Privacy Policy

Last updated: January 25, 2025

Your privacy is fundamental to NovaLexy. This policy explains how we collect, use, and protect your personal information in compliance with GDPR and international privacy laws.

1. Information We Collect

1.1 Personal Information

We collect information you provide directly to us when you:

  • Create an account (name, email address, password)
  • Subscribe to our services (payment information)
  • Contact us for support (correspondence content)
  • Participate in surveys or feedback forms
  • Use our AI tools (translations, text submissions for evaluation)

1.2 Usage Information

We automatically collect certain information about your use of our platform:

  • Device information (IP address, browser type, operating system)
  • Usage patterns (features used, time spent, click patterns)
  • Performance data (response times, error logs)
  • Cookies and similar tracking technologies

1.3 Content Data

When you use our AI tools, we process:

  • Text you submit for translation or evaluation
  • Your translation attempts and revisions
  • Chat conversations with our AI mentors
  • Progress tracking and learning analytics

2. How We Use Your Information

We use the information we collect to:

  • Provide our services: Process translations, generate AI feedback, track your progress
  • Improve our platform: Analyze usage patterns to enhance features and performance
  • Customer support: Respond to your questions and resolve technical issues
  • Account management: Maintain your account, process payments, send service updates
  • Research and development: Improve our AI models and develop new features
  • Legal compliance: Meet legal obligations and protect our rights

Legal Basis for Processing (GDPR)

We process your personal data based on:

  • Contract performance (providing services you requested)
  • Legitimate interests (improving our platform, customer support)
  • Consent (marketing communications, optional features)
  • Legal obligations (data retention, fraud prevention)

3. AI Data Processing and Model Training

3.1 Content Processing

  • Text you submit is processed by our AI systems to provide feedback and evaluations
  • Your content may be temporarily cached to improve response times
  • We do not store your translation content longer than necessary to provide the service
  • Personal information is removed from any data used for model improvement

3.2 Model Improvement

  • We may use aggregated, anonymized usage patterns to improve our AI models
  • Direct translation content is not used for training without explicit consent
  • You can opt out of contributing to model improvement in your account settings

4. Information Sharing and Disclosure

We do not sell, trade, or rent your personal information. We may share information in the following limited circumstances:

4.1 Service Providers

  • Payment processors: Stripe for subscription payments
  • AI providers: OpenAI for certain AI model capabilities
  • Cloud hosting: AWS/Google Cloud for data storage and processing
  • Analytics: Privacy-focused analytics tools

4.2 Legal Requirements

We may disclose information if required by law or to:

  • Comply with legal processes or government requests
  • Enforce our Terms of Use
  • Protect our rights, property, or safety
  • Prevent fraud or illegal activities

5. Data Security

We implement comprehensive security measures to protect your information:

  • Encryption: Data is encrypted in transit (TLS) and at rest (AES-256)
  • Access controls: Limited employee access on a need-to-know basis
  • Regular audits: Security assessments and vulnerability testing
  • Monitoring: 24/7 system monitoring for security threats
  • Compliance: SOC 2 Type II and industry best practices

Note: While we use industry-standard security measures, no system is 100% secure. We encourage you to use strong passwords and report any suspicious activity immediately.

6. Data Retention

We retain your information for different periods based on the type of data:

  • Account information: Until you delete your account + 30 days
  • Payment records: 7 years for tax and legal compliance
  • Translation content: 90 days maximum unless saved to your profile
  • Usage analytics: 24 months in aggregated, anonymized form
  • Support communications: 3 years for quality and training purposes

You can request earlier deletion of your data by contacting us at [email protected]

7. Your Rights and Choices

7.1 GDPR Rights (EU/UK Users)

Under GDPR, you have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete information
  • Erasure: Request deletion of your personal data
  • Portability: Receive your data in a machine-readable format
  • Restriction: Limit how we process your data
  • Objection: Object to processing based on legitimate interests
  • Withdraw consent: For processing based on consent

7.2 How to Exercise Your Rights

Email: [email protected]

Account Settings: Many preferences can be managed in your account

Contact Form: Use our contact page for privacy-related requests

We will respond to valid requests within 30 days (EU) or as required by local law.

8. Cookies and Tracking Technologies

We use cookies and similar technologies for:

  • Essential cookies: Required for platform functionality
  • Performance cookies: Help us understand how you use our platform
  • Functional cookies: Remember your preferences and settings
  • Analytics cookies: Measure and improve platform performance

You can control cookie preferences through your browser settings or our cookie banner when you first visit our site.

9. International Data Transfers

NovaLexy operates globally, and your information may be transferred to and processed in countries other than your own. When we transfer data internationally, we ensure adequate protection through:

  • Standard Contractual Clauses (SCCs) for EU data transfers
  • Data Processing Addendums with all service providers
  • Privacy Shield frameworks where applicable
  • Local data residency options for enterprise customers

10. Children's Privacy

NovaLexy is not intended for children under 16. We do not knowingly collect personal information from children under 16. If you believe we have collected information from a child under 16, please contact us immediately at [email protected]

For users aged 16-18, we require parental consent before creating an account.

11. Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will:

  • Notify you by email of material changes
  • Post the updated policy on our website
  • Update the "Last updated" date at the top
  • Maintain previous versions for reference

Your continued use of NovaLexy after policy updates constitutes acceptance of the revised policy.

12. Contact Information

For privacy-related questions, concerns, or requests, please contact us:

Data Protection Officer

Email: [email protected]

Response time: Within 72 hours

General Contact

Contact Form: novalexy.com/contact

Email: [email protected]

EU Representative

For EU users with GDPR-related inquiries

Email: [email protected]

If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.