1. Controller and contact details
The controller for website, account and commercial-contact data is Leximise SRL, Romania, registered office: [ADD REGISTERED OFFICE ADDRESS], registration number: [ADD TRADE REGISTER NUMBER], tax number: [ADD VAT / TAX NUMBER].
Privacy requests: [email protected]. Website: https://leximise.ai.
2. Scope and roles
For website visitors, prospects, account administrators and our direct business contacts, Leximise generally acts as controller. When a customer uses the platform to process employee, learner, auditor or other end-user data, the customer normally acts as controller and Leximise acts as processor under the applicable Data Processing Agreement.
3. Data we collect
- Demo and contact data: name, company, work email, company size, country, interests and message.
- Account data: identity, organisation, role, permissions, authentication and security events.
- Service data: assessments, policies, evidence metadata, training assignments, progress, quiz results and certificates submitted or generated by authorised users.
- Technical data: IP address, browser, device, timestamps, logs and security diagnostics.
- Billing and contractual data, where relevant.
- Communications and support requests.
4. Purposes and legal bases
- Responding to enquiries and taking pre-contractual steps: contract or legitimate interests.
- Providing, securing and administering the service: contract and legitimate interests.
- Billing, accounting and legal compliance: contract and legal obligations.
- Product improvement and service analytics: legitimate interests, or consent where required.
- Marketing communications: consent or legitimate interests where permitted; you may opt out at any time.
- Preventing fraud, abuse and security incidents: legitimate interests and legal obligations.
5. Recipients and service providers
We may share data with vetted hosting, database, email, support, analytics, payment and professional-service providers only where needed. We may also disclose data where required by law or in connection with a corporate transaction. We do not sell personal data.
A current sub-processor list should be made available to customers before production contracting.
6. International transfers
Where data is transferred outside the EEA, we use an adequacy decision, Standard Contractual Clauses or another lawful safeguard, together with supplementary measures where appropriate.
7. Retention
- Demo and inactive prospect records: normally up to 24 months after the last meaningful interaction.
- Customer account and service data: for the subscription term and the documented deletion period after termination.
- Billing and legal records: for periods required by applicable law.
- Security logs and backups: for limited periods based on security and recovery needs.
8. Security
We use risk-based technical and organisational measures, including access controls, authentication safeguards, encryption where appropriate, logging, backups, vulnerability management and role-based permissions. No online service can guarantee absolute security.
9. Your GDPR rights
- Access, rectification and erasure.
- Restriction, objection and data portability, where applicable.
- Withdrawal of consent without affecting earlier lawful processing.
- The right not to be subject to certain solely automated decisions.
Send requests to [email protected]. We may need to verify your identity. You may complain to the Romanian supervisory authority, ANSPDCP, or another competent EEA authority.
10. Automated processing and AI
Leximise may use AI-assisted features to generate drafts, recommendations, policies or training content. These outputs support authorised users and should be reviewed by a qualified person. We do not use website or customer-account data to make decisions producing legal or similarly significant effects about individuals unless expressly agreed and lawfully implemented.
11. Children
The commercial website and platform are not directed to children. Customers that use training with minors remain responsible for an appropriate legal basis, notices and safeguards.
12. Changes
We may update this policy when our services, providers or legal obligations change. The revised date will appear above, and material changes will be communicated where required.