
Data Processing Addendum
Last updated October 5, 2026
This Data Processing Addendum ("Addendum") forms part of the Terms of Service or other written agreement ("Agreement") between Lexos, Inc., a Delaware corporation with offices at 128 Dorrance St, Ste 220, Providence, RI 02903, USA ("Lexos"), and the customer that accepted the Agreement ("Customer"). It applies whenever Lexos processes personal data on Customer's behalf. Customer accepts it by accepting the Agreement. Lexos will countersign a copy on request to privacy@golexos.com.
TABLE OF CONTENTS
- DEFINITIONS
- ROLES AND SCOPE
- CUSTOMER'S INSTRUCTIONS
- CONFIDENTIALITY AND PERSONNEL
- SECURITY
- SUB-PROCESSORS
- DATA SUBJECT REQUESTS
- PERSONAL DATA BREACH
- ASSISTANCE
- RETENTION, DELETION AND RETURN
- AUDITS
- INTERNATIONAL TRANSFERS
- LEXOS'S PROCESSING AS A CONTROLLER
- UNITED STATES STATE PRIVACY LAWS
- LIABILITY
- GENERAL
- ANNEX I: DETAILS OF THE PROCESSING
- ANNEX II: TECHNICAL AND ORGANIZATIONAL MEASURES
- ANNEX III: SUB-PROCESSORS
- ANNEX IV: INTERNATIONAL TRANSFER TERMS
1. DEFINITIONS
1.1 "Data Protection Laws" means the laws that apply to the processing of Customer Personal Data. They include the EU General Data Protection Regulation ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and United States state privacy laws such as the California Consumer Privacy Act ("CCPA").
1.2 "Customer Personal Data" means personal data within Customer Data that Lexos processes on Customer's behalf to provide the Services.
1.3 "End Customer" means a person whose move Customer is surveying or quoting.
1.4 "Job Media" means photos and videos submitted to the Services.
1.5 "Sub-processor" means a third party Lexos engages to process Customer Personal Data.
1.6 "Standard Contractual Clauses" means the clauses annexed to European Commission Implementing Decision (EU) 2021/914.
1.7 "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
1.8 The terms "controller", "processor", "data subject", "personal data", "processing" and "supervisory authority" have the meanings given in the GDPR. Other capitalized terms have the meanings given in the Agreement.
2. ROLES AND SCOPE
2.1 Customer is the controller of Customer Personal Data, or a processor acting for its own client. Lexos is Customer's processor, or sub-processor where Customer is itself a processor.
2.2 Annex I describes the subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects.
2.3 Lexos is an independent controller of the data described in section 13. This Addendum's processor obligations do not apply to that processing, but section 13 does.
3. CUSTOMER'S INSTRUCTIONS
3.1 Lexos will process Customer Personal Data only on Customer's documented instructions, unless the law requires otherwise. In that case Lexos will tell Customer first, unless the law forbids it.
3.2 The Agreement, this Addendum and Customer's use and configuration of the Services are Customer's complete instructions.
3.3 Lexos will tell Customer if it believes an instruction breaks Data Protection Laws.
3.4 Customer is responsible for the lawfulness of its instructions, for having a lawful basis to collect Customer Personal Data, and for the notices it owes to End Customers.
4. CONFIDENTIALITY AND PERSONNEL
4.1 Lexos limits access to Customer Personal Data to employees and contractors who need it to provide the Services.
4.2 Everyone with that access is bound by a written duty of confidentiality that continues after their engagement ends.
5. SECURITY
5.1 Lexos maintains the technical and organizational measures in Annex II. They are designed to protect Customer Personal Data against a Personal Data Breach.
5.2 Lexos may update the measures over time, but will not materially reduce the overall level of protection.
6. SUB-PROCESSORS
6.1 Customer gives Lexos general authorization to engage Sub-processors. The current list is at https://golexos.com/subprocessors.
6.2 Lexos will give at least 30 days' notice before adding or replacing a Sub-processor. It does so by updating that page and emailing customers who have subscribed to updates there.
6.3 Customer may object within that 30 days on reasonable data protection grounds by emailing privacy@golexos.com. The parties will work in good faith on a solution. If none is found, Customer may terminate the affected Services and Lexos will refund any prepaid fees for the period after termination.
6.4 Lexos binds each Sub-processor by written contract to data protection obligations no less protective than this Addendum. Lexos remains responsible for each Sub-processor's performance.
7. DATA SUBJECT REQUESTS
7.1 If a data subject contacts Lexos about Customer Personal Data, Lexos will forward the request to Customer without undue delay. Lexos will not answer it directly, except to say that it has been passed on.
7.2 Lexos will give Customer reasonable help to respond to requests for access, correction, deletion, restriction, portability and objection. This includes the deletion tools in the Services.
8. PERSONAL DATA BREACH
8.1 Lexos will notify Customer without undue delay, and in any case within 72 hours, after becoming aware of a Personal Data Breach.
8.2 The notice will describe, as far as Lexos knows, the nature of the breach, the data and data subjects affected, the likely consequences, and the steps taken or planned. Lexos will send updates as it learns more.
8.3 Lexos will take reasonable steps to contain and remedy the breach. A notice under this section is not an admission of fault or liability.
9. ASSISTANCE
Taking into account the nature of the processing and the information available to it, Lexos will give Customer reasonable help with data protection impact assessments and with consultations with supervisory authorities that relate to the Services.
10. RETENTION, DELETION AND RETURN
10.1 Customer controls how long Customer Personal Data is kept. Customer may delete a survey at any time through the Services or by written request. Lexos will complete a requested deletion within 30 days.
10.2 Within 30 days after the Agreement ends, Lexos will delete Customer Personal Data. If Customer asks before that deadline, Lexos will first make it available for export.
10.3 Copies in backups are overwritten in the ordinary course of the backup cycle. Until then they stay protected under this Addendum and are not otherwise processed.
10.4 Lexos may keep Customer Personal Data where the law requires it, and only for as long as the law requires.
11. AUDITS
11.1 On written request, Lexos will give Customer the information reasonably needed to show compliance with this Addendum. This includes its Sub-processor list, a description of its security measures, and written answers to a reasonable questionnaire.
11.2 If that information is not enough to show compliance, Customer may carry out an audit. An audit takes place at most once in any 12 months, on 30 days' written notice, remotely where possible, and during business hours. It is limited to Customer's own data and the systems that process it.
11.3 Customer bears its own audit costs and those of any auditor. The auditor must be bound by confidentiality and must not be a competitor of Lexos.
11.4 These limits do not apply where a supervisory authority requires an audit or where a Personal Data Breach affecting Customer has occurred.
12. INTERNATIONAL TRANSFERS
12.1 Lexos hosts Customer Personal Data in the United States. Authorized Lexos personnel may access it remotely from other countries to provide and support the Services, under the confidentiality and security obligations in this Addendum.
12.2 Where Customer Personal Data protected by the GDPR, the UK GDPR or Swiss law is transferred to Lexos in a country without an adequacy decision, the transfer terms in Annex IV apply and form part of this Addendum.
12.3 Lexos will not transfer Customer Personal Data onward to a Sub-processor in such a country without a transfer mechanism that Data Protection Laws accept.
13. LEXOS'S PROCESSING AS A CONTROLLER
13.1 Account and business data. Lexos is a controller of the personal data it needs to run its business. Examples are Customer's user accounts, billing records, support messages and security logs. The Lexos Privacy Policy describes that processing.
13.2 De-identified and aggregated data. Customer instructs Lexos to create data that does not identify Customer, any End Customer or any other person. Lexos may use it to operate, analyze and improve the Services and to develop new products. Lexos will not try to re-identify it and will require the same of anyone who receives it.
13.3 Model improvement program. Lexos may use Job Media and the inventories generated from it to evaluate, train and improve the models behind the Services. The program covers only surveys where the End Customer was shown a notice of the program with a way to opt out, and where neither Customer nor the End Customer has opted out. Job Media from any other survey is not used for training. For this processing Lexos acts as an independent controller and takes responsibility for its own compliance with Data Protection Laws. Lexos will:
- include a survey in the program only after the End Customer has been shown that notice and opt-out;
- separate Job Media from End Customer names, contact details and addresses before use;
- take reasonable steps to exclude or obscure people, documents and screens in Job Media;
- use the data only to develop its own models and Services, and never sell, license or disclose it to third parties other than Sub-processors acting for Lexos;
- stop using Customer's Job Media for new training within 30 days of an opt-out by Customer, and stop using an End Customer's Job Media on that person's opt-out.
13.4 Opting out. Customer may opt its account out at any time by emailing privacy@golexos.com. An opt-out does not affect Customer's use of the Services or its fees.
13.5 After termination. Section 10 does not require Lexos to delete data created under section 13.2, or Job Media already included in the program in the separated form described in section 13.3.
14. UNITED STATES STATE PRIVACY LAWS
14.1 Where the CCPA or a similar state law applies, Lexos is Customer's service provider or processor. Customer discloses Customer Personal Data to Lexos only for the business purposes set out in the Agreement and this Addendum.
14.2 Lexos will not sell or share Customer Personal Data. Lexos will not keep, use or disclose it outside its direct business relationship with Customer, or for any purpose other than those business purposes, except as those laws allow a service provider to do. That includes building or improving the quality of its services without building household or consumer profiles.
14.3 Lexos will not combine Customer Personal Data with personal data from other sources, except as those laws allow.
14.4 Lexos will tell Customer if it decides it can no longer meet its obligations under those laws. Customer may then take reasonable steps to stop and remedy any unauthorized use.
15. LIABILITY
Each party's liability under this Addendum, including the Standard Contractual Clauses, is subject to the limits and exclusions of liability in the Agreement. Nothing in this Addendum limits a data subject's rights under Data Protection Laws or the Standard Contractual Clauses.
16. GENERAL
16.1 Term. This Addendum lasts as long as Lexos processes Customer Personal Data.
16.2 Order of precedence. If documents conflict on the processing of personal data, the order is: the Standard Contractual Clauses, then this Addendum, then the Agreement. A data protection agreement that Customer and Lexos have signed separately takes precedence over this Addendum.
16.3 Changes. Lexos may update this Addendum to reflect changes in law or in the Services. Lexos will give 30 days' notice of a change that materially reduces Customer's rights.
16.4 Governing law. The governing law and courts named in the Agreement apply to this Addendum, except where Annex IV says otherwise for the transfer terms.
ANNEX I: DETAILS OF THE PROCESSING
A. Parties
| Data exporter | Data importer | |
|---|---|---|
| Name | Customer, as identified in its Lexos account | Lexos, Inc. |
| Address | As given in Customer's account or order | 128 Dorrance St, Ste 220, Providence, RI 02903, USA |
| Contact | The account owner's email address | privacy@golexos.com |
| Role | Controller, or processor for its own client | Processor, or sub-processor |
| Activities | Moving, relocation and related services | Pre-move survey and inventory software |
B. Description of the processing
| Item | Description |
|---|---|
| Data subjects | End Customers and members of their households. Customer's employees and other users of its account. |
| Personal data | Names, phone numbers, email addresses, origin and destination addresses, and move details. Photos and videos of homes and belongings. Audio, video and transcripts of guided survey calls. Inventories and notes. Names and email addresses of Customer's users. |
| Sensitive data | None is requested. Photos and videos may show it incidentally. |
| Frequency | Continuous for the term of the Agreement. |
| Nature | Collection, storage, analysis by AI models, generation of inventories, delivery of survey links by SMS, WhatsApp and email, live video calls, transcription, and deletion. |
| Purpose | Providing the Services to Customer under the Agreement. |
| Retention | Until Customer deletes the data or the Agreement ends, as set out in section 10. |
| Sub-processors | Listed at https://golexos.com/subprocessors, for the same subject matter and duration. |
C. Competent supervisory authority
The supervisory authority of the EU member state where Customer is established. If Customer is not established in the EU, it is the authority where Customer's EU representative is established, or otherwise where the affected data subjects are located.
ANNEX II: TECHNICAL AND ORGANIZATIONAL MEASURES
Lexos keeps these measures in place.
| Area | Measure |
|---|---|
| Hosting | Customer Personal Data is hosted on Google Cloud Platform in the us-central1 region (Iowa, USA). |
| Encryption | Data is encrypted in transit with TLS and at rest with Google Cloud's default encryption. |
| Tenant separation | Each customer's data is logically separated by account, and users see only their own company's data. |
| Access control | Production access is limited to the personnel who need it. Google accounts with administrative or production access require 2-Step Verification. |
| Secrets | Credentials and API keys are kept in a managed secrets service, not in source code. |
| Backups | The database is backed up automatically. |
| Personnel | Employees and contractors with access to Customer Personal Data are bound by written confidentiality obligations. |
| Vendors | Lexos has a data processing agreement with each Sub-processor. Its AI providers are contractually barred from training their models on Customer Personal Data. |
| Incidents | Lexos assesses, contains and reports any Personal Data Breach as set out in section 8. |
| Deletion | Customers can delete surveys in the Services. Lexos deletes data on request and at the end of the Agreement, as set out in section 10. |
ANNEX III: SUB-PROCESSORS
The current list is published at https://golexos.com/subprocessors and forms part of this Addendum.
ANNEX IV: INTERNATIONAL TRANSFER TERMS
1. Transfers from the European Economic Area. The Standard Contractual Clauses are incorporated into this Addendum and apply as follows:
| Clause | Selection |
|---|---|
| Module | Module Two (controller to processor) where Customer is a controller. Module Three (processor to processor) where Customer is a processor. |
| Clause 7, docking | Applies. |
| Clause 9(a), sub-processors | Option 2, general written authorization, with the 30-day notice period in section 6. |
| Clause 11(a), redress | The optional wording does not apply. |
| Clause 13, supervision | The authority identified in Annex I.C. |
| Clause 17, governing law | Option 1, the law of Ireland. |
| Clause 18(b), courts | The courts of Ireland. |
| Annexes I to III of the Clauses | Completed by Annexes I to III of this Addendum. |
2. Transfers from the United Kingdom. The International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0, issued by the UK Information Commissioner, is incorporated into this Addendum. Its Tables 1 to 3 are completed by Annexes I to III and by paragraph 1 above. For Table 4, neither party may end that addendum under its section 19.
3. Transfers from Switzerland. The Standard Contractual Clauses apply as selected in paragraph 1, with these changes. References to the GDPR are read as references to the Swiss Federal Act on Data Protection. The Federal Data Protection and Information Commissioner is the competent supervisory authority. The term "member state" does not prevent data subjects in Switzerland from bringing a claim where they live.
4. Other transfer mechanisms. If Lexos adopts another transfer mechanism that Data Protection Laws accept, such as certification under the EU-US Data Privacy Framework, that mechanism applies to the transfers it covers in place of paragraphs 1 to 3.
5. Conflict. If this Addendum or the Agreement conflicts with the Standard Contractual Clauses, the Clauses control.