Lattiva Privacy Policy

Effective date: 2026-02-19

§1. Data Controller

1. The controller of Users' personal data is Lattiva (hereinafter: "Controller"). 2. For data protection inquiries, contact the Controller at: [email protected].

§2. Scope of Collected Data

1. During registration, we collect: email address, first name (optional), and profile picture (optional). 2. While using the Service and Extension, we may collect: — text entered by the User for correction purposes (processed in real time, not permanently stored on servers), — user dictionary data (custom terms), — Service usage data (correction statistics, activity), — technical data (IP address, browser type, operating system).

§3. Purposes of Data Processing

1. Personal data is processed for the purpose of: a) providing the Service — text autocorrection and Service features (legal basis: Art. 6(1)(b) GDPR — performance of a contract), b) managing the User's Account (legal basis: Art. 6(1)(b) GDPR), c) handling payments and subscriptions (legal basis: Art. 6(1)(b) GDPR), d) communicating with the User, including notifications about Service changes (legal basis: Art. 6(1)(f) GDPR — legitimate interest), e) improving Service quality and analytics (legal basis: Art. 6(1)(f) GDPR).

§4. Text Processing

1. Text entered by the User is transmitted to the server solely for the purpose of correction. 2. Text is processed in real time and is not permanently stored on the Controller's servers. 3. The Controller does not use User text content for AI model training or marketing purposes. 4. When using AI-based correction from a third-party provider, text may be forwarded to the AI service provider in accordance with their data processing policy. The Controller uses only providers that ensure an adequate level of data protection.

§5. Data Sharing

1. Personal data may be shared with: a) payment service providers (Stripe) — to the extent necessary for payment processing, b) hosting and infrastructure providers (Railway, AWS) — to the extent necessary for Service provision, c) AI service providers — to the extent described in §4, d) governmental authorities — based on applicable legal provisions. 2. The Controller does not sell Users' personal data to third parties.

§6. Cookies

1. The Service uses cookies for: a) maintaining User sessions (session cookies), b) remembering User preferences (interface language, theme), c) website traffic analytics. 2. The User can manage cookies in their browser settings. 3. Disabling cookies may limit the functionality of the Service.

§7. User Rights

1. The User has the right to: a) access their personal data, b) rectification of data, c) erasure of data (right to be forgotten), d) restriction of processing, e) data portability, f) object to processing, g) lodge a complaint with the relevant supervisory authority. 2. To exercise these rights, contact the Controller at: [email protected] or use the account deletion feature in your profile settings.

§8. Data Retention Period

1. Personal data is retained for the duration of an active Account. 2. After Account deletion, personal data is permanently removed within 30 days, except for data required to be retained by law (e.g., billing data — 5 years). 3. Technical logs (IP addresses) are retained for no more than 90 days.

§9. Data Security

1. The Controller applies appropriate technical and organizational measures to protect personal data, including: a) connection encryption (HTTPS/TLS), b) password hashing (bcrypt), c) access control to systems, d) regular software updates. 2. Despite security measures, the Controller advises that no method of data transmission over the internet is completely secure.

§10. Changes to the Privacy Policy

1. The Controller reserves the right to amend this Privacy Policy. 2. Users will be notified of significant changes via email or an in-Service notification at least 14 days before the changes take effect. 3. The current version of the Privacy Policy is available at lattiva.ai/privacy.