Data Privacy Statement (Canada, North America)

GLOBAL PRIVACY NOTICE

Company: LXT AI Inc. 4312 Village Centre Ct, Mississauga, ON L4Z 1S2, Canada
Effective Date:12th March, 2026
Last Updated:12th March, 2026

1. Introduction

This Global Privacy Notice explains how LXT AI Inc. ("LXT," "we," "us," or "our") collects, uses, stores, transfers, discloses, and protects personal data relating to individuals who access or interact with our platforms and services. This includes contributors (also referred to as "clickworkers"), clients, vendors, applicants, and website visitors.

We take privacy and data protection seriously. This Notice is intended to provide transparent information about our processing practices and to support compliance with privacy and data protection laws that apply to our activities in Canada, the United States, Mexico, the European Union, and other jurisdictions in which we operate.

Certain projects may involve additional or different processing. In those cases, we will provide a project-specific privacy statement or addendum before the relevant personal data is collected. That project-specific notice supplements this Notice and, for the processing it describes, will prevail if there is a conflict.

2. Corporate Structure, Hosting, and Roles

LXT AI Inc. is an Ontario, Canada corporation with its business address at 4312 Village Centre Ct, Mississauga, ON L4Z 1S2, Canada. clickworker.com, Inc. and clickworker Germany GmbH are subsidiaries of LXT AI Inc.

To provide our services securely and efficiently, LXT operates through an international corporate structure consisting primarily of LXT AI Inc. in Canada and clickworker Germany GmbH in Germany.

Joint Data Controllers

LXT AI, Inc.
4312 Village Centre Ct
Mississauga, ON L4Z 1S2, Canada

clickworker Germany GmbH
Theodor-Althoff-Straße 41
45133 Essen, Germany

LXT AI Inc. and clickworker Germany GmbH jointly determine the purposes and means of processing personal data in connection with operation of the platform and therefore act as joint controllers where applicable, including under Article 26 of the General Data Protection Regulation (GDPR). Internal agreements allocate responsibility for compliance obligations and the handling of individual rights requests. Individuals may contact our Data Protection Officer using the details in Section 15, regardless of which joint controller is responsible for a particular processing operation.

Hosting and Technical Operations

The platform is technically hosted, maintained, and supported by clickworker Germany GmbH in Germany under the joint-controller arrangement. Personal data is stored and processed on OVH servers in France and on Amazon Web Services servers and storage located in Germany and Ireland.

Because we operate internationally, personal data collected from individuals in Canada, the United States, Mexico, and other countries may be transferred to and processed in the European Union and may be accessed by authorized personnel or service providers in other jurisdictions where necessary to provide the services. Transfers are subject to applicable contractual, organizational, and technical safeguards.

3. Scope of This Notice

This Notice applies when we collect and process personal data relating to platform users and independent contractors (clickworkers), clients and vendors, job applicants, and website visitors. It covers interactions with our websites, mobile applications, platform features, communications, surveys, support channels, recruitment processes, and related services.

4. Categories and Sources of Personal Data

We collect personal data directly from you, automatically through your device or your use of our services, and, where legally permitted, from clients, service providers, verification providers, public sources, and other third parties.

  • Identifiers. Name, postal address, email address, Internet Protocol address, account name, Social Insurance Number, Social Security number, tax identification number, or comparable identifiers required for payment, verification, or regulatory compliance.
  • Demographic information. Age, gender, nationality, and primary language, where voluntarily provided or strictly required for participation in a particular project.
  • Professional or employment data. Resumes, work history, qualifications, certifications, application information, and related recruitment records.
  • Financial information. Payment account details, transaction identifiers, payment processor information, and other information necessary to process compensation or payments.
  • Work product data. Materials submitted during task completion, including text, images, audio recordings, video recordings, annotations, responses, and associated metadata.
  • Technical and usage data. Browser type, device type, operating system, device and network identifiers, interaction logs, authentication records, timestamps, diagnostic data, and access logs.
  • Sensitive personal data and special categories. Certain projects may require personal data that is sensitive or is treated as a special category under applicable law, including biometric identifiers or characteristics, facial or voice recordings, precise geolocation, or government identifiers. Before collecting such information, we will provide a project-specific privacy statement or addendum describing the categories collected, the project purposes, relevant recipients, retention, safeguards, choices, and other information required by applicable law. Where required, we will obtain express consent before collection or processing.

5. Purposes and Legal Bases for Processing

We process personal data only where permitted by applicable law and where a valid legal basis applies. Depending on the context and jurisdiction, processing may be based on performance of a contract, our legitimate interests or those of another party, compliance with legal obligations, or consent.

  • Performance of Contract: To provide platform access, administer accounts, match contributors with projects, receive work submissions, communicate about services, process payments, and manage the contractual relationship.
  • Legitimate Interests: To prevent fraud, ensure platform and information security, verify identity and account integrity, improve our services and AI models (including fraud detection), maintain business records, and establish, exercise, or defend legal claims.
  • Provided Project specific Consent: For project-specific tasks involving sensitive personal data or special categories of personal data, including facial or voice recordings, and for optional marketing communications where consent is required. Details will be provided in the relevant project-specific privacy statement or addendum.
  • Legal Obligations: To comply with tax reporting, anti-money laundering requirements, sanctions and trade controls, privacy and data protection requirements, lawful government requests, and other legal or regulatory duties.

Where processing is based on legitimate interests, we assess those interests against the rights and freedoms of affected individuals and implement safeguards designed to ensure fairness and proportionality. Where we rely on consent, consent may be withdrawn as explained in Section 13, without affecting the lawfulness of processing that occurred before withdrawal.

6. Automated Processing and Profiling

We use automated tools to analyze activity patterns in order to detect fraud, maintain platform security, verify account integrity, and match users with appropriate projects. These systems may evaluate indicators such as usage behavior, device consistency, login patterns, and historical task performance.

Such automated processing does not produce legal or similarly significant effects without meaningful human involvement. Individuals may request human review of an automated outcome, obtain additional information about the factors or logic involved where applicable, and contest an outcome by contacting our Data Protection Officer.

7. Disclosure of Personal Data

We do not sell personal data or user profiles to third parties. We disclose personal data only where necessary for legitimate business or legal purposes and only to recipients subject to appropriate confidentiality and data protection obligations.

Recipients may include:

  • Service providers and subprocessors Providers supporting platform infrastructure, hosting, payments, identity verification, analytics, communications, security, and internal support functions
  • Clients. Clients may receive work product submitted as part of task performance together with related metadata required for service delivery
  • Authorities and legal recipients. Courts, regulators, law enforcement bodies, tax authorities, or other public authorities where disclosure is required or permitted by applicable law or valid legal process
  • Professional advisers. Auditors, insurers, lawyers, accountants, and consultants subject to professional or contractual confidentiality duties

8. Data Retention

We retain personal data only for as long as necessary for the purposes described in this Notice, including to fulfill contractual obligations, comply with legal and regulatory requirements, resolve disputes, enforce agreements, maintain platform integrity, and establish or defend legal claims.

  • Account Data: Until account termination or permanent suspension, plus 40 days, except where particular data must be retained longer under another category below or for an applicable legal, security, dispute, or enforcement reason.
  • Work Submissions & Ratings: For the duration of the applicable customer contract or project, plus three years after contract termination or project completion, as applicable.
  • Payment & Tax Records: Seven to ten years, where legally required.
  • System/Security Logs: Twelve to thirty-six months, depending on the type of log and security purpose.
  • Recruitment Data: Six months after completion of the recruitment process unless the applicant is hired, consents to a longer period, or a different period is required or permitted by law.
  • Project-specific sensitive data: As specified in the applicable project-specific privacy statement or addendum.

Retention periods may be suspended or extended where preservation is reasonably necessary for litigation, investigations, legal holds, or the establishment, exercise, or defence of claims. When retention is no longer necessary, personal data is securely deleted, anonymized, or aggregated. Residual copies may remain temporarily in protected backups until they are overwritten in accordance with our backup schedules.

9. International Data Transfers

Due to our international operations, personal data may be transferred to, accessed from, or processed in countries other than the country in which it was originally collected. Those countries may have privacy and data protection laws that differ from the laws in your jurisdiction.

Where required, we use appropriate safeguards such as contractual protections, approved Standard Contractual Clauses, transfer impact and supplier risk assessments, encryption, access controls, and other legally recognized measures. LXT remains accountable under applicable Canadian privacy law for personal data transferred to service providers for processing and uses contractual or other measures intended to provide a comparable level of protection.

10. Data Security

We maintain administrative, technical, and physical safeguards designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These safeguards include encryption, access controls, monitoring, logging, network protections, employee confidentiality obligations, incident response procedures, and business continuity programs.

Personal data processed in another country may be accessible to courts, law enforcement agencies, national security authorities, or other public authorities in that country in accordance with local law. Individuals may contact our Data Protection Officer for further information about relevant service-provider locations and safeguards, subject to legal and security limitations

10. Data Security and Privacy Breaches

We maintain administrative, technical, and physical safeguards designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Depending on the nature and sensitivity of the data, these safeguards may include encryption, access controls, monitoring, logging, network protections, employee confidentiality obligations, incident response procedures, supplier controls, and business continuity measures.

No security measure can eliminate all risk. If a breach of security safeguards occurs, we will investigate and take steps required by applicable law, which may include notifying affected individuals and relevant regulators where the applicable legal threshold is met.

11. Cookies and Tracking Technologies

We use cookies and similar technologies to provide essential platform functionality, maintain security, remember preferences, analyze usage, and improve our services. Where required by applicable law, non-essential cookies and similar technologies are used only after consent has been obtained. Users may modify available cookie preferences at any time through our cookie settings. Browser or device controls may also allow users to block or delete cookies, although doing so may affect platform functionality.

12. Children’s Privacy

Our platform is intended for individuals aged eighteen or older. We do not knowingly collect or process personal data relating to minors through the platform. If we become aware that personal data of a minor has been processed inadvertently, we will take appropriate steps to delete it, subject to applicable legal requirements.

13. Your Privacy Rights

Depending on your jurisdiction and subject to applicable exceptions, you may have rights relating to your personal data, including rights of access, correction, deletion, restriction, objection, portability, withdrawal of consent, and rights relating to automated decision-making. Canadian rights are described in more detail in Appendix A.

To exercise a right, contact our Data Protection Officer using the details in Section 15. Please describe your request and your relationship with LXT sufficiently to allow us to identify the relevant records. We may request information reasonably necessary to verify identity and authority before acting on a request. Authorized agents may be required to provide proof of authority.

We will respond within the period required by applicable law. Some rights may be limited where an exception applies, including where data must be retained to comply with law, protect another person’s rights, preserve security, or establish, exercise, or defend legal claims. We will explain a refusal or limitation where required by law.

14. Changes to This Notice

We may update this Notice periodically to reflect changes in our processing practices, services, corporate arrangements, or legal requirements. The updated Notice will state its effective date. Where required by applicable law, material changes will be communicated by email, through the platform, or by another appropriate notice, and additional consent will be obtained where required

15. Contact Us

For all questions relating to data protection concerning our website and range of services, or to exercise your privacy rights, please contact our Data Protection Officer:

Prof. Dr. Thomas Jäschke
DATATREE AG
Märkische Straße 212–218
44141 Dortmund, Germany
Email: [email protected]
Telephone: +49 231 54380-798

Appendix A — Jurisdiction-Specific Privacy Notices

A.1 United States Privacy Addendum

This section applies to residents of U.S. states that have enacted comprehensive data privacy laws, including but not limited to New York, California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana

Notice of Collection and Processing

We collect the categories of personal information listed in Section 4 for the business and commercial purposes described in Section 5.

Selling and Sharing of Personal Information

  • No Sale of Data: We do not sell your personal information for monetary compensation.
  • No Cross-Context Behavioral Advertising: We do not share personal data for cross-context behavioral advertising.

Sensitive Data and Biometrics

Certain platform projects may require the collection of sensitive personal data such as biometric identifiers or precise geolocation. The applicable project-specific privacy statement or addendum will provide additional details, and where required by law we obtain express consent before processing such data.

Your State Privacy Rights

Depending on applicable state law, you may have the right to access or know, correct, or delete personal information; opt out of certain profiling; and receive equal service and pricing without unlawful discrimination for exercising a privacy right. Requests may be submitted to the Data Protection Officer identified in Section 15.

A.2 Canada Privacy Addendum

Application

For Canadian residents, LXT handles personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) where it applies and with applicable provincial privacy laws, including Quebec’s private-sector privacy legislation. In Ontario, PIPEDA generally applies to personal information collected, used, or disclosed by private-sector organizations in the course of commercial activities. Ontario’s Personal Health Information Protection Act may apply if LXT acts as a health information custodian or agent in a relevant context.

consent and Choices

We obtain consent for the collection, use, and disclosure of personal information where consent is required. The form of consent will reflect the sensitivity of the information and the reasonable expectations of the individual. Express consent will be obtained where required, including for sensitive or biometric information described in a project-specific privacy statement or addendum.

You may withdraw consent at any time, subject to reasonable notice and any legal or contractual restrictions. Withdrawal does not affect processing that occurred lawfully before withdrawal. Depending on the processing concerned, withdrawal may mean that we cannot offer a particular project, feature, payment method, or service. We will explain the relevant consequences when you make the request

Canadian Privacy Rights

  • Access: Access. You may request confirmation of whether we hold personal information about you and access to that information. You may also request information about how it has been used and an account of third parties to which it has been disclosed, subject to applicable exceptions.
  • Correction: You may challenge the accuracy and completeness of your personal information and request that it be corrected or supplemented as appropriate. Where appropriate, corrected information will be transmitted to relevant third parties.
  • Withdrawal of consent and deletion: You may withdraw consent as described above and may request deletion of personal information that is no longer required for an identified purpose, subject to applicable legal, contractual, security, and record-retention requirements.
  • Information about policies and practices: You may ask for information about our personal information management practices, including relevant categories of service providers and cross-border processing arrangements.
  • Challenge compliance: You may submit a privacy question or complaint to our Data Protection Officer. We will investigate complaints and take appropriate steps where a complaint is justified.

Submitting and Processing a Canadian Request

Submit your request to the Data Protection Officer identified in Section 15. Include your name, contact details, account or applicant identifier if applicable, the nature of the request, and enough detail to locate the relevant records. We may ask for reasonable identity verification. We will use verification information only for that purpose, unless otherwise permitted by law.

For requests governed by PIPEDA, we will respond with due diligence and normally no later than 30 calendar days after receipt. Where PIPEDA permits an extension, we may extend the response period by up to an additional 30 days and will notify you within the initial period of the extension, the reason for it, and your right to complain. Access will be provided at no or minimal cost as required by law, and we will advise you in advance of any permitted cost.

Cross-Border Processing

LXT and its service providers may process Canadian personal information outside Canada, including in France, Germany, and Ireland. LXT remains accountable for personal information transferred to a service provider for processing and uses contractual or other measures intended to provide a comparable level of protection. Personal information processed abroad may be accessible to foreign courts, law enforcement agencies, national security authorities, or other public authorities under local law. Contact our Data Protection Officer for additional information about relevant processing locations and safeguards.

Complaints and Regulatory Recourse

We encourage you to raise a concern with our Data Protection Officer first so that we can investigate and respond. If you are not satisfied, you may have the right to complain to the Office of the Privacy Commissioner of Canada at www.priv.gc.ca or to the applicable provincial privacy regulator. Contacting us first does not prevent you from contacting a regulator at any time.

A.3 Mexico Privacy Addendum

FFor residents of Mexico, processing complies with the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP).

  • ARCO Rights: You may exercise rights of Access, Rectification, Cancellation, and Opposition.
  • Requests: Send requests to the Data Protection Officer identified in Section 15.

15. Contact Us

Data Privacy Team
LXT AI, Inc.
4312 Village Centre Ct.
Mississauga, ON L4Z 1S2, Canada
Email: [email protected]