CLOCOT PRIVACY POLICY
Effective Date: October 2, 2026 Last Updated: October 2, 2026
This Privacy Policy explains how LexLupi LLC, a Delaware limited liability company operating the Clocot platform (“LexLupi,” “Clocot,” “we,” “us,” or “our”), collects, uses, stores, discloses, transfers, and otherwise processes personal information in connection with Clocot.
Clocot is an AI-powered software platform that may provide websites, applications, workspaces, Offices, Directors, Agents, automation tools, AI model access, integrations, APIs, CRM functionality, communications tools, file processing, memory features, analytics, developer tools, presale and beta programs, and related services (collectively, the “Services”).
This Policy is intended to explain our privacy practices in a clear and comprehensive way. It applies to personal information processed through our public websites, account registration, paid and unpaid Services, Clocot Lab, beta programs, support channels, integrations, APIs, business operations, and related interactions, unless a more specific privacy notice applies.
If you use Clocot on behalf of an organization, that organization may also control personal information processed through its workspace. In those situations, this Policy should be read together with the organization’s privacy notices and any applicable Data Processing Addendum.
Nothing in this Policy limits privacy rights that cannot lawfully be waived under applicable law.
1. WHO WE ARE
The Services are operated by:
LexLupi LLC Delaware, United States Operator of Clocot
Privacy and Legal Contact: Tatjana Sindjelic Email: office@clocot.com U.S. registered office: 131 Continental Dr, Suite 305, Newark, DE 19713, United States Serbian principal business address: Save Kovacevic 29/4, 34000 Kragujevac, Serbia
For privacy questions, requests, complaints, or data-subject rights, contact us at office@clocot.com.
2. SCOPE OF THIS POLICY
This Policy applies when we process personal information in connection with:
- clocot.com and related Clocot websites;
- account creation and authentication;
- Clocot workspaces and Organizations;
- Offices, Directors, Agents, and workflows;
- Office Brain, memory, context, and knowledge features;
- AI prompts, conversations, instructions, and Generated Output;
- uploaded files and connected data sources;
- CRM records, contacts, leads, and customer records;
- integrations and connected third-party accounts;
- OAuth connections and tokens;
- user-supplied API keys and credentials;
- payment, subscription, presale, and billing activities;
- Clocot Credits and usage records;
- customer support and communications;
- product analytics, security, fraud prevention, and service administration;
- email, messaging, social, voice, and other automation features;
- APIs, webhooks, SDKs, extensions, and developer tools;
- beta, preview, Lab, and experimental features;
- marketing, events, surveys, and business communications; and
- other activities that link to or expressly reference this Policy.
This Policy does not govern third-party websites, products, or services that operate under their own privacy policies.
3. OUR PRIVACY ROLES
Clocot can process personal information in different legal roles depending on the context.
3.1 When LexLupi Acts as a Controller or Business
LexLupi generally acts as a data controller, business, or equivalent responsible entity when we determine why and how personal information is processed, including for:
- account registration;
- authentication and account security;
- subscription and billing administration;
- payment status and transaction records;
- fraud prevention and abuse detection;
- product administration;
- service analytics;
- website analytics;
- communications about the Services;
- support operations;
- legal compliance;
- enforcement of our agreements;
- security monitoring;
- service improvement based on operational data;
- presale and Lab administration; and
- our own business records.
3.2 When LexLupi Acts as a Processor or Service Provider
When a business customer, Organization, agency, developer, or other customer submits personal information to Clocot for processing on its behalf, LexLupi generally acts as a processor, service provider, contractor, or equivalent role.
Examples include:
- customer CRM contacts;
- leads and prospect records;
- uploaded customer databases;
- end-user records;
- employee or contractor records;
- data in an Organization’s Office Brain;
- data processed through customer automations;
- communications sent on customer instructions;
- customer-configured workflows;
- data obtained from customer-controlled integrations; and
- other Customer Content processed according to customer instructions.
In these situations, the customer is generally responsible for providing required notices, identifying a lawful basis, responding to data-subject requests, obtaining necessary consent, and ensuring that its use of Clocot complies with applicable law.
3.3 Mixed Roles
Some processing can involve both roles. For example, we may process customer-provided data as a processor to perform a workflow while separately processing security logs associated with that workflow as a controller for fraud prevention and system security.
Where required, our Data Processing Addendum further describes processor obligations.
4. DEFINITIONS
For this Policy:
“Personal Information” or “Personal Data” means information relating to an identified or identifiable individual, or information otherwise protected as personal information under applicable law.
“Customer Content” means prompts, files, records, text, images, audio, video, code, databases, contact data, business data, instructions, and other content submitted to or made available through Clocot by or for a customer.
“Office” means a configurable Clocot operational workspace for a business function or goal.
“Director” means an AI-enabled or software-enabled orchestration component coordinating Agents, memory, tools, permissions, and workflows.
“Agent” means an AI-enabled or software-enabled component configured to perform tasks, analyses, communications, or actions.
“Office Brain” means Clocot functionality designed to maintain workspace context, knowledge, preferences, files, memory, or learned operational patterns.
“AI Provider” means a third-party provider of AI, machine learning, text, coding, search, image, video, voice, speech, data, or related model services.
“Integration” means a connection between Clocot and a third-party account, platform, software service, API, model, database, communications channel, or other system.
“Organization” means a company, agency, team, institution, or other entity using Clocot through one or more accounts.
5. PERSONAL INFORMATION WE COLLECT
The information we collect depends on how you use Clocot, which features you enable, your Organization’s configuration, your plan, your location, and the third-party services you connect.
5.1 Account and Profile Information
We may collect:
- name;
- email address;
- username or account identifier;
- password-related authentication records;
- organization name;
- job title or role;
- profile preferences;
- locale and language;
- account status;
- account creation date;
- account verification information; and
- other profile information you choose to provide.
We do not store plaintext account passwords where authentication systems are designed to store cryptographic password representations instead.
5.2 Organization and Workspace Information
We may process:
- Organization name;
- business contact details;
- workspace identifiers;
- team membership;
- user roles;
- administrator permissions;
- Office configuration;
- Agent configuration;
- approval rules;
- workflows;
- operational preferences;
- workspace settings;
- connected services;
- internal labels and metadata; and
- Organization-owned Customer Content.
5.3 Billing, Subscription, Presale, and Transaction Information
We may process:
- billing name;
- billing address;
- country or region;
- tax-related information;
- plan or package;
- subscription status;
- invoice records;
- transaction identifiers;
- amount paid;
- currency;
- refund and dispute information;
- payment status;
- presale package;
- Lab participation;
- purchase date;
- renewal information;
- Clocot Credit balances and usage records; and
- limited payment-method metadata provided by a payment processor, such as card brand or last four digits, where available.
Payment card details may be collected directly by our payment processor rather than by LexLupi. We generally do not need to receive a complete payment-card number to operate standard hosted or embedded payment processing.
5.4 Device, Network, and Technical Information
We may automatically collect:
- IP address;
- browser type and version;
- device type;
- operating system;
- language;
- time zone;
- approximate location derived from IP address;
- device or session identifiers;
- referring page;
- visited pages;
- application version;
- request metadata;
- API request metadata;
- network information;
- crash information;
- diagnostic records; and
- similar technical information.
We do not intentionally collect precise geolocation unless a feature requires it and the user, device, or connected service supplies it.
5.5 Log, Security, and Audit Information
We may collect records about:
- sign-ins;
- failed authentication;
- session creation and termination;
- permission changes;
- workspace administration;
- API calls;
- integration activity;
- automation events;
- configuration changes;
- approval actions;
- account recovery;
- security alerts;
- suspicious activity;
- rate-limit events;
- policy enforcement;
- administrative actions; and
- other audit events.
5.6 Usage and Product Analytics
We may collect information about how the Services are used, including:
- pages and features used;
- frequency and duration of use;
- Office and Agent activity;
- workflow execution counts;
- feature adoption;
- buttons or interface elements used;
- errors and latency;
- token, model, or resource usage;
- storage usage;
- usage-based billing events;
- completion or failure of tasks;
- product performance; and
- aggregated usage patterns.
5.7 Cookies and Similar Technologies
Our websites and applications may use cookies, local storage, pixels, SDKs, tags, or similar technologies for:
- authentication;
- security;
- session continuity;
- preferences;
- analytics;
- performance;
- fraud prevention;
- consent management; and
- marketing where enabled and legally permitted.
Non-essential cookies or similar technologies are subject to consent or opt-out requirements where applicable.
5.8 Prompts, Instructions, and AI Conversations
When you interact with AI functionality, we may process:
- prompts;
- system or user instructions;
- conversational messages;
- model parameters;
- Agent instructions;
- tool calls;
- task descriptions;
- structured inputs;
- generated responses;
- corrections;
- feedback; and
- contextual information required to perform the task.
5.9 Uploaded Files and Documents
We may process files you upload or make available through integrations, including:
- documents;
- spreadsheets;
- images;
- audio;
- video;
- code;
- archives;
- presentations;
- PDFs;
- databases;
- exported CRM data;
- research materials; and
- other digital content.
The files may contain personal information about you or other individuals.
5.10 Office Brain, Memory, and Context Data
Where memory or persistent-context features are enabled, Clocot may retain or derive information such as:
- business facts;
- preferences;
- style preferences;
- process rules;
- brand information;
- customer instructions;
- recurring goals;
- historical workflow context;
- project context;
- organizational knowledge;
- audience information;
- content patterns;
- learned operational preferences; and
- references to stored assets or records.
Memory may be created from data you submit, data from connected services, or information generated through your use of Clocot.
5.11 Automation and Action Records
Clocot may process records of:
- triggers;
- schedules;
- instructions;
- approvals;
- automated actions;
- failed actions;
- recipient information;
- delivery status;
- tool execution;
- workflow state;
- human intervention;
- escalation;
- action history; and
- results returned by connected services.
5.12 Connected Accounts and OAuth Information
If you connect a third-party account, we may receive or process:
- account identifier;
- account name;
- profile information;
- authorization scope;
- OAuth tokens;
- refresh tokens;
- connection status;
- permissions;
- workspace or page identifiers;
- channel information; and
- data made available through the authorization you grant.
We request access only to scopes that are relevant to the connected functionality, although the third-party provider determines the technical permissions available.
5.13 API Keys and Credentials
If you choose to connect your own AI provider, service provider, or API account, Clocot may process credentials such as:
- API keys;
- access tokens;
- secret tokens;
- webhook secrets;
- connection strings;
- service-account credentials; and
- related configuration.
These credentials are treated as sensitive security information and are used to establish or operate the requested connection.
5.14 CRM, Contact, Lead, and Prospect Data
Customers may upload, create, import, synchronize, or process:
- names;
- email addresses;
- phone numbers;
- company names;
- roles;
- mailing addresses;
- notes;
- relationship history;
- lead status;
- sales activity;
- communication history;
- campaign membership;
- source information;
- preferences;
- consent or opt-out status; and
- other CRM fields.
When this data concerns another person, the customer is generally responsible for having a lawful basis to process it.
5.15 Communications Data
If Clocot sends, receives, drafts, analyzes, or coordinates communications, we may process:
- sender and recipient details;
- message content;
- subject lines;
- timestamps;
- delivery records;
- call or voice metadata;
- recordings where enabled and lawful;
- transcripts;
- attachments;
- messaging identifiers;
- opt-out requests;
- suppression records; and
- engagement information.
5.16 Support and Service Communications
When you contact us, we may process:
- your contact details;
- support tickets;
- chat messages;
- emails;
- attachments;
- screenshots;
- troubleshooting information;
- call notes;
- feedback;
- complaint information; and
- information needed to resolve your request.
5.17 Marketing, Survey, and Event Information
Where applicable, we may process:
- marketing preferences;
- campaign engagement;
- event registration;
- survey responses;
- referral source;
- business interests;
- newsletter status;
- communication preferences; and
- records of consent or opt-out.
5.18 Publicly Available and Third-Party Information
We may receive information from:
- publicly available websites;
- business directories;
- public professional profiles;
- authorized data providers;
- connected platforms;
- integration partners;
- customers;
- affiliates;
- fraud-prevention providers; and
- other lawful sources.
Where we obtain personal information indirectly, we process it subject to applicable notice obligations, exceptions, customer instructions, and legal restrictions.
5.19 Derived and Inferred Information
Clocot may derive information from other data, such as:
- likely language;
- engagement patterns;
- workflow preferences;
- risk signals;
- account-security indicators;
- product recommendations;
- audience groupings;
- operational patterns; and
- contextual classifications.
We do not intend these inferences to determine sensitive characteristics unless a feature expressly requires such processing and applicable legal requirements are satisfied.
5.20 Sensitive Personal Information
Depending on how customers use Clocot, Customer Content may include information considered sensitive under applicable law, such as:
- authentication credentials;
- financial information;
- health-related information;
- government identifiers;
- precise location;
- racial or ethnic origin;
- religious beliefs;
- political opinions;
- trade-union membership;
- genetic or biometric data;
- sexual orientation or sex-life information;
- criminal-history information; or
- other specially protected data.
Clocot does not require most categories of sensitive information for ordinary use. Customers should submit sensitive information only where they have a lawful basis, the use is appropriate for the relevant feature, and required safeguards are in place.
Voice, audio, image, or video data is not automatically treated by us as biometric identification data. If a feature is specifically designed to identify a person using biometric characteristics, we will provide additional notice and obtain legally required authorization.
6. SOURCES OF PERSONAL INFORMATION
We may obtain personal information:
- directly from you;
- from your Organization;
- from Organization administrators;
- from other users who collaborate with you;
- from customers who upload or synchronize records;
- from connected third-party services;
- from OAuth providers;
- from AI Providers;
- from payment processors;
- from analytics and security providers;
- from public sources;
- from authorized data providers;
- from APIs and webhooks;
- from devices and browsers;
- from our own logs and systems; and
- by deriving information from your use of the Services.
7. WHY WE USE PERSONAL INFORMATION
We may process personal information to:
- provide and operate the Services;
- create and administer accounts;
- authenticate users;
- establish Organizations and workspaces;
- run Offices, Directors, Agents, and workflows;
- maintain Office Brain and contextual memory;
- process prompts and generate output;
- execute authorized automations;
- connect integrations;
- communicate with third-party services;
- provide APIs and developer functionality;
- process subscriptions, presales, payments, and Credits;
- provide customer support;
- maintain service reliability;
- diagnose errors;
- measure product usage;
- improve user experience;
- personalize features;
- maintain security;
- detect fraud, abuse, and unauthorized access;
- enforce terms and policies;
- comply with law;
- respond to lawful requests;
- protect users, LexLupi, and third parties;
- maintain records;
- send service communications;
- send marketing where permitted;
- manage opt-outs and preferences;
- conduct research and analytics;
- develop new features;
- perform corporate administration; and
- establish, exercise, or defend legal claims.
We do not use personal information for materially different purposes without providing additional notice or obtaining consent where required.
8. LEGAL BASES FOR PROCESSING IN THE EEA, UK, SWITZERLAND, AND SIMILAR JURISDICTIONS
Where the GDPR, UK GDPR, Swiss law, Serbian law, or another law requires a lawful basis, we rely on one or more of the following.
8.1 Performance of a Contract
We may process personal data where necessary to:
- create and operate your account;
- provide purchased or requested Services;
- execute workflows you initiate;
- provide support;
- administer subscriptions;
- process service entitlements;
- provide integrations;
- maintain requested memory features; and
- otherwise perform our agreement with you.
8.2 Legitimate Interests
We may process personal data where necessary for legitimate interests such as:
- securing the Services;
- detecting fraud and abuse;
- preventing unauthorized access;
- maintaining service reliability;
- understanding product usage;
- improving the Services;
- supporting customers;
- maintaining business records;
- protecting legal rights;
- operating a B2B software platform; and
- communicating with customers about relevant product matters.
We balance these interests against the rights and interests of affected individuals.
8.3 Consent
We may rely on consent for:
- non-essential cookies where required;
- certain marketing;
- optional integrations;
- certain location or device permissions;
- certain sensitive-data processing;
- certain call or recording features;
- certain AI or personalization features; and
- other processing where law requires consent.
You may withdraw consent at any time, subject to the limitations described in applicable law. Withdrawal does not affect processing that was lawful before withdrawal.
8.4 Legal Obligation
We may process information to comply with:
- tax laws;
- accounting obligations;
- sanctions requirements;
- lawful government requests;
- consumer protection obligations;
- privacy law;
- court orders;
- regulatory requirements; and
- other legal duties.
8.5 Vital Interests and Public Interest
In rare circumstances, we may process information to protect a person’s vital interests or for another basis recognized by applicable law.
8.6 Special Categories of Personal Data
Where we act as controller and intentionally process special-category data, we rely on an additional legal condition where required. When we act as a processor, the customer is responsible for identifying the applicable legal basis unless our agreement states otherwise.
9. CUSTOMER DATA AND BUSINESS-CUSTOMER RESPONSIBILITIES
Business customers often control the personal information they submit to Clocot.
If you are an Organization using Clocot to process data about employees, customers, prospects, users, suppliers, or other individuals, you are responsible for:
- determining whether you are permitted to collect and use that data;
- providing legally required privacy notices;
- obtaining legally required consent;
- honoring opt-outs;
- complying with marketing and communications rules;
- responding to data-subject requests;
- defining appropriate retention periods;
- ensuring instructions given to Clocot are lawful;
- configuring appropriate permissions; and
- using appropriate security controls.
Where we act as processor, we process personal data according to the customer’s documented instructions, our agreement, and applicable law.
10. AI PROCESSING
Clocot uses AI functionality to provide many Services.
AI processing may involve:
- sending prompts or context to a model;
- analyzing documents;
- summarizing information;
- generating text;
- generating or analyzing images;
- generating or analyzing audio or video;
- generating code;
- classifying records;
- extracting structured information;
- routing tasks between models;
- retrieving context;
- coordinating Agents;
- selecting tools;
- creating recommendations;
- generating drafts; and
- performing other AI-assisted functions.
The information sent to an AI Provider depends on the task, configuration, provider, model, and tools used.
We seek to send only information reasonably necessary for the requested function, but users control much of the content submitted to AI features.
11. THIRD-PARTY AI PROVIDERS
Clocot may integrate with multiple AI Providers.
Depending on the feature, data may be processed through:
- a provider selected by Clocot;
- a provider selected by the user;
- a provider selected automatically based on task or availability;
- a model hosted by an infrastructure provider; or
- the customer’s own provider account using customer-supplied credentials.
Different providers may have different:
- retention periods;
- logging practices;
- locations;
- security controls;
- model-improvement practices;
- contract terms; and
- privacy policies.
When Clocot provides managed access to an AI Provider, we seek to use provider terms and settings appropriate for business use where commercially and technically available.
When you connect your own provider account or API key, the provider may process information under your direct agreement with that provider. In that case, you are responsible for reviewing the provider’s privacy and data-use terms.
12. MODEL TRAINING, PRODUCT IMPROVEMENT, AND CUSTOMER CONTENT
LexLupi does not treat Customer Content as unrestricted data that may be used for any purpose.
Customer Content is primarily processed to provide, secure, support, and administer the Services you request.
We may use operational, statistical, aggregated, or de-identified information to:
- understand reliability;
- measure performance;
- improve routing;
- reduce errors;
- improve user experience;
- develop product functionality;
- detect abuse; and
- plan capacity.
We do not use Customer Content to train a general-purpose foundation model by default unless that use is separately disclosed and legally permitted.
Limited Customer Content may be accessed where reasonably necessary for support, security, abuse investigation, debugging, legal compliance, or when the customer requests assistance.
Third-party AI Providers may have their own model-improvement or retention rules. Where a customer uses its own provider account or API key, that provider’s terms govern the provider’s use of the data. Where Clocot manages the provider relationship, applicable contract settings and provider terms may restrict or permit particular uses.
If we materially change how LexLupi uses Customer Content for generalized AI training, we will update this Policy and provide any legally required notice, choice, or consent before the new use applies.
13. OFFICE BRAIN, MEMORY, AND PERSONALIZATION
Office Brain and related memory features may store or derive persistent context so Clocot can operate more consistently over time.
Memory may include:
- preferences;
- business facts;
- brand rules;
- style patterns;
- workflow conventions;
- frequently used instructions;
- approved processes;
- recurring objectives;
- references to historical work; and
- context derived from past interactions.
Memory is designed to support the customer’s workspace and is not a public profile.
Customers may be able to modify, replace, disable, or delete memory depending on the feature and plan.
Deletion of source data may not instantly remove every derived or cached representation if technical systems require a reasonable period to synchronize deletion across active systems and backups.
14. AUTOMATED DECISION-MAKING AND PROFILING
Clocot may use automated processing for:
- fraud detection;
- abuse prevention;
- security alerts;
- rate limiting;
- task routing;
- recommendations;
- prioritization;
- classification;
- workflow decisions;
- content analysis; and
- other software-enabled decisions.
Clocot is not intended to make final, solely automated decisions that produce legal or similarly significant effects on individuals in regulated areas such as employment, credit, insurance, healthcare, housing, or access to essential services unless the use is lawful, specifically supported, and appropriate safeguards are implemented.
Customers using Clocot in high-impact contexts are responsible for required human review, notices, lawful bases, impact assessments, and appeal or contest mechanisms.
Where applicable law grants a right concerning automated decision-making or profiling, you may contact us or the relevant customer controlling the decision.
15. INTEGRATIONS AND CONNECTED SERVICES
If you connect a third-party service, you direct Clocot to exchange information with that service.
This may include:
- importing records;
- exporting records;
- reading messages;
- sending messages;
- accessing files;
- synchronizing contacts;
- publishing content;
- accessing analytics;
- creating records;
- updating CRM data;
- performing actions; and
- receiving webhook events.
The third-party service independently controls its own systems and privacy practices.
You can generally stop future data exchange by disconnecting the integration, revoking authorization, removing the relevant credential, or changing permissions. Disconnecting may not delete information already imported into Clocot or already transmitted to the third party.
16. COMMUNICATIONS, EMAIL, MESSAGING, AND VOICE FEATURES
Clocot may support communications through email, messaging platforms, social platforms, SMS, WhatsApp, voice, or other channels.
When customers use these features, Clocot may process:
- contact details;
- communication content;
- delivery status;
- engagement data;
- opt-out status;
- call metadata;
- audio or transcripts where enabled;
- campaign information; and
- suppression records.
Customers are responsible for having a lawful basis to contact recipients and for complying with applicable anti-spam, telemarketing, privacy, ePrivacy, consent, recording, and do-not-call requirements.
We may maintain suppression information to prevent communications to individuals who have opted out where necessary to honor the opt-out.
17. COOKIES AND SIMILAR TECHNOLOGIES
We use or may use cookies and similar technologies for:
- essential site operation;
- authentication;
- fraud prevention;
- security;
- session continuity;
- preferences;
- analytics;
- performance measurement; and
- marketing where enabled.
Strictly necessary technologies may be used without consent where permitted by law because they are required to provide requested functionality.
Where consent is required for analytics or marketing technologies, we provide an appropriate choice mechanism.
Additional details may be provided in a separate Cookie Policy or cookie settings interface.
18. ANALYTICS
We may use analytics services to understand:
- website traffic;
- acquisition sources;
- product usage;
- feature adoption;
- page performance;
- errors;
- conversion events;
- geographic region at an approximate level; and
- aggregate engagement.
Analytics providers may receive device, browser, IP, cookie, and usage information.
Where required, analytics technologies are subject to consent or opt-out choices.
19. MARKETING
We may send product news, launch information, offers, event information, surveys, or other marketing where legally permitted.
You may opt out of marketing emails by using the unsubscribe method in the message or contacting us.
Opting out of marketing does not prevent transactional or service messages such as:
- security alerts;
- billing notices;
- password or authentication messages;
- legal notices;
- purchase confirmations;
- operational notices; and
- important product-account communications.
20. PAYMENTS AND PAYMENT PROCESSORS
Payments may be processed by third-party payment providers.
Those providers may independently collect payment information needed to authorize a transaction.
We may receive:
- payment status;
- transaction identifier;
- amount;
- currency;
- billing information;
- payment-method metadata;
- dispute status;
- refund status; and
- other transaction information needed to administer the purchase.
Payment processors process information under their own legal obligations and contractual terms.
21. HOW WE DISCLOSE PERSONAL INFORMATION
We may disclose personal information to the following categories of recipients when necessary for the purposes described in this Policy.
21.1 Infrastructure and Hosting Providers
Providers supporting:
- application hosting;
- databases;
- storage;
- compute;
- backups;
- networking;
- content delivery;
- monitoring; and
- security.
21.2 AI Providers
Providers supporting:
- text;
- code;
- search;
- embeddings;
- image;
- audio;
- speech;
- video;
- model inference; and
- other AI functions.
21.3 Integration Providers
Third-party services you connect to Clocot or that Clocot uses to perform a requested workflow.
21.4 Payment and Billing Providers
Providers that process:
- payments;
- invoices;
- refunds;
- tax calculations;
- fraud checks; or
- subscription billing.
21.5 Communications Providers
Providers supporting:
- transactional email;
- marketing email;
- SMS;
- voice;
- messaging;
- notifications; and
- delivery infrastructure.
21.6 Analytics and Performance Providers
Providers that help us measure performance, reliability, traffic, or product usage.
21.7 Security and Fraud Providers
Providers that help detect:
- abuse;
- fraud;
- credential compromise;
- malicious traffic;
- security incidents; and
- policy violations.
21.8 Professional Advisers
We may disclose information to:
- lawyers;
- accountants;
- auditors;
- insurers;
- consultants; and
- other professional advisers where reasonably necessary.
21.9 Affiliates and Corporate Transactions
Information may be disclosed in connection with:
- financing;
- due diligence;
- merger;
- acquisition;
- reorganization;
- sale of assets;
- corporate restructuring; or
- transfer of the Clocot business.
Any recipient remains subject to applicable privacy and confidentiality obligations.
21.10 Legal and Safety Disclosures
We may disclose information where we reasonably believe disclosure is necessary to:
- comply with law;
- respond to valid legal process;
- protect rights or safety;
- investigate fraud;
- enforce agreements;
- protect the Services;
- respond to regulators; or
- establish, exercise, or defend legal claims.
22. SUBPROCESSORS AND SERVICE PROVIDERS
We use service providers and subprocessors to operate Clocot.
The provider list may change as we add, remove, or replace infrastructure, AI, communications, payment, analytics, security, and other vendors.
Where required by contract or law, we provide information about relevant subprocessors and may offer notice of material changes.
A current subprocessor list may be published in the Clocot Legal Center or made available to eligible business customers.
23. SALE OR SHARING OF PERSONAL INFORMATION
Clocot does not operate a business model based on selling personal information to third parties for monetary consideration.
Some privacy laws define “sale,” “sharing,” or “targeted advertising” broadly enough that certain analytics, advertising, or third-party technology disclosures can qualify even when no money is exchanged.
Where our use of such technologies is legally considered a sale, sharing, or targeted advertising activity, we will provide the legally required notice and opt-out mechanism.
We do not knowingly sell or share the personal information of children under 16 for cross-context behavioral advertising.
24. INTERNATIONAL DATA TRANSFERS
Clocot is a global service.
Personal information may be processed in countries different from the country where the individual resides, including the United States and other locations where LexLupi or service providers operate.
Different countries may have different privacy laws.
Where required, we use recognized transfer mechanisms or safeguards, which may include:
- adequacy decisions;
- the European Commission’s Standard Contractual Clauses;
- the UK International Data Transfer Addendum or other UK transfer mechanisms;
- contractual safeguards;
- data-processing terms;
- technical and organizational measures; and
- other mechanisms recognized by applicable law.
Customers using their own third-party providers may independently cause data to be transferred according to those providers’ locations and terms.
25. DATA STORAGE LOCATIONS
The physical or logical location of data may vary depending on:
- customer region;
- infrastructure configuration;
- provider;
- service type;
- redundancy;
- backup design;
- model provider;
- integration; and
- technical availability.
We do not promise that all information will remain in one country unless a written enterprise agreement specifically provides a data-residency commitment.
26. DATA RETENTION
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including to:
- provide the Services;
- maintain accounts;
- preserve workspace functionality;
- comply with law;
- maintain security;
- resolve disputes;
- enforce agreements;
- maintain accounting records;
- prevent fraud;
- preserve suppression records;
- respond to legal claims; and
- maintain business continuity.
Retention depends on the type of information.
26.1 Account Data
Account and profile information is generally retained while the account is active and for a reasonable period afterward where necessary for legal, security, operational, or dispute purposes.
26.2 Customer Content
Customer Content may be retained according to:
- customer settings;
- workspace configuration;
- plan;
- feature requirements;
- customer instructions;
- contract terms; and
- applicable law.
26.3 AI Conversations and Memory
Conversation history and memory may be retained when the relevant feature is designed to preserve context.
Users or administrators may have tools to delete or disable such data. Technical copies may remain for a limited period in backups or logs.
26.4 Billing Records
Billing, tax, invoice, and transaction information may be retained for periods required by accounting, tax, anti-fraud, and legal obligations.
26.5 Security Logs
Security and audit logs may be retained for a period appropriate to:
- incident investigation;
- fraud prevention;
- access review;
- legal compliance; and
- system integrity.
26.6 Support Records
Support records may be retained to resolve issues, maintain service history, improve support, and defend legal claims.
26.7 Suppression Lists
Minimal opt-out information may be retained after other data is deleted where necessary to ensure that a marketing or communications opt-out continues to be honored.
27. ACCOUNT DELETION AND DATA DELETION
Where available, account owners or Organization administrators may request deletion through account settings or by contacting us.
Deletion can be limited where we must retain information to:
- comply with law;
- maintain accounting records;
- detect fraud;
- preserve security records;
- enforce contracts;
- resolve disputes;
- comply with legal holds; or
- protect rights.
Deleting an account does not necessarily delete information held by a customer, third-party integration, AI Provider, payment processor, or other independent third party.
When LexLupi acts as a processor, requests concerning customer-controlled data may need to be directed to the customer that controls the workspace.
28. BACKUPS AND DISASTER RECOVERY
Deleted data may remain for a limited period in backups or disaster-recovery systems until those copies are rotated, overwritten, or expire under our backup practices.
Backup copies are not intended to be used as active production records after deletion except where restoration is necessary for disaster recovery, legal compliance, or security.
If restored, deleted data may be re-applied to deletion workflows where technically feasible and legally required.
29. SECURITY
We use technical and organizational measures designed to protect personal information against:
- unauthorized access;
- alteration;
- misuse;
- disclosure;
- destruction;
- accidental loss; and
- other security risks.
Measures may include, as appropriate:
- access controls;
- authentication;
- role-based permissions;
- network protections;
- environment separation;
- secrets management;
- logging;
- monitoring;
- secure development practices;
- vulnerability management;
- backups;
- incident response; and
- encryption in transit or at rest where technically appropriate.
No system is completely secure. We cannot guarantee that unauthorized access, cyberattacks, human error, hardware failure, provider failure, or other incidents will never occur.
Users are responsible for protecting their own credentials, API keys, devices, integrations, and administrator permissions.
30. SECURITY INCIDENTS
If we identify a personal-data breach or security incident that triggers legal notification obligations, we will provide required notices to affected customers, individuals, regulators, or other parties within the time required by applicable law.
When we act as a processor, we will notify the relevant customer as required by applicable contract and law.
31. YOUR PRIVACY RIGHTS
Depending on your location and the role in which LexLupi processes your information, you may have rights to:
- access personal information;
- obtain a copy;
- correct inaccurate information;
- request deletion;
- restrict processing;
- object to processing;
- request portability;
- withdraw consent;
- opt out of marketing;
- opt out of certain sales, sharing, or targeted advertising;
- limit certain sensitive-data processing;
- appeal a privacy-rights decision;
- object to certain automated decision-making;
- request information about recipients or categories of recipients; and
- complain to a privacy regulator.
Rights are not absolute. Exceptions may apply.
Where we process information solely on behalf of a customer, we may direct your request to that customer.
32. EEA AND EU GDPR RIGHTS
If the GDPR applies, you may have the right to:
- access your personal data;
- rectify inaccurate personal data;
- erase personal data in applicable circumstances;
- restrict processing;
- object to processing based on legitimate interests;
- receive portable data where applicable;
- withdraw consent;
- object to direct marketing at any time;
- request safeguards concerning certain automated decisions; and
- lodge a complaint with a supervisory authority.
You may also contact the data-protection authority in the EEA country where you live, work, or believe an infringement occurred.
33. UNITED KINGDOM PRIVACY RIGHTS
Where UK data-protection law applies, individuals may have rights broadly including:
- access;
- correction;
- erasure;
- restriction;
- objection;
- portability;
- withdrawal of consent;
- rights concerning direct marketing;
- rights concerning certain automated decisions; and
- the right to complain to the UK Information Commissioner’s Office.
Where a UK representative is legally required and appointed, the relevant contact information will be published in the Clocot Legal Center.
34. SWITZERLAND AND SERBIA
Individuals in Switzerland and Serbia may have rights under applicable local data-protection law, including rights concerning:
- transparency;
- access;
- correction;
- deletion where applicable;
- objection or restriction where applicable;
- lawful processing;
- international transfers; and
- complaints to the competent authority.
LexLupi will honor applicable mandatory rights even where this Policy uses GDPR terminology for convenience.
35. CALIFORNIA PRIVACY NOTICE
This section applies to California residents where the California Consumer Privacy Act, as amended, applies to LexLupi.
35.1 Categories of Personal Information
Depending on how an individual uses Clocot, in the preceding 12 months we may have collected categories such as:
- identifiers;
- customer-record information;
- commercial information;
- internet or electronic-network activity;
- approximate geolocation;
- professional or employment-related information;
- audio, electronic, visual, or similar information;
- inferences;
- account credentials;
- financial-account or transaction information;
- communications content; and
- other personal information contained in Customer Content.
We collect these categories from the sources described in this Policy and use them for the business and commercial purposes described in this Policy.
35.2 Categories of Recipients
We may disclose relevant categories to:
- infrastructure providers;
- AI Providers;
- payment processors;
- communications providers;
- analytics providers;
- security providers;
- connected services;
- professional advisers;
- corporate transaction parties; and
- government or legal recipients where required.
35.3 California Rights
Subject to applicable exceptions, California residents may have rights to:
- know categories and specific pieces of personal information;
- delete personal information;
- correct inaccurate personal information;
- opt out of sale or sharing;
- limit certain uses or disclosures of sensitive personal information;
- receive information about collection and disclosure practices; and
- receive equal service and pricing without unlawful discrimination for exercising privacy rights.
35.4 Sensitive Personal Information
We do not use sensitive personal information to infer characteristics about individuals for unrelated purposes.
Where California law provides a right to limit certain uses of sensitive personal information and our processing falls within that right, we will provide an appropriate mechanism.
35.5 Global Privacy Control
Where legally required and technically applicable, we recognize qualifying browser-based opt-out preference signals such as Global Privacy Control for the relevant browser or device.
36. OTHER U.S. STATE PRIVACY RIGHTS
Residents of certain U.S. states may have rights concerning:
- access;
- correction;
- deletion;
- portability;
- targeted advertising;
- sale of personal data;
- certain profiling;
- sensitive-data consent;
- appeals of denied requests; and
- other state-specific rights.
Where a state law provides an appeal process, you may appeal by replying to our response or contacting office@clocot.com with the subject “Privacy Appeal.”
37. CANADA
Where Canadian privacy law applies, we process personal information in accordance with applicable accountability, consent, purpose limitation, safeguards, access, correction, and retention requirements.
Individuals may request:
- access to personal information;
- correction;
- information about use and disclosure; and
- review of privacy concerns.
Consent may be withdrawn subject to legal or contractual restrictions and reasonable notice.
38. BRAZIL
Where Brazil’s Lei Geral de Proteção de Dados Pessoais, or LGPD, applies, individuals may have rights including, as applicable:
- confirmation of processing;
- access;
- correction;
- anonymization, blocking, or deletion of unnecessary or unlawful data;
- portability;
- information about sharing;
- information concerning consent;
- withdrawal of consent;
- deletion of data processed based on consent where applicable;
- objection in applicable circumstances; and
- review of certain automated decisions.
Requests may be submitted to office@clocot.com.
39. AUSTRALIA AND NEW ZEALAND
Where Australian or New Zealand privacy law applies, individuals may have rights to request access to or correction of personal information.
We take reasonable measures to manage personal information openly and securely and to address cross-border disclosures in accordance with applicable law.
Privacy complaints may be submitted to office@clocot.com. We will investigate and respond within a reasonable period and within any legally required timeframe.
40. SINGAPORE AND OTHER APAC JURISDICTIONS
Where Singapore’s Personal Data Protection Act or similar APAC privacy laws apply, individuals may have rights relating to:
- notice;
- consent;
- withdrawal of consent;
- access;
- correction;
- protection;
- retention;
- transfer safeguards; and
- complaints.
Specific rights depend on the jurisdiction and applicable exemptions.
41. INDIA
Where India’s Digital Personal Data Protection framework or other applicable Indian privacy law applies, we provide notices, consent mechanisms, correction or erasure processes, grievance channels, and other rights as required by applicable law when those provisions apply to our processing.
42. CHILDREN’S PRIVACY
Clocot is not directed to children.
Unless expressly authorized under a separate program, users must be at least 18 years old or the age of legal majority in their jurisdiction, whichever is higher.
We do not knowingly collect personal information directly from children for ordinary Clocot accounts.
If we learn that personal information was collected from a child in violation of applicable law, we will take reasonable steps to delete or otherwise address the information.
Customers must not use Clocot to unlawfully collect, profile, market to, or make high-impact decisions about children.
43. ORGANIZATION ADMINISTRATORS
If you use Clocot through an Organization, administrators may be able to:
- access workspace content;
- manage accounts;
- reset access;
- change permissions;
- configure retention;
- connect or disconnect integrations;
- review audit activity;
- reassign workspace data;
- export Organization data;
- suspend users; and
- delete or control content.
Your Organization may have its own privacy notice governing how it uses your information.
LexLupi is not responsible for an Organization’s independent privacy practices.
44. DATA ABOUT OTHER PEOPLE
Clocot allows users to process information about other individuals.
If you submit personal information about another person, you represent that you have the right to process and disclose that information to Clocot for the intended purpose.
Examples include:
- CRM contacts;
- employees;
- contractors;
- customers;
- prospects;
- event attendees;
- suppliers;
- social-media contacts; and
- communication recipients.
Do not submit personal information merely because it is technically accessible. You remain responsible for lawful collection and use.
45. DATA-SUBJECT REQUESTS WHEN A CUSTOMER CONTROLS THE DATA
If your personal information appears in a customer’s Clocot workspace, we may act only as that customer’s processor.
In that situation:
- the customer determines the purpose of processing;
- the customer is generally responsible for responding to your request; and
- we may forward your request to the customer or tell you how to contact them.
We will assist customers with legally required requests as required by contract and law.
46. HOW TO EXERCISE PRIVACY RIGHTS
To exercise a privacy right, contact:
office@clocot.com
Use the subject line “Privacy Request” and describe the request clearly.
You may also use any privacy-request tool or form we make available in the Services.
We may request information reasonably necessary to verify:
- your identity;
- your authority;
- the account concerned;
- the relevant jurisdiction; and
- whether LexLupi or a customer controls the data.
We will not request more verification information than is reasonably necessary.
47. AUTHORIZED AGENTS
Where applicable law permits an authorized agent to submit a request, we may require:
- evidence of the agent’s authority;
- verification of the individual’s identity; and
- direct confirmation from the individual where permitted by law.
48. RESPONSE TIMES AND APPEALS
We respond within the period required by applicable law.
Some laws permit an extension where a request is complex or numerous. If an extension applies, we will provide notice where required.
If we deny a request, we will explain the basis where legally required.
Where local law provides a right to appeal, instructions for appeal will be included in the response or may be submitted to office@clocot.com.
49. IDENTITY VERIFICATION AND FRAUD PREVENTION
We may deny or limit a privacy request if we cannot reasonably verify the requester, if the request is fraudulent, or where applicable law permits refusal.
Verification information is used primarily to process the request and protect against unauthorized disclosure or deletion.
50. DO NOT TRACK
Some browsers provide a “Do Not Track” signal.
Because there is no single universally adopted technical standard governing all Do Not Track signals, our Services may not respond to every such signal.
Where applicable law requires recognition of a specific opt-out preference signal, such as Global Privacy Control, we handle that signal as required.
51. DE-IDENTIFIED AND AGGREGATED INFORMATION
We may create aggregated or de-identified information that does not reasonably identify an individual.
We may use such information for:
- analytics;
- research;
- product planning;
- benchmarking;
- security;
- capacity planning;
- service improvement; and
- business operations.
Where applicable law regulates de-identified data, we maintain it in de-identified form and do not attempt to re-identify it except as permitted by law, such as to test de-identification methods.
52. PUBLIC CONTENT AND SHARING FEATURES
If you deliberately publish content publicly or share a public link, the information may be accessible to others.
Before publishing personal information, ensure that you have the right to disclose it.
Removing a public link may prevent future access through Clocot but may not remove copies already downloaded, indexed, captured, or redistributed by third parties.
53. THIRD-PARTY LINKS
The Services may contain links to third-party websites or services.
We are not responsible for the privacy practices of a third party merely because Clocot links to or integrates with it.
Review the third party’s privacy policy before providing personal information.
54. BUSINESS CHANGES
If LexLupi undergoes a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or transfer of the Clocot business, personal information may be transferred as part of that transaction.
Where required, we will provide notice of material changes to the identity of the controller or to relevant privacy practices.
55. GOVERNMENT AND LAW-ENFORCEMENT REQUESTS
We may receive requests for information from courts, law-enforcement agencies, regulators, or government bodies.
We evaluate requests based on applicable law and may require valid legal process.
Where legally permitted and appropriate, we may challenge overly broad or unlawful requests.
We may be prohibited from notifying affected individuals in some circumstances.
56. DATA MINIMIZATION AND PRIVACY BY DESIGN
We seek to design Clocot so that data access can be limited according to:
- purpose;
- permissions;
- role;
- workspace;
- integration;
- workflow; and
- user configuration.
Because Clocot is highly configurable, customers also play an important role in data minimization.
Customers should avoid giving Agents or integrations broader access than necessary for the intended task.
57. CHANGES TO THIS PRIVACY POLICY
We may update this Policy as:
- laws change;
- Clocot evolves;
- providers change;
- new features launch;
- processing changes; or
- our corporate structure changes.
The “Last Updated” date identifies the current version.
If a change materially affects privacy rights or how we use personal information, we will provide additional notice where legally required.
Continued use of the Services after an update does not replace any consent that applicable law requires us to obtain separately.
58. PREVIOUS VERSIONS
We may maintain archived versions of this Policy or make them available on request where reasonably necessary to document historical terms.
59. COMPLAINTS
If you believe we have processed personal information improperly, contact us first at:
office@clocot.com
We will review the complaint and respond within a reasonable period.
You may also have the right to complain to the privacy or data-protection regulator in your jurisdiction.
60. DATA PROTECTION OFFICER AND REPRESENTATIVES
LexLupi will appoint a Data Protection Officer, EU representative, UK representative, or other statutory privacy representative where required by applicable law.
If such an appointment is required and made, current contact details will be published in the Clocot Legal Center or otherwise provided as required by law.
The Privacy and Legal Contact listed in this Policy is not necessarily a formally designated statutory Data Protection Officer unless expressly stated.
61. CONTACT US
For privacy questions, rights requests, complaints, or data-protection matters:
LexLupi LLC Operator of Clocot
Privacy and Legal Contact: Tatjana Sindjelic Email: office@clocot.com U.S. registered office: 131 Continental Dr, Suite 305, Newark, DE 19713, United States Serbian principal business address: Save Kovacevic 29/4, 34000 Kragujevac, Serbia
When contacting us about a privacy request, include enough information for us to identify the relevant account or processing activity without sending unnecessary sensitive information.