Version 1.0. This agreement is part of the Lixor Terms of Service and is accepted when you accept the Terms.
Last updated: September 24, 2026
This Data Processing Agreement ("DPA") is part of the Lixor Terms of Service (the "Terms") between Intelliwav LLC, doing business as Lixor, a Washington limited liability company, 37 103rd Ave NE, Unit 502, Bellevue, WA 98004, USA ("Lixor", "we") and the business that holds the Lixor account ("Customer", "you"). It applies whenever we handle personal data for you and a data protection law listed in section 1 applies to that data. If this DPA and the Terms disagree about personal data, this DPA wins.
Effective from the date shown above. Need a signed copy for your records? Write to support@lixor.ai. A signature is not needed for this DPA to bind.
"Data Protection Law" means, as far as each applies: the EU General Data Protection Regulation 2016/679 ("GDPR"); the UK GDPR and the Data Protection Act 2018; the Swiss Federal Act on Data Protection; Brazil's Lei Geral de Proteção de Dados (Law 13.709/2018); Japan's Act on the Protection of Personal Information; Mexico's Ley Federal de Protección de Datos Personales en Posesión de los Particulares; and US state privacy laws.
"Customer Personal Data" means personal data that you or your staff put into Lixor, or that Lixor receives for you from a connected system such as a point-of-sale or distributor feed, and that we handle on your behalf. It does not include the data described in section 3.
"Controller", "processor", "personal data", "processing" and "data subject" have the meanings in the GDPR. Where another Data Protection Law uses a different word for the same role (for example "operador" in Brazil, "encargado" in Mexico, or an entrusted business operator in Japan), the matching meaning applies.
"Sub-processor" means another company we use to process Customer Personal Data.
"Standard Contractual Clauses" or "SCCs" means the clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
You are the controller of Customer Personal Data. We are your processor. You decide which staff to add, what they record and how long you keep using Lixor. We run the service.
You are responsible for having a lawful reason to put your staff's data into Lixor and for telling your staff that you use it. Our Privacy Policy is written so you can point them to it.
We decide for ourselves how to handle a limited set of data, and for that data we are a controller, not your processor: account and login details of the people who hold Lixor accounts; billing and tax records; our support correspondence with you; security and audit logs; and product usage analytics. Our Privacy Policy covers this data. We do not use it to advertise other companies' products to your staff, and we do not sell it.
We process Customer Personal Data only on your documented instructions. The Terms, this DPA, your account settings and what you and your staff do in the product are your complete instructions. If you need something further, write to support@lixor.ai and we will follow it where it is technically reasonable and lawful, or tell you that we cannot.
We will tell you if we think an instruction breaks Data Protection Law. If a law that applies to us requires us to process Customer Personal Data in some other way, we will tell you first unless that law forbids it.
Annex 1 sets out the subject matter, duration, nature and purpose of the processing, the kinds of personal data and the kinds of people it is about.
Anyone we authorise to handle Customer Personal Data is bound by a duty of confidentiality, by contract or by law.
We maintain the technical and organisational measures in Annex 2. We may change them as long as the overall level of protection does not go down. You are responsible for using the security features we provide, such as strong passwords, removing staff who leave, and choosing the right role for each user.
8.1 You give us general authorisation to use Sub-processors. The current list is at lixor.ai/legal/subprocessors and forms Annex 3.
8.2 We give at least 30 days' notice before adding or replacing a Sub-processor, by updating that page and by emailing account owners who have subscribed to updates on that page. Where we must replace a Sub-processor urgently for security or continuity reasons, we will give as much notice as we reasonably can.
8.3 You may object on reasonable data protection grounds within those 30 days by writing to support@lixor.ai. We will try to offer a workaround. If we cannot, you may cancel the affected service and we will refund any prepaid fees for the period after cancellation. That is your sole remedy for an objection.
8.4 Each Sub-processor's own standard data processing agreement applies automatically once we use its service, and matches this DPA in substance; none required us to sign a separate copy. We remain responsible to you for what our Sub-processors do with Customer Personal Data.
If one of your staff, or anyone else, asks us to access, correct, delete, restrict, move or object to the use of Customer Personal Data, we will pass the request to you without undue delay and will not answer it ourselves except to say that we have passed it on. Lixor lets you correct data in the product, delete an account in the mobile app, and download count results as Excel spreadsheets. For anything else, such as a full export of products, suppliers and invoices, we will give reasonable help on request.
Taking into account what we do and the information we have, we will give you reasonable help with security, breach notification, data protection impact assessments and consultations with regulators. If the help you need goes well beyond what an ordinary customer needs, we may charge our reasonable costs after agreeing them with you first.
If we become aware of a breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data, we will tell the account owner by email without undue delay, and in any case within 72 hours of confirming it. We will share what we know as we learn it: what happened, what data and roughly how many people are affected, the likely consequences, and what we are doing about it. Telling you about a breach is not an admission of fault.
12.1 Lixor stores and processes Customer Personal Data in the United States. By using Lixor you instruct us to do so.
12.2 EU and EEA. Where the GDPR applies to you and sending Customer Personal Data to us is a restricted transfer, the SCCs are incorporated into this DPA and apply as follows: Module Two (controller to processor); you are the data exporter and we are the data importer; Clause 7 (docking) does not apply; Clause 9(a) Option 2 (general authorisation) applies with a notice period of 30 days; the optional wording in Clause 11(a) does not apply; under Clause 13 the competent supervisory authority is the one responsible for you; under Clause 17 Option 1 applies and the SCCs are governed by the law of Ireland; under Clause 18(b) disputes under the SCCs go to the courts of Ireland; Annex I of the SCCs is completed by Annex 1 of this DPA and the parties' details above; Annex II by Annex 2; Annex III by Annex 3.
12.3 United Kingdom. Where the UK GDPR applies, the SCCs apply as amended by the International Data Transfer Addendum issued by the UK Information Commissioner (version B1.0, in force 21 March 2022), which is incorporated into this DPA. Tables 1 to 3 of the Addendum are completed by the information in section 12.2 and the Annexes. For Table 4, either party may end the Addendum as it provides.
12.4 Switzerland. Where the Swiss Federal Act on Data Protection applies, the SCCs apply with these changes: references to the GDPR include the Swiss Act; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; "Member State" is read so that people in Switzerland can sue for their rights in Switzerland; and the SCCs are governed by Swiss law as far as the transfer is subject only to the Swiss Act.
12.5 Brazil. Where the Lei Geral de Proteção de Dados applies and your sending Customer Personal Data to us is an international transfer that needs a safeguard, the standard contractual clauses approved by the Autoridade Nacional de Proteção de Dados in Resolution CD/ANPD No. 19/2024 apply between us, with you as exporter and us as importer, completed by the Annexes to this DPA. We will sign them as a separate document when you ask.
12.6 Onward transfers. We transfer Customer Personal Data to Sub-processors only under a lawful transfer tool: their certification under the EU-US Data Privacy Framework (and its UK Extension and Swiss counterpart), or the SCCs with the UK Addendum where needed.
12.7 If a transfer tool we rely on is struck down or withdrawn, we will work with you in good faith to put another in place. If the SCCs and this DPA disagree, the SCCs win.
If a government body asks us for Customer Personal Data, we will tell you unless the law forbids it, challenge a request we believe is unlawful, and hand over only what is strictly required. As of September 24, 2026, we have never received such a request.
We will give you the information reasonably needed to show that we meet this DPA, including written answers to a reasonable security questionnaire once a year. If that is not enough to meet a legal duty you have, or a regulator requires it, you may audit us once a year on 30 days' written notice, during business hours, under a confidentiality agreement, at your cost, and without access to other customers' data. You may use an independent auditor who is not our competitor.
Some features send Customer Personal Data to AI providers named in Annex 3, for example the text of a question you ask the in-app assistant, a recording of your voice for transcription, or a photograph of a delivery invoice sent to Google's Gemini API for reading. OpenAI's terms do not allow it to use data sent through its programming interface to train its models. We use Google's Gemini API on its paid service, not its free tier; under Google's terms for the paid service, it does not use that data to improve its products. We do not use Customer Personal Data to train AI models.
While your account is open you can download count results as Excel spreadsheets, and we will help with any other export you ask for. We keep Customer Personal Data until your account is deleted. After your account closes, or earlier if you ask, we delete it from our database within 30 days; our database backups are kept on a rolling 7-day basis, so deleted data drops out of them within that window. Deletion removes database records; it does not currently remove photos or voice recordings from our file storage, which can remain after deletion. We may keep data longer only where a law requires it, and then only for that purpose.
The limits of liability in the Terms apply to this DPA. Nothing in this DPA limits the rights of individuals under Data Protection Law or under the SCCs, or either party's liability to them.
This DPA lasts as long as we hold Customer Personal Data. It is governed by the law that governs the Terms, except where section 12 says otherwise. We may update it to reflect changes in law, in our Sub-processors or in the service. We will give 30 days' notice of any change that reduces your protection.
| Item | Detail |
|---|---|
| Data exporter (controller) | The Customer named on the Lixor account, at the address and contact email given in the account |
| Data importer (processor) | Intelliwav LLC dba Lixor, 37 103rd Ave NE, Unit 502, Bellevue, WA 98004, USA. Contact: support@lixor.ai |
| Subject matter and purpose | Providing the Lixor inventory service: taking inventory, recording counts, products, suppliers, invoices and sales feeds, reports, the in-app assistant and voice counting, and customer support |
| Nature of processing | Hosting, storage, retrieval, display, transmission to connected systems you switch on, transcription of speech, generation of spoken prompts, automated answers to questions, backup and deletion |
| Duration | The life of your account, plus the deletion period in section 16 |
| People the data is about | Your owners, managers and staff who use Lixor; staff listed in a point-of-sale system you connect; contacts at your suppliers and distributors whose names appear in records or invoices you upload |
| Kinds of personal data | Name, work or personal email address, role and permissions, password (stored only as a hash), records of activity in the product (who counted what, when, in which area), voice recordings of spoken product lists (sent for transcription and stored until the account is deleted), questions typed or spoken to the assistant, device and app version, push notification token, IP address in server logs, and any personal data contained in notes, photos or invoices you choose to upload |
| Special categories of data | None intended. Do not put health, biometric, religious or similar data into Lixor |
| Frequency of transfer | Continuous while the account is active |
| Retention | As in section 16 |
| Sub-processor transfers | As listed in Annex 3, for the life of the account |
The list at lixor.ai/legal/subprocessors on the effective date.