| Anonymization | The process of altering personal data so that it can no longer be associated with an identified or identifiable individual. |
| Company | Means Lucy Bridge PLC, a legal entity incorporated under Ethiopian law, duly licensed to operate in Ethiopia |
| Consent | Any freely given, specific, informed, and unambiguous indication by which a data subject signifies agreement to the processing of their personal data. |
| Data Breach | A confirmed or suspected incident leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed. |
| Data Controller | A person or entity that determines the purposes and means of processing personal data. For the purposes of this Policy. |
| Data Processor | A person or entity that processes personal data on behalf of the Data Controller under a contractual or legal obligation. |
| Data Protection Officer | The individual appointed by the Company to oversee compliance with data protection laws and this Policy. |
| Data Retention | The period during which personal data is stored by the Company in active or archived systems before being securely disposed of in accordance with legal and regulatory requirements. |
| Data Subject | Any natural person whose personal data is collected, held, or processed by the Company or its agents. |
| Encryption | A technical measure that converts data into a coded format to prevent unauthorized access or disclosure. |
| Personal Data | Any information relating to an identified or identifiable natural person ("data subject"); an identifiable person is one who can be identified directly or indirectly by reference to identifiers such as a name, identification number, location data, online identifier, or factors specific to physical, physiological, mental, economic, cultural, or social identity. |
| Proclamation | The Personal Data Protection Proclamation No. 1321/2024 |
| Processing | Any operation or set of operations performed on personal data, including collection, recording, organization, storage, adaptation, alteration, retrieval, consultation, use, disclosure, transmission, dissemination, alignment, combination, restriction, erasure, or destruction. |
| Third Party Recipient | Any entity or person, other than the data subject, the Data Controller, or the Data Processor, to whom personal data is disclosed or made available. |
| Sensitive Personal Data | Personal data revealing racial or ethnic origin, political opinion, religious or philosophical beliefs, trade union membership, health or biometric data, sexual orientation, or other data that require enhanced protection under the Proclamation. |