Back to lexsophos.ai

Legal

Privacy policy

How Lexsophos collects, uses and protects personal information. Effective October 8, 2026. Last updated October 8, 2026.

1Who we are

Lexsophos Inc. (“Lexsophos”, “lexsophos.ai”, “we”, “us”, or “our”) is a Delaware corporation based in Miami, Florida. We provide a contract negotiation intelligence platform for the aviation sectors (the “Platform”), and we operate the website at lexsophos.ai (the “Website”).

This Privacy Policy explains how we collect, use, store, share and delete personal information in connection with the Website and the Platform, and the choices and rights available to you.

2Our two roles

  • Customer Content. When a customer uploads contracts, redlines, margin comments or other documents to the Platform (“Customer Content”), we process that content on the customer's behalf and only on its consent. The customer is the controller (or “business”) and Lexsophos is the processor (or “service provider”). Our handling of Customer Content is governed by our agreement with that customer, including our Data Processing Addendum. If your personal information appears in Customer Content, please contact the relevant customer to exercise your rights.
  • Our own information. For information about Website visitors, account users and business contacts, Lexsophos decides how the information is used and is the controller.

3Information we collect

3.1 Information you provide

  • Details you enter in the walkthrough request form on the Website: your name, work email address, company, role and message.
  • Contact and business details, such as name, business email address, job title, company and phone number, when you otherwise contact us or meet us at an event where we exhibit.
  • Platform account information, such as user name, login details, role and user settings, when your organisation gives you access to the Platform.
  • Billing information needed to invoice and collect payment. Lexsophos uses Stripe as the payment processor, who handle the card details in accordance to their procedures, and such data is not stored by Lexsophos.
  • The contents of any messages you send us.

3.2 Customer Content

Documents and related information that customers upload to the Platform. These may include names, titles and contact details of individuals that appear in contracts and correspondence. See Section 5 for how Customer Content is handled.

3.3 Information collected automatically

  • Technical and log data, such as IP address, browser type, device information, access times and pages viewed.
  • Platform activity and audit records, which record actions taken in the Platform, used to operate, secure and audit the service.
  • Cookies and analytics. The Website uses cookies and similar technologies. With your consent, we use Google Analytics to understand how visitors use the Website, HubSpot to understand how visitors interact with the Website and our communications, and Apollo to identify the companies whose networks visit the Website. These tools run only after you agree through the cookie banner. Cookies that are strictly necessary for the Website to work, including the cookie that remembers your choice, do not require consent. You can change your choice at any time using Cookie settings at the bottom of any page.

3.4 Information from other sources

We may obtain business contact information from publicly available professional sources, industry directories, business data providers, events and referrals.

4How we use information

  • To provide, operate, maintain and support the Platform and the Website.
  • To create and manage accounts and authenticate users.
  • To respond to enquiries and walkthrough requests.
  • To understand how visitors use the Website and improve it, using analytics where you have consented or where consent is not required.
  • To invoice and collect payment.
  • To protect the security and integrity of the Platform, prevent fraud and misuse, and keep audit records.
  • To improve the functionality of the Website and the Platform. This does not include using Customer Content to train AI models (see Section 5).
  • To send service and administrative messages, and, where permitted, business communications about our products. You can opt out of marketing messages at any time.
  • To comply with legal obligations and enforce our agreements.

Legal bases. Where the EU or UK General Data Protection Regulation applies, we rely on the following legal bases: performance of a contract; our legitimate interests in operating and promoting our business, provided those interests are not overridden by your rights; compliance with legal obligations; and your consent where required.

5How we handle Customer Content

  • Single-tenant environment. Each customer runs in its own single-tenant environment, dedicated to that customer and hosted on Amazon Web Services (AWS). Customer Content is not shared with or accessible to other customers, and each customer's data is kept separate inside the database.
  • How documents are processed. Uploaded documents are divided into segments and converted into vector representations held within that customer's environment. This enables search and precedent matching for that customer only.
  • No model training. Customer Content is not used to train, fine-tune or otherwise change the weights of any AI model, whether ours or a third party's, and is not used to benefit any other customer.
  • AI processing. The Platform's AI Assistant is powered by Anthropic's Claude models, accessed through Amazon Bedrock. Text entered in the AI Assistant may be processed in another AWS region and is handled in accordance with AWS's terms for Amazon Bedrock, as described in Amazon Bedrock data protection and Cross-Region inference. Excepting Anthropic's model Fable5 (not adopted by Lexsophos), the data is not shared with the model provider and is handled in accordance with conventional data protection practices described herein this section.
  • Human decision. Content produced by AI is visibly marked in the Platform, and every AI-suggested change must be accepted, modified or rejected by a person before it is applied.
  • Customer-controlled deletion. A customer administrator can delete the customer's contract data from its environment at any time using the Purge command in the Platform, without needing to contact or obtain approval from Lexsophos. User accounts and audit records are kept, as described in Section 7.

6How we share information

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We share information only as follows:

  • Service providers. Service providers and subprocessors that help us run our business, under contracts that limit their use of the information. These currently include: Amazon Web Services (hosting, storage and AI model access through Amazon Bedrock); Google Workspace (business email); Google Analytics (Website analytics); HubSpot (customer relationship management, Website analytics and cookie consent); Apollo (sales engagement, email and identifying the companies that visit the Website); BlueHost (hosting); and, where enabled for a customer, Sentry and Honeycomb (application monitoring); Stripe for payment processing.
  • Professional advisers. Lawyers, accountants and other professional advisers, under duties of confidentiality.
  • Legal requirements. Where required by law, regulation or legal process, or to protect the rights, property or safety of Lexsophos, our customers or others.
  • Business transfers. In connection with a merger, acquisition, financing or sale of all or part of our business, subject to appropriate confidentiality protections.
  • With consent. With your consent or at your direction.

7How long we keep information

  • Customer Content. Kept for the duration of the customer's subscription unless the customer deletes it earlier. If a customer's subscription ends without the customer having used the Purge command, Lexsophos deletes that customer's Customer Content promptly following termination. To allow recovery from accidental deletion, backups of Customer Content are kept for up to 90 days by default, after which they are deleted, unless the customer requests a shorter period in writing.
  • Audit records. Kept for the life of the customer's environment. When a person asks for their personal data to be erased, their personal details in these records are replaced with pseudonyms, so the audit history is preserved without identifying them.
  • Account, billing and business records. Kept for as long as needed for the purposes described in this policy and as required for legal, tax, accounting and dispute-resolution purposes.
  • Logs and enquiries. Technical logs are kept for up to 90 days and security logs for up to 12 months, unless we need them for longer to investigate a specific incident. Walkthrough requests and other enquiries are kept for up to 24 months after our last contact with you, unless you ask us to delete them sooner or your organization becomes a customer, in which case they form part of its account records.

8Security

We use technical and organizational measures designed to protect personal information, including a single-tenant environment for each customer, separation of each customer's data inside the database, role-based access controls with five built-in roles and support for custom roles, approval workflows, and audit records of activity in the Platform. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9International transfers

The Website is operated from the United States, and Website and business contact information is processed in the United States. The locations where Customer Content is processed are set out in our agreement with each customer. Text entered in the AI Assistant may be processed in another AWS region depending on the language model Cross-Region inference, as described in Section 5. Where personal information from the European Economic Area, the United Kingdom or Switzerland is transferred to a country that has not been found to provide adequate protection, we rely on Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism.

10Your rights

  • access the personal information we hold about you, and receive a copy of it;
  • correct inaccurate information;
  • delete your information;
  • restrict or object to certain processing;
  • receive your information in a portable format;
  • withdraw consent where processing is based on consent;
  • opt out of the sale or sharing of personal information (we do not sell or share it for advertising); and
  • lodge a complaint with a data protection supervisory authority.

To exercise these rights, email us at legal@lexsophos.ai. We may need to verify your identity before responding, and we will respond within the time required by applicable law. We will not discriminate against you for exercising your rights. Requests concerning Customer Content will be referred to the relevant customer, as described in Section 2.

11Marketing communications

You can unsubscribe from marketing emails at any time by using the link in the email or by contacting us. We will still send service and administrative messages related to your account.

12Children

The Website and the Platform are intended for business use and are not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us and we will delete it.

13Third-party websites

The Website may link to third-party websites and services. Their privacy practices are governed by their own policies, and we are not responsible for them.

14Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version with a new “Last updated” date and, where changes are material, give reasonable notice through the Website or the Platform.

15Contact us

1738 SW 57th Ave

Unit #A160

Miami, FL 33155

Email: legal@lexsophos.ai

Effective October 8, 2026  |  Lexsophos Inc. (doing business as Lexsophos.ai)