Effective · January 1, 2025 · Last updated · July 16, 2026
Privacy Policy
1. Introduction
Lalexi is operated by NOCODE LTD ("we," "our," or "us"). We are committed to protecting your privacy and the privacy of your customers. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our WhatsApp and Telegram business management platform ("Service").
This policy applies to all users of our Service, including businesses, employees, and end customers whose communications are processed through our platform.
For End User communications and contact lists you upload or message through the Service, you are the data controller (or equivalent) and we act as your service provider / processor. You are solely responsible for having a lawful basis — including consent where required — to collect and message those contacts, and for the accounts you choose to connect. We do not obtain End User consent for you.
Descriptive security or product statements on our website do not modify this Privacy Policy or our Terms of Service.
2. Information We Collect
2.1 Information You Provide Directly
- Account Information: Name, email address, phone number, company information
- Billing Information: Payment details, billing address (processed securely through third-party payment processors)
- Profile Information: Profile pictures, display names, and other account customization data
2.2 Communication Data
- Message Content: Text messages, images, videos, documents, and other media sent through connected WhatsApp and Telegram accounts
- Conversation Metadata: Timestamps, sender/recipient information, delivery status, read receipts
- Contact Information: Names and phone numbers of individuals your team communicates with
- Campaign Data: Bulk messaging campaigns, templates, and distribution lists
2.3 Technical Information
- Device Information: IP addresses, browser type, operating system, device identifiers
- Usage Data: Features used, time spent on platform, interaction patterns
- Log Data: Server logs, error reports, system activity
2.4 Third-Party Platform Data
- WhatsApp Integration: Account connection data, conversation histories, contact lists
- Telegram Integration: Account connection data, conversation histories, contact lists
3. Legal Basis for Processing (EU Users)
Under the General Data Protection Regulation (GDPR), where we act as a data controller (for example account, billing, and website visitor data), we process personal data based on:
- Consent: When you explicitly agree to data processing for specific purposes
- Contract Performance: To provide our Service and fulfill our contractual obligations
- Legitimate Interests: To improve our Service, prevent fraud, and ensure security
- Legal Compliance: To comply with applicable laws and regulations
For End User personal data processed through the Service, we act as your processor and process that data on your instructions. You are responsible for establishing the lawful basis for that processing.
4. How We Use Your Information
4.1 Service Provision
- Connecting and managing your WhatsApp and Telegram accounts
- Displaying unified conversation dashboards
- Enabling bulk messaging campaigns
- Providing real-time conversation monitoring
- Preserving conversation histories
- Facilitating team collaboration and oversight
- Automated and AI-assisted processing of conversations when you use features that require it (for example quality or SLA review). We do not sell message content, and we do not train third-party models on your customer content unless separately agreed
4.2 Business Operations
- Processing payments and managing subscriptions
- Providing customer support
- Analyzing usage to improve our Service
- Detecting and preventing fraud or abuse
- Ensuring platform security and stability
4.3 Communications
- Sending service updates and notifications
- Providing technical support
- Marketing communications (with your consent)
- Legal notices and policy updates
5. Information Sharing and Disclosure
5.1 We Do Not Sell Personal Data
We do not sell, rent, or trade personal information to third parties.
5.2 Service Providers
We may share information with trusted third-party service providers who assist us in:
- Cloud hosting and data storage
- Payment processing
- Customer support tools
- Analytics and performance monitoring
- Security and fraud prevention
All service providers are bound by strict confidentiality agreements and data protection requirements. A current list of subprocessors is available on request at [email protected].
5.3 Legal Requirements
We may disclose information when required by law or in response to:
- Valid legal process (subpoenas, court orders)
- Government investigations
- Protecting rights, property, or safety
- Preventing fraud or illegal activities
5.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, personal information may be transferred as part of the business transaction, subject to continued privacy protection.
6. Data Security
6.1 Security Measures
We implement industry-standard security measures including:
- Encryption in transit and at rest
- Encrypted data storage
- Access controls and authentication
- Regular security audits and monitoring
- Secure data centers with physical security
- Employee training on data protection
6.2 Data Breach Response
In the event of a personal data breach, we will:
- Investigate and contain the breach without undue delay
- Where we act as processor, notify the affected customer (controller) without undue delay so they can meet their obligations
- Where we act as controller, notify the Office of the Commissioner for Personal Data Protection (Cyprus) within 72 hours when required by GDPR
- Notify affected individuals without undue delay when the breach is likely to result in a high risk to their rights and freedoms
- Cooperate with regulatory authorities and implement additional security measures as needed
7. Data Retention
7.1 Retention Periods
- Account Data: Retained while your account is active and for 90 days after closure
- Communication Data: Retained as specified in your service agreement or until deletion requested
- Billing Records: Retained for 7 years for tax and accounting purposes
- Support Data: Retained for 3 years after case resolution
7.2 Deletion Procedures
You can request deletion of your data by contacting us at [email protected]. We will process deletion requests within one month, subject to legal retention requirements.
8. Your Privacy Rights
8.1 All Users
- Access: Request information about data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data
- Opt-out: Unsubscribe from marketing communications
8.2 EU Users (Additional GDPR Rights)
- Portability: Request your data in a structured, machine-readable format
- Restriction: Request limitation of data processing
- Objection: Object to processing based on legitimate interests
- Withdraw Consent: Withdraw consent for specific processing activities
- Lodge Complaints: File a complaint with the Office of the Commissioner for Personal Data Protection (Cyprus), or with your local EU/EEA data protection authority
8.3 California Users (CCPA/CPRA Rights)
- Know: Right to know what personal information is collected
- Delete: Right to delete personal information
- Opt-out: Right to opt-out of the sale or sharing of personal information (note: we do not sell or share personal information for cross-context behavioral advertising)
- Non-discrimination: Right not to be discriminated against for exercising privacy rights
9. International Data Transfers
9.1 Data Location
Your data may be processed and stored in the United States and other countries where our service providers operate.
9.2 Transfer Safeguards
For EU users, we ensure adequate protection through:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions by the European Commission
- Other appropriate safeguards as required by GDPR
10. Children's Privacy
Our Service is not intended for children under 16 (or 13 in the US). We do not knowingly collect personal information from children. If we become aware that we have collected information from a child, we will delete it promptly.
11. Third-Party Platforms
11.1 WhatsApp and Telegram
Our Service integrates with WhatsApp and Telegram. These platforms have their own privacy policies and terms of service that govern your use of their services. Account connection is under your control and at your risk; you choose which accounts to link and remain responsible for compliance with those platforms' rules.
11.2 Third-Party Links
Our Service may contain links to third-party websites. We are not responsible for the privacy practices of these external sites.
12. Cookies and Tracking
12.1 Cookie Usage
We use cookies and similar technologies for:
- Authentication and security
- Preferences and settings
- Analytics and performance monitoring, where enabled for operating or improving the Service
12.2 Cookie Control
You can manage cookie preferences through your browser settings. Note that disabling certain cookies may affect Service functionality.
13. Marketing Communications
13.1 Consent
We will only send marketing communications with your explicit consent.
13.2 Opt-out
You can unsubscribe from marketing emails at any time using the unsubscribe link or by contacting us.
14. Updates to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated through:
- Email notifications to registered users
- Prominent notices on our website
- In-app notifications
Continued use of our Service after updates constitutes acceptance of the revised policy.
15. Contact Information
15.1 Privacy Questions
For privacy-related questions or requests, contact us at:
NOCODE LTD
Email: [email protected]
15.2 Data Protection Contact (EU)
If you are located in the EU, you may contact us regarding data protection at:
Email: [email protected]
15.3 Response Time
We will respond to privacy requests within:
- One month for GDPR rights requests (extendable by up to two further months for complex requests)
- 45 days for CCPA-related requests
- As soon as practicable for other general privacy inquiries
16. Regulatory Compliance
We are committed to compliance with applicable data protection laws, including:
- General Data Protection Regulation (GDPR) – EU
- California Consumer Privacy Act / CPRA – California
- Children's Online Privacy Protection Act (COPPA) – US
- Other applicable state and federal privacy laws