Privacy Policy & Data Protection | LeXi AI Legal Platform
Skip to main content

Privacy Policy

Effective Date: 11-07-2026  ·  Astute Lex Servicado Private Limited

Introduction

IMPORTANT: PLEASE READ THIS PRIVACY POLICY CAREFULLY.This Privacy Policy explains how Astute Lex Servicado Private Limited (the "Company", "we", "us", or "our") collects, uses, discloses, retains, protects, and otherwise processes Personal Data in connection with the LeXi AI ecosystem of products and services. It applies to the LeXi AI Platform, the LeXi AI Agents, the LeXi AI Workspace, LeXi LiTT, LeXi Desk, LeXi AI Academy, and every other product, module, feature, application programming interface, and service that the Company makes available under the "LeXi AI" name and marks (collectively, the "Services" or the "Ecosystem"), except where a separate privacy notice is expressly provided for a particular product or service.LeXi AI is an artificial intelligence platform for legal and legal education use. Because the Services are used by advocates, law firms, in-house legal teams, enterprises, universities, law schools, and government organizations, and because they process legal documents and other sensitive material, this Privacy Policy has been written to reflect privacy-by-design principles and to be suitable for review by enterprise legal teams, institutional data protection officers, security auditors, and investors.This Privacy Policy should be read together with the LeXi AI Terms of Service (the "Terms of Service" or "Terms"), any applicable Supplemental Terms, any Data Processing Agreement, and any Enterprise Agreement. Capitalized terms that are used but not defined in this Privacy Policy have the meanings given to them in the Terms of Service.Version and status. This document is Version 2.0 of the LeXi AI Privacy Policy. It supersedes and replaces Version 1.0 in its entirety with effect from the Effective Date, and it supersedes all prior privacy notices, statements, and understandings relating to its subject matter, except to the extent expressly preserved in a separate written agreement between You and the Company. This Privacy Policy was last reviewed on 10-07-2026.

1. Introduction, Scope, and About This Policy

1.1 Purpose of this Privacy Policy

This Privacy Policy describes the categories of Personal Data that the Company processes, the sources from which that Personal Data is obtained, the purposes and legal bases for the processing, the circumstances in which Personal Data is shared, the periods for which it is retained, the safeguards applied to protect it, and the rights and choices available to individuals. It also explains how each product within the Ecosystem processes Personal Data, and how future products, modules, Agents, and application programming interfaces are governed by this Privacy Policy.

1.2 Who this Privacy Policy applies to

This Privacy Policy applies to the processing of Personal Data relating to:
Visitors to the Company's websites and marketing pages;
Individuals who register for, subscribe to, or use the Services in an individual capacity;
Individuals who use the Services as Authorized Users under an Organization, Institution, Enterprise Agreement, or subscription established by another person;
Administrators and other personnel who configure, manage, or administer an Organization or Institution;
Students, faculty, and Institution personnel who use LeXi AI Academy;
Individuals whose Personal Data is contained within Customer Data, Inputs, uploaded documents, or other content that a User submits to or generates within the Services; and
Individuals who contact the Company for support, sales, or other purposes. The way in which this Privacy Policy applies to a given individual depends on the capacity in which the relevant Personal Data is processed and on the Company's role in respect of that processing, as described in Section 3.

1.3 Scope across the Ecosystem

This Privacy Policy applies across the entire Ecosystem. It is designed to describe processing that is common to all products in a single, consistent framework, and then to explain, in Section 4, how that framework applies to each specific product. Where a product has processing characteristics that differ from the common framework, those differences are explained in the relevant part of Section 4 or in a separate privacy notice, Supplemental Terms, or Data Processing Agreement applicable to that product.

1.4 Relationship with the Terms of Service and other agreements

This Privacy Policy forms part of the contractual framework governing Your use of the Services, together with the Terms of Service and any applicable Supplemental Terms, Order Form, Data Processing Agreement, and Enterprise Agreement. This Privacy Policy is not intended to, and does not, contradict the Terms of Service. In the event of any conflict between this Privacy Policy and a Data Processing Agreement or Enterprise Agreement that has been separately executed between the Company and a Customer in respect of the processing of Personal Data, the Data Processing Agreement or Enterprise Agreement prevails to the extent of the conflict and to the extent permitted by Applicable Data Protection Laws.

1.5 Structure of this Privacy Policy

This Privacy Policy is organized as follows: Section 2 sets out defined terms and rules of interpretation; Section 3 explains the Company's roles as a data fiduciary or controller and as a data processor; Section 4 explains how this Privacy Policy applies to each product in the Ecosystem; Sections 5 and 6 describe the categories of Personal Data and the treatment of uploaded documents and special categories of data; Section 7 describes the sources of Personal Data; Section 8 describes the use of artificial intelligence; Section 9 sets out the purposes of processing and the legal bases; Sections 10 and 11 explain sharing, service providers, subprocessors, and third-party artificial intelligence providers; Section 12 addresses international transfers; Section 13 addresses retention; Section 14 addresses security; Section 15 sets out privacy rights and choices; Section 16 addresses cookies; Section 17 addresses children and students; Section 18 addresses third-party services; Section 19 addresses enterprise and institution controls; Section 20 addresses changes; Section 21 addresses future products; Section 22 sets out region-specific disclosures; and Section 23 provides grievance redressal and contact information.

1.6 Changes and continuing effect

The Company may update this Privacy Policy from time to time in accordance with Section 20. The version of this Privacy Policy in force at the time Personal Data is processed governs that processing, subject to Applicable Data Protection Laws and to any separately executed Data Processing Agreement or Enterprise Agreement.

2. Definitions and Interpretation

2.1 Definitions

In this Privacy Policy, unless the context otherwise requires, the following capitalized terms have the meanings set out below. Capitalized terms used but not defined here have the meanings given to them in the Terms of Service."Account" means the credentialed access provided to a User or an Organization to enable use of the Services, including all associated identifiers, authentication factors, settings, and usage data."Administrator" means a User designated (whether by an Organization, an Institution, or by the Terms of Service) with elevated permissions to configure, manage, monitor, provision, suspend, or de-provision Accounts, Seats, Workspaces, roles, permissions, and other settings within an Organization's or Institution's environment on the Services."Affiliate" means, in relation to any entity, any other entity that directly or indirectly controls, is controlled by, or is under common control with that first entity, where "control" means the ownership of more than fifty percent (50%) of the voting securities or equivalent interests, or the power to direct the management and policies of an entity."Applicable Data Protection Laws" means all laws and regulations relating to the processing, privacy, protection, or security of Personal Data that are applicable to a party's performance under the Terms of Service and this Privacy Policy, including, without limitation and where applicable, the Digital Personal Data Protection Act, 2023 of India and the rules made under it; the Information Technology Act, 2000 of India and the rules made under it, including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011; the General Data Protection Regulation (Regulation (EU) 2016/679); the United Kingdom General Data Protection Regulation and the Data Protection Act 2018; and applicable United States federal and state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act, in each case as amended, replaced, or supplemented and in force from time to time."Authorized User" means an individual who is authorized by You (or, in the case of an Organization or Institution, by the relevant Administrator) to access and use the Services under Your Account or subscription, and for whom a Seat or equivalent right of access has been allocated where required."Controller" means the natural or legal person that, alone or jointly with others, determines the purposes and means of the processing of Personal Data, and includes a "Data Fiduciary" as that term is used under the Digital Personal Data Protection Act, 2023, and equivalent concepts under other Applicable Data Protection Laws."Cookies" means cookies, pixels, tags, software development kits, local storage, and similar technologies used to store or access information on a device, as further described in Section 16."Customer Data" means all data, documents, files, text, materials, and other content that is uploaded, submitted, entered, transmitted, stored, or otherwise made available to the Services by or on behalf of You or Your Authorized Users, including Inputs, but excluding Outputs and excluding the Company's Confidential Information and pre-existing materials, consistent with the meaning given in the Terms of Service. Customer Data includes User Content and may contain Personal Data."Data Principal" means the individual to whom Personal Data relates, and includes a "Data Subject" as that term is used under the General Data Protection Regulation and the United Kingdom General Data Protection Regulation, a "consumer" as that term is used under applicable United States state privacy laws, and equivalent concepts under other Applicable Data Protection Laws. References in this Privacy Policy to "You" in the context of privacy rights should be read as references to the relevant Data Principal."Data Processing Agreement" or "DPA" means a data processing agreement, data processing addendum, or equivalent instrument entered into between the Company and a Customer that governs the processing of Personal Data by the Company on the Customer's behalf, where such an instrument is required by Applicable Data Protection Laws or is otherwise agreed."Enterprise Agreement" means a master services agreement, enterprise subscription agreement, institutional agreement, or other negotiated written agreement between the Company and a Customer that governs the Customer's use of the Services and prevails over the standard Terms of Service to the extent stated in it."Input" means the prompts, instructions, queries, questions, materials, and other content that You or Your Authorized Users submit to the Services, including to any Agent, for processing."Institution" means a university, law school, college, educational body, or other organization that licenses or uses LeXi AI Academy or another part of the Services for the benefit of its students, faculty, or personnel."Organization" means a law firm, company, chambers, in-house legal team, government body, or other entity that establishes an environment on the Services and under which one or more Authorized Users are provisioned."Output" means the content, responses, drafts, analyses, summaries, citations, and other material generated by the Services, including by any Agent, in response to an Input or otherwise, consistent with the meaning given in the Terms of Service."Personal Data" means any data about an individual who is identified or identifiable, whether directly or indirectly, by or in relation to such data, and includes "personal data", "personal information", and equivalent concepts under Applicable Data Protection Laws. Personal Data may be contained within Account information, usage data, Customer Data, Inputs, Outputs, uploaded documents, and other categories described in this Privacy Policy."Processing" (and "process" and "processed") means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, analysis, disclosure, dissemination, alignment, combination, restriction, erasure, or destruction."Processor" means the natural or legal person that processes Personal Data on behalf of, and under the instructions of, a Controller, and includes a "Data Processor" as that term is used under Applicable Data Protection Laws."Sensitive Personal Data" means Personal Data that is afforded special protection under Applicable Data Protection Laws, including, depending on the applicable law, data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership; genetic data and biometric data processed for the purpose of uniquely identifying an individual; data concerning health; data concerning an individual's sex life or sexual orientation; data relating to offenses, criminal convictions, or their commission; financial data; and other categories designated as sensitive by Applicable Data Protection Laws. This Privacy Policy uses "Sensitive Personal Data" to refer to all such categories collectively, and also encompasses "special categories of personal data" under the General Data Protection Regulation and the United Kingdom General Data Protection Regulation and "sensitive personal data or information" under the Information Technology Act, 2000 and rules made under it."Services" or "Ecosystem" means the LeXi AI Platform, the LeXi AI Agents, the LeXi AI Workspace, LeXi LiTT, LeXi Desk, LeXi AI Academy, and all other products, modules, Agents, features, functionality, application programming interfaces, integrations, websites, and services offered by the Company under the "LeXi AI" name and marks, as they may evolve from time to time."Subprocessor" means a third party engaged by the Company to process Personal Data in connection with the provision of the Services, where the Company acts as a Processor."User" means any individual who accesses or uses the Services, whether in an individual capacity or as an Authorized User, and "You" and "Your" refer to the User and, where the User accepts this Privacy Policy on behalf of an Organization or Institution, to that Organization or Institution."User Content" means content that is created, authored, uploaded, or contributed by a User within the Services, and forms part of Customer Data.

2.2 Interpretation

In this Privacy Policy, unless the context otherwise requires:
The singular includes the plural and the plural includes the singular;
A reference to a Section is to a section of this Privacy Policy;
The words "include", "includes", "including", and "in particular" are illustrative and do not limit the generality of the related words;
Headings and section numbers are for convenience only and do not affect interpretation;
A reference to a statute or statutory provision is a reference to it as amended, extended, replaced, or re-enacted from time to time, and includes any subordinate legislation made under it;
A reference to "writing" or "written" includes email and electronic communication; and
References to the Company acting in its "discretion" mean its reasonable discretion exercised in good faith, unless stated otherwise.

2.3 No adverse construction

This Privacy Policy has been drafted to be read and understood by enterprise legal teams, institutional data protection officers, and individual Users alike. No provision of this Privacy Policy will be construed adversely against the Company solely on the ground that the Company was responsible for its preparation.

3. Our Roles: Data Fiduciary or Controller, and Data Processor

3.1 Why the Company's role matters

Under Applicable Data Protection Laws, the obligations that apply to the processing of Personal Data, and the rights that individuals may exercise, depend on whether the Company is acting as a Controller (that is, determining the purposes and means of processing) or as a Processor (that is, processing Personal Data on behalf of, and under the instructions of, another Controller). Because the Services are used both by individuals acting for themselves and by Organizations and Institutions acting for their own purposes, the Company acts in different roles in respect of different categories of processing. This Section 3 explains those roles. The remainder of this Privacy Policy should be read in light of this Section 3.

3.2 When the Company acts as a Controller

The Company acts as a Controller (or Data Fiduciary) in respect of processing where it determines the purposes and means of that processing. This includes the processing of Personal Data for the following purposes:
Creating, administering, securing, and supporting Accounts, Organizations, and Institutions;
Authenticating Users and protecting the security and integrity of the Services;
Billing, invoicing, payment processing, and the management of Subscriptions;
Providing customer support and responding to inquiries;
Operating, maintaining, monitoring, analyzing, and improving the Services, and developing new features, subject to the position on the use of Customer Data for model training set out in Section 8;
Marketing the Company's own products and services to the extent permitted by Applicable Data Protection Laws;
Detecting, preventing, and investigating fraud, misuse, and security incidents;
Complying with the Company's own legal, regulatory, and contractual obligations; and
Establishing, exercising, or defending legal claims. When the Company acts as a Controller, it is responsible for the processing described in this Privacy Policy in respect of those purposes, and this Privacy Policy serves as the Company's notice to Data Principals.

3.3 When the Company acts as a Processor

The Company acts as a Processor (or Data Processor) in respect of Customer Data that is processed on behalf of, and under the instructions of, an Organization, Institution, or other Customer that is the Controller of that Customer Data. This includes the processing of Personal Data contained within Inputs, uploaded documents, Workspace content, matter and contract materials, and Outputs, to the extent that such processing is carried out to provide the Services to the relevant Organization, Institution, or Customer. In these circumstances:
The Organization, Institution, or Customer is the Controller and is responsible for establishing a lawful basis for the processing, for providing any required notices to, and obtaining any required consents from, the relevant Data Principals, and for responding to requests by Data Principals to exercise their rights;
The Company processes the Customer Data in accordance with the Terms of Service, this Privacy Policy, any applicable Data Processing Agreement, and the documented instructions of the Controller; and
Where a Data Principal wishes to exercise rights in respect of Customer Data, the Company will, where required, direct the Data Principal to the relevant Controller and will provide reasonable assistance to that Controller as described in Section 15.7.

3.4 Individual Users

Where an individual uses the Services in an individual capacity, and not as an Authorized User of an Organization or Institution, the Company generally acts as a Controller in respect of the Personal Data processed to provide the Services to that individual, and this Privacy Policy applies directly to that individual. Even in this case, the individual remains responsible for the content that the individual submits to the Services, including any Personal Data of third parties contained within it, as described in Section 6.

3.5 Organizations and Institutions as Controllers

An Organization or Institution that establishes an environment on the Services, provisions Authorized Users, and determines how the Services are used within that environment is the Controller of the Customer Data processed within that environment, and of Personal Data relating to its Authorized Users to the extent it determines the purposes and means of that processing. The Organization or Institution is responsible for:
The lawfulness of its instructions and of its use of the Services;
Providing appropriate privacy notices to its Authorized Users, students, faculty, personnel, and other Data Principals;
Obtaining and maintaining any consents or authorizations required under Applicable Data Protection Laws; and
Configuring the Services, including permissions, retention settings where available, and administrative controls, in a manner consistent with its obligations. The Company makes available administrative controls to assist Organizations and Institutions in meeting these responsibilities, as described in Section 19.

3.6 Data Processing Agreements

Where the Company acts as a Processor on behalf of a Customer, and where required by Applicable Data Protection Laws or otherwise agreed, the Company and the Customer will enter into a Data Processing Agreement that governs the processing of Personal Data, including the subject matter and duration of the processing, the nature and purpose of the processing, the categories of Data Principals and Personal Data, the security measures applied, the use of Subprocessors, the assistance the Company will provide, and the treatment of Personal Data on termination. Enterprise and Institution Customers may request a Data Processing Agreement through the contacts in Section 23. Where a Data Processing Agreement is in place, it governs the relevant processing to the extent set out in it.

3.7 Interaction of roles across the Ecosystem

A single Account, Organization, or Institution may involve processing in respect of which the Company is a Controller (for example, Account administration and billing) and processing in respect of which the Company is a Processor (for example, the analysis of an uploaded contract or case file within a Workspace). The role of the Company in respect of any given processing is determined by the nature and purpose of that processing, applying the principles in this Section 3, and not by the product within which the processing occurs.

4. The LeXi AI Ecosystem and How This Privacy Policy Applies to Each Product

4.1 Overview

This Section 4 explains how this Privacy Policy applies to each product within the Ecosystem. The categories of Personal Data described in Section 5, the treatment of uploaded documents in Section 6, the artificial intelligence processing described in Section 8, the purposes and legal bases in Section 9, and the sharing, retention, and security provisions in Sections 10 to 14 apply across all products, subject to any product-specific points described in this Section 4. Nothing in this Section 4 expands the purposes for which Personal Data is processed beyond those set out in Section 9.

4.2 LeXi AI Platform

The LeXi AI Platform is the foundational layer of the Ecosystem through which Users access the other products. In connection with the LeXi AI Platform, the Company processes Personal Data relating to: Accounts, including registration details, credentials, and settings; Organizations and Institutions, including organizational details, structure, and configuration; Subscriptions and billing, including plan details, billing contacts, payment metadata, and transaction records; the Workspace environment and its configuration; security and authentication, including authentication logs, session data, and security events; teams, roles, and permissions, including the assignment of Authorized Users to Seats and the configuration of access rights; audit logs, including records of actions taken within an Organization's or Institution's environment; Enterprise Accounts and Institution Accounts, including the details of Administrators and the provisioning of Authorized Users; and future Platform services that the Company may introduce. The Company generally acts as a Controller in respect of Account administration, billing, security, and platform operation, and as a Processor in respect of Customer Data processed within the Platform on behalf of an Organization or Institution, as described in Section 3.

4.3 LeXi AI Agents

The LeXi AI Agents are specialized and general artificial intelligence capabilities made available within the Ecosystem. They include, without limitation, the Legal Research Agent, the Litigation Agent, the Drafting Agent, the Contract Review Agent, the Clause Analysis Agent, the Knowledge Retrieval Agent, the Document Intelligence Agent, the Risk Analysis Agent, the Compliance Agent, the Workflow Agent, and the Matter Management Agent, together with any general assistant capability and any Agent that the Company introduces in the future. In connection with the Agents, the Company processes: the Inputs that You submit to an Agent, including prompts, instructions, queries, and materials; the documents, matter content, and other Customer Data that an Agent is directed to analyze or use as context; the Outputs that an Agent generates; and associated metadata, including records of Agent use for the purposes of providing, securing, supporting, and improving the Services in accordance with this Privacy Policy. The manner in which the Agents process this data using artificial intelligence is described in Section 8. Additional Agents released in the future are automatically governed by this Privacy Policy unless a separate privacy notice is issued for a particular Agent, consistent with Section 4.7 and Section 21.

4.4 LeXi AI Workspace

The LeXi AI Workspace is the environment in which Users organize matters, store and manage documents, collaborate, and interact with the Agents. In connection with the LeXi AI Workspace, the Company processes Personal Data relating to: matter management, including matter records, descriptions, and associated metadata; document storage, including uploaded documents, folders, and projects; collaboration, including shared Workspaces, comments, and collaboration activity; the knowledge base, including materials that Users add to it; uploads, including the content and metadata of uploaded files; version history, including prior versions of documents and records of changes; search, including search and research queries submitted within the Workspace; Workspace metadata, including organizational and structural information about a Workspace; audit logs, including records of Workspace activity; permissions, including the access rights configured for Users within a Workspace; and Organization administration, including the configuration and management of Workspaces by Administrators. Because Workspace content is determined by Users and, in the case of an Organization or Institution, by the relevant Controller, the Company generally acts as a Processor in respect of Workspace content, and as a Controller in respect of the operation, security, and support of the Workspace, as described in Section 3.

4.5 LeXi LiTT

LeXi LiTT is the litigation intelligence module of the Ecosystem and is exclusively for Indian law. In connection with LeXi LiTT, the Company processes the legal materials that a User submits to, uploads to, or generates within the module in order to provide litigation-related functionality. These materials may include: case files; court orders; judgments; legal notices; evidence; client documents; pleadings; written arguments; research queries; drafts; case strategies; legal citations; procedural documents; matter metadata; and timeline data. These materials frequently contain Personal Data, and may contain Sensitive Personal Data, relating to the User, the User's clients, opposing parties, witnesses, and other individuals, as further described in Section 6. Because LeXi LiTT is for Indian law, the substantive legal analysis, references, and Outputs generated by the module are oriented to Indian law, and the module should not be relied upon for the law of any other jurisdiction. The Company processes LeXi LiTT materials as a Processor where they are submitted by or on behalf of an Organization that is the Controller, and otherwise in accordance with Section 3. The Company does not represent any User before any court or authority, does not create any advocate-client relationship, and does not provide legal advice, as set out in the Terms of Service.

4.6 LeXi Desk

LeXi Desk is the contract lifecycle management module of the Ecosystem. Unlike the other products, LeXi Desk supports more than one jurisdiction, namely India, the United Kingdom, and the United States. In connection with LeXi Desk, the Company processes: contracts; templates; clauses; negotiation documents; legal reviews; redlines; clause libraries; approval workflows; contract metadata; and document intelligence derived from the foregoing. Contract-related documents processed within LeXi Desk may relate to different jurisdictions depending on the jurisdiction that the User selects, and the Company processes those documents on the basis of the User's selection. The selection of the correct jurisdiction is the responsibility of the User, and the Company does not verify that a document, clause, or Output is appropriate for the jurisdiction selected or for any other jurisdiction. Contract materials frequently contain Personal Data relating to the parties to a contract, their personnel, and other individuals, as described in Section 6. The Company generally acts as a Processor in respect of contract materials submitted by or on behalf of an Organization that is the Controller, and otherwise in accordance with Section 3. The fact that LeXi Desk supports the jurisdictions of India, the United Kingdom, and the United States does not, of itself, mean that Personal Data is stored or processed in any particular one of those countries; the location of processing is addressed in Section 12.

4.7 LeXi AI Academy

LeXi AI Academy is the educational and learning module of the Ecosystem, made available to Institutions, universities, law schools, and their students, faculty, and personnel. In connection with LeXi AI Academy, the Company processes Personal Data relating to: students; faculty; Institutions; universities; law schools; Institution Administrators; assignments; assessments; courses; certificates; progress; learning analytics; and Institution dashboards. This may include enrolment and identification details, course and assignment content, assessment results, learning progress, engagement and analytics data, and records of certificates issued. Where LeXi AI Academy is made available through an Institution, the Institution is generally the Controller of the Personal Data of its students, faculty, and personnel, and the Company acts as a Processor in respect of that Personal Data, as described in Section 3 and Section 19. The treatment of children and students, including any applicable age requirements and consent obligations, is addressed in Section 17. Certificates issued through LeXi AI Academy are not a professional qualification, license, or accreditation, as set out in the Terms of Service.

4.8 Future products, modules, and Agents

The Ecosystem is designed to evolve. Any new product, module, Agent, application programming interface, feature, integration, or service that the Company introduces under the "LeXi AI" name and marks is automatically governed by this Privacy Policy, and the categories of Personal Data, purposes, legal bases, sharing, retention, and security provisions of this Privacy Policy apply to it, unless and until the Company publishes a separate privacy notice for it or issues Supplemental Terms that address its processing. Where a new product involves categories of Personal Data or purposes of processing that are not adequately described by this Privacy Policy, the Company will update this Privacy Policy in accordance with Section 20 or publish a separate privacy notice. This future-proofing provision is intended to ensure continuity of privacy governance across the Ecosystem without requiring a complete rewrite of this Privacy Policy each time the Ecosystem is extended, and it operates consistently with the corresponding provision of the Terms of Service.

5. Categories of Personal Data We Process

5.1 Overview and approach

This Section 5 describes the categories of Personal Data that the Company processes across the Ecosystem. The specific categories processed in respect of any given individual depend on how that individual uses the Services, the products used, the configuration chosen by the relevant Organization or Institution, and the content that Users submit. Not all categories are processed in respect of every individual. A significant proportion of the Personal Data processed within the Services is contained within Customer Data and is determined by Users rather than by the Company; the Company's treatment of that Customer Data is described in Section 6.

5.2 Identity and contact data

The Company processes identity and contact data, including name, email address, phone number, and, where voluntarily provided, postal address and other contact details. This data is used to create and administer Accounts, to communicate with Users, and for the other purposes described in Section 9.

5.3 Professional and organizational data

The Company processes professional and organizational data, including organization name, job title, role, the name of the law firm, chambers, company, or Institution with which an individual is associated, professional area of practice, and, where voluntarily provided, Bar Council information, enrolment details, or other professional identifiers. Bar Council information and similar professional data are processed only where the individual chooses to provide them, for example to support identity verification, eligibility, or product configuration.

5.4 Account, profile, and authentication data

The Company processes Account, profile, and authentication data, including usernames and account identifiers, credentials and authentication factors (which are stored using appropriate protection), profile settings and preferences, authentication logs, session data, and records relating to multi-factor authentication and single sign-on. This data is used to authenticate Users, to secure the Services, and to administer Accounts.

5.5 Billing and payment data

The Company processes billing and payment data, including billing name and contact details, billing address, plan and Subscription details, payment metadata (such as the type of payment method, the outcome of a transaction, and partial identifiers returned by a payment provider), invoices, and transaction and tax records. The Company uses third-party payment providers to process payments, and does not itself store complete payment card numbers; the role of payment providers is described in Section 11 and Section 18.

5.6 Usage, device, and technical data

The Company processes usage, device, and technical data generated when Users access and use the Services, including IP address, browser information, operating system, device information and identifiers, language and locale settings, referring and exit pages, features and functions used, dates and times of access, session duration, interaction and navigation data, log data, crash reports, and diagnostic and performance data. This data is collected automatically, as described in Section 7, and is used to operate, secure, monitor, and improve the Services.

5.7 Content and artificial intelligence interaction data

The Company processes content and artificial intelligence interaction data, including Inputs (such as prompts, instructions, and queries), AI prompt history and AI conversation history, search queries and research queries, uploaded documents, generated Outputs (such as generated drafts, generated legal research, generated litigation strategies, generated contracts, and generated summaries), and associated metadata. This category is central to the operation of the Agents and the other artificial intelligence features of the Services, and the manner in which it is processed using artificial intelligence is described in Section 8. Much of this data constitutes Customer Data and is subject to Section 6.

5.8 Product-specific legal and educational data

The Company processes product-specific data arising from the use of particular products, including: litigation data processed within LeXi LiTT (such as case files, court orders, judgments, legal notices, evidence, pleadings, written arguments, drafts, case strategies, legal citations, procedural documents, matter metadata, and timeline data); contract data processed within LeXi Desk (such as contracts, templates, clauses, negotiation documents, legal reviews, redlines, clause libraries, approval workflows, and contract metadata); and course and educational data processed within LeXi AI Academy (such as course data, assignments, assessment results, learning progress, learning analytics, certificates, and Institution dashboard data). This data frequently constitutes Customer Data and is subject to Section 6, and, in the case of LeXi AI Academy, to Section 17.

5.9 Workspace, collaboration, and organizational metadata

The Company processes Workspace, collaboration, and organizational metadata, including Workspace metadata, Organization metadata, matter and project structure, folder structure, collaboration activity, comments, version history, permissions and access configurations, and Administrator activity. This metadata is used to provide, organize, secure, and administer the Workspace and the environments of Organizations and Institutions.

5.10 Support, feedback, and communications data

The Company processes support, feedback, and communications data, including support requests and the content of support interactions, feedback that Users choose to provide, communication history with the Company, and records of correspondence. This data is used to provide support, to respond to inquiries, to improve the Services, and for the other purposes described in Section 9.

5.11 Logs, security, and audit data

The Company processes logs, security, and audit data, including audit logs, security logs, authentication logs, access logs, records of security events and incidents, and records used for monitoring, detection, and investigation. This data is used to secure the Services, to detect and prevent fraud and misuse, to maintain the integrity and availability of the Services, and to comply with legal obligations.

5.12 Integration, application programming interface, and webhook data

The Company processes integration and interface data, including API usage data, credentials issued for programmatic access, webhook logs, integration metadata, and data exchanged with third-party services and customer-connected sources that a User chooses to connect. The Company processes this data to enable and operate integrations and interfaces at the User's direction, and the role of third-party services is described in Section 18.

5.13 Marketing and communication preferences

The Company processes marketing and communication preferences, including subscription and unsubscribe status, preferences relating to product updates and announcements, and Cookie and tracking preferences. The Company uses this data to manage communications and preferences in accordance with Section 15 and Section 16 and Applicable Data Protection Laws.

5.14 Future categories of data

The Company may process additional categories of Personal Data as the Ecosystem evolves and as new products, modules, Agents, features, and integrations are introduced. Where the Company begins to process a materially new category of Personal Data, or to process Personal Data for a materially new purpose, it will update this Privacy Policy in accordance with Section 20 or publish a separate privacy notice, consistent with Section 4.8 and Section 21.

6. User Content, Uploaded Documents, and Special Categories of Data

6.1 The nature of documents and content processed by the Services

The Services are designed to process legal and educational documents and other content that Users upload or generate. This content is a core part of how the Services operate, and it frequently contains Personal Data, and may contain Sensitive Personal Data, relating not only to the User but also to third parties such as clients, opposing parties, witnesses, employees, counterparties, students, and other individuals. Examples of the documents and content that Users may submit to or generate within the Services include: contracts; employment agreements; non-disclosure agreements; court orders; judgments; pleadings; legal notices; first information reports; evidence; legal opinions; research notes; corporate documents; due diligence documents; compliance reports; internal policies; templates; student assignments; educational materials; other User generated content; and content generated by the Services, including generated drafts, generated legal research, generated litigation strategies, generated contracts, and generated summaries.

6.2 The Company's role in respect of uploaded documents and content

Where documents and content are submitted by or on behalf of an Organization or Institution, the Organization or Institution is the Controller of the Personal Data contained within them, and the Company processes that Personal Data as a Processor, in accordance with Section 3, the Terms of Service, this Privacy Policy, and any applicable Data Processing Agreement. Where documents and content are submitted by an individual User acting in an individual capacity, the Company processes the Personal Data contained within them to provide the Services to that User, and the User remains responsible for that content as described in Section 6.4. The Company does not monitor, review, or moderate the content of documents and content except as necessary to provide, secure, and support the Services, to enforce the Terms of Service and the Acceptable Use Policy, or to comply with a legal obligation.

6.3 Sensitive Personal Data within documents and content

Legal documents, case files, and contract materials may, by their nature, contain Sensitive Personal Data, including data concerning health, data relating to offenses or criminal proceedings, financial data, and other categories described in Section 2.1. The Company processes Sensitive Personal Data contained within Customer Data solely to provide the Services, as a Processor acting on the instructions of the relevant Controller, or, in the case of an individual User, to provide the Services to that User. The Company does not use Sensitive Personal Data contained within Customer Data for its own independent purposes, and, in particular, does not use it to train generally available artificial intelligence models in a manner that would expose it to other customers or Users, except as described in Section 8. Where the processing of Sensitive Personal Data requires a specific lawful basis, consent, or authorization under Applicable Data Protection Laws, the relevant Controller is responsible for establishing and maintaining that basis, consent, or authorization, as described in Section 6.4.

6.4 Your responsibilities in respect of documents and content

You are responsible for the documents and content that You submit to or generate within the Services, and for ensuring that You are permitted to do so. In particular, You represent and undertake that, in respect of Personal Data contained within Customer Data that You submit:
You have a valid lawful basis under Applicable Data Protection Laws for the collection and processing of that Personal Data, including its submission to and processing by the Services;
You have provided all notices, and obtained all consents and authorizations, required under Applicable Data Protection Laws from the relevant Data Principals, including in respect of Sensitive Personal Data where required;
Your submission and use of the Personal Data does not violate the rights of any Data Principal or any obligation of confidentiality, privilege, or professional duty to which You are subject; and
Your instructions to the Company in respect of the processing of that Personal Data are lawful. Where You are an Authorized User of an Organization or Institution, these responsibilities are borne by You together with, and subject to the policies of, that Organization or Institution as the Controller.

6.5 Confidentiality and privilege

The Company recognizes that documents and content processed within the Services may be confidential or subject to legal professional privilege. The Company treats Customer Data as Confidential Information in accordance with the Terms of Service, and applies the security measures described in Section 14. Nothing in the provision of the Services is intended to, or does, waive any privilege or confidentiality attaching to Customer Data. You remain responsible for managing privilege and confidentiality in respect of Your documents and content, including by configuring permissions and access appropriately within an Organization or Institution.

6.6 Outputs and generated content

Outputs generated by the Services may contain, reproduce, or be derived from Personal Data contained within the Inputs and documents that a User provides, and may themselves contain Personal Data. Outputs are Customer Data for the purposes of this Privacy Policy to the extent they contain Personal Data, and are subject to this Section 6. Outputs are generated using artificial intelligence, are probabilistic in nature, and may be inaccurate, incomplete, or outdated, as described in Section 8 and in the Terms of Service, and must be independently reviewed and verified by a suitably qualified human before any reliance. The Company does not warrant that Outputs are accurate or free from error, and the responsibility for the use of Outputs rests with the User.

7. How We Collect Personal Data

7.1 Personal Data collected directly from Users

The Company collects Personal Data directly from Users when they register for an Account, configure a profile, subscribe to or pay for the Services, submit Inputs, upload documents, create or contribute User Content, use the Agents and other features, contact support, provide feedback, respond to communications, or otherwise interact with the Services. Much of the Personal Data processed within the Services is provided directly by Users in this way, including within Customer Data.

7.2 Personal Data collected automatically

The Company collects certain Personal Data automatically when Users access and use the Services, including usage, device, and technical data as described in Section 5.6, and data collected through Cookies and similar technologies as described in Section 16. This collection occurs through the operation of the Services, servers, and infrastructure, and through logging, analytics, and security tooling.

7.3 Personal Data received from Organizations, Institutions, and Administrators

Where a User accesses the Services as an Authorized User of an Organization or Institution, the Company may receive Personal Data relating to that User from the Organization, Institution, or relevant Administrator, including identity and contact data, role and permission assignments, and configuration data. The Company processes that Personal Data in accordance with Section 3 and the instructions of the relevant Controller. Organizations and Institutions are responsible for ensuring that they are permitted to provide such Personal Data to the Company and for providing appropriate notices to the relevant individuals.

7.4 Personal Data received through integrations and interfaces

Where a User enables an integration between the Services and a third-party service, or connects a customer-controlled data source, or uses an application programming interface, the Company may receive Personal Data through that integration, connection, or interface, as directed by the User. The Company processes that Personal Data to enable and operate the relevant integration, connection, or interface, and the role of third-party services is described in Section 18.

7.5 Personal Data received from third-party identity providers

Where a User authenticates using a third-party identity provider or single sign-on service, the Company may receive Personal Data from that provider, such as an identifier, name, and email address, to the extent necessary to authenticate the User and to establish or link the Account. The Company processes that Personal Data for authentication and Account administration.

7.6 Personal Data received from payment providers

Where a User makes a payment, the Company may receive Personal Data from its third-party payment providers, such as payment metadata, the outcome of a transaction, and partial identifiers, to enable billing, to confirm payment, and to prevent fraud. The Company does not receive or store complete payment card numbers from its payment providers.

7.7 Personal Data received through support and other interactions

The Company collects Personal Data through support interactions, sales interactions, event participation, survey responses, and other communications that Users choose to engage in. The Company processes that Personal Data to respond to and manage those interactions and for the other purposes described in Section 9.

7.8 Cookies and analytics

The Company collects Personal Data through Cookies and similar technologies and through analytics tooling, as described in Section 16. This includes data relating to how Users interact with the Services and the Company's websites, which the Company uses for necessary operation, security, preferences, performance, and, where permitted, analytics.

7.9 Future sources

As the Ecosystem evolves and new products, features, integrations, and interfaces are introduced, the Company may collect Personal Data from additional sources consistent with the categories described in this Section 7. Where the Company begins to collect Personal Data from a materially new source, it will update this Privacy Policy in accordance with Section 20 or publish a separate privacy notice.

8. How LeXi AI Uses Artificial Intelligence to Process Data

8.1 Overview of artificial intelligence processing

The Services use artificial intelligence, including machine learning models, large language models, and retrieval-augmented generation systems, to process Inputs and documents and to generate Outputs. This Section 8 describes, in general terms, how the Services process Personal Data using artificial intelligence. This Section 8 should be read together with the provisions of the Terms of Service relating to artificial intelligence, the non-provision of legal advice, and professional responsibility, which continue to apply.

8.2 How Inputs and prompts are processed

When a User submits an Input to the Services, including to an Agent, the Services process that Input in order to interpret the User's request and to generate a response. This processing may involve analyzing the text and structure of the Input, identifying the task requested, and applying the relevant model or Agent to produce an Output. Inputs may contain Personal Data, and are processed as Customer Data in accordance with Section 6.

8.3 How uploaded documents are analyzed

When a User uploads a document or directs the Services to use a document as context, the Services process that document in order to perform the requested task, such as reviewing a contract, analyzing a clause, extracting information, summarizing content, or supporting research. This processing may involve parsing the document, dividing it into segments for analysis, generating representations of its content to enable retrieval and analysis, and applying models and Agents to it. Uploaded documents may contain Personal Data and Sensitive Personal Data, and are processed as Customer Data in accordance with Section 6.

8.4 How context is used

To generate relevant Outputs, the Services may use context, including the content of the current Input, documents and materials that the User has provided or directed the Services to use, and, within a session or matter, prior Inputs and Outputs that form part of the relevant interaction. The Services use this context to produce Outputs that are responsive to the User's request. The use of context is limited to providing the Services and does not, of itself, authorize the use of Customer Data for the Company's independent purposes.

8.5 How legal and other information is retrieved

Certain features of the Services, including the Legal Research Agent and the Knowledge Retrieval Agent, retrieve information from legal and other sources in order to support research and analysis. This retrieval may involve matching a User's query against indexed sources and returning relevant material, which is then used to inform an Output. The retrieval and use of such information is subject to the accuracy limitations described in Section 8.8 and in the Terms of Service.

8.6 How Agents perform tasks

The Agents apply artificial intelligence to perform specific tasks, such as research, drafting, contract review, clause analysis, document intelligence, risk analysis, compliance analysis, workflow support, and matter management support. In performing these tasks, an Agent processes the relevant Inputs, documents, and context, and generates Outputs. The processing performed by an Agent is limited to performing the task requested and providing the Services, in accordance with this Privacy Policy.

8.7 How Outputs are generated

Outputs are generated by artificial intelligence based on the Inputs, documents, and context provided, and on the patterns learned by the underlying models. Outputs may contain Personal Data derived from the Inputs and documents provided, and are treated as Customer Data to the extent they contain Personal Data, in accordance with Section 6.

8.8 Outputs are probabilistic and may be inaccurate

Outputs are generated by artificial intelligence, are probabilistic in nature, and may be inaccurate, incomplete, outdated, or otherwise unreliable. The Services may generate Outputs that appear authoritative but that contain errors, including inaccurate statements of law, incorrect analysis, and fabricated or incorrect citations or references. Outputs are provided as decision support and must be independently reviewed and verified by a suitably qualified human, against primary and authoritative sources, before any reliance or use. The Company does not warrant the accuracy, completeness, currency, or reliability of any Output, and the responsibility for the use of Outputs rests with the User, as set out in the Terms of Service.

8.9 Automated processing and human oversight

The Services are designed to support, and not to replace, human judgment. The Company does not use the Services to make decisions producing legal or similarly significant effects concerning an individual solely on the basis of automated processing, without human involvement. Outputs are intended to be reviewed and acted upon by Users, who retain responsibility for any decision made and any action taken. Where an Organization or Institution configures or uses the Services in a manner that involves automated processing, that Organization or Institution is responsible for ensuring that its use complies with Applicable Data Protection Laws, including any requirements relating to automated decision-making and human review.

8.10 Use of data to provide and improve the Services

The Company processes Inputs, documents, Outputs, and related data to provide, secure, support, maintain, and improve the Services. Improving the Services may include analyzing usage patterns, diagnosing and fixing errors, evaluating and enhancing the quality and safety of Outputs, and developing new features. Where the Company uses Customer Data to improve the Services, it does so in a manner consistent with this Section 8, with Section 3, and with any applicable Data Processing Agreement or Enterprise Agreement.

8.11 Position on training of generally available models

The Company does not use Customer Data to train generally available artificial intelligence models in a manner that would expose that Customer Data, or content derived from it, to other customers or Users, except:
With the consent of the relevant Customer or User;
Where required or permitted by law; or
As expressly agreed in an Enterprise Agreement or Data Processing Agreement. The Company may use aggregated or de-identified data, from which individuals are not reasonably identifiable, to operate, analyze, and improve the Services and its models, provided that such data is maintained in aggregated or de-identified form and is not re-identified. Where an Enterprise Agreement or Data Processing Agreement addresses the use of Customer Data for model training or improvement, that agreement governs to the extent of any inconsistency. This Section 8.11 is consistent with the corresponding provision of the Terms of Service.

8.12 Third-party artificial intelligence models and infrastructure

To provide the Services, the Company may use third-party artificial intelligence models and artificial intelligence infrastructure providers, as described in Section 11. Where the Company does so, it processes Personal Data with those providers only to the extent necessary to provide the Services, subject to appropriate contractual and security safeguards, and in accordance with this Privacy Policy.

10. How We Share and Disclose Personal Data

10.1 General approach to sharing

The Company shares Personal Data only as described in this Privacy Policy, as permitted or required by Applicable Data Protection Laws, and, where the Company acts as a Processor, in accordance with the instructions of the relevant Controller and any applicable Data Processing Agreement. The Company does not sell Personal Data, and does not share Personal Data for cross-context behavioral advertising, as those concepts are understood under applicable United States state privacy laws. The Company imposes appropriate confidentiality and data protection obligations on the recipients of Personal Data as described in this Section 10 and in Section 11.

10.2 Service providers and Subprocessors

The Company shares Personal Data with service providers and Subprocessors that process Personal Data on the Company's behalf to provide, secure, support, and improve the Services. These include the categories of providers described in Section 11, such as cloud and hosting providers, artificial intelligence infrastructure and model providers, analytics providers, authentication providers, and payment providers. The Company engages such providers under written contracts that require them to process Personal Data only for the purposes of providing their services to the Company, to protect Personal Data with appropriate security measures, and to comply with applicable obligations under Applicable Data Protection Laws.

10.3 Enterprise Administrators and Organizations

Where a User accesses the Services as an Authorized User of an Organization, the Company shares Personal Data relating to that User's use of the Services with the Organization and its Administrators to the extent necessary to enable the Organization to administer, monitor, secure, and manage its environment, including through audit logs, usage data, and administrative controls. The Organization is the Controller of that Personal Data to the extent it determines the purposes and means of that processing, and is responsible for its use of that Personal Data, as described in Section 3 and Section 19.

10.4 Institution Administrators and Institutions

Where a User accesses LeXi AI Academy or another part of the Services as a student, faculty member, or personnel of an Institution, the Company shares Personal Data relating to that User with the Institution and its Administrators to the extent necessary to enable the Institution to administer courses, assignments, assessments, certificates, learning analytics, and its environment. The Institution is the Controller of that Personal Data to the extent it determines the purposes and means of that processing, and is responsible for its use of that Personal Data, as described in Section 3, Section 17, and Section 19.

10.5 Professional advisors

The Company may share Personal Data with its professional advisors, including legal advisors, accountants, auditors, and insurers, where necessary for the purposes of obtaining professional advice, managing risk, or establishing, exercising, or defending legal claims. The Company shares Personal Data with such advisors under obligations of confidentiality.

10.6 Government authorities and law enforcement

The Company may disclose Personal Data to courts, government authorities, regulators, and law enforcement agencies where it reasonably believes that disclosure is required or permitted by Applicable Data Protection Laws or other applicable law, or by a valid legal process, or where necessary to comply with a legal obligation, to respond to a lawful request, to establish, exercise, or defend legal claims, or to protect the rights, property, or safety of the Company, its Users, or others. Where the Company receives a request for Personal Data that it processes as a Processor on behalf of a Controller, the Company will, to the extent permitted by law, direct the request to the relevant Controller or notify the Controller, and will disclose the Personal Data only to the extent legally required.

10.7 Business transfers and successors

The Company may share or transfer Personal Data in connection with, or during negotiations concerning, a merger, acquisition, reorganization, financing, sale of assets, or other corporate transaction, or in the event of insolvency or a similar proceeding, in which case Personal Data may be transferred to a successor or acquirer as part of the transaction. The Company will require the recipient of such Personal Data to respect the terms of this Privacy Policy, or to provide a comparable level of protection, and, to the extent required by Applicable Data Protection Laws, will provide notice of any such transfer.

10.8 Affiliates

The Company may share Personal Data with its Affiliates for the purposes described in this Privacy Policy, including to provide, secure, support, and administer the Services, and for internal administrative purposes. The Company's Affiliates process Personal Data consistently with this Privacy Policy and under appropriate obligations.

10.9 With Your direction or consent

The Company may share Personal Data with third parties where a User directs it to do so, including through an integration, connection, or interface that the User enables, or where the individual otherwise consents to the sharing. The role of third-party services is described in Section 18.

10.10 Aggregated and de-identified data

The Company may share aggregated or de-identified data, from which individuals are not reasonably identifiable, for purposes such as analytics, reporting, benchmarking of the Company's own operations, and improvement of the Services, provided that such data is maintained in aggregated or de-identified form and is not re-identified.

11. Service Providers, Subprocessors, and Third-Party Artificial Intelligence Providers

11.1 Categories of service providers and Subprocessors

To provide the Services, the Company engages service providers and Subprocessors that process Personal Data on its behalf. These fall into categories including: cloud infrastructure and hosting providers, which host the Services and store data; artificial intelligence infrastructure and model providers, which provide the models and computing infrastructure used to process Inputs and generate Outputs; data storage, indexing, and retrieval providers, which support the storage and retrieval of content; analytics and monitoring providers, which support the analysis, monitoring, and performance of the Services; authentication and identity providers, which support secure access; payment providers, which process payments; communications and support providers, which support communications and customer support; and security providers, which support the security and integrity of the Services. The Company engages such providers under written contracts consistent with Section 10.2.

11.2 Third-party artificial intelligence models and infrastructure

The Services may use third-party artificial intelligence models and artificial intelligence infrastructure providers where necessary to provide the Services, including to process Inputs, analyze documents, retrieve information, and generate Outputs. The Company describes these providers by category rather than by name in this Privacy Policy, and the specific providers used may change over time as the Company develops and improves the Services. Where the Company uses such providers, it processes Personal Data with them only to the extent necessary to provide the Services, applies appropriate contractual and security safeguards, and does so in accordance with this Privacy Policy and any applicable Data Processing Agreement. The Company seeks to engage artificial intelligence providers that do not use Customer Data processed on the Company's behalf to train their own generally available models in a manner inconsistent with Section 8.11, subject to the terms agreed with each provider.

11.3 Subprocessor obligations and flow-down

Where the Company engages a Subprocessor to process Personal Data in respect of which the Company acts as a Processor, the Company imposes on the Subprocessor data protection obligations that are consistent with those applicable to the Company under the relevant Data Processing Agreement, to the extent required by Applicable Data Protection Laws, and remains responsible for the performance of the Subprocessor's obligations to the extent provided in that Data Processing Agreement.

11.4 Information about Subprocessors

Enterprise and Institution Customers may request information about the categories of Subprocessors engaged by the Company in respect of the processing of their Customer Data, and, where a Data Processing Agreement so provides, information about changes to Subprocessors, through the contacts in Section 23. The manner in which the Company provides such information, and any right to object to a new Subprocessor, is as set out in the applicable Data Processing Agreement.

12. International Data Transfers

12.1 Cross-border processing

The Company, its Affiliates, and its service providers and Subprocessors may process Personal Data in countries other than the country in which the relevant individual is located, including where the Company uses cloud infrastructure, artificial intelligence infrastructure, or support functions located in other countries. As a result, Personal Data may be transferred to, stored in, and processed in jurisdictions whose data protection laws may differ from those of the individual's own jurisdiction.

12.2 Safeguards for international transfers

Where the Company transfers Personal Data across borders and Applicable Data Protection Laws require appropriate safeguards for that transfer, the Company implements one or more appropriate safeguards or transfer mechanisms recognized under the relevant law. Depending on the jurisdictions and laws involved, these may include: the use of standard contractual clauses or equivalent contractual protections; reliance on transfers to jurisdictions recognized as providing an adequate level of protection; reliance on applicable statutory bases for transfer; and the implementation of supplementary technical, organizational, and contractual measures. Where a transfer is subject to the Digital Personal Data Protection Act, 2023, the Company effects the transfer in accordance with that Act and any restrictions or conditions imposed under it and in force from time to time.

12.3 Transfers in the context of LeXi Desk and multi-jurisdiction use

The fact that LeXi Desk supports the jurisdictions of India, the United Kingdom, and the United States relates to the substantive law to which contract-related documents may pertain, based on the User's selection, and does not, of itself, determine the country in which Personal Data is processed. The location of processing is determined by the Company's infrastructure and provider arrangements, subject to this Section 12 and to any data residency arrangements agreed in an Enterprise Agreement.

12.4 Enterprise and Institution transfer arrangements

Enterprise and Institution Customers may agree specific arrangements relating to international transfers, data residency, or the location of processing in an Enterprise Agreement or Data Processing Agreement, to the extent the Company offers such arrangements. Where such arrangements are agreed, they govern the relevant transfers to the extent set out in them.

12.5 Future international expansion

As the Company expands the Services and its infrastructure, the countries in which Personal Data is processed may change. The Company will continue to apply appropriate safeguards to international transfers in accordance with this Section 12 and Applicable Data Protection Laws, and will update this Privacy Policy in accordance with Section 20 where required.

12.6 Requesting information about transfers

Individuals may request further information about the safeguards that the Company applies to international transfers of their Personal Data, and, where applicable, a copy of the relevant safeguards, through the contacts in Section 23, subject to the protection of confidential and commercially sensitive information and the rights of third parties.

13. Data Retention

13.1 Retention principles

The Company retains Personal Data for as long as necessary to fulfill the purposes for which it was collected and processed, as described in this Privacy Policy, and thereafter for such additional period as is necessary or permitted, taking into account:
The duration of the relationship with the User and the provision of the Services;
The instructions and configuration of the relevant Organization or Institution, where the Company acts as a Processor;
The Company's legal, regulatory, tax, and accounting obligations;
The need to establish, exercise, or defend legal claims and to resolve disputes;
Operational and security needs, including the maintenance of backups and the integrity of the Services; and
Requests by Users and Data Principals to delete Personal Data, subject to applicable exceptions. Different categories of Personal Data are retained for different periods according to these principles.

13.2 Retention of Customer Data, documents, and matter content

Where the Company acts as a Processor, Customer Data, including uploaded documents, Workspace content, matter records, litigation files, contract materials, and research history, is retained for the duration of the relevant subscription or engagement and in accordance with the instructions, configuration, and retention settings of the relevant Organization, Institution, or Customer, and any applicable Data Processing Agreement. On termination or expiry, such Customer Data is handled as described in Section 13.7 and in the Terms of Service.

13.3 Retention of Account and profile data

Account and profile data is retained for the duration of the Account and for a reasonable period thereafter to enable the Company to administer the closure of the Account, to comply with legal obligations, and to establish, exercise, or defend legal claims.

13.4 Retention of billing and transaction records

Billing, invoice, tax, and transaction records are retained for the periods required by applicable tax, accounting, and other legal obligations, which may extend beyond the termination of the Account or subscription.

13.5 Retention of support and communications records

Support requests, communications history, and related records are retained for a period reasonably necessary to provide and improve support, to maintain a record of interactions, and to comply with legal obligations.

13.6 Retention of logs, security, and audit data

Audit logs, security logs, authentication logs, and related records are retained for the periods reasonably necessary to secure the Services, to detect and investigate incidents and misuse, to maintain the integrity of the Services, and to comply with legal obligations. Retention periods for logs are set having regard to security and operational considerations.

13.7 Deletion on termination and on request

On termination or expiry of the relevant Account, subscription, or engagement, the Company handles Customer Data in accordance with the Terms of Service and, where applicable, the relevant Data Processing Agreement, which may provide for the return or deletion of Customer Data within a defined period, subject to routine backups and legal retention requirements. Users are responsible for exporting Customer Data that they wish to retain before termination or expiry. Where an individual exercises a right to deletion under Applicable Data Protection Laws, the Company gives effect to that right in accordance with Section 15, subject to the exceptions and limitations described there and to applicable retention obligations.

13.8 Backups

The Company maintains backups of data for resilience, continuity, and disaster recovery purposes. Personal Data that has been deleted from active systems may persist in backups for a limited period until the backups are overwritten or expire in the ordinary course, after which it is no longer available. During that period, backups are subject to the security measures described in Section 14.

13.9 De-identified and aggregated data

The Company may retain aggregated or de-identified data, from which individuals are not reasonably identifiable, for longer periods, for the purposes described in Section 8.11 and Section 10.10, provided that such data is maintained in aggregated or de-identified form and is not re-identified.

13.10 Enterprise and Institution retention arrangements

Enterprise and Institution Customers may agree specific retention arrangements in an Enterprise Agreement or Data Processing Agreement, to the extent the Company offers such arrangements. Where such arrangements are agreed, they govern the retention of the relevant Personal Data to the extent set out in them.

14. Information Security

14.1 Security program

The Company maintains a security program that includes technical and organizational measures designed to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, and disclosure, having regard to the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing, and the risks to individuals. This Section 14 describes categories of measures that the Company applies; the specific measures may evolve as the Services and the threat environment develop.

14.2 Encryption

The Company applies encryption to Personal Data in transit over public networks and to Personal Data at rest, using industry-accepted cryptographic methods, as part of its measures to protect the confidentiality and integrity of data.

14.3 Access controls and least privilege

The Company applies access controls designed to restrict access to Personal Data to authorized personnel and systems that require access for the purposes described in this Privacy Policy. The Company applies the principle of least privilege, role-based access controls, and administrative controls, and restricts and monitors privileged access.

14.4 Authentication

The Company applies authentication measures to protect access to the Services and to internal systems, and supports authentication mechanisms for Users, including, where offered, multi-factor authentication and single sign-on.

14.5 Logging and monitoring

The Company maintains logging and monitoring of relevant systems and activity to detect, investigate, and respond to security events, misuse, and anomalies, and to support the integrity and availability of the Services.

14.6 Incident response and breach notification

The Company maintains an incident response capability designed to identify, assess, contain, remediate, and, where appropriate, notify security incidents affecting Personal Data. Where the Company becomes aware of a personal data breach affecting Personal Data for which it is responsible, it will act in accordance with Applicable Data Protection Laws, which may include notifying the relevant supervisory or regulatory authority and affected individuals within applicable timeframes. Where the Company acts as a Processor, it will notify the relevant Controller of a personal data breach affecting the Controller's Personal Data without undue delay after becoming aware of it, and will provide reasonable assistance to the Controller in meeting the Controller's own notification obligations, as further set out in any applicable Data Processing Agreement.

14.7 Backups and resilience

The Company maintains backups and resilience measures designed to support the availability, continuity, and recoverability of the Services and of Personal Data, as described in Section 13.8.

14.8 Organizational and personnel measures

The Company applies organizational security measures, including policies and procedures relating to information security, obligations of confidentiality on personnel who have access to Personal Data, security awareness, and controls relating to the engagement and oversight of service providers and Subprocessors.

14.9 Secure development and change management

The Company applies measures relating to the secure development, testing, and change management of the Services, designed to address security throughout the lifecycle of the Services.

14.10 Shared responsibility and no absolute security

Security is a shared responsibility. Users, Organizations, and Institutions are responsible for their own security practices, including safeguarding credentials, configuring permissions and access appropriately, managing their Authorized Users, and using the security features made available by the Services. No method of transmission, storage, or processing is completely secure, and the Company does not and cannot guarantee that Personal Data will be absolutely secure. The Company's obligations in respect of security are as set out in this Privacy Policy, the Terms of Service, and any applicable Data Processing Agreement.

15. Your Privacy Rights and Choices

15.1 Overview of rights

Depending on the individual's location and the Applicable Data Protection Laws, and subject to the conditions, exceptions, and limitations in those laws, individuals may have rights in respect of their Personal Data, including the rights described in this Section 15. This Section 15 describes these rights in general terms; the specific rights available to a given individual, and the conditions attaching to them, are determined by the Applicable Data Protection Laws, and region-specific rights are addressed in Section 22.

15.2 Right of access

Individuals may have the right to obtain confirmation as to whether the Company processes Personal Data about them, to access that Personal Data, and to obtain certain information about the processing, including the purposes of the processing and the recipients or categories of recipients to whom the Personal Data has been disclosed.

15.3 Right to correction

Individuals may have the right to obtain the correction of inaccurate Personal Data, and the completion of incomplete Personal Data, concerning them.

15.4 Right to deletion or erasure

Individuals may have the right to obtain the deletion or erasure of their Personal Data in certain circumstances, subject to exceptions, including where the Company is required or permitted to retain the Personal Data to comply with a legal obligation, to establish, exercise, or defend legal claims, or for other purposes permitted by Applicable Data Protection Laws.

15.5 Right to data portability

Individuals may have the right, in certain circumstances, to receive certain Personal Data that they have provided to the Company in a structured, commonly used, and machine-readable format, and to have that Personal Data transmitted to another controller where technically feasible.

15.6 Rights to restriction and objection

Individuals may have the right, in certain circumstances, to restrict the processing of their Personal Data, and to object to processing that is based on the Company's legitimate interests or that is carried out for direct marketing purposes. Where an individual objects to processing for direct marketing, the Company will cease processing the Personal Data for that purpose.

15.7 Rights in respect of Customer Data processed as a Processor

Where the Company processes Personal Data as a Processor on behalf of an Organization, Institution, or other Controller, an individual who wishes to exercise rights in respect of that Personal Data should generally direct the request to the relevant Controller, which is responsible for responding to it. Where the Company receives such a request directly, it will, to the extent required and permitted, direct the individual to the relevant Controller or forward the request to the Controller, and will provide reasonable assistance to the Controller in responding to the request, as further set out in any applicable Data Processing Agreement.

15.8 Withdrawal of consent

Where the Company relies on consent to process Personal Data, the individual may withdraw that consent at any time, without affecting the lawfulness of processing carried out before the withdrawal. The withdrawal of consent may affect the availability of certain features or Services that depend on that consent.

15.9 Marketing preferences

Individuals may opt out of receiving marketing communications from the Company at any time, by using the unsubscribe mechanism included in such communications or by contacting the Company through the contacts in Section 23. The Company may continue to send non-marketing communications relating to the Services, such as service, security, and transactional communications.

15.10 Cookie preferences

Individuals may manage their preferences in respect of Cookies and similar technologies as described in Section 16.

15.11 Account closure

Users may close their Account, subject to any committed subscription term and to the provisions of the Terms of Service. Where a User accesses the Services as an Authorized User of an Organization or Institution, the closure or de-provisioning of that User's access may be managed by the relevant Administrator.

15.12 How to exercise rights

Individuals may exercise their rights, where available, by contacting the Company through the contacts in Section 23, or, where provided, through in-product controls. To protect Personal Data, the Company may need to verify the identity of the individual making a request before acting on it, and may request additional information for that purpose. The Company will respond to requests within the timeframes required by Applicable Data Protection Laws.

15.13 No fee and exceptions

The Company does not generally charge a fee for individuals to exercise their rights, except where permitted by Applicable Data Protection Laws, for example where a request is manifestly unfounded or excessive. The Company may decline to act on a request, in whole or in part, where an exception or limitation under Applicable Data Protection Laws applies, in which case it will inform the individual of the reason to the extent required.

15.14 Appeals and complaints

Where an individual is dissatisfied with the Company's response to a request or with the Company's processing of Personal Data, the individual may appeal or complain to the Company through the contacts in Section 23, including to the Grievance Officer where applicable. Individuals also have the right to lodge a complaint with the relevant supervisory or regulatory authority under Applicable Data Protection Laws, as described in Section 22 and Section 23.

16. Cookies and Similar Technologies

16.1 Use of Cookies

The Company and its service providers use Cookies and similar technologies on the Company's websites and, where applicable, within the Services, to operate and secure the Services, to remember preferences, to analyze usage, and to improve the Services. This Section 16 describes the categories of Cookies used and the choices available to individuals.

16.2 Necessary and authentication Cookies

The Company uses necessary Cookies that are essential to operate the Services and the Company's websites, including authentication Cookies that enable Users to sign in and remain signed in, and Cookies that support core functionality. Because these Cookies are necessary to provide the Services, they cannot be disabled through the Company's Cookie controls without affecting the operation of the Services.

16.3 Security Cookies

The Company uses security Cookies to support the security and integrity of the Services and the Company's websites, including to detect and prevent fraud and misuse and to protect Users.

16.4 Preference Cookies

The Company uses preference Cookies to remember choices and settings, such as language and locale, in order to provide a more consistent experience.

16.5 Analytics and performance Cookies

The Company uses analytics and performance Cookies, where permitted, to understand how the Services and the Company's websites are used, to measure and improve performance, and to develop and improve features. Where required by Applicable Data Protection Laws, the Company obtains consent before using non-essential analytics and performance Cookies.

16.6 Future Cookies

The Company may use additional Cookies and similar technologies as the Services and the Company's websites evolve, consistent with the categories described in this Section 16 and with Applicable Data Protection Laws.

16.7 Cookie controls and browser controls

Individuals can manage their preferences in respect of non-essential Cookies through the Cookie controls that the Company provides, where applicable, and through their browser and device settings, which can be configured to block or delete Cookies. Disabling certain Cookies may affect the functionality and performance of the Services and the Company's websites. Some browsers offer a "Do Not Track" or similar signal; the Company responds to recognized preference signals to the extent required by Applicable Data Protection Laws.

17. Children's and Students' Privacy

17.1 Minimum age and intended users

The Services are intended for use by professionals and, in the case of LeXi AI Academy, by students, faculty, and personnel of Institutions. The Services are not directed to, and the Company does not knowingly collect Personal Data directly from, children below the minimum age required to use the Services in their jurisdiction, except through, and under the responsibility of, an Institution as described in this Section 17. Except as provided in Section 17.2, Users must be at least eighteen (18) years of age, or the age of majority in their jurisdiction, to use the Services in an individual capacity.

17.2 Institution-managed student accounts

Where LeXi AI Academy or another part of the Services is made available to students through an Institution, students may use the Services under accounts provisioned and managed by the Institution. In these circumstances, the Institution is the Controller of the students' Personal Data and is responsible for:
Establishing the lawful basis for the processing of students' Personal Data;
Providing appropriate privacy notices to students and, where required, to their parents or guardians; and
Obtaining and maintaining any consents or authorizations required under Applicable Data Protection Laws, including verifiable parental or guardian consent where a student is below the age at which the student can provide consent on the student's own behalf. The Company processes students' Personal Data as a Processor, on the instructions of the Institution, in accordance with Section 3 and Section 19.

17.3 Children under Applicable Data Protection Laws

Certain Applicable Data Protection Laws, including the Digital Personal Data Protection Act, 2023, treat all individuals below a specified age as children and require verifiable consent of a parent or lawful guardian, and impose restrictions on certain processing, in respect of children. Where the Services are used in a manner that involves the Personal Data of children within the meaning of the Applicable Data Protection Laws, the relevant Controller, including an Institution or a parent or guardian as applicable, is responsible for ensuring that the applicable requirements are met, and the Company processes such Personal Data in accordance with its role as described in Section 3 and with the applicable requirements. The Company does not undertake processing of children's Personal Data that is likely to cause a detrimental effect on the well-being of a child, and does not undertake tracking, behavioral monitoring, or targeted advertising directed at children, in each case as prohibited by Applicable Data Protection Laws.

17.4 Removal of children's Personal Data

If the Company becomes aware that it has collected Personal Data directly from a child in circumstances that do not comply with Applicable Data Protection Laws and outside the responsibility of an Institution, parent, or guardian, it will take steps to delete that Personal Data. Parents, guardians, and Institutions may contact the Company through the contacts in Section 23 in relation to the Personal Data of a child.

19. Enterprise, Institution, and Administrator Controls

19.1 Organization and Institution control

Where the Services are used within an Organization or Institution, the Organization or Institution controls its environment on the Services and determines how the Services are used within that environment, including the provisioning and de-provisioning of Authorized Users, the configuration of Workspaces, roles, and permissions, and, where available, retention and other settings. The Organization or Institution is the Controller of the Customer Data processed within its environment and of Personal Data relating to its Authorized Users to the extent it determines the purposes and means of that processing, as described in Section 3.

19.2 Administrator visibility and actions

Administrators may have the ability to access, monitor, manage, export, and delete data and content within their Organization's or Institution's environment, to configure security and access settings, to view audit logs and usage data, and to manage Authorized Users. Authorized Users should be aware that their use of the Services within an Organization's or Institution's environment is subject to the control and visibility of the relevant Administrators, in accordance with the policies of the Organization or Institution. Administrator actions are actions of the Organization or Institution as Controller, and the Company is not responsible for the manner in which an Administrator exercises these controls.

19.3 Responsibilities of Organizations and Institutions

Organizations and Institutions are responsible for their use of the administrative controls made available by the Services, for providing appropriate privacy notices to their Authorized Users, students, faculty, personnel, and other Data Principals, for obtaining and maintaining any required consents and authorizations, and for configuring the Services in a manner consistent with their obligations under Applicable Data Protection Laws, as described in Section 3.

19.4 Rights of Authorized Users

Authorized Users who wish to exercise privacy rights in respect of Personal Data processed within an Organization's or Institution's environment should generally direct their requests to the relevant Organization or Institution as the Controller, as described in Section 15.7. The Company will provide reasonable assistance to the Controller in responding to such requests, as further set out in any applicable Data Processing Agreement.

19.5 Data Processing Agreements

Enterprise and Institution Customers may enter into a Data Processing Agreement with the Company as described in Section 3.6. Where a Data Processing Agreement is in place, it governs the processing of Personal Data by the Company on behalf of the Customer to the extent set out in it.

20. Changes to This Privacy Policy

20.1 Updates to this Privacy Policy

The Company may update this Privacy Policy from time to time to reflect changes in the Services, in the Company's data practices, in Applicable Data Protection Laws, or for other legitimate reasons. When the Company updates this Privacy Policy, it will revise the version and the date at the beginning of this Privacy Policy.

20.2 Notice of material changes

Where a change to this Privacy Policy is material, the Company will provide notice through the Services, by email, or by other appropriate means, and, where required by Applicable Data Protection Laws, will obtain consent or provide an opportunity to object. The manner and timing of notice will be consistent with the corresponding provision of the Terms of Service relating to changes.

20.3 Continued use

Except where Applicable Data Protection Laws require consent, an individual's continued use of the Services after the effective date of an updated Privacy Policy constitutes acknowledgment of the updated Privacy Policy. Where consent is required, the relevant processing will be carried out on the basis of consent obtained in accordance with Applicable Data Protection Laws.

20.4 Prior versions

The version of this Privacy Policy in force at the time Personal Data is processed governs that processing, subject to Applicable Data Protection Laws and to any separately executed Data Processing Agreement or Enterprise Agreement.

21. Future Products, Agents, Application Programming Interfaces, and Modules

21.1 Continuity of privacy governance

Consistent with Section 4.8, any new product, module, Agent, application programming interface, feature, integration, or service that the Company introduces under the "LeXi AI" name and marks is automatically governed by this Privacy Policy, and the provisions of this Privacy Policy apply to it, unless and until the Company publishes a separate privacy notice for it or issues Supplemental Terms that address its processing.

21.2 Updates for new processing

Where a new product, module, Agent, application programming interface, feature, integration, or service involves categories of Personal Data, sources, purposes, or recipients that are not adequately described by this Privacy Policy, the Company will update this Privacy Policy in accordance with Section 20, or publish a separate privacy notice, before or at the time it begins the relevant processing, to the extent required by Applicable Data Protection Laws.

21.3 Relationship with the Terms of Service

This Section 21 operates consistently with the corresponding future-proofing provision of the Terms of Service, so that the extension of the Ecosystem is governed by a coherent framework across both the Terms of Service and this Privacy Policy.

23. Grievance Redressal, Data Protection Contacts, and How to Reach Us

23.1 The Company

The Services are provided by Astute Lex Servicado Private Limited, a company incorporated under the Companies Act, 2013 of India, which operates the LeXi AI Ecosystem. The Company's details are:Astute Lex Servicado Private Limited Product: LeXi AI Corporate Identification Number (CIN): U74999PB2022PTC056982 Registered office: H/no 681A, W/no 11, Green Avenue Colony Bathwala Road Gurdaspur, Punjab, India 143521

23.2 Privacy and data protection contact

For questions, requests, or concerns relating to this Privacy Policy or to the Company's processing of Personal Data, including to exercise the rights described in Section 15, individuals may contact the Company at:Email: ceo@lexiai.legal

23.3 Enterprise, Institution, and administrative contacts

Enterprise and Institution Customers may use the contacts set out in their Enterprise Agreement, Data Processing Agreement, or Order Form for matters relating to the processing of Personal Data, including requests for a Data Processing Agreement or information about Subprocessors, and may otherwise contact the Company through the contacts in this Section 23.