Sign In
LIXOR

Data Processing Agreement

Version 1.0. This agreement is part of the Lixor Terms of Service and is accepted when you accept the Terms.

Last updated: September 24, 2026

This Data Processing Agreement ("DPA") is part of the Lixor Terms of Service (the "Terms") between Intelliwav LLC, doing business as Lixor, a Washington limited liability company, 37 103rd Ave NE, Unit 502, Bellevue, WA 98004, USA ("Lixor", "we") and the business that holds the Lixor account ("Customer", "you"). It applies whenever we handle personal data for you and a data protection law listed in section 1 applies to that data. If this DPA and the Terms disagree about personal data, this DPA wins.

Effective from the date shown above. Need a signed copy for your records? Write to support@lixor.ai. A signature is not needed for this DPA to bind.

1. Definitions

"Data Protection Law" means, as far as each applies: the EU General Data Protection Regulation 2016/679 ("GDPR"); the UK GDPR and the Data Protection Act 2018; the Swiss Federal Act on Data Protection; Brazil's Lei Geral de Proteção de Dados (Law 13.709/2018); Japan's Act on the Protection of Personal Information; Mexico's Ley Federal de Protección de Datos Personales en Posesión de los Particulares; and US state privacy laws.

"Customer Personal Data" means personal data that you or your staff put into Lixor, or that Lixor receives for you from a connected system such as a point-of-sale or distributor feed, and that we handle on your behalf. It does not include the data described in section 3.

"Controller", "processor", "personal data", "processing" and "data subject" have the meanings in the GDPR. Where another Data Protection Law uses a different word for the same role (for example "operador" in Brazil, "encargado" in Mexico, or an entrusted business operator in Japan), the matching meaning applies.

"Sub-processor" means another company we use to process Customer Personal Data.

"Standard Contractual Clauses" or "SCCs" means the clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.

2. Who does what

You are the controller of Customer Personal Data. We are your processor. You decide which staff to add, what they record and how long you keep using Lixor. We run the service.

You are responsible for having a lawful reason to put your staff's data into Lixor and for telling your staff that you use it. Our Privacy Policy is written so you can point them to it.

3. Where Lixor is a controller in its own right

We decide for ourselves how to handle a limited set of data, and for that data we are a controller, not your processor: account and login details of the people who hold Lixor accounts; billing and tax records; our support correspondence with you; security and audit logs; and product usage analytics. Our Privacy Policy covers this data. We do not use it to advertise other companies' products to your staff, and we do not sell it.

4. Your instructions

We process Customer Personal Data only on your documented instructions. The Terms, this DPA, your account settings and what you and your staff do in the product are your complete instructions. If you need something further, write to support@lixor.ai and we will follow it where it is technically reasonable and lawful, or tell you that we cannot.

We will tell you if we think an instruction breaks Data Protection Law. If a law that applies to us requires us to process Customer Personal Data in some other way, we will tell you first unless that law forbids it.

5. Details of the processing

Annex 1 sets out the subject matter, duration, nature and purpose of the processing, the kinds of personal data and the kinds of people it is about.

6. Confidentiality

Anyone we authorise to handle Customer Personal Data is bound by a duty of confidentiality, by contract or by law.

7. Security

We maintain the technical and organisational measures in Annex 2. We may change them as long as the overall level of protection does not go down. You are responsible for using the security features we provide, such as strong passwords, removing staff who leave, and choosing the right role for each user.

8. Sub-processors

8.1 You give us general authorisation to use Sub-processors. The current list is at lixor.ai/legal/subprocessors and forms Annex 3.

8.2 We give at least 30 days' notice before adding or replacing a Sub-processor, by updating that page and by emailing account owners who have subscribed to updates on that page. Where we must replace a Sub-processor urgently for security or continuity reasons, we will give as much notice as we reasonably can.

8.3 You may object on reasonable data protection grounds within those 30 days by writing to support@lixor.ai. We will try to offer a workaround. If we cannot, you may cancel the affected service and we will refund any prepaid fees for the period after cancellation. That is your sole remedy for an objection.

8.4 Each Sub-processor's own standard data processing agreement applies automatically once we use its service, and matches this DPA in substance; none required us to sign a separate copy. We remain responsible to you for what our Sub-processors do with Customer Personal Data.

9. Helping you with people's rights

If one of your staff, or anyone else, asks us to access, correct, delete, restrict, move or object to the use of Customer Personal Data, we will pass the request to you without undue delay and will not answer it ourselves except to say that we have passed it on. Lixor lets you correct data in the product, delete an account in the mobile app, and download count results as Excel spreadsheets. For anything else, such as a full export of products, suppliers and invoices, we will give reasonable help on request.

10. Helping you with your other duties

Taking into account what we do and the information we have, we will give you reasonable help with security, breach notification, data protection impact assessments and consultations with regulators. If the help you need goes well beyond what an ordinary customer needs, we may charge our reasonable costs after agreeing them with you first.

11. Personal data breaches

If we become aware of a breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data, we will tell the account owner by email without undue delay, and in any case within 72 hours of confirming it. We will share what we know as we learn it: what happened, what data and roughly how many people are affected, the likely consequences, and what we are doing about it. Telling you about a breach is not an admission of fault.

12. International transfers

12.1 Lixor stores and processes Customer Personal Data in the United States. By using Lixor you instruct us to do so.

12.2 EU and EEA. Where the GDPR applies to you and sending Customer Personal Data to us is a restricted transfer, the SCCs are incorporated into this DPA and apply as follows: Module Two (controller to processor); you are the data exporter and we are the data importer; Clause 7 (docking) does not apply; Clause 9(a) Option 2 (general authorisation) applies with a notice period of 30 days; the optional wording in Clause 11(a) does not apply; under Clause 13 the competent supervisory authority is the one responsible for you; under Clause 17 Option 1 applies and the SCCs are governed by the law of Ireland; under Clause 18(b) disputes under the SCCs go to the courts of Ireland; Annex I of the SCCs is completed by Annex 1 of this DPA and the parties' details above; Annex II by Annex 2; Annex III by Annex 3.

12.3 United Kingdom. Where the UK GDPR applies, the SCCs apply as amended by the International Data Transfer Addendum issued by the UK Information Commissioner (version B1.0, in force 21 March 2022), which is incorporated into this DPA. Tables 1 to 3 of the Addendum are completed by the information in section 12.2 and the Annexes. For Table 4, either party may end the Addendum as it provides.

12.4 Switzerland. Where the Swiss Federal Act on Data Protection applies, the SCCs apply with these changes: references to the GDPR include the Swiss Act; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; "Member State" is read so that people in Switzerland can sue for their rights in Switzerland; and the SCCs are governed by Swiss law as far as the transfer is subject only to the Swiss Act.

12.5 Brazil. Where the Lei Geral de Proteção de Dados applies and your sending Customer Personal Data to us is an international transfer that needs a safeguard, the standard contractual clauses approved by the Autoridade Nacional de Proteção de Dados in Resolution CD/ANPD No. 19/2024 apply between us, with you as exporter and us as importer, completed by the Annexes to this DPA. We will sign them as a separate document when you ask.

12.6 Onward transfers. We transfer Customer Personal Data to Sub-processors only under a lawful transfer tool: their certification under the EU-US Data Privacy Framework (and its UK Extension and Swiss counterpart), or the SCCs with the UK Addendum where needed.

12.7 If a transfer tool we rely on is struck down or withdrawn, we will work with you in good faith to put another in place. If the SCCs and this DPA disagree, the SCCs win.

13. Government requests

If a government body asks us for Customer Personal Data, we will tell you unless the law forbids it, challenge a request we believe is unlawful, and hand over only what is strictly required. As of September 24, 2026, we have never received such a request.

14. Audits and information

We will give you the information reasonably needed to show that we meet this DPA, including written answers to a reasonable security questionnaire once a year. If that is not enough to meet a legal duty you have, or a regulator requires it, you may audit us once a year on 30 days' written notice, during business hours, under a confidentiality agreement, at your cost, and without access to other customers' data. You may use an independent auditor who is not our competitor.

15. Artificial intelligence features

Some features send Customer Personal Data to AI providers named in Annex 3, for example the text of a question you ask the in-app assistant, a recording of your voice for transcription, or a photograph of a delivery invoice sent to Google's Gemini API for reading. OpenAI's terms do not allow it to use data sent through its programming interface to train its models. We use Google's Gemini API on its paid service, not its free tier; under Google's terms for the paid service, it does not use that data to improve its products. We do not use Customer Personal Data to train AI models.

16. Return and deletion

While your account is open you can download count results as Excel spreadsheets, and we will help with any other export you ask for. We keep Customer Personal Data until your account is deleted. After your account closes, or earlier if you ask, we delete it from our database within 30 days; our database backups are kept on a rolling 7-day basis, so deleted data drops out of them within that window. Deletion removes database records; it does not currently remove photos or voice recordings from our file storage, which can remain after deletion. We may keep data longer only where a law requires it, and then only for that purpose.

17. Liability

The limits of liability in the Terms apply to this DPA. Nothing in this DPA limits the rights of individuals under Data Protection Law or under the SCCs, or either party's liability to them.

18. Term, law and changes

This DPA lasts as long as we hold Customer Personal Data. It is governed by the law that governs the Terms, except where section 12 says otherwise. We may update it to reflect changes in law, in our Sub-processors or in the service. We will give 30 days' notice of any change that reduces your protection.

Annex 1: Details of the processing

ItemDetail
Data exporter (controller)The Customer named on the Lixor account, at the address and contact email given in the account
Data importer (processor)Intelliwav LLC dba Lixor, 37 103rd Ave NE, Unit 502, Bellevue, WA 98004, USA. Contact: support@lixor.ai
Subject matter and purposeProviding the Lixor inventory service: taking inventory, recording counts, products, suppliers, invoices and sales feeds, reports, the in-app assistant and voice counting, and customer support
Nature of processingHosting, storage, retrieval, display, transmission to connected systems you switch on, transcription of speech, generation of spoken prompts, automated answers to questions, backup and deletion
DurationThe life of your account, plus the deletion period in section 16
People the data is aboutYour owners, managers and staff who use Lixor; staff listed in a point-of-sale system you connect; contacts at your suppliers and distributors whose names appear in records or invoices you upload
Kinds of personal dataName, work or personal email address, role and permissions, password (stored only as a hash), records of activity in the product (who counted what, when, in which area), voice recordings of spoken product lists (sent for transcription and stored until the account is deleted), questions typed or spoken to the assistant, device and app version, push notification token, IP address in server logs, and any personal data contained in notes, photos or invoices you choose to upload
Special categories of dataNone intended. Do not put health, biometric, religious or similar data into Lixor
Frequency of transferContinuous while the account is active
RetentionAs in section 16
Sub-processor transfersAs listed in Annex 3, for the life of the account

Annex 2: Security measures

  • Data is encrypted in transit with TLS and encrypted at rest by our database and hosting providers (AES-256).
  • Each customer's data is separated from every other customer's by checks on our servers that tie every request to the signed-in user's organisation. Database row-level security is switched on for every table that holds customer or personal data; one internal table with no personal data (a log of past cost corrections) does not carry it.
  • Exception: photos you upload (bottles, shelves, invoices) are stored at long web addresses that anyone who has the address can open without signing in. They are not access-controlled.
  • Passwords are stored only as salted hashes by our authentication provider. We never see them.
  • Access to production systems (Supabase, Vercel, Stripe, GitHub, PostHog, Sentry, OpenAI, ElevenLabs and the domain registrar) is limited to the founder; no other staff member or contractor holds production access.
  • Role-based permissions inside the product, so you decide which staff can see or change what.
  • Payment card details are handled entirely by Stripe and never reach our servers.
  • Database backups run daily and are kept for 7 days on a rolling basis. Point-in-time recovery is not currently on.
  • Source code changes are reviewed and deployed through version control, with secrets kept out of the code.
  • Error and crash monitoring, with personal data kept out of error reports as far as practical.
  • A written process for deleting an organisation's data on request, tested in use.
  • A written incident response process: contain, assess, notify affected customers under section 11, fix, and record.
  • Sub-processors are chosen for their published security standing. Supabase, Vercel and OpenAI currently publish SOC 2 Type II reports; see each vendor's own trust page for its current certification. Each is under its own standard data protection contract, which applies automatically once we use its service.

Annex 3: Sub-processors

The list at lixor.ai/legal/subprocessors on the effective date.

Data Processing Agreement | Lixor