IMAGINE
session--:--:--
Imagine Privacy

Privacy Policy

This policy explains how Imagine Tech Limited handles personal data on the corporate site and related brand surfaces. It is written to work as a practical transparency notice across Europe, the United States, and key Latin American regimes, while allowing product-specific notices such as Lucid to add more detail where needed.

This Privacy Policy covers the corporate site, portfolio brand presentation flows, contact channels, and related web surfaces controlled by Imagine Tech Limited. Product-specific services, including Lucid wallet flows, may also publish supplemental notices that apply in parallel to the relevant product experience.
Live legal baseline16 sectionsRights routing activeDocs-ready presentation
Last updated May 31, 2026
01
Document section

1. Controller, scope, and product relationship

Imagine Tech Limited is the controller for personal data processed through the corporate site and associated contact, lead, brand, media, and informational surfaces described in this notice.

Where you move into a product-specific service, beta, brand-operated application, commerce flow, or Lucid wallet surface, a supplemental notice or product-specific privacy layer may also apply.

02
Document section

2. Categories of personal data we may process

  • Identity and contact details, such as name, email address, company name, phone number, and the content of messages you send us.
  • Commercial or relationship information, such as requests for demos, partnerships, support, press materials, or brand engagement.
  • Technical and device data, such as IP address, browser type, operating system, approximate region, timestamps, crash information, and security telemetry.
  • Site interaction data, such as page visits, navigation paths, referral information, and feature usage where measurement is enabled.
  • Cookie, local storage, and session data necessary for consent handling, authentication, cart functionality, accessibility preferences, or other selected features.
03
Document section

3. Sources of personal data

  • Directly from you, such as when you submit forms, send emails, create an account, request support, ask for a partnership discussion, or otherwise contact us.
  • Automatically from your browser, device, or session when you access the site, including security, consent, accessibility, and performance-related data.
  • From service providers or workflow tools acting on our behalf, such as email-delivery, hosting, security, or customer-support vendors.
  • From child brands, partners, affiliates, or referral sources where you ask to be introduced, routed, or onboarded through a shared business process.
  • From publicly available sources or business-professional sources where reasonably necessary to evaluate an inbound request, partnership, press inquiry, or fraud risk.
05
Document section

5. Data minimization, purpose limitation, sensitive data, and children

We aim to collect only the data reasonably necessary for the purposes disclosed in this notice. We do not intentionally collect special-category or sensitive personal data through the corporate site unless it is strictly necessary for a lawful, clearly disclosed purpose and handled with additional safeguards.

If a form or workflow unexpectedly asks for sensitive data that is not necessary, you should avoid providing it until we have given you an appropriate legal notice for that use.

The corporate site is not directed to children under 13 and is not intended to be a child-directed service. If we learn that personal data was collected from a child in a way that is inconsistent with applicable law, we will take reasonable steps to delete, restrict, or remediate the data and the relevant workflow.

06
Document section

6. Cookies, local storage, and similar technologies

We use strictly necessary technologies to keep the site functioning, preserve security, remember essential settings, and maintain selected sessions. We may also use optional analytics or preference technologies only where the relevant law allows and, where required, only after obtaining valid consent.

You can review our Cookie Policy for category-level details, retention expectations, and preference choices. You can also change browser settings, use privacy tools, or revisit the live Cookie Preference Center made available on the site.

Where a supported browser sends a recognized Global Privacy Control or similar browser-based opt-out signal, we treat it as a restrictive browser-layer preference on the covered surfaces unless and until you make an explicit site-specific choice.

07
Document section

7. Sharing of personal data and processor governance

  • With hosting, infrastructure, email, support, security, analytics, and workflow vendors acting on our instructions under appropriate contractual protections.
  • Within Imagine Tech Limited and controlled group entities where reasonably necessary for brand, support, legal, or operational handling.
  • With child brands, partners, or affiliates only where you ask us to connect you, where the interaction clearly requires it, or where another lawful basis exists.
  • With regulators, courts, law enforcement, auditors, or advisers where required by law or reasonably necessary to protect rights, safety, or service integrity.
  • In connection with a restructuring, financing, acquisition, merger, or sale of assets, subject to lawful transfer safeguards.
  • For the covered repository surfaces, a current vendor and subprocessor register is published at /subprocessors to improve transparency around infrastructure and processor dependencies.
08
Document section

8. International transfers

Because our infrastructure, service providers, and collaborators may operate internationally, personal data may be processed outside your country. Where required, we aim to use appropriate safeguards such as contractual commitments, adequacy mechanisms, or comparable protections for cross-border transfers.

If you would like more information about the transfer safeguards relevant to your situation, contact us using the details in this notice.

09
Document section

9. Retention and deletion criteria

  • Inquiry and support communications: retained for as long as reasonably necessary to answer, follow up on, and document the request, plus any legally required period.
  • Security and fraud-prevention logs: retained for the period reasonably necessary to investigate misuse, maintain integrity, and meet legal obligations.
  • Consent and cookie preference records: retained for the period necessary to remember or evidence the choice, subject to the applicable storage period and legal requirements.
  • Account or order-related information, where relevant: retained for the relationship lifecycle and any accounting, legal, or dispute-related retention period that applies.
  • If a record is no longer needed for the disclosed purpose, is no longer required by law, and is not subject to a live security, dispute, or audit hold, we aim to delete, minimize, anonymize, or archive it in line with the applicable retention schedule.
10
Document section

10. Security, fraud prevention, and incident response

We use administrative, technical, and organizational safeguards designed to protect personal data, including encrypted transport, access controls, secure cookie settings where appropriate, environment-based secret handling, and operational security practices proportionate to the risk and scope of the relevant system.

We may also use logs, alerts, anomaly detection, abuse-prevention tools, and manual review to detect fraud, misuse, or threats to the site. These controls are used to protect users, the service, and the organization.

No service can be guaranteed to be immune from every incident. If a security event occurs, we will respond in line with our obligations and internal incident-handling procedures.

11
Document section

11. Automated decision-making and profiling

The corporate site is not designed to make solely automated decisions with legal or similarly significant effects about visitors. If that changes for a specific workflow, we will update the relevant notice and explain the logic and consequences where required by law.

12
Document section

12. Regional privacy rights

  • EEA, UK, and similar regimes: you may have rights to access, rectify, erase, restrict, object, port data, withdraw consent, and complain to a supervisory authority.
  • California residents: you may have rights to know categories, sources, purposes, disclosures, and specific pieces of personal information, request deletion or correction, opt out of sale or sharing, use an authorized agent, limit certain sensitive-personal-information uses where applicable, and receive non-discriminatory treatment.
  • Virginia, Colorado, and Connecticut residents: you may have rights to access, correct, delete, obtain a portable copy of personal data, opt out of targeted advertising, sale, or certain profiling, and appeal a denial under the rules of the relevant state.
  • Utah residents: you may have rights to confirm processing, access personal data, delete personal data you provided to us, obtain a portable copy of that data, and opt out of targeted advertising or sale where applicable. Utah does not follow the same correction-and-appeal model as every other state in this group.
  • Brazilian users: you may have rights to confirmation of processing, access, correction, anonymization, blocking, deletion, portability, information about public and private entities with which data is shared, consent withdrawal, and petition to the ANPD or consumer-protection bodies where applicable.
  • Argentine users: you may have rights to information, access, rectification, update, suppression, confidentiality, and habeas-data style recourse, including complaint routes to the AAIP.
  • Chilean users: current rights and the Law 21.719 reform track are treated as part of an implementation path. Before the reform effective date, any remaining Chile-specific deltas should be finalized before a market-specific launch relies on them.
  • Colombian users: you may have rights of consultation, update, rectification, deletion, revocation, and complaint handling before the SIC, generally after first using the controller-side request route.
  • Mexican users: you may have ARCO rights of access, rectification, cancellation, and opposition, as well as consent-revocation pathways and complaint routes before INAI where applicable.
  • Israeli users: you may have rights and protections under the Protection of Privacy Law, 5741-1981, related regulations, and any database-management or transfer rules that apply to the relevant system and use case.
13
Document section

13. Verification, authorized agents, appeals, and complaints

You can submit privacy, access, deletion, correction, export, opt-out, or objection requests through our Privacy Request Center or by email to privacy-requests@imagine-tech.org. We may need to verify your identity, authority, or relationship to the data before acting on a request, and we may request additional information where this is reasonably necessary to prevent unauthorized disclosure or deletion.

Where local law allows the use of an authorized agent or representative, we may require signed authority, proof of identity, or direct confirmation from the data subject before completing the request. If a request is denied, delayed, or limited, we will explain the decision to the extent required by law and preserve any appeal route that applies to the jurisdiction.

You may also complain to the relevant supervisory or regulatory authority where local law gives you that right, including an EEA or UK supervisory authority, the California Privacy Protection Agency or other relevant California authority, the applicable US state attorney general or consumer-protection authority, the ANPD in Brazil, the AAIP in Argentina, the SIC in Colombia, INAI in Mexico, or the relevant Israeli privacy or court forum as applicable.

14
Document section

14. No sale statement and targeted advertising position

We do not currently sell personal information as that term is commonly used in modern privacy statutes, and we do not intentionally activate cross-context behavioral advertising on these surfaces before meeting the required notice and consent standards.

If a future site surface uses a data practice that triggers sale, sharing, targeted advertising, or similar opt-out rights, we will publish an updated notice and provide the required control before activating that practice for the relevant users.

15
Document section

15. Changes to this notice

We may update this Privacy Policy to reflect legal, technical, product, or operational changes. The updated version will be published on the site together with a revised effective or revision date where appropriate.

Where required by law or where the change is material, we may also provide banner, account, or email notice using reasonable means.

16
Document section

16. Contact

Privacy and rights requests: privacy-requests@imagine-tech.org.

General support: support@imagine-tech.org. Legal notices: legal@imagine-tech.org. Mailing address: Unit 1-3, Irish Place, Irish Town, GX11 1AA, Gibraltar.

Need to exercise a privacy right?

Use the Privacy Request Center for access, deletion, correction, export, objection, opt-out, consent-withdrawal, or appeal requests tied to the Imagine corporate site.

Open Privacy Request Center

Need the law-by-law regulatory map?

The Regulatory Atlas expands this policy into a jurisdiction-by-jurisdiction view, and the Regulatory Annexes tie those laws back to the actual privacy, terms, and cookie documents that are live on the covered surfaces.

Regional deltas

Regional privacy supplements

These supplements summarize how the published privacy baseline is intended to map to specific regional laws. They complement the main policy, preserve mandatory local rights, and clarify response timing, complaint routes, verification expectations, and consent posture where those details matter to the user.

Regions
13
Active cards
3
Official sources
16
EEA, UK, and similar European regimes

GDPR

The privacy baseline is written to disclose controller identity, purposes, legal bases, recipients, transfers, retention, rights, and complaint paths in a GDPR-style format.

Interpretation note

Each card below is written as an operational supplement to the baseline document family, not as a standalone contract. It highlights where timing, appeal rights, complaint routes, or consent posture need to diverge by jurisdiction.

01
Regional supplement

Core rights

  • Access, rectification, erasure, restriction, objection, portability, and consent withdrawal routes are preserved where applicable.
  • A rights request can be submitted through the Privacy Request Center or by email to privacy-requests@imagine-tech.org.
  • We disclose transfer safeguards, retention categories, and complaint escalation expectations in the main notice.
  • Where verification is required, it should be proportionate to the request and should not collect more identity data than is reasonably necessary.
02
Regional supplement

Cookie and consent position

  • Non-essential cookies and trackers are intended to remain behind prior consent on covered surfaces.
  • Consent can be refused or withdrawn without losing access to strictly necessary functions.
  • A supported Global Privacy Control signal is treated as a restrictive browser-layer baseline on the covered repository surfaces until the user makes an explicit site-specific choice.
  • Where product-specific analytics or ad-tech changes the scope, the notice and controls should be refreshed before activation.
03
Regional supplement

Response timing

  • Requests are generally handled within one month.
  • Where complexity or volume justifies it, the period may be extended by up to two additional months with notice.
  • Users may also complain to a supervisory authority in their habitual residence, place of work, or place of the alleged infringement where the law provides that route.