technical processing may occur.

For Australian users, our principal overseas processing locations and recipient locations include Cyprus and other EU/EEA countries, the United Kingdom and the United States. Other locations may be involved where a global service provider or authorised support provider uses them.

You may contact us if you would like further information about the safeguards relevant to a particular transfer.


14. How long we keep personal data

We do not apply one retention period to every category of information.

Larsson Line Pro account and user-created data

While Larsson Line Pro access is active, we retain the account data reasonably necessary to provide the Service.

After paid Larsson Line Pro access expires, we generally retain ordinary LLP account and user-created data for 24 months so that a returning customer can reactivate the Service and recover their previous data.

After that period, we delete ordinary user-created LLP data associated with the expired account, including, as applicable:

  • private Portfolio information;
  • private comments and notes;
  • legacy shared comments;
  • legacy shared images;
  • legacy shared asset lists; and
  • similar ordinary LLP user-created content.

You may request deletion earlier, subject to the exceptions described below.

Course accounts

Where a customer remains entitled to continuing course access, account information and course-progress information may be retained while that access continues.

Marketing

Marketing contact information is retained while the relevant marketing relationship continues or until you unsubscribe, object or withdraw consent as applicable.

We may retain limited suppression information after an unsubscribe so that we can respect the request and avoid unintentionally adding the address back to the same marketing list.

Payment, tax, accounting and contractual records

Purchase, payment, invoice, tax, accounting, contract and related evidence is retained for the period required or permitted by applicable law.

Certain VAT and One-Stop-Shop records and evidence may need to be retained for 10 years.

This may include transaction-location evidence such as billing country, transaction-time IP information or other evidence relied upon for VAT purposes.

We may also retain evidence of service delivery, Terms acceptance, subscription history, cancellation and termination requests, statutory-withdrawal requests, acknowledgements, refunds and related matters for applicable legal, regulatory and limitation periods.

Support, security and administration records

Support correspondence, activity logs, troubleshooting information and security information are retained only for as long as reasonably necessary for the relevant operational, security, evidential or legal purpose.

Records relating to a particular security incident, dispute, legal claim, legacy content report or moderation decision may be retained for longer where necessary.

Email and customer correspondence

Emails and other direct correspondence with customers or prospective customers may remain in our business email and support systems after the immediate enquiry has been resolved. We do not routinely delete individual messages immediately after each interaction because correspondence may be relevant to later customer support, account or contract administration, complaints, security or fraud investigations, accounting or tax matters, regulatory compliance, or the establishment, exercise or defence of legal claims.

Legal and regulatory exceptions

We may retain information beyond an ordinary retention period where necessary to:

  • comply with accounting, tax or other legal obligations;
  • comply with a lawful regulatory, court or authority requirement;
  • establish, exercise or defend legal claims;
  • investigate fraud or a security incident;
  • preserve evidence relating to a complaint or moderation decision; or
  • resolve a dispute.

Deletion from live systems may not immediately remove every residual copy from protected backup systems. Backup copies are deleted or overwritten in accordance with the applicable backup cycle and are not used for ordinary business purposes after deletion from the live system.


15. Security

We use technical and organisational measures designed to provide a level of security appropriate to the risks associated with the personal data we process.

Measures may include access controls, authentication, restricted administrative permissions, cloud security measures, logging, backups and organisational controls over access to customer information.

Information may also have to be provided to regulated banks, auditors, tax authorities or other organisations that process it under their own legal and security responsibilities.

No internet, email, cloud or information-storage system can guarantee complete security.


16. Your privacy rights

The rights available to you depend on the law applicable to the processing.

Where the GDPR or UK GDPR applies, you may have the following rights.

Access

You may ask whether we process your personal data and request a copy of personal data relating to you together with the information required by applicable law.

Rectification

You may ask us to correct inaccurate personal data and complete incomplete data where appropriate.

Erasure

You may ask us to delete personal data where the applicable legal conditions are met.

The right to erasure is not absolute. We may retain information where continued processing is necessary or permitted, including for legal, accounting, tax or regulatory obligations or the establishment, exercise or defence of legal claims.

Restriction

You may ask us to restrict processing in circumstances provided by applicable law.

Data portability

Where processing is based on consent or contract and is carried out by automated means, you may have the right to receive personal data that you provided to us in a structured, commonly used and machine-readable format and, where technically feasible and legally applicable, have it transmitted to another controller.

Object to processing based on legitimate interests

Where processing is based on our legitimate interests, you may object on grounds relating to your particular situation.

We will stop the relevant processing unless we can demonstrate applicable compelling legitimate grounds for continuing it or the processing is necessary for the establishment, exercise or defence of legal claims.

Object to direct marketing

You may object to processing of your personal data for direct marketing at any time.

If you object to direct marketing, we will stop using the relevant personal data for that purpose.

Withdraw consent

Where processing is based on your consent, you may withdraw that consent at any time.

Withdrawal does not affect processing that was lawful before the consent was withdrawn.

Complaints

You may contact us at info@ctolarsson.com if you have a concern about how we process your personal data.

Where the GDPR applies, you also have the right to lodge a complaint with an applicable data-protection supervisory authority.

Because LK Technology Frontier Ltd is established in Cyprus, you may contact the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus.

You may also have the right to complain to another competent supervisory authority, including an authority in the EU/EEA country of your habitual residence, place of work or the place of the alleged infringement.

We may need to verify your identity before fulfilling a privacy request, particularly where disclosure or deletion of account information is requested.


17. United Kingdom

Where the UK GDPR and Data Protection Act 2018 apply, individuals in the United Kingdom have the rights provided by applicable UK data-protection law.

You may exercise applicable privacy rights or raise a data-protection complaint directly with us by contacting:

Email: info@ctolarsson.com

We will handle applicable privacy requests and complaints in accordance with UK data-protection law.

You may also have the right to complain to the UK Information Commissioner's Office (ICO).


18. Switzerland

Where the Swiss Federal Act on Data Protection applies, individuals in Switzerland have the rights provided by that Act, including applicable rights to information about processing, access to personal data and correction or deletion of personal data where the legal conditions are met.

Information concerning international transfers is provided in the section above.

Individuals may also contact the Swiss Federal Data Protection and Information Commissioner (FDPIC) in accordance with applicable Swiss law.


19. Australia

Where the Australian Privacy Act 1988 and Australian Privacy Principles apply, we manage personal information in accordance with the applicable requirements of those laws.

Australian individuals may contact us to:

  • request access to personal information we hold about them;
  • request correction of inaccurate information; or
  • make a complaint concerning our handling of their personal information.

We will investigate applicable privacy complaints and respond in accordance with Australian law.

If a matter cannot be resolved with us, you may be entitled to complain to the Office of the Australian Information Commissioner (OAIC).

Our principal overseas recipient and processing locations relevant to Australian personal information include Cyprus and other EU/EEA countries, the United Kingdom and the United States, with other locations possible where international cloud or authorised service providers operate.


20. Canada

Where Canadian private-sector privacy law applies, including PIPEDA or applicable provincial privacy legislation, we process personal information in accordance with the requirements applicable to the relevant activity.

Canadian individuals may have rights to:

  • request information about the personal information we hold;
  • obtain access to applicable personal information;
  • challenge its accuracy and request correction; and
  • raise a complaint about our privacy practices.

Where consent is the applicable basis under Canadian law, consent may be withdrawn subject to applicable legal or contractual restrictions and reasonable notice.

You may also be entitled to complain to the Office of the Privacy Commissioner of Canada or an applicable provincial privacy regulator.


21. United States

Privacy rights in the United States vary by state.

Where an applicable US state privacy law gives you rights concerning personal information we process, we will provide and honour those rights as required by that law. Depending on the jurisdiction, these may include rights to request access, correction or deletion of certain personal information and rights concerning sale, sharing, targeted advertising or certain forms of profiling.

As explained above, we do not sell customer contact lists to projects or other third parties for their independent marketing.

Certain advertising technologies may nevertheless fall within specialised statutory definitions of "sharing", "sale" or "targeted advertising" under some US state privacy laws.

Where applicable law requires it, eligible users can exercise the relevant advertising opt-out rights through our cookie/privacy controls or another method we make available, and we will recognise legally required opt-out preference signals where applicable.


22. Other jurisdictions

Customers may live in other countries that provide additional mandatory privacy rights.

Nothing in this Privacy Policy is intended to exclude or restrict a privacy or data-protection right that cannot lawfully be excluded.

Where applicable local law provides additional mandatory rights, we will process applicable requests in accordance with that law.


23. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our Services, technology, service providers, business practices or legal requirements.

The current version and its last-updated date will be published on our website.

Where applicable law requires additional notice or consent for a material change in processing, we will provide it.


24. Contact

For questions about this Privacy Policy, our processing of personal data, a privacy-rights request or a privacy complaint, contact:

LK Technology Frontier Ltd
Makariou III, 34
Hadjiyianni Bldg, Office 203
Limassol 3065
Cyprus
Email: info@ctolarsson.com
Telephone: +44 20 39968761