Leximise legal

Privacy Policy

This policy explains how Leximise processes personal data when you visit our website, request a demo or use our services.

Last updated: 20 August 2026

1. Controller and contact details

The controller for website, account and commercial-contact data is Leximise SRL, Romania.

Privacy requests: [email protected]. Website: https://leximise.ai.

2. Scope and roles

For website visitors, prospects, account administrators and our direct business contacts, Leximise generally acts as controller. When a customer uses the platform to process employee, learner, auditor or other end-user data, the customer normally acts as controller and Leximise acts as processor under the applicable Data Processing Agreement.

3. Data we collect

  • Demo and contact data: name, company, work email, company size, country, interests and message.
  • Account data: identity, organisation, role, permissions, authentication and security events.
  • Service data: assessments, policies, evidence metadata, training assignments, progress, quiz results and certificates submitted or generated by authorised users.
  • Technical data: IP address, browser, device, timestamps, logs and security diagnostics.
  • Billing and contractual data, where relevant.
  • Communications and support requests.

4. Purposes and legal bases

  • Responding to enquiries and taking pre-contractual steps: contract or legitimate interests.
  • Providing, securing and administering the service: contract and legitimate interests.
  • Billing, accounting and legal compliance: contract and legal obligations.
  • Product improvement and service analytics: legitimate interests, or consent where required.
  • Marketing communications: consent or legitimate interests where permitted; you may opt out at any time.
  • Preventing fraud, abuse and security incidents: legitimate interests and legal obligations.

5. Recipients and service providers

We may share data with vetted hosting, database, email, support, analytics, payment and professional-service providers only where needed. We may also disclose data where required by law or in connection with a corporate transaction. We do not sell personal data.

A current sub-processor list should be made available to customers before production contracting.

6. International transfers

Where data is transferred outside the EEA, we use an adequacy decision, Standard Contractual Clauses or another lawful safeguard, together with supplementary measures where appropriate.

7. Retention

  • Demo and inactive prospect records: normally up to 24 months after the last meaningful interaction.
  • Customer account and service data: for the subscription term and the documented deletion period after termination.
  • Billing and legal records: for periods required by applicable law.
  • Security logs and backups: for limited periods based on security and recovery needs.

8. Security

We use risk-based technical and organisational measures, including access controls, authentication safeguards, encryption where appropriate, logging, backups, vulnerability management and role-based permissions. No online service can guarantee absolute security.

9. Your GDPR rights

  • Access, rectification and erasure.
  • Restriction, objection and data portability, where applicable.
  • Withdrawal of consent without affecting earlier lawful processing.
  • The right not to be subject to certain solely automated decisions.

Send requests to [email protected]. We may need to verify your identity. You may complain to the Romanian supervisory authority, ANSPDCP, or another competent EEA authority.

10. Automated processing and AI

Leximise may use AI-assisted features to generate drafts, recommendations, policies or training content. These outputs support authorised users and should be reviewed by a qualified person. We do not use website or customer-account data to make decisions producing legal or similarly significant effects about individuals unless expressly agreed and lawfully implemented.

11. Children

The commercial website and platform are not directed to children. Customers that use training with minors remain responsible for an appropriate legal basis, notices and safeguards.

12. Changes

We may update this policy when our services, providers or legal obligations change. The revised date will appear above, and material changes will be communicated where required.