Privacy Policy

Effective Date: July 2, 2026

This Privacy Policy describes how BIG Light Luxembourg (“we,” “us,” or “our”) collects, uses, discloses, and protects your personal information when you visit and use our e-commerce website www.biglightlu.com (the “Site”) and buy products from our online store.

We operate from our registered address at 74 Route de Longwy, L-8080 Bertrange, Luxembourg. We serve as the data controller for the processing of your personal data under the European Union General Data Protection Regulation (GDPR). We respect your privacy and commit to safeguarding your personal information through compliance with this policy.


1. Information We Collect

We collect several types of information from and about users of our Site, including:

Information You Provide to Us

  • Identity Data: First name, last name, title, date of birth, and gender.
  • Contact Data: Billing address, delivery address, email address (such as your interaction with our team), and telephone number (+352450483 when you contact us).
  • Financial Data: Bank account and payment card details handled securely by our third-party payment processors.
  • Transaction Data: Details about payments to and from you and other details of products you have purchased from us.
  • Profile Data: Your username, password, purchases or orders made by you, your interests, preferences, feedback, and survey responses.
  • Communications Data: Your preferences in receiving marketing from us and our third parties and your communication preferences.

Information We Collect Automatically

  • Technical Data: Internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this Site.
  • Usage Data: Information about how you use our website, products, and services, including the pages you view, the links you click, and the time spent on our store.

2. How We Use Your Information

We use your personal data only when the law allows us to. Most commonly, we use your data in the following circumstances:

Performance of a Contract

  • To register you as a new customer.
  • To process and deliver your order, including managing payments, fees, and charges.
  • To collect and recover money owed to us.
  • To notify you about changes to our terms or privacy policy.

Legitimate Interests

  • To manage our relationship with you, including asking you to leave a review or take a survey.
  • To administer and protect our business and this Site, including troubleshooting, data analysis, testing, system maintenance, support, reporting, and hosting of data.
  • To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you.
  • To use data analytics to improve our website, products, marketing, customer relationships, and experiences.

Consent

  • To provide you with information, products, or services that you request from us or which we feel may interest you, where you have consented to be contacted for such purposes.

3. Legal Basis for Processing (GDPR Compliance)

If you reside in the European Economic Area (EEA), our legal basis for collecting and using the personal information described above depends on the personal information concerned and the specific context in which we collect it.

  • Consent: You have given clear consent for us to process your personal data for a specific purpose (e.g., subscribing to our newsletter).
  • Contract: The processing is necessary for a contract we have with you, or because you have asked us to take specific steps before entering into a contract (e.g., fulfilling an online order).
  • Legal Obligation: The processing is necessary for us to comply with the law (not including contractual obligations), such as tax laws or financial accounting rules.
  • Legitimate Interests: The processing is necessary for our legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect your personal data which overrides those legitimate interests.

4. How We Share Your Information

We do not sell, rent, or trade your personal information to third parties. We share your personal data only with trusted third parties who assist us in operating our online store, conducting our business, or servicing you.

  • Service Providers: We share data with third parties providing IT and system administration services, cloud storage, order fulfillment, shipping carriers (to deliver your products), and marketing agencies.
  • Payment Processors: We use secure third-party payment gateways to handle credit card and financial transactions. We do not store your full payment card details on our servers.
  • Professional Advisers: We may share data with lawyers, bankers, auditors, and insurers who provide consultancy, banking, legal, insurance, and accounting services.
  • Legal Requirements: We may disclose your information if required to do so by law, court order, or government authority, or if we believe that disclosure is necessary to protect our rights or the safety of our customers and the public.

5. Data Security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorized way, altered, or disclosed.

In addition, we limit access to your personal data to those employees, agents, contractors, and other third parties who have a business need to know. They will only process your personal data on our instructions, and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.


6. International Data Transfers

Our business operates within Luxembourg, and your data is primary stored within the European Union. However, some of our third-party service providers may be located outside the European Economic Area (EEA). Whenever we transfer your personal data out of the EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:

  • We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission.
  • Where we use certain service providers, we may use specific contracts approved by the European Commission (Standard Contractual Clauses) which give personal data the same protection it has in Europe.

7. Data Retention

We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data, and whether we can achieve those purposes through other means, as well as applicable legal requirements.

By law, we must keep basic information about our customers (including Contact, Identity, Financial, and Transaction Data) for ten years after they cease being customers for tax and legal purposes in Luxembourg.


8. Your Legal Rights (Under GDPR)

Under certain circumstances, you have rights under data protection laws in relation to your personal data. You have the right to:

  • Request access to your personal data. This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
  • Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected.
  • Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it.
  • Object to processing of your personal data where we are relying on a legitimate interest and there is something about your particular situation which makes you want to object to processing on this ground.
  • Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in certain scenarios.
  • Request the transfer of your personal data to you or to a third party (data portability).
  • Withdraw consent at any time where we are relying on consent to process your personal data.

If you wish to exercise any of the rights set out above, please contact us directly via email at driftw@biglightlu.com.


9. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to distinguish you from other users of our website. This helps us to provide you with a good experience when you browse our website and also allows us to improve our online store.

You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this Site may become inaccessible or not function properly. For detailed information on the cookies we use and the purposes for which we use them, please see our separate Cookie Policy on our platform.


10. Third-Party Links

This Site may include links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.


11. Children’s Privacy

Our website and online store are not intended for children under the age of 16. We do not knowingly collect personal information from children under 16. If you are under 16, do not use or provide any information on this Site or make any purchases through the store. If we learn we have collected or received personal information from a child under 16 without verification of parental consent, we will delete that information immediately.


12. Changes to This Privacy Policy

We keep our privacy policy under regular review. We reserve the right to update this policy at any time. Any changes we make to our privacy policy in the future will be posted on this page and, where appropriate, notified to you by email. Please check back frequently to see any updates or changes to our privacy policy.


13. Contact Information

If you have any questions about this Privacy Policy, including any requests to exercise your legal rights, please contact us using the details set out below:

  • Company Name: BIG Light Luxembourg
  • Website: www.biglightlu.com
  • Postal Address: 74 Route de Longwy, L-8080 Bertrange, Luxembourg
  • Contact Email: driftw@biglightlu.com
  • Telephone Number: +352450483

You also have the right to make a complaint at any time to the National Commission for Data Protection (CNPD), the Luxembourg supervisory authority for data protection issues (www.cnpd.lu). We would, however, appreciate the chance to deal with your concerns before you approach the CNPD, so please contact us in the first instance.