Last updated: June 2026

Julexis Privacy Policy

Your Privacy Matters to Us

At Julexis, we are committed to protecting your privacy and being transparent about how we collect, use, and share your information. This Privacy Policy explains our data practices in detail and outlines your rights regarding your personal information.

Data Controller

Giulio Palumbo Schiavone (Sole Proprietorship / Impresa Individuale)

Via Emanuele Gianturco 30, 80046 San Giorgio a Cremano (NA), Italy

VAT: IT09223291213 | Tax Code: PLMGLI87L29A509H | REA: NA - 1020907

Email: privacy@julexis.com | PEC: giulio.palumboschiavone@pec.it

GDPR and Privacy Framework Compliance

This Privacy Policy complies with the European Union's General Data Protection Regulation (GDPR - Regulation EU 2016/679) and the Italian Privacy Code (D.Lgs. 196/2003 as amended by D.Lgs. 101/2018) and, where applicable, other privacy laws such as the California Consumer Privacy Act (CCPA). We respect your privacy rights regardless of where you are located.

1. Information We Collect

1.1 Information You Provide Directly:

  • Account Information: Name, email address, password, company name, profile picture
  • Billing Information: Payment method details (processed by Stripe), billing address, VAT numbers
  • Content Data: Social media posts, content plans, images, videos, client information
  • Communication Records: Support tickets, feedback, survey responses
  • Settings and Preferences: Language preferences, notification settings, dashboard configurations
  • Integration Data: Social media account connections, platform permissions

1.2 Information We Collect Automatically:

  • Usage Analytics: Pages visited, features used, time spent, click patterns
  • Technical Information: IP address, browser type, device information, operating system
  • Performance Data: Loading times, error reports, system performance metrics
  • Location Data: General geographic location based on IP address
  • Cookies and Tracking: Session cookies, preference cookies (see our Cookie Policy)

1.3 Information from Third Parties:

  • Social Media Platforms: Profile information, follower counts, engagement metrics
  • Payment Processors (Stripe): Transaction status, payment confirmations
  • AI Service Providers (OpenAI): Content generation requests and responses
  • Inbox and messages: Direct messages, comments, and replies shown in the Inbox are fetched live from the connected platforms when you open them. We do not store the content of these messages on our servers

1.4 Provision of Data: Providing your personal data is voluntary, except where indicated as mandatory (e.g., account registration, billing). If you do not provide mandatory data, you may not be able to use certain features of the Service. Data marked as optional can be withheld without any effect on your use of the Service.

2. Legal Basis for Processing (GDPR Art. 6)

Processing ActivityLegal Basis
Account creation and managementContract performance (Art. 6(1)(b))
Subscription billing and paymentsContract performance (Art. 6(1)(b))
AI content generationContract performance (Art. 6(1)(b))
Social media publishingContract performance (Art. 6(1)(b))
Service improvement and bug fixesLegitimate interest (Art. 6(1)(f))
Security monitoring and fraud preventionLegitimate interest (Art. 6(1)(f))
Marketing communicationsConsent (Art. 6(1)(a))
Analytics cookiesConsent (Art. 6(1)(a))
Tax and accounting recordsLegal obligation (Art. 6(1)(c))
Response to legal requestsLegal obligation (Art. 6(1)(c))

3. How We Use Your Information

3.1 Service Provision:

  • Create and maintain your user account
  • Process and generate AI-powered content based on your input
  • Schedule and publish content to connected social media platforms
  • Store and organize your content plans and media libraries
  • Enable collaboration features with clients and team members
  • Generate reports, analytics, and performance insights

3.2 Service Improvement:

  • Analyze usage patterns to improve user experience
  • Develop new features and functionality
  • Optimize AI algorithms and content generation quality
  • Perform security monitoring and threat detection
  • Debug technical issues and optimize performance

3.3 Communication:

  • Send account-related notifications and updates
  • Provide customer support and respond to inquiries
  • Share product updates, features, and educational content
  • Send billing notifications and payment confirmations
  • Deliver marketing communications (with your consent)

3.4 Legal and Compliance:

  • Comply with applicable laws and regulations
  • Respond to legal requests and court orders
  • Protect our rights and prevent fraud or abuse
  • Enforce our Terms of Use and other policies
  • Maintain records for tax and accounting purposes

4. Automated Decision-Making and AI Processing

AI-Powered Content Generation (GDPR Art. 22)

Julexis uses AI models to generate social media content based on your input. This processing involves:

  • What happens: Your content briefs, prompts, and preferences are sent to OpenAI's API to generate text content suggestions
  • Human oversight: All AI-generated content is presented to you as suggestions. You always have the ability to review, edit, or reject any AI-generated content before publishing
  • No automated decisions with legal effects: The AI does not make any decisions that produce legal effects or similarly significant effects concerning you. Content generation is purely assistive
  • Data sent to OpenAI: Only the text content of your prompts and briefs is sent. We do not send personal identification data, billing info, or account credentials. Per OpenAI's API terms, this data is not used to train their models
  • Your right to object: You can choose not to use AI features and create all content manually

5. Information Sharing and Disclosure

We do not sell, rent, or trade your personal information to third parties for their marketing purposes.

5.1 Service Providers (Data Processors): We share information with trusted third-party service providers who process data on our behalf under Data Processing Agreements (DPAs) compliant with GDPR Art. 28:

  • Supabase: Database hosting and backend services (data center: EU/US)
  • Vercel: Web hosting and deployment services (data center: Global CDN), including anonymous, cookieless performance measurement (Vercel Speed Insights)
  • Railway: Hosting of our social publishing and analytics backend API (data center: EU/US)
  • OpenAI: AI content generation. When you use AI features, the text of your prompts, briefs, and post content is sent to OpenAI's API for processing using our own server-side API key. Data is processed in the US under Standard Contractual Clauses and, per OpenAI's API terms, is not used to train OpenAI's models
  • Google Analytics (Google Ireland Ltd): Website usage analytics, loaded only after you grant analytics consent (see our Cookie Policy)
  • Upload-Post API: Social media publishing services
  • Resend: Email delivery and communication services
  • Stripe: Payment processing (PCI DSS compliant)

5.2 Social Media Platforms: When you connect and authorize social media accounts:

  • We share content you choose to publish through our Service
  • We may access public profile information as needed for functionality
  • We retrieve engagement metrics and analytics data
  • All sharing is based on your explicit authorization
  • Content already published to a social platform remains on that platform after you delete your Julexis account. To remove it, delete it directly on each platform; deleting your Julexis account only disconnects the account and removes the data we hold

5.3 Legal Requirements: We may disclose your information if required by:

  • Valid legal process, such as court orders or subpoenas
  • Government investigations or regulatory requests
  • Law enforcement agencies in connection with criminal investigations
  • Emergency situations involving immediate threats to safety

5.4 Business Transfers: In the event of a merger, acquisition, or sale of assets:

  • Your information may be transferred to the acquiring entity
  • We will provide notice before any transfer occurs
  • The acquiring entity will be bound by this Privacy Policy
  • You will have the option to delete your account before transfer

6. Data Security and Protection

6.1 Security Measures: We implement security measures to protect your data:

  • Encryption: Data is encrypted in transit using TLS and at rest using encryption provided by our infrastructure providers
  • Access Controls: Role-based access with authentication requirements
  • Network Security: Infrastructure-level protections provided by Vercel and Supabase
  • Incident Response: Monitoring and rapid response procedures

6.2 Data Breach Response: In the unlikely event of a security incident:

  • We will investigate and contain the incident immediately
  • Affected users will be notified within 72 hours as required by GDPR Art. 33
  • The Garante per la Protezione dei Dati Personali will be notified as required by law
  • We will provide regular updates on remediation efforts
  • A detailed incident report will be made available

6.3 Your Security Responsibilities:

  • Use strong, unique passwords for your account
  • Enable two-factor authentication when available
  • Keep your contact information up to date
  • Report suspicious activity immediately
  • Log out from shared or public devices

7. Your Privacy Rights

7.1 Rights Under GDPR and Italian Law:

  • Right of Access (Art. 15): Request a copy of all personal data we hold about you
  • Right to Rectification (Art. 16): Correct inaccurate or incomplete data
  • Right to Erasure (Art. 17): Request deletion of your personal data ("right to be forgotten")
  • Right to Restriction (Art. 18): Restrict processing of your data in certain circumstances
  • Right to Data Portability (Art. 20): Export your data in a machine-readable format (JSON) directly from your account settings
  • Right to Object (Art. 21): Object to processing based on legitimate interests
  • Right to Withdraw Consent (Art. 7): Withdraw consent at any time for consent-based processing
  • Right Regarding Automated Decisions (Art. 22): Not be subject to solely automated decisions with legal effects

7.2 Exercising Your Rights: To exercise any of these rights:

7.3 Right to Lodge a Complaint: You have the right to lodge a complaint with the competent supervisory authority:

Garante per la Protezione dei Dati Personali

Piazza Venezia 11, 00187 Roma, Italy

Email: protocollo@gpdp.it

PEC: protocollo@pec.gpdp.it

Website: www.garanteprivacy.it

8. Cookies and Tracking Technologies

For detailed information about how we use cookies, please refer to our dedicated Cookie Policy.

8.1 Types of Cookies We Use:

  • Essential Cookies: Required for basic functionality and security (always active)
  • Preference Cookies: Remember your settings and customizations (with consent)
  • Analytics Cookies: Help us understand how you use our Service (with consent)
  • Marketing Cookies: Enable personalized advertising (with consent)

8.2 Cookie Control: You can manage cookies through:

  • Our cookie consent banner (shown on first visit)
  • Your browser settings to block or delete cookies
  • Privacy settings in your user account

9. International Data Transfers

9.1 Data Processing Locations:

  • Primary data processing occurs within the European Union
  • Some service providers (Vercel, Supabase, AI providers) may process data in the United States
  • We ensure appropriate safeguards for all international transfers

9.2 Transfer Safeguards: When we transfer data internationally, we use:

  • Standard Contractual Clauses (SCCs): EU-approved data transfer agreements as adopted by Commission Implementing Decision (EU) 2021/914
  • Adequacy Decisions: Transfers to countries deemed adequate by the European Commission
  • EU-US Data Privacy Framework: For certified US-based processors where applicable
  • Transfer Impact Assessments: We assess the laws and practices of destination countries

9.3 Your Rights Regarding International Transfers:

  • Request information about specific countries where your data is processed
  • Object to transfers that don't meet adequate protection standards
  • Request copies of safeguard documentation
  • File complaints with the Garante per la Protezione dei Dati Personali

10. Data Retention

10.1 Retention Periods by Data Type:

  • Account Information: Retained until account deletion + 30 days for backups
  • Content Plans and Posts: Retained until manual deletion or account closure
  • Content Published to Social Platforms: Not under our control — it remains on the relevant platform until you delete it there, even after you close your Julexis account
  • Usage Analytics: Aggregated data retained for 2 years, individual data for 90 days
  • Communication Records: Support tickets and emails retained for 2 years
  • Financial Records: Billing and payment data retained for 10 years (Italian tax law requirement)
  • Security Logs: Authentication and access logs retained for 1 year

11. Children's Privacy

Julexis is not intended for children under the age of 18.

We do not knowingly collect personal information from children under 18 years of age. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@julexis.com.

If we become aware that we have collected personal information from a child under 18, we will take steps to delete such information from our systems as quickly as possible.

For users in the European Union, we do not process personal data of individuals under 16 years of age without explicit parental consent, as required by GDPR.

12. Changes to This Privacy Policy

12.1 Policy Updates: We may update this Privacy Policy from time to time. When we make changes:

  • We will update the "Last updated" date at the top of this policy
  • We will notify you via email for material changes
  • We will provide in-app notifications for significant updates
  • We will maintain an archive of previous versions

12.2 Material Changes: For significant changes that affect your rights:

  • We will provide at least 30 days advance notice
  • You will have the opportunity to review and accept the changes
  • You may delete your account if you don't agree to the changes
  • Continued use of the Service constitutes acceptance

Privacy Contact Information

Data Controller: Giulio Palumbo Schiavone

Address: Via Emanuele Gianturco 30, 80046 San Giorgio a Cremano (NA), Italy

Privacy Inquiries: privacy@julexis.com

PEC: giulio.palumboschiavone@pec.it

General Support: support@julexis.com

Supervisory Authority: Garante per la Protezione dei Dati Personali

Response Time: We respond to privacy requests within 30 days

This privacy policy is also available as part of our complete legal documentation.