MARKETAAI
Legal

Privacy Notice

Last updated: June 10, 2026

1. Who we are

Lexi Core Systems LLC (“we”) operates Marketa AI. We act as the data controller for personal data we collect from you when you use the Service.

2. What we collect and why

We collect the following categories of personal data:

  • Account data — email address, password hash. Used to create and authenticate your account.
  • Brand profile — business name, industry, target audience, brand voice, value proposition, optional website. Used to generate on-brand AI outputs for you.
  • Generated content — your prompts and AI outputs, stored as your campaign history.
  • Usage and telemetry — IP address, device/browser identifiers, pages visited, generation requests. Used for security, fraud prevention, debugging, and product improvement.
  • Support messages — anything you send us via support channels. Used to respond to your inquiry.

Legal bases: contract performance (account & service delivery), legitimate interests (security, product improvement, fraud prevention), consent (marketing, where applicable), and legal obligation (tax, accounting, regulatory).

3. Who we share your data with

  • Service providers / subprocessors: hosting (Cloudflare, Supabase), AI inference (Anthropic), analytics, support tooling. They process data only on our instructions.
  • Merchant of Record (Paddle): for the sale of our products, subscription management, payments, tax compliance, and invoicing. Paddle's privacy notice is at paddle.com/legal/privacy.
  • Professional advisers: legal, accounting, when needed.
  • Authorities: where required by law (court order, valid subpoena, fraud investigation).

We do not sell your personal data. We do not use your prompts or generated content to train third-party AI models.

4. International transfers

Some of our service providers operate outside the UK/EEA. Where we transfer personal data across borders, we rely on adequacy decisions or Standard Contractual Clauses to ensure protections equivalent to those in your home jurisdiction.

5. Retention

We retain account and brand-profile data for as long as your account is active. Generated campaigns are retained until you delete them or close your account. Billing records are retained for the period required by tax law (typically 7 years). When data is no longer needed, we delete or anonymise it.

6. Your rights

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you
  • Have inaccurate data corrected
  • Request erasure (“right to be forgotten”)
  • Restrict or object to certain processing
  • Receive your data in a portable format
  • Withdraw consent at any time (where processing is based on consent)
  • Lodge a complaint with your local data protection authority

To exercise these rights, email privacy@marketaai.com. We'll respond within 30 days.

7. Security

We use industry-standard technical and organisational measures to protect your data: encryption in transit (TLS), encryption at rest, role-based access controls, and regular security reviews. No system is perfectly secure, so we ask you to use a strong unique password and enable any available account protections.

8. Cookies

We use essential cookies to keep you signed in and remember your preferences. We may use a small number of analytics cookies to understand how the Service is used. We do not use marketing or advertising cookies.

9. Children

The Service is not intended for users under 18. We do not knowingly collect data from children.

10. Changes

We may update this notice. Material changes will be announced via email or in-app notice.

11. Contact

Privacy questions: privacy@marketaai.com. Data controller: Lexi Core Systems LLC.