Effective Date: May 27, 2026 · Last Updated: June 5, 2026
This Privacy Policy explains how Lexonica Inc. ("Lexonica," "Company," "we," "us," or "our"), a corporation incorporated under the laws of Canada with its registered office in the Province of New Brunswick, collects, uses, discloses, stores, and protects personal information in connection with the ReputationCalc website, applications, and related services (collectively, the "Service").
This Privacy Policy applies to all users of the Service, including visitors, registered users, and subscribers. By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy.
This Privacy Policy is incorporated into and forms part of our Terms of Service. Where the Service processes personal data on behalf of customers, the terms of our Data Processing Agreement (DPA) also apply. In the event of a conflict between this Privacy Policy and the Terms of Service, the Terms of Service shall prevail to the maximum extent permitted by applicable law.
You acknowledge that you do not rely on this Privacy Policy, or on any description of our data handling practices, as a guarantee of security, regulatory compliance, or risk-free processing. The Service is not intended to be relied upon as the sole basis for any legal, regulatory, compliance, or business decision regarding the processing of personal data. The disclaimers, limitations of liability, and indemnification provisions in our Terms of Service apply to all matters arising under this Privacy Policy.
For the purposes of applicable data protection laws:
Where Lexonica acts as a data processor, our processing is governed by the Data Processing Agreement and the user's instructions. This Privacy Policy primarily describes Lexonica's practices as a data controller.
Lexonica is committed to complying with applicable privacy and data protection laws, including but not limited to:
Where local law provides additional rights or protections, those rights apply to the extent required by law.
While Lexonica implements measures designed to comply with applicable data protection laws, we do not guarantee compliance in all jurisdictions or under all circumstances. Data protection laws vary by jurisdiction and are subject to change, differing regulatory interpretations, and evolving enforcement practices. To the extent permitted by applicable law, Lexonica disclaims liability for any non-compliance resulting from changes in law, conflicting regulatory requirements, or circumstances beyond our reasonable control.
We may collect personal information that you voluntarily provide, including:
When you access the Service, we may automatically collect:
We may receive information from Third-Party Services integrated with the Service, including sanctions databases, adverse media sources, court record providers, company registries, and news aggregators. This information is used to generate screening results and risk assessments at your direction.
Personal information obtained from third-party sources may be inaccurate, incomplete, outdated, or contain errors. Lexonica does not independently verify the accuracy of data received from third-party providers and makes no representations or warranties regarding such data. You are responsible for independently verifying all information before making any decision based on it.
When you submit personal data of third parties (such as names, addresses, dates of birth, national identifiers, or other identifying information of individuals or entities) to the Service for screening or due diligence purposes, you are the data controller for that data and bear sole responsibility for:
Lexonica processes this data solely as a data processor under your instructions and in accordance with our Data Processing Agreement. Lexonica disclaims all liability arising from your failure to comply with your obligations as data controller for third-party personal data submitted to the Service.
You assume all risks associated with submitting, processing, and storing personal data through the Service, including the risk that screening results based on such data may be inaccurate, incomplete, or outdated. Lexonica does not verify the lawfulness or accuracy of data you submit.
We use personal information for the following purposes:
We do not sell personal information.
Lexonica may create aggregate, anonymized, or de-identified data derived from personal information by removing or obscuring any identifying characteristics. Such data is not personal information under applicable data protection laws. Lexonica may use, disclose, and retain aggregate or de-identified data for any lawful purpose, including service improvement, analytics, research, benchmarking, and statistical reporting, without restriction and without obligation to you.
Lexonica may process and retain personal information where reasonably necessary to:
Personal information retained for these purposes will be processed only to the extent necessary and will be protected with appropriate safeguards.
Where GDPR applies, Lexonica processes personal information based on one or more of the following legal bases:
Where consent is the legal basis for processing, Lexonica obtains consent through clear, affirmative actions, including:
Consent records — including the type of consent, timestamp, IP address, and method (e.g., checkbox, banner) — are stored in our database. These records are retained for the duration required to demonstrate compliance with applicable laws.
You may withdraw consent at any time by contacting us at tim@lexonica.com, deleting your account through your account settings, or adjusting your cookie preferences by clearing your browser cookies (which will re-trigger the consent banner). Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
The Service includes AI-assisted features that analyze data from multiple sources to produce risk assessments and screening reports.
AI-generated outputs may be inaccurate, incomplete, outdated, or misleading. Screening results may produce false positives (incorrectly flagging an entity) or false negatives (failing to identify a genuine risk indicator). AI outputs are provided on an "as is" basis and do not constitute legal, regulatory, compliance, or professional advice. You must independently verify all AI-generated content before making any decision. Lexonica disclaims all liability for decisions, actions, losses, or consequences arising from reliance on AI-generated outputs, to the maximum extent permitted by applicable law.
The limitations of liability, disclaimers, and indemnification provisions set out in our Terms of Service (Sections 16, 17, and 18) apply with full force to all data processing and AI-generated outputs described in this Privacy Policy.
Lexonica does not make automated decisions that produce legal or similarly significant effects solely through automated processing, within the meaning of applicable data protection laws. Risk scores and screening results are provided as informational tools to support human decision-making. No screening result generated by the Service should be treated as a final determination of risk or compliance status.
We use cookies and similar technologies for the following purposes:
The Service does not currently use analytics cookies, advertising cookies, or tracking pixels. If we introduce such technologies in the future, this Privacy Policy will be updated accordingly.
On your first visit, a cookie consent banner is displayed at the bottom of the page, allowing you to choose between:
Your preference is stored in a cookie (cookie_consent) for up to 12 months. You may reset your preference at any time by clearing your browser cookies, which will re-trigger the consent banner on your next visit.
Note: Google reCAPTCHA is used for security and abuse prevention. Even if you select "Necessary Only," reCAPTCHA may still be loaded on form submissions to protect the Service from automated abuse, as this falls under the legitimate interest and security exemption under applicable cookie regulations.
Some browsers transmit "Do Not Track" (DNT) signals. Because there is no universally accepted standard for how to respond to DNT signals, the Service does not currently alter its data collection or processing practices in response to DNT signals. If a uniform standard is adopted in the future, we will update this Privacy Policy accordingly.
You may also control cookies through your browser settings, including blocking or deleting cookies. However, disabling strictly necessary cookies may prevent you from using the Service. Third-party cookies set by Google reCAPTCHA can be controlled through your browser settings or Google's own privacy controls.
We may share personal information only in the following circumstances:
All service providers and sub-processors are contractually required to protect personal information, use it only for authorized purposes, and implement security measures consistent with this Privacy Policy. Lexonica does not sell, rent, or lease personal information to third parties.
While Lexonica requires its service providers and sub-processors to maintain appropriate data protection standards, Lexonica is not responsible for the independent actions, omissions, security practices, or data breaches of third-party service providers (including Stripe, Google, SendGrid, and third-party data sources) that act beyond the scope of Lexonica's instructions. Lexonica's liability for third-party processing is limited to the extent set out in our Terms of Service (Section 17) and Data Processing Agreement.
Personal information may be processed and stored in Canada, the United States, or other jurisdictions where our service providers operate. These jurisdictions may have data protection laws that differ from those in your country of residence.
When transferring personal information outside of your jurisdiction, Lexonica implements one or more of the following safeguards to ensure an adequate level of protection:
You may request a copy of the safeguards used for specific transfers by contacting us at tim@lexonica.com.
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected. The following retention guidelines apply:
Where personal information is retained to comply with legal obligations, resolve disputes, or enforce our agreements, it will be retained only for as long as required by the applicable obligation and then deleted.
You may delete your account at any time through your account settings. Account deletion removes your profile information and associated data from the primary database. You may also request deletion by contacting us at tim@lexonica.com. We will respond to deletion requests within 30 days, subject to legal retention requirements.
Lexonica implements reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, or disclosure. These measures include, but are not limited to:
No system is completely secure, and Lexonica cannot guarantee absolute security. Despite our commercially reasonable efforts, unauthorized access, data breaches, or security incidents may occur. Lexonica does not guarantee that the Service will be secure or free from unauthorized access, vulnerabilities, viruses, or other security threats. To the maximum extent permitted by applicable law, Lexonica shall not be liable for any unauthorized access to, or breach of, our security measures, except where such breach results directly from our gross negligence or willful misconduct. For the purposes of this Privacy Policy, "gross negligence" and "willful misconduct" shall be interpreted narrowly under the applicable governing law, consistent with the definitions in our Terms of Service (Section 17), and shall not include the inherent limitations of technology, third-party service failures, or security threats that could not reasonably have been prevented.
In the event of a data breach affecting your personal information, Lexonica will notify you and the relevant supervisory authorities without undue delay and in accordance with applicable breach notification laws, including PIPEDA, GDPR Article 33/34, and applicable state breach notification laws.
Depending on your jurisdiction, you may have the right to:
Authenticated users can exercise certain rights directly through their account settings:
For requests that cannot be fulfilled through self-service features, you may email tim@lexonica.com with the subject line "Data Subject Request." We may verify your identity before processing your request to prevent unauthorized access.
Lexonica will acknowledge receipt of your request within 5 business days and will respond substantively within 30 calendar days of receipt. If your request is complex or we receive a high volume of requests, we may extend the response period by an additional 60 days, in which case we will notify you of the extension and the reasons for it within the initial 30-day period, as permitted under GDPR Article 12(3).
There is no fee for exercising your data protection rights, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or decline the request, as permitted by applicable law.
This section applies to California residents and supplements the information in the rest of this Privacy Policy. Under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), California residents have the following rights:
In the preceding 12 months, Lexonica has collected the following categories of personal information as defined by the CCPA: identifiers (name, email, IP address), commercial information (subscription and billing records), internet or electronic network activity (usage logs, browser type), and professional or employment-related information (job title, company name). Lexonica has not collected biometric data, precise geolocation data, or financial account numbers directly.
California residents may submit requests by emailing tim@lexonica.com with the subject line "California Privacy Request," or by using the self-service data export and account deletion features in your account settings. We will verify your identity before processing your request. Authorized agents may submit requests on your behalf with verifiable written authorization.
The Service is not directed to children. We do not knowingly collect personal information from children under the age of 13 (as defined by the U.S. Children's Online Privacy Protection Act, "COPPA") or under the age of 16 (as defined by the GDPR).
During account registration, users are required to confirm via a mandatory checkbox that they are at least 16 years old. If you are under the age of 13, you may not use the Service under any circumstances. If you are between 13 and 16, you may only use the Service with verifiable parental or guardian consent, as required by applicable law.
If we become aware that we have collected personal information from a child without the required parental consent, we will take prompt steps to delete such information and terminate the associated account. If you believe that a child under 13 (or under 16 in the EEA/UK) has provided us with personal information, please contact us immediately at tim@lexonica.com.
This Privacy Policy describes Lexonica's data handling practices but does not create obligations, warranties, or guarantees beyond those required by applicable law. The limitations of liability, disclaimers, indemnification provisions, and dispute resolution mechanisms set out in our Terms of Service apply with full force to all matters arising under or in connection with this Privacy Policy.
To the maximum extent permitted by applicable law, you agree to indemnify and hold Lexonica harmless from any claims, damages, losses, liabilities, costs, and expenses (including reasonable legal fees) arising from:
This indemnification obligation is in addition to, and does not limit, the indemnification provisions in the Terms of Service (Section 18).
Lexonica may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. For material changes, Lexonica will provide notice by email to registered users or by prominently posting notice within the Service at least fifteen (15) days before the changes take effect, unless an earlier effective date is required by law or is necessary to address an immediate security or fraud concern.
Continued use of the Service after the effective date of any modification constitutes your acceptance of the updated Privacy Policy. If you do not agree with a material change, you must stop using the Service before the change takes effect and, if applicable, delete your account.
We encourage you to review this Privacy Policy periodically. The "Last Updated" date at the top of this page indicates when this Privacy Policy was last revised.
For questions about this Privacy Policy or to exercise your data protection rights, please contact us:
Lexonica Inc.
New Brunswick, Canada
Email: tim@lexonica.com
Website: ReputationCalc
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the appropriate supervisory authority:
We encourage you to contact us first so that we may attempt to resolve your concern directly.
To generate reputation reports on legal entities, the Service collects and processes information that is publicly available on the internet, including search engine results, review platforms, news articles, social media profiles, government registries, and corporate databases. This processing is conducted under the following legal bases:
The Service is designed exclusively for generating reports on legal entities (businesses, organizations, government bodies). However, reports about legal entities may incidentally reference natural persons in their professional capacity (e.g., directors, officers, spokespersons, or key personnel). Such incidental processing is based solely on publicly available information and occurs in the context of analyzing the legal entity, not the individual. Lexonica Inc. processes this data under the following basis:
Individuals referenced in entity reports who wish to exercise their rights under applicable data protection law (including the right to rectification, erasure, or objection) may contact us using the information in Section 18 above.
Under GDPR Article 14, data controllers must provide certain information to data subjects when personal data is not obtained directly from them. Where entity reports incidentally reference natural persons in their professional capacity, Lexonica relies on the exemption provided by Article 14(5)(b), which provides that the obligation does not apply where the provision of such information proves impossible or would involve a disproportionate effort. In the context of entity reputation reports:
Notwithstanding the above, individuals referenced in entity reports retain all rights under applicable data protection law, including the right to object under GDPR Article 21 and the right to erasure under GDPR Article 17, subject to applicable exceptions. Requests may be submitted using the contact information in Section 18.
Reports are generated using third-party artificial intelligence models that process and summarize publicly available data. These AI models may produce inaccurate, incomplete, or fabricated outputs ("hallucinations"). Lexonica Inc. does not manually review or verify AI-generated content and cannot guarantee the accuracy of any output. No automated decision-making with legal or similarly significant effects (as described in GDPR Article 22) is performed — reports are informational summaries only.
Lexonica Inc. does not control the accuracy, completeness, or legality of information published by third parties on the internet. To the maximum extent permitted by applicable law, Lexonica Inc. is not responsible for inaccurate, outdated, or defamatory content that originates from third-party sources and is reflected in reports generated by the Service.
By using ReputationCalc, you acknowledge that you have read and understood this Privacy Policy.
Our support team is here to assist you with any questions
Registered users can contact support directly through the messaging system.