Possessions · LIGHT AND DARK ENERGY LTD
Privacy Policy
LIGHT AND DARK ENERGY LTD is the controller for account, security, billing and service-operation information processed through Possessions. Company number 15095270; registered office 71–75 Shelton Street, Covent Garden, London WC2H 9JQ. Privacy contact: contact@lightanddarkenergy.uk.
Information we process
- Quantum ID, cryptographic verifiers and encrypted key envelopes;
- session, device/browser, IP-derived security and event information;
- after optional analytics consent: public page path without its query string, referring channel, limited funnel events and ordinary browser, device and network information;
- asset names, types, vehicle details, values and valuation source, addresses, cities, countries, display coordinates and operational notes;
- obligations, cash flow, occupancy and imported calendar information;
- encrypted Private Vault payloads, encrypted attachment names and encrypted attachment contents, plus readable file size and upload time;
- anonymous feedback messages, page context and diagnostic references you choose to send;
- billing identifiers and subscription status from Stripe; Stripe/Link separately processes payment, billing, tax and transaction-support details.
Purposes and lawful bases
We process information to perform the service contract, authenticate access, calculate portfolio views, provide billing and support, and protect the service. Security, abuse prevention and limited service improvement rely on our legitimate interests. Legal records are retained to comply with legal obligations and establish or defend claims.
What you must provide
A Quantum ID and cryptographic account material are necessary to create and secure a vault. Information about possessions is optional, but the corresponding feature cannot work without the fields you choose to enter. A permanent billing address in an open sales territory and Stripe/Link billing information are required to purchase. We do not use solely automated decisions that produce legal or similarly significant effects.
Encryption is not anonymity
Quantum IDs reduce direct identification, but account, billing, network and asset information may still be personal data. Encrypted information remains within data-protection law. Private Vault encryption limits our ability to read protected content but does not make the complete account anonymous.
Recipients
DigitalOcean hosts the production service for us in its London region and acts as our infrastructure processor. DigitalOcean uses disclosed subprocessors, including AWS for backup and infrastructure support, Cloudflare for platform security and Traversal for troubleshooting and support. We operate a self-hosted Matomo instance at matomo.possessionsglobal.com for optional analytics on public pages; it is not loaded inside the authenticated private vault. For paid memberships, Stripe’s Link service acts as merchant of record and separately processes billing, tax, fraud, dispute and transaction-support information under the notices shown at checkout. Mapping tiles are requested from OpenStreetMap infrastructure when the map loads. A location search sends the city, street or address query you enter to OpenStreetMap’s Nominatim service. Airbnb receives a request for a private calendar URL only when you initiate an import. We may disclose information where legally required or necessary to protect rights and security.
International transfers
The production Droplet is located in London, United Kingdom. DigitalOcean and some subprocessors may perform support, security or backup processing in the United States. Where required, DigitalOcean’s DPA provides the UK Addendum, Standard Contractual Clauses and Data Privacy Framework mechanisms. Other suppliers apply their own transfer safeguards as described in their notices.
Retention
Unactivated drafts expire after 48 hours. Expired session records are removed after 30 days, security events after 12 months, and optional public-page analytics, product events and feedback after 24 months. Active vault data remains while the account exists. Deleting a vault removes its active account and linked content from the production database; encrypted disaster-recovery backups expire after a maximum 35-day operational cycle. Legal acceptance and billing records may be retained separately for up to six years where reasonably required for legal claims, fraud prevention or accounting.
Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, objection or portability. You may object specifically to processing based on legitimate interests. Because we do not require an email and cannot read protected content, we must verify requests through an authenticated vault or other proportionate evidence. Contact us at the address above; we normally respond within one month. You may complain to the UK Information Commissioner’s Office at ico.org.uk.
Children and changes
Possessions is not intended for anyone under 18. Material privacy changes will be presented before they take effect where required.
Professional customer content
When a business, family office or professional customer enters personal data about another person, that customer normally determines why the information is used and is the controller for that content. LIGHT AND DARK ENERGY LTD acts as processor to provide the service, subject to the Data Processing Addendum. We remain controller for our own account, security, billing, fraud-prevention and legal-compliance processing.