GDPR COMPLIANCE

Your Rights Under the General Data Protection Regulation

Our Commitment to GDPR

Zylex AI is committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

The GDPR gives you control over your personal data. This page explains your rights and how to exercise them.

Note: While Zylex AI strives to comply with GDPR principles globally, specific GDPR rights only apply to individuals in the European Economic Area (EEA), UK, and Switzerland.

Your GDPR Rights

Right to Access

You have the right to access your personal data and know how we use it.

How to exercise: Log in to your dashboard to view your account information and credit history. For a complete data export, contact us at privacy@zylexai.app.

Right to Rectification

You can update or correct your personal information at any time.

How to exercise: Update your email address through your account settings. Contact us for any corrections we need to make.

Right to Erasure (Right to be Forgotten)

You can request deletion of your personal data.

How to exercise: Contact us at privacy@zylexai.app with your account email. We will delete your data within 30 days, except where we have legal obligations to retain it.

Right to Restrict Processing

You can request that we limit how we use your data.

How to exercise: Contact us at privacy@zylexai.app to discuss restrictions on data processing.

Right to Data Portability

You can receive your data in a structured, machine-readable format.

How to exercise: Request a data export by emailing privacy@zylexai.app. We will provide your data in JSON format within 30 days.

Right to Object

You can object to certain types of data processing, including marketing.

How to exercise: Opt out of marketing emails by clicking the unsubscribe link in any email, or contact us directly.

Data Processing Details

Under GDPR, we must be transparent about what data we collect, why we collect it, and how long we keep it. Here's a detailed breakdown:

Account Data

Data Collected:

Email address, password (hashed), account creation date

Purpose:

Account management and authentication

Legal Basis:

Contractual necessity

Retention Period:

Until account deletion

Usage Data

Data Collected:

Tool usage, credit transactions, generation timestamps

Purpose:

Service provision and improvement

Legal Basis:

Legitimate interest

Retention Period:

90 days for transactions, account lifetime for totals

Content Data

Data Collected:

Your inputs to AI tools

Purpose:

AI processing through third-party APIs

Legal Basis:

Contractual necessity

Retention Period:

Temporary (not permanently stored)

Technical Data

Data Collected:

IP address, browser type, device info

Purpose:

Security, fraud prevention, analytics

Legal Basis:

Legitimate interest

Retention Period:

30 days for logs

International Data Transfers

Zylex AI uses third-party services that may process data outside the EEA:

  • Supabase (Database): Hosted on secure cloud infrastructure with GDPR-compliant safeguards.
  • OpenRouter (AI Processing): Your inputs are processed through AI APIs. OpenRouter implements appropriate security measures.
  • Payment Processors: Stripe and other payment providers comply with PCI-DSS and GDPR standards.

We ensure all third-party processors have adequate safeguards in place, including Standard Contractual Clauses (SCCs) where applicable.

Contact & Complaints

Data Protection Inquiries

For any questions about your data or to exercise your GDPR rights, contact us at:

privacy@zylexai.app

Response Time

We will respond to all GDPR requests within 30 days as required by law. Complex requests may take up to 60 days, and we will notify you if an extension is needed.

File a Complaint

If you believe we have not handled your data appropriately, you have the right to file a complaint with your local data protection authority:

  • EU: Your country's Data Protection Authority
  • UK: Information Commissioner's Office (ICO)
  • Switzerland: Federal Data Protection and Information Commissioner (FDPIC)

Security Measures

We implement appropriate technical and organizational measures to protect your data:

  • End-to-end HTTPS encryption
  • Password hashing (bcrypt)
  • Row Level Security (RLS) in database
  • Regular security audits
  • Access controls and authentication
  • Secure data centers (Supabase)

For more details, please see our Privacy Policy and Terms of Service.

Last Updated: November 30, 2025