Privacy Policy
Last updated: March 26, 2026
This Privacy Policy describes how Lygo collects, uses, and protects the personal data of users of the platform available at www.lygo.it and app.lygo.it.
1. Data Controller
The Data Controller is Lygo, with registered office at Via Placeholder 1, 00100 Rome (RM), Italy. For any privacy-related inquiries, you can contact us at privacy@lygo.it.
2. Data We Collect
Lygo collects the following categories of personal data:
- Account data: email address, display name, and cryptographic password hash (bcrypt). We never store passwords in plain text.
- Browsing data: visitor IP address, browser user-agent, referrer URL, and request timestamps at the time of redirect.
- Analytics data: click count per shortened link, visitor country of origin (detected at country level via IP geolocation, without individual identification), and temporal distribution of visits.
- Billing data: for paid plans, billing data is handled by the external payment provider; Lygo does not store credit card data.
3. Purposes of Processing
The collected data is processed for the following purposes:
- Service delivery: account creation and management, generation and resolution of shortened links, workspace and custom domain management.
- Aggregate analytics: providing click statistics, geographic distributions, and temporal trends related to your links.
- Security: prevention of abuse, unauthorized access, phishing, and fraudulent activity on the platform.
- Service communications: transactional notifications related to your account (e.g., password reset, import completion notifications).
4. Legal Basis for Processing
Data processing is based on the following legal grounds under Article 6 of Regulation (EU) 2016/679 (GDPR):
- Performance of a contract (Art. 6(1)(b)): for data necessary to provide the service following registration.
- Legitimate interest (Art. 6(1)(f)): for security purposes, fraud prevention, and anonymized aggregate analytics.
- Consent (Art. 6(1)(a)): for non-essential cookies, as described in the Cookie Policy.
5. Data Retention
Personal data is retained for the duration of the active account. Upon account deletion, data is removed within 30 days of the request, unless legal obligations require longer retention (e.g., tax records). System logs may be retained for up to 90 days for security purposes.
6. Sharing with Third Parties
Lygo does not sell, rent, or disclose users' personal data to third parties for commercial purposes. Data may be shared exclusively with the following sub-processors, in compliance with GDPR safeguards:
- Amazon Web Services (AWS): cloud infrastructure for service hosting, databases, and storage. Data is processed in the EU region (eu-south-1 / eu-west-1).
- Amazon CloudFront: content delivery network (CDN) used for application distribution and redirect handling.
All sub-processors are subject to GDPR-compliant Data Processing Agreements (DPAs).
7. Your Rights
As a data subject, you have the following rights under Articles 15-22 of the GDPR:
- Right of access (Art. 15): obtain confirmation of processing and a copy of your personal data.
- Right to rectification (Art. 16): request correction of inaccurate or incomplete data.
- Right to erasure (Art. 17): request deletion of your data ("right to be forgotten"), where applicable.
- Right to data portability (Art. 20): receive your data in a structured, machine-readable format.
- Right to object (Art. 21): object to processing based on legitimate interest.
- Right to restriction (Art. 18): request restriction of processing in certain cases.
To exercise your rights, send a request to privacy@lygo.it. We will respond within 30 days of receiving the request. You also have the right to lodge a complaint with the competent supervisory authority (in Italy: Garante per la Protezione dei Dati Personali, www.garanteprivacy.it).
8. Cookies
For detailed information about how Lygo uses cookies, please refer to the Cookie Policy.
9. Data Security
Lygo implements appropriate technical and organizational measures to protect personal data from unauthorized access, disclosure, alteration, or destruction. All communications between client and server are transmitted exclusively via HTTPS/TLS. Passwords are stored as bcrypt hashes with an appropriate salt.
10. Contact Information
For any questions regarding this Privacy Policy or to exercise your rights, contact us at:
- Email: privacy@lygo.it
- Mailing address: Lygo — Privacy, Via Placeholder 1, 00100 Rome (RM), Italy