Lexiom Privacy Policy

Effective Date: [September 1, 2025]
Version: V1.0

1. Scope and Overview

LEXIOM TECHNOLOGIES INC. ("Lexiom," "we," "us," or "our") prioritizes your privacy. This Privacy Policy ("Policy") outlines how we collect, use, disclose, and protect the personal information of users ("user," "you," "your") of our Lexiom product and related services (collectively, the "Services"). The Services include: (i) searching for job seekers online based on your needs; (ii) providing candidate information (including contact details and LinkedIn contact information); (iii) generating AI-powered Email content and LinkedIn outreach content; and (iv) account management (e.g., email registration, LinkedIn/Gmail account binding).

Please read this Policy carefully before using the Services. By accessing or using the Services, you acknowledge that you have read, understood, and agreed to the practices described herein.

2. Definitions

2.1 Controller and Processor Information

Lexiom operates the Services. For most personal information processed through the Services (e.g., information collected for account registration, job seeker searches, and AI content generation), where Lexiom determines the purpose and means of processing, Lexiom acts as a "data controller" (or "business" under applicable laws such as the CCPA/CPRA).

If Lexiom processes personal information on behalf of third parties (e.g., sharing candidate data with you as authorized), Lexiom acts as a "data processor" (or "service provider"). This Policy primarily governs our activities as a data controller; processing activities as a data processor are subject to separate agreements with relevant parties.

2.2 Personal Information

Personal information refers to any information (recorded electronically or otherwise) that can identify a specific individual alone or in combination with other information. For the Services, this includes:

  Your information: Full name, professional role (role), company name, job title, email address (used for account registration), LinkedIn account information (e.g., profile details, contact permissions), and Gmail account information (e.g., sending permissions).

  Candidate information: Job seekers’ full names, contact details (e.g., phone numbers, emails), and LinkedIn contact information.

This excludes information that has been fully anonymized (i.e., information that can no longer identify any individual, even when combined with other data).

2.3 Sensitive Personal Information

Sensitive personal information is data that, if leaked or misused, could easily infringe on an individual’s dignity or endanger their personal/property safety. This includes (but is not limited to) biometric data, religious beliefs, medical records, financial account details, and information about individuals under the age of 16. The Services do not intentionally collect or process sensitive personal information, unless explicitly disclosed by you or required by law.

3. Information We Collect and How We Use It

We collect Personal Information only for the purposes of providing and improving the Services. Below is a detailed breakdown of collection purposes, types of information collected, and intended uses:

No.

Collection Purpose

Types of Collected Personal Information

1

Account Registration & Login

Your email address (used as login credentials), password (stored in encrypted form), full name (for account identification).

2

Binding Third-Party Accounts (LinkedIn/Gmail)

LinkedIn account information (e.g., profile ID, contact access permissions, connection data) and Gmail account information (e.g., email sending permissions, draft access, and email content access). We read customer email content to help users more efficiently identify candidates’ job-seeking intentions, and we will comply with Google Gmail security requirements and applicable Google policies.

3

Providing Job Seeker Search Services

Your role, company name, and job title (to tailor job seeker matching to your hiring needs); candidate information (full name, contact details, LinkedIn contact information) (to deliver candidate lists to you).

4

AI-Generated Content (Email/LinkedIn Outreach)

Your input (e.g., hiring requirements, candidate background notes) and candidate information (to train and optimize AI for contextually relevant content).

5

Customer Support & Service Improvement

Your contact details (email, phone number if provided), communication history (e.g., support tickets, chat records), and feedback on the Services.

How We Use the Collected Information

We use the Personal Information described above to:

  Provide, operate, and maintain the Services (e.g., verifying your account, enabling LinkedIn/Gmail integration, delivering candidate search results).

  Generate AI-powered content: Create personalized Email drafts and LinkedIn outreach messages based on your needs and candidate profiles.

  Read customer email content to help users more efficiently identify candidates’ job-seeking intentions and support recruitment communications, and we will handle such access in compliance with Google Gmail security requirements and applicable Google policies.

  Improve the Services: Analyze user behavior (e.g., search preferences, content usage) to optimize matching accuracy, AI performance, and user experience.

  Communicate with you: Respond to your inquiries, send service updates (e.g., account notifications, feature announcements), and provide customer support.

  Ensure security: Protect the integrity of the Services, prevent unauthorized access to your account, and detect/fight fraud or illegal activities.

  Comply with legal obligations: Fulfill requirements under applicable data protection laws, tax regulations, or legal processes.

4. Legal Grounds for Processing

We process your Personal Information based on the following legal grounds (as applicable to your region):

For Users in the European Economic Area (EEA), UK, or Switzerland

We rely on the following under the GDPR/UK GDPR:

  Performance of a contract: Processing is necessary to fulfill our agreement with you (e.g., providing job seeker search services or AI content generation as requested).

  Legal obligation: Processing is required to comply with laws (e.g., retaining records for tax or audit purposes).

  Legitimate interests: Processing is necessary to pursue our legitimate business interests, such as improving the Services, ensuring security, or providing customer support—provided these interests do not override your privacy rights.

  Consent: Where required (e.g., binding LinkedIn/Gmail accounts), we process information only with your explicit consent. You may withdraw this consent at any time (see Section 10).

For Users in California (U.S.)

Under the CCPA/CPRA, we process Personal Information to:

  Perform a service requested by you (e.g., job seeker searches, AI content generation).

  Comply with legal obligations or protect our legal rights (e.g., responding to subpoenas).

For Users in Other Regions (e.g., Singapore, Australia/New Zealand)

We process Personal Information in accordance with local laws (e.g., Singapore’s PDPA, Australia’s Privacy Act):

  With your consent (for optional activities like third-party account binding).

  To fulfill contractual obligations (e.g., delivering the Services you purchased).

  For legitimate business purposes (e.g., service maintenance, fraud prevention).

5. How We Share Your Information

We do not sell your Personal Information for monetary gain. We may share Personal Information only in the following limited circumstances, and only with parties that commit to protecting data security:

5.1 Service Providers

We engage trusted third-party vendors to assist with operating the Services. These providers are contractually required to process data only as instructed by Lexiom and to implement adequate security measures. Examples include:

  Cloud hosting providers (to store your account data and candidate information securely).

  AI technology partners (to support the development and optimization of AI content generation features).

  LinkedIn and Google (to facilitate account binding and access permissions for LinkedIn/Gmail integration—subject to their respective privacy policies).

5.2 Corporate Transactions

In the event of a merger, acquisition, asset sale, or other corporate restructuring, your Personal Information may be transferred to the acquiring entity. We will notify you of such a transfer via email or a prominent notice on the Services, where required by law.

5.3 Legal Requirements

We may disclose Personal Information if required by law, regulation, legal process (e.g., a subpoena), or governmental request. We may also disclose information to protect our rights, property, or safety, or the rights, safety, or property of other users or third parties (e.g., responding to fraud or harassment claims).

6. International Data Transfers

Lexiom is based in [Insert Lexiom’s Country of Operation, e.g., the United States]. Your Personal Information may be processed in:

  Lexiom’s operating jurisdictions.

  Countries where our service providers are located (e.g., cloud servers in the EU, Singapore, or the U.S.).

These countries may have different data protection laws. To ensure your data is protected during cross-border transfers, we use the following lawful mechanisms:

  For transfers from the EEA/UK/Switzerland to non-"adequate" countries: We rely on the EU-U.S. Data Privacy Framework (DPF), UK Extension to the EU-U.S. DPF, Swiss-U.S. DPF (if Lexiom is certified), or Standard Contractual Clauses (SCCs) approved by the European Commission or UK ICO.

  For transfers from other regions: We use adequacy decisions (e.g., EU adequacy for Japan, Canada) or other locally recognized mechanisms.

7. Cookies and Similar Technologies

We and our service providers use cookies, web beacons, and similar tracking technologies to enhance the Services, analyze user behavior, and maintain account security. Below is a summary of key technologies used:

No.

Technology Name

Purpose

Types of Personal Information Processed

Technology Provider

Contact Information for Provider

1

Essential Cookies

Enable account login, session management, and basic service functionality (e.g., saving your search filters).

Your login status, session ID (encrypted), search preferences.

Lexiom Technologies Inc.

mokahr.dev@gmail.com

 

2

Google Analytics

Analyze website/app traffic, user engagement (e.g., search frequency, AI content usage), and optimize service performance.

IP address (anonymized), device information (e.g., browser type, OS), browsing behavior (e.g., page visits).

Google LLC

https://support.google.com/analytics

3

LinkedIn Insight Tag

Facilitate LinkedIn account binding, track the effectiveness of LinkedIn-related features (e.g., candidate outreach), and enable LinkedIn profile matching.

IP address, LinkedIn user ID (if logged in), page visit data.

LinkedIn Corporation

https://www.linkedin.com/help/linkedin/answer/65521

You may manage your cookie preferences at any time:

  Through the cookie banner displayed when you first access the Services.

  Via your browser settings (e.g., Chrome, Firefox, Safari) to block or delete cookies. Note that disabling essential cookies may prevent you from using core features of the Services (e.g., account login).

8. Data Security and Retention

8.1 Data Security

We implement technical, administrative, and physical measures to protect your Personal Information from unauthorized access, disclosure, alteration, or destruction. These measures include:

  Encryption of data in transit (via TLS 1.2+) and at rest (via AES-256 encryption).

  Access controls (e.g., role-based permissions, multi-factor authentication for admin accounts).

  Regular security audits and vulnerability assessments (conducted by third-party experts).

No method of data transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. If a data breach occurs, we will notify you and relevant authorities promptly (as required by law) and take corrective action.

8.2 Data Retention

We retain your Personal Information only for as long as necessary to fulfill the purposes outlined in this Policy, unless a longer retention period is required or permitted by law (e.g., tax records, legal disputes).

  Your account information: Retained for 2 years after your account is deactivated (to comply with legal obligations and resolve potential disputes).

  Candidate information: Retained for 1 year after you last accessed the candidate list (or longer if you request to archive it, subject to local laws).

  AI training data: Your input and candidate information used for AI training are anonymized after 6 months (to prevent identification of individuals).

Once retention periods expire, we securely delete or anonymize the Personal Information (e.g., via permanent data wiping or encryption with unrecoverable keys).

10. Your Privacy Rights & Choices

Your privacy rights may vary based on your region, but we generally support the following rights. To exercise these rights, please contact us at mokahr.dev@gmail.com (see Section 14 for full contact details). We will verify your identity (e.g., via a confirmation email to your registered address) before processing your request, to protect your data from unauthorized access.

10.1 General Rights

  Access: Request a copy of the Personal Information we hold about you (e.g., your account details, candidate lists you’ve accessed).

  Correction: Request correction of inaccurate or incomplete Personal Information (e.g., updating your job title or company name).

  Deletion: Request deletion of your Personal Information (e.g., closing your account and erasing your data), subject to legal retention requirements.

  Restriction: Request restriction of processing (e.g., pausing AI training using your data) if you dispute the accuracy of the information or object to processing.

  Data Portability: Request your Personal Information in a structured, machine-readable format (e.g., CSV file of your account data) to transfer to another service provider.

  Withdraw Consent: Withdraw consent for optional processing (e.g., unbinding your LinkedIn account). Note that withdrawing consent may limit your ability to use certain features (e.g., AI-generated LinkedIn outreach).

10.2 Regional-Specific Rights

  EEA/UK (GDPR/UK GDPR): You have the rights listed in Section 10.1. You may also lodge a complaint with your local data protection authority (e.g., ICO in the UK, CNIL in France) if you are dissatisfied with our response to your request.

  California (CCPA/CPRA): As a "consumer," you have the rights in Section 10.1. You also have the right to:

  Opt out of "sharing" of your Personal Information for cross-context behavioral advertising (Lexiom does not currently engage in this activity, but you may still request opt-out).

  Not be discriminated against for exercising your privacy rights (e.g., we will not charge you more or reduce service quality).

  Singapore (PDPA): You have the right to access and correct your Personal Information. Withdrawing consent may affect our ability to provide the Services (e.g., unbinding Gmail will prevent sending AI-generated Emails).

  Australia/New Zealand (Privacy Act/Privacy Act 2020): You have the right to access/correct your Personal Information and complain to the Office of the Australian Information Commissioner (OAIC) or New Zealand’s Privacy Commissioner.

11. Children’s Privacy

The Services are not intended for individuals under the age of 16. We do not knowingly collect Personal Information from children under 16. If we become aware that we have collected Personal Information from a child under 16, we will immediately cease processing and take steps to delete the data. Parents or guardians who believe their child has provided information to us may contact us at mokahr.dev@gmail.com to request deletion.

12. Third-Party Links and Services

The Services may contain links to third-party websites or services (e.g., LinkedIn, Gmail, or job boards). This Policy does not apply to these third parties. We are not responsible for the privacy practices or content of third-party platforms. We encourage you to review the privacy policies of any third parties you interact with through the Services.

13. Changes to This Policy

We may update this Policy to reflect changes in our practices, legal requirements, or the Services. When we make changes:

  We will post the updated Policy on the Lexiom website (e.g., https://hire-r1-voyage.mokahr.com/privacy-policy.html ) and update the "Effective Date" at the top.

  For material changes (e.g., new data collection purposes, changes to data sharing practices), we will notify you via email (to your registered address) or a prominent notice on the Services at least 7 days before the changes take effect (as required by law).

Your continued use of the Services after the effective date of the updated Policy constitutes your acceptance of the changes. We encourage you to review this Policy periodically.

14. Contact Us

If you have questions, concerns, or requests regarding this Policy or our privacy practices, please contact us via:

  Mailing Address: LEXIOM TECHNOLOGIES INC., []

  Privacy Inquiries / Data Subject Requests: mokahr.dev@gmail.com

  Security Issues: mokahr.dev@gmail.com

We aim to respond to all requests within the timeframe required by applicable law (e.g., 30 days under the CCPA/CPRA, 1 month under the GDPR).

Last Updated: [September 1, 2025]
Version: V1.0