Datenschutzerklärung
Standards for personal data processed for waitlist, inquiries, payment, onboarding, project notices, and service operation.
June 30, 2026
1. Data controller and contact
The data controller is LILIHA, and the service name is CiteLex.
Privacy inquiries and rights requests may be sent to contact@citelex.app. The privacy officer is Kim Riha, reachable at contact@citelex.app.
2. Personal data processed
Waitlist and inquiries: business or store name, email address, phone number, inquiry details, submission time, and access logs.
Payment and order management: order identifier, payment email, payment status, payment processor transaction identifier, payment amount and currency, refund or cancellation history, and access tokens.
Onboarding and production: business name, English name, industry, address, phone number, email, operating hours, holidays, reservation and parking information, descriptions, reviews, SNS, blog or YouTube links, representative image URLs, qualification or registration information, awards, press mentions, and industry-specific details entered by the customer.
Technical operation: IP address, user-agent, language settings in cookies or local storage, security logs, API call logs, error logs, and email delivery status may be processed. Raw card details are handled by payment processors such as PayPal and are not intentionally stored on company servers.
3. Purposes of processing
Personal data is used for waitlist notices, vacancy or next-schedule notices, inquiry response, payment confirmation, order identification, temporary onboarding storage and continuation, project-start and completion emails, website build, content production, domain connection, SSL application, operational monitoring, refund and dispute handling, and security auditing.
Business information submitted by the customer may be used to generate website copy, structured data, LLMs.txt, sitemap entries, content, facts payloads, and records sent to external site-building or automation platforms.
4. Retention period
The company retains personal data for the period necessary to achieve the purpose of processing and deletes it without delay when there is no legal retention obligation or dispute-handling need.
Waitlist and inquiry information may be retained for a necessary period after the notice or consultation purpose is achieved for follow-up response, reservation history confirmation, or dispute handling.
Records related to contracts, payment, supply, refunds, consumer complaints, or disputes may be retained for periods required by applicable e-commerce, tax, accounting, or related laws.
Security logs and access records may be retained for a necessary period to prevent misuse, respond to security incidents, and verify service stability.
5. Third-party provision and processing delegation
The company may provide or delegate processing of personal data or business information to payment processors, email services, cloud or hosting services, database services, map or address enrichment services, external automation programs, webhook receivers, and site-building platforms as needed.
Waitlist and inquiry content may be delivered through email services to contact@citelex.app or another designated operations inbox.
Information sent to external programs is, in principle, limited to what is needed for website build, content generation, information enrichment, and operational verification.
If cloud, payment, email, or database services provided by overseas operators are used, information may be stored or processed outside the customer’s country.
6. Security measures
The company applies reasonable technical and administrative safeguards such as admin authentication, access restrictions, request rate limiting, security headers, audit logs, encryption or tokenization of sensitive fields, environment-variable secret management, and server-to-server API key isolation.
Access to customer information is limited to personnel and systems needed for service operation, and the company seeks to reduce unnecessary collection and long-term retention.
The company may not be responsible for problems caused when the customer shares onboarding access links, order identifiers, or access tokens with third parties.
7. User rights
Customers may request access, correction, deletion, restriction of processing, or withdrawal of consent regarding their personal data.
However, information necessary for service provision, settlement, tax or accounting processing, legal retention, or dispute handling may be retained until that purpose ends.
Rights requests may be sent to contact@citelex.app, and the company handles them after identity verification in accordance with applicable law.
8. Cookies and local storage
The company may use cookies or browser local storage for language settings, onboarding continuation, security checks, and usability improvements.
Cookie storage may be refused through browser settings, but some functions may be limited.
9. Destruction and revisions
Electronic files are deleted in a way that makes recovery difficult, and printed materials are destroyed by shredding or an equivalent method.
This policy may be revised due to service structure, processing purpose, processor, or legal changes. Changes are announced by website posting or email.