Juridisk

Databehandleraftale

Indgås mellem kunden som dataansvarlig og Lexi Technologies ApS som databehandler. Aftalen er en integreret del af kundeaftalen og opfylder kravene i GDPR artikel 28.

Version v1.2 · Publiceret 19. april 2026

Åbn PDF i ny faneDownload PDF

Teksten nedenfor er udtrukket fra den offentliggjorte PDF, så den kan læses og søges direkte på siden. Ved uoverensstemmelser er PDF-versionen den gældende.

Lexii Data Processing Agreement Lexii Data Processing Agreement Lexi Technologies ApS · CVR no. 45484017 · Denmark Version 1.0 Effective from 18 April 2026 Contact hey@lexii.io This Data Processing Agreement accompanies the Lexii Customer Agreement and is entered into alongside it. Both documents are available at lexii.io.

This Data Processing Agreement (“DPA”) is entered into between the Customer as controller and Lexi Technologies ApS, CVR no. 45484017, Denmark, as processor. The DPA forms an integral part of the Lexii Customer Agreement and satisfies the requirements of Article 28 of Regulation (EU) 2016/679 of the European Parliament and of the Council (“GDPR”).

1. Purpose and background

  • Lexii provides a software-based service under the Lexii brand, including functionality for handling inquiries via web, chat, forms, email and related support and automation flows.
  • To the extent Lexii, as part of providing the service, processes personal data on behalf of the Customer, Lexii is the processor and the Customer is the controller.

2. Acceptance and entry into force

  • This DPA enters into force when the Customer accepts it electronically in connection with account creation, profile creation or subscription at Lexii.
  • The electronic acceptance is considered documented instruction to Lexii to process personal data in accordance with the Lexii Customer Agreement, this DPA and the Customer’s configuration and use of the service.

3. Instructions

  • Lexii may only process personal data on documented instruction from the Customer, unless processing is required by EU law or national law; in such case, Lexii shall inform the Customer of the legal requirement, unless such information is prohibited.
  • The Lexii Customer Agreement, this DPA, the Customer’s use of the platform, configurations in the platform and any written support or administration instructions together constitute the Customer’s documented instruction.
  • Lexii shall not use personal data for its own purposes, including not for training general-purpose AI models.
  • Lexii shall immediately inform the Customer if Lexii believes an instruction infringes data protection law.

4. Subject matter, nature and purpose of the processing

  • Lexii’s processing is carried out for the purpose of delivering, operating, maintaining, supporting and securing the Lexii service and the features the Customer has ordered or activated.
  • The processing may include collection, recording, structuring, organisation, storage, adaptation, searching, use, disclosure by transmission, restriction, deletion and other processing necessary for the provision of the service.
  • A more detailed description of the subject matter, categories of data subjects and personal data and duration is set out in Annex 1.

5. Customer responsibility

  • The Customer is responsible for ensuring that there is a valid legal basis for the personal data processed using the service.
  • The Customer is responsible for ensuring that the personal data uploaded, collected or otherwise made available to Lexii is relevant, necessary and lawfully processed.
  • The Customer may not use the service for processing special categories of personal data (GDPR art. 9), data on criminal convictions and offences, or CPR numbers, unless expressly agreed in writing in an addendum.

6. Confidentiality and authorisation

  • Lexii ensures that persons authorised to process personal data have committed to confidentiality or are subject to an appropriate statutory obligation of confidentiality.
  • Access to personal data is limited to persons with a legitimate work-related need.

7. Security

  • Lexii implements appropriate technical and organisational security measures, taking into account the state of the art, the cost of implementation and the nature, scope, context, purposes and risks of the processing, cf. GDPR art. 32.
  • Security measures are further described in Annex 2.

8. Sub-processors

  • By accepting this DPA, the Customer grants Lexii a general prior authorisation to engage sub-processors.
  • The sub-processors approved from time to time are set out in Annex 3 and/or Lexii’s sub-processor list, available via the platform or Lexii’s website.
  • Lexii shall give at least 30 days’ prior notice of material changes to the sub-processor list (addition or replacement), allowing the Customer reasonable time to object.
  • If the Customer raises a reasoned objection to a new sub-processor and the parties cannot find a solution, the Customer may terminate the affected part of the service with effect from the date the change takes effect, without compensation to either party.
  • Lexii shall impose on sub-processors data protection obligations at least equivalent to those in this DPA and is directly liable for the sub-processor’s compliance.

9. Transfers to third countries

  • Lexii may only transfer personal data to countries outside the EU/EEA or to international organisations if the conditions in GDPR Chapter V are met.
  • Where third-country transfers take place, Lexii generally relies on the European Commission’s Standard Contractual Clauses (SCCs) and carries out a Transfer Impact Assessment (TIA) and relevant supplementary measures.
  • Current third-country transfers are set out in Annex 3.

10. Assistance to the Customer

  • Lexii shall, taking into account the nature of the processing and the information available to Lexii, assist the Customer in fulfilling obligations relating to data subjects’ rights (GDPR art. 12–23).
  • Lexii shall further assist the Customer with reasonable and necessary information regarding security, personal data breaches, impact assessments and any prior consultation with authorities (GDPR art. 32–36).
  • Assistance beyond ordinary standard assistance may be invoiced at Lexii’s hourly rates from time to time, subject to prior notice to the Customer.

11. Personal data breaches

  • Lexii shall notify the Customer without undue delay, and no later than 48 hours after Lexii becomes aware of a personal data breach.
  • The notification shall, to the extent possible, contain the nature of the breach, the types of data and data subjects affected, the likely consequences, any remedial measures taken or proposed and a Lexii point of contact.

12. Audit and documentation

  • Lexii shall, upon request, make available the information necessary to demonstrate compliance with this DPA.
  • The Customer is entitled to audit Lexii’s compliance with the DPA. Lexii will generally satisfy this by making relevant documentation available, including descriptions of security measures, declarations or audit reports (e.g. ISAE 3000, ISO 27001 or equivalent, where available).
  • If such documentation is not sufficient, the Customer may, with at least 30 days’ written notice, request an audit no more than once per year, unless special circumstances justify more frequent audits. Audits shall take place during ordinary business hours and must not unduly disrupt Lexii’s operations. The Customer shall bear its own costs for audits.

13. Deletion and return

  • Upon termination of the Lexii Customer Agreement, Lexii shall, at the Customer’s option and to the extent technically possible within the standard functionality of the service, make data available for export in a commonly used machine-readable form for up to 30 days after termination, and subsequently delete or anonymise the personal data within a reasonable period, generally no later than 90 days after termination.
  • Backup data may be deleted in accordance with Lexii’s ordinary backup cycle (maximum 90 days), provided that the data remains protected and is not made available for other purposes.

14. Changes, liability and governing law

  • Lexii may amend this DPA with reasonable notice if necessary due to legislation, regulatory practice, changes in the service or sub-processors, or the need for clarification.
  • The parties’ liability under this DPA is governed by the liability provisions of the Lexii Customer Agreement, unless mandatory data protection law provides otherwise.
  • This DPA is governed by Danish law.

Annex 1 – Description of the processing

Topic Description Purpose Delivery of the Lexii platform, AI-supported customer dialogue on web and email, handling and responding to inquiries, routing, support and case preparation, operations, hosting, maintenance and technical support.

Categories of data subjects Customers, prospective customers, leads, website visitors, persons contacting the Customer via chat, form or email, and the Customer’s employees and contact persons.

Categories of personal data Name, email address, phone number, company name, position, content of communications in messages, chats, forms and emails, technical metadata and log information, and other data entered by the Customer or the data subject.

Special categories The solution is not intended for the processing of sensitive data (GDPR art. 9), data on criminal convictions and offences, or CPR numbers, unless specifically agreed in writing.

Duration For as long as the Customer uses the service, and for a subsequent limited period (generally up to 90 days) necessary for export, support, backup, error handling, security and statutory retention.

Annex 2 – General security measures

  • Role-based access control and least-privilege principle.
  • Password policies and strong authentication (MFA) for privileged users.
  • Encryption in transit (TLS 1.2+) and, where relevant, encryption at rest.
  • Relevant backup and restore procedures with testing.
  • Logging of administrative actions and security-relevant events.
  • Patching and maintenance of infrastructure in accordance with vendor recommendations.
  • Internal procedures for confidentiality, incident handling and personal data breaches.
  • Vendor management for sub-processors, including assessment of third-country transfers.
  • Separation of production and test environments.

Annex 3 – Sub-processors and third-country transfers

Lexii’s current sub-processors are set out in the table below. The updated list is available at any time on Lexii’s website or via the platform.

Sub-processor Function Processing location Transfer basis Heroku (Salesforce Inc.)

Application hosting and PostgreSQL database incl. pgvector for structured data, customer data and knowledge management EU (Ireland) N/A (EU/EEA)

Airtable, Inc. Structured data management USA SCCs + supplementary measures Voyage AI, Inc. Generation of vector representations (embeddings)

USA SCCs + supplementary measures Anthropic, PBC Generation of AI responses (primary LLM)

USA SCCs + supplementary measures Together AI, Inc. Generation of AI responses (secondary LLM, summarisation)

USA SCCs + supplementary measures Microsoft Ireland Operations Ltd. (Graph API)

Email integration for Outlook/Microsoft 365 customers EU N/A (EU/EEA)

Google Ireland Ltd. (Gmail API)

Email integration for Google Workspace customers EU/USA SCCs where relevant Where third-country transfers take place, they are based on the European Commission’s Standard Contractual Clauses (Module 2: Controller-to-Processor or Module 3: Processor-to- Processor, depending on the processing role). Lexii has carried out a Transfer Impact Assessment (TIA) and applies relevant supplementary measures, including encryption in transit and data processing agreements with all sub-processors.