Privacy Policy

Version 1.0 · Effective 13 September 2026

In case of any conflict between the English and Arabic texts, the Arabic text prevails.

This Policy is a binding legal document issued by Genius Artificial Intelligence Solutions LLC (the "Company" or "Lerix"), registered in the Sultanate of Oman under commercial registration number 1674746, with its head office in Muscat, Sultanate of Oman. It explains how the Company collects, processes, retains, shares and protects personal data in operating the Lerix platform available at lerix.dev.

The Company holds itself to high standards of privacy protection and applies this Policy in line with the Personal Data Protection Law issued by Royal Decree 6/2022 (the "Data Protection Law" or the "Law") and its Executive Regulations issued by Ministerial Decision 34/2024 (the "Executive Regulations"). It also observes the corresponding requirements of the EU General Data Protection Regulation (GDPR) where these apply to dealings with clients in EU member states.

By using or subscribing to the Lerix platform, the Client confirms that it has read, understood and accepted this Policy. Where the Client is acting as agent or representative of a legal person, it confirms that it holds sufficient authority to accept this Policy on that entity's behalf.

1. Article One — Definitions

The following words and expressions carry the meanings set against each of them for the purposes of this Policy, unless the context requires otherwise:

a. Personal Data: any information relating to an identified or identifiable natural person, such as a name, email address, IP address, device identifiers and any other information allowing the person to be identified directly or indirectly.

b. Processing: any operation or set of operations performed on personal data, whether by automated means or otherwise, including collection, recording, organisation, storage, retrieval, use, disclosure, erasure and destruction.

c. Controller: the natural or legal person who determines the purposes and means of processing personal data. The Company acts in this capacity in respect of Client account data and operational data.

d. Processor: the natural or legal person who processes personal data on behalf of the Controller and on its instructions. The Company acts in this capacity in respect of the end user data of Client applications received through the SDK.

e. Data Subject: the natural person to whom the personal data relates.

f. Client: any natural or legal person who has entered into a subscription with the Company or who accesses the platform for commercial or professional purposes.

g. End User: any person who uses the Client's application or service and whose data is sent to the Lerix platform through the SDK.

h. Software Development Kit (SDK): the code, libraries and tools provided by the Company and integrated by the Client into its applications in order to send telemetry and record errors.

i. Telemetry and Error Data: the technical data sent from the Client's applications through the SDK to the platform, including error logs, performance data and session identifiers.

j. Aggregated Anonymous Data: data from which all personal identifiers have been irreversibly removed, so that it cannot be attributed to a particular person.

k. Sub-processor: any third party the Company engages to help deliver the services and to which it may disclose personal data.

l. Regulator: the government body competent for personal data protection in the Sultanate of Oman under the Data Protection Law.

m. Data Protection Officer (DPO): the person appointed by the Company to ensure compliance with the Data Protection Law and to oversee the application of this Policy.

n. Security Incident: any breach, unauthorised access, loss or accidental disclosure affecting personal data processed by the Company.

o. MCP Integration: integration with the Model Context Protocol, which allows AI agents to read and process platform data.

p. Cookies: small data files stored on a user's device for session, analytics and personalisation purposes.

2. Article Two — The Company's Dual Role in Processing

This Policy draws a careful and explicit distinction between the Company's two roles in processing personal data, since the Company acts in two separate capacities as follows:

2-1. The Company as Controller: The Company acts as controller in respect of the following categories of personal data:

a. Client account registration and profile data (name, email address, job title, organisation name).

b. Billing and payment data linked to the Client account.

c. Correspondence with the support and sales teams.

d. Operational usage data tied to the Client account itself (logins, account settings, preferences).

e. Cookie data relating to the lerix.dev website.

As controller, the Company bears full responsibility for determining the purposes and means of processing these categories, and is directly subject to the obligations of the Data Protection Law towards these data subjects.

2-2. The Company as Processor: The Company acts as processor on behalf of the Client, as controller, in respect of all personal data sent from the Client's applications through the SDK, including:

a. End user data of the Client's applications.

b. IP addresses of the users of the Client's applications.

c. Device identifiers of end users.

d. Telemetry and error data sent from the Client's applications.

e. Any other personal data the Client sends through the SDK or the APIs.

As processor, the Company processes this data only on the Client's documented instructions and for the limited purposes set out in the Data Processing Agreement (DPA). The Client, as controller, bears full responsibility for having a lawful basis for collecting its end users' data and sending it to the platform.

2-3. Why the distinction matters in practice: The Parties recognise that this distinction has substantive legal consequences. It means that the Company, in its role as processor, does not owe direct obligations to the end users of the Client's applications, and that those end users should direct requests concerning their data to the Client as controller, which in turn coordinates with the Company under the mechanisms of the Data Processing Agreement.

3. Article Three — What Data We Collect and How

The Company collects different types of data under the categories and methods set out below:

3-1. First: Client account, profile and billing data (as controller):

The Company collects the following data when an account is created or updated, or a subscription renewed:

a. Identity data: full name, email address, organisation name, job title.

b. Account data: username, security settings, notification preferences, subscription and renewal dates.

c. Billing data: payment information (processed through a licensed external payment provider; the Company does not store full card numbers), tax invoice data, billing address.

d. Correspondence data: email exchanges with the support team, records of technical assistance requests.

This data is collected directly from the Client at registration, on entry into the control panel, or during payment.

3-2. Second: usage data and technical server logs (as controller):

The Company automatically collects operational technical data when the Client or its team members access the platform, including:

a. Access logs: the IP address used to reach the control panel, browser and operating system details, login and logout times.

b. Operational usage data: pages and tools used inside the control panel, queries run, alert settings.

c. Technical performance data: page load times, technical errors occurring in the control panel interface itself.

This data is collected automatically through server logs and internal monitoring tools.

3-3. Third: data received through the SDK from the Client's applications (as processor):

Through the SDK, the platform receives the following data sent from the Client's applications:

a. IP addresses: the IP addresses of the users of the Client's applications, used for geographic diagnostics and for analysing end user activity.

b. Device identifiers: unique identifiers of the devices running the Client's application (such as Device ID and UDID), used for session tracking and for determining monthly active users (MAU).

c. Telemetry and performance logs: application response times, memory and processor consumption, operation execution times.

d. Error and exception data: error logs and stack traces, error messages, application state at the moment of the error.

e. Custom user identifiers: any identifiers the Client voluntarily adds to SDK calls in order to link telemetry to particular users.

f. Additional custom data: any further contextual data the Client chooses to send through the custom SDK interfaces.

Important notice: the Company does not dictate what data the Client sends through the SDK; the Client is the controller and decides what is sent. The Client bears full responsibility for ensuring that the data sent goes no further than is necessary for diagnostic and monitoring purposes, and that it has obtained the necessary consents from its end users in accordance with Article Twelve of this Policy.

3-4. Fourth: data the Company does not collect:

The Company does not knowingly collect or request the following categories of data:

a. Health or medical data of the users of the Client's applications.

b. National identity or passport numbers of end users.

c. Precise financial data such as bank account numbers or full card numbers of end users.

d. Biometric data.

If the Client sends data in these categories through the SDK, it alone bears full responsibility for legal compliance.

4. Article Four — Purposes of Processing and Legal Bases

The Company processes personal data for the following purposes and on the following legal bases, drawn from the Personal Data Protection Law issued by Royal Decree 6/2022 and, for clients to whom it applies, the EU General Data Protection Regulation (GDPR):

4-1. Performance of the contract and delivery of the service (legal basis: necessity for performance of the contract):

Data is processed on this basis for the purposes of:

a. Creating, administering and verifying the Client account.

b. Delivering the platform's functions: error tracking, performance monitoring, analytics and notifications.

c. Processing payments, issuing invoices and managing subscriptions.

d. Communicating with the Client about its account, service changes and material updates.

e. Enabling SDK functions and MCP integrations to serve the Client's applications.

4-2. The Company's legitimate interests (legal basis: legitimate interests):

Data is processed on this basis for the purposes of:

a. Platform security: detecting suspicious activity, preventing fraud and unauthorised access, protecting the infrastructure.

b. Service improvement: analysing aggregate usage patterns to develop new features and improve overall platform performance.

c. Client support: diagnosing and resolving technical issues reported by the Client.

d. Fraud and manipulation: detecting and limiting use that breaches the acceptable use policy.

In every case where the Company relies on legitimate interests, it balances its own interests against the interests and fundamental rights of data subjects, and stops the processing where the data subjects' interests are found to prevail.

4-3. Compliance with legal obligations (legal basis: legal obligation):

Data is processed on this basis to meet the requirements of:

a. Retaining tax and accounting records under Omani tax law.

b. Responding to orders of the judicial authorities and competent government bodies in the Sultanate of Oman.

c. Complying with security incident reporting requirements under the Data Protection Law.

d. Maintaining records of processing activities under Executive Regulations 34/2024.

4-4. Express consent (legal basis: consent):

Where processing does not fall under the bases above, such as sending marketing messages and newsletters, the Company asks for the Client's express consent. Consent is treated as separate and can be withdrawn at any time without affecting the lawfulness of processing carried out beforehand.

4-5. Alignment of purposes with GDPR:

For clients resident in EU member states or the European Economic Area, the legal bases set out above correspond respectively to those in Article 6 of the GDPR: performance of a contract (Article 6(1)(b)), legitimate interests (Article 6(1)(f)), legal obligation (Article 6(1)(c)) and consent (Article 6(1)(a)).

5. Article Five — Sharing and Disclosure of Data

The Company does not sell personal data to third parties and does not share it for marketing purposes. The Company shares data only in the cases set out below:

5-1. Infrastructure and hosting providers (sub-processors):

The Company relies on cloud and hosting providers to run the platform. Those providers process data on the Company's behalf under written contracts binding them to data protection standards equivalent to the Company's own. This category includes:

a. The primary cloud hosting provider: [hosting provider name, e.g. Amazon Web Services / Google Cloud / Microsoft Azure], hosting in [hosting country].

b. The database service provider (where separate).

c. The email service provider for operational notifications.

d. The licensed payment processing provider.

5-2. External AI service providers:

To enable AI token processing features and MCP integration, anonymised or pseudonymised telemetry and error data may be sent to external AI model providers. The Company applies safeguards to minimise data to what is strictly necessary before sending. The Client is responsible for reviewing the privacy policies of AI providers and confirming they align with its own obligations to its end users.

5-3. Compliance with legal and judicial requirements:

The Company may disclose data where

a. A court order or binding request is issued by a competent government body in the Sultanate of Oman.

b. A lawful enforcement request is made with clear legal authority.

c. Disclosure is strictly necessary to protect the Company's legal rights in the context of litigation.

The Company makes reasonable efforts to notify the Client before disclosure whenever the legal circumstances allow it.

5-4. Merger and acquisition:

If the Company takes part in a merger, acquisition or sale of assets, data may transfer to the successor entity, with prior notice to clients and assurance that equivalent data protection continues.

5-5. What the Company does not do:

The Company expressly undertakes that it:

a. Does not sell personal data to third parties for any consideration.

b. Does not share data for third party advertising or marketing purposes.

c. Does not share end user data of the Client's applications for purposes beyond delivering the agreed service.

6. Article Six — Cross-Border Data Transfers

6-1. Legal framework for cross-border transfers:

Transfers of personal data outside the Sultanate of Oman are governed by the Personal Data Protection Law issued by Royal Decree 6/2022 and its Executive Regulations 34/2024. Omani law requires the recipient of the data in the foreign country to provide an adequate level of protection equivalent to the level applied in the Sultanate of Oman.

6-2. Safeguards applied:

When transferring personal data outside the Sultanate of Oman, the Company relies on one or more of the following safeguards:

a. Contracting with external service providers through binding contractual clauses that secure an adequate level of protection.

b. Relying on Standard Contractual Clauses (SCCs) meeting the required level in respect of clients in EU member states, where needed.

c. Ensuring data is anonymised or pseudonymised before transfer wherever possible.

6-3. Sensitive data:

Where transferred data contains sensitive personal data as defined in the Data Protection Law, the Company undertakes to obtain the approval of the competent Regulator [the Cyber Defence Centre or the competent regulator — please verify with a licensed Omani lawyer] before completing the transfer.

6-4. In-country hosting option:

The Company offers enterprise plan clients the option of hosting their data inside the Sultanate of Oman, under a dedicated service level agreement whose terms are set out in the contract concluded with the enterprise client. Where the client takes up this option, its data is not transferred outside Omani territory except with its express written consent.

6-5. GDPR alignment for European clients:

For clients resident in EU member states or the European Economic Area, the transfer mechanisms set out in Article 46 of the GDPR apply (Standard Contractual Clauses or other approved mechanisms), complementing and aligning with the requirements of Omani data protection law. European clients may ask to see the transfer mechanism applied and its safeguards.

7. Article Seven — Data Retention and Deletion

The Company retains personal data only for as long as is necessary to achieve the purposes for which it was collected, or for the period required by law, on the following schedule:

7-1. Active client account data:

Account data is retained throughout the active subscription, including the profile, team data and account settings. This data is updated continuously as the Client enters it.

7-2. Billing data and tax records:

Billing and payment records are retained for [10] years from the invoice date, in compliance with Omani tax and accounting requirements. [Note: please verify the period stated in Omani income tax and accounting law with a licensed lawyer.]

7-3. Telemetry and error data received through the SDK:

Detailed error and telemetry data for individual sessions is retained for [90] days from receipt, then automatically deleted or aggregated and anonymised. Aggregated anonymous data may be retained for longer for service improvement purposes.

7-4. Technical access logs:

Detailed server access logs are retained for [30] days for security and diagnostic purposes, then deleted or anonymously aggregated.

7-5. Technical support records:

Support correspondence and service tickets are retained for [2] years from the date the ticket is closed, for quality and verification purposes.

7-6. Deletion on account termination:

On termination of a subscription for any reason:

a. The Client has a grace period of [90] days from termination to retrieve and export its data through the export tools available in the control panel.

b. After the grace period expires, Client data and the end user data of its applications are permanently and securely deleted from the Company's systems under approved secure deletion standards.

c. Full deletion across all servers and backup systems may take a further period not exceeding [30] days from the date of the request.

d. Data the law requires to be retained, such as tax and financial records, is excluded from deletion and is kept separate from the rest of the data.

7-7. Notice to the Client:

The Company sends the Client a reminder [15] days before the deletion grace period ends, so that it can retrieve its data in good time.

8. Article Eight — Data Subject Rights

The Personal Data Protection Law issued by Royal Decree 6/2022 and the GDPR grant data subjects specific rights. The Company honours these rights in respect of the data it processes as controller (data of the Client and its team members).

8-1. Right of access:

A data subject may make a written request for a copy of the personal data the Company processes, together with information on the purposes of processing, its duration and the recipients of the data. The Company responds within a period not exceeding [30] days from receipt.

8-2. Right to rectification and updating:

A data subject may request correction of any personal data that is inaccurate, incomplete or out of date. Rectification requests are handled within [14] working days of receipt.

8-3. Right to erasure (right to be forgotten):

A data subject may request erasure of their personal data in the following cases:

a. The data is no longer needed for the purposes for which it was collected.

b. Consent on which the processing was based has been withdrawn and there is no other legal basis.

c. A successful objection to processing under clause 8-4.

This right does not apply to data the law requires to be retained, such as tax and financial records.

8-4. Right to object to processing:

A data subject may object to the processing of their data where the Company relies on legitimate interests as its legal basis. The Company stops the processing unless it establishes compelling legitimate grounds that override the data subject's interests.

8-5. Right to data portability:

A data subject may request the personal data they have provided to the Company in a structured, commonly used, machine-readable format, and transmit it to another controller, where the processing is based on consent or performance of the contract.

8-6. Right to withdraw consent:

Where processing is based on the data subject's consent, they may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before the date of withdrawal.

8-7. Right to restriction of processing:

A data subject may request restriction of processing in specific cases, such as while the accuracy of the data is being verified or an objection to processing is being considered.

8-8. How to exercise these rights:

To exercise any of these rights, the data subject sends a written request to:

• Email: [privacy@lerix.dev]

• Or through the request form available in the control panel.

The request must include: full name, the registered email address, and a description of the right being exercised. The Company may verify the identity of the person making the request before responding. The Company refuses abusive or unreasonably repetitive requests, and tells the data subject why.

8-9. Right to complain to the Regulator:

Without prejudice to the right to litigate, a data subject may lodge a complaint with the competent Regulator in the Sultanate of Oman if they consider that the processing of their data breaches the Data Protection Law.

8-10. Note on data processed in the capacity of processor:

In respect of data the Company processes as processor on behalf of the Client (end user data received through the SDK), end users must direct requests to exercise their rights to the Client directly, as controller. The Company supports the Client in responding to such requests under the mechanisms of the Data Processing Agreement (DPA).

9. Article Nine — Cookies and Tracking Technologies

9-1. What cookies are:

Cookies are small text files placed on a user's device when they visit lerix.dev or use the control panel. The Company uses these files and similar tracking technologies for the purposes set out below.

9-2. Types of cookies used:

a. Strictly necessary cookies (no consent required): needed for the website and control panel to work properly, including session, authentication and basic security preference files. These cannot be disabled without affecting core functions.

b. Functional cookies (consent required): improve the user experience by saving the Client's preferences (language, interface appearance, a