Privacy Policy
Plain-language explanation of what we collect, why, how long we keep it and how to get it deleted.
Overview
This Privacy Policy explains what Lorynix AI collects, why we collect it, who we share it with and the controls you have. It applies to our website, dashboard and chatbot widgets.
Data we collect
Account data
Name, work email, company, billing details and login metadata such as IP address and device type.
Training content
Websites you crawl and files you upload (PDF, DOCX, TXT, CSV, XLS) plus any text you paste into the knowledge base.
Conversation data
Messages exchanged between your visitors and your bot, timestamps, language and any lead details a visitor chooses to submit.
Usage data
Feature usage, message credits consumed, error logs and aggregated analytics.
How we use data
| Purpose | Data used | Legal basis |
|---|---|---|
| Provide and operate the service | Account, training, conversation | Contract |
| Billing and fraud prevention | Account, usage | Contract / legal obligation |
| Support and troubleshooting | Usage, limited conversation | Legitimate interest |
| Product analytics and improvement | Aggregated usage | Legitimate interest |
| Marketing emails | Account | Consent (opt-out anytime) |
Retention
- Conversations: 12 months by default, configurable down to 7 days.
- Training content: kept until you delete the source or the bot.
- Account and billing records: 7 years where tax law requires it.
- Backups: rolling 30-day encrypted backups, then permanent deletion.
GDPR & your rights
If you are in the EEA, the UK or California you can exercise the following rights free of charge, and we respond within 30 days.
- Access — request a copy of the personal data we hold about you.
- Rectification — correct anything inaccurate from your dashboard or by request.
- Erasure — delete your account and all associated bots and conversations.
- Portability — export conversations and knowledge sources as JSON or CSV.
- Objection — object to processing based on legitimate interest.
- Do not sell or share — we never sell personal data, so there is nothing to opt out of.
Security
- TLS 1.2+ in transit and AES-256 at rest.
- Role-based access, SSO and audit logs on Premium.
- Least-privilege internal access, reviewed quarterly.
- Annual third-party penetration testing and a public disclosure policy.
International transfers
Data may be processed outside your country. Transfers out of the EEA rely on standard contractual clauses plus supplementary technical measures. EU-only storage is available as a paid add-on.
Children’s privacy
Lorynix AI is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has submitted personal data, contact us and we will delete it.
Changes to this policy
We post material changes here at least 14 days before they take effect and email account owners. Older versions are available on request.
Contact the DPO
Email info@lorynixai.com or use the contact form and choose “Privacy & GDPR”. You also have the right to complain to your local supervisory authority.