This Exhibit describes certain operational, technical, organizational, and privacy-related practices implemented by LEXZUR in connection with the Services.
To the extent this Exhibit relates to the processing of Personal Data, it shall be read together with Exhibit A – Data Processing Addendum.
Capitalized terms not defined in this Exhibit shall have the meanings assigned to them in the Agreement.
LEXZUR may update its operational practices, infrastructure, technologies, and security measures from time to time, provided that such updates do not materially reduce the overall level of security of the Services.
In connection with the Services, LEXZUR may collect information provided directly by Customers and Authorized Users, including account registration information, contact details, billing information, support requests, and data uploaded or processed through the Services.
LEXZUR may also automatically collect certain technical and usage information relating to access to and use of the Services and LEXZUR’s website, including browser type, operating system, IP address, device information, pages visited, session duration, referral sources, and usage analytics. Such information may be collected through cookies, web beacons, log files, analytics technologies, and similar tools for purposes relating to the operation, maintenance, monitoring, security, support, improvement, and optimization of the Services and user experience.
LEXZUR may process information for purposes including providing and maintaining the Services, account administration, authentication, billing, customer support, operational monitoring, security, analytics, service improvement, legal compliance, communications with Customers, and other legitimate business and operational purposes related to the Services.
Except as otherwise stated in the Agreement, Customer retains ownership and control of Customer Data uploaded or processed through the Services. LEXZUR processes Customer Data in accordance with the Agreement and applicable data protection obligations.
LEXZUR may share information with affiliates, subprocessors, infrastructure providers, hosting providers, service providers, advisors, and governmental or regulatory authorities where necessary for the provision of the Services, legal compliance, security, operational purposes, or protection of legitimate business interests, subject to applicable laws.
Customers and users may voluntarily submit information through newsletters, events, blogs, forums, wikis, support channels, community features, or similar website functionalities made available by LEXZUR.
Information voluntarily submitted to public areas of the website may become publicly visible depending on the nature of the feature used. LEXZUR may retain IP addresses, timestamps, and related technical information associated with public website activity for security, fraud prevention, monitoring, and operational purposes.
Users may unsubscribe from marketing or newsletter communications using the unsubscribe functionality included in such communications.
LEXZUR implements commercially reasonable technical and organizational measures designed to protect Customer Data and information processed through the Services against unauthorized access, disclosure, destruction, loss, alteration, misuse, or disruption.
Access to Customer Data is restricted to authorized personnel with a legitimate operational, support, security, compliance, or legal need to access such data.
While LEXZUR implements measures designed to protect Customer Data and systems, no method of transmission, storage, or security measure can guarantee absolute security.
Individuals may contact LEXZUR regarding applicable privacy or data protection requests in accordance with the Agreement, applicable law, and LEXZUR’s privacy procedures.
LEXZUR maintains operational and technical procedures designed to support the confidentiality, integrity, availability, and resilience of the Services.
LEXZUR may use third-party hosting providers, infrastructure providers, cloud platforms, subprocessors, and service providers in connection with the operation and delivery of the Services.
LEXZUR periodically reviews and updates operational and security practices in accordance with business, technical, legal, and security requirements. LEXZUR maintains internal procedures designed to detect, investigate, respond to, mitigate, and remediate security incidents affecting the Services.
LEXZUR maintains internal development and change management procedures intended to evaluate and review material changes to systems, infrastructure, applications, and configurations. LEXZUR may implement secure software development lifecycle practices, including code review procedures, testing methodologies, vulnerability remediation processes, and security awareness measures, taking into consideration applicable industry practices where appropriate.
LEXZUR may implement commercially reasonable monitoring, logging, authentication, access control, account protection, and session management measures designed to support the security and operation of the Services.
LEXZUR maintains internal policies, procedures, and operational practices intended to support compliance with applicable legal, regulatory, security, and privacy obligations.
LEXZUR may periodically review and update its internal controls, operational procedures, security measures, and governance practices in accordance with evolving business, legal, operational, and security requirements.
Nothing in this Exhibit shall be construed as a guarantee or warranty that the Services will be uninterrupted, error-free, or immune from security threats or vulnerabilities.
LEXZUR may implement operational, technical, and governance measures intended to support the responsible deployment and operation of AI Features.
Such measures may include retrieval-grounded outputs, citation mechanisms, explainability features, confidence scoring, workflow controls, user approval mechanisms, human review processes, auditability features, monitoring procedures, and model access controls where appropriate.
AI Features may be supported through third-party infrastructure or model providers operating within approved hosting environments or regional deployment configurations.
LEXZUR maintains commercially reasonable backup, business continuity, and disaster recovery procedures designed to minimize data loss and operational disruption.
Backups may be performed periodically and retained in accordance with operational requirements, infrastructure design, retention procedures, and business continuity objectives. LEXZUR may maintain redundancy measures, restoration testing procedures, monitoring systems, and disaster recovery processes intended to support service continuity and recovery.
Recovery objectives, restoration timelines, and backup procedures may vary depending on the Services, infrastructure, hosting environment, operational requirements, and circumstances of the incident.
LEXZUR uses commercially reasonable efforts to maintain service availability, excluding scheduled maintenance, emergency maintenance, force majeure events, internet disruptions, third-party failures, and circumstances beyond LEXZUR’s reasonable control.
LEXZUR may provide support services through customer portals, ticketing systems, email communications, or other support channels made available by LEXZUR. Any response times, support targets, or service level objectives communicated by LEXZUR are operational targets only and do not constitute guaranteed service commitments unless expressly agreed otherwise in a separate written agreement.
LEXZUR provides support services in accordance with the support plan purchased by the Customer. Support targets, response times, workaround targets, and resolution objectives may vary depending on the applicable support tier, hosting model, deployment environment, and purchased services.
The service levels below represent operational targets for standard support services provided remotely unless otherwise agreed in writing.
Service level commitments exclude scheduled maintenance, emergency maintenance, force majeure events, Customer-caused issues, third-party failures, internet connectivity issues, unsupported configurations, misuse, unauthorized modifications, and circumstances outside LEXZUR’s reasonable control.
Response times and resolution objectives commence once sufficient information has been provided by Customer to allow LEXZUR to investigate the issue.
Remote access or Customer cooperation may be required for troubleshooting, investigation, workaround implementation, and issue resolution.
| Type of Request | Priority | Definition | First Time to Response | Time to Workaround by Remote Access | Time to Final Resolution by Remote Access |
|---|---|---|---|---|---|
| Incident / Bug | Critical | Your application is degraded. Users aren’t able to perform their job function, and no workarounds are available. | 20 Minutes | 6 Hours | 2 Business Days |
| High | A feature is unavailable, application performance is significantly degraded, or users job functions are impaired. | 4 Hours | 2 Business Days | 5 Business Days | |
| Medium | The application or specific feature isn’t working as expected, but there is a workaround available. Users’ experience is impacted, but their job function is not impaired. | 4 Hours | 3 Business Days | 20 Business Days | |
| Low | Typically, smaller paper cuts such as cosmetic errors, or non-critical functionality not behaving as expected. | 4 Hours | 5 Business Days | 20 Business Days |
LEXZUR shall use commercially reasonable efforts to meet the above service levels.
Any applicable service credits shall be governed by the Terms and Conditions and shall constitute Customer’s sole and exclusive remedy for covered service failures.
LEXZUR reserves the right to reasonably reclassify support tickets where the reported severity does not align with the applicable priority definitions.
LEXZUR may offer different hosting or deployment models, including cloud-hosted, private SaaS, hybrid, or on-premises environments.
LEXZUR may also offer Customers different hosting, deployment, or data residency options, including hosting environments located in the Kingdom of Saudi Arabia, the United Arab Emirates, the European Union, or other jurisdictions made available by LEXZUR from time to time. The Customer remains responsible for selecting a hosting region suitable for its regulatory obligations.
Customer acknowledges that certain operational, regulatory, privacy, security, support, data residency, and data processing requirements applicable to the Services may vary depending on the hosting region, deployment model, infrastructure environment, or applicable laws and regulatory requirements associated with the selected hosting location. The selected hosting region or deployment environment may be specified in the applicable Order Form, Statement of Work, Commercial Proposal, or other written agreement between the Parties.
Customer Data may be processed, hosted, backed up, or stored in jurisdictions where LEXZUR, its affiliates, hosting providers, infrastructure providers, or subprocessors operate, subject to applicable safeguards and the Agreement.
Certain third-party hosting or infrastructure providers used by LEXZUR may maintain industry-recognized certifications or compliance frameworks, including SOC or ISO certifications. Kindly refer to Lexzur Trust Center https://trust.lexzur.com/
LEXZUR may use industry-standard encryption technologies designed to protect data in transit and, where applicable, data at rest. LEXZUR may also implement password protection measures, authentication controls, account protection mechanisms, access logging, user permission settings, and session monitoring functionalities where appropriate.
Customer acknowledges that certain features or functionalities of the Services may rely on third-party providers, integrations, or external services that are not controlled by LEXZUR and may be subject to separate terms, policies, and operational practices of such third parties.
Where Customers enable or use third-party integrations, plugins, APIs, or connected services in connection with the Services, LEXZUR may process limited information necessary to establish, maintain, support, and operate such integrations.
Customers are responsible for maintaining the confidentiality of account credentials, configuring user permissions and access rights, maintaining appropriate security within their own systems and environments, ensuring lawful use of the Services, and maintaining independent backups where appropriate.
Customers remain solely responsible for the content, legality, accuracy, and integrity of Customer Data uploaded or processed through the Services.
LEXZUR retains Personal Data for the duration necessary to provide the Services, comply with applicable law, resolve disputes, enforce legal rights, maintain operational records, and fulfill legitimate business and compliance purposes.
Customer Data may be retained in backup systems, archived systems, logs, or disaster recovery environments for limited periods in accordance with operational procedures and retention practices.
Deletion or return of Customer Data following termination of the Services shall be governed by the Agreement and Exhibit A – Data Processing Addendum.
Customer acknowledges that compliance with any specific legal, regulatory, industry, governmental, or sector-specific requirements applicable to the Customer, including without limitation banking, financial services, healthcare, governmental, or data localization requirements, remains the Customer’s responsibility unless expressly agreed otherwise in writing.
LEXZUR may modify or update this Exhibit from time to time to reflect operational, technical, legal, regulatory, security, or business changes.
Updated versions of this Exhibit may become effective upon publication on LEXZUR’s website or otherwise being made available to Customers.
Additional information regarding privacy and data protection practices, including GDPR-related matters, is available in Exhibit A – Data Processing Addendum.