LexiMeld — Privacy Policy For the LexiMeld software and related online services Version: 2.1 · Effective: 2026-10-08 This English text is a translation. In case of any discrepancy, the Hungarian version prevails. ──────────────────────────────────────── 1. Introductory provisions ──────────────────────────────────────── 1.1. This privacy policy (hereinafter: the "Policy") contains the essential information on the processing of personal data related to the LexiMeld software operated by 1i2s E-Commerce LLC and the related online services, including the https://leximeld.app website and the trial (demo) feature available there. 1.2. The Policy covers natural person users located in the European Union or the European Economic Area, the natural person representatives, contact persons and staff of business users, and natural persons whose personal data is transmitted to the Controller through use of the Service. 1.3. The Controller processes personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: "GDPR") and the applicable national data protection laws. ──────────────────────────────────────── 2. Controller details ──────────────────────────────────────── | Item | Details | |------|---------| | Controller | 1i2s E-Commerce LLC | | Registered office | 30 N Gould St, Suite 24294, Sheridan, Wyoming 82801, United States of America | | Registration number | Wyoming Filing ID: 2019-000856017 | | US tax ID | EIN: 32-0604244 | | Electronic contact | info@leximeld.app | | Website | https://leximeld.app | | EU representative under Article 27 GDPR | [TO BE COMPLETED BEFORE PUBLICATION: name, postal address and electronic contact] | Data subjects may send requests related to data processing to info@leximeld.app or to the contact details of the EU representative under Article 27 GDPR indicated above. ──────────────────────────────────────── 3. Subject matter of processing and controller roles ──────────────────────────────────────── 3.1. The Controller acts as an independent controller with respect to its own records related to concluding contracts, orders, licence and entitlement management, payment and invoicing, service security, abuse prevention, customer support, complaint handling and the handling of legal claims. 3.2. During local processing carried out solely on the user's device, without transmission to the Controller or to a third party, the Controller has no access to the processed content. The Controller's processing does not extend to such content unless the user transmits it to the Controller in a support request, bug report or other action. 3.3. When a feature that uses external infrastructure is used, the audio recording, text, instruction, settings and technical data necessary to perform the operation may be transmitted to the systems of the Controller or of the provider used. 3.4. With respect to personal data processed by a business user through the Service for its own processing purposes, the business user is the controller and 1i2s E-Commerce LLC is the processor, provided that the latter processes the data solely on the business user's documented instructions. The terms of such processing are governed by a separate data processing agreement complying with Article 28 GDPR. 1i2s E-Commerce LLC acts as an independent controller with respect to contractual, account, licence, entitlement, billing, service security and legal compliance data. ──────────────────────────────────────── 4. Individual processing operations ──────────────────────────────────────── | Purpose of processing | Data processed | Legal basis | Retention period | |-----------------------|----------------|-------------|------------------| | Concluding contracts, orders and recording contractual statements | name or user identifier; e-mail address; order data; version of the accepted terms; time of the statement; licence and machine identifier of the device making the statement, and the language and version of the Software | Article 6(1)(b) GDPR | for the term of the contract, then until the limitation period for applicable civil law claims expires | | Licence and entitlement management | licence or entitlement identifier; package; entitlement status; where necessary, device or installation identifier (machine identifier) | Article 6(1)(b) GDPR | for the term of the entitlement, then until contractual claims are time-barred; data processed for security purposes for the shorter period necessary for that purpose | | Providing a trial or free access | e-mail address; device or installation identifier, including the hardware identifier hash (a one-way, non-reversible value derived from the serial numbers of the motherboard, BIOS and hard disk and from the Windows installation ID – we do not process the serial numbers themselves); start and end time of the trial; the fact of a previous trial | Article 6(1)(b) GDPR; for abuse prevention, point (f) | for the duration of the trial; the hardware identifier hash and the fact of a previous trial also after the trial expires, for as long as necessary to prevent repeated trials (for up to 24 months from the end of the trial period) | | Payment, recurring charges and invoicing | billing name and address; e-mail address; customer, transaction and invoice identifiers; limited metadata of the payment method; charge and cancellation status; for business buyers, the EU VAT identification number provided and the result of its VIES check; data needed to determine the place of supply for VAT (country of the billing address, country derived from the IP address, issuing country of the payment card) | Article 6(1)(b) and (c) GDPR | for the term of the contract and until the end of the applicable accounting, tax and claims enforcement periods; records kept under the EU VAT One Stop Shop (OSS) scheme: 10 years from the end of the year of the transaction | | Providing external AI, speech recognition or text processing features | audio recording; text; instruction; language and technical settings; technical metadata necessary for the operation | Article 6(1)(b) GDPR; for special categories of personal data, the additional condition set out in section 8 | the time necessary to complete the operation; the duration of technical logs, temporary storage and provider caches | | Service security, quota management and abuse prevention | user or licence identifier; time; IP address, if logged (as a one-way hash for rate limiting); number of calls; API route; error code; security event | Article 6(1)(f) GDPR; legitimate interest: ensuring the security, availability and proper use of the Service | for the period necessary for the security purpose, as defined per log type; counters containing the IP address hash for up to 90 days | | In-app messages (Chapter 19 of the End User Agreement) | licence and machine identifier; package; status and expiry of the trial or subscription; the fact and time of displaying and acknowledging a message; the fact and time of opting out of offers | for service messages, Article 6(1)(b) GDPR; for LexiMeld's own offers, point (f) – legitimate interest: informing existing users about the Controller's own product | for the term of the entitlement; display and acknowledgement data for the period necessary for operation | | Referral (affiliate) programme: linking a click on a referral link on the website with the subsequent installation | referrer identifier; time of the click; one-way hash of the IP address of the clicking and the installing device (we do not store the raw IP address); licence or device identifier of the installation | Article 6(1)(f) GDPR; legitimate interest: operating the referral programme, settling rewards and preventing abuse | click data for up to 90 days (linking can take place within 30 minutes of the click); the result of the linking for the term of the entitlement and until rewards are settled | | Website trial feature (demo) | audio sample recorded by the visitor; the resulting text and AI Output; technical data of bot filtering (Cloudflare Turnstile); one-way hash of the IP address for rate limiting | Article 6(1)(b) GDPR (at the data subject's request, prior to entering into a contract); for bot filtering and rate limiting, point (f) | the Controller does not store the audio sample, the text or the AI Output; they are processed only for the time necessary to complete the operation; the usage counter containing the IP address hash for up to 90 days | | Reviews | star rating; written review; licence, customer and support identifiers; result of the automated (AI-based) pre-screening of the review; time of publication, if published | Article 6(1)(f) GDPR; legitimate interest: improving the Service and moderating reviews; for anonymous publication on the website, point (a) (consent given by submitting the review) | for the term of the entitlement; a published review until consent is withdrawn | | Customer support, complaint handling and business enquiries | name; e-mail address; company name and phone number (for business enquiries); content of the request; attachment; case identifier; one-way hash of the IP address for abuse prevention; technical data necessary for the investigation | Article 6(1)(b), (c) or (f) GDPR, depending on the subject of the request | until the case is closed, then until the end of the applicable mandatory retention and claims enforcement periods | | Enforcing legal claims or complying with legal obligations | contractual, transactional, communication and log data necessary to assess the matter | Article 6(1)(c) or (f) GDPR | for the duration of the legal obligation or proceedings, or until the related claim is time-barred | ──────────────────────────────────────── 5. Processing based on legitimate interest ──────────────────────────────────────── 5.1. Where processing is based on Article 6(1)(f) GDPR, the Controller carries out a balancing test before starting the processing. The legitimate interest may in particular be the interest in protecting the security of the Service and IT systems, preventing unauthorised access, abuse and fraud, and establishing, exercising and defending legal claims. 5.2. The data subject may object to processing based on legitimate interest under Article 21 GDPR. In the event of an objection, the Controller no longer processes the personal data unless it demonstrates compelling legitimate grounds that override the interests, rights and freedoms of the data subject, or the processing relates to the establishment, exercise or defence of legal claims. ──────────────────────────────────────── 6. Source of the data and nature of the provision of data ──────────────────────────────────────── 6.1. As a rule, the source of the personal data is the data subject. The Controller may also receive payment, transaction and entitlement metadata from a payment service provider or a sales partner. 6.2. Providing the personal data necessary to conclude and perform the contract is a contractual requirement. Without such data, the order, payment, licence and entitlement management, or the external feature requested by the data subject cannot be provided. ──────────────────────────────────────── 7. Recipients and processors ──────────────────────────────────────── 7.1. The Controller makes personal data available only to persons with appropriate access rights for the performance of their tasks and to the following categories of recipients: | Recipient or category of recipients | Role in the processing | Data concerned | |-------------------------------------|------------------------|----------------| | Google Cloud Platform and the Google Cloud services actually used | cloud infrastructure, backend, database, API and logging services; processor, depending on the service used | account, technical, log and content data necessary to operate the service | | Google Vertex AI / Gemini, if the user uses such a feature | external AI and text processing service; processor, depending on the configuration used | audio, text, instruction and technical metadata necessary for the operation | | Stripe, if used in the payment process | payment and transaction service; processor or independent controller depending on the operation | billing, customer, transaction and payment data, including the EU VAT identification number and the data needed to determine VAT; Stripe checks the EU VAT identification number in the European Commission's VIES system | | Cloudflare, Inc. (Turnstile) | bot filtering for the website demo (the service starts when the website loads); processor, depending on the configuration used | technical data of the browser and device necessary for bot filtering, IP address | | Hostinger International Ltd. | hosting of the https://leximeld.app website and e-mail services; processor | technical data necessary to serve the website (for example IP address in server logs); contact data and messages | | E-mail and customer support service providers | communication, customer support case management | contact data, messages, attachments and case data | | Authorities, courts, legal and other professional advisers | compliance with legal obligations, establishing, exercising or defending legal claims | personal data necessary for the given proceedings | 7.2. The Controller engages processors only under a contract that meets the requirements of Article 28 GDPR. A processor may process personal data only on the Controller's documented instructions and for the purpose set out in the contract. ──────────────────────────────────────── 8. Special categories of personal data and audio recordings ──────────────────────────────────────── 8.1. The content of an audio recording or text provided by the user may also contain special categories of personal data. Processing of special categories of personal data is lawful only if, in addition to an appropriate legal basis under Article 6 GDPR, one of the conditions set out in Article 9(2) GDPR is also met. 8.2. It is the responsibility of the data subject or the business user to transmit personal data relating to third parties, in particular special categories of personal data, to the Service only if they have an appropriate legal basis and have properly informed the data subject. 8.3. Processing an audio recording does not in itself constitute processing of biometric data. Biometric processing takes place where the purpose or result of specific technical processing of the audio recording is the unique identification of a natural person or confirmation of their identity. The intended use of LexiMeld is not aimed at voice-based identification. ──────────────────────────────────────── 9. Transfers to third countries ──────────────────────────────────────── 9.1. The Controller has its registered office in the United States of America. Transfers from the EU/EEA to the Controller or to other recipients outside the EU/EEA are subject to the provisions of Chapter V GDPR. 9.2. Personal data is transferred to third countries only where the conditions set out in Chapter V GDPR are met. Transfers to a recipient validly certified under the EU–US Data Privacy Framework may be based on the adequacy decision under Article 45 GDPR. For other recipients, the Controller applies appropriate safeguards under Article 46 GDPR, in particular the standard contractual clauses adopted by the European Commission and, where necessary, supplementary technical and organisational measures. 9.3. The data subject may request further information at the Controller's contact details given in section 2 on the legal basis for the transfer, the appropriate safeguards and the means of obtaining a copy of them or where they have been made available. ──────────────────────────────────────── 10. Retention of data ──────────────────────────────────────── 10.1. The Controller retains personal data for the periods set out in section 4, or on the basis of the criteria set out there. Where the same data relates to several processing purposes, it may be processed until the longest applicable retention period expires, after which it must be deleted or anonymised. 10.2. The user decides on the deletion of content stored solely on their own device. The Controller has no access to such content and is not obliged to restore it. 10.3. The duration of temporary storage, caching and security logging in the systems of external providers is determined by the contractual terms and technical settings applicable to the given provider. The Controller uses these services in a configuration that complies with the principles of data minimisation and storage limitation. ──────────────────────────────────────── 11. Service and marketing communications ──────────────────────────────────────── 11.1. The Controller may send or display messages related to the operation, security, entitlement status, updates or material changes of the Service for the performance of the contract or to comply with its legal obligations. 11.2. Electronic communications for direct marketing or other marketing purposes may take place only with the data subject's prior consent. The data subject may withdraw consent at any time without affecting the lawfulness of processing before the withdrawal. 11.3. Messages related to LexiMeld displayed in the Software – including LexiMeld's own offers – form part of the Service under Chapter 19 of the End User Agreement; the legal basis set out in section 4 applies to them, not section 11.2. To select these messages, the Controller uses only licence and subscription data, never the content dictated or processed by the user. The data subject may object at any time, under Article 21(2) GDPR, to processing related to LexiMeld's own offers: with the "Do not show me offers in the app" checkbox on the acceptance screen of the Software or under Settings → Legal documents, or by writing to info@leximeld.app. Following an objection, the Controller does not display messages containing offers; service messages and personal messages from customer support continue to be displayed. ──────────────────────────────────────── 12. Automated decision-making and profiling ──────────────────────────────────────── 12.1. Using the personal data covered by this Policy, the Controller does not carry out decision-making based solely on automated processing that produces legal effects concerning the data subject or similarly significantly affects them within the meaning of Article 22(1) GDPR. ──────────────────────────────────────── 13. Data security ──────────────────────────────────────── 13.1. Having regard to Article 5(1)(f) and Articles 24, 25 and 32 GDPR, the Controller ensures the security of personal data with technical and organisational measures proportionate to the risks of the processing. 13.2. The measures applied cover in particular the regulation of access rights, security of transmission, logging, vulnerability and incident management, data minimisation and, where necessary, backup and recovery. 13.3. The Controller notifies personal data breaches to the competent supervisory authority and communicates them to the data subject under the conditions set out in Articles 33 and 34 GDPR. ──────────────────────────────────────── 14. Rights of the data subject ──────────────────────────────────────── 14.1. Under the conditions set out in the GDPR, the data subject has the right: • to request information on and access to their personal data; • to request the rectification of inaccurate personal data or the completion of incomplete personal data; • to request the erasure of personal data or restriction of processing; • to object to processing based on legitimate interest; • to withdraw consent at any time without affecting the lawfulness of processing before the withdrawal; • to receive the personal data concerning them that they have provided in a structured, commonly used and machine-readable format, or to have it transmitted to another controller, where the conditions of Article 20 GDPR are met; • to the protection set out in Article 22 GDPR against automated individual decision-making; • to lodge a complaint with a supervisory authority and to seek a judicial remedy. 14.2. The Controller responds to a data subject request without undue delay and in any event within one month of its receipt. In the cases set out in Article 12(3) GDPR, this period may be extended by two further months; the Controller informs the data subject of the extension and the reasons for it within the original one-month period. 14.3. Exercising data subject rights is, as a rule, free of charge. Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, the Controller may charge a reasonable fee or refuse to act on the request under Article 12(5) GDPR. ──────────────────────────────────────── 15. Remedies ──────────────────────────────────────── 15.1. Under Article 77 GDPR, the data subject has the right to lodge a complaint, in particular with the supervisory authority of their habitual residence, place of work or place of the alleged infringement. 15.2. In Hungary, the supervisory authority is the Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság); registered office: 1055 Budapest, Falk Miksa utca 9–11.; postal address: 1363 Budapest, Pf. 9.; website: https://naih.hu. 15.3. Under Articles 78 and 79 GDPR, the data subject may seek a judicial remedy against a legally binding decision of the supervisory authority, its failure to act, or the unlawful processing of their personal data. ──────────────────────────────────────── 16. Amendments to this Policy ──────────────────────────────────────── 16.1. The Controller may amend this Policy if the circumstances of the processing or the applicable laws change. The Controller informs data subjects in an appropriate manner of any change that materially affects the processing of personal data before it takes effect.