Lenavix
Effective · July 29, 2026

Privacy Policy

This global business privacy policy explains how Lenavix handles personal information across its website, waitlist, accounts, and regulatory-intelligence platform.

1. Scope and our role

Lenavix Intelligence Inc. (“Lenavix,” “we,” or “us”) provides the Lenavix website, waitlist, and B2B regulatory-intelligence platform assisting legal and compliance professionals. This policy applies to website visitors, waitlist applicants, customer administrators, authorized users, business contacts, and people represented in Customer Data. “Customer Data” means the documents, prompts, messages, analyses, outputs, and other material submitted or generated through the platform.

Lenavix is the controller or business for personal information we process for our website, waitlist, accounts, security, commercial relationships, and direct contacts. Lenavix ordinarily acts as a processor or service provider for Customer Data that we process on a customer's instructions. Customers are responsible for providing required notices and for having the authority, lawful bases, and instructions needed for that processing. Signed customer agreements and Data Processing Agreements (“DPAs”) may add privacy or processing terms and control conflicts within their scope.

Customer owns Customer Data and Generated Work Product to the extent permitted by law. This policy does not apply to Lenavix employee or job-applicant data unless we state otherwise in a separate notice.

2. Public website and waitlist

This part applies when you visit https://lenavix.com, read its public pages, contact us, or join the waitlist. We may receive the information you submit, including your full name, company name, and work email, together with submission and delivery status. Firestore stores waitlist submissions.

The public website may use Firebase Analytics, subject to applicable settings and consent controls, to receive technical visit data such as browser or device information, page or referrer, approximate location, and event data. The public website does not receive the documents, prompts, messages, or analyses that authorized users submit through the Lenavix application merely because someone visits the public website.

3. Lenavix application

This part applies when an authorized user accesses the authenticated regulatory-intelligence platform at https://app.lenavix.com. The application processes account and authentication information, Customer Data, activity and security information, and support information to provide and protect the contracted service.

Optional first-party product analytics in the application are consent-based and use an anonymous ID stored in the browser, a per-tab session ID, templated route or feature events, and allowlisted properties. At the effective date, these authenticated-platform analytics are operated by Lenavix and are not Google Analytics or GA4. No optional product analytics events are sent before affirmative consent, and analytics route templates and allowlisted properties exclude query strings and unrestricted raw values.

4. Information we collect

  • Website and waitlist information — full name, company name, work email, and submission and delivery status. Firestore stores waitlist submissions.
  • account and authentication information — email, display name, Firebase ID, organization, workspace, role, and login metadata.
  • Customer Data — uploaded documents, metadata, extracted text and fields, prompts, chat messages, analyses, findings, evidence links, and generated outputs.
  • Activity and security information — audit events, deletion records, IP-derived security identifiers, timestamps, user-agent, browser or device information, and diagnostic events.
  • consent-based product analytics — anonymous ID, session ID, templated route or feature events, and allowlisted properties.
  • Communications and commercial information — support and business correspondence, and Order and billing data where applicable.
  • Information from customers and configured sources — information received from customer administrators, authorized users, identity providers, regulatory sources, and configured third-party services.

5. How we use information

  • To provide, administer, secure, diagnose, support, and maintain the website and platform.
  • To process documents and produce requested analysis.
  • To handle waitlist, sales, support, legal, and privacy inquiries.
  • To measure product performance only when analytics consent is provided.
  • To enforce agreements, comply with law, and protect rights.
  • To improve the service using feedback and aggregated or de-identified performance information, but not Customer Data for Lenavix general-purpose model training.

Where applicable, our legal bases include performance of a contract, legitimate interests, consent, legal obligation, and protection of rights.

6. AI processing

Qwen is the active primary AI model and operates on Lenavix-controlled Google Cloud infrastructure. Google Document AI processes documents for text and layout extraction. Google Gemini may be used for search grounding and exceptional startup fallback. Documents, prompts, and related context may be transmitted to this configured infrastructure to produce the outputs requested by the Customer.

Lenavix does not use Customer Data to train or fine-tune AI models. Our configured Google Cloud services process Customer Data to provide the requested services under Google Cloud's applicable enterprise data terms.

Lenavix does not use AI to make solely automated legal or similarly significant decisions about individuals; outputs require human professional review.

7. Service providers and disclosure

We use Google Cloud and Firebase for hosting, authentication, database, storage, document processing, search, and model infrastructure; Resend for waitlist and transactional email; and Cloudflare for network or delivery functions where active. We may also disclose information to professional advisers, competent authorities where required, and parties to a protected corporate transaction. Lenavix does not sell personal information or share it for cross-context behavioural advertising. We do not use third-party advertising cookies.

8. Analytics and storage

We use essential authentication, security, and session storage to operate the service. Within the authenticated platform, optional first-party product analytics are consent-based: no optional product analytics events are sent before affirmative consent. Analytics route templates and allowlisted properties exclude query strings and unrestricted raw values. The public website may use Firebase Analytics to receive technical visit data such as browser or device information, page or referrer, approximate location, and event data, subject to applicable settings and consent controls. You can withdraw analytics consent through the applicable consent controls; withdrawal does not affect processing that occurred before it.

9. International processing

Lenavix is Canadian and principally operates from Ontario. Information may be processed in Canada and other countries where authorized providers operate. We use safeguards and transfer measures where applicable. A VPN changes connectivity, not the origin or legal character of personal information.

10. Retention and deletion

We retain information only as long as reasonably necessary for the relevant purposes, commitments, and legal requirements. Retention covers website and waitlist information for application and communications administration; account and authentication information for access and account lifecycle; activity and security information for operations, security, auditing, and abuse prevention; consent-based analytics information for measurement and consent administration; communications and commercial information for relationship, support, billing, and recordkeeping; and Customer Data according to customer instructions, applicable agreements, and documented deletion procedures.

Following termination or a verified deletion request, Lenavix deletes or de-identifies Customer Data according to the applicable Order or Data Processing Agreement and its documented deletion procedures, subject to legal, security, fraud prevention, and dispute-preservation requirements. Residual copies may remain in versioned storage or protected backups after deletion from active systems. Those copies are isolated from ordinary use, are not used for product operations, and are handled through applicable technical, contractual, and legal retention processes.

Evidence-freshness dates and document-expiry dates are not automatic deletion dates. Lenavix may retain information as required for legal obligations, security, fraud prevention, and preservation of claims or disputes. Durable deletion and audit records may be retained to document and enforce deletion. Irreversibly de-identified information may be retained.

11. Security

We use reasonable administrative, organizational, and technical safeguards. These include, at a high level, tenant separation, access controls, authentication, audit logging, and protected cloud infrastructure. No system is completely secure.

12. Your rights

Where applicable, you may have rights to access, confirmation, correction, deletion, restriction, objection, portability, withdrawal of consent, opt-out, appeal, and complaint to a regulator. We may verify identity and authority before responding. For Customer Data, Lenavix may direct a request to the controlling Customer or assist that Customer in responding. These rights may arise in Canada, the United Kingdom, applicable US states, and other jurisdictions; those examples are non-exhaustive.

13. Changes

We may update this policy as our services or legal obligations change. Material changes will receive appropriate notice and a new effective date.

14. Contact

Questions and rights requests can be sent to michael@lenavix.com.