Privacy Notice

(“Notice”)

We are pleased that you visited Lexa. Lexa is an artificial-intelligence-based online service (hereinafter: “Lexa” or the “Service”), so data protection and data security are especially important to us. Pursuant to Article 12(1) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (“General Data Protection Regulation”, “GDPR”), we hereby inform you, as a user of the www.lexa-ai.eu website (the “Website”) (the “User” or “you”), about the processing of personal data carried out when you use the Website and its circumstances.

Information about the Website’s data processing is continuously available in the footer of the Website’s home page.

The Controller is entitled to amend this Notice unilaterally. In the event of amendment, we will notify you by publishing the amended Notice on the Website. By using the Website after the amendment enters into force, you accept the amended Notice.

It is up to you whether and which personal data you provide; providing data is not mandatory. However, providing personal data is indispensable for the successful provision of the Service, and, when requesting a subscription, it is a condition of concluding and performing the contract, as detailed below.

1. Name and contact details of the Controller

Company name: SynthMind Solutions Kft.

Registered seat: 1053 Budapest, Veres Pálné utca 9., Hungary

Company registration number: 01-09-437218

Managing director: Bálint Bojkó

Website: <www.lexa-ai.eu>

E-mail: support@lexa-ai.eu

hereinafter: the “Controller”

2. Individual data processing activities

2.1. Registration and subscription

Using the Service requires registration (“Registration”), i.e. creation of a user account (“User Account”), and starting a subscription (“Subscription”). The User may delete the User Account at any time; in this case, the data provided and stored there will also be deleted. The User may pause the Subscription (“Pause”), which, however, does not automatically delete the User Account data; the User Account data remains available.

During Registration and Subscription, the following data must be provided:

DATA PROCESSEDPURPOSE OF PROCESSINGLEGAL BASISRETENTION PERIOD
User Account data
Your name, e-mail address and the password you providedManaging the Registration, creating the User Account, customer identification.Performance of a contract under Article 6(1)(b) GDPRThe Controller processes the data provided until you delete your User Account, or for 5 years from the start of a Pause, whichever is earlier.
Your professionUnderstanding users and the target audience for the purpose of developing the ServiceConsent of the data subject under Article 6(1)(a) GDPRThe Controller processes the data provided until you delete your User Account, or for 5 years from the start of a Pause, whichever is earlier.
Type, status, start and expiry date of the Subscription selected by you; billing name, billing address, e-mail address, transaction identifierAdministration and operation of the Subscription; performance of the Subscription, processing of the Subscription and the related payment through a payment service provider, documentation and administration of the payment, for example: sending notices related to the Subscription.The legal basis of the processing is the performance of a contract (Article 6(1)(b) GDPR)The Controller processes the data provided until you delete your User Account, or for 5 years from the start of a Pause, whichever is earlier.
Invoice data
Your name, e-mail address, billing address, the number, date and time of the transaction, the content of the accounting document and, in the case of a VAT invoice, your tax number (if provided)Issuing the accounting documents for purchase transactions and retaining them within the deadlines set out in legislation.Compliance with a legal obligation of the Controller (Article 6(1)(c) GDPR; Section 169 of Hungarian Act CXXVII of 2007 on Value Added Tax; Section 169 of Hungarian Act C of 2000 on Accounting)8 years after the invoice is issued, or the period specified in the tax and accounting laws in force at any given time.

2.2. Chat

After Registration and Subscription, you can use the Service through the Website by asking questions and receiving answers to your questions generated by artificial intelligence on the basis of legislation (“Chat”). While using the Chat through the Website, it is also possible to upload a document, in connection with which the User may also ask questions about the document. You will receive an answer generated by artificial intelligence to these questions as well. Please note that the document uploaded by you may contain personal data. Anonymization of the document is the User’s responsibility.

During the Chat, we process the following data:

Data processedPurpose of processingLegal basisRetention period
Textual question provided by the User, the uploaded document and the raw text of the document (anonymized at the User’s choice) (“Input”), which may also contain personal data.Processing the question and the uploaded document (raw text of the document), generating a legal-information answer, and ensuring that earlier questions can be retrieved (“Chat History”)Performance of a contract (Article 6(1)(b) GDPR).Textual question: until the User Account is deleted or for 5 years from the start of a Pause, whichever is earlier. Raw text of the document (anonymized at the User’s choice): until the relevant Chat History is deleted, or for 5 years from the start of a Pause, whichever is earlier.
Text of the answer generated by the Service (“Output”), if the Input contained personal data.Performance of the Service, ensuring that earlier questions can be retrieved (“Chat History”)Performance of a contract (Article 6(1)(b) GDPR).Until the User Account is deleted or for 5 years from the start of a Pause, whichever is earlier.
Document uploaded as Input, which may also contain personal data.Providing an optional anonymization feature for uploaded documents and performing the anonymization if the User decides, at their own discretion, to use this featurePerformance of a contract (Article 6(1)(b) GDPR).The document is not retained for this purpose. Lexa processes only the anonymized document.

2.3. Integration with external generative AI services

Your Subscription may be connected to certain external generative artificial intelligence services. We currently offer integration with the following services: ChatGPT, Claude. As a result, you may also initiate a Chat question in Lexa based on Input provided in the external generative AI service. Questions initiated in the external generative AI service do not appear in the Chat History stored by the Controller, and the Controller does not store them in the form of Chat History. In connection with providing the integration, we process the following personal data:

Data processedPurpose of processingLegal basisRetention period
User identifier (user ID), Subscription type, and the token generated on the basis of theseIdentification of the User in order to provide integration with external generative AI servicesPerformance of a contract (Article 6(1)(b) GDPR).Not stored permanently; available only for the duration of the identification session (for the time of linking the subscriptions).
User ID, Subscription type, parameters required for the search tools determined on the basis of the Input provided in the external generative AI service (IP address, location data, document title and identifier, search queries, areas of law, keywords, conversation history), tool calls, and answers provided by Lexa (identifiers, titles, summaries and citations of relevant legal sources). The listed personal data is stored in the form of logs.Processing questions initiated from external generative AI services, generating legal-information answers. Ensuring product quality, troubleshooting, improving the quality of the Service and measuring its performance, preparing aggregated product-usage statistics (for this purpose, personal data is processed in a form aggregated per User).Performance of a contract (Article 6(1)(b) GDPR). Legitimate interest of the Controller (Article 6(1)(f) GDPR).For 6 months, or until the User Account is deleted, whichever is earlier.

2.4. Newsletter

On the Website you can subscribe to our newsletter so that you can always stay informed about, among other things but not exclusively, new subscription options and other news and information related to the Website or the Service (e.g. updates, new features). You can unsubscribe from the newsletter in the User Account or by clicking the unsubscribe link in the newsletter.

Data processedPurpose of processingLegal basisRetention period
Your name, e-mail addressSending e-mail newsletters to subscribers.Consent of the data subject (Article 6(1)(a) GDPR)Until consent to receiving the newsletter is withdrawn.
User behavior (which area of the given Website the User visits within the newsletter, which links they use)Preparing statistics on the success of newsletters, personalizing the sending of newsletters.Consent of the data subject (Article 6(1)(a) GDPR)Until consent to receiving the newsletter is withdrawn or until you unsubscribe from it.

2.5. Inquiries and feedback

A) Inquiries from Users

You can contact the Controller by e-mail through the Website. In your inquiry, you may report any technical errors that may arise (hereinafter: “Bug Report”) and share with the Controller any other comments or suggestions regarding the Service (hereinafter: “Feedback”).

Data processedPurpose of processingLegal basisRetention period
Your name, e-mail address and the content of the e-mail sent.Ensuring contact and answering any questions; enforcement of legal claims, if the content of the e-mail is directed at this.The legal basis of the processing is Article 6(1)(f) GDPR, the legitimate interest of the Controller.5 years from receipt of the inquiry.

B) Feedback Form

The Controller may from time to time send you a short questionnaire (“Feedback Form”), the completion of which is entirely voluntary. The Controller uses the answers provided solely to further develop the Service and improve the user experience.

Data processedPurpose of processingLegal basisRetention period
Your name, e-mail address.Sending a feedback-request e-mail in which the Controller asks for feedback on the Service in order to assess user needs and evaluations for the purpose of developing the ServiceArticle 6(1)(f) GDPR, the legitimate interest of the controllerUntil the User Account is deleted or until the User objects, whichever is earlier.
Your name, e-mail address, profession, and the content of and answers to the Feedback Form.Assessing user needs and evaluations for the purpose of developing the ServiceArticle 6(1)(a) GDPR, the consent of the data subjectUntil consent to the processing of the data provided on the Feedback Form is withdrawn, but no longer than 5 years from completion of the Feedback Form.

2.6. Cookie notice

In addition to the cookies (Cookies) that are technically essential for the operation of the site, the Website also uses cookies for marketing purposes. The purpose of the essential Cookies is the secure and undisturbed operation of the Website. The Cookies placed by the Meta (Facebook) Pixel are third-party marketing cookies that operate for the purpose of analyzing user behavior and displaying targeted advertisements.

Data processedPurpose of processingLegal basisRetention period
Session IDRemembering login, operating navigation.Article 6(1)(f) GDPR – legitimate interest30 days
Device ID, browser identifier, IP address (full or partially anonymized), user behavior data (page visits, clicks, viewed content), unique third-party identifierSupporting marketing and remarketing activities, displaying targeted advertisements, measuring campaign effectiveness, analyzing user behaviorArticle 6(1)(a) GDPR – consent of the data subject (through the cookie banner)Between 90 days and 2 years (depending on the type of Meta Cookie)

The use of Meta Pixel Cookies requires the User’s prior and explicit consent. In the absence of consent, the Meta Pixel and its related Cookies are not placed and user behavior is not tracked.

2.7. Business intelligence and statistical analysis

In order to analyze the operation and performance of the Service and to support its business decisions, the Controller synchronizes User Account data and Subscription-related payment data every three hours into a business intelligence (BI) data warehouse. Access to the data stored in the data warehouse is restricted through column-level access control: BI reports and dashboards, statistical analysis and analysis performed with an artificial-intelligence-based data analysis tool (AI agent) are based exclusively on columns that do not contain personal data. Persons and processes with access to the BI dashboards or the AI-based data analysis tool cannot access columns containing data suitable for identifying a natural person or sensitive data, and no personal data is transferred to these tools.

Data processedPurpose of processingLegal basisRetention period
User Account data under section 2.1 of this Notice and Subscription-related payment data, which are synchronized into and stored in the BI data warehouse. Only columns that do not contain personal data are used on BI dashboards, in statistical analysis and in AI-based analysis; access to columns containing personal data is restricted through column-level access control.Statistical analysis, preparation of business intelligence (BI) reports and dashboards, analysis of the operation and performance of the Service, and artificial-intelligence-based (AI agent) data analysis.Legitimate interest of the Controller (Article 6(1)(f) GDPR).Source data synchronized into the BI data warehouse is stored for the retention period under section 2.1 of this Notice (until the User Account is deleted or for 5 years from the start of a Pause, whichever is earlier). The results of statistical and AI-based analysis do not contain personal data.

3. Recipients of personal data and categories of recipients

Your personal data may be accessed by the Controller’s staff and the persons engaged by it.

During the processing activities described in this Notice, the Controller uses the following processors (“Processor”):

Name, registered seat and company registration number of the ProcessorProcessing activityData processed by the Processor
Amazon Web Services EMEA Sàrl (AWS) Registered seat: 38 Avenue John F. Kennedy, L-1855, Luxembourg Company registration number: B186284Hosting provider – technical operation of the Website and the chat interfaceUser Account data specified under section 2.1 of this Notice; and data specified under sections 2.2, 2.3 and 2.6
KBOSS.hu Kft. (Számlázz.hu) Registered seat: 1031 Budapest, Záhony utca 7/D., Hungary Company registration number: 01-09-303201Invoicing system – issuing invoices compliant with Hungarian lawInvoice data specified under section 2.1 of this Notice
Emergence-Engineering Kft. (Számlabridge) Registered seat: 1123 Budapest, Nagyenyed utca 5. pinceszint, Hungary Company registration number: 01-09-380162Technical conversion and forwarding of invoice dataInvoice data specified under section 2.1 of this Notice
Stripe Payments Europe, Ltd. Registered seat: 3 Dublin Landings, North Wall Quay, Dublin 1, D01 C4E0, Ireland Company registration number: 513174Payment service provider – processing online Subscriptions, initiating invoicingInvoice data specified under section 2.1 of this Notice; bank card data (please note that the Controller does not process the bank card data provided by you!)
OpenAI L.L.C. (“OpenAI”) Registered seat: 3180 18th Street, San Francisco, CA 94110, USA Company registration number: 7063675Artificial-intelligence-based answer generation – processing chat questionsContent of the Inputs and Outputs specified under section 2.2 of this Notice (anonymously, without identifiers), and the data specified under section 2.3
Apple Inc., iCloud Registered seat: One Apple Park Way, Cupertino, California, USA Company registration number: RA000598Hosting provider – storage of inquiry messagesData specified under section 2.5 of this Notice
The Rocket Science Group LLC (Mailchimp) Registered seat: 675 Ponce De Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA Company registration number: 0028959Automated messagingUser data specified under section 2.1 of this Notice
Google Ireland Ltd. Registered seat: Gordon House, Barrow Street, Dublin 4, D04 E5W5, Ireland Company registration number: 368047Handling and storage of the Feedback FormData specified in the second row of the table in section 2.5 B) of this Notice
Meta Platforms Ireland Ltd. Registered seat: 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland Company registration number: 462932Remarketing, ad display, campaign analytics (Meta Pixel)Data specified under section 2.6 of this Notice
Neon, Inc. Registered seat: 209 Orange Street, City of Wilmington, County of New Castle, Delaware 19801, USA Company registration number: 7400891Database service for storing User data and Chat HistoryUser Account data specified under section 2.1 of this Notice; and data specified under section 2.2
Functional Software, Inc. (d/b/a Sentry) Registered seat: 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA Company registration number: 5551283Logging of Website operation, error detectionUser Account data specified under section 2.1 of this Notice; data specified under section 2.2; data specified under section 2.6
Netlify Inc. Registered seat: 512 2nd Street, 2nd Floor, San Francisco, CA 94107, United States Company registration number: 5575893Providing Website hosting and operationUser Account data specified under section 2.1 of this Notice; data specified under section 2.2; data specified under section 2.6
Microsoft Ireland Operations Limited Registered seat: 70 Sir John Rogerson’s Quay, D02 R296 Dublin 2, Ireland Company registration number: 256796Anonymization of uploaded documents based on the User’s decisionData specified under section 2.2 of this Notice
Google Cloud EMEA Limited (Google BigQuery) Registered seat: 70 Sir John Rogerson’s Quay, D02 R296, Dublin 2, Ireland Company registration number: 660412Business intelligence (BI) data warehouse and database service – technical provision of data storage and processing for statistical and data analysis purposesUser Account data and payment data specified under section 2.1 of this Notice (within the BI processing under section 2.7)

4. Data security

The Controller pays special attention to protecting personal data and processes it in accordance with the highest security standards. Personal data is stored on our own servers or on our processors’ strongly protected European servers, which can be accessed only on the basis of strictly controlled permissions.

Information about OpenAI and other US-based processors:

During operation of the Service, the questions provided by you are processed through a secure technical channel. The text of the Inputs is processed on OpenAI’s servers in the United States to generate the Outputs; however, under the Zero Data Retention principle, OpenAI uses the questions asked by the User only for the time needed to prepare the answer, Chat History is not stored permanently on OpenAI’s servers, and OpenAI does not use the content of conversations for training the model or for its later development.

Additional providers registered in the United States (Neon, Netlify, Sentry) also participate in operating the Service, so certain data may be transferred to the United States in order to operate the Service. Data transfers are always performed in accordance with the applicable data protection requirements (SCC).

The business intelligence (BI) data warehouse used to analyze the operation of the Service runs on Google Cloud (BigQuery). Data processed in the BI data warehouse is stored and processed exclusively on Google Cloud servers located in the European Union (Frankfurt); this data is not transferred to the United States. The BI data warehouse also stores personal data under section 2.1 of this Notice; access to the data fields containing such data is restricted through column-level access control.

Please note that OpenAI, Netlify and Neon are currently not members of the EU-US Data Privacy Framework (DPF). By using the Service, you expressly accept and consent to this transfer. If you do not wish to consent, please stop using the Service immediately.

We also recommend that you do not include personal or confidential data in Inputs, such as data concerning health, religion or political affiliation.

For document uploads, the Website also gives the User the option to anonymize the document in order to implement data minimization. Anonymization of the document nevertheless remains the User’s responsibility. If you use the anonymization option provided by the Website, the document is anonymized before its content (raw text) is loaded into Lexa, so Lexa processes only the anonymized content (raw text). Regardless of the anonymization feature, we do not store the original document, only the raw text extracted from the document, which, if the anonymization feature is used, does not contain personal data. Please note that the anonymization feature operates on artificial-intelligence-based technology (Microsoft Azure), so its complete accuracy cannot be guaranteed. It may occur that the anonymization fails to recognize and omit certain personal data, so the raw text may exceptionally contain personal data. In view of this risk, we recommend that, particularly in the case of sensitive documents, you also verify the result of the anonymization. While the anonymization feature is running – i.e. during the processing of the document – the original document containing personal data is available to the system only temporarily, for the time necessary to complete the anonymization process, and is not stored permanently.

Uploaded documents are not used for model training either by Lexa or by the other recipients involved in the processing.

In the course of the integration enabled with external generative AI services, the Controller appropriately segregates its databases, so that, in connection with the integration, for the purpose of answering, the external generative AI service provider does not have access to any server that stores the Users’ account data.

5. Processing of special categories of data

The Controller does not process special categories of data in the course of this processing and does not process data of persons under 18 years of age.

Furthermore, please refrain from providing special categories of personal data (e.g. health data, personal data revealing political opinions, religious or philosophical beliefs, or trade union membership) in Inputs while using the Service, including uploading personal data belonging to special categories of personal data contained in documents.

6. Other information related to data processing

For processing activities not covered by this Notice, the Controller will always inform you when the data is collected. We also inform you that the Website may contain links to other websites; the controller of the relevant website is responsible for the processing carried out after you are redirected there.

We also inform you that courts, the prosecution service, investigative authorities, minor-offence authorities, administrative authorities, the Hungarian National Authority for Data Protection and Freedom of Information, or other bodies may, on the basis of statutory authorization, contact the Controller to provide information, disclose or transfer data, or make documents available. In such cases, the Controller discloses to the authorities only as much data – provided that the authorities have specified the precise purpose and the scope of the data – as is necessary to achieve the purpose of the request and as it can be obliged to disclose by law.

7. Responsibility for the correctness and accuracy of data

The Controller does not verify the correctness of the data provided; you are therefore responsible for its adequacy.

If, in connection with any processing, you provide personal data other than your own, you are obliged to obtain the data subject’s consent.

If, while using the Service, you provide personal data of third parties or other data qualifying as attorney-client privileged information or business secrets, or upload documents containing such data, you are obliged to obtain the data subject’s consent. The Controller assumes no responsibility whatsoever for third parties’ data or for the use of data qualifying as attorney-client privileged information or business secrets; the User bears sole and full responsibility for their lawful processing and use.

8. Data subject rights in connection with the processing

8.1. Right of access

Under Article 15 GDPR, you are entitled at any time to request information on whether and how the Controller processes your personal data, including the purposes of processing, the recipients to whom your data has been disclosed, the source from which the Controller received the data, the retention period, any of your rights relating to the processing, and, in the case of transfers to a third country or an international organization, information on the safeguards relating to the transfer. When exercising the right of access, you are also entitled to request a copy of the data. If your right of access adversely affects the rights and freedoms of others, in particular the business secrets or intellectual property of others, the Controller is entitled to refuse to comply with your request to the extent necessary and proportionate. If your request is excessive or manifestly unfounded, the Controller may charge a reasonable fee in accordance with Article 12(5)(a) GDPR or may refuse to act on the request (Article 12(5)(b) GDPR).

8.2. Right to rectification

Under Article 16 GDPR, the Controller will rectify or supplement your personal data at your request. If there is doubt about the rectified data, the Controller may ask you to prove the corrected data to the Controller in an appropriate manner, primarily by documentary evidence.

8.3. Right to erasure (“right to be forgotten”)

Under Article 17 GDPR, if you request the erasure of your personal data, the Controller erases it without undue delay:

  • if it is no longer needed for the purpose for which it was originally stored, or the processing is unlawful,
  • if you withdraw your consent and the Controller has no overriding, compelling legitimate ground for the processing.

Personal data may not be erased if the processing is necessary:

  • for exercising the right of freedom of expression and information;
  • for compliance with an obligation under Union or Member State law applicable to the Controller which requires the processing of personal data;
  • for the establishment, exercise or defense of legal claims.

You may exercise your right to be forgotten by sending an electronic message or a postal letter to our contact details provided in section 1 of this Notice; in the case of unsubscribing from the newsletter, you may also exercise this right by clicking the “Unsubscribe” link at the bottom of the newsletter.

8.4. Right to restriction of processing

Under Article 18 GDPR, you may request the restriction of the processing of your personal data in the following cases:

  • the processing is unlawful, but you oppose the erasure of the data and instead request the restriction of their use;
  • the Controller no longer needs the personal data for the purposes of the processing, but you require them for the establishment, exercise or defense of legal claims.

8.5. Right to data portability

Under Article 20 GDPR, you are entitled to receive the personal data concerning you which you have provided to the Controller, and to have the Controller transmit this data directly to another controller, provided that the legal basis of the processing is your consent.

8.6. Right to object

Under Article 21 GDPR, where the legal basis of the processing concerning you is the legitimate interest of the Controller or of a third party, you are entitled to object to the processing. The Controller is not obliged to comply with the objection if it demonstrates that the processing is justified by compelling legitimate grounds which override your interests, rights and freedoms, or that the processing is related to the establishment, exercise or defense of the Controller’s legal claims.

8.7. Right to complain and seek remedies

If you believe that the Controller’s processing of your personal data violates applicable data protection laws, especially the GDPR, you may lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, your place of work or the place of the alleged infringement. The supervisory authority competent for the Controller’s registered seat is the Hungarian National Authority for Data Protection and Freedom of Information (NAIH).

NAIH contact details:

You may also turn to a court in accordance with the rules of the GDPR and the Hungarian Information Act.

Your detailed rights and remedies are set out in Chapters III and VIII of the GDPR and in Sections 14–23 of the Hungarian Information Act (Act CXII of 2011).

8.8. Deadline for responding to data subject requests

The Controller ensures that if you exercise any of your rights in connection with this processing and contact the Controller in this regard, the Controller responds to such requests without undue delay, and no later than within 30 days.

If you wish to exercise any of your rights, or if you have any questions or comments, please contact us at the contact details indicated in section 1 of this Notice.