News: Lightbringer raises $10 million in Series A funding

Privacy policy

Last updated: 2026-09-15

In brief

What this policy means for you

  • Lightbringer AB, based in Malmö, Sweden, runs the platform and is responsible for your account, usage and MCP connection data. This policy explains how we handle it.
  • Anything your team uploads to the platform stays under your organisation's control. Your organisation is the controller, and we process it only on its instructions under our Data Processing Addendum.
  • Personal data is kept in the EU/EEA by default. Where a sub-processor sits outside the EU/EEA, we rely on an adequacy decision or Standard Contractual Clauses.
  • We never train or fine-tune AI models on your content, and our agreements stop our AI providers from doing so either.
  • You can access, correct, delete or object to our use of your personal data at any time. Email privacy@lightbringer.com and we will respond within one month.

Last updated: . The full policy below is the authoritative version.

1. Who we are and what this policy covers

Lightbringer AB ("Lightbringer", "we", "us", "our") is a company registered in Sweden, company registration number 559426-2213, with its registered office at Jagaregatan 4, 211 19 Malmö, Sweden.

We provide an AI-native patent platform and related professional services.

This policy explains what personal data we handle, why, on what legal basis, who we share it with, how long we keep it, and what rights you have. It applies to:

  • our websites at lightbringer.com and app.lightbringer.com;
  • the Lightbringer platform and services (the "Service");
  • the Lightbringer MCP connector;
  • our professional patent services; and
  • our communications with customers, prospects, and visitors.

It does not cover personal data we process about our own employees, contractors, and job applicants.

2. Which data we control, and which we handle for you

Our role differs by data category:

We act asForWhat that means
ProcessorCustomer Content – anything your team submits to the Service, including any personal data it containsYour organisation is the controller. We process it on their documented instructions under our Data Processing Addendum.
ControllerAccount Data, Usage Data, and MCP connection data – everything in §3 other than Customer ContentWe decide why and how this is processed, and this policy governs it.
ControllerInventor and applicant details submitted to patent offices as part of a filingWe act as controller (alongside your organisation) in respect of our own professional and regulatory obligations as a patent services provider. See §6.

Where we are a processor, the DPA takes precedence over this policy if the two conflict.

3. Personal data we collect

3.1 Account and identity data

Name, work email address, organisation name, job role, organisation role assignment, authentication identifiers, and login records. Collected from you at sign-up, from your organisation's administrator, or via Google or Microsoft SSO if you sign in that way.

3.2 Customer Content

Invention disclosures, technical descriptions, design documents, drawings, meeting notes, attorney comments and redlines, filing records, and anything else you or your colleagues submit to the Service. This frequently contains personal data – inventor names, contributor names, email addresses in pasted correspondence.

3.3 Usage and technical data

Features used, session duration and frequency, actions taken in the platform, device and browser type, IP address, approximate location derived from IP, error and diagnostic data, and security event logs.

3.4 Communications and support data

Emails, support tickets, chat messages, demo and webinar registrations, and notes from calls with our team. Support phone conversations are not recorded or stored.

3.5 Billing and transaction data

Billing contact details, organisation billing address, VAT or tax identifiers, invoices, subscription records, and payment status. Card details are handled directly by our payment provider and are never stored on Lightbringer systems.

3.6 MCP connection data

Where your organisation enables the Lightbringer MCP connector: the OAuth authorisation record, which organisation the connection is scoped to, the identity of the connecting user, and logs of the tool calls made through the connection. See §7 for how this works and what leaves our control.

3.7 Website and marketing data

Pages visited, referral source, campaign identifiers, form submissions, and cookie and similar-technology data. See §13.

3.8 Special category data

We do not ask for special category personal data (health, biometric, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation), and the Service is not designed for it. Please do not submit it as part of Customer Content. Where it nonetheless appears in material you submit, we process it only as part of Customer Content on your organisation's instructions, and your organisation is responsible for having an Art. 9 condition for it.

Most of this data comes from you or your organisation. Where personal data about you reaches us from a colleague or your organisation's administrator rather than from you directly, this policy is how we tell you about it.

4. Why we process personal data, and our legal basis

Our lawful bases under Art. 6 GDPR and the equivalent UK GDPR provisions:

PurposeCategories usedLegal basis
Creating and administering your account; authenticating you3.1Contract – Art. 6(1)(b). Where the contract is with your employer rather than you personally, our legitimate interest in administering that contract – Art. 6(1)(f)
Providing the Service: capturing disclosures, generating drafts, routing work to attorneys, managing filings3.1, 3.2Contract – Art. 6(1)(b) for account users. For personal data inside Customer Content, we act as processor on your organisation's instructions; your organisation determines the basis
Preparing and submitting patent applications; corresponding with patent offices; renewals3.1, 3.2, 3.5Contract – Art. 6(1)(b), and legal obligation – Art. 6(1)(c) where patent law requires inventor identification. See §6
Billing, invoicing, collections3.1, 3.5Contract – Art. 6(1)(b)
Keeping statutory accounting records3.5Legal obligation – Art. 6(1)(c) (Swedish Bookkeeping Act, bokföringslagen 1999:1078)
Service, security, and technical notifications3.1Contract – Art. 6(1)(b)
Customer support3.1, 3.4Contract – Art. 6(1)(b)
Maintaining, debugging, and improving the Service; capacity and performance management3.3Legitimate interests – Art. 6(1)(f): running a reliable, functional product
Security monitoring, access logging, fraud and abuse detection, incident investigation3.1, 3.3, 3.6Legitimate interests – Art. 6(1)(f): protecting the Service, our customers, and highly confidential pre-filing invention data
Product analytics and aggregate usage reporting3.3, 3.7Consent where delivered via non-essential cookies or similar technologies – Art. 6(1)(a). Otherwise legitimate interests – Art. 6(1)(f)
Marketing emails to existing customers about closely related services3.1, 3.7Legitimate interests – Art. 6(1)(f), subject to an unsubscribe link in every message
Marketing to prospects; webinars and events; newsletter3.7Consent – Art. 6(1)(a)
Non-essential cookies and similar technologies3.7Consent – Art. 6(1)(a), and Ch. 9 §28 of the Swedish Electronic Communications Act (lag 2022:482 om elektronisk kommunikation)
Responding to data subject rights requests; maintaining compliance records3.1, 3.4Legal obligation – Art. 6(1)(c)
Responding to valid legal demands, court orders, and regulatory requestsanyLegal obligation – Art. 6(1)(c), or legitimate interests – Art. 6(1)(f) where the demand is from a jurisdiction whose law does not directly bind us
Establishing, exercising, or defending legal claimsanyLegitimate interests – Art. 6(1)(f)
Corporate transactions (merger, acquisition, financing, sale of assets)3.1, 3.5Legitimate interests – Art. 6(1)(f)

Where we rely on legitimate interests, we have assessed our interest against your rights and freedoms. You can request a summary of the relevant assessment, and you have the right to object – see §12.

5. AI processing of Customer Content

We use pre-trained third-party AI models to generate drafts and analyses in the Service. We do not train or fine-tune any model on Customer Content, and our agreements prohibit our AI providers from using inputs or outputs to train or improve their models.

AI processing of Customer Content takes place on infrastructure located in the EU. Retention terms vary by provider: some retain no Customer Content once a request completes, while others retain it briefly for security and abuse-prevention purposes. In each case, retention is limited to what the provider's terms permit, and no provider may use Customer Content to train or improve their models. Current providers and processing locations are listed at https://lightbringer.com/about/legal/subprocessor-list.

The Service does not make decisions producing legal or similarly significant effects based solely on automated processing (Article 22 GDPR). Outputs are drafts for review by a qualified person.

6. Patent filings make some personal data public

Filing a patent application makes personal data public. Published applications ordinarily include inventor names, and in many jurisdictions the applicant's address and the representative's details, which then sit permanently in public patent registers.

This cannot be undone. A deletion request will not remove your name from a published application, and in most cases neither can the patent offices. Identifying inventors is a statutory requirement, so this processing rests on Art. 6(1)(c) and, for the filing service itself, Art. 6(1)(b).

If you have a concern about publication of your name or address, raise it with your Lightbringer contact before filing.

7. The Lightbringer MCP connector and third-party AI assistants

Lightbringer offers an MCP (Model Context Protocol) connector that lets AI assistants such as Claude, ChatGPT, and Cursor work with your Lightbringer data in a chat session. An administrator at your organisation must enable MCP access before anyone can connect. Users then authenticate over OAuth, and access is scoped to the single organisation they select. It can be revoked at any time by the administrator or by disconnecting in the client. Within that scope, an assistant has read and write access to invention disclosures, attorney reviews, comments, and related patent-workflow documents.

Once an assistant reads your data through the connector, that copy sits with the assistant's provider, and your own account and agreement with that provider govern how it is handled, including retention and whether it is used to train their models. We have no control over this and no visibility into it. The safeguards we impose on our own AI providers, described in §5, do not extend to an assistant you connect yourself, and depending on the provider and your plan the data may be processed outside the EU/EEA. Your organisation is the controller of the decision to connect an assistant and of what flows into it.

Before connecting sensitive, pre-filing invention details, we recommend checking your AI provider's data controls. Enterprise and zero-retention tiers usually give materially better guarantees than consumer plans.

We log MCP authorisation events and tool calls for security and audit purposes, on the basis of our legitimate interest in protecting the Service.

8. Who we share personal data with

We do not sell or rent personal data, and we share it only as described here:

  • Sub-processors – hosting, infrastructure, analytics, authentication, communications, payments, and patent-specific tooling. The current list, with each provider's purpose and location, is at https://lightbringer.com/about/legal/subprocessor-list.
  • Patent offices and IP authorities – the EPO, national and regional offices, the USPTO, WIPO, and their agents, as required to prosecute your filings. See §6.
  • Foreign associates and local counsel – local patent attorneys instructed where a filing requires representation in a jurisdiction we do not cover directly.
  • Professional advisers – auditors, insurers, accountants, and legal advisers.
  • Acquirers – in connection with a merger, acquisition, financing, reorganisation, or sale of assets, subject to confidentiality protections and the continued application of this policy.

Every recipient is bound by confidentiality, and every sub-processor by a written agreement imposing data protection obligations comparable to our own. Our vetting, attestation, and audit commitments, along with the notice period and objection rights that apply when we add a new sub-processor, are set out in the Data Processing Addendum.

We disclose personal data to authorities only where required by valid legal demand. We assess every demand, do not process ones that are overly broad or vague, and disclose only what is specifically demanded. We notify affected customers unless legally prohibited from doing so, and we do not voluntarily disclose personal data to law enforcement or government agencies. Our handling of government access requests relating to transferred data is set out in the DPA.

9. Where your data is stored and processed

Our default is to keep personal data within the EU/EEA. Core application data and backups are hosted within the EU, and AI processing runs through providers operating under EU data residency. Our sub-processor list names each provider and its location.

Some of our sub-processors are nonetheless located in, or may access data from, countries outside the EU/EEA. As of the date of this policy that includes the United Kingdom and the United States; the sub-processor list gives the current position. Where data leaves the EU/EEA, one of the following applies:

  • An adequacy decision. The European Commission renewed its adequacy decisions for the United Kingdom on 19 December 2025, running until 27 December 2031 unless extended. Transfers to the UK proceed on that basis.
  • Standard Contractual Clauses. Where no adequacy decision applies, we rely on the Commission's SCCs (Decision 2021/914), supported where appropriate by a Transfer Impact Assessment and supplementary technical measures including encryption in transit and at rest.

Onward transfers from the UK use the SCCs as amended by the UK International Data Transfer Addendum, and Swiss transfers use the SCCs with the modifications set out in our DPA.

10. Our people, and where they work from

Some of our personnel work from the United Kingdom and the United States. Where they access personal data held on our EU infrastructure, that access is an international transfer under Chapter V GDPR even though the data itself does not move. For UK-based personnel, the UK adequacy decision covers this. For US-based personnel, we rely on the transfer safeguards described in §9, together with least-privilege role-based access, mandatory security and data privacy training, confidentiality undertakings, and logging of access to Confidential data.

11. How long we keep personal data

We keep personal data only as long as necessary for the purpose it was collected for. In practice the period is set by how long you remain a customer, how long the data is needed to run and secure the Service, and any statutory minimum. Customer Content is deleted within 60 days of contract termination. Accounting records are kept for seven years under the Swedish Bookkeeping Act. Specific periods for other categories are available on request.

12. Your rights

Under the GDPR and UK GDPR you have the right to:

  • Access – obtain a copy of the personal data we hold about you and information about how we process it (Art. 15);
  • Rectification – have inaccurate data corrected and incomplete data completed (Art. 16);
  • Erasure – have your data deleted where one of the grounds in Art. 17 applies;
  • Restriction – have processing limited in the circumstances set out in Art. 18;
  • Portability – receive data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible (Art. 20);
  • Object – object to processing based on our legitimate interests, including profiling (Art. 21), and object to direct marketing at any time, which we will always honour;
  • Withdraw consent – where processing is based on consent, withdraw it at any time, without affecting the lawfulness of processing before withdrawal (Art. 7(3));
  • Not be subject to solely automated decisions producing legal or similarly significant effects (Art. 22) – see §5;
  • Complain to a supervisory authority – see §18.

To exercise any of these, email privacy@lightbringer.com stating which right you wish to exercise. We will ask you to verify your identity, usually by confirming control of the email address on the account; if an agent submits a request for you, they must identify you. We respond within one month of receipt, and where a request is complex or you have made several we may extend by up to two further months, telling you within the first month if we do. Requests are free, though for manifestly unfounded or excessive requests, or additional copies of the same data, we may charge a reasonable administrative fee or decline (Art. 12(5) and Art. 15(3)).

If your personal data is in Customer Content, your organisation is the controller. We will normally refer your request to them and assist them in responding, and we will tell you when we do. We may also be unable to comply in full where data is subject to professional privilege, a legal hold, or a statutory retention obligation, or where it has already been published by a patent office and is outside our control (see §6). We will explain the reason in each case.

13. Cookies and similar technologies

We use cookies and similar technologies on our websites in four categories: strictly necessary cookies that support login, session state, and security; performance cookies that show us how the site is used; targeting cookies used to measure and deliver advertising; and functionality cookies that remember your preferences.

Only strictly necessary cookies are set without your consent. The others are set only if you enable them through our cookie banner, which presents each category switched off by default. The cookie declaration, reachable through Cookie settings, lists every cookie in each category, its purpose, and its duration, including those set by third parties. Declining non-essential cookies does not affect your access to the Service.

You can change or withdraw your consent at any time using the Cookie settings button in the bottom-left corner of any page.

14. How we protect personal data

A summary – full detail is on our Data Security page.

  • Certifications. SOC 2 Type II (Security, Availability, Confidentiality).
  • Encryption. TLS 1.2–1.3 in transit, AES-256 at rest, including backups.
  • Access control. Least-privilege internal access, with company devices encrypted and access to Confidential data logged. Sign-in via Okta, Google SSO, or Microsoft SSO. Role-based access within your organisation, controlled by you.
  • Testing. Independent penetration testing annually, with continuous vulnerability scanning.
  • People. Confidentiality agreements for all personnel and contractors. Mandatory security and data privacy training at hire and annually.
  • Resilience. Customer data backed up every 12 hours and retained a minimum of 7 days, so access to personal data can be restored after an incident (Art. 32(1)(c)).

We build data protection safeguards into systems from the design stage and configure them so that by default only the personal data necessary for each purpose is processed (Art. 25). Where processing is likely to result in a high risk to individuals, we carry out a Data Protection Impact Assessment (Art. 35).

15. Data breaches

If a personal data breach occurs, we follow our documented Incident Response Plan and record the breach, its effects, and the action taken.

  • Where we are the controller, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach that poses a risk to individuals. Where the risk is high, we also tell the affected individuals directly, in clear and plain language.
  • Where we are the processor, we notify the affected customer without undue delay, within the timeframe set out in our Data Processing Addendum, with the information they need to meet their own notification obligations.
16. Children

The Service is a business tool intended for use by organisations and their personnel. It is not directed at children, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@lightbringer.com and we will delete it.

17. Changes to this policy

We review this policy at least annually and update it when our processing changes. When we do, we update the "last updated" date and post the revised policy here. Where a change materially affects how we process your personal data, we will notify affected customers and users directly, by email or in-product notice, before it takes effect, and where a change requires your consent we will ask for it. Previous versions are available on request.

18. Contact us

Use the address privacy@lightbringer.com for privacy enquiries, complaints, and data subject requests. It also reaches our Data Protection Officer, who you can contact directly by marking your message for their attention.

Our lead supervisory authority is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), Box 8114, 104 20 Stockholm, imy@imy.se, +46 8 657 61 00.

You have the right to lodge a complaint with IMY, or with the supervisory authority in your country of residence or place of work. In the UK, that is the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to address your concern first.