Who we are
Lexi is a writing platform built by Lexi d.o.o., registered in Zagreb, Croatia. For the purposes of the GDPR, Lexi acts as a data controller for the data we collect about our own website visitors and account holders, and as a data processor for the content our business customers put into the product.
If you are an employee of a company that uses Lexi, your employer is the controller of the content you write in the product. This policy explains what we do with it on their behalf.
What we collect
| Category | Examples |
|---|---|
| Account data | Name, work email, company, role, password hash. |
| Customer content | Briefs, customer messages, and drafts you write or paste into Lexi. |
| Usage data | Which features you used, when, and from which browser and country. |
| Support data | Emails and messages you send us, plus anything you attach. |
| Website data | Pages visited, referrer, approximate location from IP. |
We do not ask for, and do not want, special category data: health records, biometric data, political views, or anything comparable. Please keep it out of the product.
Why we process it
- To run the productGenerating drafts, scoring text, and keeping your workspace available. Legal basis: performance of a contract.
- To keep it secureDetecting abuse, debugging failures, and maintaining audit logs. Legal basis: legitimate interest.
- To improve itUnderstanding which features get used, in aggregate. Legal basis: legitimate interest, or your consent where cookies are involved.
- To talk to youAnswering support requests and sending service notices. Legal basis: contract, or consent for marketing email.
- To meet legal dutiesAccounting records and lawful requests from authorities. Legal basis: legal obligation.
Customer content
Everything you write or paste into Lexi belongs to your company, not to us. It is stored in the EU, kept isolated per tenant, and accessible only to the people your administrator has authorised.
Our engineers can access customer content only when you ask us to investigate a specific problem, under a logged, time-limited access grant. We do not browse it otherwise.
Model training
Your content is never used to train another company's Lexi. Lexi's writing models are built on our own corpus of texts written by our copywriters and psychologists. Your data does not enter that corpus, and it does not improve any other customer's output.
If your company chooses to have Lexi trained on your own brand materials, that training is scoped to your tenant alone and covered by a separate agreement.
How long we keep it
| Data | Retention |
|---|---|
| Customer content | For the life of your contract, then deleted within 30 days of termination. |
| Account data | For the life of your account, then deleted within 30 days. |
| Audit logs | 12 months. |
| Invoices | As required by Croatian accounting law. |
Your rights
Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or port it elsewhere. You can also object to processing based on legitimate interest, and withdraw consent at any time.
Write to privacy@lexi.hr and we will respond within 30 days. If you are unhappy with our answer, you can complain to the Croatian Personal Data Protection Agency (AZOP).
Security
Data is encrypted in transit and at rest, access is role-based and logged, and infrastructure sits in EU regions. For the detail on architecture, isolation, and compliance, see our Trust page.
Contact
Questions about this policy, or about your data: privacy@lexi.hr. Anything else: hi@lexi.hr.
Lexi d.o.o., Zagreb, Croatia.

