Privacy Policy
Changed since 2 September 2026: section 2 and section 3(g) describe the Copilot's four modes and, for the three result buttons, exactly what leaves the device (the engine's result summary, never the figures entered), the daily allowance token and the per-address ceiling; the processor list, retention table and transfer note say the same. Changed since 1 September 2026: section 3(f) describes payment through Stripe Checkout, the plan token and the sign-in link; sections 4, 7, 8 and 9 add Stripe and the email provider. The 2 September version is kept unchanged at privacy-2026-09-02, the 1 September version at privacy-2026-09-01; the 29 July version at privacy-2026-07-29.
1. Who we are and how to reach us
This Privacy Policy explains how LEXUN ("LEXUN", "we", "us") handles personal data in connection with the website and application at lexun.co.uk (the "Service"). LEXUN is the data controller for that personal data for the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018).
Contact for any privacy matter, including a request to exercise your rights: privacy@lexun.co.uk. General contact: hello@lexun.co.uk.
Legal entity. LEXUN is a service of CA Capital Limited, a company registered at Companies House in the United Kingdom. CA Capital Limited is the data controller for the personal data described in this policy, which means it decides why and how that data is processed and is the organisation accountable to you and to the ICO for it. It is registered in England and Wales, company number 10848369, registered office 320 Firecrest Court, Centre Park, Warrington, United Kingdom, WA1 1RG — the record at Companies House. In practice the founder remains the only person who handles personal data. Legal notices should be sent to hello@lexun.co.uk.
ICO registration. Most UK organisations that process personal data must pay the ICO's annual data protection fee and appear on the ICO's public register of fee payers. CA Capital Limited's registration is not yet in place; it will be completed and the registration number published here at that point. We are not claiming an exemption, and we are not going to print a number we do not hold. Nothing about that pending status limits your rights below or your right to complain to the ICO today.
2. What the Service does by default: your decisions never leave your device
The decision engine runs entirely in your browser. The questions you type, the assumptions and figures you enter, the simulated probabilities the engine produces, the outcomes you later report and your personal track record are written to your browser's own local storage on your own device. They are not transmitted to us, we hold no copy, and we could not produce them if we were asked to.
This is a design constraint, not a promise about intent: there is no account system, no upload endpoint and no decision database. A consequence worth stating plainly is that we cannot recover your data for you — if you clear your browser storage, that data is gone. Export before you clear.
The LEXUN Key does not change any of that. The dashboard asks you to create a Key before it will save a decision, and before it will show you your saved record. That Key is a passcode which encrypts the record on your own device with AES-256-GCM, under a key derived from your passcode by PBKDF2-HMAC-SHA256 at 600,000 iterations. The passcode is never transmitted, never stored and never recoverable — there is no reset link because there is nobody on our side to reset anything. The only thing that leaves your device when you create a Key is the email address you type in, plus a yes/no marketing choice, and that is described in section 3(b) below. Running a decision works without a Key — see the next paragraph.
Where the Key is asked for, and how that line has moved. You can frame and run a full decision with no Key: the engine writes nothing while it runs, so there is nothing to encrypt. The Key is asked for at the moment you press save, because that is the first action that puts a decision into storage, and a record saved without a Key would sit in your browser unencrypted. Between 30 July and 5 August 2026 a Key was required to run a decision as well. Both changes are recorded here rather than quietly deleted, because the first reversed something this page had promised and the second reversed the first. What did not change across either is the architecture: the maths has always happened entirely in your browser, and nothing about your decision has ever been transmitted. And the pages that let you check our claims without taking our word for anything — accuracy, reproduce, verify and trust — remain open to everyone with no Key, no email and no account, because a claim you cannot check is not a claim.
The one exception to "nothing leaves your device": the Copilot. The workspace carries an optional text assistant, the Copilot, in four places: the conversation box on the sign-in screen, the "describe the decision in your own words" box on New decision, and the "Explain this result", "Challenge my assumptions" and (for Organisation seats) "Board summary" buttons under a result. It is the only feature on this site that transmits anything you type or anything derived from a decision, and it does so only when you press its button. What goes to Anthropic PBC, whose model produces the reply: for the conversation and description boxes, the words you typed (which may include figures you chose to type); for the three result buttons, the engine's result summary — the band, the probability range, the scenario survival percentages, the names of your inputs and which of them you marked as assumptions, the sensitivity ranking, the resolution criterion and date — and never the figures you entered: no cash balance, revenue, costs, buffer or income figure is included, and the server discards anything outside that list before the request is built. Nothing else goes with them: not your email, not your Key, not your passcode, not your encrypted record, not a saved decision. We do not store any of it — it is held in your browser's memory for the visit — and we write none of it to any database, log or file of ours. Every number in a reply is checked against what the engine produced, and any figure the model wrote on its own is removed before you see it. It is described in section 3(g) below; each box carries the same warning before you use it. If you would rather nothing at all left your device, do not press those buttons: every other part of LEXUN works without them.
Every key we write, what it holds and how to delete it is listed in full on the Cookies & local storage page, which also carries a control that erases all of it in two clicks. There are no cookies of any kind on this site.
3. The personal data we actually receive
There are exactly eight ways personal data can reach us or a processor acting for us. Nothing else on this site collects anything.
a) The waitlist form
If you submit the form at /join we receive the email address you type, and nothing else. We use it to email you when a named feature ships (sync, exports, reminders). We do not add it to any other list, and every email carries a one-click unsubscribe.
b) The LEXUN Key sign-up
When you create a LEXUN Key on the dashboard we receive at most two things: the email address you type if you choose to give one (the field is optional and says so), and whether you ticked the marketing box (recorded literally as "yes" or "no"). That is the entire transmission. Specifically, we do not receive your passcode, any key derived from it, the encrypted record, or anything you have analysed — the browser sends the email address and the marketing flag and nothing else, which you can confirm in your browser's network inspector.
The email address is held so that we can reach you about the Key itself: to warn you before anything changes that could affect a locally encrypted record, and to answer you if you contact us about it. We will only send you product or launch marketing if you ticked the box, and the box is never pre-ticked. You can withdraw that consent at any time using the unsubscribe link in any email or by emailing privacy@lexun.co.uk, and withdrawing it does not disable your Key or touch your data — the two are unconnected, because there is no account linking them.
If the sign-up request fails (you were offline, for example) your browser keeps the email address and the marketing choice in local storage and tries once on your next visit, then deletes them whether or not that retry worked. It is not a queue that holds your email address indefinitely. The key it uses is listed on the cookies page.
Because your Key is not an account, deleting your email address from our side is straightforward and has no side effects: email privacy@lexun.co.uk from the address in question, or ask from any address and tell us which one to remove, and we will delete it from the form store and from the mailing list. Your decisions are unaffected either way, since we never had them. To erase the encrypted record itself, use "Delete all data" in the dashboard's Settings, or the erase control on the cookies page — both act only on your device.
c) The contact form
If you submit the form at /contact we receive the fields you complete: first name, last name, work email, job title, company, team or function, company size, what you want to analyse, how you decide today, and your free-text message. We use these solely to answer you. Only first name, last name and email are required; the rest you may leave blank and the form will still send.
d) Email you send us
If you email hello@ or privacy@lexun.co.uk we hold that correspondence in our mailbox in order to reply, and to keep a record of requests we are obliged to log — for example a rights request under section 10 below.
e) Server request logs
Our hosting provider records standard web-server information when a page is requested — IP address, timestamp, the URL requested, user-agent and referrer — for security, abuse prevention and availability. These logs sit with the host under its own retention policy. We do not copy them into any analytics tool, join them to anything else, or use them to identify individuals.
f) Payments — Pro and Organisation seats
Paid plans are bought through Stripe Checkout, a page on Stripe’s own domain. Card details, Apple Pay and Google Pay are handled entirely by Stripe and never reach us or are visible to us. Checkout takes money only once the operator has configured Stripe for this site; until then the buy buttons do not appear and this paragraph describes software that is built but not yet taking payment.
What goes to Stripe when you start a checkout. The plan and seat count you chose; if your LEXUN Key holds an email address, that address, so you do not retype it; and a short non-reversible reference derived from your Key’s creation record, so that a payment can later be matched to the same Key without your email or passcode appearing in any URL. Stripe then collects your billing details itself, under Stripe’s privacy policy, acting as an independent controller for payment processing and as our processor for the subscription record.
What comes back to us. Stripe’s customer reference, the subscription’s status (trialing, active, past due, cancelled), its plan, seat count and dates, and the email you gave Stripe. That is the whole of your subscription record on our side, and it is held by Stripe, not in a database of ours: our server functions read it from Stripe when needed and write short audit notes (the last subscription event and when it happened) back onto your Stripe customer record. We keep no card number, no partial card number and no bank detail, ever. Stripe notifies our server of subscription events (a payment succeeded or failed, a plan changed or ended) by signed webhook; those notifications carry the same fields and no card data.
The plan token. After a checkout completes, our server hands your browser a signed token naming your Stripe customer reference and your plan; it is stored in your browser (see the cookies page), presented to our server on each visit so the plan can be re-confirmed with Stripe, and removed when the plan ends or when you sign the device out in Settings. Nothing in your browser is treated as proof of payment on its own.
Signing in on another device. If you ask for a sign-in link, the email address you type is used once, to look up whether a Stripe customer exists for it and to send that address a link valid for thirty minutes. The reply on screen is the same whether or not the address is known, so the feature cannot be used to test who is a customer. The link is sent through an email provider acting as our processor (named in section 8 once connected); the address is not stored by us after sending.
Your decision data plays no part in any of this: nothing about what you decided, entered or scored is sent to Stripe, to the email provider, or to us.
g) The Copilot
The workspace at /platform carries an optional text assistant, the Copilot. It is the only feature on LEXUN that transmits anything you type or anything derived from a decision, it acts only when you press its button, and each of its boxes says so before you use it.
What is sent, by mode. Conversation (the sign-in screen): the message you type, plus the earlier messages and replies in that same conversation so the assistant can follow the thread. Describe the decision (New decision): the description you type, which may include figures you chose to type; the Copilot fills the form only with figures that appear in your own words and never adds one. Explain this result, Challenge my assumptions and, for Organisation seats, Board summary: the engine's result summary — the band, the probability range, each scenario's survival percentage, the names of your inputs and which are assumptions, the sensitivity ranking, the resolution criterion and date — and never the figures you entered. All of it goes to Anthropic PBC (San Francisco, USA), which runs the model that writes the reply, acting as our processor. What is never sent: your email address, your Key, your passcode, your encrypted record, any saved decision, and any input figure — the request is built from a fixed list of fields that does not contain them, and you can confirm it in your browser's network inspector. Every number in a reply is checked against what the engine produced; a figure the model wrote on its own is removed before it reaches you and the reply says how many were removed.
What is kept. By us: nothing. The conversation lives in your browser's memory for the length of the visit and is discarded when you close or reload the tab; it is never written to your device's storage, to our forms store, or to any log of ours. The only thing our server records is that a request happened and how long it took — not its contents. By Anthropic: their API terms provide that inputs and outputs submitted through it are not used to train their models, and they retain them only briefly for abuse monitoring. We link to their terms in section 8.
Because you can type anything into a free-text box, treat it like an email to a stranger: do not paste bank details, passwords, medical information or anyone else's personal data into it. The assistant is instructed to refuse financial, legal, medical and investment advice and never to invent a figure, but it is a language model and it can still be wrong — the numbers on LEXUN come from the engine, which is reproducible, not from the assistant, which is not.
The allowance. Free plans have three Copilot messages a day, Pro sixty and Organisation seats two hundred. The count is kept by our server in a signed token that your browser holds (lexun.copilot.v1) and presents with each request; it contains the day, the count and your plan tier, and nothing about you. If you hold a paid plan, the plan token described in section 3(f) is sent with the request so the server knows the allowance to apply. Our server also keeps, for one day and in memory only, a count of requests per connecting address as a ceiling against abuse; it is not linked to you and is not written anywhere.
h) The organisations request form
If you submit the request form on /organisations, /packages, /pilot, /decision-audit or /procurement we receive the fields you complete: your name, work email, organisation, role, team size, the type of decision you have in mind, your preferred next step, an optional message, and your consent tick. The form also records which page and button it was sent from, the page that referred you, and any campaign (utm) codes in the address you arrived on, so we know which route brought the request; it never records anything about a decision you may have analysed. The same answers are packaged into a single structured field so the request can be moved into a customer-relationship tool without retyping; no such tool is connected today — requests sit in the hosting provider’s form store and are read by the founder. We use these details solely to respond to the request you chose. Submitting the form books nothing: a pilot, an audit or a call starts only when we have confirmed it with you in writing. To have a request deleted, email privacy@lexun.co.uk; it is removed from the form store within 30 days and confirmed to you.
4. Our lawful bases for processing
UK GDPR Article 6 requires a lawful basis for every processing activity. Ours are:
| What | Purpose | Lawful basis |
|---|---|---|
| Waitlist email | Emailing you when a feature ships | Consent — Article 6(1)(a). You give it by submitting the form having read the wording beside the button; you can withdraw it at any time via the unsubscribe link or by emailing us. Regulation 22 of the Privacy and Electronic Communications Regulations 2003 also requires consent for this kind of email, which is why the waitlist is opt-in and never pre-ticked. |
| LEXUN Key sign-up email | Contacting you about the Key itself — chiefly to warn you before a change that could affect a locally encrypted record | Legitimate interests — Article 6(1)(f): telling someone who has encrypted data under our software about a change that could cost them that data. We have weighed your interests: it is one address, given deliberately, used for a message you would want to receive, and removable on request in one email. |
| LEXUN Key marketing box | Sending you product and launch email | Consent — Article 6(1)(a), and Regulation 22 PECR. The box is unticked when the page loads and the Key is created whether or not you tick it, so ticking it is a positive act. Withdrawable at any time under Article 7(3) via unsubscribe or email, without affecting your Key or your data. |
| Contact form | Answering the enquiry you sent | Legitimate interests — Article 6(1)(f): replying to someone who has deliberately contacted us. Where your enquiry concerns taking a plan, Article 6(1)(b) — steps at your request prior to a contract — also applies. |
| Email correspondence | Replying, and logging rights requests | Legitimate interests — Article 6(1)(f) for replies; legal obligation — Article 6(1)(c) for the record of a rights request or a breach. |
| Server logs | Security, abuse prevention, availability | Legitimate interests — Article 6(1)(f). We have weighed your interests: the data is transient, is not used to identify anyone, and no service can be operated safely without it. |
| Copilot messages and result summaries | Sending what you type — or, when you press one of the result buttons, the engine's result summary without your figures — to Anthropic's API so a reply can be produced, and only that | Legitimate interests — Article 6(1)(f): delivering the feature you have just deliberately used, in the only way it can be delivered. We have weighed your interests: the assistant is optional, it warns you before you type, it is not used for anything except answering you, no copy is kept by us, and you can simply not use it without losing any other part of the Service. If you object under Article 21, the answer is immediate — stop using the box, and there is nothing left to object to. |
| Local storage on your device | Making the application work and remembering your preferences | No Article 6 basis is engaged, because none of it reaches us. The separate Regulation 6 PECR question of storing information on your device is dealt with on the cookies page. |
| Payments and the plan token | Taking payment through Stripe; confirming which plan you hold each time you open the workspace; sending a sign-in link you asked for; keeping tax records | Contract — Article 6(1)(b): delivering the plan you bought, and only that; and legal obligation — Article 6(1)(c) for the retention of financial records. |
Where we rely on legitimate interests you have the right to object under Article 21, and we will stop unless we can demonstrate compelling grounds that override your rights. Where we rely on consent you can withdraw it at any time under Article 7(3), which does not affect processing already carried out.
5. Special category and criminal offence data
We do not ask for, and have no use for, the special categories of data listed in Article 9 — health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, sex life or sexual orientation — or criminal offence data under Article 10.
The free-text boxes on the contact form will accept whatever you type. Please do not put special category data in them. If you do, we will use it only to answer you and will delete it as soon as that is done. If your enquiry genuinely requires it, email us first and we will agree a safer route.
The same applies inside the application, with one difference that works in your favour: text you type into the decision engine never reaches us at all, so it cannot be disclosed by us even in error.
6. Automated decision-making and profiling (Article 22)
Article 22 gives you the right not to be subject to a decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you. A product that produces probabilities should be explicit about where it stands, so:
- LEXUN's engine runs a simulation over figures you supply and returns a probability band for you to act on. It does not make any decision about you: it does not score you, rank you, grant or refuse you anything, price anything by reference to you, or pass a judgement about you to anyone.
- It produces no legal effects and nothing similarly significant in the Article 22 sense. The consequential decision is always yours, taken by you, after reading the output.
- We do not profile you. There is no behavioural model of any user, because there is no user record — the engine has no memory of anyone beyond the browser it is running in.
- The processing happens in your browser, on your device, on data we never receive.
Even though Article 22 is not engaged, we have built the safeguards it contemplates anyway, because they are the point of the product: every output states its drivers and assumptions, labels what is fact and what is assumed, shows the random seed and the model version, and links to a reproduction of the same run. If a result looks wrong to you, you can see why it came out that way and challenge it — and you can email privacy@lexun.co.uk to have a human explain it.
7. How long we keep things
| Data | Kept for |
|---|---|
| Waitlist email | Until you unsubscribe or ask us to delete it, or 24 months after the last launch email we send you — whichever comes first. Then deleted from the form store and the mailing list. |
| LEXUN Key sign-up email | Until you ask us to delete it, or 24 months after the last email we send you — whichever comes first. Deleting it does not lock, unlock or erase anything on your device, because nothing on our side is joined to it. |
| Failed sign-up held on your device | Until the single retry on your next visit, then deleted from your browser whether or not the retry succeeded. |
| Contact submission | 24 months from our last correspondence with you, then deleted. Sooner on request, unless we need it for a legal claim. |
| Organisations request | 24 months from our last correspondence with you, then deleted; where the request leads to a contract, for the life of the contract and six years after it ends, as UK law on business records requires. Sooner on request where no contract exists. |
| Email correspondence | 24 months from the last message in the thread. Records of rights requests and of any breach are kept longer, where we are obliged to be able to demonstrate compliance. |
| Server logs | Held by the hosting provider under its own retention policy. We do not extend it, export the logs, or retain a separate copy. |
| Copilot conversation and result summaries | Not kept by us at all. It is held in your browser's memory for the length of the visit and is discarded when you close or reload the tab. It is never written to your device's storage or to any store of ours. Anthropic retains inputs and outputs only for the limited period set out in its own policy for abuse monitoring; we do not extend that and hold no copy. |
| Copilot allowance token | Until you clear your browser data; the count inside it resets each day. It holds the day, a count and a plan tier, identifies nothing about you, and is presented to our server with each Copilot request. |
| Data on your device | Until you erase it. Nothing expires it for you, and nothing on our side can reach it. See the cookies page for the erase control. |
| Subscription record (held by Stripe) | For the life of the subscription and six years from the end of the financial year the last payment relates to, as UK tax law requires for financial records. Deleting your Stripe customer record earlier is possible on request where no payment was ever taken (a trial that ended without a card). |
| Plan token in your browser | Until the plan ends, you sign the device out in Settings, or you erase your browser data. Re-verified with Stripe on each visit; tokens expire after thirty days and are re-issued on verification. |
| Sign-in link request | The email address is used once to send the link and is not stored by us. The link itself expires after thirty minutes. |
8. Who else processes your data
We use a small number of processors. Each acts on our documented instructions under a contract meeting Article 28 UK GDPR. This is the complete list at the date above.
| Who | What they do | Where |
|---|---|---|
| Netlify, Inc. | Hosts the site and its CDN; receives and stores submissions from the waitlist form, both contact forms, the organisations request form, the accuracy-record notification form and the LEXUN Key sign-up; keeps the server request logs | United States |
| Mailbox provider | Delivers and stores email sent to and from our @lexun.co.uk addresses | Named on request |
| Anthropic PBC | Runs the model behind the optional Copilot. Receives the messages you type into its boxes, and — only when you press Explain, Challenge or Board summary — the engine's result summary (band, probability range, scenario percentages, input names and which are assumptions), and nothing else: no email address, no Key, no passcode, no input figure, no saved decision. Used only to produce the reply. Under its API terms, inputs and outputs are not used to train its models. | United States |
| Stripe Payments Europe Limited / Stripe, Inc. | Processes card, Apple Pay and Google Pay payments on its own pages and holds the subscription record (customer reference, plan, seats, status, dates, billing email, invoices). We receive the subscription fields, never a card number. Active only once the operator has configured Stripe for this site. | Ireland / United States |
| Email provider for sign-in links (when connected) | Sends the thirty-minute sign-in link to the address you type on the plans page. Receives that address and the link, once. Named here the day it is connected; until then the feature says it is not connected. | Named on connection |
We do not use an analytics provider, an advertising network, a customer-data platform or a chat widget. We do use one AI vendor, Anthropic, and only for the Copilot described in section 3(g) — it receives what you type into its boxes and, when you ask it to explain, challenge or summarise a result, the result summary described there; it never receives the figures you entered or a saved decision, which do not leave your device for any purpose. We may disclose personal data where we are legally required to — for example in response to a valid court order — and we will tell you when that happens unless we are prohibited from doing so.
9. International transfers
Our hosting provider is headquartered in the United States, so form submissions and server logs may be processed outside the UK. The same is true of the Copilot: what is typed into it, and the result summaries described in section 3(g), are sent to Anthropic PBC in the United States. Payments are processed by Stripe Payments Europe Limited in Ireland, with Stripe, Inc. in the United States as a sub-processor, and a sign-in link you ask for is sent through an email provider that may be in the United States. Where that happens we rely on the transfer safeguards permitted by Article 46 UK GDPR — the ICO's International Data Transfer Agreement, or the ICO's Addendum to the EU Standard Contractual Clauses — and, where it applies to the recipient, the UK Extension to the EU–US Data Privacy Framework. You can ask us which mechanism is relied on for any specific transfer and we will tell you.
None of this applies to your decision data, which is not transferred anywhere, because it never leaves your device.
10. Your rights
Under UK GDPR and the DPA 2018 you have the following rights over personal data we hold about you. Where the data is on your device you can exercise most of them yourself, immediately, without asking us.
| Right | What it means | How to use it |
|---|---|---|
| Access Art 15 | A copy of your personal data, and information about how it is used | Email us; or for on-device data, export it yourself from the app |
| Rectification Art 16 | Correction of data that is inaccurate or incomplete | Email us; on-device data you can edit directly |
| Erasure Art 17 | Deletion of your data, where we have no overriding reason to keep it | Email us; or erase everything on your device from the cookies page |
| Restriction Art 18 | Freezing our use of your data while a dispute about it is resolved | Email us |
| Portability Art 20 | Your data in a structured, machine-readable format | Export from the app as JSON; email us for form data |
| Object Art 21 | Objecting to processing based on legitimate interests | Email us, telling us what you object to |
| Object to marketing Art 21(2) | An absolute right to stop direct marketing — we cannot refuse it or ask you to justify it | Unsubscribe link in any email, or email us |
| Withdraw consent Art 7(3) | Withdrawing consent as easily as you gave it | Unsubscribe link, or email us |
| Automated decisions Art 22 | Not being subject to solely automated decisions with legal or similar effects | See section 6 — we make none. Ask us anyway if you want that in writing |
| Complain Art 77 | Complaining to the ICO, whether or not you have complained to us first | See section 16 |
How we handle a request. Email privacy@lexun.co.uk. We will respond within one month. If a request is genuinely complex we may extend that by up to two further months under Article 12(3), and we will tell you within the first month if we do, and why. There is no charge. We will ask for proof of identity only where we have a real doubt about who you are, and only so far as that is proportionate — we will not use an identity check to slow you down. If we refuse a request we will tell you why, and tell you that you can complain to the ICO and seek a judicial remedy.
11. Security
We take technical and organisational measures appropriate to the risk (Article 32). Rather than assert good practice in the abstract, here is what is actually in place and independently checkable:
- The site is served only over HTTPS, with HTTP Strict Transport Security, so a browser will not fall back to an unencrypted connection.
- A Content-Security-Policy is enforced, alongside X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy and Cross-Origin-Opener-Policy. You can verify these in your browser's network panel or with any public header scanner.
- There is no server-side store of decision data to breach, because there is no server-side store of decision data.
- No third-party script runs on this site, so there is no supply-chain route into your session. Fonts are self-hosted for the same reason.
- Form submissions and email are held by the providers named in section 8, protected by their own controls and by multi-factor authentication on our accounts.
No system is perfectly secure, and we will not pretend otherwise. If you believe you have found a vulnerability, please tell us at privacy@lexun.co.uk before disclosing it publicly, and we will work with you.
12. Children
The Service is not directed at children. Under section 9 of the DPA 2018 the age at which a child can consent to an online service in the UK is 13, and we do not knowingly collect personal data from anyone under that age. If you believe a child has sent us personal data, email privacy@lexun.co.uk and we will delete it.
13. If something goes wrong: personal data breaches
If a personal data breach occurs we will assess it immediately. Where it is likely to result in a risk to your rights and freedoms we will report it to the ICO within 72 hours of becoming aware of it (Article 33). Where it is likely to result in a high risk to you we will also tell you directly, without undue delay and in plain language, along with what we are doing about it and what you should do (Article 34). We keep a record of every breach, including those we decide are not reportable, and our reasons.
14. Data Protection Officer
We have not appointed a Data Protection Officer, and we are not required to: we are not a public authority, and our core activities do not consist of large-scale regular and systematic monitoring, or large-scale processing of special category data. Privacy requests are handled by the founder, reachable at privacy@lexun.co.uk. If that position changes, this section changes with it.
15. If you are outside the UK
The Service is offered from, and aimed at, the United Kingdom. We have not appointed a representative in the EU under Article 27 of the EU GDPR, because we do not target the EU market or monitor behaviour there. You are welcome to use the Service from anywhere — the engine runs in your browser regardless — but this policy is written to UK law, and if you contact us from the EU we will handle your request to the same standard set out above.
16. Complaints, and the ICO
If you are unhappy with how we have handled your personal data or a request, tell us first at privacy@lexun.co.uk — we would rather fix it than have you chase it. But you do not have to come to us first, and nothing in this policy requires you to. You have the right under Article 77 to complain directly to the UK's supervisory authority at any time:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline 0303 123 1113 · ico.org.uk
You may also seek a remedy through the courts.
17. Changes to this policy
We will update this policy when what we do changes. The honest version of that promise is a specific one: this policy is re-read against the codebase whenever a release changes what data is collected, stored or sent, and the date at the top records when that last happened. If a change materially affects your rights we will say so prominently rather than quietly moving the date. Previous versions are available on request.